system
Use the following commands for system related settings.
system admin-session
Use this command to view and kill log in sessions.
Syntax
diagnose system admin-session kill <sid>
diagnose system admin-session list
diagnose system admin-session status
Variable |
Description |
---|---|
kill <sid> |
Kill a current session.
|
list |
List log in sessions. |
status |
Show the current session. |
system aiserver
Use this command to view the FortiAI server.
Syntax
diagnose system aiserver get
Variable |
Description |
---|---|
get |
Get current FortiAI server. |
system csf
Use this command for Security Fabric diagnostics.
Syntax
diagnose system csf authorization {accept | deny | pending-list} <SN> [name]
diagnose system csf downstream [-x] [-a]
diagnose system csf downstream-devices
diagnose system csf global
diagnose system csf resync-fmg-cluster
diagnose system csf upstream
Variable |
Description |
---|---|
authorization {accept | deny | pending-list} <sn> [name] |
Authorization requests and permits.
|
downstream [-x] [-a] |
Show connected downstream devices.
|
downstream-devices |
Show downstream fabric device. |
global |
Show a summary of all connected members in Security Fabric. |
resync-fmg-cluster |
Resync " |
upstream |
Show connected upstream devices. |
system disk
Use this command to view disk diagnostic information.
Only |
Syntax
diagnose system disk attributes
diagnose system disk delete
diagnose system disk disable
diagnose system disk enable
diagnose system disk errors
diagnose system disk health
diagnose system disk info
diagnose system disk sed <sed-key>
diagnose system disk usage <parameter> <parameter> <parameter> <parameter> <parameter> <parameter> <parameter> <parameter> <parameter> <parameter>
Variable |
Description |
||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
attributes |
Show vendor specific SMART attributes. |
||||||||||||||||||||||||
delete |
Delete the disk. |
||||||||||||||||||||||||
disable |
Disable SMART support. |
||||||||||||||||||||||||
enable |
Enable SMART support. |
||||||||||||||||||||||||
errors |
Show the SMART error logs. |
||||||||||||||||||||||||
health |
Show the SMART health status. |
||||||||||||||||||||||||
info |
Show the SMART information. |
||||||||||||||||||||||||
sed <sed-key> |
SED encryption key. The key requires 8-32 characters, and it must include upper case, lower case, number, and special character (excluding '\). This command is only available on hardware models that support self-encrypting drives. For more information, see the FortiManager Administration Guide. |
||||||||||||||||||||||||
usage <parameter> ... <parameter> |
Display the disk usage. Enter a parameter. |
||||||||||||||||||||||||
|
|
system export
Use this command to export logs.
Syntax
diagnose system export autoupdatelog <sftp | ftp> <(s)ftp server> <username> <password> <directory> <filename>
diagnose system export crashlog <ftp server> <username> <password> <directory> <filename>
diagnose system export dminstallog <devid> <ftp server> <username> <password> <directory> <filename>
diagnose system export fmwslog {ftp | sftp} <type> <(s)ftp server> <username> <password> <directory> <filename>
diagnose system export raidlog <ftp server> <username> <password> [remote path] [filename]
diagnose system export umlog {ftp | sftp} <type> <(s)ftp server> <username> <password> <directory> <filename>
diagnose system export upgradelog <ftp server> <username> <password> <directory> <filename>
diagnose system export vartmp <ftp server> <username> <password> <directory> <filename>
Variable |
Description |
---|---|
autoupdatelog <sftp | ftp> <(s)ftp server> <username> <password> <directory> <filename> |
Export autoupdate debug log files. For filename, enter the tgz filename. For example, |
crashlog <sftp | ftp> <(s)ftp server> <username> <password> <directory> <filename> |
Export the crash log. |
dminstallog <devid> <sftp | ftp> <(s)ftp server> <username> <password> <directory> <filename> |
Export the deployment manager install log. |
fmwslog {ftp | sftp} <type> <(s)ftp server> <username> <password> <directory> <filename> |
Export the web service log files. The type is the log file prefix and can be: |
raidlog <ftp server> <username> <password> [remote path] [filename] |
Export the RAID log. This command is only available on devices that support RAID. |
umlog {ftp | sftp} <type> <(s)ftp server> <username> <password> <directory> <filename> |
Export the update manager and firmware manager log files. The |
upgradelog <sftp | ftp> <(s)ftp server> <username> <password> <directory> <filename> |
Export the upgrade error log. |
vartmp <sftp | ftp> <(s)ftp server> <username> <password> <directory> <filename> |
Export the system log files in |
system flash
Use this command to diagnose the flash memory.
Syntax
diagnose system flash list
Variable |
Description |
---|---|
list |
List flash images. The information displayed includes the image name, version, total size (KB), used (KB), percent used, boot image, and running image. |
system fsck
Use this command to check and repair the filesystem.
Syntax
diagnose system fsck harddisk
diagnose system fsck reset-mount-count
Variable |
Description |
---|---|
harddisk |
Check and repair the file system, then reboot the system. |
reset-mount-count |
Reset the mount-count of the disk on the next reboot. |
system geoip
Use these commands to get geographic IP information.
FortiManager uses a MaxMind GeoLite database of mappings between geographic regions and all public IPv4 addresses that are known to originate from them.
Syntax
diagnose system geoip dump
diagnose system geoip info
diagnose system geoip ip <ip>
Variable |
Description |
---|---|
dump |
Display all geographic IP information. |
info |
Display a brief geography IP information. |
ip <ip> |
Find the specified IP address' country. |
Example
Find the country of the IP address 4.3.2.1:
FMG-VM64 # diagnose system geoip ip 4.3.2.1
4.3.2.1 : US - United States
system geoip-city
Use these commands to get geographic IP information at a city level.
Syntax
diagnose system geoip-city info
diagnose system geoip-city ip <ip>
Variable |
Description |
---|---|
info |
Display geographic IP information. |
ip <ip> |
Find the specified IP address' city. |
system interface
Use this command to diagnose the interface.
Syntax
diagnose system interface segmentation-offload <intf-name> <action>
Variable |
Description |
---|---|
segmentation-offload <intf-name> <action> |
Print/set segmentation-offload for all interfaces:
|
system mapserver
Use this command to access the map server information.
Syntax
diagnose system mapserver checksum
diagnose system mapserver clearcache
diagnose system mapserver get
diagnose system mapserver test
Variable |
Description |
---|---|
checksum |
Get map server checksum. |
clearcache |
Clear the map server cache. |
get |
Get the current map server. |
test |
Test the map server connection. |
system ntp
Use this command to list NTP server information.
Syntax
diagnose system ntp status
Variable |
Description |
---|---|
status |
List NTP server information. |
system print
Use this command to print server information.
Syntax
diagnose system print connector [adom] <server_type> <server> <tag>
diagnose system print cpuinfo
diagnose system print df [arg0] [arg1] [arg2] .... [arg9]
diagnose system print hosts
diagnose system print interface <interface>
diagnose system print loadavg
diagnose system print netstat
diagnose system print partitions
diagnose system print route
diagnose system print rtcache
diagnose system print slabinfo
diagnose system print sockets
diagnose system print uptime
Variable |
Description |
---|---|
connector [adom] <server_type> <server> <tag> |
Print connector information. Enter the ADOM name, or Global, the server type (pxGrid, clearpass, or nsx), and then the server name. |
cpuinfo |
Print the CPU information. |
df [arg0] [arg1] [arg2] .... [arg9] |
Print the file system disk space usage. Optionally, enter arguments. |
hosts |
Print the static table lookup for host names. |
interface <interface> |
Print the specified interface's information. |
loadavg |
Print the average load of the system. |
netstat |
Print the network statistics for active Internet connections (servers and established). |
partitions |
Print the disk partition information. |
route |
Print the main route list. |
rtcache |
Print the contents of the routing cache. |
slabinfo |
Print the slab allocator statistics. |
sockets |
Print the currently used socket ports. |
uptime |
Print how long the system has been running. |
system process
Use this command to view and kill processes.
Syntax
diagnose system process fdlist <pid> [list]
diagnose system process kill -<signal> <pid>
diagnose system process killall {Scriptmgr | deploymgr | fgfm}
diagnose system process list
Variable |
Description |
---|---|
fdlist <pid> [list] |
List all file descriptors that the process is using.
|
kill -<signal> <pid> |
Kill a process:
|
killall {Scriptmgr | deploymgr | fgfm} |
Kill all the related processes. |
list |
List all processes running on the FortiManager. The information displayed includes the PID, user, VSZ, stat, and command. |
system raid
Use this command to view RAID information.
This command is only available on FortiManager models that support RAID. |
Syntax
diagnose system raid hwinfo
diagnose system raid status
Variable |
Description |
---|---|
hwinfo |
Show RAID controller hardware information. |
status |
Show RAID status. |
system route
Use this command to help diagnose routes. The listed information includes the destination IP, gateway IP, netmask, flags, metric, reference, use, and interface for each IPv4 route.
The following flags can appear in the route list table:
-
U: the route is up
-
G: the route is to a gateway
-
H: the route is to a host rather than a network
-
D: the route was dynamically created by a redirect
-
M: the route was modified by a redirect
Syntax
diagnose system route list
system route6
Use this command to help diagnose routes. The listed information includes the destination IP, gateway IP, netmask, flags, metric, reference, use, and interface for each IPv6 route.
For a list of flags that can appear in the route6 list table, see information for the diagnose system route list
command above.
Syntax
diagnose system route6 list
system server
Use this command to start the FortiManager server.
Syntax
diagnose system server start