Fortigate Troubleshooting Notes

 

Define a baseline 
  • CPU usage
  • Memory usage
  • Traffic levels

# get system status

# get system performance status

# diagnose sys top

# diagnose debug crashlog read     
! check if a demon has been crashing frequently, intrusive  for FG under performance issues
.

# execute tac report                          
intrusive  for FG under performance issues.

# diagnose hardware sys conserve   
! aid in conserve mode issue

# get hardware memory

# diagnose hardware deviceinfo disk

# print tabblesize
!Per-child-table limit *  Per-VDOM limit * System-wide (global) limit * Current usage





# diag debug application ike





# diagnose test application 

diagnose test application ipsmonitor 1
diagnose test application ipsmonitor
!display or toggle IPS engine

# diag sniffer packet <interface> <Filter> <verbose> <cout> <a>
https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-Using-the-FortiOS-built-in-packet-sniffer/ta-p/194222



















Comments