Skip to main content
suthomas1
New Member
August 6, 2020
Question

diagnosis

  • August 6, 2020
  • 6 replies
  • 7274 views

Good day all,

 

We are seeing an issue where the user traffic is not being successful & it is through a fortigate firewall.

To diagnose further, i used diagnosis debug flow cli options to check but with repeated attempts this does not show anything.

I then tried with diagnos sniff packet and then i was able to see the syn packets for this traffic on the firewall.

 

But the problem is because the debug flow is not showing details, i am not able to check if its a rule issue or something else on the firewall.

Is there a difference between debug flow & debug sniff commands. how can i check the problem further on this fortigate 500e with 6.1.

 

Please help.

    6 replies

    localhost
    Visitor III
    August 6, 2020

    If the SYN packet comes in on one interface but not going out on any other interface, you are most likely missing a firewall policy.

     

    Is your diagnose debug flow syntax correct?

     

    https://kb.fortinet.com/kb/documentLink.do?externalID=FD33882

    suthomas1
    suthomas1Author
    New Member
    August 6, 2020

    Yes the syntax is correct, i wrote it again from the site.

    suprising that diagnos sniffer shows some packets but not the full flow filter command.

     

    Any other way to troubleshoot this issue further?

    localhost
    Visitor III
    August 6, 2020

    The debug flow command does not show anything at all?

     

    Even if you do something like this:

     

    diagnose debug reset

    diagnose debug flow filter clear

    diagnose debug flow filter proto 1

    diagnose debug flow trace start 100
    diagnose debug enable

     

    If this gives you some output, your filter settings are probably wrong.

     

    Are you using vdom's and are you in the right vdom while running the debug commands?

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.