| Description | This article describes the Debug flow tool in the FortiGate GUI. | ||||||||||||||||
| Scope | FortiOS v7.2. | ||||||||||||||||
| Solution |
To run the debug flow in the Firewall CLI, use the following command:
diagnose debug reset diagnose debug flow filter saddr <IP1> <IP5> <----- Where IP1 is the first IP address, IP5 is the last IP address. diagnose debug flow filter daddr y.y.y.y <----- Destination IP. diagnose debug flow filter daddr <IP1> <IP5> <----- Where IP1 is the first IP address, IP5 is the last IP address. diagnose debug flow filter port zzz
To stop the debug, run the following command:
diagnose debug disable diagnose debug reset
Note: These are the different filters that can be configured in the packet flow over the CLI console:
For more detailed information, check this guide: Technical Tip: Using filters to review traffic traversing the FortiGate
Related document: Embed real-time debug flow tool on Diagnostics page
Note: By default, the duration is 30 minutes. If it is necessary to increase or decrease the time, refer to Technical Tip: Changing debug duration. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.