Created on
‎07-17-2023
10:57 PM
Edited on
‎01-11-2026
10:34 PM
By
Jean-Philippe_P
| Description | This article describes the initial troubleshooting steps for a GUI or CLI access issue. |
| Scope | FortiGate. |
| Solution |
To check the GUI or CLI access issues:
show system interface
config system global show full-configuration | grep 'set admin-\(port\|sport\|ssh-port\|telnet-port\)'
Check if the above administrative accesses are enabled at the interface level:
show system interface
show system admin
Note: Check if the user IP address is getting S-NAT before reaching FortiGate. If yes, make sure that the IP address is part of the trusted host list.
show firewall local-in-policy
Debug:
execute console timestamp enable
Attempt to connect from the client.
diagnose debug disable
Sniffer:
diagnose sniffer packet any "host <Client_Source_IP>" 6 0 a
Attempt to connect from the client. Press Ctrl+C to stop the capture.
config system global set admin-sport <port> end
show system settings | grep ike-tcp
Starting from v7.6.1, GUI access may conflict with the IPSec tunnel IKE TCP port for interfaces bound to an IPsec tunnel where the GUI admin port is also using port 443. See the document GUI access conflict with IPSec TCP tunnel on the same interface. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2026 Fortinet, Inc. All Rights Reserved.