Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Umesh
Contributor

Debug command for understanding

Dear Team,

 

Anyone can help me the command which I have written here and description is correct.

 

Please guide me.

 

I am writing this post for the sake of knowledge, As I was trying to access https://www.fortinet.com from LAN machine. I just want to check which policy is using.

diagnose debug enable (to enable debug)
diagnose debug flow filter (addr,clear,daddr,dport,negate,port,proto,saddr,sport) (to filter source/destination address)
diagnose debug flow show function-name enable (not aware of this command)
diagnose debug console timestamp enable (not aware of this command)

diagnose debug flow trace start 100 (it will start capturing 100 packets)
diagnose debug flow trace stop (to stop capturing the packets)
diagnose debug disable (to disable debug)
diagnose debug flow console enable (not aware of this command)
diagnose debug reset (to reset debug, may ealier debug command used)


Go to LAN machine and try to access - https://www.fortinet.com

 

1 REPLY 1
msolanki
Staff
Staff

Hi Umesh,

 

You can run the  command mention and in about it generally shows "allowed by and policy ID number which indicates the traffic passing through which policy.

regarding command 

 

diagnose debug console timestamp enable  -it enables the time stamp of logs 

You can run the mention command set and it will generate logs about the flow of traffic. 

 

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors