Is there an easy (preferrably, but anything goes..) way to cross-check any references to other items in the cli?
I just realised I don't know any way to do this...
Is it even possible?
Grep doesn' count...
:)
Richie
NSE7
Solved! Go to Solution.
yes
diag system checkused is a good thing to know.
http://socpuppet.blogspot.com/2014/10/a-few-examples-of-how-to-do-dependency.html
This is basically what the webGUI does. You ca check most object via he cli
examples
diag sys checkused firewall.adress.name <the exact name >
diag sys checkused firewall.addrgrp.name <the exact name>
diag sys checkused firewall.service.group.name msql
diag sys checkused firewall.vip.name < the exactname>
diag sys checkused firewall.service.custom.name < theexact name>
diag sys checkused firewall.policy.id
diag sys checkusd system.interface.name <interface exact name >
PCNSE
NSE
StrongSwan
yes
diag system checkused is a good thing to know.
http://socpuppet.blogspot.com/2014/10/a-few-examples-of-how-to-do-dependency.html
This is basically what the webGUI does. You ca check most object via he cli
examples
diag sys checkused firewall.adress.name <the exact name >
diag sys checkused firewall.addrgrp.name <the exact name>
diag sys checkused firewall.service.group.name msql
diag sys checkused firewall.vip.name < the exactname>
diag sys checkused firewall.service.custom.name < theexact name>
diag sys checkused firewall.policy.id
diag sys checkusd system.interface.name <interface exact name >
PCNSE
NSE
StrongSwan
Cool, thanks!
Richie
NSE7
A few more cool ones;
( vpn users and ldap )
diag sys checkused user.local.name theusernamehere
diag sys checkused user.ldap.name usernamehere
( interface in a vdom )
diag sys checkused system.vdom.name <vdomname>
( vpn interface )
dia sys checkused vpn.ipsec.phase1-interface.name interfacename
PCNSE
NSE
StrongSwan
Sorry for 2-year-old thread resurrection, but is there a version dependency here? FG100E, running v6.0.4 build0231 (GA), and diag sys doesn't have a "checkused" ?
sussed it out...
diagnose sys cmdb refcnt show firewall.vip.name
(for example)
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1749 | |
1114 | |
765 | |
447 | |
241 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.