FortiGate packet capture commands and useful filters
Capture one FortiGate traffic flow with bounded sniffer commands. Find ingress, egress and replies, account for NAT, and stop captures safely.
Find the command for the question you need to answer. Browse by platform, then choose a task such as checking an interface, finding a route, inspecting a BGP peer or following one connection through a firewall.
61 references
Read-only results link to an individual observation command. Other commands on the same page can have different effects.
No matching references. Try a task such as packet capture, route lookup, BGP or interface errors.
Each reference separates the command from its meaning. You will find the required CLI context, the fields to inspect, common interpretation mistakes and cleanup steps for diagnostics that keep running. Platform notes explain where the example applies; a similar command on another operating system is not a compatibility guarantee.
Use "packet capture" when you need to see where a flow appears. Use "route lookup" when you need to identify the selected next hop. Use "BGP" to distinguish a working session from a usable route. Use "interface errors" to compare current counter changes with a historical total.
The cross-vendor command comparison is a starting point when you switch between platforms. Open the linked reference before running a command whose scope or effect is unfamiliar.
Capture one FortiGate traffic flow with bounded sniffer commands. Find ingress, egress and replies, account for NAT, and stop captures safely.
Run a bounded FortiGate debug flow for one connection. Understand policy, route and session messages, then stop debugging and clear filters.
Read-only command: diagnose debug flow filter
Filter FortiGate sessions by client, destination and port. Read policy IDs, NAT actions and reply counters without clearing live connections.
Read-only command: diagnose sys session filter
Check the route to a destination and match a complete flow against FortiGate policy routing. Separate route availability from forwarding decisions.
Read-only command: get router info routing-table detail 192.0.2.80
Check FortiGate BGP state, accepted and advertised routes, and routing-table installation. Diagnose one peer without resetting the BGP session.
Read-only command: get router info bgp summary
Inspect FortiGate link state, interface counters and ARP resolution. Compare counter changes and separate physical faults from Layer 3 problems.
Read-only command: diagnose hardware deviceinfo nic wan1
Inspect FortiGate FGCP members, roles and configuration checksums. Localize a synchronization mismatch without forcing failover or resynchronization.
Read-only command: get system status
Check FortiGate SD-WAN health, members and rule selection. Use the right service command for your FortiOS version and verify the actual flow.
Read-only command: diagnose sys sdwan member
Inspect FortiGate FQDN resolution and NTP synchronization. Distinguish cached addresses, DNS reachability, clock offset and time-zone display.
Read-only command: get system status
Correlate FortiGate IKE and RADIUS authentication with FAC push approval. Capture one login, identify timeout boundaries and stop debugging cleanly.
Read RouterOS Ethernet link speed, errors, traffic counters and SFP diagnostics with a focused command reference and an evidence-first workflow.
Read-only command: /interface/print
Find a MAC address on a RouterOS bridge and inspect VLAN membership, PVID and hardware-offload state without changing the bridge configuration.
Read-only command: /interface/bridge/print detail
Inspect RouterOS v7 routes, next hops, custom tables and policy rules. Separate a missing route from selection of the wrong routing table.
Read-only command: /ip/route/print detail where dst-address=0.0.0.0/0
Inspect RouterOS firewall counters, NAT rules and connection tracking to follow one connection without flushing sessions or adding broad allow rules.
Read-only command: /ip/firewall/filter/print stats
Choose Torch or the RouterOS packet sniffer, filter one host or service, and understand NAT, hardware-offload and FastTrack visibility limits.
Read-only command: /tool/sniffer/print
Find RouterOS DHCP leases, check pool use and inspect delivered network settings. Separate server, client and relay questions before changing leases.
Read-only command: /ip/dhcp-server/print detail
Inspect RouterOS v7 BGP session state and one received prefix. Separate session establishment, route acceptance and next-hop selection.
Read-only command: /system/resource/print
Read RouterOS v7 OSPF neighbour states, interface templates and LSAs. Check adjacency and route installation as separate troubleshooting stages.
Read-only command: /routing/ospf/instance/print detail
Choose RouterOS binary backup or readable export, protect sensitive files and use Safe Mode for small remote changes without confusing it with a backup.
Read-only command: /system/identity/print
Inspect RouterOS IPsec IKE peers, matching policies and selected SA counters while avoiding session resets and accidental exposure of encryption keys.
Read-only command: /ip/ipsec/active-peers/print detail
Check Juniper link state, interface errors, flaps and optical receive power. A practical read-only workflow for MX, with EX and SRX differences.
Read-only command: show interfaces terse
Find IPv4 and IPv6 routes in Junos inet.0 and VRF tables. Compare a destination lookup, an exact prefix and the Routing Engine forwarding table.
Read-only command: show route summary
Troubleshoot Juniper BGP state, received routes and advertised prefixes. Understand what each command proves before resetting a session.
Read-only command: show bgp summary
Check Junos OSPF neighbors, interface timers, MTU and learned routes. Distinguish normal 2-Way behavior from a failed adjacency.
Read-only command: show ospf neighbor
Inspect IS-IS neighbors, Level 1 and Level 2 operation, interface metrics and the database on Juniper MX without resetting the protocol.
Read-only command: show isis adjacency
Trace an endpoint from IP to MAC to switch port. Separate Juniper EX ELS switching commands from MX bridge-domain commands.
Read-only command: show arp no-resolve
Inspect Junos stateless firewall filters, counters and policers. Verify attachment and compare counter changes without clearing production evidence.
Read-only command: show firewall
Review a Junos candidate, validate syntax and use commit confirmed deliberately. Understand rollback 0 versus rollback 1 before changing a device.
Read-only command: show system commit
Check Juniper LACP actor and partner state, packet counters and aggregate members. Diagnose a missing link without bouncing the whole bundle.
Read-only command: show interfaces ae0 terse
Collect Juniper logs, current time, NTP peer state and alarms before troubleshooting. Build a reliable incident timeline with read-only commands.
Read-only command: show version
Check Cisco IOS XE interface status, CRC errors, drops and err-disabled ports. Read-only Catalyst commands with a practical troubleshooting workflow.
Read-only command: show interfaces status
Troubleshoot Cisco Catalyst VLANs and 802.1Q trunks with read-only IOS XE commands. Compare allowed, active and forwarding VLANs at both ends.
Read-only command: show vlan brief
Find the STP root, inspect blocked ports and investigate inconsistent states on Cisco IOS XE. Includes separate PVST and MST read-only workflows.
Read-only command: show spanning-tree summary
Check Cisco IOS XE port-channel status, LACP neighbors and member flags. Understand suspended links and uneven traffic without resetting the bundle.
Read-only command: show etherchannel summary
Trace an IP address to a Cisco switch port using ARP, MAC tables, CDP and LLDP. Learn which table to check and where the method stops working.
Read-only command: show ip arp 192.0.2.10
Look up an IPv4 route in Cisco IOS XE, select the correct VRF and inspect CEF forwarding. Separate routing-table evidence from end-to-end reachability.
Read-only command: show ip route 203.0.113.25
Check IOS XE BGP sessions, accepted prefixes, advertised routes and route installation. Read-only commands with practical interpretation and scope limits.
Read-only command: show ip bgp summary
Troubleshoot OSPFv2 on IOS XE using neighbor, interface and database commands. Understand 2-Way, ExStart and Full without resetting the process.
Read-only command: show ip ospf
Check IOS XE IPv4 ACL attachment and rule matches. Learn why zero software counters on Catalyst 9000 do not prove that hardware traffic missed an ACL.
Read-only command: show ip interface GigabitEthernet0/0/0
Inspect IOS XE IPv4 NAT translations and statistics without clearing sessions. Follow a single flow and distinguish NAT state from successful connectivity.
Read-only command: show ip nat translations
Find the right UniFi SSH credentials and collect read-only device logs. Separate console, AP and switch access from legacy USG and EdgeOS commands.
Read-only command: tail -n 100 /var/log/messages
Choose a useful UniFi capture point for DHCP, DNS and TCP failures. Run short tcpdump captures and distinguish missing packets from a wrong interface.
Understand key UniFi management ports by endpoint and purpose. Separate device communication, browser access and discovery before changing firewall rules.
Save the right UniFi backup and collect console or device support files. Build a useful incident bundle without confusing recovery data with logs.
Understand EdgeOS operational and configuration modes. Preview changes and use commit-confirm correctly, including its reboot and saved-config behavior.
Read-only command: show configuration commands | no-more
Check EdgeOS routes, BGP sessions and advertised prefixes. Separate the BGP table, active routing table and policy-routing path before changing peers.
Read-only command: show ip route
Inspect EdgeOS interfaces and interface MAC addresses, then capture ARP on the correct LAN. Separate a physical port from its VLAN or switch interface.
Read-only command: show version
Read EdgeOS firewall and NAT counters without clearing sessions. Check interface attachment, WAN_IN versus WAN_LOCAL, rule order and a fresh test connection.
Read-only command: show firewall name WAN_IN statistics
Copy focused tcpdump filters for hosts, networks, DNS and TCP. Learn where to capture, how to save a PCAP and what missing packets really mean.
Read-only command: tcpdump -D
Find practical Wireshark display filters and matching capture filters for hosts, ports, DNS and TCP. Avoid common mistakes when investigating packet loss.
Read-only command: ip.addr == 192.0.2.20 && tcp.port == 443
Diagnose DNS with dig: choose a resolver, compare A and AAAA answers, test TCP, inspect response codes and distinguish NXDOMAIN from an empty answer.
Use Test-NetConnection, Resolve-DnsName and Get-NetTCPConnection to separate DNS, route, TCP and local-listener problems on Windows.
Read-only command: Get-NetTCPConnection -State Listen -LocalPort 443
Inspect Linux addresses, route selection, neighbors and sockets with read-only ip and ss commands. Find the right interface and local listener before changing configuration.
Read-only command: ip -br address show
Check a server certificate with OpenSSL while preserving SNI and hostname verification. Inspect expiry, SAN names and the difference between a supplied and trusted chain.
Read-only command: openssl x509 -in server.pem -noout -subject -issuer -dates
Separate DNS, TCP, TLS and HTTP failures with curl. Test one backend with --resolve, preserve hostname verification and read timing results correctly.
Run repeatable iperf3 tests and interpret single-stream, reverse and UDP results. Separate path capacity from endpoint limits without hiding weak performance.
Interpret all six BGP neighbor states, common reset reasons and an Established session with zero routes. Start with targeted read-only checks.
Read-only command: show ip bgp summary
Interpret SFP receive power, alarms and growing CRC counters. Compare both ends, use the actual optic limits and avoid replacing parts without evidence.
Read-only command: show interfaces diagnostics optics xe-0/0/0
Understand tagged and untagged VLAN traffic across vendors. Compare ingress classification, allowed membership and egress tagging before changing a port.
Read-only command: /interface bridge port print detail
Locate a DHCPv4 failure by following Discover, Offer, Request and ACK. Use packet evidence to distinguish VLAN, relay, scope and client problems.
Read-only command: udp port 67 or udp port 68
Find interface, IPv4 route and BGP inspection commands across FortiGate, MikroTik, Junos and Cisco, with context and links to detailed references.
Read-only command: get system interface physical