FortiGate packet capture commands and useful filters
Capture one FortiGate traffic flow with bounded sniffer commands. Find ingress, egress and replies, account for NAT, and stop captures safely.
Follow one traffic flow through the FortiGate before changing policy. These references help you choose the correct VDOM, inspect the active session and separate packet forwarding from routing, authentication and management-plane behavior.
10 references
Read-only results link to an individual observation command. Other commands on the same page can have different effects.
No matching references. Try a task such as packet capture, route lookup, BGP or interface errors.
Start with packet capture to establish where traffic is visible. Use the session table to inspect the policy and translations attached to an existing connection. Add a filtered debug flow when you need the firewall's decision for the packets being investigated. Debugging and captures change diagnostic state or consume resources; the articles include the relevant stopping steps.
For control-plane problems, choose the routing, BGP, SD-WAN or HA reference. The DNS/NTP reference separates name resolution from clock synchronization. The FAC and IKEv2 article follows the authentication result across FortiGate and FortiAuthenticator instead of assuming that accepting a phone notification completes the VPN.
Commands are grouped by task and scoped to the documented FortiOS syntax. For a specific failure message, continue to the existing FortiGate troubleshooting guides. For a planned configuration batch, use the address, address-group and service generators.
Capture one FortiGate traffic flow with bounded sniffer commands. Find ingress, egress and replies, account for NAT, and stop captures safely.
Run a bounded FortiGate debug flow for one connection. Understand policy, route and session messages, then stop debugging and clear filters.
Read-only command: diagnose debug flow filter
Filter FortiGate sessions by client, destination and port. Read policy IDs, NAT actions and reply counters without clearing live connections.
Read-only command: diagnose sys session filter
Check the route to a destination and match a complete flow against FortiGate policy routing. Separate route availability from forwarding decisions.
Read-only command: get router info routing-table detail 192.0.2.80
Check FortiGate BGP state, accepted and advertised routes, and routing-table installation. Diagnose one peer without resetting the BGP session.
Read-only command: get router info bgp summary
Inspect FortiGate link state, interface counters and ARP resolution. Compare counter changes and separate physical faults from Layer 3 problems.
Read-only command: diagnose hardware deviceinfo nic wan1
Inspect FortiGate FGCP members, roles and configuration checksums. Localize a synchronization mismatch without forcing failover or resynchronization.
Read-only command: get system status
Check FortiGate SD-WAN health, members and rule selection. Use the right service command for your FortiOS version and verify the actual flow.
Read-only command: diagnose sys sdwan member
Inspect FortiGate FQDN resolution and NTP synchronization. Distinguish cached addresses, DNS reachability, clock offset and time-zone display.
Read-only command: get system status
Correlate FortiGate IKE and RADIUS authentication with FAC push approval. Capture one login, identify timeout boundaries and stop debugging cleanly.