pjhtech Tools
Command references

FortiGate CLI Command References

Follow one traffic flow through the FortiGate before changing policy. These references help you choose the correct VDOM, inspect the active session and separate packet forwarding from routing, authentication and management-plane behavior.

How to use these references

Start with packet capture to establish where traffic is visible. Use the session table to inspect the policy and translations attached to an existing connection. Add a filtered debug flow when you need the firewall's decision for the packets being investigated. Debugging and captures change diagnostic state or consume resources; the articles include the relevant stopping steps.

For control-plane problems, choose the routing, BGP, SD-WAN or HA reference. The DNS/NTP reference separates name resolution from clock synchronization. The FAC and IKEv2 article follows the authentication result across FortiGate and FortiAuthenticator instead of assuming that accepting a phone notification completes the VPN.

Commands are grouped by task and scoped to the documented FortiOS syntax. For a specific failure message, continue to the existing FortiGate troubleshooting guides. For a planned configuration batch, use the address, address-group and service generators.