List Firewall Policies
Run: show firewall policy
1 step
-
Send
show firewall policySends Enter afterwards.
FortiOS policies, VPNs, SD-WAN and the session-table diagnostics.
by Nathan Kirk · 124 downloads · MIT licence · revision 1 · published 14 Aug 2026
Add Local User — Changes credentials or access (steps[3], sent text)
set passwd {{PASSWORD}}
Reboot FortiGate — Reboots or reloads the device (steps[1], sent text)
execute reboot
Shut Down FortiGate — Shuts down an interface (steps[1], sent text)
execute shutdown
Factory Reset — Factory resets the device (steps[1], sent text)
execute factoryreset
Flagged automatically by matching command text. It is a prompt to read the script, not a verdict — plenty of legitimate buttons reboot things on purpose.
4 sets, 133 buttons, 274 steps · 184.9 KB
File format version 1 · exported by Smartcom Revisited
5ca1b94130779243243a8539371db0321be6368bc28817f329d17281a22df189
You get the exact file the uploader submitted, byte for byte — that checksum is what
sha256sum will print. Import it from the button panel in
SmartCom Revisited.
Exactly what gets sent
This is the complete script of the file below — nothing is summarised or hidden. Read it before you download it, the same way you would read a script someone emailed you.
Firewall policies, address and service objects, NAT rules.
Run: show firewall policy
1 step
show firewall policy
Sends Enter afterwards.
Run: get firewall policy
1 step
get firewall policy
Sends Enter afterwards.
Run: diagnose firewall iprope show 100004
1 step
diagnose firewall iprope show 100004
Sends Enter afterwards.
Run: show firewall policy {{POLICY_ID}}
1 step · 1 input
show firewall policy {{POLICY_ID}}
Sends Enter afterwards.
Run: diagnose firewall proute list
1 step
diagnose firewall proute list
Sends Enter afterwards.
Run: show firewall address
1 step
show firewall address
Sends Enter afterwards.
Run: show firewall address {{OBJECT}}
1 step · 1 input
show firewall address {{OBJECT}}
Sends Enter afterwards.
Run: show firewall addrgrp
1 step
show firewall addrgrp
Sends Enter afterwards.
Run: show firewall service custom
1 step
show firewall service custom
Sends Enter afterwards.
Run: show firewall service group
1 step
show firewall service group
Sends Enter afterwards.
Run: show firewall schedule recurring
1 step
show firewall schedule recurring
Sends Enter afterwards.
Run: show firewall vip
1 step
show firewall vip
Sends Enter afterwards.
Run: show firewall ippool
1 step
show firewall ippool
Sends Enter afterwards.
Run: diagnose firewall ippool list
1 step
diagnose firewall ippool list
Sends Enter afterwards.
Run: diagnose sys vd list | grep name
1 step
diagnose sys vd list | grep name
Sends Enter afterwards.
Run: show firewall central-snat-map
1 step
show firewall central-snat-map
Sends Enter afterwards.
Run: show firewall profile-group
1 step
show firewall profile-group
Sends Enter afterwards.
Run: show webfilter profile
1 step
show webfilter profile
Sends Enter afterwards.
Run: show application list
1 step
show application list
Sends Enter afterwards.
Run: show ips sensor
1 step
show ips sensor
Sends Enter afterwards.
Run: config firewall address ; edit "{{OBJECT}}" ; set subnet {{SUBNET}} ; set comment "{{COMMENT}}" ; next ; end
6 steps · asks for confirmation before it runs · 3 inputs
config firewall address
Sends Enter afterwards.
edit "{{OBJECT}}"
Sends Enter afterwards.
set subnet {{SUBNET}}
Sends Enter afterwards.
set comment "{{COMMENT}}"
Sends Enter afterwards.
next
Sends Enter afterwards.
end
Sends Enter afterwards.
Run: config firewall address ; edit "{{OBJECT}}" ; set type fqdn ; set fqdn "{{FQDN}}" ; next ; end
6 steps · asks for confirmation before it runs · 2 inputs
config firewall address
Sends Enter afterwards.
edit "{{OBJECT}}"
Sends Enter afterwards.
set type fqdn
Sends Enter afterwards.
set fqdn "{{FQDN}}"
Sends Enter afterwards.
next
Sends Enter afterwards.
end
Sends Enter afterwards.
Run: config firewall addrgrp ; edit "{{GROUP}}" ; append member "{{OBJECT}}" ; next ; end
5 steps · asks for confirmation before it runs · 2 inputs
config firewall addrgrp
Sends Enter afterwards.
edit "{{GROUP}}"
Sends Enter afterwards.
append member "{{OBJECT}}"
Sends Enter afterwards.
next
Sends Enter afterwards.
end
Sends Enter afterwards.
Run: config firewall service custom ; edit "{{SERVICE}}" ; set protocol TCP/UDP/SCTP ; set tcp-portrange {{PORT_RANGE}} ; next ; end
6 steps · asks for confirmation before it runs · 2 inputs
config firewall service custom
Sends Enter afterwards.
edit "{{SERVICE}}"
Sends Enter afterwards.
set protocol TCP/UDP/SCTP
Sends Enter afterwards.
set tcp-portrange {{PORT_RANGE}}
Sends Enter afterwards.
next
Sends Enter afterwards.
end
Sends Enter afterwards.
Run: config firewall policy ; edit 0 ; set name "{{NAME}}" ; set srcintf "{{SRC_IFACE}}" ; set dstintf "{{DST_IFACE}}" ; set srcaddr "{{SRC}}" ; set dstaddr "{{DST}}" ; set service "{{SERVICE}}" ; set action accept ; set schedule always ; set nat enable ; set logtraffic all ; next ; end
14 steps · asks for confirmation before it runs · 6 inputs
config firewall policy
Sends Enter afterwards.
edit 0
Sends Enter afterwards.
set name "{{NAME}}"
Sends Enter afterwards.
set srcintf "{{SRC_IFACE}}"
Sends Enter afterwards.
set dstintf "{{DST_IFACE}}"
Sends Enter afterwards.
set srcaddr "{{SRC}}"
Sends Enter afterwards.
set dstaddr "{{DST}}"
Sends Enter afterwards.
set service "{{SERVICE}}"
Sends Enter afterwards.
set action accept
Sends Enter afterwards.
set schedule always
Sends Enter afterwards.
set nat enable
Sends Enter afterwards.
set logtraffic all
Sends Enter afterwards.
next
Sends Enter afterwards.
end
Sends Enter afterwards.
Run: config firewall policy ; edit {{POLICY_ID}} ; set comments "{{COMMENT}}" ; next ; end
5 steps · asks for confirmation before it runs · 2 inputs
config firewall policy
Sends Enter afterwards.
edit {{POLICY_ID}}
Sends Enter afterwards.
set comments "{{COMMENT}}"
Sends Enter afterwards.
next
Sends Enter afterwards.
end
Sends Enter afterwards.
Run: config firewall policy ; edit {{POLICY_ID}} ; set logtraffic all ; next ; end
5 steps · asks for confirmation before it runs · 1 input
config firewall policy
Sends Enter afterwards.
edit {{POLICY_ID}}
Sends Enter afterwards.
set logtraffic all
Sends Enter afterwards.
next
Sends Enter afterwards.
end
Sends Enter afterwards.
Run: config firewall policy ; move {{POLICY_ID}} before {{TARGET_ID}} ; end
3 steps · asks for confirmation before it runs · 2 inputs
config firewall policy
Sends Enter afterwards.
move {{POLICY_ID}} before {{TARGET_ID}}
Sends Enter afterwards.
end
Sends Enter afterwards.
Run: config firewall policy ; edit {{POLICY_ID}} ; set status disable ; next ; end
6 steps · asks for confirmation before it runs · 1 input
Asks yes or no: “Disable policy {{POLICY_ID}}. Traffic it was allowing now falls through to the rules below it, or is denied. Continue?”
Answering no stops the script here.
config firewall policy
Sends Enter afterwards.
edit {{POLICY_ID}}
Sends Enter afterwards.
set status disable
Sends Enter afterwards.
next
Sends Enter afterwards.
end
Sends Enter afterwards.
Run: config firewall policy ; edit 0 ; set name "{{NAME}}" ; set srcintf "{{SRC_IFACE}}" ; set dstintf "{{DST_IFACE}}" ; set srcaddr "{{SRC}}" ; set dstaddr "{{DST}}" ; set service "{{SERVICE}}" ; set action deny ; set schedule always ; set logtraffic all ; next ; end
14 steps · asks for confirmation before it runs · 6 inputs
Asks yes or no: “Add a deny policy. New rules land at the bottom unless you move them — check the position before you rely on it, and make sure it cannot match your own management traffic. Continue?”
Answering no stops the script here.
config firewall policy
Sends Enter afterwards.
edit 0
Sends Enter afterwards.
set name "{{NAME}}"
Sends Enter afterwards.
set srcintf "{{SRC_IFACE}}"
Sends Enter afterwards.
set dstintf "{{DST_IFACE}}"
Sends Enter afterwards.
set srcaddr "{{SRC}}"
Sends Enter afterwards.
set dstaddr "{{DST}}"
Sends Enter afterwards.
set service "{{SERVICE}}"
Sends Enter afterwards.
set action deny
Sends Enter afterwards.
set schedule always
Sends Enter afterwards.
set logtraffic all
Sends Enter afterwards.
next
Sends Enter afterwards.
end
Sends Enter afterwards.
Run: config firewall policy ; delete {{POLICY_ID}} ; end
4 steps · asks for confirmation before it runs · 1 input
Asks yes or no: “Delete policy {{POLICY_ID}} permanently. Anything it was permitting stops immediately. Continue?”
Answering no stops the script here.
config firewall policy
Sends Enter afterwards.
delete {{POLICY_ID}}
Sends Enter afterwards.
end
Sends Enter afterwards.
Run: config firewall address ; delete "{{OBJECT}}" ; end
4 steps · asks for confirmation before it runs · 1 input
Asks yes or no: “Delete address object {{OBJECT}}. This fails if a policy still references it, and breaks that policy if it does not. Continue?”
Answering no stops the script here.
config firewall address
Sends Enter afterwards.
delete "{{OBJECT}}"
Sends Enter afterwards.
end
Sends Enter afterwards.
Interfaces, routes, SD-WAN members and link health checks.
Run: get system interface physical
1 step
get system interface physical
Sends Enter afterwards.
Run: show system interface
1 step
show system interface
Sends Enter afterwards.
Run: get system interface {{IFACE}}
1 step · 1 input
get system interface {{IFACE}}
Sends Enter afterwards.
Run: diagnose netlink interface list {{IFACE}}
1 step · 1 input
diagnose netlink interface list {{IFACE}}
Sends Enter afterwards.
Run: get system arp
1 step
get system arp
Sends Enter afterwards.
Run: get router info routing-table all
1 step
get router info routing-table all
Sends Enter afterwards.
Run: get router info routing-table details {{PREFIX}}
1 step · 1 input
get router info routing-table details {{PREFIX}}
Sends Enter afterwards.
Run: get router info routing-table static
1 step
get router info routing-table static
Sends Enter afterwards.
Run: get router info routing-table connected
1 step
get router info routing-table connected
Sends Enter afterwards.
Run: diagnose firewall proute list
1 step
diagnose firewall proute list
Sends Enter afterwards.
Run: show router policy
1 step
show router policy
Sends Enter afterwards.
Run: get router info bgp summary
1 step
get router info bgp summary
Sends Enter afterwards.
Run: get router info bgp neighbors {{PEER}}
1 step · 1 input
get router info bgp neighbors {{PEER}}
Sends Enter afterwards.
Run: get router info ospf neighbor
1 step
get router info ospf neighbor
Sends Enter afterwards.
Run: get router info ospf interface
1 step
get router info ospf interface
Sends Enter afterwards.
Run: diagnose sys sdwan health-check
1 step
diagnose sys sdwan health-check
Sends Enter afterwards.
Run: diagnose sys sdwan member
1 step
diagnose sys sdwan member
Sends Enter afterwards.
Run: diagnose sys sdwan service
1 step
diagnose sys sdwan service
Sends Enter afterwards.
Run: show system sdwan
1 step
show system sdwan
Sends Enter afterwards.
Run: execute dhcp lease-list
1 step
execute dhcp lease-list
Sends Enter afterwards.
Run: show system dns
1 step
show system dns
Sends Enter afterwards.
Run: execute ping {{HOST}}
1 step · 1 input
execute ping {{HOST}}
Sends Enter afterwards.
Run: execute traceroute {{HOST}}
1 step · 1 input
execute traceroute {{HOST}}
Sends Enter afterwards.
Run: execute ping {{FQDN}}
1 step · 1 input
execute ping {{FQDN}}
Sends Enter afterwards.
Run: execute ping-options source {{IP}} ; execute ping {{HOST}} ; execute ping-options reset
3 steps · 2 inputs
execute ping-options source {{IP}}
Sends Enter afterwards.
execute ping {{HOST}}
Sends Enter afterwards.
execute ping-options reset
Sends Enter afterwards.
Run: config system interface ; edit "{{IFACE}}" ; set ip {{IP}} {{MASK}} ; set allowaccess ping https ssh ; next ; end
6 steps · asks for confirmation before it runs · 3 inputs
config system interface
Sends Enter afterwards.
edit "{{IFACE}}"
Sends Enter afterwards.
set ip {{IP}} {{MASK}}
Sends Enter afterwards.
set allowaccess ping https ssh
Sends Enter afterwards.
next
Sends Enter afterwards.
end
Sends Enter afterwards.
Run: config system interface ; edit "{{IFACE}}" ; set description "{{DESCRIPTION}}" ; next ; end
5 steps · asks for confirmation before it runs · 2 inputs
config system interface
Sends Enter afterwards.
edit "{{IFACE}}"
Sends Enter afterwards.
set description "{{DESCRIPTION}}"
Sends Enter afterwards.
next
Sends Enter afterwards.
end
Sends Enter afterwards.
Run: config router static ; edit 0 ; set dst {{PREFIX}} ; set gateway {{GATEWAY}} ; set device "{{IFACE}}" ; set comment "{{COMMENT}}" ; next ; end
8 steps · asks for confirmation before it runs · 4 inputs
config router static
Sends Enter afterwards.
edit 0
Sends Enter afterwards.
set dst {{PREFIX}}
Sends Enter afterwards.
set gateway {{GATEWAY}}
Sends Enter afterwards.
set device "{{IFACE}}"
Sends Enter afterwards.
set comment "{{COMMENT}}"
Sends Enter afterwards.
next
Sends Enter afterwards.
end
Sends Enter afterwards.
Run: config system interface ; edit "{{IFACE}}" ; set status down ; next ; end
6 steps · asks for confirmation before it runs · 1 input
Asks yes or no: “Administratively down {{IFACE}}. If this is the interface carrying your session, you lose the connection here and need out-of-band access to undo it. Continue?”
Answering no stops the script here.
config system interface
Sends Enter afterwards.
edit "{{IFACE}}"
Sends Enter afterwards.
set status down
Sends Enter afterwards.
next
Sends Enter afterwards.
end
Sends Enter afterwards.
Run: config router static ; delete {{ID}} ; end
4 steps · asks for confirmation before it runs · 1 input
Asks yes or no: “Delete static route {{ID}}. Traffic for that destination follows whatever is left in the table. Continue?”
Answering no stops the script here.
config router static
Sends Enter afterwards.
delete {{ID}}
Sends Enter afterwards.
end
Sends Enter afterwards.
Run: execute clear system arp table
2 steps · asks for confirmation before it runs
Asks yes or no: “Flush the ARP table. Expect a short pause on active flows while it repopulates. Continue?”
Answering no stops the script here.
execute clear system arp table
Sends Enter afterwards.
Run: diagnose sys sdwan health-check-update
2 steps · asks for confirmation before it runs
Asks yes or no: “Force SD-WAN health checks to re-run. Members may briefly flap out of service and steer traffic elsewhere. Continue?”
Answering no stops the script here.
diagnose sys sdwan health-check-update
Sends Enter afterwards.
IPsec and SSL VPN state, tunnels, user sessions and auth.
Run: get vpn ipsec tunnel summary
1 step
get vpn ipsec tunnel summary
Sends Enter afterwards.
Run: get vpn ipsec tunnel details
1 step
get vpn ipsec tunnel details
Sends Enter afterwards.
Run: show vpn ipsec phase1-interface
1 step
show vpn ipsec phase1-interface
Sends Enter afterwards.
Run: show vpn ipsec phase2-interface
1 step
show vpn ipsec phase2-interface
Sends Enter afterwards.
Run: diagnose vpn ike gateway list
1 step
diagnose vpn ike gateway list
Sends Enter afterwards.
Run: diagnose vpn ike gateway list name {{TUNNEL}}
1 step · 1 input
diagnose vpn ike gateway list name {{TUNNEL}}
Sends Enter afterwards.
Run: diagnose vpn tunnel list
1 step
diagnose vpn tunnel list
Sends Enter afterwards.
Run: diagnose vpn tunnel list name {{TUNNEL}}
1 step · 1 input
diagnose vpn tunnel list name {{TUNNEL}}
Sends Enter afterwards.
Run: get vpn ssl monitor
1 step
get vpn ssl monitor
Sends Enter afterwards.
Run: show vpn ssl settings
1 step
show vpn ssl settings
Sends Enter afterwards.
Run: show vpn ssl web portal
1 step
show vpn ssl web portal
Sends Enter afterwards.
Run: show user local
1 step
show user local
Sends Enter afterwards.
Run: show user group
1 step
show user group
Sends Enter afterwards.
Run: show user ldap
1 step
show user ldap
Sends Enter afterwards.
Run: show user radius
1 step
show user radius
Sends Enter afterwards.
Run: diagnose test authserver radius {{SERVER}} pap {{USER}} {{PASSWORD}}
1 step · 3 inputs
diagnose test authserver radius {{SERVER}} pap {{USER}} {{PASSWORD}}
Sends Enter afterwards.
Run: diagnose test authserver ldap {{SERVER}} {{USER}} {{PASSWORD}}
1 step · 3 inputs
diagnose test authserver ldap {{SERVER}} {{USER}} {{PASSWORD}}
Sends Enter afterwards.
Run: diagnose firewall auth list
1 step
diagnose firewall auth list
Sends Enter afterwards.
Run: show system admin
1 step
show system admin
Sends Enter afterwards.
Run: get system admin list
1 step
get system admin list
Sends Enter afterwards.
Run: get vpn certificate local details
1 step
get vpn certificate local details
Sends Enter afterwards.
Run: get vpn certificate ca details
1 step
get vpn certificate ca details
Sends Enter afterwards.
Run: config user local ; edit "{{USER}}" ; set type password ; set passwd {{PASSWORD}} ; set status enable ; next ; end
7 steps · asks for confirmation before it runs · 2 inputs
config user local
Sends Enter afterwards.
edit "{{USER}}"
Sends Enter afterwards.
set type password
Sends Enter afterwards.
set passwd {{PASSWORD}}
Sends Enter afterwards.
set status enable
Sends Enter afterwards.
next
Sends Enter afterwards.
end
Sends Enter afterwards.
Run: config user group ; edit "{{GROUP}}" ; append member "{{USER}}" ; next ; end
5 steps · asks for confirmation before it runs · 2 inputs
config user group
Sends Enter afterwards.
edit "{{GROUP}}"
Sends Enter afterwards.
append member "{{USER}}"
Sends Enter afterwards.
next
Sends Enter afterwards.
end
Sends Enter afterwards.
Run: diagnose vpn tunnel down {{TUNNEL}}
2 steps · asks for confirmation before it runs · 1 input
Asks yes or no: “Tear down tunnel {{TUNNEL}}. Everything crossing it drops until it renegotiates — which will not happen at all if the far end initiates only on demand. Continue?”
Answering no stops the script here.
diagnose vpn tunnel down {{TUNNEL}}
Sends Enter afterwards.
Run: diagnose vpn tunnel up {{TUNNEL}}
2 steps · asks for confirmation before it runs · 1 input
Asks yes or no: “Force tunnel {{TUNNEL}} to renegotiate. Existing sessions over it reset. Continue?”
Answering no stops the script here.
diagnose vpn tunnel up {{TUNNEL}}
Sends Enter afterwards.
Run: diagnose vpn ike gateway flush name {{TUNNEL}}
2 steps · asks for confirmation before it runs · 1 input
Asks yes or no: “Flush the IKE gateway for {{TUNNEL}}. Both phases restart and traffic stops until they complete. Continue?”
Answering no stops the script here.
diagnose vpn ike gateway flush name {{TUNNEL}}
Sends Enter afterwards.
Run: execute vpn sslvpn del-tunnel {{USER}}
2 steps · asks for confirmation before it runs · 1 input
Asks yes or no: “Disconnect SSL VPN user {{USER}}. Their session ends immediately with no warning. Continue?”
Answering no stops the script here.
execute vpn sslvpn del-tunnel {{USER}}
Sends Enter afterwards.
Run: diagnose firewall auth clear
2 steps · asks for confirmation before it runs
Asks yes or no: “Clear every authenticated firewall user. Everyone behind an auth policy has to log in again. Continue?”
Answering no stops the script here.
diagnose firewall auth clear
Sends Enter afterwards.
Run: config user local ; delete "{{USER}}" ; end
4 steps · asks for confirmation before it runs · 1 input
Asks yes or no: “Delete local user {{USER}}. Any group membership and active session goes with it. Continue?”
Answering no stops the script here.
config user local
Sends Enter afterwards.
delete "{{USER}}"
Sends Enter afterwards.
end
Sends Enter afterwards.
Sessions, sniffer, logs, HA state, config backup and reboot.
Run: get system status
1 step
get system status
Sends Enter afterwards.
Run: get system performance status
1 step
get system performance status
Sends Enter afterwards.
Run: diagnose sys top 2 20
1 step
diagnose sys top 2 20
Sends Enter afterwards.
Run: diagnose hardware sysinfo memory
1 step
diagnose hardware sysinfo memory
Sends Enter afterwards.
Run: diagnose hardware sysinfo conserve
1 step
diagnose hardware sysinfo conserve
Sends Enter afterwards.
Run: diagnose sys session stat
1 step
diagnose sys session stat
Sends Enter afterwards.
Run: diagnose sys session list
1 step
diagnose sys session list
Sends Enter afterwards.
Run: diagnose sys session filter clear ; diagnose sys session filter src {{IP}} ; diagnose sys session list
3 steps · 1 input
diagnose sys session filter clear
Sends Enter afterwards.
diagnose sys session filter src {{IP}}
Sends Enter afterwards.
diagnose sys session list
Sends Enter afterwards.
Run: diagnose sys session filter clear ; diagnose sys session filter dport {{PORT}} ; diagnose sys session list
3 steps · 1 input
diagnose sys session filter clear
Sends Enter afterwards.
diagnose sys session filter dport {{PORT}}
Sends Enter afterwards.
diagnose sys session list
Sends Enter afterwards.
Run: diagnose sys session filter clear
1 step
diagnose sys session filter clear
Sends Enter afterwards.
Run: diagnose sniffer packet any "host {{IP}}" 4 {{COUNT}} l
1 step · 2 inputs
diagnose sniffer packet any "host {{IP}}" 4 {{COUNT}} l
Sends Enter afterwards.
Run: diagnose sniffer packet any "port {{PORT}}" 4 {{COUNT}} l
1 step · 2 inputs
diagnose sniffer packet any "port {{PORT}}" 4 {{COUNT}} l
Sends Enter afterwards.
Run: diagnose sniffer packet {{IFACE}} "" 4 {{COUNT}} l
1 step · 2 inputs
diagnose sniffer packet {{IFACE}} "" 4 {{COUNT}} l
Sends Enter afterwards.
Traces how the firewall decides on traffic to or from a host. Stop it with Stop Debug Output.
5 steps · 2 inputs
diagnose debug reset
Sends Enter afterwards.
diagnose debug flow filter addr {{IP}}
Sends Enter afterwards.
diagnose debug flow show function-name enable
Sends Enter afterwards.
diagnose debug flow trace start {{COUNT}}
Sends Enter afterwards.
diagnose debug enable
Sends Enter afterwards.
Run: diagnose debug disable ; diagnose debug reset
2 steps
diagnose debug disable
Sends Enter afterwards.
diagnose debug reset
Sends Enter afterwards.
Run: execute log display
1 step
execute log display
Sends Enter afterwards.
Run: execute log filter category 1 ; execute log filter view-lines {{LINES}} ; execute log display
3 steps · 1 input
execute log filter category 1
Sends Enter afterwards.
execute log filter view-lines {{LINES}}
Sends Enter afterwards.
execute log display
Sends Enter afterwards.
Run: diagnose debug crashlog read
1 step
diagnose debug crashlog read
Sends Enter afterwards.
Run: get system ha status
1 step
get system ha status
Sends Enter afterwards.
Run: show system ha
1 step
show system ha
Sends Enter afterwards.
Run: diagnose sys ha status
1 step
diagnose sys ha status
Sends Enter afterwards.
Run: diagnose sys ha checksum cluster
1 step
diagnose sys ha checksum cluster
Sends Enter afterwards.
Run: get system fortiguard-service status
1 step
get system fortiguard-service status
Sends Enter afterwards.
Run: diagnose autoupdate versions
1 step
diagnose autoupdate versions
Sends Enter afterwards.
Run: diagnose sys logdisk usage
1 step
diagnose sys logdisk usage
Sends Enter afterwards.
Run: get system status | grep Version
1 step
get system status | grep Version
Sends Enter afterwards.
Run: get system performance status | grep Uptime
1 step
get system performance status | grep Uptime
Sends Enter afterwards.
Run: show | grep -f
1 step
show | grep -f
Sends Enter afterwards.
Run: show full-configuration system admin
1 step
show full-configuration system admin
Sends Enter afterwards.
Run: execute backup config tftp {{FILE}} {{SERVER}}
1 step · asks for confirmation before it runs · 2 inputs
execute backup config tftp {{FILE}} {{SERVER}}
Sends Enter afterwards.
Run: config system global ; set hostname "{{HOSTNAME}}" ; end
3 steps · asks for confirmation before it runs · 1 input
config system global
Sends Enter afterwards.
set hostname "{{HOSTNAME}}"
Sends Enter afterwards.
end
Sends Enter afterwards.
Run: config system ntp ; set ntpsync enable ; set type custom ; config ntpserver ; edit 1 ; set server "{{NTP}}" ; next ; end ; end
9 steps · asks for confirmation before it runs · 1 input
config system ntp
Sends Enter afterwards.
set ntpsync enable
Sends Enter afterwards.
set type custom
Sends Enter afterwards.
config ntpserver
Sends Enter afterwards.
edit 1
Sends Enter afterwards.
set server "{{NTP}}"
Sends Enter afterwards.
next
Sends Enter afterwards.
end
Sends Enter afterwards.
end
Sends Enter afterwards.
Run: config system global ; set admintimeout {{MINUTES}} ; end
3 steps · asks for confirmation before it runs · 1 input
config system global
Sends Enter afterwards.
set admintimeout {{MINUTES}}
Sends Enter afterwards.
end
Sends Enter afterwards.
Run: diagnose sys session clear
2 steps · asks for confirmation before it runs
Asks yes or no: “Drop every session in the table. Every connection through this firewall breaks and has to be re-established — this is felt by users immediately. Continue?”
Answering no stops the script here.
diagnose sys session clear
Sends Enter afterwards.
Run: execute restore config tftp {{FILE}} {{SERVER}}
2 steps · asks for confirmation before it runs · 2 inputs
Asks yes or no: “Replace the running configuration with {{FILE}} and reboot. Everything not in that file is lost, including the access you are using. Continue?”
Answering no stops the script here.
execute restore config tftp {{FILE}} {{SERVER}}
Sends Enter afterwards.
Run: execute reboot
2 steps · asks for confirmation before it runs
Asks yes or no: “Reboot this FortiGate now. All traffic through it stops for the length of the boot. Save the config first. Continue?”
Answering no stops the script here.
execute reboot
Sends Enter afterwards.
Run: execute shutdown
2 steps · asks for confirmation before it runs
Asks yes or no: “Power off this FortiGate. It will not come back without physical intervention. Continue?”
Answering no stops the script here.
execute shutdown
Sends Enter afterwards.
Run: execute factoryreset
2 steps · asks for confirmation before it runs
Asks yes or no: “Erase the entire configuration and reboot to factory defaults. Everything is lost and the device comes back on its default address only. Continue?”
Answering no stops the script here.
execute factoryreset
Sends Enter afterwards.
Run: diagnose sys ha reset-uptime
2 steps · asks for confirmation before it runs
Asks yes or no: “Reset HA uptime so the other unit takes over. Sessions that are not synchronised drop during the switch. Continue?”
Answering no stops the script here.
diagnose sys ha reset-uptime
Sends Enter afterwards.
Sign in to report it, or email abuse@smartcomrevisited.com.