Skip to content

Fortinet FortiGate

FortiOS policies, VPNs, SD-WAN and the session-table diagnostics.

Fortinet Requires SmartCom Revisited 1.0.0 or newer

by Nathan Kirk · 124 downloads · MIT licence · revision 1 · published 14 Aug 2026

This bundle can change or destroy device state

  • Reboots or reloads the device (1 step) — Restarts the device. Any session on it drops, and anything not saved is lost.
  • Shuts down an interface (1 step) — Administratively disables an interface. If it is the interface you are connected over, you lose the session.
  • Factory resets the device (1 step) — Returns the device to factory settings, including management addressing. Expect to need console access afterwards.
  • Changes credentials or access (1 step) — Creates, changes or removes a login. Getting this wrong can lock everyone out of the device.
Show exactly which steps matched
  • Add Local User — Changes credentials or access (steps[3], sent text)

    set passwd {{PASSWORD}}
  • Reboot FortiGate — Reboots or reloads the device (steps[1], sent text)

    execute reboot
  • Shut Down FortiGate — Shuts down an interface (steps[1], sent text)

    execute shutdown
  • Factory Reset — Factory resets the device (steps[1], sent text)

    execute factoryreset

Flagged automatically by matching command text. It is a prompt to read the script, not a verdict — plenty of legitimate buttons reboot things on purpose.

Download

4 sets, 133 buttons, 274 steps · 184.9 KB

File format version 1 · exported by Smartcom Revisited

Download .buttons.json
SHA-256 5ca1b94130779243243a8539371db0321be6368bc28817f329d17281a22df189

You get the exact file the uploader submitted, byte for byte — that checksum is what sha256sum will print. Import it from the button panel in SmartCom Revisited.

About this set

FortiOS from the CLI: read and edit policies and objects, watch IPsec and SSL VPN tunnels, check SD-WAN health, and run the sniffer and session filters that show what a policy is really doing.

Every button, in full

Exactly what gets sent

This is the complete script of the file below — nothing is summarised or hidden. Read it before you download it, the same way you would read a script someone emailed you.

FortiGate - Policies & Objects

32 buttons

Firewall policies, address and service objects, NAT rules.

List Firewall Policies

Run: show firewall policy

1 step

  1. Send
    show firewall policy

    Sends Enter afterwards.

Policy Table Summary

Run: get firewall policy

1 step

  1. Send
    get firewall policy

    Sends Enter afterwards.

Policy Hit Counters

Run: diagnose firewall iprope show 100004

1 step

  1. Send
    diagnose firewall iprope show 100004

    Sends Enter afterwards.

Show Single Policy

Run: show firewall policy {{POLICY_ID}}

1 step · 1 input

  1. Send
    show firewall policy {{POLICY_ID}}

    Sends Enter afterwards.

Policy Lookup

Run: diagnose firewall proute list

1 step

  1. Send
    diagnose firewall proute list

    Sends Enter afterwards.

List Address Objects

Run: show firewall address

1 step

  1. Send
    show firewall address

    Sends Enter afterwards.

Show Address Object

Run: show firewall address {{OBJECT}}

1 step · 1 input

  1. Send
    show firewall address {{OBJECT}}

    Sends Enter afterwards.

List Address Groups

Run: show firewall addrgrp

1 step

  1. Send
    show firewall addrgrp

    Sends Enter afterwards.

List Service Objects

Run: show firewall service custom

1 step

  1. Send
    show firewall service custom

    Sends Enter afterwards.

List Service Groups

Run: show firewall service group

1 step

  1. Send
    show firewall service group

    Sends Enter afterwards.

List Schedules

Run: show firewall schedule recurring

1 step

  1. Send
    show firewall schedule recurring

    Sends Enter afterwards.

List VIPs

Run: show firewall vip

1 step

  1. Send
    show firewall vip

    Sends Enter afterwards.

List IP Pools

Run: show firewall ippool

1 step

  1. Send
    show firewall ippool

    Sends Enter afterwards.

IP Pool Usage

Run: diagnose firewall ippool list

1 step

  1. Send
    diagnose firewall ippool list

    Sends Enter afterwards.

List Virtual Domains

Run: diagnose sys vd list | grep name

1 step

  1. Send
    diagnose sys vd list | grep name

    Sends Enter afterwards.

Central SNAT Map

Run: show firewall central-snat-map

1 step

  1. Send
    show firewall central-snat-map

    Sends Enter afterwards.

Security Profile Groups

Run: show firewall profile-group

1 step

  1. Send
    show firewall profile-group

    Sends Enter afterwards.

Web Filter Profiles

Run: show webfilter profile

1 step

  1. Send
    show webfilter profile

    Sends Enter afterwards.

Application Control Lists

Run: show application list

1 step

  1. Send
    show application list

    Sends Enter afterwards.

IPS Sensors

Run: show ips sensor

1 step

  1. Send
    show ips sensor

    Sends Enter afterwards.

Create Address Object

Run: config firewall address ; edit "{{OBJECT}}" ; set subnet {{SUBNET}} ; set comment "{{COMMENT}}" ; next ; end

6 steps · asks for confirmation before it runs · 3 inputs

  1. Send
    config firewall address

    Sends Enter afterwards.

  2. Send
    edit "{{OBJECT}}"

    Sends Enter afterwards.

  3. Send
    set subnet {{SUBNET}}

    Sends Enter afterwards.

  4. Send
    set comment "{{COMMENT}}"

    Sends Enter afterwards.

  5. Send
    next

    Sends Enter afterwards.

  6. Send
    end

    Sends Enter afterwards.

Create FQDN Address Object

Run: config firewall address ; edit "{{OBJECT}}" ; set type fqdn ; set fqdn "{{FQDN}}" ; next ; end

6 steps · asks for confirmation before it runs · 2 inputs

  1. Send
    config firewall address

    Sends Enter afterwards.

  2. Send
    edit "{{OBJECT}}"

    Sends Enter afterwards.

  3. Send
    set type fqdn

    Sends Enter afterwards.

  4. Send
    set fqdn "{{FQDN}}"

    Sends Enter afterwards.

  5. Send
    next

    Sends Enter afterwards.

  6. Send
    end

    Sends Enter afterwards.

Add Object to Group

Run: config firewall addrgrp ; edit "{{GROUP}}" ; append member "{{OBJECT}}" ; next ; end

5 steps · asks for confirmation before it runs · 2 inputs

  1. Send
    config firewall addrgrp

    Sends Enter afterwards.

  2. Send
    edit "{{GROUP}}"

    Sends Enter afterwards.

  3. Send
    append member "{{OBJECT}}"

    Sends Enter afterwards.

  4. Send
    next

    Sends Enter afterwards.

  5. Send
    end

    Sends Enter afterwards.

Create Service Object

Run: config firewall service custom ; edit "{{SERVICE}}" ; set protocol TCP/UDP/SCTP ; set tcp-portrange {{PORT_RANGE}} ; next ; end

6 steps · asks for confirmation before it runs · 2 inputs

  1. Send
    config firewall service custom

    Sends Enter afterwards.

  2. Send
    edit "{{SERVICE}}"

    Sends Enter afterwards.

  3. Send
    set protocol TCP/UDP/SCTP

    Sends Enter afterwards.

  4. Send
    set tcp-portrange {{PORT_RANGE}}

    Sends Enter afterwards.

  5. Send
    next

    Sends Enter afterwards.

  6. Send
    end

    Sends Enter afterwards.

Create Allow Policy

Run: config firewall policy ; edit 0 ; set name "{{NAME}}" ; set srcintf "{{SRC_IFACE}}" ; set dstintf "{{DST_IFACE}}" ; set srcaddr "{{SRC}}" ; set dstaddr "{{DST}}" ; set service "{{SERVICE}}" ; set action accept ; set schedule always ; set nat enable ; set logtraffic all ; next ; end

14 steps · asks for confirmation before it runs · 6 inputs

  1. Send
    config firewall policy

    Sends Enter afterwards.

  2. Send
    edit 0

    Sends Enter afterwards.

  3. Send
    set name "{{NAME}}"

    Sends Enter afterwards.

  4. Send
    set srcintf "{{SRC_IFACE}}"

    Sends Enter afterwards.

  5. Send
    set dstintf "{{DST_IFACE}}"

    Sends Enter afterwards.

  6. Send
    set srcaddr "{{SRC}}"

    Sends Enter afterwards.

  7. Send
    set dstaddr "{{DST}}"

    Sends Enter afterwards.

  8. Send
    set service "{{SERVICE}}"

    Sends Enter afterwards.

  9. Send
    set action accept

    Sends Enter afterwards.

  10. Send
    set schedule always

    Sends Enter afterwards.

  11. Send
    set nat enable

    Sends Enter afterwards.

  12. Send
    set logtraffic all

    Sends Enter afterwards.

  13. Send
    next

    Sends Enter afterwards.

  14. Send
    end

    Sends Enter afterwards.

Add Comment to Policy

Run: config firewall policy ; edit {{POLICY_ID}} ; set comments "{{COMMENT}}" ; next ; end

5 steps · asks for confirmation before it runs · 2 inputs

  1. Send
    config firewall policy

    Sends Enter afterwards.

  2. Send
    edit {{POLICY_ID}}

    Sends Enter afterwards.

  3. Send
    set comments "{{COMMENT}}"

    Sends Enter afterwards.

  4. Send
    next

    Sends Enter afterwards.

  5. Send
    end

    Sends Enter afterwards.

Enable Logging on Policy

Run: config firewall policy ; edit {{POLICY_ID}} ; set logtraffic all ; next ; end

5 steps · asks for confirmation before it runs · 1 input

  1. Send
    config firewall policy

    Sends Enter afterwards.

  2. Send
    edit {{POLICY_ID}}

    Sends Enter afterwards.

  3. Send
    set logtraffic all

    Sends Enter afterwards.

  4. Send
    next

    Sends Enter afterwards.

  5. Send
    end

    Sends Enter afterwards.

Move Policy Before Another

Run: config firewall policy ; move {{POLICY_ID}} before {{TARGET_ID}} ; end

3 steps · asks for confirmation before it runs · 2 inputs

  1. Send
    config firewall policy

    Sends Enter afterwards.

  2. Send
    move {{POLICY_ID}} before {{TARGET_ID}}

    Sends Enter afterwards.

  3. Send
    end

    Sends Enter afterwards.

Disable Policy

Run: config firewall policy ; edit {{POLICY_ID}} ; set status disable ; next ; end

6 steps · asks for confirmation before it runs · 1 input

  1. Confirm

    Asks yes or no: “Disable policy {{POLICY_ID}}. Traffic it was allowing now falls through to the rules below it, or is denied. Continue?”

    Answering no stops the script here.

  2. Send
    config firewall policy

    Sends Enter afterwards.

  3. Send
    edit {{POLICY_ID}}

    Sends Enter afterwards.

  4. Send
    set status disable

    Sends Enter afterwards.

  5. Send
    next

    Sends Enter afterwards.

  6. Send
    end

    Sends Enter afterwards.

Create Deny Policy

Run: config firewall policy ; edit 0 ; set name "{{NAME}}" ; set srcintf "{{SRC_IFACE}}" ; set dstintf "{{DST_IFACE}}" ; set srcaddr "{{SRC}}" ; set dstaddr "{{DST}}" ; set service "{{SERVICE}}" ; set action deny ; set schedule always ; set logtraffic all ; next ; end

14 steps · asks for confirmation before it runs · 6 inputs

  1. Confirm

    Asks yes or no: “Add a deny policy. New rules land at the bottom unless you move them — check the position before you rely on it, and make sure it cannot match your own management traffic. Continue?”

    Answering no stops the script here.

  2. Send
    config firewall policy

    Sends Enter afterwards.

  3. Send
    edit 0

    Sends Enter afterwards.

  4. Send
    set name "{{NAME}}"

    Sends Enter afterwards.

  5. Send
    set srcintf "{{SRC_IFACE}}"

    Sends Enter afterwards.

  6. Send
    set dstintf "{{DST_IFACE}}"

    Sends Enter afterwards.

  7. Send
    set srcaddr "{{SRC}}"

    Sends Enter afterwards.

  8. Send
    set dstaddr "{{DST}}"

    Sends Enter afterwards.

  9. Send
    set service "{{SERVICE}}"

    Sends Enter afterwards.

  10. Send
    set action deny

    Sends Enter afterwards.

  11. Send
    set schedule always

    Sends Enter afterwards.

  12. Send
    set logtraffic all

    Sends Enter afterwards.

  13. Send
    next

    Sends Enter afterwards.

  14. Send
    end

    Sends Enter afterwards.

Delete Policy

Run: config firewall policy ; delete {{POLICY_ID}} ; end

4 steps · asks for confirmation before it runs · 1 input

  1. Confirm

    Asks yes or no: “Delete policy {{POLICY_ID}} permanently. Anything it was permitting stops immediately. Continue?”

    Answering no stops the script here.

  2. Send
    config firewall policy

    Sends Enter afterwards.

  3. Send
    delete {{POLICY_ID}}

    Sends Enter afterwards.

  4. Send
    end

    Sends Enter afterwards.

Delete Address Object

Run: config firewall address ; delete "{{OBJECT}}" ; end

4 steps · asks for confirmation before it runs · 1 input

  1. Confirm

    Asks yes or no: “Delete address object {{OBJECT}}. This fails if a policy still references it, and breaks that policy if it does not. Continue?”

    Answering no stops the script here.

  2. Send
    config firewall address

    Sends Enter afterwards.

  3. Send
    delete "{{OBJECT}}"

    Sends Enter afterwards.

  4. Send
    end

    Sends Enter afterwards.

FortiGate - Interfaces, Routing & SD-WAN

32 buttons

Interfaces, routes, SD-WAN members and link health checks.

Interface Status

Run: get system interface physical

1 step

  1. Send
    get system interface physical

    Sends Enter afterwards.

Interface Config

Run: show system interface

1 step

  1. Send
    show system interface

    Sends Enter afterwards.

Single Interface Detail

Run: get system interface {{IFACE}}

1 step · 1 input

  1. Send
    get system interface {{IFACE}}

    Sends Enter afterwards.

Interface Traffic Counters

Run: diagnose netlink interface list {{IFACE}}

1 step · 1 input

  1. Send
    diagnose netlink interface list {{IFACE}}

    Sends Enter afterwards.

ARP Table

Run: get system arp

1 step

  1. Send
    get system arp

    Sends Enter afterwards.

Routing Table

Run: get router info routing-table all

1 step

  1. Send
    get router info routing-table all

    Sends Enter afterwards.

Route for Prefix

Run: get router info routing-table details {{PREFIX}}

1 step · 1 input

  1. Send
    get router info routing-table details {{PREFIX}}

    Sends Enter afterwards.

Static Routes

Run: get router info routing-table static

1 step

  1. Send
    get router info routing-table static

    Sends Enter afterwards.

Connected Routes

Run: get router info routing-table connected

1 step

  1. Send
    get router info routing-table connected

    Sends Enter afterwards.

Route Lookup

Run: diagnose firewall proute list

1 step

  1. Send
    diagnose firewall proute list

    Sends Enter afterwards.

Policy Routes

Run: show router policy

1 step

  1. Send
    show router policy

    Sends Enter afterwards.

BGP Summary

Run: get router info bgp summary

1 step

  1. Send
    get router info bgp summary

    Sends Enter afterwards.

BGP Neighbours

Run: get router info bgp neighbors {{PEER}}

1 step · 1 input

  1. Send
    get router info bgp neighbors {{PEER}}

    Sends Enter afterwards.

OSPF Neighbours

Run: get router info ospf neighbor

1 step

  1. Send
    get router info ospf neighbor

    Sends Enter afterwards.

OSPF Interfaces

Run: get router info ospf interface

1 step

  1. Send
    get router info ospf interface

    Sends Enter afterwards.

SD-WAN Health Check

Run: diagnose sys sdwan health-check

1 step

  1. Send
    diagnose sys sdwan health-check

    Sends Enter afterwards.

SD-WAN Member Status

Run: diagnose sys sdwan member

1 step

  1. Send
    diagnose sys sdwan member

    Sends Enter afterwards.

SD-WAN Service Rules

Run: diagnose sys sdwan service

1 step

  1. Send
    diagnose sys sdwan service

    Sends Enter afterwards.

SD-WAN Config

Run: show system sdwan

1 step

  1. Send
    show system sdwan

    Sends Enter afterwards.

DHCP Server Leases

Run: execute dhcp lease-list

1 step

  1. Send
    execute dhcp lease-list

    Sends Enter afterwards.

DNS Settings

Run: show system dns

1 step

  1. Send
    show system dns

    Sends Enter afterwards.

Ping Host

Run: execute ping {{HOST}}

1 step · 1 input

  1. Send
    execute ping {{HOST}}

    Sends Enter afterwards.

Traceroute

Run: execute traceroute {{HOST}}

1 step · 1 input

  1. Send
    execute traceroute {{HOST}}

    Sends Enter afterwards.

Test DNS Resolution

Run: execute ping {{FQDN}}

1 step · 1 input

  1. Send
    execute ping {{FQDN}}

    Sends Enter afterwards.

Ping from Interface

Run: execute ping-options source {{IP}} ; execute ping {{HOST}} ; execute ping-options reset

3 steps · 2 inputs

  1. Send
    execute ping-options source {{IP}}

    Sends Enter afterwards.

  2. Send
    execute ping {{HOST}}

    Sends Enter afterwards.

  3. Send
    execute ping-options reset

    Sends Enter afterwards.

Set Interface Address

Run: config system interface ; edit "{{IFACE}}" ; set ip {{IP}} {{MASK}} ; set allowaccess ping https ssh ; next ; end

6 steps · asks for confirmation before it runs · 3 inputs

  1. Send
    config system interface

    Sends Enter afterwards.

  2. Send
    edit "{{IFACE}}"

    Sends Enter afterwards.

  3. Send
    set ip {{IP}} {{MASK}}

    Sends Enter afterwards.

  4. Send
    set allowaccess ping https ssh

    Sends Enter afterwards.

  5. Send
    next

    Sends Enter afterwards.

  6. Send
    end

    Sends Enter afterwards.

Set Interface Description

Run: config system interface ; edit "{{IFACE}}" ; set description "{{DESCRIPTION}}" ; next ; end

5 steps · asks for confirmation before it runs · 2 inputs

  1. Send
    config system interface

    Sends Enter afterwards.

  2. Send
    edit "{{IFACE}}"

    Sends Enter afterwards.

  3. Send
    set description "{{DESCRIPTION}}"

    Sends Enter afterwards.

  4. Send
    next

    Sends Enter afterwards.

  5. Send
    end

    Sends Enter afterwards.

Add Static Route

Run: config router static ; edit 0 ; set dst {{PREFIX}} ; set gateway {{GATEWAY}} ; set device "{{IFACE}}" ; set comment "{{COMMENT}}" ; next ; end

8 steps · asks for confirmation before it runs · 4 inputs

  1. Send
    config router static

    Sends Enter afterwards.

  2. Send
    edit 0

    Sends Enter afterwards.

  3. Send
    set dst {{PREFIX}}

    Sends Enter afterwards.

  4. Send
    set gateway {{GATEWAY}}

    Sends Enter afterwards.

  5. Send
    set device "{{IFACE}}"

    Sends Enter afterwards.

  6. Send
    set comment "{{COMMENT}}"

    Sends Enter afterwards.

  7. Send
    next

    Sends Enter afterwards.

  8. Send
    end

    Sends Enter afterwards.

Bring Interface Down

Run: config system interface ; edit "{{IFACE}}" ; set status down ; next ; end

6 steps · asks for confirmation before it runs · 1 input

  1. Confirm

    Asks yes or no: “Administratively down {{IFACE}}. If this is the interface carrying your session, you lose the connection here and need out-of-band access to undo it. Continue?”

    Answering no stops the script here.

  2. Send
    config system interface

    Sends Enter afterwards.

  3. Send
    edit "{{IFACE}}"

    Sends Enter afterwards.

  4. Send
    set status down

    Sends Enter afterwards.

  5. Send
    next

    Sends Enter afterwards.

  6. Send
    end

    Sends Enter afterwards.

Delete Static Route

Run: config router static ; delete {{ID}} ; end

4 steps · asks for confirmation before it runs · 1 input

  1. Confirm

    Asks yes or no: “Delete static route {{ID}}. Traffic for that destination follows whatever is left in the table. Continue?”

    Answering no stops the script here.

  2. Send
    config router static

    Sends Enter afterwards.

  3. Send
    delete {{ID}}

    Sends Enter afterwards.

  4. Send
    end

    Sends Enter afterwards.

Clear ARP Table

Run: execute clear system arp table

2 steps · asks for confirmation before it runs

  1. Confirm

    Asks yes or no: “Flush the ARP table. Expect a short pause on active flows while it repopulates. Continue?”

    Answering no stops the script here.

  2. Send
    execute clear system arp table

    Sends Enter afterwards.

Restart SD-WAN Health Check

Run: diagnose sys sdwan health-check-update

2 steps · asks for confirmation before it runs

  1. Confirm

    Asks yes or no: “Force SD-WAN health checks to re-run. Members may briefly flap out of service and steer traffic elsewhere. Continue?”

    Answering no stops the script here.

  2. Send
    diagnose sys sdwan health-check-update

    Sends Enter afterwards.

FortiGate - VPN & Users

30 buttons

IPsec and SSL VPN state, tunnels, user sessions and auth.

IPsec Tunnel Summary

Run: get vpn ipsec tunnel summary

1 step

  1. Send
    get vpn ipsec tunnel summary

    Sends Enter afterwards.

IPsec Tunnel Details

Run: get vpn ipsec tunnel details

1 step

  1. Send
    get vpn ipsec tunnel details

    Sends Enter afterwards.

IPsec Phase 1 Config

Run: show vpn ipsec phase1-interface

1 step

  1. Send
    show vpn ipsec phase1-interface

    Sends Enter afterwards.

IPsec Phase 2 Config

Run: show vpn ipsec phase2-interface

1 step

  1. Send
    show vpn ipsec phase2-interface

    Sends Enter afterwards.

IKE Gateway List

Run: diagnose vpn ike gateway list

1 step

  1. Send
    diagnose vpn ike gateway list

    Sends Enter afterwards.

IKE Gateway for Peer

Run: diagnose vpn ike gateway list name {{TUNNEL}}

1 step · 1 input

  1. Send
    diagnose vpn ike gateway list name {{TUNNEL}}

    Sends Enter afterwards.

IPsec SA List

Run: diagnose vpn tunnel list

1 step

  1. Send
    diagnose vpn tunnel list

    Sends Enter afterwards.

IPsec Tunnel by Name

Run: diagnose vpn tunnel list name {{TUNNEL}}

1 step · 1 input

  1. Send
    diagnose vpn tunnel list name {{TUNNEL}}

    Sends Enter afterwards.

SSL VPN Sessions

Run: get vpn ssl monitor

1 step

  1. Send
    get vpn ssl monitor

    Sends Enter afterwards.

SSL VPN Settings

Run: show vpn ssl settings

1 step

  1. Send
    show vpn ssl settings

    Sends Enter afterwards.

SSL VPN Portals

Run: show vpn ssl web portal

1 step

  1. Send
    show vpn ssl web portal

    Sends Enter afterwards.

Firewall Users

Run: show user local

1 step

  1. Send
    show user local

    Sends Enter afterwards.

User Groups

Run: show user group

1 step

  1. Send
    show user group

    Sends Enter afterwards.

LDAP Servers

Run: show user ldap

1 step

  1. Send
    show user ldap

    Sends Enter afterwards.

RADIUS Servers

Run: show user radius

1 step

  1. Send
    show user radius

    Sends Enter afterwards.

Test RADIUS Auth

Run: diagnose test authserver radius {{SERVER}} pap {{USER}} {{PASSWORD}}

1 step · 3 inputs

  1. Send
    diagnose test authserver radius {{SERVER}} pap {{USER}} {{PASSWORD}}

    Sends Enter afterwards.

Test LDAP Auth

Run: diagnose test authserver ldap {{SERVER}} {{USER}} {{PASSWORD}}

1 step · 3 inputs

  1. Send
    diagnose test authserver ldap {{SERVER}} {{USER}} {{PASSWORD}}

    Sends Enter afterwards.

Authenticated Users

Run: diagnose firewall auth list

1 step

  1. Send
    diagnose firewall auth list

    Sends Enter afterwards.

Admin Accounts

Run: show system admin

1 step

  1. Send
    show system admin

    Sends Enter afterwards.

Admin Sessions

Run: get system admin list

1 step

  1. Send
    get system admin list

    Sends Enter afterwards.

Certificate List

Run: get vpn certificate local details

1 step

  1. Send
    get vpn certificate local details

    Sends Enter afterwards.

CA Certificates

Run: get vpn certificate ca details

1 step

  1. Send
    get vpn certificate ca details

    Sends Enter afterwards.

Add Local User

Run: config user local ; edit "{{USER}}" ; set type password ; set passwd {{PASSWORD}} ; set status enable ; next ; end

7 steps · asks for confirmation before it runs · 2 inputs

  • Changes credentials or access
  1. Send
    config user local

    Sends Enter afterwards.

  2. Send
    edit "{{USER}}"

    Sends Enter afterwards.

  3. Send
    set type password

    Sends Enter afterwards.

  4. Send
    set passwd {{PASSWORD}}

    Sends Enter afterwards.

  5. Send
    set status enable

    Sends Enter afterwards.

  6. Send
    next

    Sends Enter afterwards.

  7. Send
    end

    Sends Enter afterwards.

Add User to Group

Run: config user group ; edit "{{GROUP}}" ; append member "{{USER}}" ; next ; end

5 steps · asks for confirmation before it runs · 2 inputs

  1. Send
    config user group

    Sends Enter afterwards.

  2. Send
    edit "{{GROUP}}"

    Sends Enter afterwards.

  3. Send
    append member "{{USER}}"

    Sends Enter afterwards.

  4. Send
    next

    Sends Enter afterwards.

  5. Send
    end

    Sends Enter afterwards.

Bring IPsec Tunnel Down

Run: diagnose vpn tunnel down {{TUNNEL}}

2 steps · asks for confirmation before it runs · 1 input

  1. Confirm

    Asks yes or no: “Tear down tunnel {{TUNNEL}}. Everything crossing it drops until it renegotiates — which will not happen at all if the far end initiates only on demand. Continue?”

    Answering no stops the script here.

  2. Send
    diagnose vpn tunnel down {{TUNNEL}}

    Sends Enter afterwards.

Bring IPsec Tunnel Up

Run: diagnose vpn tunnel up {{TUNNEL}}

2 steps · asks for confirmation before it runs · 1 input

  1. Confirm

    Asks yes or no: “Force tunnel {{TUNNEL}} to renegotiate. Existing sessions over it reset. Continue?”

    Answering no stops the script here.

  2. Send
    diagnose vpn tunnel up {{TUNNEL}}

    Sends Enter afterwards.

Flush IKE Gateway

Run: diagnose vpn ike gateway flush name {{TUNNEL}}

2 steps · asks for confirmation before it runs · 1 input

  1. Confirm

    Asks yes or no: “Flush the IKE gateway for {{TUNNEL}}. Both phases restart and traffic stops until they complete. Continue?”

    Answering no stops the script here.

  2. Send
    diagnose vpn ike gateway flush name {{TUNNEL}}

    Sends Enter afterwards.

Disconnect SSL VPN User

Run: execute vpn sslvpn del-tunnel {{USER}}

2 steps · asks for confirmation before it runs · 1 input

  1. Confirm

    Asks yes or no: “Disconnect SSL VPN user {{USER}}. Their session ends immediately with no warning. Continue?”

    Answering no stops the script here.

  2. Send
    execute vpn sslvpn del-tunnel {{USER}}

    Sends Enter afterwards.

Deauthenticate Firewall User

Run: diagnose firewall auth clear

2 steps · asks for confirmation before it runs

  1. Confirm

    Asks yes or no: “Clear every authenticated firewall user. Everyone behind an auth policy has to log in again. Continue?”

    Answering no stops the script here.

  2. Send
    diagnose firewall auth clear

    Sends Enter afterwards.

Delete Local User

Run: config user local ; delete "{{USER}}" ; end

4 steps · asks for confirmation before it runs · 1 input

  1. Confirm

    Asks yes or no: “Delete local user {{USER}}. Any group membership and active session goes with it. Continue?”

    Answering no stops the script here.

  2. Send
    config user local

    Sends Enter afterwards.

  3. Send
    delete "{{USER}}"

    Sends Enter afterwards.

  4. Send
    end

    Sends Enter afterwards.

FortiGate - Diagnostics & System

39 buttons

Sessions, sniffer, logs, HA state, config backup and reboot.

System Status

Run: get system status

1 step

  1. Send
    get system status

    Sends Enter afterwards.

Performance Status

Run: get system performance status

1 step

  1. Send
    get system performance status

    Sends Enter afterwards.

CPU by Process

Run: diagnose sys top 2 20

1 step

  1. Send
    diagnose sys top 2 20

    Sends Enter afterwards.

Memory Usage

Run: diagnose hardware sysinfo memory

1 step

  1. Send
    diagnose hardware sysinfo memory

    Sends Enter afterwards.

Conserve Mode State

Run: diagnose hardware sysinfo conserve

1 step

  1. Send
    diagnose hardware sysinfo conserve

    Sends Enter afterwards.

Session Count

Run: diagnose sys session stat

1 step

  1. Send
    diagnose sys session stat

    Sends Enter afterwards.

Session List

Run: diagnose sys session list

1 step

  1. Send
    diagnose sys session list

    Sends Enter afterwards.

Sessions for Host

Run: diagnose sys session filter clear ; diagnose sys session filter src {{IP}} ; diagnose sys session list

3 steps · 1 input

  1. Send
    diagnose sys session filter clear

    Sends Enter afterwards.

  2. Send
    diagnose sys session filter src {{IP}}

    Sends Enter afterwards.

  3. Send
    diagnose sys session list

    Sends Enter afterwards.

Sessions for Port

Run: diagnose sys session filter clear ; diagnose sys session filter dport {{PORT}} ; diagnose sys session list

3 steps · 1 input

  1. Send
    diagnose sys session filter clear

    Sends Enter afterwards.

  2. Send
    diagnose sys session filter dport {{PORT}}

    Sends Enter afterwards.

  3. Send
    diagnose sys session list

    Sends Enter afterwards.

Clear Session Filter

Run: diagnose sys session filter clear

1 step

  1. Send
    diagnose sys session filter clear

    Sends Enter afterwards.

Sniff Traffic for Host

Run: diagnose sniffer packet any "host {{IP}}" 4 {{COUNT}} l

1 step · 2 inputs

  1. Send
    diagnose sniffer packet any "host {{IP}}" 4 {{COUNT}} l

    Sends Enter afterwards.

Sniff Traffic on Port

Run: diagnose sniffer packet any "port {{PORT}}" 4 {{COUNT}} l

1 step · 2 inputs

  1. Send
    diagnose sniffer packet any "port {{PORT}}" 4 {{COUNT}} l

    Sends Enter afterwards.

Sniff Interface

Run: diagnose sniffer packet {{IFACE}} "" 4 {{COUNT}} l

1 step · 2 inputs

  1. Send
    diagnose sniffer packet {{IFACE}} "" 4 {{COUNT}} l

    Sends Enter afterwards.

Debug Flow for Host

Traces how the firewall decides on traffic to or from a host. Stop it with Stop Debug Output.

5 steps · 2 inputs

  1. Send
    diagnose debug reset

    Sends Enter afterwards.

  2. Send
    diagnose debug flow filter addr {{IP}}

    Sends Enter afterwards.

  3. Send
    diagnose debug flow show function-name enable

    Sends Enter afterwards.

  4. Send
    diagnose debug flow trace start {{COUNT}}

    Sends Enter afterwards.

  5. Send
    diagnose debug enable

    Sends Enter afterwards.

Stop Debug Output

Run: diagnose debug disable ; diagnose debug reset

2 steps

  1. Send
    diagnose debug disable

    Sends Enter afterwards.

  2. Send
    diagnose debug reset

    Sends Enter afterwards.

Recent Event Log

Run: execute log display

1 step

  1. Send
    execute log display

    Sends Enter afterwards.

Set Log Filter to Traffic

Run: execute log filter category 1 ; execute log filter view-lines {{LINES}} ; execute log display

3 steps · 1 input

  1. Send
    execute log filter category 1

    Sends Enter afterwards.

  2. Send
    execute log filter view-lines {{LINES}}

    Sends Enter afterwards.

  3. Send
    execute log display

    Sends Enter afterwards.

Crash Log

Run: diagnose debug crashlog read

1 step

  1. Send
    diagnose debug crashlog read

    Sends Enter afterwards.

HA Status

Run: get system ha status

1 step

  1. Send
    get system ha status

    Sends Enter afterwards.

HA Config

Run: show system ha

1 step

  1. Send
    show system ha

    Sends Enter afterwards.

HA Cluster Members

Run: diagnose sys ha status

1 step

  1. Send
    diagnose sys ha status

    Sends Enter afterwards.

HA Checksum Compare

Run: diagnose sys ha checksum cluster

1 step

  1. Send
    diagnose sys ha checksum cluster

    Sends Enter afterwards.

Licence & Contract Status

Run: get system fortiguard-service status

1 step

  1. Send
    get system fortiguard-service status

    Sends Enter afterwards.

FortiGuard Update Status

Run: diagnose autoupdate versions

1 step

  1. Send
    diagnose autoupdate versions

    Sends Enter afterwards.

Disk Usage

Run: diagnose sys logdisk usage

1 step

  1. Send
    diagnose sys logdisk usage

    Sends Enter afterwards.

Firmware Version

Run: get system status | grep Version

1 step

  1. Send
    get system status | grep Version

    Sends Enter afterwards.

Uptime

Run: get system performance status | grep Uptime

1 step

  1. Send
    get system performance status | grep Uptime

    Sends Enter afterwards.

Configuration Diff

Run: show | grep -f

1 step

  1. Send
    show | grep -f

    Sends Enter afterwards.

Current Admin Config

Run: show full-configuration system admin

1 step

  1. Send
    show full-configuration system admin

    Sends Enter afterwards.

Back Up Config to TFTP

Run: execute backup config tftp {{FILE}} {{SERVER}}

1 step · asks for confirmation before it runs · 2 inputs

  1. Send
    execute backup config tftp {{FILE}} {{SERVER}}

    Sends Enter afterwards.

Set Hostname

Run: config system global ; set hostname "{{HOSTNAME}}" ; end

3 steps · asks for confirmation before it runs · 1 input

  1. Send
    config system global

    Sends Enter afterwards.

  2. Send
    set hostname "{{HOSTNAME}}"

    Sends Enter afterwards.

  3. Send
    end

    Sends Enter afterwards.

Add NTP Server

Run: config system ntp ; set ntpsync enable ; set type custom ; config ntpserver ; edit 1 ; set server "{{NTP}}" ; next ; end ; end

9 steps · asks for confirmation before it runs · 1 input

  1. Send
    config system ntp

    Sends Enter afterwards.

  2. Send
    set ntpsync enable

    Sends Enter afterwards.

  3. Send
    set type custom

    Sends Enter afterwards.

  4. Send
    config ntpserver

    Sends Enter afterwards.

  5. Send
    edit 1

    Sends Enter afterwards.

  6. Send
    set server "{{NTP}}"

    Sends Enter afterwards.

  7. Send
    next

    Sends Enter afterwards.

  8. Send
    end

    Sends Enter afterwards.

  9. Send
    end

    Sends Enter afterwards.

Set Admin Timeout

Run: config system global ; set admintimeout {{MINUTES}} ; end

3 steps · asks for confirmation before it runs · 1 input

  1. Send
    config system global

    Sends Enter afterwards.

  2. Send
    set admintimeout {{MINUTES}}

    Sends Enter afterwards.

  3. Send
    end

    Sends Enter afterwards.

Clear All Sessions

Run: diagnose sys session clear

2 steps · asks for confirmation before it runs

  1. Confirm

    Asks yes or no: “Drop every session in the table. Every connection through this firewall breaks and has to be re-established — this is felt by users immediately. Continue?”

    Answering no stops the script here.

  2. Send
    diagnose sys session clear

    Sends Enter afterwards.

Restore Config from TFTP

Run: execute restore config tftp {{FILE}} {{SERVER}}

2 steps · asks for confirmation before it runs · 2 inputs

  1. Confirm

    Asks yes or no: “Replace the running configuration with {{FILE}} and reboot. Everything not in that file is lost, including the access you are using. Continue?”

    Answering no stops the script here.

  2. Send
    execute restore config tftp {{FILE}} {{SERVER}}

    Sends Enter afterwards.

Reboot FortiGate

Run: execute reboot

2 steps · asks for confirmation before it runs

  • Reboots or reloads the device
  1. Confirm

    Asks yes or no: “Reboot this FortiGate now. All traffic through it stops for the length of the boot. Save the config first. Continue?”

    Answering no stops the script here.

  2. Send
    execute reboot

    Sends Enter afterwards.

Shut Down FortiGate

Run: execute shutdown

2 steps · asks for confirmation before it runs

  • Shuts down an interface
  1. Confirm

    Asks yes or no: “Power off this FortiGate. It will not come back without physical intervention. Continue?”

    Answering no stops the script here.

  2. Send
    execute shutdown

    Sends Enter afterwards.

Factory Reset

Run: execute factoryreset

2 steps · asks for confirmation before it runs

  • Factory resets the device
  1. Confirm

    Asks yes or no: “Erase the entire configuration and reboot to factory defaults. Everything is lost and the device comes back on its default address only. Continue?”

    Answering no stops the script here.

  2. Send
    execute factoryreset

    Sends Enter afterwards.

Force HA Failover

Run: diagnose sys ha reset-uptime

2 steps · asks for confirmation before it runs

  1. Confirm

    Asks yes or no: “Reset HA uptime so the other unit takes over. Sessions that are not synchronised drop during the switch. Continue?”

    Answering no stops the script here.

  2. Send
    diagnose sys ha reset-uptime

    Sends Enter afterwards.

Version history

  • Revision 1 current

    First published version.

    14 Aug 2026 · 184.9 KB · needs 1.0.0+ · 5ca1b94130779243…

Something wrong with this set?

Sign in to report it, or email abuse@smartcomrevisited.com.