Troubleshooting security policies and profiles

Fixing errors generated by a security policy requires tools to verify the network traffic flow, including verifications of protocols and ports. The following CLI tools are fundamental to troubleshooting issues related to security filters.

FortiOS packet sniffer

All FortiGate units have a built-in packet sniffer (or network analyser, a feature that captures all the data packets that pass through a given network interface or device). The packet sniffer includes six levels of information numbered from verbose 1 (basic information) to verbose 6 (that incorporates a lot of information also regarding the interfaces).

The command to use is:

  • diagnose sniffer packet. The parameters are:
    • <interface>: A specific ...

Get Getting Started with FortiGate now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.