Skip to main content
AD Academy
Network security: Fortinet
Intermediate14 minLast updated: Topic 8 of 14

Logs and troubleshooting

A clear workflow: from the GUI log to CLI sniffer and debug flow.

Not read

What you will learn here

  • A step-by-step troubleshooting method
  • How to read logs in the GUI
  • When to use sniffer and debug flow

Worth reading first:Security profiles and SSL inspection

Most FortiGate issues come down to three causes: the policy did not match, routing sends traffic the wrong way, or a security profile is blocking. A fixed checking order saves hours.

  • 1. Log & Report → Forward Traffic — check whether the packet arrived and which policy ID handled it.
  • 2. Routing — verify a return path exists; without it the reply disappears.
  • 3. Sniffer — see whether packets physically reach the interface.
  • 4. Debug flow — follow the internal decision for each packet.
# sniffer: verbose=4 -> заголовки + интерфейс
diagnose sniffer packet any "host 10.10.10.20 and port 443" 4 0 a

# debug flow: почему пакет разрешён или отброшен
diagnose debug flow filter addr 10.10.10.20
diagnose debug flow show function-name enable
diagnose debug flow trace start 20
diagnose debug enable

# сброс отладки
diagnose debug disable
diagnose debug reset
text

Check yourself

Which command shows why a packet was allowed or dropped?

Was this page helpful?