Post

Commands (FortiGate)

Commands (FortiGate)

Enable/Disable Debugging

CommandDescription
diagnose debug resetStop all the prior debugs that were enabled and running in the foreground or background.
diagnose debug enableStart printing debugs in the console.
diagnose debug disableStop printing debugs in the console. The debugs are still running in the background; use diagnose debug reset to completely stop them.
diagnose debug duration 0Start debugging for infinite duration. By default, debug is set for 30 minutes.

System

System

CommandDescription
get system statusShow system information.
execute timeShow current system time.
get system performance statusShow CPU and memory utilization.
execute tac reportExecute TAC report used to open a support ticket with Fortinet Support.
diagnose sys top {s} {n} {i}Show a list of the first n processes every s seconds for i iterations.
Shift +CSort by highest CPU
Shift + MSort by highest memory
diagnose debug crashlog readShow system and application crashes.
diagnose sys process pidof <daemon>Show PID of the daemon that is running. The names of currently running daemons can be found using diagnose sys top.
diagnose sys kill 11 <pid>Kill the PID with signal 11.
diagnose sys session statShow session statistics.
diagnose sys session exp-statShow expectation session statistics.
diagnose sys vd listShow virtual domain information and system statistics.
diagnose sys cmdb infoShow information about the latest configuration change performed by the daemon.
execute factoryreset [keepvmlicense]Immediately reset to factory defaults and reboot. If keepvmlicense is specified (VM models only), the VM license is retained after reset.
execute factoryreset-shutdown [keepvmlicense]Immediately reset to factory defaults and shutdown. If keepvmlicense is specified (VM models only), the VM license is retained after reset.
execute factoryreset2 [keepvmlicense]Reset to factory default, except system settings, system interfaces, VDOMs, static routes, and virtual switches. If keepvmlicense is specified (VM models only), the VM license is retained after reset.
diagnose debug config-error-log readShow errors in the configuration file.
diagnose snmp ip fragsShow fragmentation and reassembly information.
diagnose sys process dump <PID>Show essential process related information for a particular process PID.
diagnose sys process pstack <PID>Show essential process related information for a particular process PID.
diagnose sys process trace <PID>Show essential process related information for a particular process PID.
diagnose sys mpstat {n}Show CPU usage every n seconds.
diagnose hardware sysinfo memoryShow system memory information.
diagnose firewall packet distributionShow packet distribution statistics.
execute rebootReboot the device.

Hardware

CommandDescription
diagnose hardware sysinfo interruptsShow hardware interrupts statistics.
diagnose hardware test suite allExecute a hardware diagnostic test, also known as an HQIP test.
diagnose hardware deviceinfo diskShow disk information.
diagnose sys flash listShow flash partitions.
execute disk listShow available mounted disks.
execute disk format <partition ref>Format the referenced partition.
diagnose disktest device <device>Execute a disk check to check if disk is faulty.
diagnose disktest block <block>Execute a disk check to check if disk is faulty.
diagnose disktest size <mb>Execute a disk check to check if disk is faulty.
diagnose disk test runExecute a disk check to check if disk is faulty.
execute formatlogdiskFormat the log disk.
diagnose hardware sysinfo cpuShow CPU information.
diagnose sys modem detectDetect the modem and start real-time debugging of the modem daemon.
diagnose debug application modemd -1Start real-time debugging of the modem daemon.
diagnose debug enableStart real-time debugging of the modem daemon.

FortiGuard

CommandDescription
diagnose webfilter fortiguard statisticsShow rating cache and daemon statistics.
diagnose debug ratingShow web filter rating server information.
diagnose debug application update -1Start debugging for updated daemon to troubleshoot FortiGuard update issues.
diagnose debug enableStart debugging for updated daemon to troubleshoot FortiGuard update issues.
execute update-nowExecute the FortiGuard update manually.
diagnose autoupdate statusShow license information.
diagnose autoupdate versionsShow license information.

Session table

CommandDescription
diagnose sys session filter <filter>Set session table filters.
diagnose sys session filterShow session filters, if set.
diagnose sys session listShow session table after filtering.
diagnose sys session clearClear the session table for the specified filter.
diagnose firewall iprope listShow FortiGate’s internal firewall table.

Network Diagnostics

CommandDescription
execute ping-options {options}Ping IP address using the specified options.
execute ping <x.x.x.x>Ping IP address using the specified options.
execute ssh-options {options}SSH to IP address using the specified options.
execute ssh <x.x.x.x>SSH to IP address using the specified options.
execute traceroute-options {options}Traceroute IP address using the specified options.
execute traceroute <x.x.x.x>Traceroute IP address using the specified options.
get system arpShow ARP entries.
diagnose ip arp listShow ARP entries.
diagnose netlink brctl listShow the names of all of the switches on the FortiGate.
diagnose netlink brctl name host <switch-name>Show the switching table of the specified switch.
get system interfaceShow a summary of interface details, including IP address information.
get sys interface physicalShow a summary of interface details, including IP address information.
diagnose ip address listShow IP address information.
diagnose hardware deviceinfo nic <interface>Show detailed interface information.
get hardware nic <interface>Show detailed interface information.
get sys interface transceiverShow connected transceivers.

Packet Sniffer

CommandDescription
diagnose sniffer packet <interface> <'filter'> <verbose> <count> <a\|l>Execute the inbuilt packet sniffer, filtered on a particular interface with the specified filter. For more information, see Performing a sniffer trace or packet capture.

Debug Flow

CommandDescription
diagnose debug resetStop all the prior debugs that were enabled and running in the foreground or background.
diagnose debug flow filter clearClear any IPv4 debug flow filters.
diagnose debug flow filter6 clearClear any IPv6 debug flow filters.
diagnose debug flow filter <filter>Set a filter for running IPv4 traffic debug flows.
diagnose debug flow filter6 <filter>Set a filter for running IPv6 traffic debug flows.
diagnose debug flow show function-name enableShow the function name of the code that the traffic accesses.
diagnose debug flow show iprope enableShow which internal firewall policy that the traffic is going through.
diagnose debug console timestamp enableStart printing timestamps on debugs.
diagnose debug flow trace start <n>Show n lines of IPv4 debugs.
diagnose debug flow trace start6 <n>Show n lines of IPv6 debugs.
diagnose debug enableStart printing debugs in the console.

UTM

CommandDescription
diagnose debug urlfilter <filter> 
diagnose debug application urlfilter -1 
diagnose debug enableStart real-time debugging for web filter traffic.
diagnose debug enable 
diagnose test application urlfilterList the web filter debug outputs.
diagnose test application urlfilter <option>Show the web filter debug output for the specified option.
diagnose debug application dnsproxy -1 
diagnose debug enableStart real-time debugging for DNS proxy. DNS proxy is responsible for DNS filter, DNS translation, DNS resolution etc.
diagnose debug enable 
diagnose test application dnsproxyList the DNS proxy debug outputs.
diagnose test application dnsproxy <option>Show the DNS proxy debug output for the specified option.
diagnose ips filter set "host <x.x.x.x> and port <port>" 
diagnose ips debug enable all 
diagnose debug enableStart IPS engine debugs for Application Control and IPS Security profile
diagnose ips debug enable av 
diagnose ips debug status show 
diagnose sys scanunit debug all enable 
diagnose sys scanunit debug level verbose 
diagnose sys scanunit debug show 
diagnose debug enableStart real-time debugging for antivirus profile when antivirus profile is configured in flow mode.
diagnose wad debug enable category scan 
diagnose wad stream-scan av-test "debug enable" 
diagnose wad stream-scan av-test "debug all:debug" 
diagnose sys scanunit debug all enable 
diagnose sys scanunit debug level verbose 
diagnose sys scanunit debug show 
diagnose debug enable 

IPS Engine

CommandDescription
diagnose test application ipsmonitor 1Show IPS engine information
diagnose test application ipsmonitor 2Set the IPS engine enable/disable status.
diagnose test application ipsmonitor 99Restart all IPS engines and monitor.
diagnose test application ipsmonitor 97Start all IPS engines.
diagnose test application ipsmonitor 98Stop all IPS engines.
diagnose ips session listShow the IPS sessions in each engine’s memory space.
diagnose test application ipsmonitor 13 
diagnose ips filter set "host <x.x.x.x> and port <port>"Show IPS engine debugs for the traffic specified by the filter.
diagnose ips debug enable all 
diagnose debug enable 

WAD

CommandDescription
diagnose test application wad 1000Show all WAD processes.
diagnose test application wad 2Show total memory usage.
diagnose test application wad 99Restart all WAD processes.
diagnose wad debug display pid enableStart real-time debugging of the traffic processed by WAD daemon.
diagnose wad filter <filter> 
diagnose wad filter list 
diagnose wad debug enable level <level> 
diagnose wad debug enable category <category> 
diagnose debug enable 
diagnose wad filter <filter>Set the filter for the WAD debugs.
diagnose wad filter listShow all the filters that have been set for debugging.
diagnose wad filter clearClear the WAD filter settings.
diagnose wad debug enable level <level>Set the verbosity level of the debugs.
diagnose wad debug enable category <category>Set the traffic category.
diagnose wad debug display pid enableShow the WAS worker PID in debugs that handle the session request.
diagnose debug enableStart printing debugs in the console.

CPU Profiling

CommandDescription
diagnose sys profile cpumask <cpu_id>Set the CPU core to profile.
diagnose sys profile startStart CPU profiling and wait for one to two minutes to stop.
diagnose sys profile stopStop CPU profiling.
diagnose sys profile moduleShow the applied kernel modules.
diagnose sys profile show detailShow the CPU profiling result for the respective core.
diagnose sys profile show order 

Tree

CommandDescription
treeShow the entire command tree.
tree executeShow the execute command tree.
tree diagnoseShow the diagnose command tree.

Routing

IPv4 and IPv6 Routing

CommandDescription
get router info routing-table allShow routing table.
get router info routing-table databaseShow IPv4 and IPv6 routing database information.
get router info6 routing-table database 
diagnose ip route listShow the IPv4 and IPv6 kernel routing table.
get router info kernel 
diagnose ipv6 route list 
get router info6 kernel 
get router info protocolsShow routing protocol information for IPv4 and IPv6.
get router info6 protocols 
execute router restartRestart the routing daemon
get router info ospf statusShow OSPF status for IPv4 and IPv6.
get router info6 ospf status 
get router info ospf neighborShow OSPF neighbors for IPv4 and IPv6.
get router info6 ospf neighbor 
get router info ospf database briefShow OSPF database in brief.
get router info bfd neighborShow BFD neighbors for IPv4 and IPv6.
get router info6 bfd neighbor 
diagnose test application bfd 1Show BFD statistics.
diagnose test application bfd 2 
diagnose test application bfd 3 
diagnose debug application bfdd <debug level>Start real-time BFD debugging.
diagnose debug enable 
get router info bgp summaryShow BGP summary for IPv4 and IPv6.
get router info6 bgp summary 
get router info bgp neighborsShow BGP peer and the advertised and received routes from the BGP peer.
get router info6 bgp neighbors 
get router info bgp neighbors <x.x.x.x> advertised-routes- Substitute with IPv4 address of the peer.
get router info6 bgp neighbors <x:x::x:x/m> advertised-routes- Substitute <x:x::x:x/m> with IPv6 address of the peer.
get router info bgp neighbors <x.x.x.x> received-routes 
get router info6 bgp neighbors <x:x::x:x/m> received-routes 
get router info bgp neighbors <x.x.x.x> routes 
get router info6 bgp neighbors <x:x::x:x/m> routes 
diagnose ip router bgp all enableStart real-time BGP debugging.
diagnose ip router bgp level info 
diagnose debug enable 
execute router clear bgp {all \| as <ASN> \| ip x.x.x.x \| ipv6 y:y:y:y:y:y:y:y}Execute a hard reset based on the specified parameters:
 - all: all BGP peers
 - as : BGP peers specified by AS number
 - ip x.x.x.x: BGP peer specified by IPv4 address (x.x.x.x)
 - ipv6 y:y:y:y:y:y:y:y: BGP peer specified by IPv6 address (y:y:y:y:y:y:y:y)
execute router clear bgp {all \| ip x.x.x.x \| ipv6 y:y:y:y:y:y:y:y} soft {in\|out}Executes soft reset based on the specified parameter:
 - all: all BGP peers
 - ip x.x.x.x: BGP peer specified by IPv4 address (x.x.x.x)
 - ipv6 y:y:y:y:y:y:y:y: BGP peer specified by IPv6 address (y:y:y:y:y:y:y:y)
 - in: received BGP routes only
 - out: advertised BGP routes only
 - A soft reset will occur in both directions if neither in nor out is specified.
get router info ospf statusShow OSPF status for IPv4 and IPv6.
get router info6 ospf status 
get router info ospf interfaceShow OSPF running on interface for IPv4 and IPv6.
get router info6 ospf interface 
get router info ospf neighbor allShow OSFP neighbor information for IPv4 and IPv6.
get router info6 ospf neighbor all 
get router info ospf database briefShow OSPF database in brief for IPv4 and IPv6.
get router info6 ospf database brief 
diagnose ip router ospf all enableStart real-time OSPF debugging.
diagnose ip router ospf level info 
diagnose debug enable 

Multicast Routing

CommandDescription
get router info multicast igmp interfaceShow IGMP statistics for an interface.
get router info multicast igmp groupsShow multicast groups subscribed to with IGMP.
diagnose ip multicast get-igmp-limitShow maximum IGMP states.
diagnose ip router igmp decode enableStart real-time debugging of IGMP daemon.
diagnose ip router igmp level info 
diagnose debug console timestamp enable 
diagnose debug enable 
execute mrouter clear igmp-interface <interface>Clear all IGMP entries from one interface.
execute mrouter clear igmp-group <group-address>Clear all IGMP entries for one or all groups.
get router info multicast pim sparse-mode <interface>Show sparse-mode interface information.
get router info multicast pim sparse-mode <neighbor>Show sparse-mode neighbor information.
get router info multicast pim sparse-mode rp-mappingShow RP to group mapping information.
get router info multicast pim sparse-mode tableShow sparse-mode routing table.
diagnose ip router pim-sm events enableStart real-time debugging of PIM sparse mode.
diagnose ip router pim-sm all enable 
diagnose ip router pim-sm level info 
diagnose debug enable 

SD-WAN

CommandDescription
diagnose sys sdwan health-check statusShow SD-WAN health check statistics.
diagnose sys sdwan serviceShow SD-WAN rules in control plane.
diagnose sys sdwan memberShow SD-WAN members.
diagnose firewall proute listShow SDWAN rule and policy routes in the data plane.
diagnose sys link-monitor statusShow link monitoring statistics.
diagnose sys link-monitor interface <interface> 
diagnose debug application link-monitor -1Start real-time link monitor debugging.
diagnose debug enable 
diagnose test application lnkmtd 1Show link monitoring statistics.
diagnose test application lnkmtd 2 
diagnose test application lnkmtd 3 

Authentication

CommandDescription
diagnose firewall auth filter <filter>Set the filter used to list entries.
diagnose firewall auth listList filtered, authenticated IPv4 users.
diagnose wad user listList current users authenticated by proxy (wad daemon).
diagnose debug application fnbamd -1Start real-time debugging for remote and local authentication.
diagnose debug application authd -1 
diagnose debug enable 
diagnose test authserver <auth_protocol> <server_name> <user> <password>Test authentication directly from the CLI. Caution: The password is visible in clear text; be careful when capture this command to a log file.
diagnose test authserver ldap <server_name> <user> <password>Test user authentication using an LDAP server. Caution: The password is visible in clear text; be careful when capture this command to a log file.
diagnose test authserver radius <server_name> <auth_type> <user> <password>Test user authentication using a Radius server. Caution: The password is visible in clear text; be careful when capture this command to a log file.
diagnose debug fsso-polling detailShow information about the polls from FortiGate to DC.
diagnose debug fsso-polling summary 
diagnose debug fsso-polling userShow FSSO logged on users when Fortigate polls the DC.
diagnose debug authd fsso list 
diagnose debug application fssod -1Start real-time debugging when the FortiGate is used for FSSO polling.
diagnose debug application smbcd -1 
diagnose debug enable 
diagnose debug fsso-polling refresh-userRefresh the current logged on FSSO users and refresh the list. Caution: This command can cause an outage, use it carefully.
execute fsso refresh 
diagnose debug authd fsso server-statusShow current status of connection between FortiGate and the collector agent.
diagnose debug application authd 8256Start real-time debugging for the connection between FortiGate and the collector agent.
diagnose debug enable 
diagnose debug authd fsso refresh-logonsResend the logged-on users list to FortiGate from the collector agent.
diagnose debug application authd 8256Start real-time debugging for the connection between FortiGate and the collector agent.
diagnose debug enable 
diagnose debug application samld -1Start real-time SAML debugging.
diagnose debug enable 

VPN

IPsec

CommandDescription
diagnose vpn ike gateway listShow IPsec phase 1 information.
diagnose vpn tunnel listShow IPsec phase 2 information.
get vpn ipsec tunnel summaryShow summary and detailed information about IPsec tunnels.
get vpn ipsec tunnel details 
diagnose vpn ipsec statusShow information about encryption counters.
diagnose vpn ike log filter <filter>Set a filter for IKE daemon debugs.
diagnose debug application ike -1Start real-time debugging of IKE daemon with the filter set.
diagnose debug enable 
diagnose vpn ike restartRestart the IKE process.
diagnose vpn ike countsShow other information, such as IKE counts, routes, errors, and statistics.
diagnose vpn ike routes 
diagnose vpn ike errors 
diagnose vpn ike stats 
diagnose vpn ike status 
diagnose vpn ike crypto 

SSL VPN

CommandDescription
diagnose vpn ssl debug-filter listShow any filters that are set for SSL VPN debug.
diagnose vpn ssl debug-filter clearClear any filters that are set for SSL VPN daemon debug.
diagnose vpn ssl debug-filter <filter>Set a filter for SSL VPN debugs.
diagnose debug application sslvpn -1Start SSL VPN debugs for traffic that the filter is applied to.
diagnose debug enable 
diagnose vpn ssl listShow the current SSL VPN sessions for both web and tunnel mode.
get vpn ssl monitor 
execute vpn sslvpn list 
diagnose vpn ssl statisticsShow the SSL VPN statistics.
diagnose vpn ssl mux-stat 
execute vpn sslvpn listShow all SSL VPN web and tunnel mode connections.
execute vpn sslvpn del-tunnelDisconnect the users from tunnel mode SSL VPN connection.
execute vpn sslvpn del-webDisconnect the users from web mode SSL VPN connection.

Managed Devices

Managed FortiSwitches

CommandDescription
diagnose switch-controller switch-info mac-tableShow managed FortiSwitch MAC address list.
diagnose switch-controller switch-info port-statsShow managed FortiSwitch port statistics.
diagnose switch-controller switch-info trunk statusShow managed FortiSwitch trunk information.
diagnose switch-controller switch-info mclagShow MCLAG related information from FortiSwitch.
diagnose switch-controller switch-info poeShow POE-related information.
diagnose switch-controller switch-info lldpShow LLDP-related information.
diagnose switch-controller switch-info port-propertiesShow managed FortiSwitch port properties.
diagnose switch-controller switch-info acl-countersShow managed FortiSwitch port ACL counters information.
diagnose switch-controller switch-info pdu-counters-listShow managed FortiSwitch pdu-counters information.
diagnose switch-controller switch-info flapguardShow managed FortiSwitch flapguard information.
diagnose switch-controller switch-info qos-statsShow managed FortiSwitch QoS statistics.
diagnose switch-controller switch-info modulesShow modules related information from FortiSwitch.
diagnose switch-controller switch-info stpShow managed FortiSwitch STP instance status.
diagnose switch-controller switch-info bpdu-guard-statusShow managed FortiSwitch STP BPDU guard status.
diagnose switch-controller switch-info igmp-snoopingShow managed FortiSwitch IGMP snooping information.
diagnose switch-controller switch-info loop-guardShow managed FortiSwitch loop-guard status.
diagnose switch-controller switch-info dhcp-snoopingShow managed FortiSwitch DHCP snooping interface list.
diagnose switch-controller switch-info arp-inspectionShow managed FortiSwitch ARP inspection interface list.
diagnose switch-controller switch-info option82-mappingShow managed FortiSwitch DHCP option 82 mapping information.
diagnose switch-controller switch-info 802.1XShow managed FortiSwitch port 802.1X status.
diagnose switch-controller switch-info 802.1X-daclShow managed FortiSwitch port 802.1X dynamic ACL status.
diagnose switch-controller switch-info mac-limit-violationsShow managed FortiSwitch violated MACs information.
diagnose switch-controller switch-info flow-trackingShow managed FortiSwitch flow information.
diagnose switch-controller switch-info mirrorShow managed FortiSwitch mirror information.
diagnose switch-controller switch-info ip-source-guardShow managed FortiSwitch source guard information in hardware.
diagnose switch-controller switch-info rpvstShow managed FortiSwitch STP port information when inter-operating with rapid PVST network.
execute switch-controller get-conn-status <FortiSwitch-SN>Show FortiSwitch connection status.
execute switch-controller get-physical-conn standard <FortiSwitch-SN>Show FortiLink connectivity graph.
execute switch-controller diagnose-connection <FortiSwitch-SN>Show FortiSwitch connection diagnostics.

Managed FortiAPs

CommandDescription
diagnose wireless-controller wlac -c wtpShow information about the FortiAP devices.
diagnose wireless-controller wlac -d wtp 
diagnose wireless-controller wlac -c staShow information about the wireless clients connected to the FortiAP devices.
diagnose wireless-controller wlac -d sta 
diagnose wireless-controller wlac helpShow a list of debug options available for the wireless controller.
diagnose wireless-controller wlac sta_filterStart real-time debugging of a wireless client/station that connects to the FortiAP.
diagnose wireless-controller wlac sta_filter clear 
diagnose wireless-controller wlac sta_filter <aa:bb:cc:dd:ee:ff> 255 
diagnose debug enable 
diagnose wireless-controller wlac -c vapShow virtual access point information, including its MAC address, BSSID, SSID, the interface name, and the IP address of the APs that are broadcasting it.
diagnose wireless-controller wlac wtp_filterShow the wireless termination point (WTP), or FortiAP, debugging on the wireless controller if FortiAP is failing to connect to FortiGate.
diagnose wireless-controller wlac wtp_filter clear 
diagnose wireless-controller wlac wtp_filter <FAP-SN> 0-<x.x.x.x>:5246 255 
diagnose debug application cw_acd 0x7ff 

Other Services

High Availability

CommandDescription
diagnose system ha statusShow HA status and information.
get system ha status 
execute ha manage <index> <username>Log into and manage a specific HA member.
diagnose sys ha checksum clusterShow checksum information of all cluster members.
diagnose sys ha checksum show <vdom>Show detailed checksum information for a VDOM.
diagnose sys ha checksum recalculateRecalculate HA checksums.
diagnose sys ha recalculate-extfile-signatureRecalculate HA external files signatures.
diagnose sys ha reset-uptimeReset the HA uptime. This is used to test failover.
diagnose debug application hatalk -1Start real-time debugging of HA daemons.
diagnose debug application hasync -1 
diagnose debug application harelay -1 
diagnose debug enable 
diagnose sys ha history readShow HA history.
execute ha synchronize stopManually start and stop HA synchronization.
execute ha synchronize start 

ZTNA

CommandDescription
diagnose endpoint fctems test-connectivity <EMS>Test FortiGate to FortiClient EMS connectivity.
execute fctems verify <EMS>Verify FortiClient EMS’s certificate.
diagnose test application fcnacd 2Show EMS connectivity information.
diagnose debug application fcnacd -1Start real-time debugging of FortiClient NAC daemon.
diagnose debug enable 
diagnose endpoint record list <ip>Show the endpoint record list. Optionally, filter by the endpoint IP address.
diagnose endpoint wad-comm find-by uid <uid>Query endpoints by client UID.
diagnose endpoint wad-comm find-by ip-vdom <ip> <vdom>Query endpoints by the client IP-VDOM pair.
diagnose wad dev query-by uid <uid>Query from WAD diagnose command by UID.
diagnose wad dev query-by ipv4 <ip>Query from WAD diagnose command by IP address.
diagnose firewall dynamic listShow EMS ZTNA tags and all dynamic IP and MAC addresses.
diagnose test application fcnacd 7Show the FortiClient NAC daemon ZTNA and route cache.
diagnose test application fcnacd 8 
diagnose wad debug display pid enableStart real-time debugging of the traffic processed by WAD daemon.
diagnose wad filter <filter> 
diagnose wad filter list 
diagnose wad debug enable level <level> 
diagnose wad debug enable category <category> 
diagnose debug enable 

Logging

CommandDescription
diagnose log testGenerate logs for testing.
execute log filter <filter>Set log filters.
execute log filterShow log filters.
exec log displayShow filtered logs.
execute log deleteDelete filtered logs.
diagnose debug application miglogd -1Start real-time debugging of logging process miglogd.
diagnose debug enable 
execute log fortianalyzer test-connectivityTest connectivity between FortiGate and FortiAnalyzer.

Traffic Shaping

CommandDescription
diagnose firewall shaper traffic-shaper listShow configured traffic shapers.
diagnose firewall shaper traffic-shaper stats listShow traffic shaper statistics.

SIP Session Helper

CommandDescription
diagnose sys sip statusShow SIP status.
diagnose sys sip mapping listShow SIP mapping list.
diagnose sys sip dialog listShow SIP dialogue list.
diagnose debug application sip -1Start real-time SIP debugging.
diagnose debug enable 

SIP ALG

CommandDescription
diagnose sys sip-proxy calls listShow list of active SIP proxy calls.
diagnose sys sip-proxy statsShow SIP proxy statistics.
diagnose sys sip-proxy session listShow SIP proxy session list.
diagnose debug application sip -1Start real-time SIP debugging.
diagnose debug enable 

Source

This post is licensed under CC BY 4.0 by the author.