Link to home
Start Free TrialLog in
Avatar of AXISHK
AXISHK

asked on

Fortigate CLI

1. What's the difference between the two commands below ?

       diagnose debug flow filter addr 192.168.99.121
       diagnose sys session filter src 192.168.99.121

2. What the meaning for the command line below ?
       diagnose debug flow trace start 100
Avatar of Garry Glendown
Garry Glendown
Flag of Germany image

1. the first is for flow debugging, which is used to see in real-time how packets are handled by the firewall, while the second is for the "diag sys sess list". Both are the filters to limit which entries/packets are displayed.

2. This command starts the actual flow debugging, and limits the processing to 100 flows.
Avatar of AXISHK
AXISHK

ASKER

What's the difference between "diagnose debug flow" and  "diagnose sys session" ? Does former is real time while the latter is not ?

Thx
ASKER CERTIFIED SOLUTION
Avatar of Garry Glendown
Garry Glendown
Flag of Germany image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of AXISHK

ASKER

Thx