没有合适的资源?快使用搜索试试~ 我知道了~
首页FortiOS 5.0防火墙命令参考手册:系统管理员必读
FortiOS 5.0防火墙命令参考手册:系统管理员必读
需积分: 50 38 下载量 148 浏览量
更新于2024-07-18
收藏 6.41MB PDF 举报
飞塔防火墙操作手册是一份专门为系统管理员设计的实用指南,适用于那些想要深入了解并掌握FortiGate设备管理与安全防护的人员。这份手册的核心内容围绕FortiOS 5.0展开,它是Fortinet公司开发的防火墙操作系统,提供了强大的网络管理和安全控制功能。
FortiOS CLI (Command Line Interface) Reference是手册的核心部分,它详细介绍了如何通过命令行界面进行高效、精确的操作。用户可以学习到如何配置防火墙规则,管理访问控制列表(ACL),监控网络流量,设置安全策略,以及执行系统维护任务等。通过这份文档,管理员能够提升对防火墙的配置能力,确保网络环境的安全稳定。
值得注意的是,手册发布日期为2016年8月31日,版权属于Fortinet,所有提及的商标如Fortinet、FortiGate、FortiCare和FortiGuard都是Fortinet公司的注册商标,在美国和其他司法管辖区享有法律保护。此外,手册中的性能指标是在理想条件下测试得出的,实际性能可能会受到网络变量、不同网络环境以及其他条件的影响,可能有所差异。
手册强调,虽然其中的信息提供了技术指导,但并不代表任何强制性的承诺。Fortinet公司保留所有权利,包括但不限于明示或默示的保修声明。只有在Fortinet与其客户签订具有明确性能保修条款的书面合同(由其总法律顾问签署)时,这些承诺才会生效。
飞塔防火墙操作手册是系统管理员必备的学习资料,它不仅提供了详细的指令集,还涵盖了最佳实践和可能遇到的问题解决方案,帮助用户充分利用FortiGate防火墙的强大功能,保护网络免受威胁。
Fortinet Technologies Inc. Page 16 FortiOS™ - CLI Reference for FortiOS 5.0
vpn ipsec tunnel down....................................................................................... 1010
vpn ipsec tunnel up ........................................................................................... 1011
vpn sslvpn del-all............................................................................................... 1012
vpn sslvpn del-tunnel......................................................................................... 1013
vpn sslvpn del-web............................................................................................ 1014
vpn sslvpn list .................................................................................................... 1015
webfilter quota-reset.......................................................................................... 1016
wireless-controller delete-wtp-image ................................................................ 1017
wireless-controller list-wtp-image ..................................................................... 1018
wireless-controller reset-wtp ............................................................................. 1019
wireless-controller restart-acd........................................................................... 1020
wireless-controller restart-wtpd......................................................................... 1021
wireless-controller upload-wtp-image............................................................... 1022
get ................................................................................................................ 1023
endpoint-control app-detect ............................................................................. 1024
firewall dnstranslation ........................................................................................ 1026
firewall iprope appctrl ........................................................................................ 1027
firewall iprope list............................................................................................... 1028
firewall proute, proute6...................................................................................... 1029
firewall service custom ...................................................................................... 1030
firewall shaper.................................................................................................... 1031
grep.................................................................................................................... 1032
gui console status.............................................................................................. 1033
gui topology status ............................................................................................ 1034
hardware cpu..................................................................................................... 1035
hardware memory.............................................................................................. 1037
hardware nic ...................................................................................................... 1038
hardware npu..................................................................................................... 1039
hardware status ................................................................................................. 1042
ips decoder status ............................................................................................. 1043
ips rule status..................................................................................................... 1044
ips session ......................................................................................................... 1045
ipsec tunnel........................................................................................................ 1046
ips view-map ..................................................................................................... 1047
mgmt-data status .............................................................................................. 1048
netscan settings................................................................................................. 1049
pbx branch-office .............................................................................................. 1050
pbx dialplan ....................................................................................................... 1051
pbx did............................................................................................................... 1052
pbx extension .................................................................................................... 1053
Fortinet Technologies Inc. Page 17 FortiOS™ - CLI Reference for FortiOS 5.0
pbx ftgd-voice-pkg ............................................................................................ 1054
pbx global .......................................................................................................... 1055
pbx ringgrp ........................................................................................................ 1056
pbx sip-trunk...................................................................................................... 1057
pbx voice-menu ................................................................................................. 1058
report database schema.................................................................................... 1059
router info bfd neighbor ..................................................................................... 1060
router info bgp ................................................................................................... 1061
router info gwdetect........................................................................................... 1064
router info isis .................................................................................................... 1065
router info kernel................................................................................................ 1066
router info multicast........................................................................................... 1067
router info ospf .................................................................................................. 1069
router info protocols .......................................................................................... 1071
router info rip ..................................................................................................... 1072
router info routing-table .................................................................................... 1073
router info vrrp ................................................................................................... 1074
router info6 bgp ................................................................................................. 1075
router info6 interface.......................................................................................... 1076
router info6 kernel.............................................................................................. 1077
router info6 ospf ................................................................................................ 1078
router info6 protocols ........................................................................................ 1079
router info6 rip ................................................................................................... 1080
router info6 routing-table................................................................................... 1081
system admin list ............................................................................................... 1082
system admin status.......................................................................................... 1083
system arp ......................................................................................................... 1084
system auto-update........................................................................................... 1085
system central-management............................................................................. 1086
system checksum.............................................................................................. 1087
system cmdb status .......................................................................................... 1088
system fortianalyzer-connectivity ...................................................................... 1089
system fortiguard-log-service status ................................................................. 1090
system fortiguard-service status ....................................................................... 1091
system ha-nonsync-csum ................................................................................. 1092
system ha status................................................................................................ 1093
system info admin ssh ....................................................................................... 1096
system info admin status................................................................................... 1097
system interface physical .................................................................................. 1098
system mgmt-csum........................................................................................... 1099
Fortinet Technologies Inc. Page 18 FortiOS™ - CLI Reference for FortiOS 5.0
system performance firewall.............................................................................. 1100
system performance status ............................................................................... 1101
system performance top.................................................................................... 1102
system session list............................................................................................. 1103
system session status ....................................................................................... 1104
system session-helper-info list .......................................................................... 1105
system session-info ........................................................................................... 1106
system source-ip ............................................................................................... 1107
system startup-error-log.................................................................................... 1108
system status..................................................................................................... 1109
test ..................................................................................................................... 1110
user adgrp.......................................................................................................... 1112
vpn ike gateway ................................................................................................. 1113
vpn ipsec tunnel details ..................................................................................... 1114
vpn ipsec tunnel name....................................................................................... 1115
vpn ipsec stats crypto ....................................................................................... 1116
vpn ipsec stats tunnel........................................................................................ 1117
vpn ssl monitor .................................................................................................. 1118
vpn status l2tp ................................................................................................... 1119
vpn status pptp.................................................................................................. 1120
vpn status ssl..................................................................................................... 1121
webfilter ftgd-statistics ...................................................................................... 1122
webfilter status .................................................................................................. 1124
wireless-controller rf-analysis............................................................................ 1125
wireless-controller scan..................................................................................... 1126
wireless-controller status................................................................................... 1127
wireless-controller vap-status ........................................................................... 1128
wireless-controller wlchanlistlic ......................................................................... 1129
wireless-controller wtp-status ........................................................................... 1132
tree............................................................................................................... 1134
Page 19
Introduction
This document describes FortiOS™ 5.0 CLI commands used to configure and manage a
FortiGate unit from the command line interface (CLI).
How this guide is organized
Most of the chapters in this document describe the commands for each configuration branch of
the FortiOS™ CLI. The command branches and commands are in alphabetical order.
This document also contains the following sections:
Managing Firmware with the FortiGate BIOS describes how to change firmware at the console
during FortiGate unit boot-up.
What’s new describes changes to the 5.0 CLI.
config chapters describe the config commands.
execute describes execute commands.
get describes get commands.
tree describes the tree command.
Availability of commands and options
Some FortiOS™ CLI commands and options are not available on all FortiGate units. The CLI
displays an error message if you attempt to enter a command or option that is not available. You
can use the question mark ‘?’ to verify the commands and options that are available.
Commands and options may not be available for the following reasons:
• FortiGate model. All commands are not available on all FortiGate models. For example, low
end FortiGate models do not support the aggregate interface type option of the config
system interface command.
• Hardware configuration. For example, some AMC module commands are only available
when an AMC module is installed.
• FortiOS Carrier, FortiGate Voice, FortiWiFi etc. Commands for extended functionality are
not available on all FortiGate models. The CLI Reference includes commands only available
for FortiWiFi units, FortiOS Carrier, and FortiGate Voice units
Page 20
Managing Firmware with the FortiGate
BIOS
FortiGate units are shipped with firmware installed. Usually firmware upgrades are performed
through the web-based manager or by using the CLI execute restore command. From the
console, you can also interrupt the FortiGate unit’s boot-up process to load firmware using the
BIOS firmware that is a permanent part of the unit.
Using the BIOS, you can:
• view system information
•format the boot device
•load firmware and reboot (see “Loading firmware” on page 21)
•reboot the FortiGate unit from the backup firmware, which then becomes the default
firmware (see “Booting the backup firmware” on page 22)
Accessing the BIOS
The BIOS menu is available only through direct connection to the FortiGate unit’s Console port.
During boot-up, “Press any key” appears briefly. If you press any keyboard key at this time,
boot-up is suspended and the BIOS menu appears. If you are too late, the boot-up process
continues as usual.
Navigating the menu
The main BIOS menu looks like this:
[C]: Configure TFTP parameters
[R]: Review TFTP paramters
[T]: Initiate TFTP firmware transfer
[F]: Format boot device
[Q]: Quit menu and continue to boot
[I]: System Information
[B]: Boot with backup firmare and set as default
[Q]: Quit menu and continue to boot
[H]: Display this list of options
Enter C,R,T,F,I,B,Q,or H:
Typing the bracketed letter selects the option. Input is case-sensitive. Most options present a
submenu. An option value in square brackets at the end of the “Enter” line is the default value
which you can enter simply by pressing Return. For example,
Enter image download port number [WAN1]:
In most menus, typing H re-lists the menu options and typing Q returns to the previous menu.
剩余1134页未读,继续阅读
2013-08-22 上传
zheyimiao
- 粉丝: 38
- 资源: 5
上传资源 快速赚钱
- 我的内容管理 展开
- 我的资源 快来上传第一个资源
- 我的收益 登录查看自己的收益
- 我的积分 登录查看自己的积分
- 我的C币 登录后查看C币余额
- 我的收藏
- 我的下载
- 下载帮助
最新资源
- 探索AVL树算法:以Faculdade Senac Porto Alegre实践为例
- 小学语文教学新工具:创新黑板设计解析
- Minecraft服务器管理新插件ServerForms发布
- MATLAB基因网络模型代码实现及开源分享
- 全方位技术项目源码合集:***报名系统
- Phalcon框架实战案例分析
- MATLAB与Python结合实现短期电力负荷预测的DAT300项目解析
- 市场营销教学专用查询装置设计方案
- 随身WiFi高通210 MS8909设备的Root引导文件破解攻略
- 实现服务器端级联:modella与leveldb适配器的应用
- Oracle Linux安装必备依赖包清单与步骤
- Shyer项目:寻找喜欢的聊天伙伴
- MEAN堆栈入门项目: postings-app
- 在线WPS办公功能全接触及应用示例
- 新型带储订盒订书机设计文档
- VB多媒体教学演示系统源代码及技术项目资源大全
安全验证
文档复制为VIP权益,开通VIP直接复制
信息提交成功