How To Show Configuration On Fortigate CLI: Comprehensive Administrative Guide
Mastering the Fortigate Command Line Interface (CLI) configuration display commands is essential for network administrators seeking granular visibility into firewall policies, routing tables, and system settings. Utilizing commands such as show, get, and execute allows engineers to audit security postures, troubleshoot connectivity bottlenecks, and verify live operational parameters across FortiOS environments.
Pre-Operation & Planning Checklist for FortiOS Environments
Executing configuration reviews on enterprise firewalls requires structured preparation to ensure operational continuity and adherence to security policies. Before initiating any administrative command-line session, administrators must verify access credentials, establish secure transport channels, and understand the scoping of the configuration tree. FortiOS organizes its configuration in a hierarchical database, meaning the output visibility heavily depends on the current administrative context and privilege level.
- Essential Equipment & Tools: A secure terminal emulator such as PuTTY, SecureCRT, or native terminal clients, along with an operational SSH, Telnet, or console cable connection to the FortiGate hardware appliance or virtual machine instance.
- Mandatory Prerequisite Knowledge: Familiarity with FortiOS CLI syntax, administrative profiles, multi-domaining (Virtual Domains or VDOMs), and the fundamental distinction between running configuration commands and operational status queries.
- Budget & Duration Benchmarks: Zero direct financial cost, with an estimated execution and review duration ranging from 5 to 30 minutes depending on the complexity of the firewall rule base and the specific objects being inspected.
Step-by-Step Procedure to Display Fortigate Configurations
Step 1: Establish Secure CLI Access and Select the Target VDOM
Initiate a secure administrative connection to the FortiGate device using SSH or a direct console cable. Log in with an administrator account holding super_admin privileges or a custom profile with read access to system configuration. If the firewall utilizes Virtual Domains, execute the command "config vdom" followed by "edit [vdom-name]" to switch to the specific context you need to audit, as default global commands may not display localized VDOM policies.
Pro-Tip: Always verify your active VDOM context by running the "get system status" command or checking the prompt string before extracting configuration files to prevent auditing the wrong security domain.
Step 2: Execute the Basic Show Command for Global and Sub-Context Settings
Type the keyword "show" at the root or within any specific configuration block (such as firewall policy, interface, or router static) to output the current active configuration. To view the entire system configuration text file, navigate to the top-level configuration mode and type "show full-configuration", which displays default values alongside user-modified parameters. For targeted reviews, append object identifiers or names, such as "show firewall policy 1", to isolate specific security rules without scrolling through thousands of lines of text.
Warning: Running "show full-configuration" on large enterprise firewalls generates massive data output. Ensure your terminal emulator has scrollback buffer limits disabled or set to a high threshold (e.g., 20,000 lines) to avoid data loss.
Step 3: Filter Configuration Output Using Grep
When searching for specific parameters within large configuration blocks, leverage the built-in grep utility by appending " | grep [search-term]" to any show command. For example, typing "show firewall policy | grep internal" filters the policy database to display only rules referencing the internal interface. You can also utilize inverse matching using " | grep -v" to exclude noisy entries, or case-insensitive searches to locate specific IP addresses, subnet masks, or user group names across complex configurations.
Step 4: Verify Operational Status Versus Stored Configuration
Differentiate between static configuration settings and dynamic operational states by utilizing the "get" command family instead of "show". While "show" displays what administrators have manually configured and saved to the running database, commands like "get system performance status", "get router info routing-table all", and "get system interface physical" display real-time metrics, dynamic routes, and live hardware interface statistics required for accurate troubleshooting.
How to setup SPAN (Port Mirroring) on Fortigate ? | Artica Wiki
FortiOS Command Matrix: Show, Get, and Execute Comparison
| Command Category | Primary Purpose | Scope of Data | Typical Use Case |
|---|---|---|---|
| Show | Displays stored configuration parameters | Running configuration database | Auditing security policies, object groups, and system settings |
| Show Full-Configuration | Displays all parameters including default values | Complete system tree with defaults | Comprehensive backups, migration planning, and compliance checks |
| Get | Retrieves real-time operational status and metrics | Live system memory and tables | Monitoring CPU usage, active routing tables, and interface states |
| Execute | Runs immediate administrative actions or tests | Active system routines | Testing network reachability via ping, clearing sessions, and rebooting |
Common Configuration Review Failures and Field Fixes
- Truncated Output in Terminal Emulator: Root Cause: The terminal emulator application has a restrictive scrollback buffer limit that cuts off the top or bottom of long configuration files. Actionable Fix: Increase the scrollback buffer settings in your SSH client preferences to infinite or at least 50,000 lines, or redirect output to an external TFTP/SFTP server using automated configuration backup scripts.
- Missing Firewall Policies or Objects: Root Cause: Executing show commands while positioned inside the wrong Virtual Domain (VDOM) or outside the correct sub-context level. Actionable Fix: Enter the global configuration mode, switch to the correct VDOM using the edit command, and re-run the targeted show query.
- Inability to View Encrypted Secrets or Passwords: Root Cause: FortiOS security architecture hashes and encrypts sensitive attributes such as pre-shared keys, local user passwords, and TACACS+ secrets by design. Actionable Fix: Understand that plaintext recovery of hashed secrets is impossible; instead, re-enter the known secret value into the configuration line if updates are required.
- Output Freezing During Large Configuration Dumps: Root Cause: Pagination stopping the stream due to terminal line height limits. Actionable Fix: Press the spacebar to page down through the output line by line, or press the enter key to advance single lines until the prompt returns.
Frequently Asked Questions
How do I view only modified settings instead of default configurations?
Using the standard "show" command inside any configuration context displays solely the parameters and attributes that have been explicitly modified or added by an administrator. To see parameters left at their default factory settings, you must explicitly use the "show full-configuration" command variant.
Can I save the CLI configuration output directly to a file?
Yes, administrators can back up the configuration directly from the CLI by executing the "execute backup config tftp" or "execute backup config sftp" commands. This pushes a complete, unencrypted or encrypted configuration script directly to an external network server without requiring manual text copying from the terminal window.
What is the difference between the show command and the get command?
The "show" command queries the running configuration database to display what rules, interfaces, and system options are currently provisioned. Conversely, the "get" command queries the active kernel and operational memory to display live statistics, dynamic routing tables, interface link statuses, and real-time hardware health metrics.
How do I search for a specific IP address within the FortiGate configuration?
You can locate any specific IP address or subnet across the entire firewall configuration by running the command "show full-configuration | grep [IP-Address]". This filters the vast configuration text and outputs only the specific lines containing your matching query string.
Why does the CLI prompt display vdom name instead of just the hostname?
When Virtual Domains are enabled on the FortiGate device, the CLI prompt includes the name of the active VDOM you are currently administrating to prevent accidental configuration modifications in the wrong security partition. You can return to the global administrative context by typing the command "end" or "config global" depending on your current sub-menu depth.
Optimize Your Enterprise Firewall Management Workflow Today
Implement structured configuration audits and leverage advanced FortiOS CLI commands to maintain absolute visibility over your network security architecture. Partner with our certified engineering team to streamline complex firewall migrations, automate configuration backups, and ensure compliance across your entire FortiGate infrastructure.