Course menu

Module 1: Getting StartedLesson 1.3 (3 of 5 in this module)3 of 18 in the FortiGate Administrator course

The FortiOS CLI

config, edit, set, next and end; show versus get; diagnose and execute; and the habits that stop CLI mistakes.

Beginner · 10 min read

What you will learn

After this lesson, you can navigate and change the FortiOS configuration with config, edit, set and end, read it with show and get, and avoid the CLI mistakes that overwrite lists or save half-finished work.

  • config/edit/set
  • show vs get
  • diagnose and execute
  • Editing lists

The FortiOS CLI is a tree of configuration tables. config opens a table, edit opens an entry in it (creating it if needed), set and unset change its fields, next saves the entry and end saves and closes the table. Four top-level verbs cover everything else: show and get to read, execute to act, diagnose to troubleshoot.

In simple terms: The configuration is a set of folders. You open a folder with config, pick an item with edit, change it with set, and close it with end.

A real-life situation

An administrator wants to add port4 to a zone that already contains port2 and port3. They type set interface port4, press Enter, and the zone now contains only port4: two networks lose their policies at once. Nothing was wrong with FortiOS. The CLI did exactly what set does. A few rules explain this and most other CLI surprises.

The four verbs at the top

VerbDoesExample
configOpens a table to change itconfig system interface
show / getReads configuration / reads values and statusshow firewall policy 1
executeRuns an actionexecute ping 10.0.1.10
diagnoseTroubleshooting and debuggingdiagnose sys session list

Changing configuration: config, edit, set, next, end

config system interface edit port3 set ip 10.0.2.1 255.255.255.0 set allowaccess ping set role dmz next end

config opens the interface table, edit port3 opens that entry, set changes fields, next saves port3 and stays in the table (to edit another interface), end saves and leaves.

  • edit creates the entry if it doesn't exist, so a typo creates a new object. For numbered tables, edit 0 creates one with the next free number.
  • unset returns a field to its default.
  • abort leaves the table without saving the changes in it, a lifesaver after a mistake.
  • Inside a table: delete, rename A to B, clone A to B and move 5 before 2 manage entries.

Lists: set replaces, append adds

config system zone edit LAN-ZONE set interface port2 port3 append interface port4 unselect interface port3 next end

Line by line: set makes the list exactly port2 port3; append adds port4 (port2 port3 port4); unselect removes port3 (port2 port4). Fields that hold several values (interfaces, addresses, services) are replaced completely by set.

Reading configuration: show and get

Example output · based on Fortinet documentation; exact format varies by model and FortiOS version
FGT1 # show system interface port2
config system interface
    edit "port2"
        set vdom "root"
        set ip 10.0.1.1 255.255.255.0
        set allowaccess ping https ssh
        set type physical
        set role lan
        set snmp-index 2
    next
end
show prints configuration in the same form you would type it, so it can be copied to another FortiGate. Only non-default settings appear; add full-configuration to see all.
Example output · based on Fortinet documentation; exact format varies by model and FortiOS version
FGT1 # get system interface physical port2
== [onboard]
        ==[port2]
                mode: static
                ip: 10.0.1.1 255.255.255.0
                ipv6: ::/0
                status: up
                speed: 1000Mbps (Duplex: full)
                ...
get adds live status: link up or down, speed, duplex. (Example output, trimmed.)
show firewall policy | grep -f port2

grep filters long output. -f prints the whole configuration block that contains the match, so every policy that uses port2 appears complete. -i ignores case.

Help while typing

  • ? lists what can come next; Tab completes a word and cycles through options.
  • Inside a table, get shows the current entry's settings and show its configuration.
  • tree (inside a table) prints every field the table supports.

Why it works this way

The configuration is a database of tables and entries, and the CLI edits it directly: set writes a field's whole value, which is why lists are replaced. Saving on next and end means a reboot doesn't lose applied work, but also that a mistake is saved the moment you leave the entry, so check before typing end, or use abort.

Common mistakes

  • Using set to add a member to a list and wiping the rest. Use append.
  • Mistyping a name after edit and creating a new, empty object.
  • Pasting configuration that uses names (addresses, interfaces) that don't exist on the target FortiGate.

Key takeaways

✅ Key takeaways
  • config opens a table, edit opens an entry, set/unset change it, next and end save.
  • abort leaves without saving; there is no separate startup configuration to copy.
  • set replaces a list; append adds and unselect removes one value.
  • show = configuration (non-default), get = values and status, execute = actions, diagnose = troubleshooting.

Check yourself

Predict · scenario 1

An address group contains SRV1 and SRV2. Which command adds SRV3 and keeps the others?

Predict · scenario 2

You made several wrong changes inside config firewall policy and haven't typed next or end. How do you leave without saving them?

Predict · scenario 3

Which command shows whether port2's link is up and at what speed?

FAQ

Is there a 'copy running-config startup-config' on FortiOS?
No. By default FortiOS writes each change to flash when you leave the entry (next) or the table (end). There is no separate running and startup configuration to keep in step.
How do I see every setting, including defaults?
show lists only what differs from the defaults. show full-configuration lists everything, and get shows the current values of a table, including state information for some objects.