A real-life situation
An administrator wants to add port4 to a zone that already contains port2 and port3. They type set interface port4, press Enter, and the zone now contains only port4: two networks lose their policies at once. Nothing was wrong with FortiOS. The CLI did exactly what set does. A few rules explain this and most other CLI surprises.
The four verbs at the top
| Verb | Does | Example |
|---|---|---|
config | Opens a table to change it | config system interface |
show / get | Reads configuration / reads values and status | show firewall policy 1 |
execute | Runs an action | execute ping 10.0.1.10 |
diagnose | Troubleshooting and debugging | diagnose sys session list |
Changing configuration: config, edit, set, next, end
config system interface
edit port3
set ip 10.0.2.1 255.255.255.0
set allowaccess ping
set role dmz
next
endconfig opens the interface table, edit port3 opens that entry, set changes fields, next saves port3 and stays in the table (to edit another interface), end saves and leaves.
editcreates the entry if it doesn't exist, so a typo creates a new object. For numbered tables,edit 0creates one with the next free number.unsetreturns a field to its default.abortleaves the table without saving the changes in it, a lifesaver after a mistake.- Inside a table:
delete,rename A to B,clone A to Bandmove 5 before 2manage entries.
Lists: set replaces, append adds
config system zone
edit LAN-ZONE
set interface port2 port3
append interface port4
unselect interface port3
next
endLine by line: set makes the list exactly port2 port3; append adds port4 (port2 port3 port4); unselect removes port3 (port2 port4). Fields that hold several values (interfaces, addresses, services) are replaced completely by set.
Reading configuration: show and get
FGT1 # show system interface port2 config system interface edit "port2" set vdom "root" set ip 10.0.1.1 255.255.255.0 set allowaccess ping https ssh set type physical set role lan set snmp-index 2 next end
full-configuration to see all.FGT1 # get system interface physical port2 == [onboard] ==[port2] mode: static ip: 10.0.1.1 255.255.255.0 ipv6: ::/0 status: up speed: 1000Mbps (Duplex: full) ...
show firewall policy | grep -f port2grep filters long output. -f prints the whole configuration block that contains the match, so every policy that uses port2 appears complete. -i ignores case.
Help while typing
?lists what can come next; Tab completes a word and cycles through options.- Inside a table,
getshows the current entry's settings andshowits configuration. tree(inside a table) prints every field the table supports.
Why it works this way
The configuration is a database of tables and entries, and the CLI edits it directly: set writes a field's whole value, which is why lists are replaced. Saving on next and end means a reboot doesn't lose applied work, but also that a mistake is saved the moment you leave the entry, so check before typing end, or use abort.
Common mistakes
- Using
setto add a member to a list and wiping the rest. Useappend. - Mistyping a name after
editand creating a new, empty object. - Pasting configuration that uses names (addresses, interfaces) that don't exist on the target FortiGate.
Key takeaways
- config opens a table, edit opens an entry, set/unset change it, next and end save.
- abort leaves without saving; there is no separate startup configuration to copy.
- set replaces a list; append adds and unselect removes one value.
- show = configuration (non-default), get = values and status, execute = actions, diagnose = troubleshooting.
Check yourself
An address group contains SRV1 and SRV2. Which command adds SRV3 and keeps the others?
You made several wrong changes inside config firewall policy and haven't typed next or end. How do you leave without saving them?
Which command shows whether port2's link is up and at what speed?