๐งฑ FortiGate ็ถฒ่ทฏ่จบๆทๅ จๆป็ฅ:ๆๅฏฆ็จ็ CLI ไป้ข、่ทฏ็ฑ่ๅฐๅ ๆๅๆไปคๆๅญธ
ๆด็็พๅ ดๆๅธธ็จ็ FortiGate ่จบๆทๆไปค:ไป้ข、่ทฏ็ฑ、ๆ่ฉฑ、็ญ็ฅๅน้ 、ๅฐๅ ๆๅ่ๆต้่ทฏๅพๅๆ,ๅฟซ้ๅฎไฝ「ๅช่ฃกไธ้、็บไฝไธ้」。
ไธ、ไป้ข่ Link ็ๆ
get system interface
diagnose netlink interface list
get hardware nic <port>
ไบ、่ทฏ็ฑ่ๅฏ้ๆง
get router info routing-table all
execute traceroute 8.8.8.8
diagnose ip route list
get router info bgp summary
ไธ、็ญ็ฅๅน้ ่ๆ่ฉฑ
diagnose sys session list
diagnose sys session filter <cond>
diagnose debug flow filter add <cond>
diagnose debug flow show console enable
diagnose debug flow trace start 200
diagnose debug enable
ๅ、ๅฐๅ ๆๅ(ๅ งๅปบ sniffer)
diagnose sniffer packet any 'host 1.1.1.1' 4 100
diagnose sniffer packet port1 'icmp' 3 0 a
# ๅๆญข:Ctrl + C
ไบ、ๅธธ่ฆๆ้ๆ ๅข
- ็ญ็ฅๆชๅฝไธญ → ๆชขๆฅ
debug flow;็ขบ่ช src/dst/port。 - ๅ็จไธ้ → ๆชขๆฅ่ทฏ็ฑ่ๅฐ็ซฏ SNAT。
- VPN ๆท็บ → ็ IKE/DPD ่ๅฐ็ซฏ็ธๅฎนๆง、ๆ้ๅๆญฅ。
๐ ็ต่ช
็จ「ไป้ข→่ทฏ็ฑ→็ญ็ฅ→ๆ่ฉฑ→ๆๅ 」ไบๆญฅ้ฉ,ๅปบ็ซๅฏ่ค่ฃฝ็ๆ้ๆต็จ;ๆ CLI ๅฎๅๅไฝ่ฎๆฅๅธธ。
๐ ๅปถไผธ้ฑ่ฎ
- FortiGate ๅธธ็จ CLI ๆไปคๆธ ๅฎ
- FortiGate ็ญ็ฅ่็ฉไปถ็ฎก็ๅฏฆๅ
- Proxmox VE ็ถฒ่ทฏ / VLAN / Bridge(ๅปถไผธ็ถฒ็ฎก)
— WWFandy・ไธป้ก็ญ่จ
ๆฒๆ็่จ:
ๅผต่ฒผ็่จ