Infiltrate Manipulate Disrupt
FortiSwitch CLI

FortiSwitch CLI Cheat Sheet

FortiGate-managed and FortiSwitch CLI commands organized from your supplied FortiSwitch command list.

Back to FortiSwitch CLI

MAC address table

dia switch-controller switch-info mac-table

Change MAC aging (Default 5mins)

Config switch-controller global
set mac-aging-interval <seconds>
End

Port status

Exec switch-controller get-conn-status <switch ID>

FGT Config switching ports

Under > Config switch-controller managed-switch > config ports

Transceivers

Dia switch-controller switch-info models <summary | detail> <switch ID> <port>

PoE Power Budget

Dia switch-controller switch-info poe summary <switch ID>

PoE Reset

Exec switch-controller switch-action poe reset <switch ID> <port>

LACP Configuration

config switch-controller managed-switch

LACP Display Configuration

diag switch-controller switch-info trunk config <switch ID>

LACP Display Status

execute switch-controller get-conn-status <switch-id>
dia switch-controller switch-info trunk status <switch-id> <trunk>

LACP Change load balancing methods

Config switch-controller managed-switch
edit <switchid)
config ports
edit <trunnk>
set port-selection-criteria <method>
next

STP Status

diag stp instance list

Reboot FSW (Managed)

Exec switch-controller switch-action restart

LED Flash (Managed)

diagnose switch physical-ports led-flash <disable | time>

LLDP Display

Dia switch-controller switch-info lldp neighbor-summary <switch-id>
Dia switch-controller switch-info lldp neighbor-detail <switch-id> <port>

LLDP Neighbors

get switch lldp neighbors-detail

CDP Config

LLDP must be enabled.

Via the FortiSwitch OS CLI …

Config switch physical-port
edit <port>
set cap-status <…>
next

CDP Display Neighbor Details

Dia switch-controller switch-info lldp neighbor-detail

Enable FSW Controller

Enabled by default on most FGT models.

Must be enabled on VM models

Config system global
set switch-controller enable
End

Authorize FSW

Config switch-controller managed-switch
edit <switch-id>
set fsw-wan1-admin enable
next

FSW status

Execute switch-controller get-conn-status

FSW Logs

Global Setting

Config switch-controller switch-log
set status enable
set severity information
End

Per FSW

Config switch-controller managed-switch
edit <switch-id>
config switch-log
set local-override enable
set severity <>
End

FSW Upgrade via FGT CLI

# execute switch-controller switch-software upload ftp | tftp <image name> <ip> username password

List images on FGT

# execute switch-controller switch-software list-available

FSW MAC address

Get systems status | grep burn

FSW STP Status

Diag switch-controller switch-info stp <switch-id> <instance>

NAC - Show Matching Devices

Diag switch-controller nac-device nac known

Show available software on FS

Execute switch-controller switch-software list-available

Cancel Upgrade

execute switch-controller switch-software cancel {all | sn <FortiSwitchserialnumber> | switch-group <switchgroupID>}
execute switch-controller switch-software cancel sn S248EPTF180018XX

Upgrade via CLI

Execute switch-controller switch-software upload tftp FSW108F….-FORTINET.out 10.20.10.16

Staged Upgrade

Execute switch-controller switch-software stage switch-group test FSW-108F-v7.4-build946-IMG.swtp

Grep MAC address on a FortiSwitch

dia switch mac list | grep e4\:f0:42:53:02

Delete MAC Table

dia switch mac-address delete all

CPU Status

get system performance status
dia sys top

Live Utilization

Dia switch physical-port literate up

Port (SFP)Information

Set switch module status

TAC Report

Dia de report

Troubleshooting

fnsysctl top