FortiSwitch CLI
FortiSwitch CLI Cheat Sheet
FortiGate-managed and FortiSwitch CLI commands organized from your supplied FortiSwitch command list.
MAC address table
dia switch-controller switch-info mac-table
Change MAC aging (Default 5mins)
Config switch-controller global set mac-aging-interval <seconds> End
Port status
Exec switch-controller get-conn-status <switch ID>
FGT Config switching ports
Under > Config switch-controller managed-switch > config ports
Transceivers
Dia switch-controller switch-info models <summary | detail> <switch ID> <port>
PoE Power Budget
Dia switch-controller switch-info poe summary <switch ID>
PoE Reset
Exec switch-controller switch-action poe reset <switch ID> <port>
LACP Configuration
config switch-controller managed-switch
LACP Display Configuration
diag switch-controller switch-info trunk config <switch ID>
LACP Display Status
execute switch-controller get-conn-status <switch-id> dia switch-controller switch-info trunk status <switch-id> <trunk>
LACP Change load balancing methods
Config switch-controller managed-switch edit <switchid) config ports edit <trunnk> set port-selection-criteria <method> next
STP Status
diag stp instance list
Reboot FSW (Managed)
Exec switch-controller switch-action restart
LED Flash (Managed)
diagnose switch physical-ports led-flash <disable | time>
LLDP Display
Dia switch-controller switch-info lldp neighbor-summary <switch-id> Dia switch-controller switch-info lldp neighbor-detail <switch-id> <port>
LLDP Neighbors
get switch lldp neighbors-detail
CDP Config
LLDP must be enabled.
Via the FortiSwitch OS CLI …
Config switch physical-port edit <port> set cap-status <…> next
CDP Display Neighbor Details
Dia switch-controller switch-info lldp neighbor-detail
Enable FSW Controller
Enabled by default on most FGT models.
Must be enabled on VM models
Config system global set switch-controller enable End
Authorize FSW
Config switch-controller managed-switch edit <switch-id> set fsw-wan1-admin enable next
FSW status
Execute switch-controller get-conn-status
FSW Logs
Global Setting
Config switch-controller switch-log set status enable set severity information End
Per FSW
Config switch-controller managed-switch edit <switch-id> config switch-log set local-override enable set severity <> End
FSW Upgrade via FGT CLI
# execute switch-controller switch-software upload ftp | tftp <image name> <ip> username password
List images on FGT
# execute switch-controller switch-software list-available
FSW MAC address
Get systems status | grep burn
FSW STP Status
Diag switch-controller switch-info stp <switch-id> <instance>
NAC - Show Matching Devices
Diag switch-controller nac-device nac known
Show available software on FS
Execute switch-controller switch-software list-available
Cancel Upgrade
execute switch-controller switch-software cancel {all | sn <FortiSwitchserialnumber> | switch-group <switchgroupID>}
execute switch-controller switch-software cancel sn S248EPTF180018XXUpgrade via CLI
Execute switch-controller switch-software upload tftp FSW108F….-FORTINET.out 10.20.10.16
Staged Upgrade
Execute switch-controller switch-software stage switch-group test FSW-108F-v7.4-build946-IMG.swtp
Grep MAC address on a FortiSwitch
dia switch mac list | grep e4\:f0:42:53:02
Delete MAC Table
dia switch mac-address delete all
CPU Status
get system performance status dia sys top
Live Utilization
Dia switch physical-port literate up
Port (SFP)Information
Set switch module status
TAC Report
Dia de report
Troubleshooting
fnsysctl top