Skip to content
Home » Fortigate Troubleshooting

Fortigate Troubleshooting

FORTIGATE / FREE PATH

Troubleshoot the failure. Prove the recovery.

Diagnose real FortiGate incidents by reading the network state, identifying the failure, applying the correct change, and validating the result.

This is the engineering problem. This is how a real engineer investigates it. This is how KiwiTut lets you practise it.

Request Access The simulator is private. Access is controlled and issued by request.

FREE PATH / FORTIGATE FOCUS / PREPARES FOR KIWITUT PRO

FGT-HQ / OPERATOR SESSIONLIVE STATE

READ THE CLI.
UNDERSTAND THE STATE.
MAKE THE CHANGE.

Diagnose the failure.
Fix the network.
Prove the recovery.
Business impact → evidence → recovery → validation
KIWITUT PRO / INCIDENT BRIEFREAL INTERFACE
KiwiTut Pro incident briefing view for a fresh mission showing priority, customer, and business impact
Incident brief — the starting state of an active mission.
KIWITUT PRO / INCIDENT COMPLETEREAL INTERFACE
KiwiTut Pro dashboard in the completed incident state showing recovery evidence
Completed incident — the recovery state and debrief.
01

Incident diagnosis

Start with business impact, define the expected path, and separate the symptom from the failure domain.

02

CLI investigation

Use FortiGate operational commands to inspect state, test a hypothesis, and gather evidence before changing configuration.

03

Routing and connectivity

Trace interfaces, routes, next hops, and return paths so forwarding behavior can be explained.

04

Firewall policy and NAT

Read policy matching, address objects, services, translation, and session behavior as one traffic decision.

05

VPN state

Separate tunnel, Phase 1, Phase 2, selector, and route state when protected traffic is unavailable.

06

Evidence-based recovery

Apply the smallest safe change, then prove that the original service recovered. This public path prepares operators for KiwiTut Pro; it is not the live simulator.

07

Symptom playbook

Work top-down: state the symptom, name the suspect layer, run the check, prove the fix.

Tunnel down

Suspect: Peer reachability / Phase 1
Check: diagnose vpn ike gateway list, then diagnose vpn tunnel list
Prove it: Gateway established, tunnel up

No route to destination

Suspect: Missing or withdrawn route
Check: get router info routing-table all + specific lookup
Prove it: Expected prefix present

Wrong exit path

Suspect: SD-WAN rule or member health
Check: diagnose sys sdwan member + load-balance
Prove it: Selected member matches intent

Drops with tunnel up

Suspect: Policy / selector mismatch
Check: show firewall policy, show vpn ipsec phase2, show firewall central-snat-map
Prove it: Matching policy + aligned selectors

08

Prove the fix

  • Original symptom reproduced once before changing anything
  • Single controlled change applied
  • Service restored end to end (execute ping / execute traceroute)
  • Change captured (execute backup config flash change-before)
  • Root cause stated in one sentence
Decision recordEvery validated fix becomes reusable engineering knowledge – that habit is the product.

Related engineering paths: VPN tunnel diagnostics, SD-WAN path control, and the CLI command reference. Or browse the full FortiGate paths catalogue.

FORTIGATE LAB? THE MODEL MATTERS

Train inside KiwiTut Pro.

These public paths describe the engineering work. The real hands-on FortiGate network operations simulator is private beta at app.kiwitut.com and is available only after controlled access is approved.

ENGINEERING

KiwiTut Engineering develops practical FortiGate-focused enterprise network engineering simulation. Request Access