Courseiva

Identify Matching Firewall Policy: CLI Commands for Traffic Lookup

A FortiGate admin is troubleshooting an issue where internal users cannot access a specific external service over TCP/443. The admin confirms that the firewall policy allows HTTP/HTTPS. Which TWO CLI commands should the admin use to diagnose? (Choose two.)

⚠ Common exam trap

Candidates often choose 'diagnose sys session filter dport 443' thinking it directly shows sessions, but they forget that it only sets a filter and requires an additional command to display results, making it incomplete for immediate diagnosis.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

diagnose firewall iprope list

'diagnose firewall iprope list' displays the kernel's internal firewall rule chains, allowing the admin to verify whether the policy lookup is matching the expected rule for TCP/443 traffic. This command helps confirm that the policy is installed and active in the kernel, which is essential for troubleshooting policy-based access issues.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    diagnose firewall iprope list

    Why this is correct

    The 'diagnose firewall iprope list' command displays the compiled IPv4/IPv6 policy chains exactly as the kernel traverses them during packet evaluation. It is invaluable for verifying the relative ordering of allow and deny policies in the actual dataplane, because a policy buried below a broad deny rule will never be reached. This tool exposes both the explicit policies and the implicit deny at the end, letting you confirm whether a matching allow rule exists before any drop rule in the sequence.

  • ✓

    diagnose debug flow

    Why this is correct

    The 'diagnose debug flow' command (often combined with 'diagnose debug enable') enables a real-time, packet-level trace that shows session setup, the exact firewall policy ID matched, and the resulting action such as accept or drop. It walks you through the kernel's decision tree for each packet, including why it was dropped by a specific deny rule or by the implicit deny. This is the definitive way to see which rule actually stored the packet, rather than just inspecting static policy lists.

  • ✗

    diagnose sys session filter dport 443

    Why it's wrong here

    The 'diagnose sys session filter dport 443' command sets a filter on the session table to display active sessions that have destination port 443, but it does not reveal which firewall policy allowed those sessions or why any other packet was dropped. It is a session inspection tool, not a packet-tracing or policy-evaluation diagnostic. While it shows existing connections, it cannot expose the ordering or matching logic of the firewall rules.

  • ✗

    get system performance status

    Why it's wrong here

    The 'get system performance status' command reports overall system health metrics such as CPU, memory, and interface link states. These indicators are unrelated to firewall policy behavior, so they cannot tell you whether an allow rule precedes a deny rule or whether a specific packet was dropped. This command is meant for capacity planning and hardware health, not for debugging rule matching or traffic permitting issues.

  • ✗

    execute ping 8.8.8.8

    Why it's wrong here

    The 'execute ping 8.8.8.8' command checks basic IP connectivity and routing to an external host, but it does not inspect firewall policy matching at all. A successful ping may occur even when the firewall policy is misordered for other protocols, and a failed ping only indicates ICMP unreachability, not the reason for a policy drop. This tool operates at Layer 3 reachability and cannot reveal whether an allow policy exists before a deny policy in the FortiGate's rule set.

About these practice questions

This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.