An administrator wants to view real-time debug output for traffic flowing through a FortiGate. Which command should they use to enable flow tracing with a specific source IP filter?
The 'diagnose debug flow filter src' command sets a source IP address filter that restricts the real-time flow debugging output to traffic originating from that specific host. This is the correct first step when you want to trace a particular user's or device's session flow through the FortiGate, because it prevents the console from being flooded with all traffic and makes the output meaningful. After setting this source filter, you must also run 'diagnose debug flow show console enable' and then 'diagnose debug enable' to see the live flow trace messages on the CLI.
Why this answer
The command 'diagnose debug flow filter src <IP>' sets a filter to capture debug flow output for a specific source IP. This is the correct first step to enable flow tracing with a source IP filter. After setting the filter, the administrator would run 'diagnose debug enable' to start the debug output.
The filter command itself is necessary to narrow down the traffic.
Exam trap
The trap is confusing session filters with debug flow filters; candidates might choose 'diagnose sys session filter src' thinking it filters debug output, but it only filters the session table.
How to eliminate wrong answers
Option A is wrong because 'diagnose debug enable' only enables debug output but does not set a filter; without a filter, the output would be overwhelming. Option C is wrong because 'diagnose sys session filter src' filters the session table, not debug flow output. Option D is wrong because 'diagnose sniffer packet filter src' is not a valid command; the sniffer uses different syntax and is for packet capture, not debug flow.