Fortinet black logo

CLI Reference

config system settings

config system settings

Configure VDOM settings.

config system settings
    Description: Configure VDOM settings.
    set comments {var-string}
    set opmode [nat|transparent]
    set manageip {user}
    set gateway {ipv4-address}
    set ip {ipv4-classnet-host}
    set manageip6 {ipv6-prefix}
    set gateway6 {ipv6-address}
    set ip6 {ipv6-prefix}
    set device {string}
    set wccp-cache-engine [enable|disable]
    set wccp-local-route [enable|disable]
    config gui-default-policy-columns
        Description: Default columns to display for policy lists on GUI.
        edit <name>
        next
    end
    set gui-icap [enable|disable]
    set gui-implicit-policy [enable|disable]
    set gui-dns-database [enable|disable]
    set gui-object-colors [enable|disable]
    set gui-replacement-message-groups [enable|disable]
    set gui-dynamic-profile-display [enable|disable]
    set gui-local-reports [enable|disable]
    set gui-wanopt-cache [enable|disable]
    set gui-explicit-proxy [enable|disable]
    set gui-dlp [enable|disable]
    set gui-dnsfilter [enable|disable]
    set gui-sslvpn-personal-bookmarks [enable|disable]
    set gui-sslvpn-realms [enable|disable]
    set gui-policy-based-ipsec [enable|disable]
    set gui-vpn [enable|disable]
    set gui-multiple-utm-profiles [enable|disable]
    set gui-spamfilter [enable|disable]
    set gui-application-control [enable|disable]
    set gui-ips [enable|disable]
    set gui-dhcp-advanced [enable|disable]
    set gui-webfilter-advanced [enable|disable]
    set gui-traffic-shaping [enable|disable]
    set gui-antivirus [enable|disable]
    set gui-webfilter [enable|disable]
    set gui-advanced-policy [enable|disable]
    set gui-allow-unnamed-policy [enable|disable]
    set gui-multiple-interface-policy [enable|disable]
    set allow-subnet-overlap [enable|disable]
end

config system settings

Parameter

Description

Type

Size

comments

VDOM comments.

var-string

Maximum length: 255

opmode

Firewall operation mode (NAT or Transparent).

option

-

Option

Description

nat

Change to NAT mode.

transparent

Change to transparent mode.

manageip

Transparent mode IPv4 management IP address and netmask.

user

Not Specified

gateway

Transparent mode IPv4 default gateway IP address.

ipv4-address

Not Specified

ip

IP address and netmask.

ipv4-classnet-host

Not Specified

manageip6

Transparent mode IPv6 management IP address and netmask.

ipv6-prefix

Not Specified

gateway6

Transparent mode IPv4 default gateway IP address.

ipv6-address

Not Specified

ip6

IPv6 address prefix for NAT mode.

ipv6-prefix

Not Specified

device

Interface to use for management access for NAT mode.

string

Maximum length: 35

wccp-cache-engine

Enable/disable WCCP cache engine.

option

-

Option

Description

enable

Enable WCCP cache engine.

disable

Disable WCCP cache engine.

wccp-local-route

Enable/disable WCCP to use local route.

option

-

Option

Description

enable

Enable WCCP to use local route.

disable

Disable WCCP to use local route.

gui-icap

Enable/disable ICAP on the GUI.

option

-

Option

Description

enable

Enable ICAP on the GUI.

disable

Disable ICAP on the GUI.

gui-implicit-policy

Enable/disable implicit firewall policies on the GUI.

option

-

Option

Description

enable

Enable implicit firewall policies on the GUI.

disable

Disable implicit firewall policies on the GUI.

gui-dns-database

Enable/disable DNS database settings on the GUI.

option

-

Option

Description

enable

Enable DNS database settings on the GUI.

disable

Disable DNS database settings on the GUI.

gui-object-colors

Enable/disable object colors on the GUI.

option

-

Option

Description

enable

Enable object colors on the GUI.

disable

Disable object colors on the GUI.

gui-replacement-message-groups

Enable/disable replacement message groups on the GUI.

option

-

Option

Description

enable

Enable replacement message groups on the GUI.

disable

Disable replacement message groups on the GUI.

gui-dynamic-profile-display

Enable/disable RADIUS Single Sign On (RSSO) on the GUI.

option

-

Option

Description

enable

Enable RADIUS Single Sign On (RSSO) on the GUI.

disable

Disable RADIUS Single Sign On (RSSO) on the GUI.

gui-local-reports

Enable/disable local reports on the GUI.

option

-

Option

Description

enable

Enable local reports on the GUI.

disable

Disable local reports on the GUI.

gui-wanopt-cache

Enable/disable WAN Optimization and Web Caching on the GUI.

option

-

Option

Description

enable

Enable WAN Optimization and Web Caching on the GUI.

disable

Disable WAN Optimization and Web Caching on the GUI.

gui-explicit-proxy

Enable/disable the explicit proxy on the GUI.

option

-

Option

Description

enable

Enable the explicit proxy on the GUI.

disable

Disable the explicit proxy on the GUI.

gui-dlp

Enable/disable DLP on the GUI.

option

-

Option

Description

enable

Enable DLP on the GUI.

disable

Disable DLP on the GUI.

gui-dnsfilter

Enable/disable DNS Filtering on the GUI.

option

-

Option

Description

enable

Enable DNS Filtering on the GUI.

disable

Disable DNS Filtering on the GUI.

gui-sslvpn-personal-bookmarks

Enable/disable SSL-VPN personal bookmark management on the GUI.

option

-

Option

Description

enable

Enable SSL-VPN personal bookmark management on the GUI.

disable

Disable SSL-VPN personal bookmark management on the GUI.

gui-sslvpn-realms

Enable/disable SSL-VPN realms on the GUI.

option

-

Option

Description

enable

Enable SSL-VPN realms on the GUI.

disable

Disable SSL-VPN realms on the GUI.

gui-policy-based-ipsec

Enable/disable policy-based IPsec VPN on the GUI.

option

-

Option

Description

enable

Enable policy-based IPsec VPN on the GUI.

disable

Disable policy-based IPsec VPN on the GUI.

gui-vpn

Enable/disable VPN tunnels on the GUI.

option

-

Option

Description

enable

Enable VPN tunnels on the GUI.

disable

Disable VPN tunnels on the GUI.

gui-multiple-utm-profiles

Enable/disable multiple UTM profiles on the GUI.

option

-

Option

Description

enable

Enable multiple UTM profiles on the GUI.

disable

Disable multiple UTM profiles on the GUI.

gui-spamfilter

Enable/disable Antispam on the GUI.

option

-

Option

Description

enable

Enable Antispam on the GUI.

disable

Disable Antispam on the GUI.

gui-application-control

Enable/disable application control on the GUI.

option

-

Option

Description

enable

Enable application control on the GUI.

disable

Disable application control on the GUI.

gui-ips

Enable/disable IPS on the GUI.

option

-

Option

Description

enable

Enable IPS on the GUI.

disable

Disable IPS on the GUI.

gui-dhcp-advanced

Enable/disable advanced DHCP options on the GUI.

option

-

Option

Description

enable

Enable advanced DHCP options on the GUI.

disable

Disable advanced DHCP options on the GUI.

gui-webfilter-advanced

Enable/disable advanced web filtering on the GUI.

option

-

Option

Description

enable

Enable advanced web filtering on the GUI.

disable

Disable advanced web filtering on the GUI.

gui-traffic-shaping

Enable/disable traffic shaping on the GUI.

option

-

Option

Description

enable

Enable traffic shaping on the GUI.

disable

Disable traffic shaping on the GUI.

gui-antivirus

Enable/disable AntiVirus on the GUI.

option

-

Option

Description

enable

Enable AntiVirus on the GUI.

disable

Disable AntiVirus on the GUI.

gui-webfilter

Enable/disable Web filtering on the GUI.

option

-

Option

Description

enable

Enable Web filtering on the GUI.

disable

Disable Web filtering on the GUI.

gui-advanced-policy

Enable/disable advanced policy configuration on the GUI.

option

-

Option

Description

enable

Enable advanced policy configuration on the GUI.

disable

Disable advanced policy configuration on the GUI.

gui-allow-unnamed-policy

Enable/disable the requirement for policy naming on the GUI.

option

-

Option

Description

enable

Enable the requirement for policy naming on the GUI.

disable

Disable the requirement for policy naming on the GUI.

gui-multiple-interface-policy

Enable/disable adding multiple interfaces to a policy on the GUI.

option

-

Option

Description

enable

Enable adding multiple interfaces to a policy on the GUI.

disable

Disable adding multiple interfaces to a policy on the GUI.

allow-subnet-overlap

Enable/disable allowing interface subnets to use overlapping IP addresses.

option

-

Option

Description

enable

Enable overlapping subnets.

disable

Disable overlapping subnets.

config gui-default-policy-columns

Parameter

Description

Type

Size

name

Select column name.

string

Maximum length: 64

config system settings

Configure VDOM settings.

config system settings
    Description: Configure VDOM settings.
    set comments {var-string}
    set opmode [nat|transparent]
    set manageip {user}
    set gateway {ipv4-address}
    set ip {ipv4-classnet-host}
    set manageip6 {ipv6-prefix}
    set gateway6 {ipv6-address}
    set ip6 {ipv6-prefix}
    set device {string}
    set wccp-cache-engine [enable|disable]
    set wccp-local-route [enable|disable]
    config gui-default-policy-columns
        Description: Default columns to display for policy lists on GUI.
        edit <name>
        next
    end
    set gui-icap [enable|disable]
    set gui-implicit-policy [enable|disable]
    set gui-dns-database [enable|disable]
    set gui-object-colors [enable|disable]
    set gui-replacement-message-groups [enable|disable]
    set gui-dynamic-profile-display [enable|disable]
    set gui-local-reports [enable|disable]
    set gui-wanopt-cache [enable|disable]
    set gui-explicit-proxy [enable|disable]
    set gui-dlp [enable|disable]
    set gui-dnsfilter [enable|disable]
    set gui-sslvpn-personal-bookmarks [enable|disable]
    set gui-sslvpn-realms [enable|disable]
    set gui-policy-based-ipsec [enable|disable]
    set gui-vpn [enable|disable]
    set gui-multiple-utm-profiles [enable|disable]
    set gui-spamfilter [enable|disable]
    set gui-application-control [enable|disable]
    set gui-ips [enable|disable]
    set gui-dhcp-advanced [enable|disable]
    set gui-webfilter-advanced [enable|disable]
    set gui-traffic-shaping [enable|disable]
    set gui-antivirus [enable|disable]
    set gui-webfilter [enable|disable]
    set gui-advanced-policy [enable|disable]
    set gui-allow-unnamed-policy [enable|disable]
    set gui-multiple-interface-policy [enable|disable]
    set allow-subnet-overlap [enable|disable]
end

config system settings

Parameter

Description

Type

Size

comments

VDOM comments.

var-string

Maximum length: 255

opmode

Firewall operation mode (NAT or Transparent).

option

-

Option

Description

nat

Change to NAT mode.

transparent

Change to transparent mode.

manageip

Transparent mode IPv4 management IP address and netmask.

user

Not Specified

gateway

Transparent mode IPv4 default gateway IP address.

ipv4-address

Not Specified

ip

IP address and netmask.

ipv4-classnet-host

Not Specified

manageip6

Transparent mode IPv6 management IP address and netmask.

ipv6-prefix

Not Specified

gateway6

Transparent mode IPv4 default gateway IP address.

ipv6-address

Not Specified

ip6

IPv6 address prefix for NAT mode.

ipv6-prefix

Not Specified

device

Interface to use for management access for NAT mode.

string

Maximum length: 35

wccp-cache-engine

Enable/disable WCCP cache engine.

option

-

Option

Description

enable

Enable WCCP cache engine.

disable

Disable WCCP cache engine.

wccp-local-route

Enable/disable WCCP to use local route.

option

-

Option

Description

enable

Enable WCCP to use local route.

disable

Disable WCCP to use local route.

gui-icap

Enable/disable ICAP on the GUI.

option

-

Option

Description

enable

Enable ICAP on the GUI.

disable

Disable ICAP on the GUI.

gui-implicit-policy

Enable/disable implicit firewall policies on the GUI.

option

-

Option

Description

enable

Enable implicit firewall policies on the GUI.

disable

Disable implicit firewall policies on the GUI.

gui-dns-database

Enable/disable DNS database settings on the GUI.

option

-

Option

Description

enable

Enable DNS database settings on the GUI.

disable

Disable DNS database settings on the GUI.

gui-object-colors

Enable/disable object colors on the GUI.

option

-

Option

Description

enable

Enable object colors on the GUI.

disable

Disable object colors on the GUI.

gui-replacement-message-groups

Enable/disable replacement message groups on the GUI.

option

-

Option

Description

enable

Enable replacement message groups on the GUI.

disable

Disable replacement message groups on the GUI.

gui-dynamic-profile-display

Enable/disable RADIUS Single Sign On (RSSO) on the GUI.

option

-

Option

Description

enable

Enable RADIUS Single Sign On (RSSO) on the GUI.

disable

Disable RADIUS Single Sign On (RSSO) on the GUI.

gui-local-reports

Enable/disable local reports on the GUI.

option

-

Option

Description

enable

Enable local reports on the GUI.

disable

Disable local reports on the GUI.

gui-wanopt-cache

Enable/disable WAN Optimization and Web Caching on the GUI.

option

-

Option

Description

enable

Enable WAN Optimization and Web Caching on the GUI.

disable

Disable WAN Optimization and Web Caching on the GUI.

gui-explicit-proxy

Enable/disable the explicit proxy on the GUI.

option

-

Option

Description

enable

Enable the explicit proxy on the GUI.

disable

Disable the explicit proxy on the GUI.

gui-dlp

Enable/disable DLP on the GUI.

option

-

Option

Description

enable

Enable DLP on the GUI.

disable

Disable DLP on the GUI.

gui-dnsfilter

Enable/disable DNS Filtering on the GUI.

option

-

Option

Description

enable

Enable DNS Filtering on the GUI.

disable

Disable DNS Filtering on the GUI.

gui-sslvpn-personal-bookmarks

Enable/disable SSL-VPN personal bookmark management on the GUI.

option

-

Option

Description

enable

Enable SSL-VPN personal bookmark management on the GUI.

disable

Disable SSL-VPN personal bookmark management on the GUI.

gui-sslvpn-realms

Enable/disable SSL-VPN realms on the GUI.

option

-

Option

Description

enable

Enable SSL-VPN realms on the GUI.

disable

Disable SSL-VPN realms on the GUI.

gui-policy-based-ipsec

Enable/disable policy-based IPsec VPN on the GUI.

option

-

Option

Description

enable

Enable policy-based IPsec VPN on the GUI.

disable

Disable policy-based IPsec VPN on the GUI.

gui-vpn

Enable/disable VPN tunnels on the GUI.

option

-

Option

Description

enable

Enable VPN tunnels on the GUI.

disable

Disable VPN tunnels on the GUI.

gui-multiple-utm-profiles

Enable/disable multiple UTM profiles on the GUI.

option

-

Option

Description

enable

Enable multiple UTM profiles on the GUI.

disable

Disable multiple UTM profiles on the GUI.

gui-spamfilter

Enable/disable Antispam on the GUI.

option

-

Option

Description

enable

Enable Antispam on the GUI.

disable

Disable Antispam on the GUI.

gui-application-control

Enable/disable application control on the GUI.

option

-

Option

Description

enable

Enable application control on the GUI.

disable

Disable application control on the GUI.

gui-ips

Enable/disable IPS on the GUI.

option

-

Option

Description

enable

Enable IPS on the GUI.

disable

Disable IPS on the GUI.

gui-dhcp-advanced

Enable/disable advanced DHCP options on the GUI.

option

-

Option

Description

enable

Enable advanced DHCP options on the GUI.

disable

Disable advanced DHCP options on the GUI.

gui-webfilter-advanced

Enable/disable advanced web filtering on the GUI.

option

-

Option

Description

enable

Enable advanced web filtering on the GUI.

disable

Disable advanced web filtering on the GUI.

gui-traffic-shaping

Enable/disable traffic shaping on the GUI.

option

-

Option

Description

enable

Enable traffic shaping on the GUI.

disable

Disable traffic shaping on the GUI.

gui-antivirus

Enable/disable AntiVirus on the GUI.

option

-

Option

Description

enable

Enable AntiVirus on the GUI.

disable

Disable AntiVirus on the GUI.

gui-webfilter

Enable/disable Web filtering on the GUI.

option

-

Option

Description

enable

Enable Web filtering on the GUI.

disable

Disable Web filtering on the GUI.

gui-advanced-policy

Enable/disable advanced policy configuration on the GUI.

option

-

Option

Description

enable

Enable advanced policy configuration on the GUI.

disable

Disable advanced policy configuration on the GUI.

gui-allow-unnamed-policy

Enable/disable the requirement for policy naming on the GUI.

option

-

Option

Description

enable

Enable the requirement for policy naming on the GUI.

disable

Disable the requirement for policy naming on the GUI.

gui-multiple-interface-policy

Enable/disable adding multiple interfaces to a policy on the GUI.

option

-

Option

Description

enable

Enable adding multiple interfaces to a policy on the GUI.

disable

Disable adding multiple interfaces to a policy on the GUI.

allow-subnet-overlap

Enable/disable allowing interface subnets to use overlapping IP addresses.

option

-

Option

Description

enable

Enable overlapping subnets.

disable

Disable overlapping subnets.

config gui-default-policy-columns

Parameter

Description

Type

Size

name

Select column name.

string

Maximum length: 64