Uploaded by John Yan Lin Aung

PALO-ALTO-CLI-CHEATSHEET

advertisement
PALO ALTO – CLI CHEATSHEET
Below is list of commands generally used in Palo Alto Networks:
COMMAND
DESCRIPTION
> show jobs processed
DESCRIPTION
USER ID COMMANDS
DEVICE MANAGEMENT COMMANDS
> show routing route
> show routing fib virtual-router
<name> | match <x.x.x.x/Y>
> show system disk-space
>show system info
> request -restart system
> less mp-log authd.log
>show running security-policy
> show system logdb-quota
> show system software status
> show system resources
> show session info
> show session id <session-id>
> show running resource-monitor
> request license info
COMMAND
Display the routing table
Look at routes for a specific destination
Displays percent usage of disk partitions
Displays general system-health information
Restart the device
Displays the authentication logs
Displays the running security policy
Displays the maximum log file size
Displays running processes
Displays processes running in the management plane
Displays session information
Displays information about a specific session
Displays resource utilization in the dataplane
Displays the licenses installed on the device
Displays when commits, downloads, and/or upgrades are
completed
IPSEC COMMANDS
> show vpn tunnel
> show vpn flow
> show vpn ipsec-sa
Displays a list of auto-key IPSec tunnel configurations
Displays IPSec counters
Displays IKE phase 2 SAs
> show vpn ike-sa
Displays IKE phase 1 SAs
> show vpn gateway
Displays a list of all IPSec gateways and their configurations
> show user server-monitor state all
> show user user-id-agent state all
> show user user-id-agent config
name
> show user server-monitor
statistics
> show user user-id-agent config
name
> show user ip-user-mapping ip
> show user user-ids
> clear user-cache ip
> clear user-cache all
To see the configuration status of PAN-OS-integrated agent
To see all configured Windows-based agents
To view the configuration of a User-ID agent from the Palo
Alto Networks device
To view how many log messages came in from syslog
senders and how many entries the User-ID agent
successfully mapped
To view the configuration of a User-ID agent from the Palo
Alto Networks device
To display user mappings for a specific IP address
To dsplay usernames
To clear a User-ID mapping for a specific IP address
To clear the User-ID cache
NAT COMMANDS
> test nat-policy-match
> show running nat-policy
> show running ippool
> show running global-ippool
Test the NAT policy
Displays the NAT policy table
Displays NAT pool utilization
TROUBLESHOOTING COMMANDS
> show netstat statistics yes
> ping source host
> ping host
networkinterview.com(An Initiative By ipwithease.com)
Displays network statistics
Ping from a data plane interface to a destination IP address
Ping from the management (MGT) interface to a
destination IP address
Download