Friday, October 17, 2025

CLI-

 




CLI Basics
> show system infoShow general system health information
> show system disk-space filesShow percent usage of disk partitions
> show system software statusShow running processes
> show system resourcesShow processes running in the management plane
> show running resource-monitorShow resource utilization in the dataplane
> request license infoShow the licenses installed on the device
> request restart systemRestart the device
> request shutdown systemShutdown the device
> show adminsShow the logged in administrators
> show admins allShow all administrators, regardless of whether they are logged in
> set cli config-output-format <default | json | set | xml>(Web GUI, CLI or API) Change the output format
> find command keyword <keyword>Show list of commands that contain the specified keywor
Jobs
> show jobs pendingshow pending jobs
> show jobs processedShow finished jobs
> show jobs id <number>Show info about specific job
Commit
> check pending changesCheck for uncommitted changes to the candidate configuration
> commitCommit entire configuration
> commit partial ?Commit part of the configuration
> show system last-commit-infoShow last commit information
Troubleshooting
> show session infoShow session information
> show session id <session-id>Show information about a specific session
> show session allShow all active sessions
> show log trafficShow traffic log
> less mp-log authd.logShow the authentication logs
> tftp export tech-support to <tftp host>Export tech support file via TFTP
> scp export tech-support to <username@host:path>Export tech support file via SCP
Important files and folders
/var/log/pan/dp-monitor.logData plane information
/var/log/pan/mp-monitor.logManagement plane information
/opt/pancfg/mgmt/saved-configs/Running configuration
/usr/local/bin/remove- private info.shScript to remove private information from log files
/var/cores/crashinfoBacktraces files for service crahses
Packet capture
> debug dataplane packet-diag show settingShow configured capture settings
> debug dataplane packet-diag clear allDelete existing filters
> debug dataplane packet-diag clear log logDelete existing log files
> debug dataplane packet-diag set filter ?Set filters
> debug dataplane packet-diag set filter enableEnable filters
> debug dataplane packet-diag set capture ?Configure capture
> debug dataplane packet-diag set capture onEnable capture
> show counter global filter delta yes packet-filter yesVerify if packets have been captured
> debug dataplane packet-diag set capture offStop capture
Network tools
> ping host <ip-address>Ping from the management interface
> ping source <ip-address-on-dp> host <destination-ip>Ping from a dataplane interface
> traceroute <interface> <ip-address>Traceroute
> dig <interface> <server address> <hostname>DNS query
> show netstat statistics yesShow network statistics
User-ID
> show user user-id-agent state allShow all configured Windows-based agents
> show user server-monitor state allVerify if the PAN-OS-integrated agent is configured
> show user server-monitor statisticsShow user-ID mapping statistics
> show user user-id-agent config name <agent-name>Show User-ID agent configuration
> show user group-mapping statisticsShow group mapping statistics
> show user group-mapping state allShow all group mappings
> show user group listShow list of user groups
> show user group name group-name>Show group members of specified group
> show user ip-user-mapping allShow all user mappings
> show user ip-user-mapping all | match <domain>\\<username>Show filtered user mapping
> show user ip-user-mapping ip <ip-address>Show user mapping for specific IP address
> show log userid datasourcename equal <agent name> direction equal backward
Show most recent addresses learned from a particular User-ID agent
> show log userid datasourcetype equal ?Show mappings from a particular type of authentication service
> clear user-cache allClear the User-ID cache
> clear user-cache ip <ip-address>Clear the User-ID mapping for a specific IP address
> debug user-id refresh user-id ip <IP-Address> agent <User-ID Agent>Refresh the User-ID mapping for a specific IP address
> debug user-id refresh group mapping allRefresh the user-group mappin
High Availability
> show high-availability cluster allShow all HA cluster configuration content
> show high-availability cluster flap-statisticsShow HA cluster flap statistics
> show high-availability cluster session-synchronization
Show information about the synchronized messages to or from an HA cluster
> show high-availability cluster stateShow HA cluster state and configuration information
> show high-availability cluster statisticsShow HA cluster statistics
> clear high-availability cluster statisticsClear HA cluster statistics
> request high-availability cluster clear-cacheClear session cache
> request high-availability cluster sync-fromRequest full session cache synchronization
URL Filtering
> show url-cloud statusShow the URL cloud status
> show log url direction equal backwardDisplay the URL log, most recent entries first
> clear url-cache allClear whole URL cache
> clear url-cache url <value>Clear specific entry from URL cache
> test url <url or IP>Test the categorization of a URL
> test url-info-cloud <url>Test the categorization of a URL in the cloud
Routing
> show routing routeShow the routing table
> show routing fib virtual-router <name> | match <x.x.x.x/Y>Show routes for a specific destination
NAT
> show running nat-policyShow the NAT policy table
> test nat-policy-matchTest NAT-policy-match
> show running ippoolShow NAT pool utilization
> show running global-ippoolShow NAT pool utilization
IPSec
> show vpn flowShow IPSec counters
>show vpn gatewayShow list of IKE gateway configurations
> show vpn ike-saShow IKE phase 1 SAs
> show vpn ipsec-saShow IKE phase 2 SAs
> clear vpn ike-sa gateway <gateway-name>Clear specific IKE phase 1 SA
> clear vpn ipsec-sa tunnel <tunnel-name>Clear specific IKE phase 2 SAs
> show vpn tunnelShow list of auto-key IPSec tunnel configurations
> test vpn ike-sa gateway <gateway-name>Initiate Phase 1 for a specific gateway
> test vpn ipsec-sa tunnel <tunnel-name>InInitiate Phase 2 for a specific tunnel
> debug ike pcap [on | off]Activate or deactivate packet capture for all IKE traffic
> view-pcap follow yes debugDisplay and follow the packet capture

No comments:

Post a Comment

Global Protect Troubleshooting

Global Protect Components Certificate Management Connections Authentication Debugging https://www.youtube.com/watch?v=0Z48WHvyW0Q authentica...