Paloalto firewall useful commands

  1. > show system info – Show general system health information such as IP Address, Serial #, sw-version.

2. >show running security-policy – Show the running security policy.

3. > request restart system – Restart the device.

4. > show admins – Show the administrators who are currently logged in to the web interface, CLI, or API.

5. >show admins all –

Show the administrators who can access the web interface, CLI, or API, regardless of whether those administrators are currently logged in.

When you run this command on the firewall, the output includes both local administrators and those pushed from a Panorama template.

6.  >show routing route – Display the routing table

7. >show running nat-policy – Show the NAT policy table

8. > show vpn flow – Show IPSec counters

9. >show vpn gateway – Show a list of all IPSec gateways and their configurations

10. >show vpn tunnel – Show a list of auto-key IPSec tunnel configurations

11. >ping host <destination-ip-address> – Ping from the management (MGT) interface to a destination IP address

12. >show config running – display configuration

13. Show users

For example

show user group name cn=vpn,cn=users,dc=chicagotech,dc=net

short name:  chicagotech\vpn

source type: ldap

source:      Chicagotech-Groups

[1     ] chicagotech\blin

[2     ] chicagotech\msmith

[3     ] payroll\sgarcia

[4     ] payroll\test1

Published by

Bob Lin

Bob Lin, Chicagotech-MVP, MCSE & CNE Data recovery, Windows OS Recovery, Networking, and Computer Troubleshooting on http://www.ChicagoTech.net How to Install and Configure Windows, VMware, Virtualization and Cisco on http://www.HowToNetworking.com