Last updated on February 16th, 2023 at 05:22 pm
Palo Alto Networks (PAN) firewalls are known for their Graphical User Interface (GUI) for management. There are times when the CLI (command line interface) is still used, as some commands are used for troubleshooting and restarting processes.
Since PAN-OS version 9.1, PAN has added GUI troubleshooting and testing, available at Device>Troubleshooting. This feature has improved over time with new versions of the OS. In the GUI, not every test is available yet as of the date of this article. Also, restarting processes is not available in the GUI but is in the CLI.
Some commands in this cheat sheet are available in the GUI, for example, ping. I included it in the cheat sheet as this command, and some others, are sometimes used in conjunction with other CLI commands.
User-ID
At the time of this article, a lot of User-ID (IP mapping) testing and process management is done via the CLI. The reason User-ID occupies a large part of this cheat sheet. Hopefully, this will be available in the GUI in future PAN-OS releases.
CLI Modes
It’s important to note the CLI mode when working in the CLI and using this cheat sheet. The CLI has two modes, “operational” and “configuration.” Operational is indicated when the command prompt is a >. This is the default mode when connecting to the console port or using SSH. Configuration is indicated when the command prompt is a #. Configuration mode is entered when entering the command configure when in operational mode.
Here is an example of operational mode.
Here is an example of configuration mode.
Download the Cheat Sheet
Click the link below to download the Palo Alto Networks CLI Cheat Sheet, or right-click on the link and select “Save Link As.”
References:
CLI Display Format:
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClHoCAK
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClUHCA0
Using the Find Command:
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClrECAS
View Config Changes:
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClEaCAK
IPSec VPN Tunnel Commands:
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClVGCA0
Management Interface Packet Capture:
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CleECAS
User-ID/IP Mappings:
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CluWCAS
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClR1CAK
PAN-OS v9.1 CLI Cheat Sheets
https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-cli-quick-start/cli-cheat-sheets
CLI Changes in PAN-OS 9.1
https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-cli-quick-start/cli-changes
PAN-OS v10.1 CLI Cheat Sheets
https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-cli-quick-start/cli-cheat-sheets
CLI Changes in PAN-OS 10.1
https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-cli-quick-start/cli-changes
PAN-OS v10.2 CLI Cheat Sheets
https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-cli-quick-start/cli-cheat-sheets
CLI Changes in PAN-OS 10.2
https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-cli-quick-start/cli-changes
Copyright © Packet Passers 2024