Palo Alto Networks CLI Cheat Sheet

Ad – Purchase on Amazon

Ad – Purchase on Amazon

Last updated on February 16th, 2023 at 05:22 pm

Palo Alto Networks (PAN) firewalls are known for their Graphical User Interface (GUI) for management. There are times when the CLI (command line interface) is still used, as some commands are used for troubleshooting and restarting processes.

Since PAN-OS version 9.1, PAN has added GUI troubleshooting and testing, available at Device>Troubleshooting. This feature has improved over time with new versions of the OS. In the GUI, not every test is available yet as of the date of this article. Also, restarting processes is not available in the GUI but is in the CLI.

Some commands in this cheat sheet are available in the GUI, for example, ping. I included it in the cheat sheet as this command, and some others, are sometimes used in conjunction with other CLI commands.

User-ID

At the time of this article, a lot of User-ID (IP mapping) testing and process management is done via the CLI. The reason User-ID occupies a large part of this cheat sheet. Hopefully, this will be available in the GUI in future PAN-OS releases.

CLI Modes

It’s important to note the CLI mode when working in the CLI and using this cheat sheet. The CLI has two modes, “operational” and “configuration.” Operational is indicated when the command prompt is a >. This is the default mode when connecting to the console port or using SSH. Configuration is indicated when the command prompt is a #. Configuration mode is entered when entering the command configure when in operational mode.

Here is an example of operational mode.

Here is an example of configuration mode.

Download the Cheat Sheet

Click the link below to download the Palo Alto Networks CLI Cheat Sheet, or right-click on the link and select “Save Link As.”


References:

CLI Display Format:

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClHoCAK

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClUHCA0

Using the Find Command:

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClrECAS

View Config Changes:

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClEaCAK

IPSec VPN Tunnel Commands:

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClVGCA0

Management Interface Packet Capture:

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CleECAS

User-ID/IP Mappings:

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CluWCAS

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClR1CAK

PAN-OS v9.1 CLI Cheat Sheets

https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-cli-quick-start/cli-cheat-sheets

CLI Changes in PAN-OS 9.1

https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-cli-quick-start/cli-changes

PAN-OS v10.1 CLI Cheat Sheets

https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-cli-quick-start/cli-cheat-sheets

CLI Changes in PAN-OS 10.1

https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-cli-quick-start/cli-changes

PAN-OS v10.2 CLI Cheat Sheets

https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-cli-quick-start/cli-cheat-sheets

CLI Changes in PAN-OS 10.2

https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-cli-quick-start/cli-changes

Copyright © Packet Passers 2024