Pan Os 81 Cli Commands
Pan Os 81 Cli Commands
Pan Os 81 Cli Commands
1 Configure Commands
check pending-changes
check full-commit-required
save config to <value> partial shared-object <excluded> device-and-network <excluded> admin [ <admin1> <admin2>...
]
save config to <value> partial shared-object <excluded> device-and-network <excluded> vsys [ <vsys1> <vsys2>... ]
save device-state
revert config partial shared-object <excluded> device-and-network <excluded> admin [ <admin1> <admin2>... ]
revert config partial shared-object <excluded> device-and-network <excluded> vsys [ <vsys1> <vsys2>... ]
load config key <value>|<default> partial from <value> from-xpath <value> to-xpath <value> mode
<merge|replace|append>
load device-state
commit description <value> force partial device-and-network <excluded> shared-object <excluded> admin [ <admin1>
<admin2>... ]
commit description <value> force partial device-and-network <excluded> shared-object <excluded> no-vsys
commit description <value> force partial device-and-network <excluded> shared-object <excluded> vsys [ <vsys1>
<vsys2>... ]
excluded> no-vsys
validate full
<admin1> <admin2>... ]
<vsys1> <vsys2>... ]
show deviceconfig
etric-key
etric-key algorithm
key
ne
mmetric-key algorithm
tokey
<name>
w <name>
hourly
daily
weekly
on
show deviceconfig setting logging enhanced-application-logging disable-applicati
on <name>
n-syn-tcp
t-traffic
p-report
-integrity
-integrity
olicy-limits
-limits
ses-alarm-threshold
on
on sync
me>
me> ip
me> ip <name>
me> ip <name>
me> ipv6
tion
tion
tion primary-device
tion first-packet
virtual-wire
virtual-wire <name>
vlan
vlan <name>
virtual-router
virtual-router <name>
<name>
show mgt-config
show network
ame>
<name>
<name>
show network interface ethernet <name> layer3 ipv6 address <name> prefix
show network interface ethernet <name> layer3 ipv6 address <name> anycast
show network interface ethernet <name> layer3 ipv6 address <name> advertise
ertisement dns-support
show network interface ethernet <name> layer3 ipv6 neighbor-discovery neighbor <
name>
show network interface ethernet <name> layer3 units <name> ipv6 address
show network interface ethernet <name> layer3 units <name> ipv6 address <name>
show network interface ethernet <name> layer3 units <name> ipv6 address <name> p
refix
show network interface ethernet <name> layer3 units <name> ipv6 address <name> a
nycast
show network interface ethernet <name> layer3 units <name> ipv6 address <name> a
dvertise
show network interface ethernet <name> layer3 units <name> ipv6 neighbor-discove
ry
show network interface ethernet <name> layer3 units <name> ipv6 neighbor-discove
ry router-advertisement
show network interface ethernet <name> layer3 units <name> ipv6 neighbor-discove
ry router-advertisement dns-support
show network interface ethernet <name> layer3 units <name> ipv6 neighbor-discove
show network interface ethernet <name> layer3 units <name> ipv6 neighbor-discove
show network interface ethernet <name> layer3 units <name> ipv6 neighbor-discove
show network interface ethernet <name> layer3 units <name> ipv6 neighbor-discove
show network interface ethernet <name> layer3 units <name> ipv6 neighbor-discove
ry neighbor
show network interface ethernet <name> layer3 units <name> ipv6 neighbor-discove
ry neighbor <name>
show network interface ethernet <name> layer3 units <name> arp <name>
show network interface ethernet <name> layer3 units <name> ndp-proxy address
show network interface ethernet <name> layer3 units <name> ndp-proxy address <na
me>
lity
se-same-system-mac
show network interface aggregate-ethernet <name> layer3 ipv6 address <name> pref
ix
show network interface aggregate-ethernet <name> layer3 ipv6 address <name> anyc
ast
show network interface aggregate-ethernet <name> layer3 ipv6 address <name> adve
rtise
router-advertisement
router-advertisement dns-support
neighbor
neighbor <name>
se-same-system-mac
mss
show network interface aggregate-ethernet <name> layer3 units <name> ipv6 addres
show network interface aggregate-ethernet <name> layer3 units <name> ipv6 addres
s <name>
show network interface aggregate-ethernet <name> layer3 units <name> ipv6 addres
s <name> prefix
show network interface aggregate-ethernet <name> layer3 units <name> ipv6 addres
s <name> anycast
show network interface aggregate-ethernet <name> layer3 units <name> ipv6 addres
s <name> advertise
show network interface aggregate-ethernet <name> layer3 units <name> ipv6 neighb
or-discovery
show network interface aggregate-ethernet <name> layer3 units <name> ipv6 neighb
or-discovery router-advertisement
show network interface aggregate-ethernet <name> layer3 units <name> ipv6 neighb
show network interface aggregate-ethernet <name> layer3 units <name> ipv6 neighb
show network interface aggregate-ethernet <name> layer3 units <name> ipv6 neighb
show network interface aggregate-ethernet <name> layer3 units <name> ipv6 neighb
show network interface aggregate-ethernet <name> layer3 units <name> ipv6 neighb
or-discovery neighbor
show network interface aggregate-ethernet <name> layer3 units <name> ipv6 neighb
show network interface aggregate-ethernet <name> layer3 units <name> arp <name>
ddress
ddress <name>
port
port server
show network interface vlan units <name> ipv6 address <name> prefix
show network interface vlan units <name> ipv6 address <name> anycast
show network interface vlan units <name> ipv6 address <name> advertise
ement
ement dns-support
show network interface vlan units <name> ipv6 neighbor-discovery neighbor <name>
show network interface loopback units <name> ipv6 address <name> prefix
show network interface loopback units <name> ipv6 address <name> anycast
show network interface tunnel units <name> ipv6 address <name> prefix
show network interface tunnel units <name> ipv6 address <name> anycast
h-and-url
show network tunnel ipsec <name> auto-key proxy-id <name> protocol any
show network tunnel ipsec <name> auto-key proxy-id <name> protocol tcp
show network tunnel ipsec <name> auto-key proxy-id <name> protocol udp
show network tunnel ipsec <name> auto-key proxy-id-v6 <name> protocol any
show network tunnel ipsec <name> auto-key proxy-id-v6 <name> protocol tcp
show network tunnel ipsec <name> auto-key proxy-id-v6 <name> protocol udp
-ip
es
show network qos interface <name> tunnel-traffic groups <name> members <name>
show network qos interface <name> regular-traffic groups <name> members <name>
show network qos interface <name> regular-traffic groups <name> members <name> m
atch
show network qos interface <name> regular-traffic groups <name> members <name> m
atch local-address
discard
ble
ble
ble unicast
ble multicast
ble both
ble no-install
itor
itor monitor-destinations
p discard
table
table
table unicast
table no-install
onitor
onitor monitor-destinations
sion
sion any-source-multicast
sion source-specific-multicast
neighbors
neighbors <name>
st
pfv3
-redist
dist
show network virtual-router <name> protocol rip auth-profile <name> md5 <name>
isable
dvertise
show network virtual-router <name> protocol ospf auth-profile <name> md5 <name>
show network virtual-router <name> protocol ospf area <name> type normal
show network virtual-router <name> protocol ospf area <name> type stub
show network virtual-router <name> protocol ospf area <name> type stub default-r
oute
show network virtual-router <name> protocol ospf area <name> type stub default-r
oute disable
show network virtual-router <name> protocol ospf area <name> type stub default-r
oute advertise
show network virtual-router <name> protocol ospf area <name> type nssa
show network virtual-router <name> protocol ospf area <name> type nssa default-r
oute
show network virtual-router <name> protocol ospf area <name> type nssa default-r
oute disable
show network virtual-router <name> protocol ospf area <name> type nssa default-r
oute advertise
show network virtual-router <name> protocol ospf area <name> type nssa nssa-ext-
range
show network virtual-router <name> protocol ospf area <name> type nssa nssa-ext-
range <name>
show network virtual-router <name> protocol ospf area <name> type nssa nssa-ext-
range <name>
show network virtual-router <name> protocol ospf area <name> type nssa nssa-ext-
show network virtual-router <name> protocol ospf area <name> type nssa nssa-ext-
range <name> suppress
show network virtual-router <name> protocol ospf area <name> range <name>
show network virtual-router <name> protocol ospf area <name> range <name>
show network virtual-router <name> protocol ospf area <name> range <name> advert
ise
show network virtual-router <name> protocol ospf area <name> range <name> suppre
ss
show network virtual-router <name> protocol ospf area <name> interface <name>
show network virtual-router <name> protocol ospf area <name> interface <name> li
nk-type
show network virtual-router <name> protocol ospf area <name> interface <name> li
nk-type broadcast
show network virtual-router <name> protocol ospf area <name> interface <name> li
nk-type p2p
show network virtual-router <name> protocol ospf area <name> interface <name> li
nk-type p2mp
show network virtual-router <name> protocol ospf area <name> interface <name> ne
ighbor
show network virtual-router <name> protocol ospf area <name> interface <name> ne
ighbor <name>
show network virtual-router <name> protocol ospf area <name> interface <name> bf
show network virtual-router <name> protocol ospf area <name> virtual-link <name>
show network virtual-router <name> protocol ospf area <name> virtual-link <name>
bfd
show network virtual-router <name> protocol ospfv3 auth-profile <name> esp authe
ntication
show network virtual-router <name> protocol ospfv3 auth-profile <name> esp authe
ntication
show network virtual-router <name> protocol ospfv3 auth-profile <name> esp authe
ntication md5
show network virtual-router <name> protocol ospfv3 auth-profile <name> esp authe
ntication sha1
show network virtual-router <name> protocol ospfv3 auth-profile <name> esp authe
ntication sha256
show network virtual-router <name> protocol ospfv3 auth-profile <name> esp authe
ntication sha384
show network virtual-router <name> protocol ospfv3 auth-profile <name> esp authe
ntication sha512
show network virtual-router <name> protocol ospfv3 auth-profile <name> esp authe
ntication none
show network virtual-router <name> protocol ospfv3 auth-profile <name> esp encry
ption
show network virtual-router <name> protocol ospfv3 area <name> type normal
show network virtual-router <name> protocol ospfv3 area <name> type stub
show network virtual-router <name> protocol ospfv3 area <name> type stub default
-route
show network virtual-router <name> protocol ospfv3 area <name> type stub default
-route disable
show network virtual-router <name> protocol ospfv3 area <name> type stub default
-route advertise
show network virtual-router <name> protocol ospfv3 area <name> type nssa
show network virtual-router <name> protocol ospfv3 area <name> type nssa default
-route
show network virtual-router <name> protocol ospfv3 area <name> type nssa default
-route disable
show network virtual-router <name> protocol ospfv3 area <name> type nssa default
-route advertise
show network virtual-router <name> protocol ospfv3 area <name> type nssa nssa-ex
t-range
show network virtual-router <name> protocol ospfv3 area <name> type nssa nssa-ex
t-range <name>
show network virtual-router <name> protocol ospfv3 area <name> type nssa nssa-ex
t-range <name>
show network virtual-router <name> protocol ospfv3 area <name> type nssa nssa-ex
show network virtual-router <name> protocol ospfv3 area <name> type nssa nssa-ex
show network virtual-router <name> protocol ospfv3 area <name> range <name>
show network virtual-router <name> protocol ospfv3 area <name> range <name> adve
rtise
show network virtual-router <name> protocol ospfv3 area <name> range <name> supp
ress
show network virtual-router <name> protocol ospfv3 area <name> interface <name>
show network virtual-router <name> protocol ospfv3 area <name> interface <name>
link-type
show network virtual-router <name> protocol ospfv3 area <name> interface <name>
link-type broadcast
show network virtual-router <name> protocol ospfv3 area <name> interface <name>
link-type p2p
show network virtual-router <name> protocol ospfv3 area <name> interface <name>
link-type p2mp
show network virtual-router <name> protocol ospfv3 area <name> interface <name>
neighbor
show network virtual-router <name> protocol ospfv3 area <name> interface <name>
neighbor <name>
show network virtual-router <name> protocol ospfv3 area <name> interface <name>
bfd
show network virtual-router <name> protocol ospfv3 area <name> virtual-link <nam
e>
show network virtual-router <name> protocol ospfv3 area <name> virtual-link <nam
e> bfd
show network virtual-router <name> protocol bgp peer-group <name> type ibgp
show network virtual-router <name> protocol bgp peer-group <name> type ebgp-conf
ed
show network virtual-router <name> protocol bgp peer-group <name> type ibgp-conf
ed
show network virtual-router <name> protocol bgp peer-group <name> type ebgp
show network virtual-router <name> protocol bgp peer-group <name> peer <name>
show network virtual-router <name> protocol bgp peer-group <name> peer <name> su
bsequent-address-family-identifier
show network virtual-router <name> protocol bgp peer-group <name> peer <name> lo
cal-address
show network virtual-router <name> protocol bgp peer-group <name> peer <name> pe
er-address
show network virtual-router <name> protocol bgp peer-group <name> peer <name> co
nnection-options
show network virtual-router <name> protocol bgp peer-group <name> peer <name> co
nnection-options incoming-bgp-connection
show network virtual-router <name> protocol bgp peer-group <name> peer <name> co
nnection-options outgoing-bgp-connection
show network virtual-router <name> protocol bgp peer-group <name> peer <name> bf
show network virtual-router <name> protocol bgp policy import rules <name>
show network virtual-router <name> protocol bgp policy import rules <name> match
show network virtual-router <name> protocol bgp policy import rules <name> match
address-prefix
show network virtual-router <name> protocol bgp policy import rules <name> match
address-prefix <name>
show network virtual-router <name> protocol bgp policy import rules <name> match
as-path
show network virtual-router <name> protocol bgp policy import rules <name> match
as-path
show network virtual-router <name> protocol bgp policy import rules <name> match
community
show network virtual-router <name> protocol bgp policy import rules <name> match
community
show network virtual-router <name> protocol bgp policy import rules <name> match
extended-community
show network virtual-router <name> protocol bgp policy import rules <name> match
extended-community
show network virtual-router <name> protocol bgp policy import rules <name> actio
show network virtual-router <name> protocol bgp policy import rules <name> actio
show network virtual-router <name> protocol bgp policy import rules <name> actio
n deny
show network virtual-router <name> protocol bgp policy import rules <name> actio
n allow
show network virtual-router <name> protocol bgp policy import rules <name> actio
n allow update
show network virtual-router <name> protocol bgp policy import rules <name> actio
show network virtual-router <name> protocol bgp policy import rules <name> actio
show network virtual-router <name> protocol bgp policy import rules <name> actio
show network virtual-router <name> protocol bgp policy import rules <name> actio
show network virtual-router <name> protocol bgp policy import rules <name> actio
show network virtual-router <name> protocol bgp policy import rules <name> actio
show network virtual-router <name> protocol bgp policy import rules <name> actio
show network virtual-router <name> protocol bgp policy import rules <name> actio
show network virtual-router <name> protocol bgp policy import rules <name> actio
show network virtual-router <name> protocol bgp policy import rules <name> actio
show network virtual-router <name> protocol bgp policy import rules <name> actio
show network virtual-router <name> protocol bgp policy import rules <name> actio
show network virtual-router <name> protocol bgp policy export rules <name>
show network virtual-router <name> protocol bgp policy export rules <name> match
show network virtual-router <name> protocol bgp policy export rules <name> match
address-prefix
show network virtual-router <name> protocol bgp policy export rules <name> match
address-prefix <name>
show network virtual-router <name> protocol bgp policy export rules <name> match
as-path
show network virtual-router <name> protocol bgp policy export rules <name> match
as-path
show network virtual-router <name> protocol bgp policy export rules <name> match
community
show network virtual-router <name> protocol bgp policy export rules <name> match
community
show network virtual-router <name> protocol bgp policy export rules <name> match
extended-community
show network virtual-router <name> protocol bgp policy export rules <name> match
extended-community
show network virtual-router <name> protocol bgp policy export rules <name> actio
show network virtual-router <name> protocol bgp policy export rules <name> actio
show network virtual-router <name> protocol bgp policy export rules <name> actio
n deny
show network virtual-router <name> protocol bgp policy export rules <name> actio
n allow
show network virtual-router <name> protocol bgp policy export rules <name> actio
n allow update
show network virtual-router <name> protocol bgp policy export rules <name> actio
show network virtual-router <name> protocol bgp policy export rules <name> actio
show network virtual-router <name> protocol bgp policy export rules <name> actio
show network virtual-router <name> protocol bgp policy export rules <name> actio
n allow update as-path remove
show network virtual-router <name> protocol bgp policy export rules <name> actio
show network virtual-router <name> protocol bgp policy export rules <name> actio
show network virtual-router <name> protocol bgp policy export rules <name> actio
show network virtual-router <name> protocol bgp policy export rules <name> actio
show network virtual-router <name> protocol bgp policy export rules <name> actio
show network virtual-router <name> protocol bgp policy export rules <name> actio
show network virtual-router <name> protocol bgp policy export rules <name> actio
show network virtual-router <name> protocol bgp policy export rules <name> actio
policy
policy <name>
show network virtual-router <name> protocol bgp policy aggregation address <name
>
show network virtual-router <name> protocol bgp policy aggregation address <name
> aggregate-route-attributes
show network virtual-router <name> protocol bgp policy aggregation address <name
show network virtual-router <name> protocol bgp policy aggregation address <name
show network virtual-router <name> protocol bgp policy aggregation address <name
show network virtual-router <name> protocol bgp policy aggregation address <name
show network virtual-router <name> protocol bgp policy aggregation address <name
show network virtual-router <name> protocol bgp policy aggregation address <name
show network virtual-router <name> protocol bgp policy aggregation address <name
show network virtual-router <name> protocol bgp policy aggregation address <name
show network virtual-router <name> protocol bgp policy aggregation address <name
show network virtual-router <name> protocol bgp policy aggregation address <name
show network virtual-router <name> protocol bgp policy aggregation address <name
show network virtual-router <name> protocol bgp policy aggregation address <name
> suppress-filters
show network virtual-router <name> protocol bgp policy aggregation address <name
show network virtual-router <name> protocol bgp policy aggregation address <name
show network virtual-router <name> protocol bgp policy aggregation address <name
show network virtual-router <name> protocol bgp policy aggregation address <name
show network virtual-router <name> protocol bgp policy aggregation address <name
show network virtual-router <name> protocol bgp policy aggregation address <name
show network virtual-router <name> protocol bgp policy aggregation address <name
show network virtual-router <name> protocol bgp policy aggregation address <name
show network virtual-router <name> protocol bgp policy aggregation address <name
show network virtual-router <name> protocol bgp policy aggregation address <name
show network virtual-router <name> protocol bgp policy aggregation address <name
> advertise-filters
show network virtual-router <name> protocol bgp policy aggregation address <name
show network virtual-router <name> protocol bgp policy aggregation address <name
show network virtual-router <name> protocol bgp policy aggregation address <name
show network virtual-router <name> protocol bgp policy aggregation address <name
show network virtual-router <name> protocol bgp policy aggregation address <name
> advertise-filters <name> match as-path
show network virtual-router <name> protocol bgp policy aggregation address <name
show network virtual-router <name> protocol bgp policy aggregation address <name
show network virtual-router <name> protocol bgp policy aggregation address <name
show network virtual-router <name> protocol bgp policy aggregation address <name
show network virtual-router <name> protocol bgp policy aggregation address <name
<name>
show network shared-gateway <name> service <name> protocol tcp override yes
show network shared-gateway <name> service <name> protocol udp override yes
show network shared-gateway <name> log-settings snmptrap <name> version v2c serv
er
show network shared-gateway <name> log-settings snmptrap <name> version v2c serv
er <name>
r <name>
show network shared-gateway <name> log-settings http <name> format config header
show network shared-gateway <name> log-settings http <name> format config header
s <name>
show network shared-gateway <name> log-settings http <name> format config params
show network shared-gateway <name> log-settings http <name> format config params
<name>
show network shared-gateway <name> log-settings http <name> format system header
show network shared-gateway <name> log-settings http <name> format system header
s <name>
show network shared-gateway <name> log-settings http <name> format system params
show network shared-gateway <name> log-settings http <name> format system params
<name>
show network shared-gateway <name> log-settings http <name> format traffic heade
rs
show network shared-gateway <name> log-settings http <name> format traffic heade
rs <name>
show network shared-gateway <name> log-settings http <name> format traffic param
show network shared-gateway <name> log-settings http <name> format traffic param
s <name>
show network shared-gateway <name> log-settings http <name> format threat header
show network shared-gateway <name> log-settings http <name> format threat header
s <name>
show network shared-gateway <name> log-settings http <name> format threat params
show network shared-gateway <name> log-settings http <name> format threat params
<name>
show network shared-gateway <name> log-settings http <name> format wildfire
show network shared-gateway <name> log-settings http <name> format wildfire head
ers
show network shared-gateway <name> log-settings http <name> format wildfire head
ers <name>
show network shared-gateway <name> log-settings http <name> format wildfire para
ms
show network shared-gateway <name> log-settings http <name> format wildfire para
ms <name>
show network shared-gateway <name> log-settings http <name> format url headers
show network shared-gateway <name> log-settings http <name> format url headers <
name>
show network shared-gateway <name> log-settings http <name> format url params
show network shared-gateway <name> log-settings http <name> format url params <n
ame>
show network shared-gateway <name> log-settings http <name> format data headers
show network shared-gateway <name> log-settings http <name> format data headers
<name>
show network shared-gateway <name> log-settings http <name> format data params
show network shared-gateway <name> log-settings http <name> format data params <
name>
show network shared-gateway <name> log-settings http <name> format tunnel header
show network shared-gateway <name> log-settings http <name> format tunnel header
s <name>
show network shared-gateway <name> log-settings http <name> format tunnel params
show network shared-gateway <name> log-settings http <name> format tunnel params
<name>
show network shared-gateway <name> log-settings http <name> format auth
show network shared-gateway <name> log-settings http <name> format auth headers
show network shared-gateway <name> log-settings http <name> format auth headers
<name>
show network shared-gateway <name> log-settings http <name> format auth params
show network shared-gateway <name> log-settings http <name> format auth params <
name>
show network shared-gateway <name> log-settings http <name> format userid header
show network shared-gateway <name> log-settings http <name> format userid header
s <name>
show network shared-gateway <name> log-settings http <name> format userid params
show network shared-gateway <name> log-settings http <name> format userid params
<name>
show network shared-gateway <name> log-settings http <name> format hip-match hea
ders
show network shared-gateway <name> log-settings http <name> format hip-match hea
ders <name>
show network shared-gateway <name> log-settings http <name> format hip-match par
ams
show network shared-gateway <name> log-settings http <name> format hip-match par
ams <name>
eaders
eaders <name>
arams
show network shared-gateway <name> log-settings http <name> format correlation p
arams <name>
>
> actions
dynamic-ip-and-port
dynamic-ip-and-port interface-address
dynamic-ip-and-port interface-address
dynamic-ip
dynamic-ip fallback
dynamic-ip fallback
static-ip
tion
-translation
show network shared-gateway <name> rulebase pbf rules <name> action forward
show network shared-gateway <name> rulebase pbf rules <name> action forward next
hop
show network shared-gateway <name> rulebase pbf rules <name> action forward moni
tor
show network shared-gateway <name> rulebase pbf rules <name> action discard
show network shared-gateway <name> rulebase pbf rules <name> action no-pbf
eturn
eturn nexthop-address-list
show shared
n <name>
n <name> operator
show shared profiles hip-objects <name> network-info criteria network is-not wif
show shared profiles hip-objects <name> network-info criteria network is-not mob
ile
show shared profiles hip-objects <name> network-info criteria network is-not eth
ernet
show shared profiles hip-objects <name> network-info criteria network is-not unk
nown
s severity
s severity
hin
-within
thin
t-within
-available
hin
-within
t-available
thin
ions
ions <name>
e>
e>
e> registry-value
show shared profiles hip-objects <name> custom-checks criteria plist <name> key
show shared profiles hip-objects <name> custom-checks criteria plist <name> key
<name>
within
not-within
malware
malware no
malware yes
udes
show shared profiles spyware <name> botnet-domains lists <name> action alert
show shared profiles spyware <name> botnet-domains lists <name> action allow
show shared profiles spyware <name> botnet-domains lists <name> action block
show shared profiles spyware <name> botnet-domains lists <name> action sinkhole
lient
erver
oth
e>
dentials
e>
e> headers
ame>
<name>
<name> or-condition
me>
me> or-condition
show shared threats spyware <name> signature standard <name> and-condition <name
>
show shared threats spyware <name> signature standard <name> and-condition <name
> or-condition
show shared threats spyware <name> signature standard <name> and-condition <name
show shared threats spyware <name> signature standard <name> and-condition <name
show shared threats spyware <name> signature standard <name> and-condition <name
show shared threats spyware <name> signature standard <name> and-condition <name
show shared threats spyware <name> signature standard <name> and-condition <name
show shared threats spyware <name> signature standard <name> and-condition <name
show shared threats spyware <name> signature standard <name> and-condition <name
show shared threats spyware <name> signature standard <name> and-condition <name
show shared threats spyware <name> signature standard <name> and-condition <name
> or-condition <name> operator greater-than
show shared threats spyware <name> signature standard <name> and-condition <name
show shared threats spyware <name> signature standard <name> and-condition <name
show shared threats spyware <name> signature standard <name> and-condition <name
show shared threats spyware <name> signature standard <name> and-condition <name
show shared threats spyware <name> signature standard <name> and-condition <name
-condition
-condition <name>
show shared log-settings userid match-list <name> actions <name> type tagging
show shared log-settings userid match-list <name> actions <name> type tagging re
gistration
show shared log-settings userid match-list <name> actions <name> type tagging re
gistration localhost
show shared log-settings userid match-list <name> actions <name> type tagging re
gistration panorama
show shared log-settings userid match-list <name> actions <name> type tagging re
gistration remote
show shared log-settings hipmatch match-list <name> actions <name> type tagging
show shared log-settings hipmatch match-list <name> actions <name> type tagging
registration
show shared log-settings hipmatch match-list <name> actions <name> type tagging
registration localhost
show shared log-settings hipmatch match-list <name> actions <name> type tagging
registration panorama
show shared log-settings hipmatch match-list <name> actions <name> type tagging
registration remote
show shared log-settings correlation match-list <name> actions <name> type taggi
ng
show shared log-settings correlation match-list <name> actions <name> type taggi
ng registration
show shared log-settings correlation match-list <name> actions <name> type taggi
ng registration localhost
show shared log-settings correlation match-list <name> actions <name> type taggi
ng registration panorama
show shared log-settings correlation match-list <name> actions <name> type taggi
ng registration remote
show shared log-settings profiles <name> match-list <name> actions <name> type
show shared log-settings profiles <name> match-list <name> actions <name> type t
agging
show shared log-settings profiles <name> match-list <name> actions <name> type t
agging registration
show shared log-settings profiles <name> match-list <name> actions <name> type t
show shared log-settings profiles <name> match-list <name> actions <name> type t
show shared log-settings profiles <name> match-list <name> actions <name> type t
gine
ne
show vsys
show vsys <name> log-settings snmptrap <name> version v2c server <name>
show vsys <name> log-settings http <name> format config headers <name>
show vsys <name> log-settings http <name> format config params <name>
show vsys <name> log-settings http <name> format system headers <name>
show vsys <name> log-settings http <name> format system params <name>
show vsys <name> log-settings http <name> format traffic headers <name>
show vsys <name> log-settings http <name> format traffic params <name>
show vsys <name> log-settings http <name> format threat headers <name>
show vsys <name> log-settings http <name> format threat params <name>
show vsys <name> log-settings http <name> format wildfire headers <name>
show vsys <name> log-settings http <name> format wildfire params <name>
show vsys <name> log-settings http <name> format url headers <name>
show vsys <name> log-settings http <name> format url params <name>
show vsys <name> log-settings http <name> format data headers <name>
show vsys <name> log-settings http <name> format data params
show vsys <name> log-settings http <name> format data params <name>
show vsys <name> log-settings http <name> format tunnel headers <name>
show vsys <name> log-settings http <name> format tunnel params <name>
show vsys <name> log-settings http <name> format auth headers <name>
show vsys <name> log-settings http <name> format auth params <name>
show vsys <name> log-settings http <name> format userid headers <name>
show vsys <name> log-settings http <name> format userid params <name>
show vsys <name> log-settings http <name> format hip-match headers <name>
show vsys <name> log-settings http <name> format hip-match params <name>
show vsys <name> log-settings http <name> format correlation headers <name>
show vsys <name> log-settings http <name> format correlation params <name>
show vsys <name> log-settings profiles <name> match-list <name> actions <name> t
ype
show vsys <name> log-settings profiles <name> match-list <name> actions <name> t
ype tagging
show vsys <name> log-settings profiles <name> match-list <name> actions <name> t
show vsys <name> log-settings profiles <name> match-list <name> actions <name> t
show vsys <name> log-settings profiles <name> match-list <name> actions <name> t
show vsys <name> log-settings profiles <name> match-list <name> actions <name> t
ervice-in-gce
show vsys <name> vm-info-source <name> Google-Compute-Engine service-auth-type s
ervice-account
file
-address
-address
-address ip
-address floating-ip
t-auth
t-auth <name>
tivity-logout
to-settings
to-settings ssl-protocol
to-settings server-cert-verification
-to-user-mapping
-to-user-mapping <name>
y-server-setting
y-server-setting <name>
ca
ca <name>
gs
gs <name>
gs <name> gateways
gs <name> internal-host-detection
gs <name> internal-host-detection-v6
gs <name> agent-ui
gs <name> hip-collection
show vsys <name> global-protect global-protect-portal <name> client-config confi
gs <name> agent-config
gs <name> gp-app-config
gs <name> client-certificate
gs <name> authentication-override
ient-certificate
ient-certificate local
ient-certificate scep
nfigs
nfigs <name>
-configs
ting-ip
ivity-logout
nnect-on-idle
name>
name> match-message
name> not-match-message
fi
bile
known
show vsys <name> profiles hip-objects <name> network-info criteria network is-no
show vsys <name> profiles hip-objects <name> network-info criteria network is-no
t wifi
show vsys <name> profiles hip-objects <name> network-info criteria network is-no
t mobile
show vsys <name> profiles hip-objects <name> network-info criteria network is-no
t ethernet
show vsys <name> profiles hip-objects <name> network-info criteria network is-no
t unknown
atches
atches severity
atches severity
n within
n not-within
on
on
on within
on not-within
e within
e not-within
me
me
me not-available
me within
me not-within
locations
locations <name>
<name>
<name>
<name> registry-value
show vsys <name> profiles hip-objects <name> custom-checks criteria plist <name>
show vsys <name> profiles hip-objects <name> custom-checks criteria plist <name>
key
show vsys <name> profiles hip-objects <name> custom-checks criteria plist <name>
key <name>
-time
-time
-time within
-time not-within
has-malware
has-malware no
has-malware yes
includes
includes <name>
show vsys <name> profiles spyware <name> botnet-domains lists <name> action
show vsys <name> profiles spyware <name> botnet-domains lists <name> action aler
show vsys <name> profiles spyware <name> botnet-domains lists <name> action allo
show vsys <name> profiles spyware <name> botnet-domains lists <name> action bloc
show vsys <name> profiles spyware <name> botnet-domains lists <name> action sink
hole
show vsys <name> profiles spyware <name> rules <name> action default
show vsys <name> profiles spyware <name> rules <name> action allow
show vsys <name> profiles spyware <name> rules <name> action alert
show vsys <name> profiles spyware <name> rules <name> action drop
show vsys <name> profiles spyware <name> rules <name> action reset-client
show vsys <name> profiles spyware <name> rules <name> action reset-server
show vsys <name> profiles spyware <name> rules <name> action reset-both
show vsys <name> profiles spyware <name> rules <name> action block-ip
show vsys <name> profiles spyware <name> threat-exception
show vsys <name> profiles spyware <name> threat-exception <name> action default
show vsys <name> profiles spyware <name> threat-exception <name> action allow
show vsys <name> profiles spyware <name> threat-exception <name> action alert
show vsys <name> profiles spyware <name> threat-exception <name> action drop
show vsys <name> profiles spyware <name> threat-exception <name> action reset-bo
th
show vsys <name> profiles spyware <name> threat-exception <name> action reset-cl
ient
show vsys <name> profiles spyware <name> threat-exception <name> action reset-se
rver
show vsys <name> profiles spyware <name> threat-exception <name> action block-ip
show vsys <name> profiles spyware <name> threat-exception <name> exempt-ip <name
>
show vsys <name> profiles vulnerability <name> rules <name> action default
show vsys <name> profiles vulnerability <name> rules <name> action allow
show vsys <name> profiles vulnerability <name> rules <name> action alert
show vsys <name> profiles vulnerability <name> rules <name> action drop
show vsys <name> profiles vulnerability <name> rules <name> action reset-client
show vsys <name> profiles vulnerability <name> rules <name> action reset-server
show vsys <name> profiles vulnerability <name> rules <name> action reset-both
show vsys <name> profiles vulnerability <name> rules <name> action block-ip
fault
low
ert
op
set-client
set-server
set-both
ock-ip
ibute
<name>
led
er
show vsys <name> profiles url-filtering <name> credential-enforcement mode domai
n-credentials
<name>
<name> headers
show vsys <name> profiles data-objects <name> pattern-type predefined pattern <n
ame>
show vsys <name> profiles data-objects <name> pattern-type regex pattern <name>
show vsys <name> profiles data-objects <name> pattern-type file-properties
rn
rn <name>
show vsys <name> profiles dos-protection <name> flood tcp-syn red block
show vsys <name> profiles dos-protection <name> flood tcp-syn syn-cookies block
show vsys <name> profiles dos-protection <name> flood udp red block
show vsys <name> profiles dos-protection <name> flood icmp red block
show vsys <name> profiles dos-protection <name> flood icmpv6 red block
show vsys <name> profiles dos-protection <name> flood other-ip red block
show vsys <name> profiles dos-protection <name> resource
show vsys <name> threats vulnerability <name> signature standard <name> and-cond
ition
show vsys <name> threats vulnerability <name> signature standard <name> and-cond
ition <name>
show vsys <name> threats vulnerability <name> signature standard <name> and-cond
show vsys <name> threats vulnerability <name> signature standard <name> and-cond
show vsys <name> threats vulnerability <name> signature standard <name> and-cond
show vsys <name> threats vulnerability <name> signature standard <name> and-cond
show vsys <name> threats vulnerability <name> signature standard <name> and-cond
show vsys <name> threats vulnerability <name> signature standard <name> and-cond
show vsys <name> threats vulnerability <name> signature standard <name> and-cond
show vsys <name> threats vulnerability <name> signature standard <name> and-cond
show vsys <name> threats vulnerability <name> signature standard <name> and-cond
show vsys <name> threats vulnerability <name> signature standard <name> and-cond
show vsys <name> threats vulnerability <name> signature standard <name> and-cond
show vsys <name> threats vulnerability <name> signature standard <name> and-cond
show vsys <name> threats vulnerability <name> signature standard <name> and-cond
show vsys <name> threats vulnerability <name> signature standard <name> and-cond
te
n <name>
n <name> or-condition
show vsys <name> threats spyware <name> signature standard <name> and-condition
<name>
show vsys <name> threats spyware <name> signature standard <name> and-condition
<name> or-condition
show vsys <name> threats spyware <name> signature standard <name> and-condition
show vsys <name> threats spyware <name> signature standard <name> and-condition
show vsys <name> threats spyware <name> signature standard <name> and-condition
show vsys <name> threats spyware <name> signature standard <name> and-condition
show vsys <name> threats spyware <name> signature standard <name> and-condition
show vsys <name> threats spyware <name> signature standard <name> and-condition
show vsys <name> threats spyware <name> signature standard <name> and-condition
show vsys <name> threats spyware <name> signature standard <name> and-condition
show vsys <name> threats spyware <name> signature standard <name> and-condition
show vsys <name> threats spyware <name> signature standard <name> and-condition
show vsys <name> threats spyware <name> signature standard <name> and-condition
show vsys <name> threats spyware <name> signature standard <name> and-condition
show vsys <name> threats spyware <name> signature standard <name> and-condition
show vsys <name> threats spyware <name> signature standard <name> and-condition
<name> or-condition <name> operator pattern-match qualifier <name>
show vsys <name> threats spyware <name> signature combination and-condition <nam
e>
show vsys <name> threats spyware <name> signature combination and-condition <nam
e> or-condition
show vsys <name> threats spyware <name> signature combination and-condition <nam
show vsys <name> application <name> signature <name> and-condition <name> or-con
dition
show vsys <name> application <name> signature <name> and-condition <name> or-con
dition <name>
show vsys <name> application <name> signature <name> and-condition <name> or-con
show vsys <name> application <name> signature <name> and-condition <name> or-con
show vsys <name> application <name> signature <name> and-condition <name> or-con
show vsys <name> application <name> signature <name> and-condition <name> or-con
show vsys <name> application <name> signature <name> and-condition <name> or-con
dition <name> operator greater-than
show vsys <name> application <name> signature <name> and-condition <name> or-con
show vsys <name> application <name> signature <name> and-condition <name> or-con
show vsys <name> application <name> signature <name> and-condition <name> or-con
show vsys <name> application <name> signature <name> and-condition <name> or-con
show vsys <name> application <name> signature <name> and-condition <name> or-con
show vsys <name> application <name> signature <name> and-condition <name> or-con
show vsys <name> rulebase security rules <name> qos marking follow-c2s-flow
ofiles
g-override
t interface-address
t interface-address
show vsys <name> rulebase nat rules <name> source-translation dynamic-ip fallbac
show vsys <name> rulebase nat rules <name> source-translation dynamic-ip fallbac
show vsys <name> rulebase nat rules <name> source-translation dynamic-ip fallbac
k interface-address
show vsys <name> rulebase nat rules <name> source-translation dynamic-ip fallbac
k interface-address
show vsys <name> rulebase qos rules <name> dscp-tos codepoints <name>
show vsys <name> rulebase qos rules <name> dscp-tos codepoints <name>
show vsys <name> rulebase qos rules <name> dscp-tos codepoints <name> ef
show vsys <name> rulebase qos rules <name> dscp-tos codepoints <name> af
show vsys <name> rulebase qos rules <name> dscp-tos codepoints <name> cs
show vsys <name> rulebase qos rules <name> dscp-tos codepoints <name> tos
show vsys <name> rulebase qos rules <name> dscp-tos codepoints <name> custom
show vsys <name> rulebase qos rules <name> dscp-tos codepoints <name> custom cod
epoint
show vsys <name> rulebase pbf rules <name> action forward nexthop
show vsys <name> rulebase pbf rules <name> action forward monitor
ess-list
ess-list <name>
show vsys <name> rulebase dos rules <name> protection classified classification-
criteria
set deviceconfig
ull-duplex|100Mbps-half-duplex|100Mbps-full-duplex|1Gbps-half-duplex|1Gbps-full-
duplex>
>
tric-key
tric-key algorithm
ey
ue>
metric-key
metric-key algorithm
okey
server-address <ip/netmask>
etry <0-500>
value>
<name>
<ip/netmask>
6|384|521>
|3072|4096>
256|384|521>
set deviceconfig system ssh regenerate-hostkeys mgmt key-type RSA key-length <20
48|3072|4096>
no>
tring <value>
<name>
<value>
pwd <value>
pwd <value>
el|userid|auth|url|data|hipmatch|wildfire>
s|no>
yes|no>
orts <yes|no>
ormation <yes|no>
p <yes|no>
g <yes|no>
ports <yes|no>
eports <yes|no>
>
download-only|download-and-install>
new-content <yes|no>
d-only|download-and-install>
tent <yes|no>
-only|download-and-install>
ent <yes|no>
nday|monday|tuesday|wednesday|thursday|friday|saturday>
d-only|download-and-install>
set deviceconfig system update-schedule threats recurring weekly disable-new-con
tent <yes|no>
36>
load-only|download-and-install>
<sunday|monday|tuesday|wednesday|thursday|friday|saturday>
nload-only|download-and-install>
no>
load-only|download-and-install>
<sunday|monday|tuesday|wednesday|thursday|friday|saturday>
load-only|download-and-install>
o>
nload-only|download-and-install>
4>
<download-only|download-and-install>
9>
<download-only|download-and-install>
wnload-only|download-and-install>
4>
<download-only|download-and-install>
-14>
n <download-only|download-and-install>
-29>
n <download-only|download-and-install>
>
download-only|download-and-install>
o>
nload-and-install>
k <sunday|monday|tuesday|wednesday|thursday|friday|saturday>
wnload-and-install>
hourly
hourly at <0-59>
daily
daily at <value>
weekly
weekly at <value>
at <0-59>
action <download-and-install|download-only>
at <value>
action <download-and-install>
day-of-week <sunday|monday|tuesday|wednesday|thursday|friday|saturday>
at <value>
action <download-and-install|download-only>
color5|color6|color7|color8|color9|color10|color11|color12|color13|color14|color
15|color16|color17>
3|color4|color5|color6|color7|color8|color9|color10|color11|color12|color13|colo
r14|color15|color16|color17>
|color14|color15|color16|color17|color18>
3|color4|color5|color6|color7|color8|color9|color10|color11|color12|color13|colo
r14|color15|color16|color17>
color3|color4|color5|color6|color7|color8|color9|color10|color11|color12|color13
|color14|color15|color16|color17|color18>
|Africa/Algiers|Africa/Asmara|Africa/Asmera|Africa/Bamako|Africa/Bangui|Africa/B
anjul|Africa/Bissau|Africa/Blantyre|Africa/Brazzaville|Africa/Bujumbura|Africa/C
airo|Africa/Casablanca|Africa/Ceuta|Africa/Conakry|Africa/Dakar|Africa/Dar_es_Sa
laam|Africa/Djibouti|Africa/Douala|Africa/El_Aaiun|Africa/Freetown|Africa/Gaboro
ne|Africa/Harare|Africa/Johannesburg|Africa/Kampala|Africa/Khartoum|Africa/Kigal
i|Africa/Kinshasa|Africa/Lagos|Africa/Libreville|Africa/Lome|Africa/Luanda|Afric
a/Lubumbashi|Africa/Lusaka|Africa/Malabo|Africa/Maputo|Africa/Maseru|Africa/Mbab
ane|Africa/Mogadishu|Africa/Monrovia|Africa/Nairobi|Africa/Ndjamena|Africa/Niame
y|Africa/Nouakchott|Africa/Ouagadougou|Africa/Porto-Novo|Africa/Sao_Tome|Africa/
Timbuktu|Africa/Tripoli|Africa/Tunis|Africa/Windhoek|America/Adak|America/Anchor
age|America/Anguilla|America/Antigua|America/Araguaina|America/Argentina/Buenos_
Aires|America/Argentina/Catamarca|America/Argentina/ComodRivadavia|America/Argen
tina/Cordoba|America/Argentina/Jujuy|America/Argentina/La_Rioja|America/Argentin
a/Mendoza|America/Argentina/Rio_Gallegos|America/Argentina/Salta|America/Argenti
na/San_Juan|America/Argentina/San_Luis|America/Argentina/Tucuman|America/Argenti
na/Ushuaia|America/Aruba|America/Asuncion|America/Atikokan|America/Atka|America/
Bahia|America/Barbados|America/Belem|America/Belize|America/Blanc-Sablon|America
/Boa_Vista|America/Bogota|America/Boise|America/Buenos_Aires|America/Cambridge_B
ay|America/Campo_Grande|America/Cancun|America/Caracas|America/Catamarca|America
/Cayenne|America/Cayman|America/Chicago|America/Chihuahua|America/Coral_Harbour|
America/Cordoba|America/Costa_Rica|America/Cuiaba|America/Curacao|America/Danmar
kshavn|America/Dawson|America/Dawson_Creek|America/Denver|America/Detroit|Americ
a/Dominica|America/Edmonton|America/Eirunepe|America/El_Salvador|America/Ensenad
a|America/Fortaleza|America/Fort_Wayne|America/Glace_Bay|America/Godthab|America
/Goose_Bay|America/Grand_Turk|America/Grenada|America/Guadeloupe|America/Guatema
la|America/Guayaquil|America/Guyana|America/Halifax|America/Havana|America/Hermo
sillo|America/Indiana/Indianapolis|America/Indiana/Knox|America/Indiana/Marengo|
America/Indiana/Petersburg|America/Indianapolis|America/Indiana/Tell_City|Americ
a/Indiana/Vevay|America/Indiana/Vincennes|America/Indiana/Winamac|America/Inuvik
|America/Iqaluit|America/Jamaica|America/Jujuy|America/Juneau|America/Kentucky/L
ouisville|America/Kentucky/Monticello|America/Knox_IN|America/La_Paz|America/Lim
a|America/Los_Angeles|America/Louisville|America/Maceio|America/Managua|America/
Manaus|America/Marigot|America/Martinique|America/Mazatlan|America/Mendoza|Ameri
ca/Menominee|America/Merida|America/Mexico_City|America/Miquelon|America/Moncton
|America/Monterrey|America/Montevideo|America/Montreal|America/Montserrat|Americ
a/Nassau|America/New_York|America/Nipigon|America/Nome|America/Noronha|America/N
orth_Dakota/Center|America/North_Dakota/New_Salem|America/Panama|America/Pangnir
tung|America/Paramaribo|America/Phoenix|America/Port-au-Prince|America/Porto_Acr
e|America/Port_of_Spain|America/Porto_Velho|America/Puerto_Rico|America/Rainy_Ri
ver|America/Rankin_Inlet|America/Recife|America/Regina|America/Resolute|America/
Rio_Branco|America/Rosario|America/Santarem|America/Santiago|America/Santo_Domin
go|America/Sao_Paulo|America/Scoresbysund|America/Shiprock|America/St_Barthelemy
|America/St_Johns|America/St_Kitts|America/St_Lucia|America/St_Thomas|America/St
_Vincent|America/Swift_Current|America/Tegucigalpa|America/Thule|America/Thunder
_Bay|America/Tijuana|America/Toronto|America/Tortola|America/Vancouver|America/V
irgin|America/Whitehorse|America/Winnipeg|America/Yakutat|America/Yellowknife|An
tarctica/Casey|Antarctica/Davis|Antarctica/DumontDUrville|Antarctica/Mawson|Anta
rctica/McMurdo|Antarctica/Palmer|Antarctica/Rothera|Antarctica/South_Pole|Antarc
tica/Syowa|Antarctica/Vostok|Arctic/Longyearbyen|Asia/Aden|Asia/Almaty|Asia/Amma
n|Asia/Anadyr|Asia/Aqtau|Asia/Aqtobe|Asia/Ashgabat|Asia/Ashkhabad|Asia/Baghdad|A
sia/Bahrain|Asia/Baku|Asia/Bangkok|Asia/Beirut|Asia/Bishkek|Asia/Brunei|Asia/Cal
cutta|Asia/Choibalsan|Asia/Chongqing|Asia/Chungking|Asia/Colombo|Asia/Dacca|Asia
/Damascus|Asia/Dhaka|Asia/Dili|Asia/Dubai|Asia/Dushanbe|Asia/Gaza|Asia/Harbin|As
ia/Ho_Chi_Minh|Asia/Hong_Kong|Asia/Hovd|Asia/Irkutsk|Asia/Istanbul|Asia/Jakarta|
Asia/Jayapura|Asia/Jerusalem|Asia/Kabul|Asia/Kamchatka|Asia/Karachi|Asia/Kashgar
|Asia/Kathmandu|Asia/Katmandu|Asia/Kolkata|Asia/Krasnoyarsk|Asia/Kuala_Lumpur|As
ia/Kuching|Asia/Kuwait|Asia/Macao|Asia/Macau|Asia/Magadan|Asia/Makassar|Asia/Man
ila|Asia/Muscat|Asia/Nicosia|Asia/Novokuznetsk|Asia/Novosibirsk|Asia/Omsk|Asia/O
ral|Asia/Phnom_Penh|Asia/Pontianak|Asia/Pyongyang|Asia/Qatar|Asia/Qyzylorda|Asia
/Rangoon|Asia/Riyadh|Asia/Riyadh87|Asia/Riyadh88|Asia/Riyadh89|Asia/Saigon|Asia/
Sakhalin|Asia/Samarkand|Asia/Seoul|Asia/Shanghai|Asia/Singapore|Asia/Taipei|Asia
/Tashkent|Asia/Tbilisi|Asia/Tehran|Asia/Tel_Aviv|Asia/Thimbu|Asia/Thimphu|Asia/T
okyo|Asia/Ujung_Pandang|Asia/Ulaanbaatar|Asia/Ulan_Bator|Asia/Urumqi|Asia/Vienti
ane|Asia/Vladivostok|Asia/Yakutsk|Asia/Yekaterinburg|Asia/Yerevan|Atlantic/Azore
s|Atlantic/Bermuda|Atlantic/Canary|Atlantic/Cape_Verde|Atlantic/Faeroe|Atlantic/
Faroe|Atlantic/Jan_Mayen|Atlantic/Madeira|Atlantic/Reykjavik|Atlantic/South_Geor
gia|Atlantic/Stanley|Atlantic/St_Helena|Australia/ACT|Australia/Adelaide|Austral
ia/Brisbane|Australia/Broken_Hill|Australia/Canberra|Australia/Currie|Australia/
Darwin|Australia/Eucla|Australia/Hobart|Australia/LHI|Australia/Lindeman|Austral
ia/Lord_Howe|Australia/Melbourne|Australia/North|Australia/NSW|Australia/Perth|A
ustralia/Queensland|Australia/South|Australia/Sydney|Australia/Tasmania|Australi
a/Victoria|Australia/West|Australia/Yancowinna|Brazil/Acre|Brazil/DeNoronha|Braz
il/East|Brazil/West|Canada/Atlantic|Canada/Central|Canada/Eastern|Canada/East-Sa
skatchewan|Canada/Mountain|Canada/Newfoundland|Canada/Pacific|Canada/Saskatchewa
n|Canada/Yukon|CET|Chile/Continental|Chile/EasterIsland|CST6CDT|Cuba|EET|Egypt|E
ire|EST|EST5EDT|Etc/GMT|Etc/GMT0|Etc/GMT-0|Etc/GMT+0|Etc/GMT-1|Etc/GMT+1|Etc/GMT
-10|Etc/GMT+10|Etc/GMT-11|Etc/GMT+11|Etc/GMT-12|Etc/GMT+12|Etc/GMT-13|Etc/GMT-14
|Etc/GMT-2|Etc/GMT+2|Etc/GMT-3|Etc/GMT+3|Etc/GMT-4|Etc/GMT+4|Etc/GMT-5|Etc/GMT+5
|Etc/GMT-6|Etc/GMT+6|Etc/GMT-7|Etc/GMT+7|Etc/GMT-8|Etc/GMT+8|Etc/GMT-9|Etc/GMT+9
|Etc/Greenwich|Etc/UCT|Etc/Universal|Etc/UTC|Etc/Zulu|Europe/Amsterdam|Europe/An
dorra|Europe/Athens|Europe/Belfast|Europe/Belgrade|Europe/Berlin|Europe/Bratisla
va|Europe/Brussels|Europe/Bucharest|Europe/Budapest|Europe/Chisinau|Europe/Copen
hagen|Europe/Dublin|Europe/Gibraltar|Europe/Guernsey|Europe/Helsinki|Europe/Isle
_of_Man|Europe/Istanbul|Europe/Jersey|Europe/Kaliningrad|Europe/Kiev|Europe/Lisb
on|Europe/Ljubljana|Europe/London|Europe/Luxembourg|Europe/Madrid|Europe/Malta|E
urope/Mariehamn|Europe/Minsk|Europe/Monaco|Europe/Moscow|Europe/Nicosia|Europe/O
slo|Europe/Paris|Europe/Podgorica|Europe/Prague|Europe/Riga|Europe/Rome|Europe/S
amara|Europe/San_Marino|Europe/Sarajevo|Europe/Simferopol|Europe/Skopje|Europe/S
ofia|Europe/Stockholm|Europe/Tallinn|Europe/Tirane|Europe/Tiraspol|Europe/Uzhgor
od|Europe/Vaduz|Europe/Vatican|Europe/Vienna|Europe/Vilnius|Europe/Volgograd|Eur
ope/Warsaw|Europe/Zagreb|Europe/Zaporozhye|Europe/Zurich|Factory|GB|GB-Eire|GMT|
GMT0|GMT-0|GMT+0|Greenwich|Hongkong|HST|Iceland|Indian/Antananarivo|Indian/Chago
s|Indian/Christmas|Indian/Cocos|Indian/Comoro|Indian/Kerguelen|Indian/Mahe|India
n/Maldives|Indian/Mauritius|Indian/Mayotte|Indian/Reunion|Iran|Israel|Jamaica|Ja
pan|Kwajalein|Libya|MET|Mexico/BajaNorte|Mexico/BajaSur|Mexico/General|Mideast/R
iyadh87|Mideast/Riyadh88|Mideast/Riyadh89|MST|MST7MDT|Navajo|NZ|NZ-CHAT|Pacific/
Apia|Pacific/Auckland|Pacific/Chatham|Pacific/Easter|Pacific/Efate|Pacific/Ender
bury|Pacific/Fakaofo|Pacific/Fiji|Pacific/Funafuti|Pacific/Galapagos|Pacific/Gam
bier|Pacific/Guadalcanal|Pacific/Guam|Pacific/Honolulu|Pacific/Johnston|Pacific/
Kiritimati|Pacific/Kosrae|Pacific/Kwajalein|Pacific/Majuro|Pacific/Marquesas|Pac
ific/Midway|Pacific/Nauru|Pacific/Niue|Pacific/Norfolk|Pacific/Noumea|Pacific/Pa
go_Pago|Pacific/Palau|Pacific/Pitcairn|Pacific/Ponape|Pacific/Port_Moresby|Pacif
ic/Rarotonga|Pacific/Saipan|Pacific/Samoa|Pacific/Tahiti|Pacific/Tarawa|Pacific/
Tongatapu|Pacific/Truk|Pacific/Wake|Pacific/Wallis|Pacific/Yap|Poland|Portugal|P
RC|PST8PDT|ROC|ROK|Singapore|Turkey|UCT|Universal|US/Alaska|US/Aleutian|US/Arizo
na|US/Central|US/Eastern|US/East-Indiana|US/Hawaii|US/Indiana-Starke|US/Michigan
|US/Mountain|US/Pacific|US/Samoa|UTC|WET|W-SU|Zulu>
>
no>
es|no>
|384>
>
35>
set deviceconfig setting session packet-buffer-protection-block-duration-time <1
-15999999>
-syn-tcp
-traffic
-report
ging <yes|no>
ons <value>
rtificate <value>
rtificate-profile <value>
set deviceconfig setting management secure-conn-client certificate-type scep
p-profile <value>
tificate-profile <value>
s|no>
mmunication <yes|no>
nication <yes|no>
mmunication <yes|no>
ation <yes|no>
<1-2000>
<1-2000>
<1-2000>
<1-2000>
1-2000>
<1-2000>
1-2000>
<1-2000>
h <1-2000>
rsum <1-2000>
sum <1-2000>
rsum <1-2000>
hsum <1-2000>
sum <1-2000>
hsum <1-2000>
rlsum <1-2000>
lsum <1-2000>
rlsum <1-2000>
pcaps <1-2000>
2000>
<1-2000>
tpsum <1-2000>
tpsum <1-2000>
<1-2000>
-2000>
1-2000>
s <1-2000>
tion-pcaps <1-2000>
ilter-pcaps <1-2000>
orts <1-2000>
>
>
>
t>
>
t>
t>
t>
>
t>
<float>
<float>
>
set deviceconfig setting management large-core <yes|no>
fined-reports1> <disable-predefined-reports2>... ]
ble-predefined-correlation-objs1> <disable-predefined-correlation-objs2>... ]
|no>
logs <yes|no>
logs <yes|no>
yes|no>
>
[ <skip-configuration-logs-for1> <skip-configuration-logs-for2>... ]
integrity
integrity
yes|no>
>
ipv4-address|ipv6-address>
eshold <1-60>
m-generation <yes|no>
alarm-notification <yes|no>
alarm-notification <yes|no>
ble-alarms <yes|no>
rypt-fail-count <1-4294967295>
licy-limits
limits
es-alarm-threshold
ment>
1000>
alf>
set deviceconfig high-availability interface ha1-backup ip-address <ip/netmask>
o>
on-hold-time <0-60000>
nterval <8000-60000>
set deviceconfig high-availability group election-option timers advanced heartbe
at-interval <1000-60000>
x <0-16>
ion-hold-time <1-60>
-fail-hold-up-time <0-60000>
nal-master-hold-up-time <0-60000>
et|ip|udp>
abled <yes|no>
tion <log-only|split-datapath>
reshold <5000-60000>
yes|no>
<shutdown|auto>
<10-600>|<disabled>
n sync
e>
e> ip
e> ip <name>
e> ip <name>
e> ipv6
ion
ion
ion primary-device
ion first-packet
|no>
ition <any|all>
irtual-wire
irtual-wire <name>
lan
lan <name>
irtual-router
irtual-router <name>
|no>
ition <any|all>
name>
set mgt-config
30>
ount <0-3>
<0-30>
<0-30>
set mgt-config password-profile <name> password-change post-expiration-admin-log
in-count <0-3>
iod <0-30>
set mgt-config users <name> preferences saved-log-query unified <name> query <va
lue>
set mgt-config users <name> preferences saved-log-query traffic <name> query <va
lue>
set mgt-config users <name> preferences saved-log-query threat <name> query <val
ue>
set mgt-config users <name> preferences saved-log-query url <name> query <value>
>
set mgt-config users <name> preferences saved-log-query config <name> query <val
ue>
set mgt-config users <name> preferences saved-log-query system <name> query <val
ue>
set mgt-config users <name> preferences saved-log-query wildfire <name> query <v
alue>
set mgt-config users <name> preferences saved-log-query hipmatch <name> query <v
alue>
set mgt-config users <name> preferences saved-log-query corr <name> query <value
>
set mgt-config users <name> preferences saved-log-query tunnel <name> query <val
ue>
set mgt-config users <name> preferences saved-log-query userid <name> query <val
ue>
>
set mgt-config users <name> preferences saved-log-query alarm <name> query <valu
e>
set mgt-config users <name> permissions role-based vsysreader <name> vsys [ <vs
ys1> <vsys2>... ]
set mgt-config users <name> permissions role-based vsysadmin <name> vsys [ <vsy
s1> <vsys2>... ]
1> <devicereader2>... ]
<deviceadmin2>... ]
set mgt-config users <name> permissions role-based custom vsys [ <vsys1> <vsys2
>... ]
set network
ssl <yes|no>
udp <yes|no>
duration <1-3600>
5>
35>
<value>
<value>
>
<0-2000000>
ate <1-2000000>
te <1-2000000>
arm-rate <0-2000000>
tivate-rate <0-2000000>
set network profiles zone-protection-profile <name> flood udp red alarm-rate <0-
2000000>
<1-2000000>
set network profiles zone-protection-profile <name> flood udp red maximal-rate <
1-2000000>
set network profiles zone-protection-profile <name> flood icmp red alarm-rate <0
-2000000>
<1-2000000>
<1-2000000>
<0-2000000>
te <1-2000000>
e <1-2000000>
o>
e <0-2000000>
rate <1-2000000>
ate <1-2000000>
o>
o>
o>
es|no>
|no>
|no>
|no>
<yes|no>
o>
op-hdr <yes|no>
hdr <yes|no>
each <yes|no>
big <yes|no>
eeded <yes|no>
oblem <yes|no>
<yes|no>
scard <yes|no>
u-discard <yes|no>
yes|no>
ard <yes|no>
es|no>
es|no>
|bypass>
es|no>
yes|no>
no>
g <yes|no>
<yes|no>
>
no>
s|no>
ent-mismatch <yes|no>
>
<yes|no>
es|no>
<yes|no>
<yes|no>
set network profiles zone-protection-profile <name> non-ip-protocol
xclude|include>
me>
ceive-only>
>
<yes|no>
name>
name>
set network interface ethernet <name> virtual-wire units <name> tag <0-4094>
<value>
set network interface ethernet <name> virtual-wire units <name> comment <value>
<ip-classifier1> <ip-classifier2>... ]
set network interface ethernet <name> virtual-wire netflow-profile <value>
e-pre-negotiation <yes|no>
e-pre-negotiation <yes|no>
set network interface ethernet <name> layer2 units <name> tag <1-4094>
set network interface ethernet <name> layer2 units <name> netflow-profile <value
>
set network interface ethernet <name> layer2 units <name> comment <value>
negotiation <yes|no>
<60-300>
set network interface ethernet <name> layer3 ipv6 address <name> enable-on-inter
face <yes|no>
set network interface ethernet <name> layer3 ipv6 address <name> prefix
set network interface ethernet <name> layer3 ipv6 address <name> anycast
set network interface ethernet <name> layer3 ipv6 address <name> advertise
set network interface ethernet <name> layer3 ipv6 address <name> advertise enabl
e <yes|no>
set network interface ethernet <name> layer3 ipv6 address <name> advertise valid
-lifetime <0-4294967294>|<infinity>
set network interface ethernet <name> layer3 ipv6 address <name> advertise prefe
rred-lifetime <0-4294967294>|<infinity>
set network interface ethernet <name> layer3 ipv6 address <name> advertise onlin
k-flag <yes|no>
set network interface ethernet <name> layer3 ipv6 address <name> advertise auto-
config-flag <yes|no>
rtisement
rtisement dns-support
monitor <yes|no>
<yes|no>
s <0-10>
<1-3600>
ime <10-36000>
set network interface ethernet <name> layer3 ipv6 neighbor-discovery neighbor <n
ame>
set network interface ethernet <name> layer3 ipv6 neighbor-discovery neighbor <n
>
>
set network interface ethernet <name> layer3 pppoe passive enable <yes|no>
es|no>
-65535>
set network interface ethernet <name> layer3 arp <name> hw-address <value>
set network interface ethernet <name> layer3 ndp-proxy address <name> negate <ye
s|no>
>
set network interface ethernet <name> layer3 units <name> decrypt-forward <yes|n
o>
set network interface ethernet <name> layer3 units <name> mtu <576-9216>
set network interface ethernet <name> layer3 units <name> adjust-tcp-mss enable
<yes|no>
set network interface ethernet <name> layer3 units <name> adjust-tcp-mss ipv4-ms
s-adjustment <40-300>
set network interface ethernet <name> layer3 units <name> adjust-tcp-mss ipv6-ms
s-adjustment <60-300>
set network interface ethernet <name> layer3 units <name> ip
set network interface ethernet <name> layer3 units <name> ipv6 enabled <yes|no>
set network interface ethernet <name> layer3 units <name> ipv6 interface-id <val
ue>|<EUI-64>
set network interface ethernet <name> layer3 units <name> ipv6 address
set network interface ethernet <name> layer3 units <name> ipv6 address <name>
set network interface ethernet <name> layer3 units <name> ipv6 address <name> en
able-on-interface <yes|no>
set network interface ethernet <name> layer3 units <name> ipv6 address <name> pr
efix
set network interface ethernet <name> layer3 units <name> ipv6 address <name> an
ycast
set network interface ethernet <name> layer3 units <name> ipv6 address <name> ad
vertise
set network interface ethernet <name> layer3 units <name> ipv6 address <name> ad
set network interface ethernet <name> layer3 units <name> ipv6 address <name> ad
set network interface ethernet <name> layer3 units <name> ipv6 address <name> ad
set network interface ethernet <name> layer3 units <name> ipv6 address <name> ad
set network interface ethernet <name> layer3 units <name> ipv6 address <name> ad
set network interface ethernet <name> layer3 units <name> ipv6 neighbor-discover
set network interface ethernet <name> layer3 units <name> ipv6 neighbor-discover
y router-advertisement
set network interface ethernet <name> layer3 units <name> ipv6 neighbor-discover
set network interface ethernet <name> layer3 units <name> ipv6 neighbor-discover
set network interface ethernet <name> layer3 units <name> ipv6 neighbor-discover
set network interface ethernet <name> layer3 units <name> ipv6 neighbor-discover
set network interface ethernet <name> layer3 units <name> ipv6 neighbor-discover
set network interface ethernet <name> layer3 units <name> ipv6 neighbor-discover
set network interface ethernet <name> layer3 units <name> ipv6 neighbor-discover
set network interface ethernet <name> layer3 units <name> ipv6 neighbor-discover
set network interface ethernet <name> layer3 units <name> ipv6 neighbor-discover
set network interface ethernet <name> layer3 units <name> ipv6 neighbor-discover
set network interface ethernet <name> layer3 units <name> ipv6 neighbor-discover
set network interface ethernet <name> layer3 units <name> ipv6 neighbor-discover
y router-advertisement dns-support
set network interface ethernet <name> layer3 units <name> ipv6 neighbor-discover
set network interface ethernet <name> layer3 units <name> ipv6 neighbor-discover
set network interface ethernet <name> layer3 units <name> ipv6 neighbor-discover
set network interface ethernet <name> layer3 units <name> ipv6 neighbor-discover
set network interface ethernet <name> layer3 units <name> ipv6 neighbor-discover
set network interface ethernet <name> layer3 units <name> ipv6 neighbor-discover
set network interface ethernet <name> layer3 units <name> ipv6 neighbor-discover
y enable-ndp-monitor <yes|no>
set network interface ethernet <name> layer3 units <name> ipv6 neighbor-discover
y enable-dad <yes|no>
set network interface ethernet <name> layer3 units <name> ipv6 neighbor-discover
y dad-attempts <0-10>
set network interface ethernet <name> layer3 units <name> ipv6 neighbor-discover
y ns-interval <1-3600>
set network interface ethernet <name> layer3 units <name> ipv6 neighbor-discover
y reachable-time <10-36000>
set network interface ethernet <name> layer3 units <name> ipv6 neighbor-discover
y neighbor
set network interface ethernet <name> layer3 units <name> ipv6 neighbor-discover
y neighbor <name>
set network interface ethernet <name> layer3 units <name> ipv6 neighbor-discover
set network interface ethernet <name> layer3 units <name> arp <name>
set network interface ethernet <name> layer3 units <name> arp <name> hw-address
<value>
set network interface ethernet <name> layer3 units <name> ndp-proxy enabled <yes
|no>
set network interface ethernet <name> layer3 units <name> ndp-proxy address
set network interface ethernet <name> layer3 units <name> ndp-proxy address <nam
e>
set network interface ethernet <name> layer3 units <name> ndp-proxy address <nam
rofile <value>
set network interface ethernet <name> layer3 units <name> tag <1-4094>
set network interface ethernet <name> layer3 units <name> dhcp-client enable <ye
s|no>
set network interface ethernet <name> layer3 units <name> dhcp-client create-def
ault-route <yes|no>
set network interface ethernet <name> layer3 units <name> dhcp-client default-ro
ute-metric <1-65535>
set network interface ethernet <name> layer3 units <name> netflow-profile <value
>
set network interface ethernet <name> layer3 units <name> comment <value>
negotiation <yes|no>
slow>
>
set network interface aggregate-ethernet <name> virtual-wire units <name> tag <0
-4094>
w-profile <value>
t <value>
lue>
>
>
ity
set network interface aggregate-ethernet <name> layer2 units <name> tag <1-4094>
ile <value>
set network interface aggregate-ethernet <name> layer2 units <name> comment <val
ue>
o>
>
ast|slow>
5535>
e-same-system-mac
ssive-pre-negotiation <yes|no>
s|no>
djustment <40-300>
djustment <60-300>
es|no>
|<EUI-64>
set network interface aggregate-ethernet <name> layer3 ipv6 address <name> enabl
e-on-interface <yes|no>
set network interface aggregate-ethernet <name> layer3 ipv6 address <name> prefi
set network interface aggregate-ethernet <name> layer3 ipv6 address <name> anyca
st
set network interface aggregate-ethernet <name> layer3 ipv6 address <name> adver
tise
set network interface aggregate-ethernet <name> layer3 ipv6 address <name> adver
set network interface aggregate-ethernet <name> layer3 ipv6 address <name> adver
tise valid-lifetime <0-4294967294>|<infinity>
set network interface aggregate-ethernet <name> layer3 ipv6 address <name> adver
set network interface aggregate-ethernet <name> layer3 ipv6 address <name> adver
set network interface aggregate-ethernet <name> layer3 ipv6 address <name> adver
outer-advertisement
outer-advertisement dns-support
nable-ndp-monitor <yes|no>
nable-dad <yes|no>
ad-attempts <0-10>
s-interval <1-3600>
eachable-time <10-36000>
eighbor
eighbor <name>
set network interface aggregate-ethernet <name> layer3 ipv6 neighbor-discovery n
o>
>
ast|slow>
5535>
e-same-system-mac
ssive-pre-negotiation <yes|no>
ssive-pre-negotiation <yes|no>
set network interface aggregate-ethernet <name> layer3 arp <name> hw-address <va
lue>
set network interface aggregate-ethernet <name> layer3 ndp-proxy
>
negate <yes|no>
ile <value>
o>
t-route <yes|no>
-metric <1-65535>
ard <yes|no>
set network interface aggregate-ethernet <name> layer3 units <name> mtu <576-921
6>
ss
ss enable <yes|no>
ss ipv4-mss-adjustment <40-300>
ss ipv6-mss-adjustment <60-300>
set network interface aggregate-ethernet <name> layer3 units <name> ipv6 enabled
<yes|no>
set network interface aggregate-ethernet <name> layer3 units <name> ipv6 interfa
ce-id <value>|<EUI-64>
set network interface aggregate-ethernet <name> layer3 units <name> ipv6 address
set network interface aggregate-ethernet <name> layer3 units <name> ipv6 address
<name>
set network interface aggregate-ethernet <name> layer3 units <name> ipv6 address
set network interface aggregate-ethernet <name> layer3 units <name> ipv6 address
<name> prefix
set network interface aggregate-ethernet <name> layer3 units <name> ipv6 address
<name> anycast
set network interface aggregate-ethernet <name> layer3 units <name> ipv6 address
<name> advertise
set network interface aggregate-ethernet <name> layer3 units <name> ipv6 address
set network interface aggregate-ethernet <name> layer3 units <name> ipv6 address
set network interface aggregate-ethernet <name> layer3 units <name> ipv6 address
set network interface aggregate-ethernet <name> layer3 units <name> ipv6 address
set network interface aggregate-ethernet <name> layer3 units <name> ipv6 address
set network interface aggregate-ethernet <name> layer3 units <name> ipv6 neighbo
r-discovery
set network interface aggregate-ethernet <name> layer3 units <name> ipv6 neighbo
r-discovery router-advertisement
set network interface aggregate-ethernet <name> layer3 units <name> ipv6 neighbo
r-discovery router-advertisement enable <yes|no>
set network interface aggregate-ethernet <name> layer3 units <name> ipv6 neighbo
set network interface aggregate-ethernet <name> layer3 units <name> ipv6 neighbo
set network interface aggregate-ethernet <name> layer3 units <name> ipv6 neighbo
set network interface aggregate-ethernet <name> layer3 units <name> ipv6 neighbo
set network interface aggregate-ethernet <name> layer3 units <name> ipv6 neighbo
set network interface aggregate-ethernet <name> layer3 units <name> ipv6 neighbo
set network interface aggregate-ethernet <name> layer3 units <name> ipv6 neighbo
d>
set network interface aggregate-ethernet <name> layer3 units <name> ipv6 neighbo
set network interface aggregate-ethernet <name> layer3 units <name> ipv6 neighbo
set network interface aggregate-ethernet <name> layer3 units <name> ipv6 neighbo
set network interface aggregate-ethernet <name> layer3 units <name> ipv6 neighbo
set network interface aggregate-ethernet <name> layer3 units <name> ipv6 neighbo
set network interface aggregate-ethernet <name> layer3 units <name> ipv6 neighbo
set network interface aggregate-ethernet <name> layer3 units <name> ipv6 neighbo
set network interface aggregate-ethernet <name> layer3 units <name> ipv6 neighbo
set network interface aggregate-ethernet <name> layer3 units <name> ipv6 neighbo
set network interface aggregate-ethernet <name> layer3 units <name> ipv6 neighbo
set network interface aggregate-ethernet <name> layer3 units <name> ipv6 neighbo
set network interface aggregate-ethernet <name> layer3 units <name> ipv6 neighbo
set network interface aggregate-ethernet <name> layer3 units <name> ipv6 neighbo
set network interface aggregate-ethernet <name> layer3 units <name> ipv6 neighbo
set network interface aggregate-ethernet <name> layer3 units <name> ipv6 neighbo
set network interface aggregate-ethernet <name> layer3 units <name> ipv6 neighbo
set network interface aggregate-ethernet <name> layer3 units <name> ipv6 neighbo
r-discovery neighbor
set network interface aggregate-ethernet <name> layer3 units <name> ipv6 neighbo
set network interface aggregate-ethernet <name> layer3 units <name> ipv6 neighbo
set network interface aggregate-ethernet <name> layer3 units <name> arp <name>
set network interface aggregate-ethernet <name> layer3 units <name> arp <name> h
w-address <value>
abled <yes|no>
dress <name>
nagement-profile <value>
set network interface aggregate-ethernet <name> layer3 units <name> tag <1-4094>
enable <yes|no>
create-default-route <yes|no>
default-route-metric <1-65535>
ile <value>
set network interface aggregate-ethernet <name> layer3 units <name> comment <val
ue>
set network interface vlan ipv6 address <name> advertise enable <yes|no>
set network interface vlan ipv6 address <name> advertise valid-lifetime <0-42949
67294>|<infinity>
set network interface vlan ipv6 address <name> advertise preferred-lifetime <0-4
294967294>|<infinity>
set network interface vlan ipv6 address <name> advertise onlink-flag <yes|no>
set network interface vlan ipv6 address <name> advertise auto-config-flag <yes|n
o>
yes|no>
rval <4-1800>
rval <3-1350>
flag <yes|no>
ag <yes|no>
<1280-9216>|<unspecified>
e-time <0-3600000>|<unspecified>
ission-timer <0-4294967295>|<unspecified>
set network interface vlan ipv6 neighbor-discovery router-advertisement hop-limi
t <1-255>|<unspecified>
<0-9000>
reference <High|Medium|Low>
onsistency-check <yes|no>
ort
ort server
ort suffix
set network interface vlan ipv6 neighbor-discovery neighbor <name> hw-address <v
alue>
00>
00>
set network interface vlan units <name> ipv6 address <name> enable-on-interface
<yes|no>
set network interface vlan units <name> ipv6 address <name> prefix
set network interface vlan units <name> ipv6 address <name> anycast
set network interface vlan units <name> ipv6 address <name> advertise
set network interface vlan units <name> ipv6 address <name> advertise enable <ye
s|no>
set network interface vlan units <name> ipv6 address <name> advertise valid-life
time <0-4294967294>|<infinity>
set network interface vlan units <name> ipv6 address <name> advertise preferred-
lifetime <0-4294967294>|<infinity>
set network interface vlan units <name> ipv6 address <name> advertise onlink-fla
g <yes|no>
set network interface vlan units <name> ipv6 address <name> advertise auto-confi
g-flag <yes|no>
ment
ment dns-support
or <yes|no>
set network interface vlan units <name> ipv6 neighbor-discovery enable-dad <yes|
no>
set network interface vlan units <name> ipv6 neighbor-discovery dad-attempts <0-
10>
set network interface vlan units <name> ipv6 neighbor-discovery ns-interval <1-3
600>
set network interface vlan units <name> ipv6 neighbor-discovery reachable-time <
10-36000>
set network interface vlan units <name> ipv6 neighbor-discovery neighbor <name>
set network interface vlan units <name> ipv6 neighbor-discovery neighbor <name>
hw-address <value>
set network interface vlan units <name> arp <name> hw-address <value>
set network interface vlan units <name> arp <name> interface <value>
set network interface vlan units <name> ndp-proxy address <name> negate <yes|no>
>
5>
40-300>
60-300>
set network interface loopback units <name> ipv6 address <name> enable-on-interf
ace <yes|no>
set network interface loopback units <name> ipv6 address <name> prefix
set network interface loopback units <name> ipv6 address <name> anycast
set network interface loopback units <name> interface-management-profile <value>
set network interface tunnel units <name> ipv6 address <name> enable-on-interfac
e <yes|no>
set network interface tunnel units <name> ipv6 address <name> prefix
set network interface tunnel units <name> ipv6 address <name> anycast
set network interface tunnel units <name> interface-management-profile <value>
-and-url
alue>
ce <yes|no>
cation <yes|no>
tch <yes|no>
e>
set network ike gateway <name> protocol ikev1 dpd enable <yes|no>
set network ike gateway <name> protocol ikev1 dpd interval <2-100>
set network ike gateway <name> protocol ikev1 dpd retry <2-100>
set network ike gateway <name> protocol ikev2 dpd enable <yes|no>
set network ike gateway <name> protocol ikev2 dpd interval <2-100>
<10-3600>
<yes|no>
tion1> <encryption2>... ]
2>... ]
1> <dh-group2>... ]
-65535>
5535>
35>
le <0-50>
encryption1> <encryption2>... ]
[ <authentication1> <authentication2>... ]
[ <authentication1> <authentication2>... ]
oup1|group2|group5|group14|group19|group20>
80-65535>
-65535>
5535>
5>
5>
5>
5>
5>
set network tunnel ipsec <name> auto-key proxy-id <name> local <ip/netmask>
set network tunnel ipsec <name> auto-key proxy-id <name> remote <ip/netmask>
set network tunnel ipsec <name> auto-key proxy-id <name> protocol number <1-254>
set network tunnel ipsec <name> auto-key proxy-id <name> protocol any
set network tunnel ipsec <name> auto-key proxy-id <name> protocol tcp
set network tunnel ipsec <name> auto-key proxy-id <name> protocol tcp local-port
<0-65535>
set network tunnel ipsec <name> auto-key proxy-id <name> protocol tcp remote-por
t <0-65535>
set network tunnel ipsec <name> auto-key proxy-id <name> protocol udp
set network tunnel ipsec <name> auto-key proxy-id <name> protocol udp local-port
<0-65535>
set network tunnel ipsec <name> auto-key proxy-id <name> protocol udp remote-por
t <0-65535>
set network tunnel ipsec <name> auto-key proxy-id-v6 <name> local <ip/netmask>
set network tunnel ipsec <name> auto-key proxy-id-v6 <name> remote <ip/netmask>
set network tunnel ipsec <name> auto-key proxy-id-v6 <name> protocol number <1-2
54>
set network tunnel ipsec <name> auto-key proxy-id-v6 <name> protocol any
set network tunnel ipsec <name> auto-key proxy-id-v6 <name> protocol tcp
set network tunnel ipsec <name> auto-key proxy-id-v6 <name> protocol tcp local-p
ort <0-65535>
set network tunnel ipsec <name> auto-key proxy-id-v6 <name> protocol tcp remote-
port <0-65535>
set network tunnel ipsec <name> auto-key proxy-id-v6 <name> protocol udp
set network tunnel ipsec <name> auto-key proxy-id-v6 <name> protocol udp local-p
ort <0-65535>
set network tunnel ipsec <name> auto-key proxy-id-v6 <name> protocol udp remote-
port <0-65535>
set network tunnel ipsec <name> manual-key esp authentication md5 key <value>
set network tunnel ipsec <name> manual-key esp authentication sha1 key <value>
set network tunnel ipsec <name> manual-key esp authentication sha256 key <value>
set network tunnel ipsec <name> manual-key esp authentication sha384 key <value>
set network tunnel ipsec <name> manual-key esp authentication sha512 key <value>
set network tunnel ipsec <name> manual-key esp encryption algorithm <des|3des|ae
s-128-cbc|aes-192-cbc|aes-256-cbc|null>
set network tunnel ipsec <name> manual-key esp encryption key <value>
<value>
value>
value>
ip
ip ipv4 <value>
ip ipv6 <value>
ish-routes1> <publish-routes2>... ]
s enable <yes|no>
ficate <value>
-profile <value>
<ipv4|ipv6|ipv4_ipv6>
<value>
<value>
<yes|no>
name <value>
password <value>
noauth <yes|no>
ue>
>... ]
etmask>|<inherited>
/netmask>|<inherited>
netmask>|<validate>|<inherited>
p/netmask>|<validate>|<inherited>
s|no>
x1> <dns-suffix2>... ]
abled <yes|no>
amily <ipv4|ipv6|ipv4_ipv6>
alue>
ue>
set network tunnel global-protect-site-to-site <name> local-address ip ipv6 <val
ue>
ipv4 <value>
ipv6 <value>
rval <1-48>
1> <ip-pool2>... ]
<value>
<ip/netmask>|<inherited>
y <ip/netmask>|<inherited>
d <yes|no>
suffix1> <dns-suffix2>... ]
le <yes|no>
ination-ip <ip/netmask>
set network tunnel global-protect-site-to-site <name> client tunnel-monitor dest
ination-ipv6 <ip/netmask>
el-monitor-profile <value>
e <value>
utes <yes|no>
valid-networks1> <valid-networks2>... ]
>
set network qos profile <name> class <name> class-bandwidth egress-max <float>
set network qos profile <name> class <name> class-bandwidth egress-guaranteed <f
loat>
set network qos interface <name> tunnel-traffic groups <name> members <name>
set network qos interface <name> tunnel-traffic groups <name> members <name> qos
-profile <value>
file <value>
at>
set network qos interface <name> regular-traffic groups <name> members <name>
set network qos interface <name> regular-traffic groups <name> members <name> qo
s-profile <value>
set network qos interface <name> regular-traffic groups <name> members <name> ma
tch
set network qos interface <name> regular-traffic groups <name> members <name> ma
tch local-address
set network qos interface <name> regular-traffic groups <name> members <name> ma
set network qos interface <name> regular-traffic groups <name> members <name> ma
e>
oat>
on <ip/netmask>
<value>
iscard
p-address <ip/netmask>
ext-vr <value>
t <10-240>
-65535>
le
le
le unicast
le multicast
le both
le no-install
le <value>|<None>
tor
tor monitor-destinations
tion <ip/netmask>
ce <value>
discard
ipv6-address <ip/netmask>
next-vr <value>
ist <10-240>
set network virtual-router <name> routing-table ipv6 static-route <name> metric
<1-65535>
able
able
able unicast
able no-install
set network virtual-router <name> routing-table ipv6 static-route <name> bfd pro
file <value>|<None>
nitor
nitor monitor-destinations
value>
<interface1> <interface2>... ]
ion
ion any-source-multicast
ion source-specific-multicast
set network virtual-router <name> multicast interface-group <name> igmp enable <
yes|no>
<1|2|3>
y-response-time <float>
terval <1-31744>
ber-query-interval <float>
e-leave <yes|no>
ss <1|2|3|4|5|6|7>
ps <1-65535>|<unlimited>
ces <1-65535>|<unlimited>
lert-policing <yes|no>
set network virtual-router <name> multicast interface-group <name> pim enable <y
es|no>
terval <0-65534>
erval <0-18000>
e-interval <1-18000>
ty <0-4294967295>
set network virtual-router <name> multicast interface-group <name> pim bsr-borde
r <yes|no>
eighbors
eighbors <name>
ss <ip/netmask>
es|no>
94967295>|<never|0>
ue>
>
no>
s [ <group-addresses1> <group-addresses2>... ]
value>
-255>
nt-interval <1-26214>
s [ <group-addresses1> <group-addresses2>... ]
no>
>
<type1> <type2>... ]
e [ <interface1> <interface2>... ]
[ <nexthop1> <nexthop2>... ]
set network virtual-router <name> protocol redist-profile <name> filter ospf pat
set network virtual-router <name> protocol redist-profile <name> filter ospf are
a [ <area1> <area2>... ]
set network virtual-router <name> protocol redist-profile <name> filter ospf tag
[ <tag1> <tag2>... ]
set network virtual-router <name> protocol redist-profile <name> filter bgp comm
set network virtual-router <name> protocol redist-profile <name> filter bgp exte
1-255>
e [ <type1> <type2>... ]
fv3
redist
ist
o>
set network virtual-router <name> protocol rip auth-profile <name> password <val
ue>
set network virtual-router <name> protocol rip auth-profile <name> md5 <name>
set network virtual-router <name> protocol rip auth-profile <name> md5 <name> ke
y <value>
set network virtual-router <name> protocol rip auth-profile <name> md5 <name> pr
eferred <yes|no>
set network virtual-router <name> protocol rip global-bfd
set network virtual-router <name> protocol rip interface <name> enable <yes|no>
sable
vertise
set network virtual-router <name> protocol rip interface <name> authentication <
value>
set network virtual-router <name> protocol rip interface <name> mode <normal|pas
sive|send-only>
set network virtual-router <name> protocol rip interface <name> bfd profile <val
ue>|<None|Inherit-vr-global-setting>
set network virtual-router <name> protocol rip export-rules <name> metric <1-16>
no>
oat>
set network virtual-router <name> protocol ospf timers lsa-interval <float>
set network virtual-router <name> protocol ospf auth-profile <name> password <va
lue>
set network virtual-router <name> protocol ospf auth-profile <name> md5 <name>
set network virtual-router <name> protocol ospf auth-profile <name> md5 <name> k
ey <value>
set network virtual-router <name> protocol ospf auth-profile <name> md5 <name> p
referred <yes|no>
>
set network virtual-router <name> protocol ospf area <name> type normal
set network virtual-router <name> protocol ospf area <name> type stub
set network virtual-router <name> protocol ospf area <name> type stub accept-sum
mary <yes|no>
set network virtual-router <name> protocol ospf area <name> type stub default-ro
ute
set network virtual-router <name> protocol ospf area <name> type stub default-ro
ute disable
set network virtual-router <name> protocol ospf area <name> type stub default-ro
ute advertise
set network virtual-router <name> protocol ospf area <name> type stub default-ro
set network virtual-router <name> protocol ospf area <name> type nssa
set network virtual-router <name> protocol ospf area <name> type nssa accept-sum
mary <yes|no>
set network virtual-router <name> protocol ospf area <name> type nssa default-ro
ute
set network virtual-router <name> protocol ospf area <name> type nssa default-ro
ute disable
set network virtual-router <name> protocol ospf area <name> type nssa default-ro
ute advertise
set network virtual-router <name> protocol ospf area <name> type nssa default-ro
set network virtual-router <name> protocol ospf area <name> type nssa default-ro
set network virtual-router <name> protocol ospf area <name> type nssa nssa-ext-r
ange
set network virtual-router <name> protocol ospf area <name> type nssa nssa-ext-r
ange <name>
set network virtual-router <name> protocol ospf area <name> type nssa nssa-ext-r
ange <name>
set network virtual-router <name> protocol ospf area <name> type nssa nssa-ext-r
set network virtual-router <name> protocol ospf area <name> type nssa nssa-ext-r
set network virtual-router <name> protocol ospf area <name> range <name>
set network virtual-router <name> protocol ospf area <name> range <name>
set network virtual-router <name> protocol ospf area <name> range <name> adverti
se
set network virtual-router <name> protocol ospf area <name> range <name> suppres
set network virtual-router <name> protocol ospf area <name> interface <name>
set network virtual-router <name> protocol ospf area <name> interface <name> ena
ble <yes|no>
set network virtual-router <name> protocol ospf area <name> interface <name> pas
sive <yes|no>
set network virtual-router <name> protocol ospf area <name> interface <name> lin
k-type
set network virtual-router <name> protocol ospf area <name> interface <name> lin
k-type broadcast
set network virtual-router <name> protocol ospf area <name> interface <name> lin
k-type p2p
set network virtual-router <name> protocol ospf area <name> interface <name> lin
k-type p2mp
set network virtual-router <name> protocol ospf area <name> interface <name> met
ric <1-65535>
set network virtual-router <name> protocol ospf area <name> interface <name> pri
ority <0-255>
set network virtual-router <name> protocol ospf area <name> interface <name> hel
lo-interval <0-3600>
set network virtual-router <name> protocol ospf area <name> interface <name> dea
d-counts <3-20>
set network virtual-router <name> protocol ospf area <name> interface <name> ret
ransmit-interval <1-3600>
set network virtual-router <name> protocol ospf area <name> interface <name> tra
nsit-delay <1-3600>
set network virtual-router <name> protocol ospf area <name> interface <name> aut
hentication <value>
set network virtual-router <name> protocol ospf area <name> interface <name> gr-
delay <1-10>
set network virtual-router <name> protocol ospf area <name> interface <name> nei
ghbor
set network virtual-router <name> protocol ospf area <name> interface <name> nei
ghbor <name>
set network virtual-router <name> protocol ospf area <name> interface <name> bfd
set network virtual-router <name> protocol ospf area <name> interface <name> bfd
profile <value>|<None|Inherit-vr-global-setting>
set network virtual-router <name> protocol ospf area <name> virtual-link <name>
set network virtual-router <name> protocol ospf area <name> virtual-link <name>
neighbor-id <ip/netmask>
set network virtual-router <name> protocol ospf area <name> virtual-link <name>
transit-area-id <value>
set network virtual-router <name> protocol ospf area <name> virtual-link <name>
enable <yes|no>
set network virtual-router <name> protocol ospf area <name> virtual-link <name>
hello-interval <0-3600>
set network virtual-router <name> protocol ospf area <name> virtual-link <name>
dead-counts <3-20>
set network virtual-router <name> protocol ospf area <name> virtual-link <name>
retransmit-interval <1-3600>
set network virtual-router <name> protocol ospf area <name> virtual-link <name>
transit-delay <1-3600>
set network virtual-router <name> protocol ospf area <name> virtual-link <name>
authentication <value>
set network virtual-router <name> protocol ospf area <name> virtual-link <name>
bfd
set network virtual-router <name> protocol ospf area <name> virtual-link <name>
e <ext-1|ext-2>
set network virtual-router <name> protocol ospf export-rules <name> new-tag <1-4
294967295>|<ip/netmask>
set network virtual-router <name> protocol ospf export-rules <name> metric <1-65
535>
set network virtual-router <name> protocol ospf graceful-restart
-1800>
yes|no>
king <yes|no>
start-time <5-1800>
s|no>
o>
float>
set network virtual-router <name> protocol ospfv3 auth-profile <name> spi <value
>
set network virtual-router <name> protocol ospfv3 auth-profile <name> esp authen
tication
set network virtual-router <name> protocol ospfv3 auth-profile <name> esp authen
tication
set network virtual-router <name> protocol ospfv3 auth-profile <name> esp authen
tication md5
set network virtual-router <name> protocol ospfv3 auth-profile <name> esp authen
set network virtual-router <name> protocol ospfv3 auth-profile <name> esp authen
tication sha1
set network virtual-router <name> protocol ospfv3 auth-profile <name> esp authen
set network virtual-router <name> protocol ospfv3 auth-profile <name> esp authen
tication sha256
set network virtual-router <name> protocol ospfv3 auth-profile <name> esp authen
set network virtual-router <name> protocol ospfv3 auth-profile <name> esp authen
tication sha384
set network virtual-router <name> protocol ospfv3 auth-profile <name> esp authen
set network virtual-router <name> protocol ospfv3 auth-profile <name> esp authen
tication sha512
set network virtual-router <name> protocol ospfv3 auth-profile <name> esp authen
set network virtual-router <name> protocol ospfv3 auth-profile <name> esp authen
tication none
set network virtual-router <name> protocol ospfv3 auth-profile <name> esp encryp
tion
set network virtual-router <name> protocol ospfv3 auth-profile <name> esp encryp
set network virtual-router <name> protocol ospfv3 auth-profile <name> esp encryp
set network virtual-router <name> protocol ospfv3 auth-profile <name> ah md5 key
<value>
y <value>
key <value>
key <value>
key <value>
ne>
set network virtual-router <name> protocol ospfv3 area <name> authentication <va
lue>
set network virtual-router <name> protocol ospfv3 area <name> type normal
set network virtual-router <name> protocol ospfv3 area <name> type stub
set network virtual-router <name> protocol ospfv3 area <name> type stub accept-s
ummary <yes|no>
set network virtual-router <name> protocol ospfv3 area <name> type stub default-
route
set network virtual-router <name> protocol ospfv3 area <name> type stub default-
route disable
set network virtual-router <name> protocol ospfv3 area <name> type stub default-
route advertise
set network virtual-router <name> protocol ospfv3 area <name> type stub default-
route advertise metric <1-16777215>
set network virtual-router <name> protocol ospfv3 area <name> type nssa
set network virtual-router <name> protocol ospfv3 area <name> type nssa accept-s
ummary <yes|no>
set network virtual-router <name> protocol ospfv3 area <name> type nssa default-
route
set network virtual-router <name> protocol ospfv3 area <name> type nssa default-
route disable
set network virtual-router <name> protocol ospfv3 area <name> type nssa default-
route advertise
set network virtual-router <name> protocol ospfv3 area <name> type nssa default-
set network virtual-router <name> protocol ospfv3 area <name> type nssa default-
set network virtual-router <name> protocol ospfv3 area <name> type nssa nssa-ext
-range
set network virtual-router <name> protocol ospfv3 area <name> type nssa nssa-ext
-range <name>
set network virtual-router <name> protocol ospfv3 area <name> type nssa nssa-ext
-range <name>
set network virtual-router <name> protocol ospfv3 area <name> type nssa nssa-ext
set network virtual-router <name> protocol ospfv3 area <name> type nssa nssa-ext
set network virtual-router <name> protocol ospfv3 area <name> range <name>
set network virtual-router <name> protocol ospfv3 area <name> range <name>
set network virtual-router <name> protocol ospfv3 area <name> range <name> adver
tise
set network virtual-router <name> protocol ospfv3 area <name> range <name> suppr
ess
set network virtual-router <name> protocol ospfv3 area <name> interface <name> e
nable <yes|no>
set network virtual-router <name> protocol ospfv3 area <name> interface <name> i
nstance-id <0-255>
set network virtual-router <name> protocol ospfv3 area <name> interface <name> p
assive <yes|no>
set network virtual-router <name> protocol ospfv3 area <name> interface <name> l
ink-type
set network virtual-router <name> protocol ospfv3 area <name> interface <name> l
ink-type broadcast
set network virtual-router <name> protocol ospfv3 area <name> interface <name> l
ink-type p2p
set network virtual-router <name> protocol ospfv3 area <name> interface <name> l
ink-type p2mp
set network virtual-router <name> protocol ospfv3 area <name> interface <name> m
etric <1-65535>
set network virtual-router <name> protocol ospfv3 area <name> interface <name> p
riority <0-255>
set network virtual-router <name> protocol ospfv3 area <name> interface <name> h
ello-interval <1-3600>
set network virtual-router <name> protocol ospfv3 area <name> interface <name> d
ead-counts <3-20>
set network virtual-router <name> protocol ospfv3 area <name> interface <name> r
etransmit-interval <1-1800>
set network virtual-router <name> protocol ospfv3 area <name> interface <name> t
ransit-delay <1-1800>
set network virtual-router <name> protocol ospfv3 area <name> interface <name> a
uthentication <value>
set network virtual-router <name> protocol ospfv3 area <name> interface <name> g
r-delay <1-10>
set network virtual-router <name> protocol ospfv3 area <name> interface <name> n
eighbor
set network virtual-router <name> protocol ospfv3 area <name> interface <name> n
eighbor <name>
set network virtual-router <name> protocol ospfv3 area <name> interface <name> b
fd
set network virtual-router <name> protocol ospfv3 area <name> interface <name> b
fd profile <value>|<None|Inherit-vr-global-setting>
set network virtual-router <name> protocol ospfv3 area <name> virtual-link <name
>
set network virtual-router <name> protocol ospfv3 area <name> virtual-link <name
set network virtual-router <name> protocol ospfv3 area <name> virtual-link <name
set network virtual-router <name> protocol ospfv3 area <name> virtual-link <name
set network virtual-router <name> protocol ospfv3 area <name> virtual-link <name
set network virtual-router <name> protocol ospfv3 area <name> virtual-link <name
set network virtual-router <name> protocol ospfv3 area <name> virtual-link <name
set network virtual-router <name> protocol ospfv3 area <name> virtual-link <name
set network virtual-router <name> protocol ospfv3 area <name> virtual-link <name
set network virtual-router <name> protocol ospfv3 area <name> virtual-link <name
set network virtual-router <name> protocol ospfv3 area <name> virtual-link <name
> bfd
set network virtual-router <name> protocol ospfv3 area <name> virtual-link <name
ype <ext-1|ext-2>
set network virtual-router <name> protocol ospfv3 export-rules <name> new-tag <1
-4294967295>|<ip/netmask>
set network virtual-router <name> protocol ospfv3 export-rules <name> metric <1-
16777215>
o>
<5-1800>
<yes|no>
ecking <yes|no>
restart-time <5-1800>
o>
|4-byte>
set network virtual-router <name> protocol bgp routing-options med
e-med <yes|no>
-med-comparison <yes|no>
ference <0-4294967295>
enable <yes|no>
stale-route-time <1-3600>
local-restart-time <1-3600>
max-peer-restart-time <1-3600>
-id <ip/netmask>
ber-as <1-4294967295>|<value>
te-med <yes|no>
set network virtual-router <name> protocol bgp auth-profile <name> secret <value
>
set network virtual-router <name> protocol bgp dampening-profile <name> enable <
yes|no>
set network virtual-router <name> protocol bgp dampening-profile <name> cutoff <
float>
set network virtual-router <name> protocol bgp dampening-profile <name> reuse <f
loat>
-time <1-3600>
lf-life-reachable <1-3600>
lf-life-unreachable <1-3600>
set network virtual-router <name> protocol bgp peer-group <name> enable <yes|no>
ed-as-path <yes|no>
-stored-info <yes|no>
set network virtual-router <name> protocol bgp peer-group <name> type ibgp
set network virtual-router <name> protocol bgp peer-group <name> type ibgp expor
t-nexthop <original|use-self>
set network virtual-router <name> protocol bgp peer-group <name> type ebgp-confe
set network virtual-router <name> protocol bgp peer-group <name> type ebgp-confe
d export-nexthop <original|use-self>
set network virtual-router <name> protocol bgp peer-group <name> type ibgp-confe
set network virtual-router <name> protocol bgp peer-group <name> type ibgp-confe
d export-nexthop <original|use-self>
set network virtual-router <name> protocol bgp peer-group <name> type ebgp
set network virtual-router <name> protocol bgp peer-group <name> type ebgp impor
t-nexthop <original|use-peer>
set network virtual-router <name> protocol bgp peer-group <name> type ebgp expor
t-nexthop <resolve|use-self>
set network virtual-router <name> protocol bgp peer-group <name> type ebgp remov
e-private-as <yes|no>
set network virtual-router <name> protocol bgp peer-group <name> peer <name>
set network virtual-router <name> protocol bgp peer-group <name> peer <name> ena
ble <yes|no>
set network virtual-router <name> protocol bgp peer-group <name> peer <name> pee
r-as <1-4294967295>|<value>
set network virtual-router <name> protocol bgp peer-group <name> peer <name> ena
ble-mp-bgp <yes|no>
set network virtual-router <name> protocol bgp peer-group <name> peer <name> add
ress-family-identifier <ipv4|ipv6>
set network virtual-router <name> protocol bgp peer-group <name> peer <name> sub
sequent-address-family-identifier
set network virtual-router <name> protocol bgp peer-group <name> peer <name> sub
set network virtual-router <name> protocol bgp peer-group <name> peer <name> sub
set network virtual-router <name> protocol bgp peer-group <name> peer <name> loc
al-address
set network virtual-router <name> protocol bgp peer-group <name> peer <name> loc
set network virtual-router <name> protocol bgp peer-group <name> peer <name> loc
al-address ip <value>
set network virtual-router <name> protocol bgp peer-group <name> peer <name> pee
r-address
set network virtual-router <name> protocol bgp peer-group <name> peer <name> pee
r-address ip <ip/netmask>
set network virtual-router <name> protocol bgp peer-group <name> peer <name> con
nection-options
set network virtual-router <name> protocol bgp peer-group <name> peer <name> con
set network virtual-router <name> protocol bgp peer-group <name> peer <name> con
set network virtual-router <name> protocol bgp peer-group <name> peer <name> con
set network virtual-router <name> protocol bgp peer-group <name> peer <name> con
set network virtual-router <name> protocol bgp peer-group <name> peer <name> con
set network virtual-router <name> protocol bgp peer-group <name> peer <name> con
set network virtual-router <name> protocol bgp peer-group <name> peer <name> con
set network virtual-router <name> protocol bgp peer-group <name> peer <name> con
nection-options incoming-bgp-connection
set network virtual-router <name> protocol bgp peer-group <name> peer <name> con
set network virtual-router <name> protocol bgp peer-group <name> peer <name> con
set network virtual-router <name> protocol bgp peer-group <name> peer <name> con
nection-options outgoing-bgp-connection
set network virtual-router <name> protocol bgp peer-group <name> peer <name> con
set network virtual-router <name> protocol bgp peer-group <name> peer <name> con
set network virtual-router <name> protocol bgp peer-group <name> peer <name> ena
ble-sender-side-loop-detection <yes|no>
set network virtual-router <name> protocol bgp peer-group <name> peer <name> ref
lector-client <non-client|client|meshed-client>
set network virtual-router <name> protocol bgp peer-group <name> peer <name> pee
ring-type <bilateral|unspecified>
set network virtual-router <name> protocol bgp peer-group <name> peer <name> max
-prefixes <1-100000>|<unlimited>
set network virtual-router <name> protocol bgp peer-group <name> peer <name> bfd
set network virtual-router <name> protocol bgp peer-group <name> peer <name> bfd
profile <value>|<None|Inherit-vr-global-setting>
set network virtual-router <name> protocol bgp policy import rules <name>
set network virtual-router <name> protocol bgp policy import rules <name> enable
<yes|no>
set network virtual-router <name> protocol bgp policy import rules <name> used-b
y [ <used-by1> <used-by2>... ]
set network virtual-router <name> protocol bgp policy import rules <name> match
set network virtual-router <name> protocol bgp policy import rules <name> match
route-table <unicast|multicast|both>
set network virtual-router <name> protocol bgp policy import rules <name> match
address-prefix
set network virtual-router <name> protocol bgp policy import rules <name> match
address-prefix <name>
set network virtual-router <name> protocol bgp policy import rules <name> match
set network virtual-router <name> protocol bgp policy import rules <name> match
set network virtual-router <name> protocol bgp policy import rules <name> match
set network virtual-router <name> protocol bgp policy import rules <name> match
med <0-4294967295>
set network virtual-router <name> protocol bgp policy import rules <name> match
as-path
set network virtual-router <name> protocol bgp policy import rules <name> match
as-path
set network virtual-router <name> protocol bgp policy import rules <name> match
set network virtual-router <name> protocol bgp policy import rules <name> match
community
set network virtual-router <name> protocol bgp policy import rules <name> match
community
set network virtual-router <name> protocol bgp policy import rules <name> match
set network virtual-router <name> protocol bgp policy import rules <name> match
extended-community
set network virtual-router <name> protocol bgp policy import rules <name> match
extended-community
set network virtual-router <name> protocol bgp policy import rules <name> match
set network virtual-router <name> protocol bgp policy import rules <name> action
set network virtual-router <name> protocol bgp policy import rules <name> action
set network virtual-router <name> protocol bgp policy import rules <name> action
deny
set network virtual-router <name> protocol bgp policy import rules <name> action
allow
set network virtual-router <name> protocol bgp policy import rules <name> action
set network virtual-router <name> protocol bgp policy import rules <name> action
allow update
set network virtual-router <name> protocol bgp policy import rules <name> action
set network virtual-router <name> protocol bgp policy import rules <name> action
set network virtual-router <name> protocol bgp policy import rules <name> action
set network virtual-router <name> protocol bgp policy import rules <name> action
set network virtual-router <name> protocol bgp policy import rules <name> action
set network virtual-router <name> protocol bgp policy import rules <name> action
set network virtual-router <name> protocol bgp policy import rules <name> action
set network virtual-router <name> protocol bgp policy import rules <name> action
set network virtual-router <name> protocol bgp policy import rules <name> action
set network virtual-router <name> protocol bgp policy import rules <name> action
set network virtual-router <name> protocol bgp policy import rules <name> action
set network virtual-router <name> protocol bgp policy import rules <name> action
set network virtual-router <name> protocol bgp policy import rules <name> action
set network virtual-router <name> protocol bgp policy import rules <name> action
set network virtual-router <name> protocol bgp policy import rules <name> action
set network virtual-router <name> protocol bgp policy import rules <name> action
set network virtual-router <name> protocol bgp policy import rules <name> action
set network virtual-router <name> protocol bgp policy import rules <name> action
set network virtual-router <name> protocol bgp policy import rules <name> action
set network virtual-router <name> protocol bgp policy import rules <name> action
set network virtual-router <name> protocol bgp policy import rules <name> action
set network virtual-router <name> protocol bgp policy import rules <name> action
set network virtual-router <name> protocol bgp policy export rules <name>
set network virtual-router <name> protocol bgp policy export rules <name> enable
<yes|no>
set network virtual-router <name> protocol bgp policy export rules <name> used-b
y [ <used-by1> <used-by2>... ]
set network virtual-router <name> protocol bgp policy export rules <name> match
set network virtual-router <name> protocol bgp policy export rules <name> match
route-table <unicast|multicast|both>
set network virtual-router <name> protocol bgp policy export rules <name> match
address-prefix
set network virtual-router <name> protocol bgp policy export rules <name> match
address-prefix <name>
set network virtual-router <name> protocol bgp policy export rules <name> match
set network virtual-router <name> protocol bgp policy export rules <name> match
set network virtual-router <name> protocol bgp policy export rules <name> match
med <0-4294967295>
set network virtual-router <name> protocol bgp policy export rules <name> match
as-path
set network virtual-router <name> protocol bgp policy export rules <name> match
as-path
set network virtual-router <name> protocol bgp policy export rules <name> match
set network virtual-router <name> protocol bgp policy export rules <name> match
community
set network virtual-router <name> protocol bgp policy export rules <name> match
community
set network virtual-router <name> protocol bgp policy export rules <name> match
set network virtual-router <name> protocol bgp policy export rules <name> match
extended-community
set network virtual-router <name> protocol bgp policy export rules <name> match
extended-community
set network virtual-router <name> protocol bgp policy export rules <name> match
set network virtual-router <name> protocol bgp policy export rules <name> action
set network virtual-router <name> protocol bgp policy export rules <name> action
set network virtual-router <name> protocol bgp policy export rules <name> action
deny
set network virtual-router <name> protocol bgp policy export rules <name> action
allow
set network virtual-router <name> protocol bgp policy export rules <name> action
allow update
set network virtual-router <name> protocol bgp policy export rules <name> action
set network virtual-router <name> protocol bgp policy export rules <name> action
set network virtual-router <name> protocol bgp policy export rules <name> action
set network virtual-router <name> protocol bgp policy export rules <name> action
set network virtual-router <name> protocol bgp policy export rules <name> action
set network virtual-router <name> protocol bgp policy export rules <name> action
set network virtual-router <name> protocol bgp policy export rules <name> action
set network virtual-router <name> protocol bgp policy export rules <name> action
set network virtual-router <name> protocol bgp policy export rules <name> action
set network virtual-router <name> protocol bgp policy export rules <name> action
set network virtual-router <name> protocol bgp policy export rules <name> action
set network virtual-router <name> protocol bgp policy export rules <name> action
set network virtual-router <name> protocol bgp policy export rules <name> action
set network virtual-router <name> protocol bgp policy export rules <name> action
set network virtual-router <name> protocol bgp policy export rules <name> action
set network virtual-router <name> protocol bgp policy export rules <name> action
set network virtual-router <name> protocol bgp policy export rules <name> action
set network virtual-router <name> protocol bgp policy export rules <name> action
set network virtual-router <name> protocol bgp policy export rules <name> action
set network virtual-router <name> protocol bgp policy export rules <name> action
set network virtual-router <name> protocol bgp policy export rules <name> action
set network virtual-router <name> protocol bgp policy export rules <name> action
set network virtual-router <name> protocol bgp policy export rules <name> action
policy
policy <name>
>
r2>... ]
>
r2>... ]
set network virtual-router <name> protocol bgp policy aggregation address <name>
set network virtual-router <name> protocol bgp policy aggregation address <name>
prefix <ip/netmask>
set network virtual-router <name> protocol bgp policy aggregation address <name>
enable <yes|no>
set network virtual-router <name> protocol bgp policy aggregation address <name>
summary <yes|no>
set network virtual-router <name> protocol bgp policy aggregation address <name>
as-set <yes|no>
set network virtual-router <name> protocol bgp policy aggregation address <name>
aggregate-route-attributes
set network virtual-router <name> protocol bgp policy aggregation address <name>
set network virtual-router <name> protocol bgp policy aggregation address <name>
set network virtual-router <name> protocol bgp policy aggregation address <name>
set network virtual-router <name> protocol bgp policy aggregation address <name>
aggregate-route-attributes nexthop <ip/netmask>
set network virtual-router <name> protocol bgp policy aggregation address <name>
set network virtual-router <name> protocol bgp policy aggregation address <name>
set network virtual-router <name> protocol bgp policy aggregation address <name>
aggregate-route-attributes as-path
set network virtual-router <name> protocol bgp policy aggregation address <name>
aggregate-route-attributes as-path
set network virtual-router <name> protocol bgp policy aggregation address <name>
set network virtual-router <name> protocol bgp policy aggregation address <name>
set network virtual-router <name> protocol bgp policy aggregation address <name>
aggregate-route-attributes community
set network virtual-router <name> protocol bgp policy aggregation address <name>
aggregate-route-attributes community
set network virtual-router <name> protocol bgp policy aggregation address <name>
set network virtual-router <name> protocol bgp policy aggregation address <name>
set network virtual-router <name> protocol bgp policy aggregation address <name>
set network virtual-router <name> protocol bgp policy aggregation address <name>
set network virtual-router <name> protocol bgp policy aggregation address <name>
set network virtual-router <name> protocol bgp policy aggregation address <name>
aggregate-route-attributes extended-community
set network virtual-router <name> protocol bgp policy aggregation address <name>
aggregate-route-attributes extended-community
set network virtual-router <name> protocol bgp policy aggregation address <name>
set network virtual-router <name> protocol bgp policy aggregation address <name>
set network virtual-router <name> protocol bgp policy aggregation address <name>
set network virtual-router <name> protocol bgp policy aggregation address <name>
set network virtual-router <name> protocol bgp policy aggregation address <name>
ite2>... ]
set network virtual-router <name> protocol bgp policy aggregation address <name>
suppress-filters
set network virtual-router <name> protocol bgp policy aggregation address <name>
suppress-filters <name>
set network virtual-router <name> protocol bgp policy aggregation address <name>
set network virtual-router <name> protocol bgp policy aggregation address <name>
set network virtual-router <name> protocol bgp policy aggregation address <name>
set network virtual-router <name> protocol bgp policy aggregation address <name>
set network virtual-router <name> protocol bgp policy aggregation address <name>
set network virtual-router <name> protocol bgp policy aggregation address <name>
set network virtual-router <name> protocol bgp policy aggregation address <name>
set network virtual-router <name> protocol bgp policy aggregation address <name>
set network virtual-router <name> protocol bgp policy aggregation address <name>
set network virtual-router <name> protocol bgp policy aggregation address <name>
set network virtual-router <name> protocol bgp policy aggregation address <name>
set network virtual-router <name> protocol bgp policy aggregation address <name>
set network virtual-router <name> protocol bgp policy aggregation address <name>
set network virtual-router <name> protocol bgp policy aggregation address <name>
set network virtual-router <name> protocol bgp policy aggregation address <name>
set network virtual-router <name> protocol bgp policy aggregation address <name>
set network virtual-router <name> protocol bgp policy aggregation address <name>
set network virtual-router <name> protocol bgp policy aggregation address <name>
advertise-filters
set network virtual-router <name> protocol bgp policy aggregation address <name>
advertise-filters <name>
set network virtual-router <name> protocol bgp policy aggregation address <name>
set network virtual-router <name> protocol bgp policy aggregation address <name>
set network virtual-router <name> protocol bgp policy aggregation address <name>
set network virtual-router <name> protocol bgp policy aggregation address <name>
set network virtual-router <name> protocol bgp policy aggregation address <name>
set network virtual-router <name> protocol bgp policy aggregation address <name>
set network virtual-router <name> protocol bgp policy aggregation address <name>
set network virtual-router <name> protocol bgp policy aggregation address <name>
set network virtual-router <name> protocol bgp policy aggregation address <name>
set network virtual-router <name> protocol bgp policy aggregation address <name>
set network virtual-router <name> protocol bgp policy aggregation address <name>
set network virtual-router <name> protocol bgp policy aggregation address <name>
set network virtual-router <name> protocol bgp policy aggregation address <name>
set network virtual-router <name> protocol bgp policy aggregation address <name>
set network virtual-router <name> protocol bgp policy aggregation address <name>
set network virtual-router <name> protocol bgp policy aggregation address <name>
set network virtual-router <name> protocol bgp policy aggregation address <name>
y-identifier <ipv4|ipv6>
set network virtual-router <name> protocol bgp redist-rules <name> route-table <
unicast|multicast|both>
set network virtual-router <name> protocol bgp redist-rules <name> enable <yes|n
o>
set network virtual-router <name> protocol bgp redist-rules <name> set-origin <i
gp|egp|incomplete>
set network virtual-router <name> protocol bgp redist-rules <name> set-med <0-42
94967295>
ference <0-4294967295>
imit <1-255>
[ <set-community1> <set-community2>... ]
set network virtual-router <name> protocol bgp redist-rules <name> metric <1-655
35>
>
<name>
d>
<domain-name2>... ]
s2>... ]
set network dhcp interface <name> server option lease timeout <0-1000000>
set network dhcp interface <name> server option inheritance source <value>
set network dhcp interface <name> server option gateway <ip/netmask>
set network dhcp interface <name> server option dns primary <ip/netmask>|<inheri
ted>
set network dhcp interface <name> server option dns secondary <ip/netmask>|<inhe
rited>
set network dhcp interface <name> server option wins primary <ip/netmask>|<inher
ited>
set network dhcp interface <name> server option wins secondary <ip/netmask>|<inh
erited>
set network dhcp interface <name> server option nis primary <ip/netmask>|<inheri
ted>
set network dhcp interface <name> server option nis secondary <ip/netmask>|<inhe
rited>
set network dhcp interface <name> server option ntp primary <ip/netmask>|<inheri
ted>
set network dhcp interface <name> server option ntp secondary <ip/netmask>|<inhe
rited>
ted>
ted>
set network dhcp interface <name> server option user-defined <name> code <1-254>
set network dhcp interface <name> server option user-defined <name> vendor-class
-identifier <value>
set network dhcp interface <name> server option user-defined <name> inherited <y
es|no>
set network dhcp interface <name> server option user-defined <name> ip [ <ip1>
<ip2>... ]
set network dhcp interface <name> server option user-defined <name> ascii [ <as
cii1> <ascii2>... ]
set network dhcp interface <name> server option user-defined <name> hex [ <hex1
> <hex2>... ]
set network dhcp interface <name> server reserved <name> mac <value>
set network dhcp interface <name> relay ipv6 server <name> interface <value>
rface2>... ]
alue>
ction <yes|no>
set network shared-gateway <name> zone <name> network layer3 [ <layer31> <layer
32>... ]
set network shared-gateway <name> zone <name> network external [ <external1> <e
xternal2>... ]
list1> <include-list2>... ]
list1> <exclude-list2>... ]
ic2>... ]
set network shared-gateway <name> service <name> protocol tcp port <0-65535,...>
set network shared-gateway <name> service <name> protocol tcp source-port <0-655
35,...>
set network shared-gateway <name> service <name> protocol tcp override yes
set network shared-gateway <name> service <name> protocol tcp override yes timeo
ut <1-604800>
set network shared-gateway <name> service <name> protocol tcp override yes halfc
lose-timeout <1-604800>
set network shared-gateway <name> service <name> protocol tcp override yes timew
ait-timeout <1-600>
set network shared-gateway <name> service <name> protocol udp port <0-65535,...>
set network shared-gateway <name> service <name> protocol udp source-port <0-655
35,...>
set network shared-gateway <name> service <name> protocol udp override yes
set network shared-gateway <name> service <name> protocol udp override yes timeo
ut <1-604800>
set network shared-gateway <name> service <name> protocol sctp port <0-65535,...
>
set network shared-gateway <name> service <name> protocol sctp source-port <0-65
535,...>
set network shared-gateway <name> service <name> tag [ <tag1> <tag2>... ]
mbers2>... ]
color5|color6|color7|color8|color9|color10|color11|color12|color13|color14|color
15|color16|color17|color19|color20|color21|color22|color23|color24|color25|color
26|color27|color28|color29|color30|color31|color32|color33|color34|color35|color
36|color37|color38|color39|color40|color41|color42>
set network shared-gateway <name> log-settings snmptrap <name> version v2c serve
set network shared-gateway <name> log-settings snmptrap <name> version v2c serve
r <name>
set network shared-gateway <name> log-settings snmptrap <name> version v2c serve
set network shared-gateway <name> log-settings snmptrap <name> version v2c serve
<name>
set network shared-gateway <name> log-settings snmptrap <name> version v3 server
set network shared-gateway <name> log-settings email <name> server <name> displa
y-name <value>
set network shared-gateway <name> log-settings email <name> server <name> from <
value>
set network shared-gateway <name> log-settings email <name> server <name> to <va
lue>
set network shared-gateway <name> log-settings email <name> server <name> and-al
so-to <value>
set network shared-gateway <name> log-settings email <name> server <name> gatewa
y <value>
set network shared-gateway <name> log-settings email <name> format traffic <valu
e>
set network shared-gateway <name> log-settings email <name> format threat <value
>
set network shared-gateway <name> log-settings email <name> format wildfire <val
ue>
set network shared-gateway <name> log-settings email <name> format url <value>
set network shared-gateway <name> log-settings email <name> format data <value>
set network shared-gateway <name> log-settings email <name> format tunnel <value
>
set network shared-gateway <name> log-settings email <name> format auth <value>
set network shared-gateway <name> log-settings email <name> format userid <value
>
set network shared-gateway <name> log-settings email <name> format config <value
>
set network shared-gateway <name> log-settings email <name> format system <value
>
set network shared-gateway <name> log-settings email <name> format hip-match <va
lue>
set network shared-gateway <name> log-settings email <name> format correlation <
value>
set network shared-gateway <name> log-settings email <name> format escaping esca
ped-characters <value>
set network shared-gateway <name> log-settings email <name> format escaping esca
pe-character <value>
set network shared-gateway <name> log-settings syslog <name> server <name> serve
r <value>
set network shared-gateway <name> log-settings syslog <name> server <name> trans
port <UDP|TCP|SSL>
set network shared-gateway <name> log-settings syslog <name> server <name> port
<1-65535>
set network shared-gateway <name> log-settings syslog <name> server <name> forma
t <BSD|IETF>
set network shared-gateway <name> log-settings syslog <name> server <name> facil
ity <LOG_USER|LOG_LOCAL0|LOG_LOCAL1|LOG_LOCAL2|LOG_LOCAL3|LOG_LOCAL4|LOG_LOCAL5|
LOG_LOCAL6|LOG_LOCAL7>
set network shared-gateway <name> log-settings syslog <name> format traffic <val
ue>
set network shared-gateway <name> log-settings syslog <name> format threat <valu
e>
set network shared-gateway <name> log-settings syslog <name> format wildfire <va
lue>
set network shared-gateway <name> log-settings syslog <name> format url <value>
set network shared-gateway <name> log-settings syslog <name> format data <value>
set network shared-gateway <name> log-settings syslog <name> format tunnel <valu
e>
set network shared-gateway <name> log-settings syslog <name> format auth <value>
set network shared-gateway <name> log-settings syslog <name> format userid <valu
e>
set network shared-gateway <name> log-settings syslog <name> format config <valu
e>
set network shared-gateway <name> log-settings syslog <name> format system <valu
e>
set network shared-gateway <name> log-settings syslog <name> format hip-match <v
alue>
<value>
set network shared-gateway <name> log-settings syslog <name> format escaping esc
aped-characters <value>
set network shared-gateway <name> log-settings syslog <name> format escaping esc
ape-character <value>
set network shared-gateway <name> log-settings http <name> server <name> address
<value>
set network shared-gateway <name> log-settings http <name> server <name> protoco
l <HTTP|HTTPS>
set network shared-gateway <name> log-settings http <name> server <name> port <1
-65535>
set network shared-gateway <name> log-settings http <name> server <name> http-me
thod <value>
set network shared-gateway <name> log-settings http <name> server <name> usernam
e <value>
set network shared-gateway <name> log-settings http <name> server <name> passwor
d <value>
set network shared-gateway <name> log-settings http <name> format config name <v
alue>
set network shared-gateway <name> log-settings http <name> format config url-for
mat <value>
set network shared-gateway <name> log-settings http <name> format config headers
set network shared-gateway <name> log-settings http <name> format config headers
<name>
set network shared-gateway <name> log-settings http <name> format config headers
set network shared-gateway <name> log-settings http <name> format config params
set network shared-gateway <name> log-settings http <name> format config params
<name>
set network shared-gateway <name> log-settings http <name> format config params
<value>
set network shared-gateway <name> log-settings http <name> format system name <v
alue>
set network shared-gateway <name> log-settings http <name> format system url-for
mat <value>
set network shared-gateway <name> log-settings http <name> format system headers
set network shared-gateway <name> log-settings http <name> format system headers
<name>
set network shared-gateway <name> log-settings http <name> format system headers
set network shared-gateway <name> log-settings http <name> format system params
set network shared-gateway <name> log-settings http <name> format system params
<name>
set network shared-gateway <name> log-settings http <name> format system params
set network shared-gateway <name> log-settings http <name> format system payload
<value>
set network shared-gateway <name> log-settings http <name> format traffic name <
value>
set network shared-gateway <name> log-settings http <name> format traffic url-fo
rmat <value>
set network shared-gateway <name> log-settings http <name> format traffic header
set network shared-gateway <name> log-settings http <name> format traffic header
s <name>
set network shared-gateway <name> log-settings http <name> format traffic header
set network shared-gateway <name> log-settings http <name> format traffic params
set network shared-gateway <name> log-settings http <name> format traffic params
<name>
set network shared-gateway <name> log-settings http <name> format traffic params
set network shared-gateway <name> log-settings http <name> format traffic payloa
d <value>
set network shared-gateway <name> log-settings http <name> format threat name <v
alue>
set network shared-gateway <name> log-settings http <name> format threat url-for
mat <value>
set network shared-gateway <name> log-settings http <name> format threat headers
set network shared-gateway <name> log-settings http <name> format threat headers
<name>
set network shared-gateway <name> log-settings http <name> format threat headers
set network shared-gateway <name> log-settings http <name> format threat params
set network shared-gateway <name> log-settings http <name> format threat params
<name>
set network shared-gateway <name> log-settings http <name> format threat params
set network shared-gateway <name> log-settings http <name> format threat payload
<value>
set network shared-gateway <name> log-settings http <name> format wildfire name
<value>
set network shared-gateway <name> log-settings http <name> format wildfire url-f
ormat <value>
set network shared-gateway <name> log-settings http <name> format wildfire heade
rs
set network shared-gateway <name> log-settings http <name> format wildfire heade
rs <name>
set network shared-gateway <name> log-settings http <name> format wildfire heade
set network shared-gateway <name> log-settings http <name> format wildfire param
set network shared-gateway <name> log-settings http <name> format wildfire param
s <name>
set network shared-gateway <name> log-settings http <name> format wildfire param
set network shared-gateway <name> log-settings http <name> format wildfire paylo
ad <value>
set network shared-gateway <name> log-settings http <name> format url name <valu
e>
set network shared-gateway <name> log-settings http <name> format url url-format
<value>
set network shared-gateway <name> log-settings http <name> format url headers
set network shared-gateway <name> log-settings http <name> format url headers <n
ame>
set network shared-gateway <name> log-settings http <name> format url headers <n
set network shared-gateway <name> log-settings http <name> format url params
set network shared-gateway <name> log-settings http <name> format url params <na
me>
set network shared-gateway <name> log-settings http <name> format url params <na
set network shared-gateway <name> log-settings http <name> format url payload <v
alue>
set network shared-gateway <name> log-settings http <name> format data name <val
ue>
set network shared-gateway <name> log-settings http <name> format data url-forma
t <value>
set network shared-gateway <name> log-settings http <name> format data headers
set network shared-gateway <name> log-settings http <name> format data headers <
name>
set network shared-gateway <name> log-settings http <name> format data headers <
set network shared-gateway <name> log-settings http <name> format data params
set network shared-gateway <name> log-settings http <name> format data params <n
ame>
set network shared-gateway <name> log-settings http <name> format data params <n
set network shared-gateway <name> log-settings http <name> format data payload <
value>
set network shared-gateway <name> log-settings http <name> format tunnel name <v
alue>
set network shared-gateway <name> log-settings http <name> format tunnel url-for
mat <value>
set network shared-gateway <name> log-settings http <name> format tunnel headers
set network shared-gateway <name> log-settings http <name> format tunnel headers
<name>
set network shared-gateway <name> log-settings http <name> format tunnel headers
set network shared-gateway <name> log-settings http <name> format tunnel params
set network shared-gateway <name> log-settings http <name> format tunnel params
<name>
set network shared-gateway <name> log-settings http <name> format tunnel params
set network shared-gateway <name> log-settings http <name> format tunnel payload
<value>
set network shared-gateway <name> log-settings http <name> format auth
set network shared-gateway <name> log-settings http <name> format auth name <val
ue>
set network shared-gateway <name> log-settings http <name> format auth url-forma
t <value>
set network shared-gateway <name> log-settings http <name> format auth headers
set network shared-gateway <name> log-settings http <name> format auth headers <
name>
set network shared-gateway <name> log-settings http <name> format auth headers <
set network shared-gateway <name> log-settings http <name> format auth params
set network shared-gateway <name> log-settings http <name> format auth params <n
ame>
set network shared-gateway <name> log-settings http <name> format auth params <n
set network shared-gateway <name> log-settings http <name> format auth payload <
value>
set network shared-gateway <name> log-settings http <name> format userid name <v
alue>
set network shared-gateway <name> log-settings http <name> format userid url-for
mat <value>
set network shared-gateway <name> log-settings http <name> format userid headers
set network shared-gateway <name> log-settings http <name> format userid headers
<name>
set network shared-gateway <name> log-settings http <name> format userid headers
set network shared-gateway <name> log-settings http <name> format userid params
set network shared-gateway <name> log-settings http <name> format userid params
<name>
set network shared-gateway <name> log-settings http <name> format userid params
<name> value <value>
set network shared-gateway <name> log-settings http <name> format userid payload
<value>
set network shared-gateway <name> log-settings http <name> format hip-match name
<value>
set network shared-gateway <name> log-settings http <name> format hip-match url-
format <value>
set network shared-gateway <name> log-settings http <name> format hip-match head
ers
set network shared-gateway <name> log-settings http <name> format hip-match head
ers <name>
set network shared-gateway <name> log-settings http <name> format hip-match head
set network shared-gateway <name> log-settings http <name> format hip-match para
ms
set network shared-gateway <name> log-settings http <name> format hip-match para
ms <name>
set network shared-gateway <name> log-settings http <name> format hip-match para
set network shared-gateway <name> log-settings http <name> format hip-match payl
oad <value>
me <value>
l-format <value>
aders
aders <name>
rams
rams <name>
yload <value>
e>
ion-logging <yes|no>
action-desc <value>
log-type <traffic|threat|wildfire|url|data|tunnel|auth>
filter <value>
send-to-panorama <yes|no>
actions
actions <name>
set network shared-gateway <name> rulebase nat rules <name> from [ <from1> <fro
m2>... ]
set network shared-gateway <name> rulebase nat rules <name> to [ <to1> <to2>...
set network shared-gateway <name> rulebase nat rules <name> source [ <source1>
<source2>... ]
set network shared-gateway <name> rulebase nat rules <name> destination [ <dest
ination1> <destination2>... ]
set network shared-gateway <name> rulebase nat rules <name> service <value>
set network shared-gateway <name> rulebase nat rules <name> nat-type <ipv4|nat64
|nptv6>
set network shared-gateway <name> rulebase nat rules <name> to-interface <value>
|<any>
ynamic-ip-and-port
ynamic-ip-and-port
ss2>... ]
ynamic-ip-and-port interface-address
ynamic-ip-and-port interface-address
ynamic-ip
set network shared-gateway <name> rulebase nat rules <name> source-translation d
ynamic-ip fallback
ynamic-ip fallback
ss2>... ]
tatic-ip
ion
translation
-binding <primary|both|0|1>
set network shared-gateway <name> rulebase nat rules <name> tag [ <tag1> <tag2>
... ]
set network shared-gateway <name> rulebase nat rules <name> disabled <yes|no>
set network shared-gateway <name> rulebase nat rules <name> description <value>
set network shared-gateway <name> rulebase pbf rules <name> from zone [ <zone1>
<zone2>... ]
set network shared-gateway <name> rulebase pbf rules <name> from interface [ <i
nterface1> <interface2>... ]
set network shared-gateway <name> rulebase pbf rules <name> source [ <source1>
<source2>... ]
set network shared-gateway <name> rulebase pbf rules <name> source-user [ <sour
ce-user1> <source-user2>... ]
set network shared-gateway <name> rulebase pbf rules <name> destination [ <dest
ination1> <destination2>... ]
set network shared-gateway <name> rulebase pbf rules <name> service [ <service1
> <service2>... ]
set network shared-gateway <name> rulebase pbf rules <name> schedule <value>
set network shared-gateway <name> rulebase pbf rules <name> tag [ <tag1> <tag2>
... ]
set network shared-gateway <name> rulebase pbf rules <name> negate-source <yes|n
o>
set network shared-gateway <name> rulebase pbf rules <name> negate-destination <
yes|no>
set network shared-gateway <name> rulebase pbf rules <name> disabled <yes|no>
set network shared-gateway <name> rulebase pbf rules <name> description <value>
set network shared-gateway <name> rulebase pbf rules <name> application [ <appl
ication1> <application2>... ]
set network shared-gateway <name> rulebase pbf rules <name> action forward
set network shared-gateway <name> rulebase pbf rules <name> action forward egres
s-interface <value>
set network shared-gateway <name> rulebase pbf rules <name> action forward nexth
op
set network shared-gateway <name> rulebase pbf rules <name> action forward nexth
op ip-address <ip/netmask>
set network shared-gateway <name> rulebase pbf rules <name> action forward monit
or
set network shared-gateway <name> rulebase pbf rules <name> action forward monit
or profile <value>
set network shared-gateway <name> rulebase pbf rules <name> action forward monit
or disable-if-unreachable <yes|no>
set network shared-gateway <name> rulebase pbf rules <name> action forward monit
or ip-address <ip/netmask>
set network shared-gateway <name> rulebase pbf rules <name> action forward-to-vs
ys <value>
set network shared-gateway <name> rulebase pbf rules <name> action discard
set network shared-gateway <name> rulebase pbf rules <name> action no-pbf
turn nexthop-address-list
-binding <both|0|1>
set shared
>
<name>
<name> operator
wn-req-udp|unknown-rsp-udp>
>... ]
.]
1> <saas-certifications2>... ]
set shared service <name> protocol tcp override yes timeout <1-604800>
set shared service <name> protocol tcp override yes halfclose-timeout <1-604800>
set shared service <name> protocol tcp override yes timewait-timeout <1-600>
set shared service <name> protocol udp override yes timeout <1-604800>
set shared profiles hip-objects <name> host-info criteria domain contains <value
>
set shared profiles hip-objects <name> host-info criteria domain is-not <value>
<value>
set shared profiles hip-objects <name> host-info criteria os contains Apple <val
ue>
set shared profiles hip-objects <name> host-info criteria os contains Google <va
lue>
set shared profiles hip-objects <name> host-info criteria os contains Linux <val
ue>
set shared profiles hip-objects <name> host-info criteria os contains Other <val
ue>
s <value>
ue>
<value>
set shared profiles hip-objects <name> host-info criteria host-name
set shared profiles hip-objects <name> host-info criteria host-name contains <va
lue>
set shared profiles hip-objects <name> host-info criteria host-name is-not <valu
e>
set shared profiles hip-objects <name> host-info criteria host-id contains <valu
e>
set shared profiles hip-objects <name> host-info criteria host-id is-not <value>
set shared profiles hip-objects <name> network-info criteria network is wifi ssi
d <value>
arrier <value>
set shared profiles hip-objects <name> network-info criteria network is-not wifi
set shared profiles hip-objects <name> network-info criteria network is-not wifi
ssid <value>
set shared profiles hip-objects <name> network-info criteria network is-not mobi
le
set shared profiles hip-objects <name> network-info criteria network is-not mobi
le carrier <value>
set shared profiles hip-objects <name> network-info criteria network is-not ethe
rnet
set shared profiles hip-objects <name> network-info criteria network is-not unkn
own
es|no>
yes|not-available>
severity
severity
severity is <0-100000>
<product1> <product2>... ]
d <yes|no>
<no|yes|not-available>
t [ <product1> <product2>... ]
no>
available>
set shared profiles hip-objects <name> firewall vendor <name> product [ <produc
t1> <product2>... ]
in
in days <1-65535>
in versions <1-65535>
within
ater-equal <value>
ater-than <value>
<value>
not <value>
s-equal <value>
s-than <value>
tains <value>
hin
-within
o>
n <no|yes|not-available>
available
in
in days <1-65535>
in hours <1-65535>
within
set shared profiles hip-objects <name> anti-malware vendor <name> product [ <pr
oduct1> <product2>... ]
-available
hin
-within
set shared profiles hip-objects <name> disk-backup vendor <name> product [ <pro
duct1> <product2>... ]
s|no>
ons
ons <name>
<product1> <product2>... ]
>
>
> registry-value
set shared profiles hip-objects <name> custom-checks criteria plist <name> negat
e <yes|no>
set shared profiles hip-objects <name> custom-checks criteria plist <name> key
set shared profiles hip-objects <name> custom-checks criteria plist <name> key <
name>
set shared profiles hip-objects <name> custom-checks criteria plist <name> key <
set shared profiles hip-objects <name> custom-checks criteria plist <name> key <
>
|yes>
es>
|yes>
within
not-within
ue>
set shared profiles hip-objects <name> mobile-device criteria imei is-not <value
>
set shared profiles hip-objects <name> mobile-device criteria model contains <va
lue>
set shared profiles hip-objects <name> mobile-device criteria model is-not <valu
e>
ins <value>
alue>
t <value>
ains <value>
value>
ot <value>
set shared profiles hip-objects <name> mobile-device criteria tag contains <valu
e>
set shared profiles hip-objects <name> mobile-device criteria tag is <value>
set shared profiles hip-objects <name> mobile-device criteria tag is-not <value>
alware
alware no
alware yes
nmanaged-app <no|yes>
des
des <name>
|reset-client|reset-server|reset-both>
lert|drop|reset-client|reset-server|reset-both>
drop|reset-client|reset-server|reset-both>
set shared profiles spyware <name> botnet-domains lists <name> action alert
set shared profiles spyware <name> botnet-domains lists <name> action allow
set shared profiles spyware <name> botnet-domains lists <name> action block
set shared profiles spyware <name> botnet-domains lists <name> action sinkhole
ask>|<127.0.0.1|pan-sinkhole-default-ip>
ask>|<::1>
-packet|extended-capture>
set shared profiles spyware <name> rules <name> severity [ <severity1> <severit
y2>... ]
set shared profiles spyware <name> rules <name> action block-ip track-by <source
|source-and-destination>
set shared profiles spyware <name> rules <name> action block-ip duration <1-3600
>
acket|extended-capture>
le|single-packet|extended-capture>
set shared profiles spyware <name> threat-exception <name> action block-ip track
-by <source|source-and-destination>
set shared profiles spyware <name> threat-exception <name> action block-ip durat
ion <1-3600>
set shared profiles vulnerability <name> rules <name> cve [ <cve1> <cve2>... ]
<vendor-id2>... ]
set shared profiles vulnerability <name> rules <name> severity [ <severity1> <s
everity2>... ]
set shared profiles vulnerability <name> rules <name> action block-ip track-by <
source|source-and-destination>
set shared profiles vulnerability <name> rules <name> action block-ip duration <
1-3600>
ngle-packet|extended-capture>
<disable|single-packet|extended-capture>
ient
rver
th
track-by <source|source-and-destination>
duration <1-3600>
interval <1-3600>
threshold <1-65535>
track-by <source|destination|source-and-destination>
>
2>... ]
2>... ]
tegorychange2>... ]
entials
ng <value>
lue>
> <alert2>... ]
> <block2>... ]
tinue1> <continue2>... ]
>
> headers
n1> <application2>... ]
<file-type2>... ]
|both>
ue>
ation1> <application2>... ]
e1> <file-type2>... ]
load|both>
|private-cloud>
set shared profiles data-objects <name> pattern-type regex pattern <name> file-t
set shared profiles data-objects <name> pattern-type regex pattern <name> regex
<value>
me>
on1> <application2>... ]
d|both>
set shared profiles dos-protection <name> flood tcp-syn red alarm-rate <0-200000
0>
set shared profiles dos-protection <name> flood tcp-syn red activate-rate <1-200
0000>
set shared profiles dos-protection <name> flood tcp-syn red maximal-rate <1-2000
000>
set shared profiles dos-protection <name> flood tcp-syn red block duration <1-21
600>
set shared profiles dos-protection <name> flood tcp-syn syn-cookies alarm-rate <
0-2000000>
<1-2000000>
set shared profiles dos-protection <name> flood tcp-syn syn-cookies block durati
on <1-21600>
set shared profiles dos-protection <name> flood udp red alarm-rate <0-2000000>
set shared profiles dos-protection <name> flood udp red activate-rate <1-2000000
>
set shared profiles dos-protection <name> flood udp red maximal-rate <1-2000000>
set shared profiles dos-protection <name> flood udp red block duration <1-21600>
set shared profiles dos-protection <name> flood icmp red alarm-rate <0-2000000>
set shared profiles dos-protection <name> flood icmp red activate-rate <1-200000
0>
set shared profiles dos-protection <name> flood icmp red maximal-rate <1-2000000
>
set shared profiles dos-protection <name> flood icmp red block duration <1-21600
>
set shared profiles dos-protection <name> flood icmpv6 red alarm-rate <0-2000000
>
set shared profiles dos-protection <name> flood icmpv6 red activate-rate <1-2000
000>
set shared profiles dos-protection <name> flood icmpv6 red maximal-rate <1-20000
00>
set shared profiles dos-protection <name> flood icmpv6 red block duration <1-216
00>
set shared profiles dos-protection <name> flood other-ip red alarm-rate <0-20000
00>
set shared profiles dos-protection <name> flood other-ip red activate-rate <1-20
00000>
set shared profiles dos-protection <name> flood other-ip red maximal-rate <1-200
0000>
set shared profiles dos-protection <name> flood other-ip red block duration <1-2
1600>
<1-4194304>
e <yes|no>
yes|no>
set shared profiles decryption <name> ssl-forward-proxy restrict-cert-exts <yes|
no>
n <yes|no>
<yes|no>
o>
s|no>
<yes|no>
no>
no>
s|no>
n <yes|no>
<yes|no>
s|no>
<yes|no>
ls1-0|tls1-1|tls1-2>
ls1-0|tls1-1|tls1-2|max>
set shared profiles decryption <name> ssl-protocol-settings keyxchg-algo-rsa <ye
s|no>
s|no>
yes|no>
o>
>
<yes|no>
<yes|no>
<yes|no>
<yes|no>
o>
no>
s|no>
s|no>
s|no>
o>
o>
2>... ]
2>... ]
2>... ]
ire-analysis2>... ]
ing2>... ]
set shared schedule <name> schedule-type recurring weekly sunday [ <sunday1> <s
unday2>... ]
set shared schedule <name> schedule-type recurring weekly monday [ <monday1> <m
onday2>... ]
<tuesday2>... ]
y1> <wednesday2>... ]
set shared schedule <name> schedule-type recurring weekly thursday [ <thursday1
> <thursday2>... ]
set shared schedule <name> schedule-type recurring weekly friday [ <friday1> <f
riday2>... ]
> <saturday2>... ]
recurring2>... ]
|source-and-destination>
>
.]
set shared threats vulnerability <name> signature standard <name> comment <value
>
set shared threats vulnerability <name> signature standard <name> scope <protoco
l-data-unit|session>
set shared threats vulnerability <name> signature standard <name> order-free <ye
s|no>
<name>
<name> or-condition
lue>
ue>
<value>
|<value>
erval <1-3600>
eshold <1-255>
ck-by <source|destination|source-and-destination>
>
e>
e> or-condition
e-and-destination>
set shared threats spyware <name> signature standard <name> comment <value>
set shared threats spyware <name> signature standard <name> scope <protocol-data
-unit|session>
set shared threats spyware <name> signature standard <name> order-free <yes|no>
set shared threats spyware <name> signature standard <name> and-condition <name>
set shared threats spyware <name> signature standard <name> and-condition <name>
or-condition
set shared threats spyware <name> signature standard <name> and-condition <name>
or-condition <name>
set shared threats spyware <name> signature standard <name> and-condition <name>
set shared threats spyware <name> signature standard <name> and-condition <name>
set shared threats spyware <name> signature standard <name> and-condition <name>
set shared threats spyware <name> signature standard <name> and-condition <name>
set shared threats spyware <name> signature standard <name> and-condition <name>
set shared threats spyware <name> signature standard <name> and-condition <name>
set shared threats spyware <name> signature standard <name> and-condition <name>
set shared threats spyware <name> signature standard <name> and-condition <name>
set shared threats spyware <name> signature standard <name> and-condition <name>
set shared threats spyware <name> signature standard <name> and-condition <name>
set shared threats spyware <name> signature standard <name> and-condition <name>
set shared threats spyware <name> signature standard <name> and-condition <name>
set shared threats spyware <name> signature standard <name> and-condition <name>
set shared threats spyware <name> signature standard <name> and-condition <name>
set shared threats spyware <name> signature standard <name> and-condition <name>
or-condition <name> operator greater-than value <0-4294967295>
set shared threats spyware <name> signature standard <name> and-condition <name>
set shared threats spyware <name> signature standard <name> and-condition <name>
set shared threats spyware <name> signature standard <name> and-condition <name>
set shared threats spyware <name> signature standard <name> and-condition <name>
>
set shared threats spyware <name> signature standard <name> and-condition <name>
set shared threats spyware <name> signature standard <name> and-condition <name>
set shared threats spyware <name> signature standard <name> and-condition <name>
set shared threats spyware <name> signature standard <name> and-condition <name>
set shared threats spyware <name> signature standard <name> and-condition <name>
set shared threats spyware <name> signature standard <name> and-condition <name>
set shared threats spyware <name> signature standard <name> and-condition <name>
e>
<1-3600>
<1-255>
set shared threats spyware <name> signature combination and-condition <name> or-
condition
set shared threats spyware <name> signature combination and-condition <name> or-
condition <name>
set shared threats spyware <name> signature combination and-condition <name> or-
list1> <exception-list2>... ]
eption-list2>... ]
day|tuesday|wednesday|thursday|friday|saturday>
<exception-list2>... ]
set shared external-list <name> type domain recurring weekly day-of-week <sunday
|monday|tuesday|wednesday|thursday|friday|saturday>
set shared external-list <name> type domain recurring monthly day-of-month <1-31
>
ception-list2>... ]
set shared external-list <name> type url recurring weekly day-of-week <sunday|mo
nday|tuesday|wednesday|thursday|friday|saturday>
set shared external-list <name> type url recurring monthly day-of-month <1-31>
lor8|color9|color10|color11|color12|color13|color14|color15|color16|color17|colo
r19|color20|color21|color22|color23|color24|color25|color26|color27|color28|colo
r29|color30|color31|color32|color33|color34|color35|color36|color37|color38|colo
r39|color40|color41|color42>
bers2>... ]
rs|last-24-hrs|last-calendar-day|last-7-days|last-7-calendar-days|last-calendar-
week|last-30-days|last-30-calendar-days|last-calendar-month>
e-by2>... ]
our-of-receive_time|hour-of-receive_time|day-of-receive_time|vsys_name>
-by2>... ]
ory-of-threatid|direction|dport|dst|dstuser|from|inbound_if|misc|natdport|natdst
|natsport|natsrc|outbound_if|proto|risk-of-app|rule|severity|sport|src|srcuser|s
ubcategory-of-app|subtype|technology-of-app|container-of-app|threatid|to|dstloc|
srcloc|vsys|quarter-hour-of-receive_time|hour-of-receive_time|day-of-receive_tim
e|vsys_name|device_name|threat-type|tunnelid|monitortag|parent_session_id|parent
_start_time|tunnel|http_method>
2>... ]
|direction|dport|dst|dstuser|from|inbound_if|misc|http_headers|natdport|natdst|n
atsport|natsrc|outbound_if|proto|risk-of-app|rule|severity|sport|src|srcuser|sub
category-of-app|technology-of-app|container-of-app|to|dstloc|srcloc|vsys|quarter
-hour-of-receive_time|hour-of-receive_time|day-of-receive_time|contenttype|user_
agent|vsys_name|device_name|url|tunnelid|monitortag|parent_session_id|parent_sta
rt_time|tunnel|http_method>
te-by2>... ]
port|dst|dstuser|from|inbound_if|misc|natdport|natdst|natsport|natsrc|outbound_i
f|proto|risk-of-app|rule|sport|src|srcuser|subcategory-of-app|technology-of-app|
container-of-app|to|dstloc|srcloc|vsys|quarter-hour-of-receive_time|hour-of-rece
ive_time|day-of-receive_time|vsys_name|device_name|filetype|filename|filedigest|
tunnelid|monitortag|parent_session_id|parent_start_time|tunnel>
y2>... ]
on|dport|dst|dstuser|from|inbound_if|misc|natdport|natdst|natsport|natsrc|outbou
nd_if|proto|risk-of-app|rule|severity|sport|src|srcuser|subcategory-of-app|subty
pe|technology-of-app|container-of-app|threatid|to|dstloc|srcloc|vsys|quarter-hou
r-of-receive_time|hour-of-receive_time|day-of-receive_time|vsys_name|device_name
|data-type|filename|tunnelid|monitortag|parent_session_id|parent_start_time|tunn
el>
by2>... ]
ry-of-threatid|direction|dport|dst|dstuser|from|inbound_if|outbound_if|risk-of-a
pp|rule|severity|src|srcuser|subcategory-of-app|subtype|technology-of-app|contai
ner-of-app|to|threatid|dstloc|srcloc|vsys|quarter-hour-of-receive_time|hour-of-r
eceive_time|day-of-receive_time|serial|vsys_name|device_name|threat-type|tunneli
d|monitortag|parent_session_id|parent_start_time|tunnel>
e-by2>... ]
-app|dport|dst|dstuser|from|inbound_if|natdport|natdst|natsport|natsrc|outbound_
if|proto|risk-of-app|rule|sessionid|sport|src|srcuser|subcategory-of-app|technol
ogy-of-app|container-of-app|to|dstloc|srcloc|vsys|quarter-hour-of-receive_time|h
our-of-receive_time|day-of-receive_time|session_end_reason|vsys_name|device_name
|action_source|tunnelid|monitortag|parent_session_id|parent_start_time|tunnel>
lapsed|packets|pkts_sent|pkts_received|repeatcnt|nunique-of-users>
-by2>... ]
user|rule|dstloc|srcloc|vsys_name|device_name|from|to|serial|inbound_if|outbound
_if|dport|action|url_domain|user_agent|category-of-app|subcategory-of-app|risk-o
f-app|vsys|quarter-hour-of-receive_time|hour-of-receive_time|day-of-receive_time
|tunnelid|monitortag|parent_session_id|parent_start_time|tunnel|http_method>
by2>... ]
bcategory-of-app|technology-of-app|container-of-app|to|dstloc|srcloc|vsys|quarte
r-hour-of-receive_time|hour-of-receive_time|day-of-receive_time|serial|vsys_name
|device_name|tunnelid|monitortag|parent_session_id|parent_start_time|tunnel>
eived|nthreats|nftrans|ndpmatches|nurlcount|ncontent|nunique-of-users|nunique-of
-apps>
-by2>... ]
|dst|dstuser|from|inbound_if|natdport|natdst|natsport|natsrc|outbound_if|proto|r
isk-of-app|rule|sessionid|sport|src|srcuser|subcategory-of-app|technology-of-app
|container-of-app|to|dstloc|srcloc|vsys|quarter-hour-of-receive_time|hour-of-rec
eive_time|day-of-receive_time|vsys_name|device_name|tunnelid|monitortag|parent_s
ession_id|parent_start_time|session_end_reason|action_source|tunnel|tunnel_insp_
rule>
eceived|packets|pkts_sent|pkts_received|max_encap|unknown_proto|strict_check|tun
nel_fragment|sessions_created|sessions_closed|nunique-of-users>
ate-by2>... ]
t|risk-of-app|rule|src|subcategory-of-app|technology-of-app|container-of-app|dst
loc|srcloc|vsys|quarter-hour-of-receive_time|hour-of-receive_time|day-of-receive
_time|serial|vsys_name|device_name|tunnelid|monitortag|parent_session_id|parent_
start_time|tunnel|tunnel_insp_rule>
set shared reports <name> type tunnelsum values [ <values1> <values2>... ]
s_received>
-by2>... ]
e|hour-of-receive_time|day-of-receive_time|vsys_name|device_name|ip|user|datasou
rcename|beginport|endport|datasource|datasourcetype|factortype|factorcompletiont
ime|factorno|subtype>
iontime>
y2>... ]
f-receive_time|hour-of-receive_time|day-of-receive_time|vsys_name|device_name|ip
|user|normalize_user|object|authpolicy|authid|vendor|clienttype|serverprofile|de
sc|event|factorno|authproto>
te-by2>... ]
pv6|srcuser|matchtype|vsys|device_name|vsys_name|os|quarter-hour-of-receive_time
|hour-of-receive_time|day-of-receive_time>
set shared reports <name> type hipmatch labels [ <labels1> <labels2>... ]
-usage-report>
ups2>... ]
|no>
<user-groups2>... ]
ne|bar|table>
ar|table>
day|thursday|friday|saturday>
set shared email-scheduler <name> recurring monthly <1-31>
|no>
-1000>
ur <1-3600>
r-hour <1-3600>
minimum-bytes <1-200>
maximum-bytes <1-200>
set shared botnet configuration unknown-applications unknown-udp
ur <1-3600>
r-hour <1-3600>
minimum-bytes <1-200>
maximum-bytes <1-200>
USERINPUT%|%USERINPUT%@%USERDOMAIN%|%USERDOMAIN%\%USERINPUT%>
>
2>... ]
es|no>
cate <value>
lue>
<value>
p <value>
le <value>
omain <value>
<factors2>... ]
tion-profiles1> <authentication-profiles2>... ]
l-name>
n|other>
s|no>
<yes|no>
le <value>
s|no>
le <value>
<yes|no>
rofile <value>
alue>
>
ue>
ue>
1> <send-snmptrap2>... ]
nd-email2>... ]
send-syslog2>... ]
1> <send-snmptrap2>... ]
nd-email2>... ]
send-syslog2>... ]
-http2>... ]
1> <send-snmptrap2>... ]
nd-email2>... ]
send-syslog2>... ]
-http2>... ]
set shared log-settings userid match-list <name> actions
set shared log-settings userid match-list <name> actions <name> type tagging
set shared log-settings userid match-list <name> actions <name> type tagging tar
get <source-address|destination-address>
set shared log-settings userid match-list <name> actions <name> type tagging act
ion <add-tag|remove-tag>
set shared log-settings userid match-list <name> actions <name> type tagging reg
istration
set shared log-settings userid match-list <name> actions <name> type tagging reg
istration localhost
set shared log-settings userid match-list <name> actions <name> type tagging reg
istration panorama
set shared log-settings userid match-list <name> actions <name> type tagging reg
istration remote
set shared log-settings userid match-list <name> actions <name> type tagging reg
set shared log-settings userid match-list <name> actions <name> type tagging tag
s [ <tags1> <tags2>... ]
ap1> <send-snmptrap2>... ]
send-email2>... ]
<send-syslog2>... ]
set shared log-settings hipmatch match-list <name> send-http [ <send-http1> <se
nd-http2>... ]
set shared log-settings hipmatch match-list <name> actions <name> type tagging
set shared log-settings hipmatch match-list <name> actions <name> type tagging t
arget <source-address|destination-address>
set shared log-settings hipmatch match-list <name> actions <name> type tagging a
ction <add-tag|remove-tag>
set shared log-settings hipmatch match-list <name> actions <name> type tagging r
egistration
set shared log-settings hipmatch match-list <name> actions <name> type tagging r
egistration localhost
set shared log-settings hipmatch match-list <name> actions <name> type tagging r
egistration panorama
set shared log-settings hipmatch match-list <name> actions <name> type tagging r
egistration remote
set shared log-settings hipmatch match-list <name> actions <name> type tagging r
set shared log-settings hipmatch match-list <name> actions <name> type tagging t
ptrap1> <send-snmptrap2>... ]
> <send-email2>... ]
<send-http2>... ]
set shared log-settings correlation match-list <name> actions <name> type taggin
set shared log-settings correlation match-list <name> actions <name> type taggin
g target <source-address|destination-address>
set shared log-settings correlation match-list <name> actions <name> type taggin
g action <add-tag|remove-tag>
set shared log-settings correlation match-list <name> actions <name> type taggin
g registration
set shared log-settings correlation match-list <name> actions <name> type taggin
g registration localhost
set shared log-settings correlation match-list <name> actions <name> type taggin
g registration panorama
set shared log-settings correlation match-list <name> actions <name> type taggin
g registration remote
set shared log-settings correlation match-list <name> actions <name> type taggin
set shared log-settings correlation match-list <name> actions <name> type taggin
set shared log-settings snmptrap <name> version v2c server <name> manager <ip/ne
tmask>|<value>
set shared log-settings snmptrap <name> version v2c server <name> community <val
ue>
set shared log-settings snmptrap <name> version v3 server <name> manager <ip/net
mask>|<value>
set shared log-settings snmptrap <name> version v3 server <name> user <value>
set shared log-settings snmptrap <name> version v3 server <name> engineid <value
>
set shared log-settings snmptrap <name> version v3 server <name> authpwd <value>
set shared log-settings snmptrap <name> version v3 server <name> privpwd <value>
0|LOG_LOCAL1|LOG_LOCAL2|LOG_LOCAL3|LOG_LOCAL4|LOG_LOCAL5|LOG_LOCAL6|LOG_LOCAL7>
set shared log-settings http <name> format config headers <name> value <value>
set shared log-settings http <name> format config params <name> value <value>
set shared log-settings http <name> format system headers <name> value <value>
set shared log-settings http <name> format system params <name> value <value>
set shared log-settings http <name> format traffic headers <name> value <value>
set shared log-settings http <name> format traffic params <name> value <value>
set shared log-settings http <name> format threat headers <name> value <value>
set shared log-settings http <name> format threat params <name> value <value>
set shared log-settings http <name> format wildfire headers <name> value <value>
set shared log-settings http <name> format wildfire params <name> value <value>
set shared log-settings http <name> format url headers <name> value <value>
set shared log-settings http <name> format url params <name> value <value>
set shared log-settings http <name> format data headers <name> value <value>
set shared log-settings http <name> format data params <name> value <value>
set shared log-settings http <name> format tunnel headers <name> value <value>
set shared log-settings http <name> format tunnel params <name> value <value>
set shared log-settings http <name> format auth params <name> value <value>
set shared log-settings http <name> format userid headers <name> value <value>
set shared log-settings http <name> format userid params <name> value <value>
set shared log-settings http <name> format hip-match headers <name> value <value
>
set shared log-settings http <name> format hip-match params <name> value <value>
set shared log-settings http <name> format correlation headers <name> value <val
ue>
set shared log-settings http <name> format correlation params <name> value <valu
e>
at|wildfire|url|data|tunnel|auth>
no>
-snmptrap1> <send-snmptrap2>... ]
ail1> <send-email2>... ]
yslog1> <send-syslog2>... ]
p1> <send-http2>... ]
set shared log-settings profiles <name> match-list <name> actions <name> type
set shared log-settings profiles <name> match-list <name> actions <name> type ta
gging
set shared log-settings profiles <name> match-list <name> actions <name> type ta
gging target <source-address|destination-address>
set shared log-settings profiles <name> match-list <name> actions <name> type ta
set shared log-settings profiles <name> match-list <name> actions <name> type ta
gging registration
set shared log-settings profiles <name> match-list <name> actions <name> type ta
set shared log-settings profiles <name> match-list <name> actions <name> type ta
set shared log-settings profiles <name> match-list <name> actions <name> type ta
set shared log-settings profiles <name> match-list <name> actions <name> type ta
set shared log-settings profiles <name> match-list <name> actions <name> type ta
tls1-1|tls1-2>
tls1-1|tls1-2|max>
s|no>
s|no>
yes|no>
o>
>
<yes|no>
<yes|no>
<yes|no>
<yes|no>
no>
s|no>
set shared ssl-tls-service-profile <name> protocol-settings auth-algo-sha384 <ye
s|no>
lue>
ue>
ue>
value>
exclude-list2>... ]
.. ]
l-exclude-cert-from-predefined1> <disabled-ssl-exclude-cert-from-predefined2>...
set shared admin-role <name> role device webui monitor logs traffic <enable|disa
ble>
set shared admin-role <name> role device webui monitor logs threat <enable|disab
le>
set shared admin-role <name> role device webui monitor logs url <enable|disable>
set shared admin-role <name> role device webui monitor logs wildfire <enable|dis
able>
set shared admin-role <name> role device webui monitor logs data-filtering <enab
le|disable>
set shared admin-role <name> role device webui monitor logs hipmatch <enable|dis
able>
set shared admin-role <name> role device webui monitor logs userid <enable|disab
le>
set shared admin-role <name> role device webui monitor logs gtp <enable|disable>
set shared admin-role <name> role device webui monitor logs tunnel <enable|disab
le>
set shared admin-role <name> role device webui monitor logs sctp <enable|disable
>
set shared admin-role <name> role device webui monitor logs configuration <enabl
e|disable>
set shared admin-role <name> role device webui monitor logs system <enable|disab
le>
set shared admin-role <name> role device webui monitor logs alarm <enable|disabl
e>
set shared admin-role <name> role device webui monitor logs authentication <enab
le|disable>
set shared admin-role <name> role device webui monitor external-logs <enable|dis
able>
ine
set shared admin-role <name> role device webui monitor packet-capture <enable|re
ad-only|disable>
set shared admin-role <name> role device webui monitor app-scope <enable|disable
>
set shared admin-role <name> role device webui monitor session-browser <enable|r
ead-only|disable>
set shared admin-role <name> role device webui monitor block-ip-list <enable|rea
d-only|disable>
set shared admin-role <name> role device webui monitor botnet <enable|read-only|
disable>
set shared admin-role <name> role device webui monitor pdf-reports manage-pdf-su
mmary <enable|read-only|disable>
set shared admin-role <name> role device webui monitor pdf-reports pdf-summary-r
eports <enable|disable>
set shared admin-role <name> role device webui monitor pdf-reports user-activity
-report <enable|read-only|disable>
set shared admin-role <name> role device webui monitor pdf-reports saas-applicat
ion-usage-report <enable|read-only|disable>
set shared admin-role <name> role device webui monitor pdf-reports report-groups
<enable|read-only|disable>
set shared admin-role <name> role device webui monitor pdf-reports email-schedul
er <enable|read-only|disable>
set shared admin-role <name> role device webui monitor custom-reports applicatio
n-statistics <enable|disable>
set shared admin-role <name> role device webui monitor custom-reports data-filte
ring-log <enable|disable>
set shared admin-role <name> role device webui monitor custom-reports threat-log
<enable|disable>
set shared admin-role <name> role device webui monitor custom-reports threat-sum
mary <enable|disable>
set shared admin-role <name> role device webui monitor custom-reports traffic-lo
g <enable|disable>
set shared admin-role <name> role device webui monitor custom-reports traffic-su
mmary <enable|disable>
set shared admin-role <name> role device webui monitor custom-reports url-log <e
nable|disable>
set shared admin-role <name> role device webui monitor custom-reports url-summar
y <enable|disable>
set shared admin-role <name> role device webui monitor custom-reports hipmatch <
enable|disable>
set shared admin-role <name> role device webui monitor custom-reports wildfire-l
og <enable|disable>
set shared admin-role <name> role device webui monitor custom-reports gtp-log <e
nable|disable>
set shared admin-role <name> role device webui monitor custom-reports gtp-summar
y <enable|disable>
set shared admin-role <name> role device webui monitor custom-reports tunnel-log
<enable|disable>
set shared admin-role <name> role device webui monitor custom-reports tunnel-sum
mary <enable|disable>
set shared admin-role <name> role device webui monitor custom-reports sctp-log <
enable|disable>
set shared admin-role <name> role device webui monitor custom-reports sctp-summa
ry <enable|disable>
set shared admin-role <name> role device webui monitor custom-reports userid <en
able|disable>
set shared admin-role <name> role device webui monitor custom-reports auth <enab
le|disable>
set shared admin-role <name> role device webui monitor view-custom-reports <enab
le|disable>
set shared admin-role <name> role device webui monitor application-reports <enab
le|disable>
set shared admin-role <name> role device webui monitor threat-reports <enable|di
sable>
set shared admin-role <name> role device webui monitor url-filtering-reports <en
able|disable>
set shared admin-role <name> role device webui monitor traffic-reports <enable|d
isable>
set shared admin-role <name> role device webui monitor gtp-reports <enable|disab
le>
set shared admin-role <name> role device webui monitor sctp-reports <enable|disa
ble>
set shared admin-role <name> role device webui policies security-rulebase <enabl
e|read-only|disable>
set shared admin-role <name> role device webui policies nat-rulebase <enable|rea
d-only|disable>
set shared admin-role <name> role device webui policies qos-rulebase <enable|rea
d-only|disable>
set shared admin-role <name> role device webui policies pbf-rulebase <enable|rea
d-only|disable>
<enable|read-only|disable>
ebase <enable|read-only|disable>
<enable|read-only|disable>
set shared admin-role <name> role device webui policies dos-rulebase <enable|rea
d-only|disable>
set shared admin-role <name> role device webui policies rule-hit-count-reset <en
able|disable>
set shared admin-role <name> role device webui objects addresses <enable|read-on
ly|disable>
set shared admin-role <name> role device webui objects address-groups <enable|re
ad-only|disable>
set shared admin-role <name> role device webui objects regions <enable|read-only
|disable>
set shared admin-role <name> role device webui objects applications <enable|read
-only|disable>
set shared admin-role <name> role device webui objects application-groups <enabl
e|read-only|disable>
set shared admin-role <name> role device webui objects application-filters <enab
le|read-only|disable>
set shared admin-role <name> role device webui objects services <enable|read-onl
y|disable>
set shared admin-role <name> role device webui objects service-groups <enable|re
ad-only|disable>
set shared admin-role <name> role device webui objects tags <enable|read-only|di
sable>
set shared admin-role <name> role device webui objects global-protect hip-object
s <enable|read-only|disable>
set shared admin-role <name> role device webui objects global-protect hip-profil
es <enable|read-only|disable>
set shared admin-role <name> role device webui objects dynamic-block-lists <enab
le|read-only|disable>
set shared admin-role <name> role device webui objects custom-objects data-patte
rns <enable|read-only|disable>
set shared admin-role <name> role device webui objects custom-objects spyware <e
nable|read-only|disable>
set shared admin-role <name> role device webui objects custom-objects vulnerabil
ity <enable|read-only|disable>
set shared admin-role <name> role device webui objects custom-objects url-catego
ry <enable|read-only|disable>
set shared admin-role <name> role device webui objects security-profiles antivir
us <enable|read-only|disable>
set shared admin-role <name> role device webui objects security-profiles anti-sp
yware <enable|read-only|disable>
set shared admin-role <name> role device webui objects security-profiles vulnera
bility-protection <enable|read-only|disable>
set shared admin-role <name> role device webui objects security-profiles url-fil
tering <enable|read-only|disable>
set shared admin-role <name> role device webui objects security-profiles file-bl
ocking <enable|read-only|disable>
set shared admin-role <name> role device webui objects security-profiles wildfir
e-analysis <enable|read-only|disable>
set shared admin-role <name> role device webui objects security-profiles data-fi
ltering <enable|read-only|disable>
set shared admin-role <name> role device webui objects security-profiles dos-pro
tection <enable|read-only|disable>
set shared admin-role <name> role device webui objects security-profile-groups <
enable|read-only|disable>
set shared admin-role <name> role device webui objects log-forwarding <enable|re
ad-only|disable>
set shared admin-role <name> role device webui objects authentication <enable|re
ad-only|disable>
set shared admin-role <name> role device webui objects decryption decryption-pro
file <enable|read-only|disable>
set shared admin-role <name> role device webui objects decryption decryption-for
warding-profile <enable|read-only|disable>
set shared admin-role <name> role device webui objects schedules <enable|read-on
ly|disable>
set shared admin-role <name> role device webui network interfaces <enable|read-o
nly|disable>
set shared admin-role <name> role device webui network zones <enable|read-only|d
isable>
set shared admin-role <name> role device webui network vlans <enable|read-only|d
isable>
set shared admin-role <name> role device webui network virtual-wires <enable|rea
d-only|disable>
set shared admin-role <name> role device webui network virtual-routers <enable|r
ead-only|disable>
set shared admin-role <name> role device webui network ipsec-tunnels <enable|rea
d-only|disable>
set shared admin-role <name> role device webui network dhcp <enable|read-only|di
sable>
set shared admin-role <name> role device webui network dns-proxy <enable|read-on
ly|disable>
set shared admin-role <name> role device webui network global-protect portals <e
nable|read-only|disable>
set shared admin-role <name> role device webui network global-protect gateways <
enable|read-only|disable>
set shared admin-role <name> role device webui network global-protect mdm <enabl
e|read-only|disable>
set shared admin-role <name> role device webui network global-protect device-blo
ck-list <enable|read-only|disable>
set shared admin-role <name> role device webui network global-protect clientless
-apps <enable|read-only|disable>
set shared admin-role <name> role device webui network global-protect clientless
-app-groups <enable|read-only|disable>
set shared admin-role <name> role device webui network qos <enable|read-only|dis
able>
set shared admin-role <name> role device webui network lldp <enable|read-only|di
sable>
set shared admin-role <name> role device webui network network-profiles gp-app-i
psec-crypto <enable|read-only|disable>
set shared admin-role <name> role device webui network network-profiles ike-gate
ways <enable|read-only|disable>
set shared admin-role <name> role device webui network network-profiles ipsec-cr
ypto <enable|read-only|disable>
set shared admin-role <name> role device webui network network-profiles ike-cryp
to <enable|read-only|disable>
set shared admin-role <name> role device webui network network-profiles tunnel-m
onitor <enable|read-only|disable>
set shared admin-role <name> role device webui network network-profiles interfac
e-mgmt <enable|read-only|disable>
set shared admin-role <name> role device webui network network-profiles zone-pro
tection <enable|read-only|disable>
set shared admin-role <name> role device webui network network-profiles qos-prof
ile <enable|read-only|disable>
set shared admin-role <name> role device webui network network-profiles lldp-pro
file <enable|read-only|disable>
set shared admin-role <name> role device webui network network-profiles bfd-prof
ile <enable|read-only|disable>
set shared admin-role <name> role device webui device setup management <enable|r
ead-only|disable>
set shared admin-role <name> role device webui device setup operations <enable|r
ead-only|disable>
set shared admin-role <name> role device webui device setup services <enable|rea
d-only|disable>
set shared admin-role <name> role device webui device setup interfaces <enable|r
ead-only|disable>
set shared admin-role <name> role device webui device setup telemetry <enable|re
ad-only|disable>
set shared admin-role <name> role device webui device setup content-id <enable|r
ead-only|disable>
set shared admin-role <name> role device webui device setup wildfire <enable|rea
d-only|disable>
set shared admin-role <name> role device webui device setup session <enable|read
-only|disable>
set shared admin-role <name> role device webui device setup hsm <enable|read-onl
y|disable>
set shared admin-role <name> role device webui device high-availability <enable|
read-only|disable>
set shared admin-role <name> role device webui device config-audit <enable|disab
le>
set shared admin-role <name> role device webui device administrators <read-only|
disable>
set shared admin-role <name> role device webui device admin-roles <read-only|dis
able>
set shared admin-role <name> role device webui device access-domain <enable|read
-only|disable>
set shared admin-role <name> role device webui device authentication-profile <en
able|read-only|disable>
set shared admin-role <name> role device webui device authentication-sequence <e
nable|read-only|disable>
set shared admin-role <name> role device webui device user-identification <enabl
e|read-only|disable>
set shared admin-role <name> role device webui device vm-info-source <enable|rea
d-only|disable>
set shared admin-role <name> role device webui device virtual-systems <enable|re
ad-only|disable>
set shared admin-role <name> role device webui device shared-gateways <enable|re
ad-only|disable>
set shared admin-role <name> role device webui device certificate-management cer
tificates <enable|read-only|disable>
set shared admin-role <name> role device webui device certificate-management cer
tificate-profile <enable|read-only|disable>
set shared admin-role <name> role device webui device certificate-management ocs
p-responder <enable|read-only|disable>
set shared admin-role <name> role device webui device certificate-management ssl
-tls-service-profile <enable|read-only|disable>
set shared admin-role <name> role device webui device certificate-management sce
p <enable|read-only|disable>
set shared admin-role <name> role device webui device certificate-management ssl
-decryption-exclusion <enable|read-only|disable>
set shared admin-role <name> role device webui device block-pages <enable|read-o
nly|disable>
set shared admin-role <name> role device webui device log-settings system <enabl
e|read-only|disable>
set shared admin-role <name> role device webui device log-settings config <enabl
e|read-only|disable>
set shared admin-role <name> role device webui device log-settings user-id <enab
le|read-only|disable>
set shared admin-role <name> role device webui device log-settings hipmatch <ena
ble|read-only|disable>
set shared admin-role <name> role device webui device log-settings correlation <
enable|read-only|disable>
set shared admin-role <name> role device webui device log-settings cc-alarm <ena
ble|read-only|disable>
set shared admin-role <name> role device webui device log-settings manage-log <e
nable|read-only|disable>
set shared admin-role <name> role device webui device server-profile snmp-trap <
enable|read-only|disable>
set shared admin-role <name> role device webui device server-profile syslog <ena
ble|read-only|disable>
set shared admin-role <name> role device webui device server-profile email <enab
le|read-only|disable>
set shared admin-role <name> role device webui device server-profile http <enabl
e|read-only|disable>
set shared admin-role <name> role device webui device server-profile netflow <en
able|read-only|disable>
set shared admin-role <name> role device webui device server-profile radius <ena
ble|read-only|disable>
set shared admin-role <name> role device webui device server-profile tacplus <en
able|read-only|disable>
set shared admin-role <name> role device webui device server-profile ldap <enabl
e|read-only|disable>
set shared admin-role <name> role device webui device server-profile kerberos <e
nable|read-only|disable>
set shared admin-role <name> role device webui device server-profile saml_idp <e
nable|read-only|disable>
set shared admin-role <name> role device webui device server-profile dns <enable
|read-only|disable>
set shared admin-role <name> role device webui device server-profile mfa <enable
|read-only|disable>
set shared admin-role <name> role device webui device local-user-database users
<enable|read-only|disable>
set shared admin-role <name> role device webui device local-user-database user-g
roups <enable|read-only|disable>
set shared admin-role <name> role device webui device scheduled-log-export <enab
le|disable>
set shared admin-role <name> role device webui device software <enable|read-only
|disable>
set shared admin-role <name> role device webui device global-protect-client <ena
ble|read-only|disable>
set shared admin-role <name> role device webui device dynamic-updates <enable|re
ad-only|disable>
set shared admin-role <name> role device webui device licenses <enable|read-only
|disable>
set shared admin-role <name> role device webui device support <enable|read-only|
disable>
set shared admin-role <name> role device webui device master-key <enable|read-on
ly|disable>
set shared admin-role <name> role device webui privacy show-full-ip-addresses <e
nable|disable>
nd-reports <enable|disable>
set shared admin-role <name> role device webui privacy view-pcap-files <enable|d
isable>
>
set shared admin-role <name> role device webui save save-for-other-admins <enabl
e|disable>
set shared admin-role <name> role device webui commit device <enable|disable>
set shared admin-role <name> role device webui commit commit-for-other-admins <e
nable|disable>
set shared admin-role <name> role device webui global system-alarms <enable|disa
ble>
devicereader>
set shared admin-role <name> role vsys webui monitor logs traffic <enable|disabl
e>
set shared admin-role <name> role vsys webui monitor logs threat <enable|disable
>
set shared admin-role <name> role vsys webui monitor logs url <enable|disable>
set shared admin-role <name> role vsys webui monitor logs wildfire <enable|disab
le>
set shared admin-role <name> role vsys webui monitor logs data-filtering <enable
|disable>
set shared admin-role <name> role vsys webui monitor logs hipmatch <enable|disab
le>
set shared admin-role <name> role vsys webui monitor logs userid <enable|disable
>
set shared admin-role <name> role vsys webui monitor logs gtp <enable|disable>
set shared admin-role <name> role vsys webui monitor logs tunnel <enable|disable
>
set shared admin-role <name> role vsys webui monitor logs sctp <enable|disable>
set shared admin-role <name> role vsys webui monitor logs authentication <enable
|disable>
set shared admin-role <name> role vsys webui monitor external-logs <enable|disab
le>
e correlation-objects <enable|disable>
e correlated-events <enable|disable>
set shared admin-role <name> role vsys webui monitor app-scope <enable|disable>
set shared admin-role <name> role vsys webui monitor session-browser <enable|rea
d-only|disable>
set shared admin-role <name> role vsys webui monitor block-ip-list <enable|read-
only|disable>
set shared admin-role <name> role vsys webui monitor pdf-reports manage-pdf-summ
ary <enable|read-only|disable>
set shared admin-role <name> role vsys webui monitor pdf-reports pdf-summary-rep
orts <enable|disable>
set shared admin-role <name> role vsys webui monitor pdf-reports user-activity-r
eport <enable|read-only|disable>
set shared admin-role <name> role vsys webui monitor pdf-reports saas-applicatio
n-usage-report <enable|read-only|disable>
set shared admin-role <name> role vsys webui monitor pdf-reports report-groups <
enable|read-only|disable>
set shared admin-role <name> role vsys webui monitor pdf-reports email-scheduler
<enable|read-only|disable>
set shared admin-role <name> role vsys webui monitor custom-reports application-
statistics <enable|disable>
set shared admin-role <name> role vsys webui monitor custom-reports data-filteri
ng-log <enable|disable>
set shared admin-role <name> role vsys webui monitor custom-reports threat-log <
enable|disable>
set shared admin-role <name> role vsys webui monitor custom-reports threat-summa
ry <enable|disable>
set shared admin-role <name> role vsys webui monitor custom-reports traffic-log
<enable|disable>
set shared admin-role <name> role vsys webui monitor custom-reports traffic-summ
ary <enable|disable>
set shared admin-role <name> role vsys webui monitor custom-reports url-log <ena
ble|disable>
set shared admin-role <name> role vsys webui monitor custom-reports url-summary
<enable|disable>
set shared admin-role <name> role vsys webui monitor custom-reports hipmatch <en
able|disable>
set shared admin-role <name> role vsys webui monitor custom-reports wildfire-log
<enable|disable>
set shared admin-role <name> role vsys webui monitor custom-reports gtp-log <ena
ble|disable>
set shared admin-role <name> role vsys webui monitor custom-reports gtp-summary
<enable|disable>
set shared admin-role <name> role vsys webui monitor custom-reports tunnel-log <
enable|disable>
set shared admin-role <name> role vsys webui monitor custom-reports tunnel-summa
ry <enable|disable>
set shared admin-role <name> role vsys webui monitor custom-reports sctp-log <en
able|disable>
set shared admin-role <name> role vsys webui monitor custom-reports sctp-summary
<enable|disable>
set shared admin-role <name> role vsys webui monitor custom-reports userid <enab
le|disable>
set shared admin-role <name> role vsys webui monitor custom-reports auth <enable
|disable>
set shared admin-role <name> role vsys webui monitor view-custom-reports <enable
|disable>
set shared admin-role <name> role vsys webui policies security-rulebase <enable|
read-only|disable>
set shared admin-role <name> role vsys webui policies nat-rulebase <enable|read-
only|disable>
set shared admin-role <name> role vsys webui policies qos-rulebase <enable|read-
only|disable>
set shared admin-role <name> role vsys webui policies pbf-rulebase <enable|read-
only|disable>
set shared admin-role <name> role vsys webui policies ssl-decryption-rulebase <e
nable|read-only|disable>
set shared admin-role <name> role vsys webui policies tunnel-inspect-rulebase <e
nable|read-only|disable>
ase <enable|read-only|disable>
set shared admin-role <name> role vsys webui policies authentication-rulebase <e
nable|read-only|disable>
set shared admin-role <name> role vsys webui policies dos-rulebase <enable|read-
only|disable>
set shared admin-role <name> role vsys webui policies rule-hit-count-reset <enab
le|disable>
set shared admin-role <name> role vsys webui objects addresses <enable|read-only
|disable>
set shared admin-role <name> role vsys webui objects address-groups <enable|read
-only|disable>
set shared admin-role <name> role vsys webui objects regions <enable|read-only|d
isable>
set shared admin-role <name> role vsys webui objects applications <enable|read-o
nly|disable>
set shared admin-role <name> role vsys webui objects application-groups <enable|
read-only|disable>
set shared admin-role <name> role vsys webui objects application-filters <enable
|read-only|disable>
set shared admin-role <name> role vsys webui objects services <enable|read-only|
disable>
set shared admin-role <name> role vsys webui objects service-groups <enable|read
-only|disable>
set shared admin-role <name> role vsys webui objects tags <enable|read-only|disa
ble>
set shared admin-role <name> role vsys webui objects global-protect hip-objects
<enable|read-only|disable>
set shared admin-role <name> role vsys webui objects global-protect hip-profiles
<enable|read-only|disable>
set shared admin-role <name> role vsys webui objects dynamic-block-lists <enable
|read-only|disable>
set shared admin-role <name> role vsys webui objects custom-objects
set shared admin-role <name> role vsys webui objects custom-objects data-pattern
s <enable|read-only|disable>
set shared admin-role <name> role vsys webui objects custom-objects spyware <ena
ble|read-only|disable>
set shared admin-role <name> role vsys webui objects custom-objects vulnerabilit
y <enable|read-only|disable>
set shared admin-role <name> role vsys webui objects custom-objects url-category
<enable|read-only|disable>
set shared admin-role <name> role vsys webui objects security-profiles antivirus
<enable|read-only|disable>
set shared admin-role <name> role vsys webui objects security-profiles anti-spyw
are <enable|read-only|disable>
set shared admin-role <name> role vsys webui objects security-profiles vulnerabi
lity-protection <enable|read-only|disable>
set shared admin-role <name> role vsys webui objects security-profiles url-filte
ring <enable|read-only|disable>
set shared admin-role <name> role vsys webui objects security-profiles file-bloc
king <enable|read-only|disable>
set shared admin-role <name> role vsys webui objects security-profiles wildfire-
analysis <enable|read-only|disable>
set shared admin-role <name> role vsys webui objects security-profiles data-filt
ering <enable|read-only|disable>
set shared admin-role <name> role vsys webui objects security-profiles dos-prote
ction <enable|read-only|disable>
set shared admin-role <name> role vsys webui objects security-profile-groups <en
able|read-only|disable>
set shared admin-role <name> role vsys webui objects log-forwarding <enable|read
-only|disable>
set shared admin-role <name> role vsys webui objects authentication <enable|read
-only|disable>
set shared admin-role <name> role vsys webui objects decryption
set shared admin-role <name> role vsys webui objects decryption decryption-profi
le <enable|read-only|disable>
set shared admin-role <name> role vsys webui objects decryption decryption-forwa
rding-profile <enable|read-only|disable>
set shared admin-role <name> role vsys webui objects schedules <enable|read-only
|disable>
set shared admin-role <name> role vsys webui network zones <enable|read-only|dis
able>
set shared admin-role <name> role vsys webui network global-protect portals <ena
ble|read-only|disable>
set shared admin-role <name> role vsys webui network global-protect gateways <en
able|read-only|disable>
set shared admin-role <name> role vsys webui network global-protect mdm <enable|
read-only|disable>
set shared admin-role <name> role vsys webui network global-protect device-block
-list <enable|read-only|disable>
set shared admin-role <name> role vsys webui network global-protect clientless-a
pps <enable|read-only|disable>
set shared admin-role <name> role vsys webui network global-protect clientless-a
pp-groups <enable|read-only|disable>
set shared admin-role <name> role vsys webui device setup management <read-only|
disable>
set shared admin-role <name> role vsys webui device setup operations <read-only|
disable>
set shared admin-role <name> role vsys webui device setup services <enable|read-
only|disable>
set shared admin-role <name> role vsys webui device setup interfaces <enable|rea
d-only|disable>
set shared admin-role <name> role vsys webui device setup telemetry <enable|read
-only|disable>
set shared admin-role <name> role vsys webui device setup content-id <read-only|
disable>
set shared admin-role <name> role vsys webui device setup wildfire <read-only|di
sable>
set shared admin-role <name> role vsys webui device setup session <read-only|dis
able>
set shared admin-role <name> role vsys webui device setup hsm <read-only|disable
>
set shared admin-role <name> role vsys webui device administrators <read-only|di
sable>
set shared admin-role <name> role vsys webui device authentication-profile <enab
le|read-only|disable>
set shared admin-role <name> role vsys webui device authentication-sequence <ena
ble|read-only|disable>
set shared admin-role <name> role vsys webui device user-identification <enable|
read-only|disable>
set shared admin-role <name> role vsys webui device vm-info-source <enable|read-
only|disable>
set shared admin-role <name> role vsys webui device certificate-management certi
ficates <enable|read-only|disable>
set shared admin-role <name> role vsys webui device certificate-management certi
ficate-profile <enable|read-only|disable>
set shared admin-role <name> role vsys webui device certificate-management ocsp-
responder <enable|read-only|disable>
set shared admin-role <name> role vsys webui device certificate-management ssl-t
ls-service-profile <enable|read-only|disable>
set shared admin-role <name> role vsys webui device certificate-management scep
<enable|read-only|disable>
set shared admin-role <name> role vsys webui device certificate-management ssl-d
ecryption-exclusion <enable|read-only|disable>
set shared admin-role <name> role vsys webui device block-pages <enable|read-onl
y|disable>
set shared admin-role <name> role vsys webui device log-settings system <read-on
ly|disable>
set shared admin-role <name> role vsys webui device log-settings config <read-on
ly|disable>
set shared admin-role <name> role vsys webui device log-settings user-id <read-o
nly|disable>
set shared admin-role <name> role vsys webui device log-settings hipmatch <read-
only|disable>
set shared admin-role <name> role vsys webui device log-settings correlation <re
ad-only|disable>
set shared admin-role <name> role vsys webui device server-profile snmp-trap <en
able|read-only|disable>
set shared admin-role <name> role vsys webui device server-profile syslog <enabl
e|read-only|disable>
set shared admin-role <name> role vsys webui device server-profile email <enable
|read-only|disable>
set shared admin-role <name> role vsys webui device server-profile http <enable|
read-only|disable>
set shared admin-role <name> role vsys webui device server-profile netflow <enab
le|read-only|disable>
set shared admin-role <name> role vsys webui device server-profile radius <enabl
e|read-only|disable>
set shared admin-role <name> role vsys webui device server-profile tacplus <enab
le|read-only|disable>
set shared admin-role <name> role vsys webui device server-profile ldap <enable|
read-only|disable>
set shared admin-role <name> role vsys webui device server-profile kerberos <ena
ble|read-only|disable>
set shared admin-role <name> role vsys webui device server-profile saml_idp <ena
ble|read-only|disable>
set shared admin-role <name> role vsys webui device server-profile dns <enable|r
ead-only|disable>
set shared admin-role <name> role vsys webui device server-profile mfa <enable|r
ead-only|disable>
set shared admin-role <name> role vsys webui device local-user-database users <e
nable|read-only|disable>
set shared admin-role <name> role vsys webui device local-user-database user-gro
ups <enable|read-only|disable>
set shared admin-role <name> role vsys webui privacy show-full-ip-addresses <ena
ble|disable>
-reports <enable|disable>
set shared admin-role <name> role vsys webui privacy view-pcap-files <enable|dis
able>
set shared admin-role <name> role vsys webui save partial-save <enable|disable>
set shared admin-role <name> role vsys webui save save-for-other-admins <enable|
disable>
set shared admin-role <name> role vsys webui commit virtual-systems <enable|disa
ble>
set shared admin-role <name> role vsys webui commit commit-for-other-admins <ena
ble|disable>
>
set vsys
.]
er2>... ]
e>|<%USERINPUT%|%USERINPUT%@%USERDOMAIN%|%USERDOMAIN%\%USERINPUT%>
value>
lue>
lue>
-list2>... ]
e>
>
>
lue>
ue>
lue>
ut <yes|no>
rtificate <value>
set vsys <name> authentication-profile <name> method saml-idp certificate-profil
e <value>
rname <value>
rgroup <value>
in-role <value>
ess-domain <value>
no>
ors1> <factors2>... ]
ntication-profiles1> <authentication-profiles2>... ]
ncipal-name>
ry|sun|other>
set vsys <name> server-profile ldap <name> server <name> address <ip/netmask>|<v
alue>
set vsys <name> server-profile ldap <name> server <name> port <1-65535>
d <yes|no>
ange <yes|no>
profile <value>
d <yes|no>
profile <value>
er-id <yes|no>
ert-profile <value>
set vsys <name> server-profile radius <name> server <name> ip-address <ip/netmas
k>|<value>
set vsys <name> server-profile radius <name> server <name> secret <value>
set vsys <name> server-profile radius <name> server <name> port <1-65535>
set vsys <name> server-profile kerberos <name> server <name> host <ip/netmask>|<
value>
set vsys <name> server-profile kerberos <name> server <name> port <1-65535>
set vsys <name> server-profile tacplus <name> server <name> address <ip/netmask>
|<value>
set vsys <name> server-profile tacplus <name> server <name> secret <value>
set vsys <name> server-profile tacplus <name> server <name> port <1-65535>
>
600>
00>
set vsys <name> server-profile netflow <name> server <name> host <ip/netmask>|<v
alue>
set vsys <name> server-profile netflow <name> server <name> port <1-65535>
ited>
erited>
>
<value>
me1> <domain-name2>... ]
set vsys <name> dns-proxy <name> static-entries <name> address [ <address1> <ad
dress2>... ]
set vsys <name> log-settings snmptrap <name> version v2c server <name> manager <
ip/netmask>|<value>
set vsys <name> log-settings snmptrap <name> version v2c server <name> community
<value>
set vsys <name> log-settings snmptrap <name> version v3 server <name> manager <i
p/netmask>|<value>
set vsys <name> log-settings snmptrap <name> version v3 server <name> user <valu
e>
set vsys <name> log-settings snmptrap <name> version v3 server <name> engineid <
value>
set vsys <name> log-settings snmptrap <name> version v3 server <name> authpwd <v
alue>
set vsys <name> log-settings snmptrap <name> version v3 server <name> privpwd <v
alue>
set vsys <name> log-settings email <name> server <name> display-name <value>
set vsys <name> log-settings email <name> server <name> from <value>
set vsys <name> log-settings email <name> server <name> and-also-to <value>
set vsys <name> log-settings email <name> server <name> gateway <value>
set vsys <name> log-settings email <name> format escaping escaped-characters <va
lue>
set vsys <name> log-settings email <name> format escaping escape-character <valu
e>
set vsys <name> log-settings syslog <name> server <name> server <value>
set vsys <name> log-settings syslog <name> server <name> transport <UDP|TCP|SSL>
set vsys <name> log-settings syslog <name> server <name> port <1-65535>
set vsys <name> log-settings syslog <name> server <name> format <BSD|IETF>
set vsys <name> log-settings syslog <name> server <name> facility <LOG_USER|LOG_
LOCAL0|LOG_LOCAL1|LOG_LOCAL2|LOG_LOCAL3|LOG_LOCAL4|LOG_LOCAL5|LOG_LOCAL6|LOG_LOC
AL7>
set vsys <name> log-settings syslog <name> format escaping escaped-characters <v
alue>
set vsys <name> log-settings syslog <name> format escaping escape-character <val
ue>
set vsys <name> log-settings http <name> server <name> address <value>
set vsys <name> log-settings http <name> server <name> protocol <HTTP|HTTPS>
set vsys <name> log-settings http <name> server <name> port <1-65535>
set vsys <name> log-settings http <name> server <name> http-method <value>
set vsys <name> log-settings http <name> server <name> username <value>
set vsys <name> log-settings http <name> server <name> password <value>
set vsys <name> log-settings http <name> format config name <value>
set vsys <name> log-settings http <name> format config url-format <value>
set vsys <name> log-settings http <name> format config headers <name>
set vsys <name> log-settings http <name> format config headers <name> value <val
ue>
set vsys <name> log-settings http <name> format config params <name>
set vsys <name> log-settings http <name> format config params <name> value <valu
e>
set vsys <name> log-settings http <name> format config payload <value>
set vsys <name> log-settings http <name> format system name <value>
set vsys <name> log-settings http <name> format system url-format <value>
set vsys <name> log-settings http <name> format system headers <name>
set vsys <name> log-settings http <name> format system headers <name> value <val
ue>
set vsys <name> log-settings http <name> format system params <name>
set vsys <name> log-settings http <name> format system params <name> value <valu
e>
set vsys <name> log-settings http <name> format system payload <value>
set vsys <name> log-settings http <name> format traffic name <value>
set vsys <name> log-settings http <name> format traffic url-format <value>
set vsys <name> log-settings http <name> format traffic headers <name>
set vsys <name> log-settings http <name> format traffic headers <name> value <va
lue>
set vsys <name> log-settings http <name> format traffic params <name>
set vsys <name> log-settings http <name> format traffic params <name> value <val
ue>
set vsys <name> log-settings http <name> format traffic payload <value>
set vsys <name> log-settings http <name> format threat name <value>
set vsys <name> log-settings http <name> format threat url-format <value>
set vsys <name> log-settings http <name> format threat headers <name>
set vsys <name> log-settings http <name> format threat headers <name> value <val
ue>
set vsys <name> log-settings http <name> format threat params <name>
set vsys <name> log-settings http <name> format threat params <name> value <valu
e>
set vsys <name> log-settings http <name> format threat payload <value>
set vsys <name> log-settings http <name> format wildfire name <value>
set vsys <name> log-settings http <name> format wildfire url-format <value>
set vsys <name> log-settings http <name> format wildfire headers <name>
set vsys <name> log-settings http <name> format wildfire headers <name> value <v
alue>
set vsys <name> log-settings http <name> format wildfire params <name>
set vsys <name> log-settings http <name> format wildfire params <name> value <va
lue>
set vsys <name> log-settings http <name> format wildfire payload <value>
set vsys <name> log-settings http <name> format url name <value>
set vsys <name> log-settings http <name> format url url-format <value>
set vsys <name> log-settings http <name> format url headers <name>
set vsys <name> log-settings http <name> format url headers <name> value <value>
set vsys <name> log-settings http <name> format url params <name>
set vsys <name> log-settings http <name> format url params <name> value <value>
set vsys <name> log-settings http <name> format url payload <value>
set vsys <name> log-settings http <name> format data name <value>
set vsys <name> log-settings http <name> format data url-format <value>
set vsys <name> log-settings http <name> format data headers <name> value <value
>
set vsys <name> log-settings http <name> format data params <name>
set vsys <name> log-settings http <name> format data params <name> value <value>
set vsys <name> log-settings http <name> format data payload <value>
set vsys <name> log-settings http <name> format tunnel name <value>
set vsys <name> log-settings http <name> format tunnel url-format <value>
set vsys <name> log-settings http <name> format tunnel headers <name>
set vsys <name> log-settings http <name> format tunnel headers <name> value <val
ue>
set vsys <name> log-settings http <name> format tunnel params <name>
set vsys <name> log-settings http <name> format tunnel params <name> value <valu
e>
set vsys <name> log-settings http <name> format tunnel payload <value>
set vsys <name> log-settings http <name> format auth name <value>
set vsys <name> log-settings http <name> format auth url-format <value>
set vsys <name> log-settings http <name> format auth headers <name>
set vsys <name> log-settings http <name> format auth headers <name> value <value
>
set vsys <name> log-settings http <name> format auth params <name>
set vsys <name> log-settings http <name> format auth params <name> value <value>
set vsys <name> log-settings http <name> format auth payload <value>
set vsys <name> log-settings http <name> format userid name <value>
set vsys <name> log-settings http <name> format userid url-format <value>
set vsys <name> log-settings http <name> format userid headers <name>
set vsys <name> log-settings http <name> format userid headers <name> value <val
ue>
set vsys <name> log-settings http <name> format userid params <name>
set vsys <name> log-settings http <name> format userid params <name> value <valu
e>
set vsys <name> log-settings http <name> format userid payload <value>
set vsys <name> log-settings http <name> format hip-match name <value>
set vsys <name> log-settings http <name> format hip-match url-format <value>
set vsys <name> log-settings http <name> format hip-match headers <name>
set vsys <name> log-settings http <name> format hip-match headers <name> value <
value>
set vsys <name> log-settings http <name> format hip-match params <name>
set vsys <name> log-settings http <name> format hip-match params <name> value <v
alue>
set vsys <name> log-settings http <name> format hip-match payload <value>
set vsys <name> log-settings http <name> format correlation name <value>
set vsys <name> log-settings http <name> format correlation url-format <value>
set vsys <name> log-settings http <name> format correlation headers <name>
set vsys <name> log-settings http <name> format correlation headers <name> value
<value>
set vsys <name> log-settings http <name> format correlation params <name>
set vsys <name> log-settings http <name> format correlation params <name> value
<value>
set vsys <name> log-settings http <name> format correlation payload <value>
o>
set vsys <name> log-settings profiles <name> match-list <name> action-desc <valu
e>
set vsys <name> log-settings profiles <name> match-list <name> log-type <traffic
|threat|wildfire|url|data|tunnel|auth>
set vsys <name> log-settings profiles <name> match-list <name> filter <value>
<yes|no>
<send-snmptrap1> <send-snmptrap2>... ]
set vsys <name> log-settings profiles <name> match-list <name> send-email [ <se
nd-email1> <send-email2>... ]
set vsys <name> log-settings profiles <name> match-list <name> send-syslog [ <s
end-syslog1> <send-syslog2>... ]
set vsys <name> log-settings profiles <name> match-list <name> send-http [ <sen
d-http1> <send-http2>... ]
set vsys <name> log-settings profiles <name> match-list <name> actions <name>
set vsys <name> log-settings profiles <name> match-list <name> actions <name> ty
pe
set vsys <name> log-settings profiles <name> match-list <name> actions <name> ty
pe tagging
set vsys <name> log-settings profiles <name> match-list <name> actions <name> ty
set vsys <name> log-settings profiles <name> match-list <name> actions <name> ty
pe tagging registration
set vsys <name> log-settings profiles <name> match-list <name> actions <name> ty
set vsys <name> log-settings profiles <name> match-list <name> actions <name> ty
set vsys <name> log-settings profiles <name> match-list <name> actions <name> ty
set vsys <name> log-settings profiles <name> match-list <name> actions <name> ty
set vsys <name> log-settings profiles <name> match-list <name> actions <name> ty
s1-0|tls1-1|tls1-2>
s1-0|tls1-1|tls1-2|max>
a <yes|no>
e <yes|no>
dhe <yes|no>
yes|no>
es|no>
8-cbc <yes|no>
6-cbc <yes|no>
8-gcm <yes|no>
6-gcm <yes|no>
<yes|no>
6 <yes|no>
e <value>
<value>
<value>
t-ca-exclude-list2>... ]
CA2>... ]
value>
.]
rvice-account
1200>
le <yes|no>
0>
>
|no>
-id-agents2>... ]
ct2>... ]
er2>... ]
.]
>... ]
.]
>... ]
me-11> <alternate-user-name-12>... ]
set vsys <name> group-mapping <name> alternate-user-name-2 [ <alternate-user-na
me-21> <alternate-user-name-22>... ]
me-31> <alternate-user-name-32>... ]
ntainer-object2>... ]
st-modify-attr2>... ]
<group-include-list2>... ]
>
vent-regex <value>
sername-regex <value>
set vsys <name> user-id-collector syslog-parse-profile <name> regex-identifier a
ddress-regex <value>
vent-string <value>
sername-prefix <value>
sername-delimiter <value>
ddress-prefix <value>
ddress-delimiter <value>
p/netmask>|<value>
k>|<value>
le <value>
sk>
udp|ssl>
set vsys <name> user-id-collector server-monitor <name> syslog syslog-parse-prof
ile
ile <name>
me <value>
o>
ude|exclude>
<ip/netmask>
.]
e2>... ]
st2>... ]
st2>... ]
address
address
address ip
address floating-ip
s-service-profile <value>
-auth
-auth <name>
icate-profile <value>
-login-page <value>
-home-page <value>
-help-page <value>
set vsys <name> global-protect global-protect-portal <name> clientless-vpn
ame <value>
ity-zone <value>
-lifetime
ivity-logout
ser <1-30000>
roxy <value>
o-settings
o-settings ssl-protocol
o-settings server-cert-verification
-list2>... ]
to-user-mapping
to-user-mapping <name>
-server-setting
-server-setting <name>
a <name>
user-override-key <value>
s <name>
s <name> gateways
code2>... ]
5|6>
s <name> internal-host-detection
s <name> internal-host-detection-v6
s <name> agent-ui
s <name> hip-collection
uct1> <product2>... ]
[ <registry-value1> <registry-value2>... ]
rocess-list2>... ]
.]
ocess-list2>... ]
clients2>... ]
s <name> agent-config
s <name> gp-app-config
s <name> client-certificate
s <name> authentication-override
<1-365>
<1-72>
es <1-59>
ent-certificate
ent-certificate local
ent-certificate scep
figs
figs <name>
<value>
configs
configs <name>
-days <1-365>
-hours <1-72>
-minutes <1-59>
.]
exclude-access-route2>... ]
include-applications2>... ]
rts2>... ]
exclude-applications2>... ]
rts2>... ]
<authentication-server-ip-pool2>... ]
file <value>
os <value>|<Any|Satellite|X-Auth>
set vsys <name> global-protect global-protect-gateway <name> client-auth <name>
authentication-profile <value>
username-label <value>
password-label <value>
authentication-message <value>
<value>
alue>
>
dress-family <ipv4|ipv6|ipv4_ipv6>
face <value>
v4 <value>
v6 <value>
ing-ip
lifetime
vity-logout
nect-on-idle
ame>
ame> match-message
ame> not-match-message
root-ca2>... ]
ue>
>
<members2>... ]
set vsys <name> profiles hip-objects <name> host-info criteria domain contains <
value>
set vsys <name> profiles hip-objects <name> host-info criteria domain is <value>
set vsys <name> profiles hip-objects <name> host-info criteria domain is-not <va
lue>
set vsys <name> profiles hip-objects <name> host-info criteria os contains Micro
soft <value>
set vsys <name> profiles hip-objects <name> host-info criteria os contains Apple
<value>
set vsys <name> profiles hip-objects <name> host-info criteria os contains Googl
e <value>
set vsys <name> profiles hip-objects <name> host-info criteria os contains Linux
<value>
set vsys <name> profiles hip-objects <name> host-info criteria os contains Other
<value>
ntains <value>
<value>
-not <value>
set vsys <name> profiles hip-objects <name> host-info criteria host-name contain
s <value>
set vsys <name> profiles hip-objects <name> host-info criteria host-name is <val
ue>
set vsys <name> profiles hip-objects <name> host-info criteria host-name is-not
<value>
set vsys <name> profiles hip-objects <name> host-info criteria host-id contains
<value>
set vsys <name> profiles hip-objects <name> host-info criteria host-id is <value
>
set vsys <name> profiles hip-objects <name> host-info criteria host-id is-not <v
alue>
set vsys <name> profiles hip-objects <name> network-info criteria network is wif
set vsys <name> profiles hip-objects <name> network-info criteria network is wif
i ssid <value>
set vsys <name> profiles hip-objects <name> network-info criteria network is mob
ile
set vsys <name> profiles hip-objects <name> network-info criteria network is mob
set vsys <name> profiles hip-objects <name> network-info criteria network is unk
nown
set vsys <name> profiles hip-objects <name> network-info criteria network is-not
set vsys <name> profiles hip-objects <name> network-info criteria network is-not
wifi
set vsys <name> profiles hip-objects <name> network-info criteria network is-not
mobile
set vsys <name> profiles hip-objects <name> network-info criteria network is-not
set vsys <name> profiles hip-objects <name> network-info criteria network is-not
ethernet
set vsys <name> profiles hip-objects <name> network-info criteria network is-not
unknown
ed <yes|no>
<no|yes|not-available>
tches
tches severity
tches severity
set vsys <name> profiles hip-objects <name> patch-management vendor <name> produ
ct [ <product1> <product2>... ]
|no>
talled <yes|no>
bled <no|yes|not-available>
<yes|no>
set vsys <name> profiles hip-objects <name> firewall criteria is-installed <yes|
no>
set vsys <name> profiles hip-objects <name> firewall criteria is-enabled <no|yes
|not-available>
set vsys <name> profiles hip-objects <name> firewall vendor <name> product [ <p
roduct1> <product2>... ]
set vsys <name> profiles hip-objects <name> firewall exclude-vendor <yes|no>
within
not-within
n greater-equal <value>
n greater-than <value>
n is <value>
n is-not <value>
n less-than <value>
n contains <value>
n within
n not-within
set vsys <name> profiles hip-objects <name> anti-malware criteria is-installed <
yes|no>
ection <no|yes|not-available>
not-available
within
not-within
set vsys <name> profiles hip-objects <name> anti-malware vendor <name> product
[ <product1> <product2>... ]
set vsys <name> profiles hip-objects <name> disk-backup criteria is-installed <y
es|no>
e not-available
e within
e not-within
<product1> <product2>... ]
d <yes|no>
ocations
ocations <name>
set vsys <name> profiles hip-objects <name> disk-encryption vendor <name> produc
t [ <product1> <product2>... ]
no>
<name>
<name> registry-value
set vsys <name> profiles hip-objects <name> custom-checks criteria plist <name>
set vsys <name> profiles hip-objects <name> custom-checks criteria plist <name>
negate <yes|no>
set vsys <name> profiles hip-objects <name> custom-checks criteria plist <name>
key
set vsys <name> profiles hip-objects <name> custom-checks criteria plist <name>
key <name>
set vsys <name> profiles hip-objects <name> custom-checks criteria plist <name>
set vsys <name> profiles hip-objects <name> custom-checks criteria plist <name>
set vsys <name> profiles hip-objects <name> mobile-device criteria jailbroken <n
o|yes>
d <no|yes>
m <no|yes>
time
time
time within
time not-within
set vsys <name> profiles hip-objects <name> mobile-device criteria imei contains
<value>
set vsys <name> profiles hip-objects <name> mobile-device criteria imei is <valu
e>
set vsys <name> profiles hip-objects <name> mobile-device criteria imei is-not <
value>
set vsys <name> profiles hip-objects <name> mobile-device criteria model contain
s <value>
set vsys <name> profiles hip-objects <name> mobile-device criteria model is <val
ue>
set vsys <name> profiles hip-objects <name> mobile-device criteria model is-not
<value>
contains <value>
is <value>
is-not <value>
contains <value>
is <value>
is-not <value>
set vsys <name> profiles hip-objects <name> mobile-device criteria tag contains
<value>
set vsys <name> profiles hip-objects <name> mobile-device criteria tag is <value
>
set vsys <name> profiles hip-objects <name> mobile-device criteria tag is-not <v
alue>
has-malware
has-malware no
has-malware yes
set vsys <name> profiles hip-objects <name> mobile-device criteria applications
has-unmanaged-app <no|yes>
includes
includes <name>
set vsys <name> profiles virus <name> decoder <name> action <default|allow|alert
|drop|reset-client|reset-server|reset-both>
set vsys <name> profiles virus <name> decoder <name> wildfire-action <default|al
low|alert|drop|reset-client|reset-server|reset-both>
set vsys <name> profiles virus <name> application <name> action <default|allow|a
lert|drop|reset-client|reset-server|reset-both>
set vsys <name> profiles virus <name> threat-exception
set vsys <name> profiles spyware <name> botnet-domains lists <name> action
set vsys <name> profiles spyware <name> botnet-domains lists <name> action alert
set vsys <name> profiles spyware <name> botnet-domains lists <name> action allow
set vsys <name> profiles spyware <name> botnet-domains lists <name> action block
set vsys <name> profiles spyware <name> botnet-domains lists <name> action sinkh
ole
set vsys <name> profiles spyware <name> botnet-domains sinkhole ipv4-address <ip
/netmask>|<127.0.0.1|pan-sinkhole-default-ip>
set vsys <name> profiles spyware <name> botnet-domains sinkhole ipv6-address <ip
/netmask>|<::1>
ingle-packet|extended-capture>
set vsys <name> profiles spyware <name> rules <name> threat-name <value>|<any>
set vsys <name> profiles spyware <name> rules <name> category <value>|<any>
set vsys <name> profiles spyware <name> rules <name> severity [ <severity1> <se
verity2>... ]
set vsys <name> profiles spyware <name> rules <name> action
set vsys <name> profiles spyware <name> rules <name> action default
set vsys <name> profiles spyware <name> rules <name> action allow
set vsys <name> profiles spyware <name> rules <name> action alert
set vsys <name> profiles spyware <name> rules <name> action drop
set vsys <name> profiles spyware <name> rules <name> action reset-client
set vsys <name> profiles spyware <name> rules <name> action reset-server
set vsys <name> profiles spyware <name> rules <name> action reset-both
set vsys <name> profiles spyware <name> rules <name> action block-ip
set vsys <name> profiles spyware <name> rules <name> action block-ip track-by <s
ource|source-and-destination>
set vsys <name> profiles spyware <name> rules <name> action block-ip duration <1
-3600>
set vsys <name> profiles spyware <name> rules <name> packet-capture <disable|sin
gle-packet|extended-capture>
set vsys <name> profiles spyware <name> threat-exception <name> packet-capture <
disable|single-packet|extended-capture>
set vsys <name> profiles spyware <name> threat-exception <name> action default
set vsys <name> profiles spyware <name> threat-exception <name> action allow
set vsys <name> profiles spyware <name> threat-exception <name> action alert
set vsys <name> profiles spyware <name> threat-exception <name> action drop
set vsys <name> profiles spyware <name> threat-exception <name> action reset-bot
set vsys <name> profiles spyware <name> threat-exception <name> action reset-cli
ent
set vsys <name> profiles spyware <name> threat-exception <name> action reset-ser
ver
set vsys <name> profiles spyware <name> threat-exception <name> action block-ip
set vsys <name> profiles spyware <name> threat-exception <name> action block-ip
track-by <source|source-and-destination>
set vsys <name> profiles spyware <name> threat-exception <name> action block-ip
duration <1-3600>
set vsys <name> profiles spyware <name> threat-exception <name> exempt-ip <name>
set vsys <name> profiles vulnerability <name> rules <name> threat-name <value>|<
any>
set vsys <name> profiles vulnerability <name> rules <name> cve [ <cve1> <cve2>.
.. ]
set vsys <name> profiles vulnerability <name> rules <name> host <any|client|serv
er>
set vsys <name> profiles vulnerability <name> rules <name> vendor-id [ <vendor-
id1> <vendor-id2>... ]
set vsys <name> profiles vulnerability <name> rules <name> severity [ <severity
1> <severity2>... ]
set vsys <name> profiles vulnerability <name> rules <name> category <value>|<any
>
set vsys <name> profiles vulnerability <name> rules <name> action default
set vsys <name> profiles vulnerability <name> rules <name> action allow
set vsys <name> profiles vulnerability <name> rules <name> action alert
set vsys <name> profiles vulnerability <name> rules <name> action drop
set vsys <name> profiles vulnerability <name> rules <name> action reset-client
set vsys <name> profiles vulnerability <name> rules <name> action reset-server
set vsys <name> profiles vulnerability <name> rules <name> action reset-both
set vsys <name> profiles vulnerability <name> rules <name> action block-ip
set vsys <name> profiles vulnerability <name> rules <name> action block-ip track
-by <source|source-and-destination>
set vsys <name> profiles vulnerability <name> rules <name> action block-ip durat
ion <1-3600>
set vsys <name> profiles vulnerability <name> rules <name> packet-capture <disab
le|single-packet|extended-capture>
ture <disable|single-packet|extended-capture>
set vsys <name> profiles vulnerability <name> threat-exception <name> action def
ault
set vsys <name> profiles vulnerability <name> threat-exception <name> action all
ow
set vsys <name> profiles vulnerability <name> threat-exception <name> action ale
rt
set vsys <name> profiles vulnerability <name> threat-exception <name> action dro
set vsys <name> profiles vulnerability <name> threat-exception <name> action res
et-client
set vsys <name> profiles vulnerability <name> threat-exception <name> action res
et-server
set vsys <name> profiles vulnerability <name> threat-exception <name> action res
et-both
set vsys <name> profiles vulnerability <name> threat-exception <name> action blo
ck-ip
set vsys <name> profiles vulnerability <name> threat-exception <name> action blo
set vsys <name> profiles vulnerability <name> threat-exception <name> action blo
<name>
ert>
-list2>... ]
-list2>... ]
>... ]
>... ]
ed
set vsys <name> profiles url-filtering <name> credential-enforcement mode ip-use
-credentials
mapping <value>
y <value>
llow1> <allow2>... ]
lert1> <alert2>... ]
lock1> <block2>... ]
<continue1> <continue2>... ]
<name>
<name> headers
set vsys <name> profiles file-blocking <name> rules <name> application [ <appli
cation1> <application2>... ]
set vsys <name> profiles file-blocking <name> rules <name> file-type [ <file-ty
pe1> <file-type2>... ]
set vsys <name> profiles file-blocking <name> rules <name> direction <upload|dow
nload|both>
set vsys <name> profiles file-blocking <name> rules <name> action <alert|block|c
ontinue>
set vsys <name> profiles wildfire-analysis <name> rules <name> application [ <a
pplication1> <application2>... ]
set vsys <name> profiles wildfire-analysis <name> rules <name> file-type [ <fil
e-type1> <file-type2>... ]
set vsys <name> profiles wildfire-analysis <name> rules <name> direction <upload
|download|both>
set vsys <name> profiles wildfire-analysis <name> rules <name> analysis <public-
cloud|private-cloud>
set vsys <name> profiles data-objects <name> pattern-type predefined pattern <na
me>
set vsys <name> profiles data-objects <name> pattern-type predefined pattern <na
set vsys <name> profiles data-objects <name> pattern-type regex pattern <name>
set vsys <name> profiles data-objects <name> pattern-type regex pattern <name> f
set vsys <name> profiles data-objects <name> pattern-type regex pattern <name> r
egex <value>
n <name>
set vsys <name> profiles data-filtering <name> rules <name> data-object <value>
set vsys <name> profiles data-filtering <name> rules <name> application [ <appl
ication1> <application2>... ]
set vsys <name> profiles data-filtering <name> rules <name> file-type [ <file-t
ype1> <file-type2>... ]
set vsys <name> profiles data-filtering <name> rules <name> direction <upload|do
wnload|both>
set vsys <name> profiles data-filtering <name> rules <name> alert-threshold <0-6
5535>
set vsys <name> profiles data-filtering <name> rules <name> block-threshold <0-6
5535>
set vsys <name> profiles data-filtering <name> rules <name> log-severity <value>
set vsys <name> profiles dos-protection <name> flood tcp-syn enable <yes|no>
000000>
set vsys <name> profiles dos-protection <name> flood tcp-syn red activate-rate <
1-2000000>
set vsys <name> profiles dos-protection <name> flood tcp-syn red maximal-rate <1
-2000000>
set vsys <name> profiles dos-protection <name> flood tcp-syn red block
set vsys <name> profiles dos-protection <name> flood tcp-syn red block duration
<1-21600>
set vsys <name> profiles dos-protection <name> flood tcp-syn syn-cookies alarm-r
ate <0-2000000>
set vsys <name> profiles dos-protection <name> flood tcp-syn syn-cookies activat
e-rate <0-2000000>
set vsys <name> profiles dos-protection <name> flood tcp-syn syn-cookies maximal
-rate <1-2000000>
set vsys <name> profiles dos-protection <name> flood tcp-syn syn-cookies block
set vsys <name> profiles dos-protection <name> flood tcp-syn syn-cookies block d
uration <1-21600>
set vsys <name> profiles dos-protection <name> flood udp enable <yes|no>
set vsys <name> profiles dos-protection <name> flood udp red alarm-rate <0-20000
00>
set vsys <name> profiles dos-protection <name> flood udp red activate-rate <1-20
00000>
set vsys <name> profiles dos-protection <name> flood udp red maximal-rate <1-200
0000>
set vsys <name> profiles dos-protection <name> flood udp red block
set vsys <name> profiles dos-protection <name> flood udp red block duration <1-2
1600>
set vsys <name> profiles dos-protection <name> flood icmp red alarm-rate <0-2000
000>
set vsys <name> profiles dos-protection <name> flood icmp red activate-rate <1-2
000000>
set vsys <name> profiles dos-protection <name> flood icmp red maximal-rate <1-20
00000>
set vsys <name> profiles dos-protection <name> flood icmp red block
set vsys <name> profiles dos-protection <name> flood icmp red block duration <1-
21600>
set vsys <name> profiles dos-protection <name> flood icmpv6 enable <yes|no>
set vsys <name> profiles dos-protection <name> flood icmpv6 red alarm-rate <0-20
00000>
set vsys <name> profiles dos-protection <name> flood icmpv6 red activate-rate <1
-2000000>
set vsys <name> profiles dos-protection <name> flood icmpv6 red maximal-rate <1-
2000000>
set vsys <name> profiles dos-protection <name> flood icmpv6 red block
set vsys <name> profiles dos-protection <name> flood icmpv6 red block duration <
1-21600>
set vsys <name> profiles dos-protection <name> flood other-ip enable <yes|no>
set vsys <name> profiles dos-protection <name> flood other-ip red alarm-rate <0-
2000000>
set vsys <name> profiles dos-protection <name> flood other-ip red activate-rate
<1-2000000>
set vsys <name> profiles dos-protection <name> flood other-ip red maximal-rate <
1-2000000>
set vsys <name> profiles dos-protection <name> flood other-ip red block
set vsys <name> profiles dos-protection <name> flood other-ip red block duration
<1-21600>
set vsys <name> profiles dos-protection <name> resource sessions enabled <yes|no
>
limit <1-4194304>
ficate <yes|no>
uer <yes|no>
<yes|no>
ersion <yes|no>
ipher <yes|no>
yes|no>
e <yes|no>
lable <yes|no>
<yes|no>
set vsys <name> profiles decryption <name> ssl-forward-proxy block-timeout-cert
<yes|no>
e <yes|no>
ersion <yes|no>
ipher <yes|no>
e <yes|no>
lable <yes|no>
lv3|tls1-0|tls1-1|tls1-2>
lv3|tls1-0|tls1-1|tls1-2|max>
a <yes|no>
e <yes|no>
dhe <yes|no>
yes|no>
es|no>
8-cbc <yes|no>
6-cbc <yes|no>
set vsys <name> profiles decryption <name> ssl-protocol-settings enc-algo-aes-12
8-gcm <yes|no>
6-gcm <yes|no>
yes|no>
<yes|no>
6 <yes|no>
4 <yes|no>
e <yes|no>
yes|no>
yes|no>
no>
o>
set vsys <name> profiles forwarding <name> routed security-chain <name> enable <
yes|no>
set vsys <name> profiles forwarding <name> routed security-chain <name> first-de
vice <ip/netmask>
set vsys <name> profiles forwarding <name> routed security-chain <name> first-de
vice-description <value>
set vsys <name> profiles forwarding <name> routed security-chain <name> last-dev
ice <ip/netmask>
set vsys <name> profiles forwarding <name> routed security-chain <name> last-dev
ice-description <value>
odulo|ip-hash|lowest-latency>
lock>
ll>
65535>
|no>
set vsys <name> profiles forwarding <name> health-check http-latency-maximum-ms
<10-65535>
<1-65535>
d <yes|no>
ility2>... ]
ering2>... ]
cking2>... ]
wildfire-analysis2>... ]
iltering2>... ]
set vsys <name> service <name> protocol tcp override yes timeout <1-604800>
set vsys <name> service <name> protocol tcp override yes halfclose-timeout <1-60
4800>
set vsys <name> service <name> protocol tcp override yes timewait-timeout <1-600
>
set vsys <name> service <name> protocol udp override yes timeout <1-604800>
-12-hrs|last-24-hrs|last-calendar-day|last-7-days|last-7-calendar-days|last-cale
ndar-week|last-30-days|last-30-calendar-days|last-calendar-month>
set vsys <name> reports <name> type appstat aggregate-by [ <aggregate-by1> <agg
regate-by2>... ]
|risk-of-name|subcategory-of-name|technology-of-name|container-of-name|vsys|quar
ter-hour-of-receive_time|hour-of-receive_time|day-of-receive_time|vsys_name>
set vsys <name> reports <name> type appstat values [ <values1> <values2>... ]
set vsys <name> reports <name> type appstat labels [ <labels1> <labels2>... ]
set vsys <name> reports <name> type threat aggregate-by [ <aggregate-by1> <aggr
egate-by2>... ]
category-of-threatid|direction|dport|dst|dstuser|from|inbound_if|misc|natdport|n
atdst|natsport|natsrc|outbound_if|proto|risk-of-app|rule|severity|sport|src|srcu
ser|subcategory-of-app|subtype|technology-of-app|container-of-app|threatid|to|ds
tloc|srcloc|vsys|quarter-hour-of-receive_time|hour-of-receive_time|day-of-receiv
e_time|vsys_name|device_name|threat-type|tunnelid|monitortag|parent_session_id|p
arent_start_time|tunnel|http_method>
set vsys <name> reports <name> type threat values [ <values1> <values2>... ]
set vsys <name> reports <name> type threat labels [ <labels1> <labels2>... ]
set vsys <name> reports <name> type url aggregate-by [ <aggregate-by1> <aggrega
te-by2>... ]
f-app|direction|dport|dst|dstuser|from|inbound_if|misc|http_headers|natdport|nat
dst|natsport|natsrc|outbound_if|proto|risk-of-app|rule|severity|sport|src|srcuse
r|subcategory-of-app|technology-of-app|container-of-app|to|dstloc|srcloc|vsys|qu
arter-hour-of-receive_time|hour-of-receive_time|day-of-receive_time|contenttype|
user_agent|vsys_name|device_name|url|tunnelid|monitortag|parent_session_id|paren
t_start_time|tunnel|http_method>
set vsys <name> reports <name> type url values [ <values1> <values2>... ]
set vsys <name> reports <name> type url labels [ <labels1> <labels2>... ]
set vsys <name> reports <name> type wildfire aggregate-by [ <aggregate-by1> <ag
gregate-by2>... ]
app|dport|dst|dstuser|from|inbound_if|misc|natdport|natdst|natsport|natsrc|outbo
und_if|proto|risk-of-app|rule|sport|src|srcuser|subcategory-of-app|technology-of
-app|container-of-app|to|dstloc|srcloc|vsys|quarter-hour-of-receive_time|hour-of
-receive_time|day-of-receive_time|vsys_name|device_name|filetype|filename|filedi
gest|tunnelid|monitortag|parent_session_id|parent_start_time|tunnel>
set vsys <name> reports <name> type wildfire values [ <values1> <values2>... ]
set vsys <name> reports <name> type wildfire labels [ <labels1> <labels2>... ]
set vsys <name> reports <name> type data aggregate-by [ <aggregate-by1> <aggreg
ate-by2>... ]
rection|dport|dst|dstuser|from|inbound_if|misc|natdport|natdst|natsport|natsrc|o
utbound_if|proto|risk-of-app|rule|severity|sport|src|srcuser|subcategory-of-app|
subtype|technology-of-app|container-of-app|threatid|to|dstloc|srcloc|vsys|quarte
r-hour-of-receive_time|hour-of-receive_time|day-of-receive_time|vsys_name|device
_name|data-type|filename|tunnelid|monitortag|parent_session_id|parent_start_time
|tunnel>
set vsys <name> reports <name> type data values [ <values1> <values2>... ]
set vsys <name> reports <name> type data labels [ <labels1> <labels2>... ]
set vsys <name> reports <name> type thsum aggregate-by [ <aggregate-by1> <aggre
gate-by2>... ]
set vsys <name> reports <name> type thsum group-by <action|app|category-of-app|c
ategory-of-threatid|direction|dport|dst|dstuser|from|inbound_if|outbound_if|risk
-of-app|rule|severity|src|srcuser|subcategory-of-app|subtype|technology-of-app|c
ontainer-of-app|to|threatid|dstloc|srcloc|vsys|quarter-hour-of-receive_time|hour
-of-receive_time|day-of-receive_time|serial|vsys_name|device_name|threat-type|tu
nnelid|monitortag|parent_session_id|parent_start_time|tunnel>
set vsys <name> reports <name> type thsum values [ <values1> <values2>... ]
set vsys <name> reports <name> type thsum labels [ <labels1> <labels2>... ]
set vsys <name> reports <name> type traffic aggregate-by [ <aggregate-by1> <agg
regate-by2>... ]
ry-of-app|dport|dst|dstuser|from|inbound_if|natdport|natdst|natsport|natsrc|outb
ound_if|proto|risk-of-app|rule|sessionid|sport|src|srcuser|subcategory-of-app|te
chnology-of-app|container-of-app|to|dstloc|srcloc|vsys|quarter-hour-of-receive_t
ime|hour-of-receive_time|day-of-receive_time|session_end_reason|vsys_name|device
_name|action_source|tunnelid|monitortag|parent_session_id|parent_start_time|tunn
el>
set vsys <name> reports <name> type traffic values [ <values1> <values2>... ]
set vsys <name> reports <name> type traffic labels [ <labels1> <labels2>... ]
ved|elapsed|packets|pkts_sent|pkts_received|repeatcnt|nunique-of-users>
set vsys <name> reports <name> type urlsum aggregate-by [ <aggregate-by1> <aggr
egate-by2>... ]
t|dstuser|rule|dstloc|srcloc|vsys_name|device_name|from|to|serial|inbound_if|out
bound_if|dport|action|url_domain|user_agent|category-of-app|subcategory-of-app|r
isk-of-app|vsys|quarter-hour-of-receive_time|hour-of-receive_time|day-of-receive
_time|tunnelid|monitortag|parent_session_id|parent_start_time|tunnel|http_method
>
set vsys <name> reports <name> type urlsum values [ <values1> <values2>... ]
set vsys <name> reports <name> type urlsum labels [ <labels1> <labels2>... ]
set vsys <name> reports <name> type trsum aggregate-by [ <aggregate-by1> <aggre
gate-by2>... ]
-of-app|dport|dst|dstuser|from|inbound_if|outbound_if|risk-of-app|rule|src|srcus
er|subcategory-of-app|technology-of-app|container-of-app|to|dstloc|srcloc|vsys|q
uarter-hour-of-receive_time|hour-of-receive_time|day-of-receive_time|serial|vsys
_name|device_name|tunnelid|monitortag|parent_session_id|parent_start_time|tunnel
>
set vsys <name> reports <name> type trsum values [ <values1> <values2>... ]
set vsys <name> reports <name> type trsum labels [ <labels1> <labels2>... ]
s_received|nthreats|nftrans|ndpmatches|nurlcount|ncontent|nunique-of-users|nuniq
ue-of-apps>
set vsys <name> reports <name> type tunnel aggregate-by [ <aggregate-by1> <aggr
egate-by2>... ]
dport|dst|dstuser|from|inbound_if|natdport|natdst|natsport|natsrc|outbound_if|pr
oto|risk-of-app|rule|sessionid|sport|src|srcuser|subcategory-of-app|technology-o
f-app|container-of-app|to|dstloc|srcloc|vsys|quarter-hour-of-receive_time|hour-o
f-receive_time|day-of-receive_time|vsys_name|device_name|tunnelid|monitortag|par
ent_session_id|parent_start_time|session_end_reason|action_source|tunnel|tunnel_
insp_rule>
set vsys <name> reports <name> type tunnel values [ <values1> <values2>... ]
set vsys <name> reports <name> type tunnel labels [ <labels1> <labels2>... ]
tes_received|packets|pkts_sent|pkts_received|max_encap|unknown_proto|strict_chec
k|tunnel_fragment|sessions_created|sessions_closed|nunique-of-users>
set vsys <name> reports <name> type tunnelsum
set vsys <name> reports <name> type tunnelsum aggregate-by [ <aggregate-by1> <a
ggregate-by2>... ]
pp|dst|risk-of-app|rule|src|subcategory-of-app|technology-of-app|container-of-ap
p|dstloc|srcloc|vsys|quarter-hour-of-receive_time|hour-of-receive_time|day-of-re
ceive_time|serial|vsys_name|device_name|tunnelid|monitortag|parent_session_id|pa
rent_start_time|tunnel|tunnel_insp_rule>
set vsys <name> reports <name> type tunnelsum values [ <values1> <values2>... ]
set vsys <name> reports <name> type tunnelsum labels [ <labels1> <labels2>... ]
|bytes_received>
set vsys <name> reports <name> type userid aggregate-by [ <aggregate-by1> <aggr
egate-by2>... ]
e_time|hour-of-receive_time|day-of-receive_time|vsys_name|device_name|ip|user|da
tasourcename|beginport|endport|datasource|datasourcetype|factortype|factorcomple
tiontime|factorno|subtype>
set vsys <name> reports <name> type userid values [ <values1> <values2>... ]
set vsys <name> reports <name> type userid labels [ <labels1> <labels2>... ]
mpletiontime>
set vsys <name> reports <name> type auth aggregate-by [ <aggregate-by1> <aggreg
ate-by2>... ]
our-of-receive_time|hour-of-receive_time|day-of-receive_time|vsys_name|device_na
me|ip|user|normalize_user|object|authpolicy|authid|vendor|clienttype|serverprofi
le|desc|event|factorno|authproto>
set vsys <name> reports <name> type auth values [ <values1> <values2>... ]
set vsys <name> reports <name> type auth labels [ <labels1> <labels2>... ]
set vsys <name> reports <name> type auth sortby <repeatcnt|vendor|time_generated
>
set vsys <name> reports <name> type hipmatch aggregate-by [ <aggregate-by1> <ag
gregate-by2>... ]
set vsys <name> reports <name> type hipmatch values [ <values1> <values2>... ]
|srcipv6|srcuser|matchtype|vsys|device_name|vsys_name|os|quarter-hour-of-receive
_time|hour-of-receive_time|day-of-receive_time>
set vsys <name> reports <name> type hipmatch labels [ <labels1> <labels2>... ]
ation-usage-report>
ue>
set vsys <name> report-group <name> all entry user-groups [ <user-groups1> <use
r-groups2>... ]
set vsys <name> report-group <name> selected-zone
<yes|no>
ups1> <user-groups2>... ]
ine|bar|table>
ednesday|thursday|friday|saturday>
tion-list1> <exception-list2>... ]
<exception-list2>... ]
set vsys <name> external-list <name> type ip recurring weekly day-of-week <sunda
y|monday|tuesday|wednesday|thursday|friday|saturday>
1>
st1> <exception-list2>... ]
ne>
set vsys <name> external-list <name> type domain auth username <value>
set vsys <name> external-list <name> type domain auth password <value>
set vsys <name> external-list <name> type domain recurring daily at <value>
set vsys <name> external-list <name> type domain recurring weekly day-of-week <s
unday|monday|tuesday|wednesday|thursday|friday|saturday>
set vsys <name> external-list <name> type domain recurring weekly at <value>
set vsys <name> external-list <name> type domain recurring monthly day-of-month
<1-31>
set vsys <name> external-list <name> type domain recurring monthly at <value>
> <exception-list2>... ]
set vsys <name> external-list <name> type url auth username <value>
set vsys <name> external-list <name> type url auth password <value>
set vsys <name> external-list <name> type url recurring daily at <value>
set vsys <name> external-list <name> type url recurring weekly day-of-week <sund
ay|monday|tuesday|wednesday|thursday|friday|saturday>
set vsys <name> external-list <name> type url recurring weekly at <value>
set vsys <name> external-list <name> type url recurring monthly day-of-month <1-
31>
set vsys <name> external-list <name> type url recurring monthly at <value>
set vsys <name> schedule <name> schedule-type recurring weekly sunday [ <sunday
1> <sunday2>... ]
set vsys <name> schedule <name> schedule-type recurring weekly monday [ <monday
1> <monday2>... ]
set vsys <name> schedule <name> schedule-type recurring weekly tuesday [ <tuesd
ay1> <tuesday2>... ]
set vsys <name> schedule <name> schedule-type recurring weekly wednesday [ <wed
nesday1> <wednesday2>... ]
set vsys <name> schedule <name> schedule-type recurring weekly thursday [ <thur
sday1> <thursday2>... ]
set vsys <name> schedule <name> schedule-type recurring weekly friday [ <friday
1> <friday2>... ]
set vsys <name> schedule <name> schedule-type recurring weekly saturday [ <satu
rday1> <saturday2>... ]
set vsys <name> schedule <name> schedule-type recurring daily [ <daily1> <daily
2>... ]
<non-recurring2>... ]
set vsys <name> threats vulnerability <name> default-action block-ip track-by <s
ource|source-and-destination>
set vsys <name> threats vulnerability <name> default-action block-ip duration <1
-3600>
e2>... ]
set vsys <name> threats vulnerability <name> signature standard <name> comment <
value>
set vsys <name> threats vulnerability <name> signature standard <name> scope <pr
otocol-data-unit|session>
set vsys <name> threats vulnerability <name> signature standard <name> order-fre
e <yes|no>
set vsys <name> threats vulnerability <name> signature standard <name> and-condi
tion
set vsys <name> threats vulnerability <name> signature standard <name> and-condi
tion <name>
set vsys <name> threats vulnerability <name> signature standard <name> and-condi
set vsys <name> threats vulnerability <name> signature standard <name> and-condi
set vsys <name> threats vulnerability <name> signature standard <name> and-condi
set vsys <name> threats vulnerability <name> signature standard <name> and-condi
set vsys <name> threats vulnerability <name> signature standard <name> and-condi
set vsys <name> threats vulnerability <name> signature standard <name> and-condi
set vsys <name> threats vulnerability <name> signature standard <name> and-condi
set vsys <name> threats vulnerability <name> signature standard <name> and-condi
set vsys <name> threats vulnerability <name> signature standard <name> and-condi
tion <name> or-condition <name> operator less-than qualifier <name> value <1-127
>|<value>
set vsys <name> threats vulnerability <name> signature standard <name> and-condi
set vsys <name> threats vulnerability <name> signature standard <name> and-condi
set vsys <name> threats vulnerability <name> signature standard <name> and-condi
set vsys <name> threats vulnerability <name> signature standard <name> and-condi
set vsys <name> threats vulnerability <name> signature standard <name> and-condi
set vsys <name> threats vulnerability <name> signature standard <name> and-condi
tion <name> or-condition <name> operator equal-to qualifier <name> value <1-127>
|<value>
set vsys <name> threats vulnerability <name> signature standard <name> and-condi
set vsys <name> threats vulnerability <name> signature standard <name> and-condi
set vsys <name> threats vulnerability <name> signature standard <name> and-condi
set vsys <name> threats vulnerability <name> signature standard <name> and-condi
set vsys <name> threats vulnerability <name> signature standard <name> and-condi
set vsys <name> threats vulnerability <name> signature standard <name> and-condi
tion <name> or-condition <name> operator greater-than qualifier <name> value <1-
127>|<value>
set vsys <name> threats vulnerability <name> signature standard <name> and-condi
set vsys <name> threats vulnerability <name> signature standard <name> and-condi
set vsys <name> threats vulnerability <name> signature standard <name> and-condi
set vsys <name> threats vulnerability <name> signature standard <name> and-condi
set vsys <name> threats vulnerability <name> signature standard <name> and-condi
set vsys <name> threats vulnerability <name> signature standard <name> and-condi
set vsys <name> threats vulnerability <name> signature standard <name> and-condi
tion <name> or-condition <name> operator pattern-match qualifier <name> value <1
-127>|<value>
e interval <1-3600>
e threshold <1-255>
e track-by <source|destination|source-and-destination>
set vsys <name> threats vulnerability <name> signature combination order-free <y
es|no>
<name>
<name> or-condition
source-and-destination>
set vsys <name> threats spyware <name> default-action block-ip duration <1-3600>
set vsys <name> threats spyware <name> signature standard <name> comment <value>
set vsys <name> threats spyware <name> signature standard <name> scope <protocol
-data-unit|session>
set vsys <name> threats spyware <name> signature standard <name> order-free <yes
|no>
set vsys <name> threats spyware <name> signature standard <name> and-condition
set vsys <name> threats spyware <name> signature standard <name> and-condition <
name>
set vsys <name> threats spyware <name> signature standard <name> and-condition <
name> or-condition
set vsys <name> threats spyware <name> signature standard <name> and-condition <
set vsys <name> threats spyware <name> signature standard <name> and-condition <
set vsys <name> threats spyware <name> signature standard <name> and-condition <
set vsys <name> threats spyware <name> signature standard <name> and-condition <
set vsys <name> threats spyware <name> signature standard <name> and-condition <
set vsys <name> threats spyware <name> signature standard <name> and-condition <
set vsys <name> threats spyware <name> signature standard <name> and-condition <
ue>
set vsys <name> threats spyware <name> signature standard <name> and-condition <
set vsys <name> threats spyware <name> signature standard <name> and-condition <
set vsys <name> threats spyware <name> signature standard <name> and-condition <
set vsys <name> threats spyware <name> signature standard <name> and-condition <
set vsys <name> threats spyware <name> signature standard <name> and-condition <
set vsys <name> threats spyware <name> signature standard <name> and-condition <
e>
set vsys <name> threats spyware <name> signature standard <name> and-condition <
set vsys <name> threats spyware <name> signature standard <name> and-condition <
set vsys <name> threats spyware <name> signature standard <name> and-condition <
set vsys <name> threats spyware <name> signature standard <name> and-condition <
set vsys <name> threats spyware <name> signature standard <name> and-condition <
set vsys <name> threats spyware <name> signature standard <name> and-condition <
set vsys <name> threats spyware <name> signature standard <name> and-condition <
set vsys <name> threats spyware <name> signature standard <name> and-condition <
set vsys <name> threats spyware <name> signature standard <name> and-condition <
set vsys <name> threats spyware <name> signature standard <name> and-condition <
set vsys <name> threats spyware <name> signature standard <name> and-condition <
set vsys <name> threats spyware <name> signature standard <name> and-condition <
set vsys <name> threats spyware <name> signature standard <name> and-condition <
<value>
set vsys <name> threats spyware <name> signature combination time-attribute inte
rval <1-3600>
set vsys <name> threats spyware <name> signature combination time-attribute thre
shold <1-255>
set vsys <name> threats spyware <name> signature combination time-attribute trac
k-by <source|destination|source-and-destination>
set vsys <name> threats spyware <name> signature combination order-free <yes|no>
set vsys <name> threats spyware <name> signature combination and-condition <name
>
set vsys <name> threats spyware <name> signature combination and-condition <name
> or-condition
set vsys <name> threats spyware <name> signature combination and-condition <name
ssion>
set vsys <name> application <name> signature <name> and-condition <name> or-cond
ition
set vsys <name> application <name> signature <name> and-condition <name> or-cond
ition <name>
set vsys <name> application <name> signature <name> and-condition <name> or-cond
set vsys <name> application <name> signature <name> and-condition <name> or-cond
set vsys <name> application <name> signature <name> and-condition <name> or-cond
set vsys <name> application <name> signature <name> and-condition <name> or-cond
set vsys <name> application <name> signature <name> and-condition <name> or-cond
set vsys <name> application <name> signature <name> and-condition <name> or-cond
set vsys <name> application <name> signature <name> and-condition <name> or-cond
set vsys <name> application <name> signature <name> and-condition <name> or-cond
set vsys <name> application <name> signature <name> and-condition <name> or-cond
set vsys <name> application <name> signature <name> and-condition <name> or-cond
set vsys <name> application <name> signature <name> and-condition <name> or-cond
set vsys <name> application <name> signature <name> and-condition <name> or-cond
set vsys <name> application <name> signature <name> and-condition <name> or-cond
set vsys <name> application <name> signature <name> and-condition <name> or-cond
set vsys <name> application <name> signature <name> and-condition <name> or-cond
set vsys <name> application <name> signature <name> and-condition <name> or-cond
set vsys <name> application <name> signature <name> and-condition <name> or-cond
set vsys <name> application <name> signature <name> and-condition <name> or-cond
set vsys <name> application <name> signature <name> and-condition <name> or-cond
set vsys <name> application <name> signature <name> and-condition <name> or-cond
unknown-req-udp|unknown-rsp-udp>
set vsys <name> application <name> signature <name> and-condition <name> or-cond
set vsys <name> application <name> signature <name> and-condition <name> or-cond
ition <name> operator equal-to mask <value>
set vsys <name> application <name> signature <name> and-condition <name> or-cond
gory2>... ]
y2>... ]
tions1> <saas-certifications2>... ]
... ]
r7|color8|color9|color10|color11|color12|color13|color14|color15|color16|color17
|color19|color20|color21|color22|color23|color24|color25|color26|color27|color28
|color29|color30|color31|color32|color33|color34|color35|color36|color37|color38
|color39|color40|color41|color42>
captive-portal|browser-challenge>
set vsys <name> rulebase security rules <name> from [ <from1> <from2>... ]
set vsys <name> rulebase security rules <name> source [ <source1> <source2>...
set vsys <name> rulebase security rules <name> source-user [ <source-user1> <so
urce-user2>... ]
set vsys <name> rulebase security rules <name> destination [ <destination1> <de
stination2>... ]
set vsys <name> rulebase security rules <name> service [ <service1> <service2>.
.. ]
set vsys <name> rulebase security rules <name> category [ <category1> <category
2>... ]
set vsys <name> rulebase security rules <name> application [ <application1> <ap
plication2>... ]
set vsys <name> rulebase security rules <name> tag [ <tag1> <tag2>... ]
set vsys <name> rulebase security rules <name> hip-profiles [ <hip-profiles1> <
hip-profiles2>... ]
ent|reset-server|reset-both>
terzone>
spection <yes|no>
set vsys <name> rulebase security rules <name> profile-setting profiles url-filt
set vsys <name> rulebase security rules <name> profile-setting profiles data-fil
set vsys <name> rulebase security rules <name> profile-setting profiles file-blo
cking [ <file-blocking1> <file-blocking2>... ]
set vsys <name> rulebase security rules <name> profile-setting profiles wildfire
set vsys <name> rulebase security rules <name> profile-setting profiles virus [
<virus1> <virus2>... ]
set vsys <name> rulebase security rules <name> profile-setting profiles spyware
[ <spyware1> <spyware2>... ]
set vsys <name> rulebase security rules <name> profile-setting profiles vulnerab
set vsys <name> rulebase security rules <name> profile-setting group [ <group1>
<group2>... ]
set vsys <name> rulebase security rules <name> qos marking ip-dscp <value>|<ef|a
f11|af12|af13|af21|af22|af23|af31|af32|af33|af41|af42|af43|cs0|cs1|cs2|cs3|cs4|c
s5|cs6|cs7>
set vsys <name> rulebase security rules <name> qos marking ip-precedence <value>
|<cs0|cs1|cs2|cs3|cs4|cs5|cs6|cs7>
set vsys <name> rulebase security rules <name> qos marking follow-c2s-flow
set vsys <name> rulebase default-security-rules rules <name> tag [ <tag1> <tag2
>... ]
files
up [ <group1> <group2>... ]
drop|reset-client|reset-server|reset-both>
es|no>
set vsys <name> rulebase application-override rules <name> from [ <from1> <from
2>... ]
set vsys <name> rulebase application-override rules <name> source [ <source1> <
source2>... ]
e-user1> <source-user2>... ]
nation1> <destination2>... ]
set vsys <name> rulebase application-override rules <name> tag [ <tag1> <tag2>.
.. ]
>
es|no>
set vsys <name> rulebase decryption rules <name> from [ <from1> <from2>... ]
set vsys <name> rulebase decryption rules <name> source [ <source1> <source2>..
.]
set vsys <name> rulebase decryption rules <name> source-user [ <source-user1> <
source-user2>... ]
set vsys <name> rulebase decryption rules <name> destination [ <destination1> <
destination2>... ]
set vsys <name> rulebase decryption rules <name> tag [ <tag1> <tag2>... ]
set vsys <name> rulebase decryption rules <name> service [ <service1> <service2
>... ]
set vsys <name> rulebase decryption rules <name> category [ <category1> <catego
ry2>... ]
ypt-and-forward>
set vsys <name> rulebase decryption rules <name> type
set vsys <name> rulebase decryption rules <name> type ssl-inbound-inspection <va
lue>
set vsys <name> rulebase authentication rules <name> from [ <from1> <from2>...
set vsys <name> rulebase authentication rules <name> source [ <source1> <source
2>... ]
1> <source-user2>... ]
1> <destination2>... ]
set vsys <name> rulebase authentication rules <name> tag [ <tag1> <tag2>... ]
set vsys <name> rulebase authentication rules <name> service [ <service1> <serv
ice2>... ]
set vsys <name> rulebase authentication rules <name> category [ <category1> <ca
tegory2>... ]
es1> <hip-profiles2>... ]
<value>
set vsys <name> rulebase authentication rules <name> log-setting <value>
<yes|no>
set vsys <name> rulebase tunnel-inspect rules <name> from [ <from1> <from2>...
set vsys <name> rulebase tunnel-inspect rules <name> source [ <source1> <source
2>... ]
1> <source-user2>... ]
1> <destination2>... ]
set vsys <name> rulebase tunnel-inspect rules <name> tag [ <tag1> <tag2>... ]
1> <application2>... ]
nspection <1|2>
ax <yes|no>
n-protocol <yes|no>
-checking <yes|no>
set vsys <name> rulebase tunnel-inspect rules <name> zone-assign
set vsys <name> rulebase tunnel-inspect rules <name> zone-assign source [ <sour
ce1> <source2>... ]
<destination1> <destination2>... ]
e <value>
<1-16777215>
-override
set vsys <name> rulebase nat rules <name> from [ <from1> <from2>... ]
set vsys <name> rulebase nat rules <name> source [ <source1> <source2>... ]
set vsys <name> rulebase nat rules <name> destination [ <destination1> <destina
tion2>... ]
interface-address
interface-address
interface-address ip <value>
set vsys <name> rulebase nat rules <name> source-translation dynamic-ip translat
set vsys <name> rulebase nat rules <name> source-translation dynamic-ip fallback
set vsys <name> rulebase nat rules <name> source-translation dynamic-ip fallback
set vsys <name> rulebase nat rules <name> source-translation dynamic-ip fallback
set vsys <name> rulebase nat rules <name> source-translation dynamic-ip fallback
interface-address
set vsys <name> rulebase nat rules <name> source-translation dynamic-ip fallback
set vsys <name> rulebase nat rules <name> source-translation dynamic-ip fallback
interface-address
set vsys <name> rulebase nat rules <name> source-translation dynamic-ip fallback
interface-address ip <value>
set vsys <name> rulebase nat rules <name> source-translation dynamic-ip fallback
set vsys <name> rulebase nat rules <name> source-translation static-ip translate
d-address <value>|<ip/netmask>|<ip-range>
set vsys <name> rulebase nat rules <name> source-translation static-ip bi-direct
ional <yes|no>
ress <value>|<ip/netmask>|<ip-range>
t <1-65535>
ated-address <value>|<ip/netmask>|<ip-range>
ated-port <1-65535>
bution <round-robin>
both|0|1>
set vsys <name> rulebase nat rules <name> tag [ <tag1> <tag2>... ]
set vsys <name> rulebase qos rules <name> from [ <from1> <from2>... ]
set vsys <name> rulebase qos rules <name> source-user [ <source-user1> <source-
user2>... ]
set vsys <name> rulebase qos rules <name> destination [ <destination1> <destina
tion2>... ]
set vsys <name> rulebase qos rules <name> service [ <service1> <service2>... ]
set vsys <name> rulebase qos rules <name> category [ <category1> <category2>...
set vsys <name> rulebase qos rules <name> application [ <application1> <applica
tion2>... ]
set vsys <name> rulebase qos rules <name> tag [ <tag1> <tag2>... ]
set vsys <name> rulebase qos rules <name> dscp-tos codepoints <name>
set vsys <name> rulebase qos rules <name> dscp-tos codepoints <name>
set vsys <name> rulebase qos rules <name> dscp-tos codepoints <name> ef
set vsys <name> rulebase qos rules <name> dscp-tos codepoints <name> ef codepoin
t <ef>
set vsys <name> rulebase qos rules <name> dscp-tos codepoints <name> af
set vsys <name> rulebase qos rules <name> dscp-tos codepoints <name> af codepoin
t <af11|af12|af13|af21|af22|af23|af31|af32|af33|af41|af42|af43>
set vsys <name> rulebase qos rules <name> dscp-tos codepoints <name> cs
set vsys <name> rulebase qos rules <name> dscp-tos codepoints <name> cs codepoin
t <cs0|cs1|cs2|cs3|cs4|cs5|cs6|cs7>
set vsys <name> rulebase qos rules <name> dscp-tos codepoints <name> tos
set vsys <name> rulebase qos rules <name> dscp-tos codepoints <name> tos codepoi
nt <cs0|cs1|cs2|cs3|cs4|cs5|cs6|cs7>
set vsys <name> rulebase qos rules <name> dscp-tos codepoints <name> custom
set vsys <name> rulebase qos rules <name> dscp-tos codepoints <name> custom code
point
set vsys <name> rulebase qos rules <name> dscp-tos codepoints <name> custom code
set vsys <name> rulebase qos rules <name> dscp-tos codepoints <name> custom code
set vsys <name> rulebase qos rules <name> action class <1|2|3|4|5|6|7|8>
set vsys <name> rulebase pbf rules <name> from zone [ <zone1> <zone2>... ]
set vsys <name> rulebase pbf rules <name> from interface [ <interface1> <interf
ace2>... ]
set vsys <name> rulebase pbf rules <name> source [ <source1> <source2>... ]
set vsys <name> rulebase pbf rules <name> source-user [ <source-user1> <source-
user2>... ]
set vsys <name> rulebase pbf rules <name> destination [ <destination1> <destina
tion2>... ]
set vsys <name> rulebase pbf rules <name> service [ <service1> <service2>... ]
set vsys <name> rulebase pbf rules <name> tag [ <tag1> <tag2>... ]
set vsys <name> rulebase pbf rules <name> application [ <application1> <applica
tion2>... ]
set vsys <name> rulebase pbf rules <name> action
set vsys <name> rulebase pbf rules <name> action forward egress-interface <value
>
set vsys <name> rulebase pbf rules <name> action forward nexthop
set vsys <name> rulebase pbf rules <name> action forward nexthop ip-address <ip/
netmask>
set vsys <name> rulebase pbf rules <name> action forward monitor
set vsys <name> rulebase pbf rules <name> action forward monitor profile <value>
set vsys <name> rulebase pbf rules <name> action forward monitor disable-if-unre
achable <yes|no>
set vsys <name> rulebase pbf rules <name> action forward monitor ip-address <ip/
netmask>
set vsys <name> rulebase pbf rules <name> action forward-to-vsys <value>
set vsys <name> rulebase pbf rules <name> enforce-symmetric-return enabled <yes|
no>
ss-list
ss-list <name>
>
set vsys <name> rulebase dos rules <name> from zone [ <zone1> <zone2>... ]
set vsys <name> rulebase dos rules <name> from interface [ <interface1> <interf
ace2>... ]
set vsys <name> rulebase dos rules <name> to zone [ <zone1> <zone2>... ]
set vsys <name> rulebase dos rules <name> to interface [ <interface1> <interfac
e2>... ]
set vsys <name> rulebase dos rules <name> source [ <source1> <source2>... ]
set vsys <name> rulebase dos rules <name> source-user [ <source-user1> <source-
user2>... ]
set vsys <name> rulebase dos rules <name> destination [ <destination1> <destina
tion2>... ]
set vsys <name> rulebase dos rules <name> service [ <service1> <service2>... ]
set vsys <name> rulebase dos rules <name> tag [ <tag1> <tag2>... ]
set vsys <name> rulebase dos rules <name> protection aggregate profile <value>
set vsys <name> rulebase dos rules <name> protection classified profile <value>
set vsys <name> rulebase dos rules <name> protection classified classification-c
riteria
set vsys <name> rulebase dos rules <name> protection classified classification-c