Common Palo Alto firewall commands for troubleshooting

Common commands

sg@fw(active)> show 
sg@fw(active)> request
sg@fw(active)> test
sg@fw(active)> configure

test example

sg@fw(active)> test http-server address protocol HTTP

System info. Able to find the basic info like the following
IP address, model, serial number,

sg@fw(active)> show system info


sg@fw(active)> show routing route
sg@fw(active)> show routing route destination

Show NAT

sg@fw(active)> show running nat-policy
sg@fw(active)> test nat-policy-match destination 116.xx.xx.xx source protocol 80


sg@fw(active)> show running ippool
sg@fw(active)> show running global-ippool

ping & traceroute

sg@fw(active)> ping host
sg@fw(active)> ping source host

sg@fw(active)> traceroute host
sg@fw(active)> traceroute source host

Check existing network (access or trunk)

Get-VMNetworkAdapterVlan -VMName "pa-firewall"


Set-VMNetworkAdapterVlan -VMName "pa-firewall" -Trunk -AllowedVlanIdList 1-200 -NativeVlanId 1

Leave a Comment

Your email address will not be published. Required fields are marked *