Professional Documents
Culture Documents
· show system info –provides the system’s management IP, serial number and
code version
· show system statistics – shows the real time throughput on the device
· show system software status – shows whether various system processes are
running
· show jobs processed – used to see when commits, downloads, upgrades, etc.
are completed
To monitor CPUs
· show session all | match – used to show specific sessions in the session
table. You can enter any text after the word match. A good example would be a
source or destination IP or an application
· show session all | filter destination <IP> dest- shows all sessions going
to a particular dest IP and port <port>- port
· show session all filter type predict – To show any pin-hole applications
(e.g.FTP)
· show counter global delta yes | match [source ip|dest ip| drop | error |
frag ] – show counter changes since last time ran this command, filter on
particular keyword
· show counter global filter packet-filter yes delta yes – show counter
changes since last time ran this command, filter on debug filter
· show counter global filter delta yes – show counter changes since last
time ran this command
NAT
Routing
· tail follow yes mp-log routed.log - To view the log in real time
Policies
PAN Agent
· show user pan-agent statistics – used to see if the agent is connected
and operational. Status should be connected OK and you should see numbers under
users, groups and IPs.
· show pan-agent user-IDs - used to see if the FW has pulled groups from
the PANAgent
URL
· test url <url or IP> – used to test the categorization of a URL on the FW
· clear url-cache – used to clear the URL cache- cache contains 100k of the
most popular URLs on this network
· show log url direction equal backward- view the URL log, most recent
entries first
IPSec
7. sho vpn flow <name> or tunnel-id <id#> -to see detailed info on the tunnel
HA
Vsys
· delete license key ? – use to delete a license file if having issues and
want to retrieve new licenses, use question mark to list file names, only delete
the files you see fit
· set cli config-output-format set- use to view the config in “set” format
from within the configure prompt (#)
Misc
· debug dataplane pool statistics - this will show the different dataplane
buffers and can be used to see if the system is nearing capacity in certain
functionality.
· grep mp-log * pattern (what your searching for-name)- to search all logs
for a specific word
· less dp0-log brdagent.log- to check to see if you have physical errors on
interface
· https://x.x.x.x/esp/restapi.esp?type=keygen&user=admin&password=admin –
To generate a API key
Debug Commands
CLEAN UP COMMANDS:
· Generate traffic
CLEAN UP COMMANDS:
· debug dataplane packet-diag clear log log