Task: ACL (v6.10.0) ================================================== Category: Security Description: ACL definitions and interfaces New: No | IPv6: No Vendor Support: ✓ aws@ec2 ✗ alcatel@aos ✓ azure ✗ brocade@fastiron ✓ cisco@ios ✓ cisco@ios-xe ✓ cisco@nx-os ✓ cisco@ios-xr ✓ cisco@asa ✗ cisco@wlc-air ✓ cisco@sg ✗ cisco@ftd ✓ cisco@aci ✗ cisco@meraki ✓ cisco@viptela ○ cisco@apic ✗ cisco@encs ○ dell@ftos ○ dell@powerconnect ○ dell@os10 ✗ fs@fsos ✓ gcp ✓ hp@comware ✗ hp@aruba ✗ hp@arubasw ✓ hp@arubacx ✗ hp@3com ○ hp@aruba-iap ○ riverbed@steelhead ○ fortinet@fortigate ✗ fortinet@fortiswitch ✗ forcepoint@ngfw ○ paloalto@pan-os ○ paloalto@prisma ✓ juniper@junos ○ juniper@mist ○ checkpoint@gaia ○ checkpoint@gaia-embedded ○ extreme@boss ○ extreme@enterasys ✗ extreme@voss ✓ extreme@exos ✓ arista@eos ○ f5@big-ip ○ huawei@vrp ○ mikrotik@routeros ○ quagga ○ frr ○ versa@vos ✗ silverpeak@unity ✓ vmware@nsx-t ✗ vmware@velocloud ✗ ruckus@vsz ✗ opengear@im ○ stormshield@sn ✗ nokia@timos ✗ citrix@adc CLI Commands: cisco@ios-xe: show object-group cisco@viptela: GET /dataservice/device/policy/accesslistassociations?deviceId= cisco@viptela: GET /dataservice/template/policy/list/dataprefix cisco@viptela: GET /dataservice/template/policy/definition/acl cisco@viptela: GET /dataservice/template/policy/definition/acl/ extreme@exos: debug vlan show vlans extreme@exos: show vlan detail extreme@exos: show access-list detail extreme@exos: show access-list cisco@sg: show access-list cisco@sg: show interfaces access-lists cisco@ios-xr: show ipv4 vrf all interface cisco@ios-xr: show running-config cisco@viptela: GET /dataservice/template/policy/vsmart cisco@ios-xe: show ip interface cisco@ios-xe: show ip access-list cisco@ios: show object-group cisco@ios: show ip interface cisco@ios: show ip access-list gcp: GET /compute/v1/projects//global/networks gcp: GET /compute/v1/projects//aggregated/instances gcp: GET /compute/v1/projects//aggregated/subnetworks gcp: GET /compute/v1/projects//global/firewalls cisco@nx-os: show object-group cisco@nx-os: show access-list summary cisco@nx-os: show ip access-list vmware@nsx-t: GET /api/v1/fabric/vifs vmware@nsx-t: GET /api/v1/ns-services vmware@nsx-t: GET /policy/api/v1/infra/segments vmware@nsx-t: GET /api/v1/firewall/sections?type=LAYER2 vmware@nsx-t: GET /api/v1/firewall/sections//rules?sort_by=priority vmware@nsx-t: GET /api/v1/firewall/sections vmware@nsx-t: GET /api/v1/ip-sets vmware@nsx-t: GET /api/v1/ns-groups//effective-logical-switch-members vmware@nsx-t: GET /api/v1/ns-groups//effective-ipset-members vmware@nsx-t: GET /api/v1/ns-groups//effective-ip-address-members vmware@nsx-t: GET /api/v1/ns-groups vmware@nsx-t: GET /api/v1/logical-ports//state vmware@nsx-t: GET /api/v1/fabric/virtual-machines cisco@asa: show dns vmware@nsx-t: GET /api/v1/logical-routers vmware@nsx-t: GET /api/v1/logical-router-ports?logical_router_id= vmware@nsx-t: GET /policy/api/v1/infra/segments//ports/ vmware@nsx-t: GET /api/v1/logical-ports cisco@viptela: GET /dataservice/template/policy/list/vpn cisco@viptela: GET /dataservice/template/policy/list/site cisco@viptela: GET /dataservice/template/policy/list/app cisco@viptela: GET /dataservice/template/config/attached/?type=CFS cisco@viptela: GET /dataservice/device/bfd/sessions?deviceId= cisco@viptela: GET /dataservice/device/interface?deviceId= cisco@viptela: GET /dataservice/template/policy/definition/data/ azure: GET /location//serviceTagDetails cisco@aci: show system internal epm vrf all cisco@aci: show system internal epm vlan all cisco@aci: show endpoint detail hp@arubacx: show running-config hp@comware: display object-group hp@comware: display packet-filter interface hp@comware: display packet-filter all hp@comware: display acl all juniper@junos: show configuration interfaces | display inheritance juniper@junos: show configuration policy-options | display inheritance juniper@junos: show configuration firewall | display inheritance azure: GET /virtualNetworks cisco@aci: show coop internal info ip-db azure: GET /networkSecurityGroups azure: GET /networkInterfaces aws@ec2: SDK ec2:GetManagedPrefixListsEntriesCommand aws@ec2: SDK ec2:DescribeVpcs aws@ec2: SDK ec2:DescribeSecurityGroupRulesCommand aws@ec2: SDK ec2:DescribeSecurityGroupsCommand aws@ec2: SDK ec2:DescribePrefixListsCommand aws@ec2: SDK ec2:DescribeNetowrkInterfacesCommand aws@ec2: SDK ec2:DescribeNetworkAclsCommand aws@ec2: SDK ec2:DescribeManagedPrefixListsCommand arista@eos: show ip access-lists summary arista@eos: show ip access-lists cisco@aci: GET /api/node/class/fvAp.json?rsp-subtree=full&rsp-subtree-class=fvAp,fvAEPg,fvAp,fvCEp,fvRsProv,fvIp,fvESg,fvRsCons&rsp-subtree-class=fvAp,fvAEPg,fvAp,fvCEp,fvRsProv,fvIp,fvESg,fvRsCons cisco@asa: show running-config all object cisco@asa: show interface detail cisco@asa: show interface cisco@asa: show run cisco@aci: GET /api/node/class/vzFilter.json&rsp-subtree=full&rsp-subtree-class=vzFilter,vzEntry cisco@aci: GET /api/node/class/vzBrCP.json&rsp-subtree=full&rsp-subtree-class=vzSubj,vzRsSubjFiltAtt cisco@aci: GET /api/node/class/mgmtOoB.json cisco@aci: GET /api/node/class/mgmtInB.json cisco@aci: GET /api/node/class/l3extInstP.json?rsp-subtree=full&rsp-subtree-class=fvRsProv,fvRsCons,l3extSubnet cisco@aci: GET /api/node/class/l2extInstP.json&rsp-subtree=full&rsp-subtree-class=fvRsProv,fvRsCons cisco@aci: GET /api/node/class/fvCtx.json&rsp-subtree=full&rsp-subtree-class=fvCtx,fvRtCtx cisco@aci: GET /api/node/class/fvBD.json&rsp-subtree=full&rsp-subtree-class=fvSubnet,fvRtBd,l3extSubnet arista@eos: show running-config cisco@aci: GET /api/node/class/fvAEPg.json cisco@aci: GET /api/node/class/fabricNode.json cisco@aci: GET /api/node/class/actrlRule.json?order-by=actrlRule.prio&rsp-subtree=full cisco@aci: GET /api/node/class/fvTenant.json?rsp-subtree=full&rsp-subtree-class=vzBrCP,fvBD,vzFilter,fvAp,fvCtx,fvAEPg,l2extInstP,l3extInstP,mgmtOoB,mgmtInB cisco@aci: show ipv6 interface vrf all cisco@aci: show interface cisco@aci: show hsrp brief cisco@aci: show ip interface vrf all cisco@aci: show inventory cisco@aci: show version cisco@aci: show isis dteps vrf overlay-1 Legend: ✓=Full, ✗=Not Yet, ○=N/A