Task: Zone firewall (v6.7.0) ================================================== Category: Security Description: Firewall security policy configuration New: No | IPv6: No Vendor Support: ○ aws@ec2 ○ alcatel@aos ✗ azure ✗ brocade@fastiron ○ cisco@ios ○ cisco@ios-xe ○ cisco@nx-os ○ cisco@ios-xr ○ cisco@asa ○ cisco@wlc-air ○ cisco@sg ✓ cisco@ftd ○ cisco@aci ○ cisco@meraki ✗ cisco@viptela ○ cisco@apic ○ cisco@encs ○ dell@ftos ○ dell@powerconnect ○ dell@os10 ✗ fs@fsos ○ gcp ○ hp@comware ○ hp@aruba ○ hp@arubasw ○ hp@arubacx ○ hp@3com ○ hp@aruba-iap ○ riverbed@steelhead ✓ fortinet@fortigate ○ fortinet@fortiswitch ✓ forcepoint@ngfw ✓ paloalto@pan-os ✗ paloalto@prisma ✓ juniper@junos ○ juniper@mist ✓ checkpoint@gaia ✓ checkpoint@gaia-embedded ○ extreme@boss ○ extreme@enterasys ○ extreme@voss ○ extreme@exos ○ arista@eos ○ f5@big-ip ○ huawei@vrp ○ mikrotik@routeros ○ quagga ○ frr ○ versa@vos ✗ silverpeak@unity ✗ vmware@nsx-t ○ ruckus@vsz ○ opengear@im ✗ stormshield@sn ○ nokia@timos ○ citrix@adc CLI Commands: checkpoint@gaia-embedded: POST /web_api/show-access-rulebase forcepoint@ngfw: GET elements/rbvpn_tunnel/ forcepoint@ngfw: GET elements forcepoint@ngfw: ip address forcepoint@ngfw: sg-status -l checkpoint@gaia-embedded: ipf_pdp monitor all checkpoint@gaia-embedded: fwm ver checkpoint@gaia-embedded: show extended commands checkpoint@gaia-embedded: POST /web_api/show-updatable-objects checkpoint@gaia-embedded: POST /web_api/show-packages checkpoint@gaia-embedded: POST /web_api/show-objects checkpoint@gaia-embedded: POST /web_api/show-object checkpoint@gaia-embedded: POST /web_api/show-gateways-and-servers forcepoint@ngfw: GET elements/single_fw//internal_gateway//internal_endpoint/ checkpoint@gaia-embedded: POST /web_api/show-access-layers checkpoint@gaia: ipf_pdp monitor all checkpoint@gaia: fwm ver checkpoint@gaia: show extended commands checkpoint@gaia: POST /web_api/show-updatable-objects checkpoint@gaia: POST /web_api/show-packages checkpoint@gaia: POST /web_api/show-objects checkpoint@gaia: POST /web_api/show-object checkpoint@gaia: POST /web_api/show-gateways-and-servers checkpoint@gaia: POST /web_api/show-access-rulebase checkpoint@gaia: POST /web_api/show-access-layers forcepoint@ngfw: GET elements/ip_country_group/ juniper@junos: show interfaces statistics detail juniper@junos: show configuration groups junos-defaults applications | display set juniper@junos: show configuration applications | display inheritance juniper@junos: show configuration security | display inheritance forcepoint@ngfw: GET /elements/mgt_server/ forcepoint@ngfw: GET elements/host/ forcepoint@ngfw: GET elements/icmp_service/ forcepoint@ngfw: GET elements/single_fw//alias_resolving forcepoint@ngfw: GET elements/address_range/ forcepoint@ngfw: GET elements/match_expression/ forcepoint@ngfw: GET elements/match_expression forcepoint@ngfw: GET elements/ip_list/ fortinet@fortigate: show system zone forcepoint@ngfw: GET elements/interface_zone/ forcepoint@ngfw: GET elements/fw_policy//fw_ipv4_access_rule/ forcepoint@ngfw: GET elements/fw_policy//fw_ipv4_access_rule forcepoint@ngfw: GET elements/ip_service/ forcepoint@ngfw: GET elements/application_situation/ forcepoint@ngfw: GET elements/udp_service/ forcepoint@ngfw: GET elements/tcp_service/ forcepoint@ngfw: GET elements/network/ forcepoint@ngfw: GET elements/single_fw//snapshot/ forcepoint@ngfw: GET elements/single_fw//snapshot forcepoint@ngfw: GET elements/[single_fw|virtual_fw|fw_cluster]/ cisco@ftd: GET /api/fmc_config/v1/domain//devicehapairs/ftddevicehapairs?expanded=true cisco@ftd: GET /api/fmc_config/v1/domain//assignment/policyassignments?expanded=true cisco@ftd: GET /api/fmc_config/v1/domain//object/icmpv6objects?expanded=true cisco@ftd: GET /api/fmc_config/v1/domain//object/icmpv4objects/ cisco@ftd: GET /api/fmc_config/v1/domain//object/icmpv4objects?expanded=true cisco@ftd: GET /api/fmc_config/v1/domain//object/securityzones?expanded=true cisco@ftd: GET /api/fmc_config/v1/domain//object/protocolportobjects?expanded=true cisco@ftd: GET /api/fmc_config/v1/domain//object/portobjectgroups?expanded=true cisco@ftd: GET /api/fmc_config/v1/domain//object/networkgroups?expanded=true cisco@ftd: GET /api/fmc_config/v1/domain//object/networkaddresses?expanded=true cisco@ftd: GET /api/fmc_config/v1/domain//object/applications?expanded=true cisco@ftd: GET /api/fmc_config/v1/domain/{domainUUID}/devicegroups/devicegrouprecords?expanded=true cisco@ftd: GET /api/fmc_config/v1/domain/{domainUUID}/deviceclusters/ftddevicecluster?expanded=true cisco@ftd: GET /api/fmc_config/v1/domain//object/interfacegroups?expanded=true cisco@ftd: GET /api/fmc_config/v1/domain//devices/devicerecords//fplogicalinterfaces?expanded=true cisco@ftd: GET /api/fmc_config/v1/domain//devices/devicerecords//fpphysicalinterfaces?expanded=true cisco@ftd: GET /api/fmc_config/v1/domain//devices/devicerecords//vlaninterfaces?expanded=true cisco@ftd: GET /api/fmc_config/v1/domain//devices/devicerecords//etherchannelinterfaces?expanded=true cisco@ftd: GET /api/fmc_config/v1/domain//devices/devicerecords//subinterfaces?expanded=true cisco@ftd: GET /api/fmc_config/v1/domain//devices/devicerecords//physicalinterfaces?expanded=true cisco@ftd: GET /api/fmc_config/v1/domain//devices/devicerecords?expanded=true cisco@ftd: GET /api/fmc_config/v1/domain//policy/accesspolicies//accessrules?expanded=true cisco@ftd: GET /api/fmc_config/v1/domain//policy/accesspolicies?expanded=true cisco@ftd: show managers cisco@ftd: show dns fortinet@fortigate: diagnose firewall fqdn list fortinet@fortigate: show system interface fortinet@fortigate: show full-configuration application list fortinet@fortigate: show firewall vipgrp fortinet@fortigate: show firewall vip fortinet@fortigate: show firewall service group fortinet@fortigate: show firewall service custom fortinet@fortigate: show firewall profile-group fortinet@fortigate: show firewall policy fortinet@fortigate: show firewall addrgrp fortinet@fortigate: show firewall address fortinet@fortigate: get system status fortinet@fortigate: diagnose internet-service id [] cisco@ftd: show summary fortinet@fortigate: diagnose firewall auth list paloalto@pan-os: show object dynamic-address-group all paloalto@pan-os: show dns-proxy fqdn all paloalto@pan-os: request system fqdn show paloalto@pan-os: show config merged paloalto@pan-os: show interface all paloalto@pan-os: show interface paloalto@pan-os: show config pushed-shared-policy vsys cisco@ftd: GET /api/fmc_config/v1/domain//object/anyprotocolportobjects?expanded=true cisco@ftd: GET /api/fmc_config/v1/domain//policy/prefilterpolicies//prefilterrules?expanded=true cisco@ftd: GET /api/fmc_config/v1/domain//policy/prefilterpolicies?expanded=true Legend: ✓=Full, ✗=Not Yet, ○=N/A