Palo Alto Networks Knowledgebase: What are the CLI Commands to View Panorama Pushed Configurations from the Managed Device?
What are the CLI Commands to View Panorama Pushed Configurations from the Managed Device?
Created On 09/27/18 10:41 AM - Last Updated 02/07/19 23:36 PM
To view all security policies on a Palo Alto Networks device, run the following command (supported on all PAN-OS versions):
> show running security-policy
In PAN-OS 4.1, the command to view only the pushed configuration is as follows:
> show config pushed
PAN-OS 5.0 introduced Templates and the ability to push device templates to the managed devices. The following CLI commands were made available from PAN-OS 5.0 and 6.0 to view the pushed configurations and templates on the managed device:
To view only the Panorama pushed configurations, which displays policies and objects pushed from Panorama:
> show config pushed-shared-policy
To view the shared policy pushed to the device per vsys:
> show config pushed-shared-policy vsys <value>
To view the template pushed to the device:
> show config pushed-template
To view templates pushed from Panorama, along with the local running config on the firewall:
> show config merged
Note: The above CLI outputs are displayed in XML format. Setting the config-output-format to "set" or "XML" (> set cli config-output-format) is useful to view only the local running configuration in configuration mode.