Kann I eine einzelne Regel mit Namen auf mit der Panorama REST API ?
12669
Created On 11/01/20 04:39 AM - Last Modified 06/19/25 10:13 AM
Question
Kann I eine einzelne Regel mit Namen auf mit der Panorama REST API ?
Environment
- PANOS Version: 8.1.x, 9.0.x, 9.1.x, 10.x
- Beliebige Panorama mit verwalteten Firewalls.
Answer
Ja. Aeinzelne Regel nach Namen mit der REST API wird von Panorama unterstützt.
Beispiel:
- Interessierte Regel
- APIAusgabe von :
linux@paloalto-networks-> curl -vk -X GET 'https://10.46.165.159/restapi/9.0/Policies/SecurityPreRules?key=LUFRPT1aK00xeStWdHYvRW1meit3Zk45di9HdWIwZTQ9MFNNYTI2OWVNaGpKbl B0R1JLUjYxRjZpUm5SYVJZSGpNc1kzeHlvVnFVb1hwc25iUTZyM29YT3F1dVl2STlYVA==&location=device-group&device-group=vm-100-device-group&name=outside-allow-1&output-format=xml' * About to connect() to 10.46.165.159 port 443 (#0) * Trying 10.46.165.159... * Connected to 10.46.165.159 (10.46.165.159) port 443 (#0) * Initializing NSS with certpath: sql:/etc/pki/nssdb * skipping SSL peer certificate verification * SSL connection using TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA * Server certificate: * subject: E=support@paloaltonetworks.com,CN=1cb6d8a21a2565540d82c6487cb195b920c849945ad47302e979ff83a79542af,O=Palo Alto Networks,L=Santa Clara,ST=CA,C=US * start date: May 11 17:58:56 2017 GMT * expire date: May 09 17:58:56 2027 GMT * common name: 1cb6d8a21a2565540d82c6487cb195b920c849945ad47302e979ff83a79542af * issuer: E=support@paloaltonetworks.com,CN=localhost,OU=Support,O=Palo Alto Networks,L=Santa Clara,ST=CA,C=US > GET /restapi/9.0/Policies/SecurityPreRules?key=LUFRPT1aK00xeStWdHYvRW1meit3Zk45di9HdWIwZTQ9MFNNYTI2OWVNaGpKblB0R1JLUjYxRjZpUm5SYVJZSGpNc1kzeHlvVnFVb1hwc25iUTZyM29YT3F1d Vl2STlYVA==&location=device-group&device-group=vm-100-device-group&name=outside-allow-1&output-format=xml HTTP/1.1 > User-Agent: curl/7.29.0 > Host: 10.46.165.159 > Accept: */* > < HTTP/1.1 200 OK < Date: Wed, 07 Oct 2020 03:50:58 GMT < Content-Type: application/xml; charset=UTF-8 < Content-Length: 818 < Connection: keep-alive < X-FRAME-OPTIONS: SAMEORIGIN < X-XSS-Protection: 1; mode=block < X-Content-Type-Options: nosniff < Content-Security-Policy: default-src 'self'; script-src 'self' 'unsafe-eval' 'unsafe-inline'; style-src 'self' 'unsafe-inline'; img-src 'self' data:; < Strict-Transport-Security: max-age=31536000 < Set-Cookie: PHPSESSID=3c1a50d7e7fbc61945ab69fee7fa51b0; path=/; secure; HttpOnly < Expires: Thu, 19 Nov 1981 08:52:00 GMT < Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 < Pragma: no-cache < Allow: GET, HEAD, POST, PUT, DELETE, OPTIONS < * Connection #0 to host 10.46.165.159 left intact <response status="success" code="19"><result total-count="1" count="1"><entry name="outside-allow-1" uuid="e391c0bc-a34c-4fb5-9c7d-51562f8d88f6" location="device-group" device-group="vm-100-device-group" loc="vm-100-device-group"><to><member>any</member></to><from><member>any</member></from><source><member>any</member></source><destination> <member>any</member></destination><source-user><member>any</member></source-user><category><member>any</member></category><application><member>any</member></application><service> <member>application-default</member></service><hip-profiles><member>any</member></hip-profiles><action>allow</action><profile-setting><group><member>security-profile</member> </group></profile-setting><target><negate>no</negate></target><description>testing</description></entry></result></response>
Additional Information
- Um die API zu verwenden, müssen Sie den Schlüssel generieren, der für die API Authentifizierung von Aufrufen erforderlich API ist.Bitte beachten Sie diesen Link: Holen Sie sich Ihren API Schlüssel
- Weitere Informationen REST API zu , siehe link: Arbeiten mit Regeln am ( Policy Panorama REST API )