<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Client want to reset vpn tunnel though API tools in Automation/API Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/client-want-to-reset-vpn-tunnel-though-api-tools/m-p/359400#M2484</link>
    <description>&lt;P&gt;Hi Guys,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have site to site vpn tunnel to client . Now client have tools that can call api from our side that can see vpn tunnel is down or not and reset it. But how we can give access to api to only specifi vpn tunnel to reset like ( clear &amp;amp; test )&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://192.168.40.10/api/?type=op&amp;amp;cmd=%3Ctest%3E%3Cvpn%3E%3Cike-sa%3E%3Cgateway%3E%3C%2Fgateway%3E%3C%2Fike-sa%3E%3C%2Fvpn%3E%3C%2Ftest%3E&amp;amp;REST_API_TOKEN=297178081" target="_rest_api"&gt;/api/?type=op&amp;amp;cmd=&amp;lt;test&amp;gt;&amp;lt;vpn&amp;gt;&amp;lt;ike-sa&amp;gt;&amp;lt;gateway&amp;gt;&amp;lt;/gateway&amp;gt;&amp;lt;/ike-sa&amp;gt;&amp;lt;/vpn&amp;gt;&amp;lt;/test&amp;gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://192.168.40.10/api/?type=op&amp;amp;cmd=%3Ctest%3E%3Cvpn%3E%3Cipsec-sa%3E%3Ctunnel%3E%3C%2Ftunnel%3E%3C%2Fipsec-sa%3E%3C%2Fvpn%3E%3C%2Ftest%3E&amp;amp;REST_API_TOKEN=294839280" target="_rest_api"&gt;/api/?type=op&amp;amp;cmd=&amp;lt;test&amp;gt;&amp;lt;vpn&amp;gt;&amp;lt;ipsec-sa&amp;gt;&amp;lt;tunnel&amp;gt;&amp;lt;/tunnel&amp;gt;&amp;lt;/ipsec-sa&amp;gt;&amp;lt;/vpn&amp;gt;&amp;lt;/test&amp;gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can anyone help where i can add the name and key it like the vpn tunnel name is ( ABC-VPN)&amp;nbsp;&lt;/P&gt;&lt;P&gt;What will be full command before we forward them.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We can reset by command line.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;test vpn ike-sa gateway ABC-VPN&lt;/P&gt;&lt;P&gt;test vpn ipsec-sa tunnel ABC-VPN&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 28 Oct 2020 17:34:53 GMT</pubDate>
    <dc:creator>NavidAlam</dc:creator>
    <dc:date>2020-10-28T17:34:53Z</dc:date>
    <item>
      <title>Client want to reset vpn tunnel though API tools</title>
      <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/client-want-to-reset-vpn-tunnel-though-api-tools/m-p/359400#M2484</link>
      <description>&lt;P&gt;Hi Guys,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have site to site vpn tunnel to client . Now client have tools that can call api from our side that can see vpn tunnel is down or not and reset it. But how we can give access to api to only specifi vpn tunnel to reset like ( clear &amp;amp; test )&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://192.168.40.10/api/?type=op&amp;amp;cmd=%3Ctest%3E%3Cvpn%3E%3Cike-sa%3E%3Cgateway%3E%3C%2Fgateway%3E%3C%2Fike-sa%3E%3C%2Fvpn%3E%3C%2Ftest%3E&amp;amp;REST_API_TOKEN=297178081" target="_rest_api"&gt;/api/?type=op&amp;amp;cmd=&amp;lt;test&amp;gt;&amp;lt;vpn&amp;gt;&amp;lt;ike-sa&amp;gt;&amp;lt;gateway&amp;gt;&amp;lt;/gateway&amp;gt;&amp;lt;/ike-sa&amp;gt;&amp;lt;/vpn&amp;gt;&amp;lt;/test&amp;gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://192.168.40.10/api/?type=op&amp;amp;cmd=%3Ctest%3E%3Cvpn%3E%3Cipsec-sa%3E%3Ctunnel%3E%3C%2Ftunnel%3E%3C%2Fipsec-sa%3E%3C%2Fvpn%3E%3C%2Ftest%3E&amp;amp;REST_API_TOKEN=294839280" target="_rest_api"&gt;/api/?type=op&amp;amp;cmd=&amp;lt;test&amp;gt;&amp;lt;vpn&amp;gt;&amp;lt;ipsec-sa&amp;gt;&amp;lt;tunnel&amp;gt;&amp;lt;/tunnel&amp;gt;&amp;lt;/ipsec-sa&amp;gt;&amp;lt;/vpn&amp;gt;&amp;lt;/test&amp;gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can anyone help where i can add the name and key it like the vpn tunnel name is ( ABC-VPN)&amp;nbsp;&lt;/P&gt;&lt;P&gt;What will be full command before we forward them.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We can reset by command line.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;test vpn ike-sa gateway ABC-VPN&lt;/P&gt;&lt;P&gt;test vpn ipsec-sa tunnel ABC-VPN&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Oct 2020 17:34:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/automation-api-discussions/client-want-to-reset-vpn-tunnel-though-api-tools/m-p/359400#M2484</guid>
      <dc:creator>NavidAlam</dc:creator>
      <dc:date>2020-10-28T17:34:53Z</dc:date>
    </item>
    <item>
      <title>Re: Client want to reset vpn tunnel though API tools</title>
      <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/client-want-to-reset-vpn-tunnel-though-api-tools/m-p/359537#M2485</link>
      <description>&lt;P&gt;So do you want to limit so this api users to only be able to run just a few commands? In this case reseting the vpn?&lt;/P&gt;</description>
      <pubDate>Thu, 29 Oct 2020 10:01:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/automation-api-discussions/client-want-to-reset-vpn-tunnel-though-api-tools/m-p/359537#M2485</guid>
      <dc:creator>hbalzac</dc:creator>
      <dc:date>2020-10-29T10:01:34Z</dc:date>
    </item>
    <item>
      <title>Re: Client want to reset vpn tunnel though API tools</title>
      <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/client-want-to-reset-vpn-tunnel-though-api-tools/m-p/359538#M2486</link>
      <description>&lt;P&gt;Yes. I want to limit the client by just only able to reset only his own VPN sit to sit tunnel.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Oct 2020 10:21:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/automation-api-discussions/client-want-to-reset-vpn-tunnel-though-api-tools/m-p/359538#M2486</guid>
      <dc:creator>NavidAlam</dc:creator>
      <dc:date>2020-10-29T10:21:41Z</dc:date>
    </item>
    <item>
      <title>Re: Client want to reset vpn tunnel though API tools</title>
      <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/client-want-to-reset-vpn-tunnel-though-api-tools/m-p/359590#M2487</link>
      <description>&lt;P&gt;The rbac functionality for api users are quite limited, so its not possible. I have heard that 10.0 will be better but not to what extent.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Other vendors have had the possibility to just allow certain commands for users but palo lacks here imo.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Not sure on how you enviorment is setup, there is always the issue with the client modify the script and run other commands that you dont want. Perhaps just having a simple webportal where they can click one button?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Oct 2020 11:22:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/automation-api-discussions/client-want-to-reset-vpn-tunnel-though-api-tools/m-p/359590#M2487</guid>
      <dc:creator>hbalzac</dc:creator>
      <dc:date>2020-10-29T11:22:41Z</dc:date>
    </item>
  </channel>
</rss>

