<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Is there any way I can make an &amp;quot;Easy Button&amp;quot; for help desk to enable/disable PBF rules in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/is-there-any-way-i-can-make-an-quot-easy-button-quot-for-help/m-p/284824#M76350</link>
    <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;However gertting better ISP's might be worth looking into as well.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;How does the saying go... "A general goes to war with the army he has"&lt;/P&gt;</description>
    <pubDate>Fri, 23 Aug 2019 16:16:03 GMT</pubDate>
    <dc:creator>Maxstr</dc:creator>
    <dc:date>2019-08-23T16:16:03Z</dc:date>
    <item>
      <title>Is there any way I can make an "Easy Button" for help desk to enable/disable PBF rules?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-there-any-way-i-can-make-an-quot-easy-button-quot-for-help/m-p/284785#M76348</link>
      <description>&lt;P&gt;I'd like to create a script or some kind of quick method to disable a PBF rule. We have a dual-ISP setup, and sometimes one ISP will get extremely slow. But it doesn't&amp;nbsp;actually go down, so it doesn't trigger the PBF rule, and we're left with nearly unusable internet.&lt;/P&gt;&lt;P&gt;As the only "firewall guy", they basically have to wait on me to disable a PBF rule. Is there a way to script this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Aug 2019 14:18:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-there-any-way-i-can-make-an-quot-easy-button-quot-for-help/m-p/284785#M76348</guid>
      <dc:creator>Maxstr</dc:creator>
      <dc:date>2019-08-23T14:18:45Z</dc:date>
    </item>
    <item>
      <title>Re: Is there any way I can make an "Easy Button" for help desk to enable/disable PBF rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-there-any-way-i-can-make-an-quot-easy-button-quot-for-help/m-p/284822#M76349</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Might be possible via the API. However gertting better ISP's might be worth looking into as well.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/8-0/pan-os-panorama-api/get-started-with-the-pan-os-xml-api/explore-the-api" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/8-0/pan-os-panorama-api/get-started-with-the-pan-os-xml-api/explore-the-api&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Fri, 23 Aug 2019 16:13:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-there-any-way-i-can-make-an-quot-easy-button-quot-for-help/m-p/284822#M76349</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2019-08-23T16:13:08Z</dc:date>
    </item>
    <item>
      <title>Re: Is there any way I can make an "Easy Button" for help desk to enable/disable PBF rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-there-any-way-i-can-make-an-quot-easy-button-quot-for-help/m-p/284824#M76350</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;However gertting better ISP's might be worth looking into as well.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;How does the saying go... "A general goes to war with the army he has"&lt;/P&gt;</description>
      <pubDate>Fri, 23 Aug 2019 16:16:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-there-any-way-i-can-make-an-quot-easy-button-quot-for-help/m-p/284824#M76350</guid>
      <dc:creator>Maxstr</dc:creator>
      <dc:date>2019-08-23T16:16:03Z</dc:date>
    </item>
    <item>
      <title>Re: Is there any way I can make an "Easy Button" for help desk to enable/disable PBF rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-there-any-way-i-can-make-an-quot-easy-button-quot-for-help/m-p/284836#M76352</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/25857"&gt;@Maxstr&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;This is an extremely good use case of the API.&lt;/P&gt;&lt;P&gt;Bonus Points: If you configure a machine so that it can utilize both ISP circuits (through two NICs or VLAN setup) you could actually automate testing the circuits and automatically enable/disable the PBF rule on the firewall once bandwidth is within expected norms. This would take any manual interaction requirements out completely.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Aug 2019 17:32:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-there-any-way-i-can-make-an-quot-easy-button-quot-for-help/m-p/284836#M76352</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2019-08-23T17:32:17Z</dc:date>
    </item>
    <item>
      <title>Re: Is there any way I can make an "Easy Button" for help desk to enable/disable PBF rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-there-any-way-i-can-make-an-quot-easy-button-quot-for-help/m-p/284838#M76354</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/25857"&gt;@Maxstr&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;This is an extremely good use case of the API.&lt;/P&gt;&lt;P&gt;Bonus Points: If you configure a machine so that it can utilize both ISP circuits (through two NICs or VLAN setup) you could actually automate testing the circuits and automatically enable/disable the PBF rule on the firewall once bandwidth is within expected norms. This would take any manual interaction requirements out completely.&amp;nbsp;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;So I looked over the API documentation, and I do see one for PBF rules. I've never used REST API though, so I guess it's time for a crash course. Any advise on where to start?&lt;/P&gt;</description>
      <pubDate>Fri, 23 Aug 2019 18:02:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-there-any-way-i-can-make-an-quot-easy-button-quot-for-help/m-p/284838#M76354</guid>
      <dc:creator>Maxstr</dc:creator>
      <dc:date>2019-08-23T18:02:02Z</dc:date>
    </item>
    <item>
      <title>Re: Is there any way I can make an "Easy Button" for help desk to enable/disable PBF rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-there-any-way-i-can-make-an-quot-easy-button-quot-for-help/m-p/284854#M76356</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/25857"&gt;@Maxstr&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;The firewall includes a fairly decent browser that follows the CLI, so PBF would start at the following API URL&lt;/P&gt;&lt;PRE&gt; /api/?type=config&amp;amp;action=gest&amp;amp;xpath=/config/devices/entry[@name='localhost.localdomain']/vsys/entry[@name='vsys1']/rulebase/pbf/rules&lt;/PRE&gt;&lt;P&gt;So you would then set this to disabled by sending the following&lt;/P&gt;&lt;PRE&gt;/api/?type=config&amp;amp;action=set&amp;amp;xpath=/config/devices/entry[@name='localhost.localdomain']/vsys/entry[@name='vsys1']/rulebase/pbf/rules/entry[@name='Test-PBF']&amp;amp;element=&amp;lt;disabled&amp;gt;yes&amp;lt;/disabled&amp;gt;&amp;amp;key=APIKEY&lt;/PRE&gt;&lt;P&gt;Just to make it clear, you would want a way to obsficate your API Key so that your help desk doesn't actually get to see what it is, otherwise they would have the same permissions as whatever account the key was generated under. You could then utilize something like RunDeck to actually get them to run a script without opening up the management interface to all of your helpdesk users.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Aug 2019 19:11:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-there-any-way-i-can-make-an-quot-easy-button-quot-for-help/m-p/284854#M76356</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2019-08-23T19:11:53Z</dc:date>
    </item>
  </channel>
</rss>

