<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to see all the set commands for an IPsec tunnel? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-see-all-the-set-commands-for-an-ipsec-tunnel/m-p/321767#M82327</link>
    <description>&lt;P&gt;I need to get the display set of all the commands for an IPsec tunnel, like I'd do with a Juniper SRX, but get no return whenever I try to see the commands set for the tunnel. Seems like the tunnel hasn't even been configured, but it shows under ike sa and ipsec sa. I'm sure that's because I'm new to PA. I just need to duplicate a tunnel and everything but just change the GW IP, so getting the display set of the tunnel, gateway, and routes, would really help.&lt;/P&gt;&lt;P&gt;Let me add that I'm trying to get it from a firewall that's on a HA pair and is linked to Panorama. I dont see any local ipsec config on the firewall!!&lt;/P&gt;</description>
    <pubDate>Thu, 09 Apr 2020 04:51:37 GMT</pubDate>
    <dc:creator>Raydar</dc:creator>
    <dc:date>2020-04-09T04:51:37Z</dc:date>
    <item>
      <title>How to see all the set commands for an IPsec tunnel?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-see-all-the-set-commands-for-an-ipsec-tunnel/m-p/321767#M82327</link>
      <description>&lt;P&gt;I need to get the display set of all the commands for an IPsec tunnel, like I'd do with a Juniper SRX, but get no return whenever I try to see the commands set for the tunnel. Seems like the tunnel hasn't even been configured, but it shows under ike sa and ipsec sa. I'm sure that's because I'm new to PA. I just need to duplicate a tunnel and everything but just change the GW IP, so getting the display set of the tunnel, gateway, and routes, would really help.&lt;/P&gt;&lt;P&gt;Let me add that I'm trying to get it from a firewall that's on a HA pair and is linked to Panorama. I dont see any local ipsec config on the firewall!!&lt;/P&gt;</description>
      <pubDate>Thu, 09 Apr 2020 04:51:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-see-all-the-set-commands-for-an-ipsec-tunnel/m-p/321767#M82327</guid>
      <dc:creator>Raydar</dc:creator>
      <dc:date>2020-04-09T04:51:37Z</dc:date>
    </item>
    <item>
      <title>Re: How to see all the set commands for an IPsec tunnel?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-see-all-the-set-commands-for-an-ipsec-tunnel/m-p/321807#M82334</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/137915"&gt;@Raydar&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To view the set command you would normally use the "&lt;SPAN&gt;&lt;SPAN class="richTextArea slds-text-longform tile__title red-txt"&gt;&lt;SPAN style="font-family: courier new, courier;"&gt;&amp;gt; set cli config-output-format"&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt; command.&lt;/P&gt;
&lt;P&gt;However, this command is only useful for local config.&amp;nbsp; It will not show anything configured through panorama.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To view only the Panorama pushed configurations, which displays policies and objects pushed from Panorama:&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-family: courier new, courier;"&gt;&amp;gt; show config pushed-shared-policy&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To view the template pushed to the device:&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-family: courier new, courier;"&gt;&amp;gt; show config pushed-template&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;LI-WRAPPER&gt;&lt;/LI-WRAPPER&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class="richTextArea slds-text-longform tile__title red-txt"&gt;Unfortunately the above CLI outputs are displayed in XML format so I'm not sure if they can help you.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;That said, there is a feature request to view the set commands pushed from Panorama.&amp;nbsp; I'd reach out to your local SE and have him add your vote to the feature request.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Hope this helps,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;-Kiwi.&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV id="ConnectiveDocSignExtentionInstalled" data-extension-version="1.0.4"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Thu, 09 Apr 2020 07:45:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-see-all-the-set-commands-for-an-ipsec-tunnel/m-p/321807#M82334</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2020-04-09T07:45:15Z</dc:date>
    </item>
  </channel>
</rss>

