<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: List all deny rules from cli in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/list-all-deny-rules-from-cli/m-p/361949#M88246</link>
    <description>&lt;P&gt;It also looks like you have multiple vsys on that system. If you want to use the entire show command as written, you have to specify the vsys.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;show vsys vsysX rulebase security | match drop&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Or you could just do show | match drop. This will expand the output but might give results that aren't relevant to what you're looking for.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 10 Nov 2020 17:59:08 GMT</pubDate>
    <dc:creator>rmfalconer</dc:creator>
    <dc:date>2020-11-10T17:59:08Z</dc:date>
    <item>
      <title>List all deny rules from cli</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/list-all-deny-rules-from-cli/m-p/360107#M88059</link>
      <description>&lt;P&gt;I have to list all deny rules (from cli)&lt;/P&gt;&lt;P&gt;The following command "show running security-policy | match index " list all security rules by name&lt;/P&gt;&lt;P&gt;For example:&lt;/P&gt;&lt;P&gt;"AllowBrach1IN; index: 1" {&lt;/P&gt;&lt;P&gt;....etc&lt;/P&gt;&lt;P&gt;What I want is:&lt;/P&gt;&lt;P&gt;- deny INBOUND traffic rules only but regarding entire subnets (those having CIDR as their destination ...like 192.168.1.0/24..etc)&lt;/P&gt;&lt;P&gt;Is there any way to filter out that type of information?&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 01 Nov 2020 17:43:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/list-all-deny-rules-from-cli/m-p/360107#M88059</guid>
      <dc:creator>jls3j999</dc:creator>
      <dc:date>2020-11-01T17:43:31Z</dc:date>
    </item>
    <item>
      <title>Re: List all deny rules from cli</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/list-all-deny-rules-from-cli/m-p/360120#M88060</link>
      <description>&lt;P&gt;Give this a shot:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;reaper@PANgurus&amp;gt; set cli config-output-format set
reaper@PANgurus&amp;gt; configure
Entering configuration mode
[edit]                                                                             reaper@PANgurus# show rulebase security | match drop&lt;/LI-CODE&gt;</description>
      <pubDate>Sun, 01 Nov 2020 21:44:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/list-all-deny-rules-from-cli/m-p/360120#M88060</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2020-11-01T21:44:56Z</dc:date>
    </item>
    <item>
      <title>Re: List all deny rules from cli</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/list-all-deny-rules-from-cli/m-p/360227#M88071</link>
      <description>&lt;P&gt;thanks a lot but it seems to me that show rulebase command is missing&lt;/P&gt;&lt;P&gt;here's the putput I get if I type show&lt;/P&gt;&lt;P&gt;&amp;gt; admins Show active administrators&lt;BR /&gt;&amp;gt; api-key-expiration-ts Shows the time before which any API keys would be invalid&lt;BR /&gt;&amp;gt; arp Show ARP information&lt;BR /&gt;&amp;gt; auth auth state variables&lt;BR /&gt;&amp;gt; authentication Show authentication related information&lt;BR /&gt;&amp;gt; chassis Chassis state and information&lt;BR /&gt;&amp;gt; chassis-ready Show whether dataplane has a running policy&lt;BR /&gt;&amp;gt; cli Show CLI properties&lt;BR /&gt;&amp;gt; clock Show system date and time&lt;BR /&gt;&amp;gt; commit-locks Show list of commit locks&lt;BR /&gt;&amp;gt; config Show configuration&lt;BR /&gt;&amp;gt; config-locks Show list of config locks&lt;BR /&gt;&amp;gt; counter Show system counter information&lt;BR /&gt;&amp;gt; device-certificate Show device certificate&lt;BR /&gt;&amp;gt; dhcp Show DHCP data&lt;BR /&gt;&amp;gt; dns-proxy Show DNS Proxy information&lt;BR /&gt;&amp;gt; dos-block-table Show hardware ACL or Block-ip table&lt;BR /&gt;&amp;gt; dos-protection Show DoS protection related information&lt;BR /&gt;&amp;gt; global-protect Show settings for GlobalProtect&lt;BR /&gt;&amp;gt; global-protect-gateway Show GlobalProtect gateway run-time objects&lt;BR /&gt;&amp;gt; global-protect-mdm Show settings for GlobalProtect MDM&lt;BR /&gt;&amp;gt; global-protect-portal Show gloabl protect poral user session info&lt;BR /&gt;--more--&lt;BR /&gt;&amp;gt; global-protect-satellite Show GlobalProtect satellite run-time objects&lt;BR /&gt;&amp;gt; gtp Show GTP information&lt;BR /&gt;&amp;gt; high-availability Show high-availability information&lt;BR /&gt;&amp;gt; hsm Show HSM information&lt;BR /&gt;&amp;gt; interface Show interface information&lt;BR /&gt;&amp;gt; jobs Show management server jobs&lt;BR /&gt;&amp;gt; lacp Show LACP state&lt;BR /&gt;&amp;gt; license-token-files Show license token files for manual license deactivation&lt;BR /&gt;&amp;gt; lldp Show LLDP state&lt;BR /&gt;&amp;gt; location Show geographic location&lt;BR /&gt;&amp;gt; log Show logs related information&lt;BR /&gt;&amp;gt; log-collector Show log-collector information&lt;BR /&gt;&amp;gt; logging-status Show logging status and info&lt;BR /&gt;&amp;gt; mac Show MAC address information&lt;BR /&gt;&amp;gt; management-clients Show internal management server clients&lt;BR /&gt;&amp;gt; max-num-images Show maximum number of software or content images&lt;BR /&gt;&amp;gt; neighbor Show IPv6 neighbor information&lt;BR /&gt;&amp;gt; netstat Print network connections and statistics&lt;BR /&gt;&amp;gt; ntp Show NTP synchronization state&lt;BR /&gt;&amp;gt; object Show IP address object&lt;BR /&gt;&amp;gt; obsolete-disabled-ssl-exclusions Show disabled predefined ssl-decrypt exclusions not present in the installed content&lt;BR /&gt;&amp;gt; operational-mode Show device operational mode setting&lt;BR /&gt;&amp;gt; oss-license show license for open source packages&lt;BR /&gt;--more--&lt;BR /&gt;&amp;gt; panorama-certificates Show panorama certificate list&lt;BR /&gt;&amp;gt; panorama-status Show panorama connection status&lt;BR /&gt;&amp;gt; parent-info show parent info&lt;BR /&gt;&amp;gt; pbf Show policy-based-forwarding run-time information&lt;BR /&gt;&amp;gt; plugins Request information of plugins&lt;BR /&gt;&amp;gt; pppoe Show pppoe statistics&lt;BR /&gt;&amp;gt; predefined Show predefined config&lt;BR /&gt;&amp;gt; qos Show QoS run-time information&lt;BR /&gt;&amp;gt; query Show query jobs&lt;BR /&gt;&amp;gt; report Show report jobs&lt;BR /&gt;&amp;gt; resource Show resource limits information&lt;BR /&gt;&amp;gt; routing Show routing run-time objects&lt;BR /&gt;&amp;gt; rule-hit-count Show policy rule hit-count information&lt;BR /&gt;&amp;gt; running Show running operational parameters&lt;BR /&gt;&amp;gt; sctp Show SCTP information&lt;BR /&gt;&amp;gt; session Show session information&lt;BR /&gt;&amp;gt; sp-metadata sp-metadata&lt;BR /&gt;&amp;gt; ssh-fingerprints Show management ssh public key fingerprints&lt;BR /&gt;&amp;gt; ssl-conn-on-cert Show setting for ssl fail connection on cert&lt;BR /&gt;&amp;gt; sslmgr-store Show sslmgr dynamic configuration&lt;BR /&gt;&amp;gt; statistics Show device statistics&lt;BR /&gt;&amp;gt; syslogng-ssl-conn-validation Show syslog-ng ssl connection validation settings&lt;BR /&gt;&amp;gt; system Show system state and information&lt;BR /&gt;--more--&lt;BR /&gt;&amp;gt; threat Show Threat id descriptions&lt;BR /&gt;&amp;gt; url-cloud Show URL cloud info&lt;BR /&gt;&amp;gt; user Show user identification information&lt;BR /&gt;&amp;gt; virtual-wire Show virtual-wire information&lt;BR /&gt;&amp;gt; vlan Show vlan information&lt;BR /&gt;&amp;gt; vm-monitor Show VM monitoring information&lt;BR /&gt;&amp;gt; vpn Show IKE/IPSec VPN run-time objects&lt;BR /&gt;&amp;gt; wildfire Show wildfire information&lt;BR /&gt;&amp;gt; zone-protection Show zone protection runtime statistics&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Nov 2020 11:44:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/list-all-deny-rules-from-cli/m-p/360227#M88071</guid>
      <dc:creator>jls3j999</dc:creator>
      <dc:date>2020-11-02T11:44:24Z</dc:date>
    </item>
    <item>
      <title>Re: List all deny rules from cli</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/list-all-deny-rules-from-cli/m-p/360230#M88073</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/160803"&gt;@jls3j999&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"show rulebase security" is command in &lt;U&gt;configuration&lt;/U&gt; mode, while you are still in user mode.&lt;/P&gt;&lt;P&gt;If you look again the instructions from &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt; you will see that before executing the "show" command you need to enter configuration mode by typing "configure"&lt;/P&gt;</description>
      <pubDate>Mon, 02 Nov 2020 13:45:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/list-all-deny-rules-from-cli/m-p/360230#M88073</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2020-11-02T13:45:54Z</dc:date>
    </item>
    <item>
      <title>Re: List all deny rules from cli</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/list-all-deny-rules-from-cli/m-p/360231#M88074</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/160803"&gt;@jls3j999&lt;/a&gt;&amp;nbsp;please follow all the steps, else it won't work &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Change the cli output mode to set commands&lt;/P&gt;&lt;P&gt;Go into configure mode&lt;/P&gt;&lt;P&gt;Run the show command&lt;/P&gt;</description>
      <pubDate>Mon, 02 Nov 2020 14:05:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/list-all-deny-rules-from-cli/m-p/360231#M88074</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2020-11-02T14:05:32Z</dc:date>
    </item>
    <item>
      <title>Re: List all deny rules from cli</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/list-all-deny-rules-from-cli/m-p/360291#M88081</link>
      <description>&lt;P&gt;thanks for your reply&lt;/P&gt;&lt;P&gt;this is what I get&lt;/P&gt;&lt;P&gt;superuser@point-1(active-primary)&amp;gt; configure&lt;BR /&gt;Entering configuration mode&lt;BR /&gt;[edit]&lt;BR /&gt;superuser@point-1(active-primary)# show&lt;BR /&gt;deviceconfig deviceconfig&lt;BR /&gt;mgt-config mgt-config&lt;BR /&gt;network network configuration&lt;BR /&gt;predefined predefined&lt;BR /&gt;shared shared&lt;BR /&gt;template template&lt;BR /&gt;vsys vsys&lt;BR /&gt;| Pipe through a command&lt;BR /&gt;&amp;lt;Enter&amp;gt; Finish input&lt;/P&gt;&lt;P&gt;Since I'm a bit scared, the command you suggested does that make any changes? I suppose not&lt;/P&gt;&lt;P&gt;I mean "show rulebase security | match drop" sorry for being a dummy&lt;/P&gt;</description>
      <pubDate>Mon, 02 Nov 2020 17:03:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/list-all-deny-rules-from-cli/m-p/360291#M88081</guid>
      <dc:creator>jls3j999</dc:creator>
      <dc:date>2020-11-02T17:03:45Z</dc:date>
    </item>
    <item>
      <title>Re: List all deny rules from cli</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/list-all-deny-rules-from-cli/m-p/361908#M88236</link>
      <description>&lt;P&gt;can anyone help me?&lt;/P&gt;&lt;P&gt;I mean are there any side-effects while entering the configuration mode?&lt;/P&gt;&lt;P&gt;My purpose is to list all deny rules only (no changes should be made)&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Tue, 10 Nov 2020 12:03:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/list-all-deny-rules-from-cli/m-p/361908#M88236</guid>
      <dc:creator>jls3j999</dc:creator>
      <dc:date>2020-11-10T12:03:00Z</dc:date>
    </item>
    <item>
      <title>Re: List all deny rules from cli</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/list-all-deny-rules-from-cli/m-p/361929#M88241</link>
      <description>&lt;P&gt;After doing what you said&lt;/P&gt;&lt;P&gt;this is the output:&lt;/P&gt;&lt;P&gt;admin_user@FW-1(active-primary)&amp;gt; set cli config-output-format set&lt;BR /&gt;admin_user@FW-1(active-primary)&amp;gt; configure&lt;BR /&gt;Entering configuration mode&lt;BR /&gt;[edit]&lt;BR /&gt;admin_user@FW-1(active-primary)# show&lt;BR /&gt;deviceconfig deviceconfig&lt;BR /&gt;mgt-config mgt-config&lt;BR /&gt;network network configuration&lt;BR /&gt;predefined predefined&lt;BR /&gt;shared shared&lt;BR /&gt;template template&lt;BR /&gt;vsys vsys&lt;BR /&gt;| Pipe through a command&lt;BR /&gt;&amp;lt;Enter&amp;gt; Finish input&lt;/P&gt;&lt;P&gt;admin_user@FW-1(active-primary)# show rulebase security |match drop&lt;/P&gt;&lt;P data-unlink="true"&gt;Invalid syntax.&lt;BR /&gt;[edit]&lt;BR /&gt;admin_user@FW-1(active-primary)#&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class="lia-message-subject lia-component-message-view-widget-subject"&gt;&lt;DIV class="MessageSubject"&gt;&lt;DIV class="MessageSubjectIcons "&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="lia-message-body lia-component-message-view-widget-body lia-component-body-signature-highlight-escalation lia-component-message-view-widget-body-signature-highlight-escalation"&gt;&lt;DIV class="lia-message-body-content"&gt;&lt;P&gt;can anyone help me?&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Tue, 10 Nov 2020 17:13:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/list-all-deny-rules-from-cli/m-p/361929#M88241</guid>
      <dc:creator>jls3j999</dc:creator>
      <dc:date>2020-11-10T17:13:27Z</dc:date>
    </item>
    <item>
      <title>Re: List all deny rules from cli</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/list-all-deny-rules-from-cli/m-p/361930#M88242</link>
      <description>&lt;P&gt;There appears to be a space missing between the pipe and 'match' ( |match should be | match)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The show command in configure mode does not make any changes at all so is safe to use&lt;/P&gt;</description>
      <pubDate>Tue, 10 Nov 2020 17:17:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/list-all-deny-rules-from-cli/m-p/361930#M88242</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2020-11-10T17:17:38Z</dc:date>
    </item>
    <item>
      <title>Re: List all deny rules from cli</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/list-all-deny-rules-from-cli/m-p/361949#M88246</link>
      <description>&lt;P&gt;It also looks like you have multiple vsys on that system. If you want to use the entire show command as written, you have to specify the vsys.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;show vsys vsysX rulebase security | match drop&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Or you could just do show | match drop. This will expand the output but might give results that aren't relevant to what you're looking for.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Nov 2020 17:59:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/list-all-deny-rules-from-cli/m-p/361949#M88246</guid>
      <dc:creator>rmfalconer</dc:creator>
      <dc:date>2020-11-10T17:59:08Z</dc:date>
    </item>
    <item>
      <title>Re: List all deny rules from cli</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/list-all-deny-rules-from-cli/m-p/361951#M88248</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/55733"&gt;@rmfalconer&lt;/a&gt; thanks this command works fine:&lt;/P&gt;&lt;P&gt;show vsys vsys1 rulebase security | match deny&lt;/P&gt;&lt;P&gt;example output:&lt;/P&gt;&lt;P&gt;set vsys vsys1 rulebase security rules FTP-INBOUND-DENY action deny&lt;/P&gt;&lt;P&gt;....&lt;/P&gt;&lt;P&gt;But I expected to get network details as well such as:&lt;/P&gt;&lt;P&gt;192.168.0.10/24&amp;nbsp; or whatever related to every rule whose action is equal to deny&lt;/P&gt;</description>
      <pubDate>Tue, 10 Nov 2020 18:27:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/list-all-deny-rules-from-cli/m-p/361951#M88248</guid>
      <dc:creator>jls3j999</dc:creator>
      <dc:date>2020-11-10T18:27:13Z</dc:date>
    </item>
    <item>
      <title>Re: List all deny rules from cli</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/list-all-deny-rules-from-cli/m-p/361955#M88251</link>
      <description>&lt;P&gt;Using the match command will only output the line where that word specifically appears. If you want detail on each policy, you'll need to match on the policy name.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;show vsys vsys1 rulebase security | match&amp;nbsp;FTP-INBOUND-DENY&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Is there a specific reason you want to use CLI? There's a filter and export function in the GUI that might work for you. You can filter on the action and then export the table to csv or pdf.&lt;/P&gt;</description>
      <pubDate>Tue, 10 Nov 2020 19:06:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/list-all-deny-rules-from-cli/m-p/361955#M88251</guid>
      <dc:creator>rmfalconer</dc:creator>
      <dc:date>2020-11-10T19:06:09Z</dc:date>
    </item>
    <item>
      <title>Re: List all deny rules from cli</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/list-all-deny-rules-from-cli/m-p/363165#M88333</link>
      <description>&lt;P&gt;Your suggestion sounds good but my purpose is to get details about the subnets involved&lt;/P&gt;&lt;P&gt;So as well as the list of all DENY rules whose action is actually "deny" I'd like to get further details on the network segment&lt;/P&gt;&lt;P&gt;For instance, with reference to the rule called FTP-INBOUND-DENY, it would be great if I could see something like:&lt;/P&gt;&lt;P&gt;&amp;nbsp;FTP-INBOUND-DENY 192.168.1.0/24&lt;/P&gt;&lt;P&gt;Through cli it would be better I believe&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 15 Nov 2020 22:40:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/list-all-deny-rules-from-cli/m-p/363165#M88333</guid>
      <dc:creator>jls3j999</dc:creator>
      <dc:date>2020-11-15T22:40:03Z</dc:date>
    </item>
    <item>
      <title>Re: List all deny rules from cli</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/list-all-deny-rules-from-cli/m-p/363382#M88357</link>
      <description>&lt;P&gt;I think using the GUI would be easier in this case. Filer the security policies with&amp;nbsp;(action eq 'deny') or&amp;nbsp;(action eq 'drop') [or whatever action you want to filter on] and export to CSV.&amp;nbsp;&lt;/P&gt;&lt;P&gt;It shows rule name, src/dst addresses, zones, plus other info. At that point, you can just hide any columns you don't want and you'll have what you're looking for.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Nov 2020 16:27:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/list-all-deny-rules-from-cli/m-p/363382#M88357</guid>
      <dc:creator>rmfalconer</dc:creator>
      <dc:date>2020-11-16T16:27:39Z</dc:date>
    </item>
    <item>
      <title>Re: List all deny rules from cli</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/list-all-deny-rules-from-cli/m-p/363414#M88361</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/55733"&gt;@rmfalconer&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;I think using the GUI would be easier in this case. Filer the security policies with&amp;nbsp;(action eq 'deny') or&amp;nbsp;(action eq 'drop') [or whatever action you want to filter on] and export to CSV.&amp;nbsp;&lt;/P&gt;&lt;P&gt;It shows rule name, src/dst addresses, zones, plus other info. At that point, you can just hide any columns you don't want and you'll have what you're looking for.&amp;nbsp;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;In this case the best filter is probably (action neq 'allow') &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Nov 2020 17:02:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/list-all-deny-rules-from-cli/m-p/363414#M88361</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2020-11-16T17:02:05Z</dc:date>
    </item>
  </channel>
</rss>

