Using XML API to query policy post rules

Showing results for 
Show  only  | Search instead for 
Did you mean: 

Using XML API to query policy post rules

L1 Bithead

Trying to find the correct syntax for querying Panorama for policy post rules by matching IP address (source or destination IP) using the PanOS XML API.


I have looked at:

  1. our XML API Browser page (i.e. https://<mypanoramahostname>/api),
  2. the online docs (,
  3. A documented Postman collection(, and
  4. this LIVEcommunity site.

Still not finding what I am looking for. Is it me, or is API not sufficiently well documented? Can anyone point me to where I can find documentation for each PanOS XML API endpoint, preferably with syntax examples for all possible endpoint parameters?


Hi @julio.toledo, the API structure for this feature will match what you see in the GUI, where there are indeed mandatory fields (the red boxes) like destination ports, and protocol is a drop-down between TCP/UDP/ICMP:


Test Policy Match GUI ScreenshotTest Policy Match GUI Screenshot


I think this feature is designed to give people a way to test if specific traffic will theoretically pass through the firewall, rather than the very broad and almost audit-type requirement which you have. If you talk with your allocated Systems Engineer or reseller (if you're unsure who they are, send me a direct message on here and I will assist) then they will be able to discuss your requirements and potentially raise a feature request.

Other options to fulfil your requirements would involve an approach of systematically checking the live configurations of your firewall estate, by exporting the Panorama running config and walking through the XML data in your programming language of choice.

Help the community: "Like" helpful comments, and click "Accept as Solution" if you found your answer 🙂

Ding, ding, ding! We have a winner. So what I am looking to accomplish is audit/research level work.


On a competitor's product (which shall remain nameless) I am able to issue the following simple, single-line CLI command (on a device-by-device basis) and get back an exhaustive std output of every member rule matching the IP that I'm searching for --either as source or as destination:

show access-list | include {{ lookupIP }}

 This is exactly the kind of functionality that I'm looking for from Panorama/PAN-OS.

L5 Sessionator

Thanks for confirming @julio.toledo. Per DM, we've connected you with your SE in order to discuss this topic in more detail.

Help the community: "Like" helpful comments, and click "Accept as Solution" if you found your answer 🙂
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!