Stupid question, but how to show all vsys in CLI with one command?

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Stupid question, but how to show all vsys in CLI with one command?

L0 Member

Hey guys, this may be a stupid question but I just cannot find the appropriate command for this after googling for nearly an hour. I just want to display all vsys via CLI in one command without the need of "?". Something like show virtual-system all or so. Is this even possible?

8 REPLIES 8

Cyber Elite

Hello @Yunus_Salem

 

from the documentation cli command hierarchy I do not see any command that will fulfil your requirement, however I think it is possible with API. Could you check whether this works (I do not have a device with vsys license to test it with)?

 

curl -X GET "https://<firewall>/api/?key=<api_key>&type=op&cmd=<show><vsys></vsys>"

 

Kind Regards

Pavel

Help the community: Like helpful comments and mark solutions.

Cyber Elite

Hi @Yunus_Salem ,

 

You can use the command "set system setting target-vsys ?" and see the virtual systems listed as options.

 

https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-cli-quick-start/cli-cheat-sheets/cli-cheat-sheet...

 

Thanks,

 

Tom

Help the community: Like helpful comments and mark solutions.

L3 Networker

Hello,

 

Just have a question regarding this command :

 

We recently upgraded our clusters to PanOS 11.1 and now when using this command, it doesn't display the vsys name anymore :

 

> set system setting target-vsys
none none
vsys1 vsys1
vsys2 vsys2
vsys3 vsys3

...        ...
<value> <value>

 

In PanOS 10.2 the vsys names were displayed along with the vsys number

 

How to easily link vsys number and vsys name?

Indeed, when you want to modify/get settings related to a particular vsys you need to know in which vsys context you are...

 

Regards,

L1 Bithead

This worked for me (on 11.1)

show session all filter vsys-name ?

but might not show vsys that don't have any active sessions.

 

Hello,

 

Thanks but my question was regarding cli command > set system setting target-vsys to change vsys cli space

 

In PanOS 10.2 we got something like :

 

> set system setting target-vsys
none none
vsys1 customer1
vsys2 customer2
vsys3 customer3

...        ...
<value> <value>

 

When needed to set / check something relate to a particular vsys environnement...

 

Now in PanOS 11.1 the vsys name is not displayed anymore, instead there is juste vsys number which is not relevant at all :

 

> set system setting target-vsys
none none
vsys1 vsys1
vsys2 vsys2
vsys3 vsys3

...        ...
<value> <value>

 

I don't even find in the webui (panorama) where to see the vsys name ...

 

 

L1 Bithead

The purpose of what I responded with was to have it provide the names of the vsys from the cli so you can know which one to use for that other command. That target command did not show the names but show sessions one did.

adminusername@PA-7050-A(active)> set system setting target-vsys
none none
vsys1 vsys1
vsys10 vsys10
vsys11 vsys11
vsys12 vsys12
etc. - names not shown

adminusername@PA-7050-A(active)> show session all filter vsys-name ?
any Any
vsys1 vsys1
vsys10 sales-floor7-vsys
vsys11 research-floor-9-vsys
vsys12 lunchroom-floor-1-vsys
vsys13 shop-vsys
etc. - names shown. Then you know which vsys number to use in set system setting target-vsys

such as

set system setting target-vsys vsys13 for the "shop-vsys" or whatever your vsys of interest is,

This should work if you have 11.1 code in multi-vsys mode (unless your target vsys has no sessions active).

There is also a way to do this in GUI.  Requires going to the firewall GUI instead of Panorama, then, device and virtual systems. At least on ours, the names and vsys numbers are both listed.

Hello,

 

Ok I did't realize the purpose of your answer.

 

Indeed this cli displays the vsys name, however you have to execute it on the appliance, not from Panorma.

 

But it could be a workaround anyway,

 

Thanks for your answer.

 

 

  • 7022 Views
  • 8 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!