Set Commands Removed in PAN-OS 11.2
Command line interface 'set' commands that are removed in PAN-OS 11.2:
| Where Can I Use This? | What Do I Need? |
| NGFW (Managed by PAN-OS or Panorama) |
|
The following commands are no longer available in the 11.2 release.
set deviceconfig system mtu <576-9216>
set deviceconfig setting auto-mac-detect <yes|no>
set deviceconfig setting wildfire cloud-inline-wildfire report-benign-file <yes|no>
set deviceconfig setting wildfire cloud-inline-wildfire report-grayware-file <yes|no>
set deviceconfig setting session timeout-sctp-init <1-120>
set deviceconfig setting session timeout-sctp-cookie <1-120>
set deviceconfig setting session timeout-discard-sctp <1-600>
set deviceconfig setting session timeout-sctp-shutdown <1-600>
set deviceconfig setting session timeout-sctp <1-86400>
set deviceconfig setting session timeout-5gc-delete <15-1800>
set deviceconfig setting management quota-settings log-expiration-period sctp <1-2000>
set deviceconfig setting management quota-settings log-expiration-period sctpsum <1-2000>
set deviceconfig setting management quota-settings log-expiration-period hourlysctpsum <1-2000>
set deviceconfig setting management quota-settings log-expiration-period dailysctpsum <1-2000>
set deviceconfig setting management quota-settings log-expiration-period weeklysctpsum <1-2000>
set deviceconfig setting management quota-settings disk-quota sctp <float>
set deviceconfig setting management quota-settings disk-quota sctpsum <float>
set deviceconfig setting management quota-settings disk-quota hourlysctpsum <float>
set deviceconfig setting management quota-settings disk-quota dailysctpsum <float>
set deviceconfig setting management quota-settings disk-quota weeklysctpsum <float>
set deviceconfig setting gtp <yes|no>
set deviceconfig setting mobile-security-policy <yes|no>
set deviceconfig setting sctp <yes|no>
set deviceconfig high-availability interface ha1 port <value>|<management>
set deviceconfig high-availability interface ha1-backup port <value>|<management>
set deviceconfig high-availability interface ha2 port <value>
set deviceconfig high-availability interface ha2-backup port <value>
set deviceconfig high-availability interface ha3 port <value>
set deviceconfig cluster
set deviceconfig cluster enabled <yes|no>
set deviceconfig cluster cluster-type <PA>
set deviceconfig cluster devices
set deviceconfig cluster devices <name>
set deviceconfig cluster devices <name> node-id <1-2>
set deviceconfig cluster devices <name> mgmt-ip-address <ip/netmask>
set deviceconfig cluster cluster-mode <device-redundancy>
set deviceconfig cluster cluster-heartbeat
set deviceconfig cluster cluster-heartbeat cluster-keepalive-threshold <3-100>
set deviceconfig cluster cluster-heartbeat cluster-heartbeat-interval <1000-60000>
set deviceconfig cluster monitoring
set deviceconfig cluster monitoring path-monitoring
set deviceconfig cluster monitoring path-monitoring enabled <yes|no>
set deviceconfig cluster monitoring path-monitoring failure-condition <any|all>
set deviceconfig cluster monitoring path-monitoring path-group
set deviceconfig cluster monitoring path-monitoring path-group virtual-wire
set deviceconfig cluster monitoring path-monitoring path-group virtual-wire <name>
set deviceconfig cluster monitoring path-monitoring path-group virtual-wire <name> source-ip <ip/netmask>
set deviceconfig cluster monitoring path-monitoring path-group virtual-wire <name> enabled <yes|no>
set deviceconfig cluster monitoring path-monitoring path-group virtual-wire <name> failure-condition <any|all>
set deviceconfig cluster monitoring path-monitoring path-group virtual-wire <name> ping-interval <200-60000>
set deviceconfig cluster monitoring path-monitoring path-group virtual-wire <name> ping-count <3-10>
set deviceconfig cluster monitoring path-monitoring path-group virtual-wire <name> destination-ip-group
set deviceconfig cluster monitoring path-monitoring path-group virtual-wire <name> destination-ip-group <name>
set deviceconfig cluster monitoring path-monitoring path-group virtual-wire <name> destination-ip-group <name> destination-ip [ <destination-ip1> <destination-ip2>... ]
set deviceconfig cluster monitoring path-monitoring path-group virtual-wire <name> destination-ip-group <name> enabled <yes|no>
set deviceconfig cluster monitoring path-monitoring path-group virtual-wire <name> destination-ip-group <name> failure-condition <any|all>
set deviceconfig cluster monitoring path-monitoring path-group vlan
set deviceconfig cluster monitoring path-monitoring path-group vlan <name>
set deviceconfig cluster monitoring path-monitoring path-group vlan <name> source-ip <ip/netmask>
set deviceconfig cluster monitoring path-monitoring path-group vlan <name> enabled <yes|no>
set deviceconfig cluster monitoring path-monitoring path-group vlan <name> failure-condition <any|all>
set deviceconfig cluster monitoring path-monitoring path-group vlan <name> ping-interval <200-60000>
set deviceconfig cluster monitoring path-monitoring path-group vlan <name> ping-count <3-10>
set deviceconfig cluster monitoring path-monitoring path-group vlan <name> destination-ip-group
set deviceconfig cluster monitoring path-monitoring path-group vlan <name> destination-ip-group <name>
set deviceconfig cluster monitoring path-monitoring path-group vlan <name> destination-ip-group <name> destination-ip [ <destination-ip1> <destination-ip2>... ]
set deviceconfig cluster monitoring path-monitoring path-group vlan <name> destination-ip-group <name> enabled <yes|no>
set deviceconfig cluster monitoring path-monitoring path-group vlan <name> destination-ip-group <name> failure-condition <any|all>
set deviceconfig cluster monitoring path-monitoring path-group virtual-router
set deviceconfig cluster monitoring path-monitoring path-group virtual-router <name>
set deviceconfig cluster monitoring path-monitoring path-group virtual-router <name> enabled <yes|no>
set deviceconfig cluster monitoring path-monitoring path-group virtual-router <name> failure-condition <any|all>
set deviceconfig cluster monitoring path-monitoring path-group virtual-router <name> ping-interval <200-60000>
set deviceconfig cluster monitoring path-monitoring path-group virtual-router <name> ping-count <3-10>
set deviceconfig cluster monitoring path-monitoring path-group virtual-router <name> destination-ip-group
set deviceconfig cluster monitoring path-monitoring path-group virtual-router <name> destination-ip-group <name>
set deviceconfig cluster monitoring path-monitoring path-group virtual-router <name> destination-ip-group <name> destination-ip [ <destination-ip1> <destination-ip2>... ]
set deviceconfig cluster monitoring path-monitoring path-group virtual-router <name> destination-ip-group <name> enabled <yes|no>
set deviceconfig cluster monitoring path-monitoring path-group virtual-router <name> destination-ip-group <name> failure-condition <any|all>
set deviceconfig cluster inter-firewall-link
set deviceconfig cluster inter-firewall-link <name>
set deviceconfig cluster group-id <1-63>
set mgt-config users <name> preferences saved-log-query gtp
set mgt-config users <name> preferences saved-log-query gtp <name>
set mgt-config users <name> preferences saved-log-query gtp <name> query <value>
set network profiles zone-protection-profile <name> flood sctp-init
set network profiles zone-protection-profile <name> flood sctp-init enable <yes|no>
set network profiles zone-protection-profile <name> flood sctp-init red
set network profiles zone-protection-profile <name> flood sctp-init red alarm-rate <0-2000000>
set network profiles zone-protection-profile <name> flood sctp-init red activate-rate <1-2000000>
set network profiles zone-protection-profile <name> flood sctp-init red maximal-rate <1-2000000>
set network profiles bfd-profile <name> min-tx-interval <200-10000>
set network profiles bfd-profile <name> min-rx-interval <200-10000>
set network interface ethernet <name> link-speed <auto>
set network interface ethernet <name> link-duplex <auto>
set network interface ethernet <name> layer3 mtu <576-1500>
set network interface ethernet <name> layer3 ipv6 pppoe neighbor-discovery enable-ndp-monitor <yes|no>
set network interface ethernet <name> layer3 ipv6 pppoe neighbor-discovery enable-dad <yes|no>
set network interface ethernet <name> layer3 ipv6 pppoe neighbor-discovery dad-attempts <1-10>
set network interface ethernet <name> layer3 ipv6 pppoe neighbor-discovery ns-interval <1-3600>
set network interface ethernet <name> layer3 ipv6 pppoe neighbor-discovery reachable-time <10-36000>
set network interface ethernet <name> layer3 units <name> ipv6 pppoe neighbor-discovery enable-ndp-monitor <yes|no>
set network interface ethernet <name> layer3 units <name> ipv6 pppoe neighbor-discovery enable-dad <yes|no>
set network interface ethernet <name> layer3 units <name> ipv6 pppoe neighbor-discovery dad-attempts <1-10>
set network interface ethernet <name> layer3 units <name> ipv6 pppoe neighbor-discovery ns-interval <1-3600>
set network interface ethernet <name> layer3 units <name> ipv6 pppoe neighbor-discovery reachable-time <10-36000>
set network interface aggregate-ethernet <name> layer3 ipv6 pppoe neighbor-discovery enable-ndp-monitor <yes|no>
set network interface aggregate-ethernet <name> layer3 ipv6 pppoe neighbor-discovery enable-dad <yes|no>
set network interface aggregate-ethernet <name> layer3 ipv6 pppoe neighbor-discovery dad-attempts <1-10>
set network interface aggregate-ethernet <name> layer3 ipv6 pppoe neighbor-discovery ns-interval <1-3600>
set network interface aggregate-ethernet <name> layer3 ipv6 pppoe neighbor-discovery reachable-time <10-36000>
set network interface aggregate-ethernet <name> layer3 units <name> ipv6 pppoe neighbor-discovery enable-ndp-monitor <yes|no>
set network interface aggregate-ethernet <name> layer3 units <name> ipv6 pppoe neighbor-discovery enable-dad <yes|no>
set network interface aggregate-ethernet <name> layer3 units <name> ipv6 pppoe neighbor-discovery dad-attempts <1-10>
set network interface aggregate-ethernet <name> layer3 units <name> ipv6 pppoe neighbor-discovery ns-interval <1-3600>
set network interface aggregate-ethernet <name> layer3 units <name> ipv6 pppoe neighbor-discovery reachable-time <10-36000>
set network interface vlan ipv6 pppoe neighbor-discovery enable-ndp-monitor <yes|no>
set network interface vlan ipv6 pppoe neighbor-discovery enable-dad <yes|no>
set network interface vlan ipv6 pppoe neighbor-discovery dad-attempts <1-10>
set network interface vlan ipv6 pppoe neighbor-discovery ns-interval <1-3600>
set network interface vlan ipv6 pppoe neighbor-discovery reachable-time <10-36000>
set network interface vlan units <name> ipv6 pppoe neighbor-discovery enable-ndp-monitor <yes|no>
set network interface vlan units <name> ipv6 pppoe neighbor-discovery enable-dad <yes|no>
set network interface vlan units <name> ipv6 pppoe neighbor-discovery dad-attempts <1-10>
set network interface vlan units <name> ipv6 pppoe neighbor-discovery ns-interval <1-3600>
set network interface vlan units <name> ipv6 pppoe neighbor-discovery reachable-time <10-36000>
set network ike crypto-profiles ipsec-crypto-profiles <name> dh-group <no-pfs|group1|group2|group5|group14|group15|group16|group19|group20|group21>
set network virtual-router <name> routing-table ip static-route <name> path-monitor monitor-destinations <name> source <value>|<DHCP|PPPOE>
set network secure-web-gateway
set network secure-web-gateway enablement
set network secure-web-gateway enablement none
set network secure-web-gateway enablement explicit-proxy
set network secure-web-gateway enablement transparent-proxy
set network secure-web-gateway enablement paloalto-networks-service-proxy
set network secure-web-gateway explicit-web-gateway
set network secure-web-gateway explicit-web-gateway connect-timeout <1-60>
set network secure-web-gateway explicit-web-gateway dns-proxy <value>
set network secure-web-gateway explicit-web-gateway interface <value>
set network secure-web-gateway explicit-web-gateway proxy-ip
set network secure-web-gateway explicit-web-gateway proxy-ip ipv4 <value>
set network secure-web-gateway explicit-web-gateway upstream-interface <value>
set network secure-web-gateway explicit-web-gateway authentication-profile <value>
set network secure-web-gateway explicit-web-gateway log-setting <value>
set network secure-web-gateway explicit-web-gateway authentication-method <none|saml-cas|kerberos-sso>
set network secure-web-gateway explicit-web-gateway skip-auth-category <value>
set network secure-web-gateway explicit-web-gateway swg-site-cookie <value>
set network secure-web-gateway explicit-web-gateway acs-return-path <value>
set network secure-web-gateway explicit-web-gateway strip-alpn <yes|no>
set network secure-web-gateway explicit-web-gateway sni-dest-check <yes|no>
set network secure-web-gateway transparent-web-gateway
set network secure-web-gateway transparent-web-gateway connect-timeout <1-60>
set network secure-web-gateway transparent-web-gateway dns-proxy <value>
set network secure-web-gateway transparent-web-gateway upstream-interface <value>
set network secure-web-gateway transparent-web-gateway proxy-ip
set network secure-web-gateway transparent-web-gateway proxy-ip ipv4 <value>
set network secure-web-gateway paloalto-networks-service-gateway
set network secure-web-gateway paloalto-networks-service-gateway connect-timeout <1-60>
set network secure-web-gateway paloalto-networks-service-gateway dns-proxy <value>
set network secure-web-gateway paloalto-networks-service-gateway interface <value>
set network secure-web-gateway paloalto-networks-service-gateway proxy-ip
set network secure-web-gateway paloalto-networks-service-gateway proxy-ip ipv4 <value>
set network secure-web-gateway paloalto-networks-service-gateway upstream-interface <value>
set network secure-web-gateway paloalto-networks-service-gateway allowed-category <value>
set network secure-web-gateway paloalto-networks-service-gateway next-hop-proxy-server <value>
set network secure-web-gateway paloalto-networks-service-gateway next-hop-proxy-port <1-65535>
set network logical-router <name> vrf <name> routing-table ip static-route <name> path-monitor monitor-destinations <name> source <value>|<DHCP|PPPOE>
set network routing-profile filters prefix-list <name> type ipv4 ipv4-entry <name> prefix entry network <validate>|<ip/netmask>|<value>
set network routing-profile bfd <name> min-tx-interval <200-10000>
set network routing-profile bfd <name> min-rx-interval <200-10000>
set shared reports <name> type decryption group-by <serial|time_generated|src|dst|natsrc|natdst|rule|srcuser|dstuser|srcloc|dstloc|app|vsys|from|to|inbound_if|outbound_if|sport|dport|natsport|natdport|proto|action|tunnel|src_uuid|dst_uuid|rule_uuid|s_encrypted|category-of-app|subcategory-of-app|technology-of-app|container-of-app|risk-of-app|vsys_name|device_name|tls_version|tls_keyxchg|tls_enc|tls_auth|ec_curve|err_index|root_status|proxy_type|policy_name|cn|issuer_cn|root_cn|sni|error|cluster_name|src_dag|dst_dag|src_edl|dst_edl|container_id|pod_namespace|pod_name|src_category|src_profile|src_model|src_vendor|src_osfamily|src_osversion|src_host|src_mac|dst_category|dst_profile|dst_model|dst_vendor|dst_osfamily|dst_osversion|dst_host|dst_mac|day-of-receive_time|hour-of-receive_time|quarter-hour-of-receive_time>
set shared reports <name> type threat group-by <serial|time_generated|src|dst|natsrc|natdst|rule|srcuser|dstuser|srcloc|dstloc|app|vsys|from|to|inbound_if|outbound_if|sport|dport|natsport|natdport|proto|action|tunnel|src_uuid|dst_uuid|rule_uuid|s_encrypted|category-of-app|subcategory-of-app|technology-of-app|container-of-app|risk-of-app|vsys_name|device_name|parent_session_id|parent_start_time|parent_session_id_64|threatid|category|severity|direction|http_method|nssai_sst|filedigest|filetype|http2_connection|xff_ip|threat_name|src_edl|dst_edl|dynusergroup_name|hostid|partial_hash|cloud_reportid|cluster_name|flow_type|http2_connection_64|src_category|src_profile|src_model|src_vendor|src_osfamily|src_osversion|src_host|src_mac|dst_category|dst_profile|dst_model|dst_vendor|dst_osfamily|dst_osversion|dst_host|dst_mac|container_id|pod_namespace|pod_name|misc|src_dag|dst_dag|day-of-receive_time|hour-of-receive_time|quarter-hour-of-receive_time|pbf-s2c|pbf-c2s|flag-nat|flag-pcap|subtype|transaction|captive-portal|flag-proxy|non-std-dport|tunnelid|imsi|monitortag|imei|users|category-of-threatid|threat-type>
set shared reports <name> type url group-by <action|app|category|category-of-app|direction|dport|dst|dstuser|from|inbound_if|misc|http_headers|natdport|natdst|natsport|natsrc|outbound_if|proto|risk-of-app|rule|rule_uuid|severity|sport|src|srcuser|subcategory-of-app|technology-of-app|container-of-app|to|dstloc|srcloc|vsys|quarter-hour-of-receive_time|hour-of-receive_time|day-of-receive_time|contenttype|user_agent|device_name|vsys_name|url|tunnelid|monitortag|imsi|imei|parent_session_id|parent_start_time|http2_connection|tunnel|http_method|url_category_list|xff_ip|container_id|pod_namespace|pod_name|src_dag|dst_dag|src_edl|dst_edl|src_category|src_profile|src_model|src_vendor|src_osfamily|src_osversion|src_host|src_mac|dst_category|dst_profile|dst_model|dst_vendor|dst_osfamily|dst_osversion|dst_host|dst_mac|cloud_reportid>
set shared reports <name> type wildfire group-by <app|category|category-of-app|dport|dst|dstuser|from|inbound_if|misc|natdport|natdst|natsport|natsrc|outbound_if|proto|risk-of-app|rule|rule_uuid|sport|src|srcuser|subcategory-of-app|technology-of-app|container-of-app|to|dstloc|srcloc|vsys|quarter-hour-of-receive_time|hour-of-receive_time|day-of-receive_time|vsys_name|device_name|filetype|filename|filedigest|tunnelid|monitortag|imsi|imei|parent_session_id|parent_start_time|http2_connection|tunnel|xff_ip|src_dag|dst_dag|src_edl|dst_edl>
set shared reports <name> type data group-by <action|app|category-of-app|direction|dport|dst|dstuser|from|inbound_if|misc|natdport|natdst|natsport|natsrc|outbound_if|proto|risk-of-app|rule|rule_uuid|severity|sport|src|srcuser|subcategory-of-app|subtype|technology-of-app|container-of-app|threatid|to|dstloc|srcloc|vsys|quarter-hour-of-receive_time|hour-of-receive_time|day-of-receive_time|vsys_name|device_name|data-type|filename|tunnelid|monitortag|imsi|imei|parent_session_id|parent_start_time|http2_connection|tunnel|xff_ip|src_dag|dst_dag|src_edl|dst_edl|src_category|src_profile|src_model|src_vendor|src_osfamily|src_osversion|src_host|src_mac|dst_category|dst_profile|dst_model|dst_vendor|dst_osfamily|dst_osversion|dst_host|dst_mac>
set shared reports <name> type thsum group-by <serial|time_generated|vsys_name|device_name|app|src|dst|rule|threatid|srcuser|dstuser|srcloc|dstloc|xff_ip|vsys|from|to|dev_serial|dport|action|severity|inbound_if|outbound_if|category|category-of-app|subcategory-of-app|technology-of-app|container-of-app|risk-of-app|parent_session_id|parent_start_time|parent_session_id_64|tunnel|direction|assoc_id|ppid|http2_connection|rule_uuid|threat_name|src_edl|dst_edl|hostid|dynusergroup_name|nssai_sst|cluster_name|http2_connection_64|src_category|src_profile|src_model|src_vendor|src_osfamily|src_osversion|src_host|src_mac|dst_category|dst_profile|dst_model|dst_vendor|dst_osfamily|dst_osversion|dst_host|dst_mac|container_id|pod_namespace|pod_name|src_dag|dst_dag|day-of-receive_time|hour-of-receive_time|quarter-hour-of-receive_time|subtype|tunnelid|imsi|monitortag|imei|category-of-threatid|threat-type>
set shared reports <name> type traffic group-by <serial|time_generated|src|dst|natsrc|natdst|rule|srcuser|dstuser|srcloc|dstloc|app|vsys|from|to|inbound_if|outbound_if|sport|dport|natsport|natdport|proto|action|tunnel|src_uuid|dst_uuid|rule_uuid|s_encrypted|category-of-app|subcategory-of-app|technology-of-app|container-of-app|risk-of-app|vsys_name|device_name|parent_session_id|parent_start_time|parent_session_id_64|category|session_end_reason|action_source|nssai_sst|nssai_sd|http2_connection|xff_ip|dynusergroup_name|src_edl|dst_edl|hostid|session_owner|policy_id|offloaded|flow_type|cluster_name|http2_connection_64|src_category|src_profile|src_model|src_vendor|src_osfamily|src_osversion|src_host|src_mac|dst_category|dst_profile|dst_model|dst_vendor|dst_osfamily|dst_osversion|dst_host|dst_mac|container_id|pod_namespace|pod_name|src_dag|dst_dag|day-of-receive_time|hour-of-receive_time|quarter-hour-of-receive_time|pbf-s2c|pbf-c2s|decrypt-mirror|threat-type|flag-nat|flag-pcap|captive-portal|flag-proxy|non-std-dport|transaction|sym-return|sessionid|flag-decrypt-fwd|tunnelid|imsi|monitortag|imei>
set shared reports <name> type urlsum group-by <serial|time_generated|vsys_name|device_name|app|category|src|dst|rule|srcuser|dstuser|srcloc|dstloc|vsys|from|to|dev_serial|inbound_if|outbound_if|dport|action|tunnel|url_domain|user_agent|http_method|http2_connection|http2_connection_64|category-of-app|subcategory-of-app|technology-of-app|container-of-app|risk-of-app|parent_session_id|parent_start_time|parent_session_id_64|rule_uuid|xff_ip|src_edl|dst_edl|hostid|dynusergroup_name|nssai_sst|cluster_name|src_category|src_profile|src_model|src_vendor|src_osfamily|src_osversion|src_host|src_mac|dst_category|dst_profile|dst_model|dst_vendor|dst_osfamily|dst_osversion|dst_host|dst_mac|container_id|pod_namespace|pod_name|url_category_list|src_dag|dst_dag|day-of-receive_time|hour-of-receive_time|quarter-hour-of-receive_time|tunnelid|imsi|monitortag|imei>
set shared reports <name> type trsum group-by <serial|time_generated|vsys_name|device_name|app|src|dst|xff_ip|rule|srcuser|dstuser|srcloc|dstloc|category|vsys|from|to|dev_serial|dport|action|tunnel|inbound_if|outbound_if|category-of-app|subcategory-of-app|technology-of-app|container-of-app|risk-of-app|parent_session_id|parent_start_time|parent_session_id_64|assoc_id|http2_connection|rule_uuid|src_edl|dst_edl|dynusergroup_name|s_decrypted|s_encrypted|hostid|nssai_sst|cluster_name|flow_type|http2_connection_64|src_category|src_profile|src_model|src_vendor|src_osfamily|src_osversion|src_host|src_mac|dst_category|dst_profile|dst_model|dst_vendor|dst_osfamily|dst_osversion|dst_host|dst_mac|container_id|pod_namespace|pod_name|src_dag|dst_dag|day-of-receive_time|hour-of-receive_time|quarter-hour-of-receive_time|tunnelid|imsi|monitortag|imei|standard-ports-of-app>
set shared reports <name> type gtp
set shared reports <name> type gtp aggregate-by [ <aggregate-by1> <aggregate-by2>... ]
set shared reports <name> type gtp group-by <serial|time_generated|src|dst|natsrc|natdst|rule|srcuser|dstuser|srcloc|dstloc|app|vsys|from|to|inbound_if|outbound_if|sport|dport|natsport|natdport|proto|action|tunnel|src_uuid|dst_uuid|rule_uuid|s_encrypted|category-of-app|subcategory-of-app|technology-of-app|container-of-app|risk-of-app|vsys_name|device_name|parent_session_id|parent_start_time|parent_session_id_64|end_ip_addr|msisdn|nssai_sd|nssai_sst|pdu_session_id|apn|cause_code|mcc|mnc|cell_id|event_code|msg_type|area_code|session_end_reason|action_source|event_type|severity|rat|gtp_interface|remote_user_ip|remote_user_id|src_dag|dst_dag|src_edl|dst_edl|dynusergroup_name|cluster_name|container_id|pod_namespace|pod_name|day-of-receive_time|hour-of-receive_time|quarter-hour-of-receive_time|imei|imsi|sessionid>
set shared reports <name> type gtp values [ <values1> <values2>... ]
set shared reports <name> type gtp labels [ <labels1> <labels2>... ]
set shared reports <name> type gtp sortby <repeatcnt|nunique-of-users|severity>
set shared reports <name> type gtpsum
set shared reports <name> type gtpsum aggregate-by [ <aggregate-by1> <aggregate-by2>... ]
set shared reports <name> type gtpsum group-by <serial|time_generated|vsys_name|device_name|parent_session_id|parent_start_time|parent_session_id_64|app|src|dst|rule|srcloc|dstloc|vsys|dev_serial|msisdn|nssai_sd|nssai_sst|pdu_session_id|apn|cause_code|mcc|mnc|action|event_type|severity|rat|msg_type|tunnel|tunnel_insp_rule|remote_user_ip|remote_user_id|rule_uuid|src_edl|dst_edl|cluster_name|category-of-app|subcategory-of-app|technology-of-app|container-of-app|risk-of-app|container_id|pod_namespace|pod_name|src_dag|dst_dag|day-of-receive_time|hour-of-receive_time|quarter-hour-of-receive_time|imei|imsi>
set shared reports <name> type gtpsum values [ <values1> <values2>... ]
set shared reports <name> type gtpsum labels [ <labels1> <labels2>... ]
set shared reports <name> type gtpsum sortby <repeatcnt|severity>
set shared reports <name> type sctp
set shared reports <name> type sctp aggregate-by [ <aggregate-by1> <aggregate-by2>... ]
set shared reports <name> type sctp group-by <serial|time_generated|src|dst|natsrc|natdst|rule|srcuser|dstuser|srcloc|dstloc|app|vsys|from|to|inbound_if|outbound_if|sport|dport|natsport|natdport|proto|action|tunnel|src_uuid|dst_uuid|rule_uuid|s_encrypted|vsys_name|device_name|ppid|severity|sctp_chunk_type|sctp_event_type|sctp_event_code|verif_tag_1|verif_tag_2|sctp_cause_code|diam_app_id|diam_cmd_code|diam_avp_code|stream_id|op_code|sccp_calling_ssn|sccp_calling_gt|sctp_filter|assoc_end_reason|cluster_name|src_dag|dst_dag|src_edl|dst_edl|container_id|pod_namespace|pod_name|day-of-receive_time|hour-of-receive_time|quarter-hour-of-receive_time|sessionid|assoc_id>
set shared reports <name> type sctp values [ <values1> <values2>... ]
set shared reports <name> type sctp labels [ <labels1> <labels2>... ]
set shared reports <name> type sctp sortby <repeatcnt|chunks|chunks_sent|chunks_received|packets|pkts_sent|pkts_received|severity>
set shared reports <name> type sctpsum
set shared reports <name> type sctpsum aggregate-by [ <aggregate-by1> <aggregate-by2>... ]
set shared reports <name> type sctpsum group-by <serial|time_generated|vsys_name|device_name|src|dst|rule|srcloc|dstloc|action|vsys|dev_serial|assoc_id|ppid|severity|sctp_chunk_type|sctp_event_type|diam_app_id|diam_cmd_code|op_code|sccp_calling_ssn|sctp_filter|rule_uuid|src_edl|dst_edl|cluster_name|container_id|pod_namespace|pod_name|src_dag|dst_dag|day-of-receive_time|hour-of-receive_time|quarter-hour-of-receive_time|app>
set shared reports <name> type sctpsum values [ <values1> <values2>... ]
set shared reports <name> type sctpsum labels [ <labels1> <labels2>... ]
set shared reports <name> type sctpsum sortby <chunks|chunks_sent|chunks_received|packets|pkts_sent|pkts_received|repeatcnt|severity>
set shared log-settings system match-list <name> actions <name> type integration
set shared log-settings system match-list <name> actions <name> type integration action <Azure-Security-Center-Integration>
set shared log-settings userid match-list <name> actions <name> type integration
set shared log-settings userid match-list <name> actions <name> type integration action <Azure-Security-Center-Integration>
set shared log-settings iptag match-list <name> actions <name> type integration
set shared log-settings iptag match-list <name> actions <name> type integration action <Azure-Security-Center-Integration>
set shared log-settings hipmatch match-list <name> actions <name> type integration
set shared log-settings hipmatch match-list <name> actions <name> type integration action <Azure-Security-Center-Integration>
set shared log-settings email <name> format gtp <value>
set shared log-settings email <name> format sctp <value>
set shared log-settings syslog <name> format gtp <value>
set shared log-settings syslog <name> format sctp <value>
set shared log-settings http <name> format gtp
set shared log-settings http <name> format gtp name <value>
set shared log-settings http <name> format gtp url-format <value>
set shared log-settings http <name> format gtp headers
set shared log-settings http <name> format gtp headers <name>
set shared log-settings http <name> format gtp headers <name> value <value>
set shared log-settings http <name> format gtp params
set shared log-settings http <name> format gtp params <name>
set shared log-settings http <name> format gtp params <name> value <value>
set shared log-settings http <name> format gtp payload <value>
set shared log-settings http <name> format sctp
set shared log-settings http <name> format sctp name <value>
set shared log-settings http <name> format sctp url-format <value>
set shared log-settings http <name> format sctp headers
set shared log-settings http <name> format sctp headers <name>
set shared log-settings http <name> format sctp headers <name> value <value>
set shared log-settings http <name> format sctp params
set shared log-settings http <name> format sctp params <name>
set shared log-settings http <name> format sctp params <name> value <value>
set shared log-settings http <name> format sctp payload <value>
set shared log-settings profiles <name> match-list <name> log-type <traffic|threat|wildfire|url|data|gtp|sctp|tunnel|auth|decryption>
set shared log-settings profiles <name> match-list <name> actions <name> type integration
set shared log-settings profiles <name> match-list <name> actions <name> type integration action <Azure-Security-Center-Integration>
set shared certificate <name>
set shared certificate <name> cloud-resource-id
set shared certificate <name> cloud-resource-id azure
set shared certificate <name> cloud-resource-id azure key-vault-uri <value>
set shared certificate <name> cloud-resource-id azure secret <value>
set shared certificate <name> cloud-resource-id aws
set shared certificate <name> cloud-resource-id aws secret <value>
set shared admin-role <name> role device webui objects security-profiles gtp-protection <enable|read-only|disable>
set shared admin-role <name> role device webui objects security-profiles sctp-protection <enable|read-only|disable>
set shared admin-role <name> role device webui network secure-web-gateway <enable|read-only|disable>
set shared admin-role <name> role device restapi objects gtp-protection-security-profiles <enable|read-only|disable>
set shared admin-role <name> role device restapi objects sctp-protection-security-profiles <enable|read-only|disable>
set import resource max-security-rules <0-65000>
set zone <name> network enable-preserve-prenat-user-info <yes|no>
set sdwan-interface-profile <name> link-type <ADSL/DSL|Cablemodem|Ethernet|Fiber|LTE/3G/4G/5G|MPLS|Microwave/Radio|Satellite|WiFi|Other>
set global-protect global-protect-gateway <name> gp-gw-dhcp entry
set global-protect global-protect-gateway <name> gp-gw-dhcp entry enable-dhcp <yes|no>
set global-protect global-protect-gateway <name> gp-gw-dhcp entry dhcp-timeout <1-120>
set global-protect global-protect-gateway <name> gp-gw-dhcp entry retry-times <0-5>
set global-protect global-protect-gateway <name> gp-gw-dhcp entry gp-dhcp-server [ <gp-dhcp-server1> <gp-dhcp-server2>... ]
set profiles wildfire-analysis <name> mica-engine-wildfire-rules <name> action <allow|block>
set profiles gtp
set profiles gtp <name>
set profiles gtp <name> description <value>
set profiles gtp <name> gtp-inspection
set profiles gtp <name> gtp-inspection gtp-c
set profiles gtp <name> gtp-inspection gtp-c gtpv1-c
set profiles gtp <name> gtp-inspection gtp-c gtpv1-c stateful-inspection <yes|no>
set profiles gtp <name> gtp-inspection gtp-c gtpv1-c validity-checks
set profiles gtp <name> gtp-inspection gtp-c gtpv1-c validity-checks action <block|alert>
set profiles gtp <name> gtp-inspection gtp-c gtpv1-c validity-checks reserved-ie <yes|no>
set profiles gtp <name> gtp-inspection gtp-c gtpv1-c validity-checks order-of-ie <yes|no>
set profiles gtp <name> gtp-inspection gtp-c gtpv1-c validity-checks length-of-ie <yes|no>
set profiles gtp <name> gtp-inspection gtp-c gtpv1-c validity-checks reserved-hdr-field <yes|no>
set profiles gtp <name> gtp-inspection gtp-c gtpv1-c validity-checks unknown-message <yes|no>
set profiles gtp <name> gtp-inspection gtp-c gtpv2-c
set profiles gtp <name> gtp-inspection gtp-c gtpv2-c stateful-inspection <yes|no>
set profiles gtp <name> gtp-inspection gtp-c gtpv2-c validity-checks
set profiles gtp <name> gtp-inspection gtp-c gtpv2-c validity-checks action <block|alert>
set profiles gtp <name> gtp-inspection gtp-c gtpv2-c validity-checks reserved-ie <yes|no>
set profiles gtp <name> gtp-inspection gtp-c gtpv2-c validity-checks length-of-ie <yes|no>
set profiles gtp <name> gtp-inspection gtp-c gtpv2-c validity-checks reserved-hdr-field <yes|no>
set profiles gtp <name> gtp-inspection gtp-c gtpv2-c validity-checks unknown-message <yes|no>
set profiles gtp <name> gtp-inspection gtp-u
set profiles gtp <name> gtp-inspection gtp-u validity-checks
set profiles gtp <name> gtp-inspection gtp-u validity-checks action <block|alert>
set profiles gtp <name> gtp-inspection gtp-u validity-checks reserved-ie <yes|no>
set profiles gtp <name> gtp-inspection gtp-u validity-checks order-of-ie <yes|no>
set profiles gtp <name> gtp-inspection gtp-u validity-checks length-of-ie <yes|no>
set profiles gtp <name> gtp-inspection gtp-u validity-checks reserved-hdr-field <yes|no>
set profiles gtp <name> gtp-inspection gtp-u validity-checks unknown-message <yes|no>
set profiles gtp <name> gtp-inspection gtp-u gtp-in-gtp <allow|block|alert>
set profiles gtp <name> gtp-inspection gtp-u user-ip-spoofing <allow|block|alert>
set profiles gtp <name> gtp-inspection gtp-u log-at-session-start <yes|no>
set profiles gtp <name> gtp-inspection gtp-u log-at-session-end <yes|no>
set profiles gtp <name> gtp-inspection gtp-u gtpu-content-inspection <yes|no>
set profiles gtp <name> gtp-inspection gtp-5g-c
set profiles gtp <name> gtp-inspection gtp-5g-c gtp-5g-http2 <yes|no>
set profiles gtp <name> gtp-inspection pfcp
set profiles gtp <name> gtp-inspection pfcp stateful-inspection <yes|no>
set profiles gtp <name> gtp-inspection pfcp check-association-msg <allow|block|alert>
set profiles gtp <name> gtp-inspection pfcp check-session-msg <allow|block|alert>
set profiles gtp <name> gtp-inspection pfcp check-seq-num <allow|block|alert>
set profiles gtp <name> gtp-inspection pfcp log-at-association-start <yes|no>
set profiles gtp <name> gtp-inspection pfcp log-at-association-end <yes|no>
set profiles gtp <name> gtp-inspection pfcp log-at-session-start <yes|no>
set profiles gtp <name> gtp-inspection pfcp log-at-session-end <yes|no>
set profiles gtp <name> correlation
set profiles gtp <name> correlation ueip-correlation <yes|no>
set profiles gtp <name> correlation mode <loose|strict>
set profiles gtp <name> correlation source <pfcp|radius|gtp>
set profiles gtp <name> correlation log-at-ueip-start <yes|no>
set profiles gtp <name> correlation log-at-ueip-end <yes|no>
set profiles gtp <name> correlation up-gtpu <yes|no>
set profiles gtp <name> filtering
set profiles gtp <name> filtering imsi-prefix
set profiles gtp <name> filtering imsi-prefix <name>
set profiles gtp <name> filtering imsi-prefix <name> description <value>
set profiles gtp <name> filtering imsi-prefix <name> action <allow|block|alert>
set profiles gtp <name> filtering apn
set profiles gtp <name> filtering apn <name>
set profiles gtp <name> filtering apn <name> description <value>
set profiles gtp <name> filtering apn <name> action <allow|block|alert>
set profiles gtp <name> filtering rat
set profiles gtp <name> filtering rat utran <allow|block|alert>
set profiles gtp <name> filtering rat geran <allow|block|alert>
set profiles gtp <name> filtering rat wlan <allow|block|alert>
set profiles gtp <name> filtering rat gan <allow|block|alert>
set profiles gtp <name> filtering rat hspa-evolution <allow|block|alert>
set profiles gtp <name> filtering rat eutran <allow|block|alert>
set profiles gtp <name> filtering rat virtual <allow|block|alert>
set profiles gtp <name> filtering rat eutran-nb-iot <allow|block|alert>
set profiles gtp <name> filtering rat lte-m <allow|block|alert>
set profiles gtp <name> filtering rat nr <allow|block|alert>
set profiles gtp <name> tunnel-limit
set profiles gtp <name> tunnel-limit gtp-u
set profiles gtp <name> tunnel-limit gtp-u max-tunnel-limit <0-100000000>
set profiles gtp <name> tunnel-limit gtp-u alert-tunnel-limit <0-100000000>
set profiles gtp <name> tunnel-limit log-frequency <1-10000000>
set profiles gtp <name> overbilling
set profiles gtp <name> overbilling vsys <value>
set profiles gtp <name> gtp-log
set profiles gtp <name> gtp-log gtpv1c-allowed-messages
set profiles gtp <name> gtp-log gtpv1c-allowed-messages tunnel-management <yes|no>
set profiles gtp <name> gtp-log gtpv1c-allowed-messages path-management <yes|no>
set profiles gtp <name> gtp-log gtpv1c-allowed-messages others <yes|no>
set profiles gtp <name> gtp-log gtpv2c-allowed-messages
set profiles gtp <name> gtp-log gtpv2c-allowed-messages tunnel-management <yes|no>
set profiles gtp <name> gtp-log gtpv2c-allowed-messages path-management <yes|no>
set profiles gtp <name> gtp-log gtpv2c-allowed-messages others <yes|no>
set profiles gtp <name> gtp-log gtpu-allowed-messages
set profiles gtp <name> gtp-log gtpu-allowed-messages tunnel-management <yes|no>
set profiles gtp <name> gtp-log gtpu-allowed-messages path-management <yes|no>
set profiles gtp <name> gtp-log gtpu-allowed-messages g-pdu <yes|no>
set profiles gtp <name> gtp-log gtpu-allowed-messages packets-per-tunnel <1-10>
set profiles gtp <name> gtp-log gtp-5g-allowed-messages
set profiles gtp <name> gtp-log gtp-5g-allowed-messages N11 <yes|no>
set profiles gtp <name> gtp-log pfcp-allowed-messages
set profiles gtp <name> gtp-log pfcp-allowed-messages session-establishment <yes|no>
set profiles gtp <name> gtp-log pfcp-allowed-messages session-modification <yes|no>
set profiles gtp <name> gtp-log pfcp-allowed-messages session-deletion <yes|no>
set profiles gtp <name> gtp-log user-location <yes|no>
set profiles gtp <name> gtp-log packet-capture <yes|no>
set profiles sctp
set profiles sctp <name>
set profiles sctp <name> description <value>
set profiles sctp <name> sctp-inspection
set profiles sctp <name> sctp-inspection validity-checks
set profiles sctp <name> sctp-inspection validity-checks unknown-chunk <allow|alert|block>
set profiles sctp <name> sctp-inspection validity-checks chunk-flags <allow|alert|block>
set profiles sctp <name> sctp-inspection validity-checks invalid-length <allow|block>
set profiles sctp <name> sctp-inspection multihoming <1-8>
set profiles sctp <name> sctp-inspection log-setting
set profiles sctp <name> sctp-inspection log-setting sctp-start <yes|no>
set profiles sctp <name> sctp-inspection log-setting sctp-end <yes|no>
set profiles sctp <name> sctp-inspection log-setting init-chunks <yes|no>
set profiles sctp <name> sctp-inspection log-setting heartbeat-chunks <yes|no>
set profiles sctp <name> sctp-inspection log-setting termination-chunks <yes|no>
set profiles sctp <name> sctp-inspection log-setting all-control-chunks <yes|no>
set profiles sctp <name> sctp-inspection log-setting state-failure-events <yes|no>
set profiles sctp <name> sctp-filtering
set profiles sctp <name> sctp-filtering sctp-ppid
set profiles sctp <name> sctp-filtering sctp-ppid <name>
set profiles sctp <name> sctp-filtering sctp-ppid <name> ppid <value>
set profiles sctp <name> sctp-filtering sctp-ppid <name> action <allow|alert|block>
set profiles sctp <name> sctp-filtering sctp-ss7
set profiles sctp <name> sctp-filtering sctp-ss7 <name>
set profiles sctp <name> sctp-filtering sctp-ss7 <name> ss7-cp-ssn
set profiles sctp <name> sctp-filtering sctp-ss7 <name> ss7-cp-ssn <name>
set profiles sctp <name> sctp-filtering sctp-ss7 <name> ss7-cp-ssn <name> ss7-op-code [ <ss7-op-code1> <ss7-op-code2>... ]
set profiles sctp <name> sctp-filtering sctp-ss7 <name> ss7-cp-ssn <name> ss7-cp-gt [ <ss7-cp-gt1> <ss7-cp-gt2>... ]
set profiles sctp <name> sctp-filtering sctp-ss7 <name> action <allow|alert|block>
set profiles sctp <name> sctp-filtering sctp-diameter
set profiles sctp <name> sctp-filtering sctp-diameter <name>
set profiles sctp <name> sctp-filtering sctp-diameter <name> diameter-application-id
set profiles sctp <name> sctp-filtering sctp-diameter <name> diameter-application-id <name>
set profiles sctp <name> sctp-filtering sctp-diameter <name> diameter-application-id <name> diameter-cmd-code [ <diameter-cmd-code1> <diameter-cmd-code2>... ]
set profiles sctp <name> sctp-filtering sctp-diameter <name> diameter-application-id <name> diameter-avp [ <diameter-avp1> <diameter-avp2>... ]
set profiles sctp <name> sctp-filtering sctp-diameter <name> action <allow|alert|block>
set profile-group <name> gtp [ <gtp1> <gtp2>... ]
set profile-group <name> sctp [ <sctp1> <sctp2>... ]
set reports <name> type decryption group-by <serial|time_generated|src|dst|natsrc|natdst|rule|srcuser|dstuser|srcloc|dstloc|app|vsys|from|to|inbound_if|outbound_if|sport|dport|natsport|natdport|proto|action|tunnel|src_uuid|dst_uuid|rule_uuid|s_encrypted|category-of-app|subcategory-of-app|technology-of-app|container-of-app|risk-of-app|vsys_name|device_name|tls_version|tls_keyxchg|tls_enc|tls_auth|ec_curve|err_index|root_status|proxy_type|policy_name|cn|issuer_cn|root_cn|sni|error|cluster_name|src_dag|dst_dag|src_edl|dst_edl|container_id|pod_namespace|pod_name|src_category|src_profile|src_model|src_vendor|src_osfamily|src_osversion|src_host|src_mac|dst_category|dst_profile|dst_model|dst_vendor|dst_osfamily|dst_osversion|dst_host|dst_mac|day-of-receive_time|hour-of-receive_time|quarter-hour-of-receive_time>
set reports <name> type threat group-by <serial|time_generated|src|dst|natsrc|natdst|rule|srcuser|dstuser|srcloc|dstloc|app|vsys|from|to|inbound_if|outbound_if|sport|dport|natsport|natdport|proto|action|tunnel|src_uuid|dst_uuid|rule_uuid|s_encrypted|category-of-app|subcategory-of-app|technology-of-app|container-of-app|risk-of-app|vsys_name|device_name|parent_session_id|parent_start_time|parent_session_id_64|threatid|category|severity|direction|http_method|nssai_sst|filedigest|filetype|http2_connection|xff_ip|threat_name|src_edl|dst_edl|dynusergroup_name|hostid|partial_hash|cloud_reportid|cluster_name|flow_type|http2_connection_64|src_category|src_profile|src_model|src_vendor|src_osfamily|src_osversion|src_host|src_mac|dst_category|dst_profile|dst_model|dst_vendor|dst_osfamily|dst_osversion|dst_host|dst_mac|container_id|pod_namespace|pod_name|misc|src_dag|dst_dag|day-of-receive_time|hour-of-receive_time|quarter-hour-of-receive_time|pbf-s2c|pbf-c2s|flag-nat|flag-pcap|subtype|transaction|captive-portal|flag-proxy|non-std-dport|tunnelid|imsi|monitortag|imei|users|category-of-threatid|threat-type>
set reports <name> type url group-by <action|app|category|category-of-app|direction|dport|dst|dstuser|from|inbound_if|misc|http_headers|natdport|natdst|natsport|natsrc|outbound_if|proto|risk-of-app|rule|rule_uuid|severity|sport|src|srcuser|subcategory-of-app|technology-of-app|container-of-app|to|dstloc|srcloc|vsys|quarter-hour-of-receive_time|hour-of-receive_time|day-of-receive_time|contenttype|user_agent|device_name|vsys_name|url|tunnelid|monitortag|imsi|imei|parent_session_id|parent_start_time|http2_connection|tunnel|http_method|url_category_list|xff_ip|container_id|pod_namespace|pod_name|src_dag|dst_dag|src_edl|dst_edl|src_category|src_profile|src_model|src_vendor|src_osfamily|src_osversion|src_host|src_mac|dst_category|dst_profile|dst_model|dst_vendor|dst_osfamily|dst_osversion|dst_host|dst_mac|cloud_reportid>
set reports <name> type wildfire group-by <app|category|category-of-app|dport|dst|dstuser|from|inbound_if|misc|natdport|natdst|natsport|natsrc|outbound_if|proto|risk-of-app|rule|rule_uuid|sport|src|srcuser|subcategory-of-app|technology-of-app|container-of-app|to|dstloc|srcloc|vsys|quarter-hour-of-receive_time|hour-of-receive_time|day-of-receive_time|vsys_name|device_name|filetype|filename|filedigest|tunnelid|monitortag|imsi|imei|parent_session_id|parent_start_time|http2_connection|tunnel|xff_ip|src_dag|dst_dag|src_edl|dst_edl>
set reports <name> type data group-by <action|app|category-of-app|direction|dport|dst|dstuser|from|inbound_if|misc|natdport|natdst|natsport|natsrc|outbound_if|proto|risk-of-app|rule|rule_uuid|severity|sport|src|srcuser|subcategory-of-app|subtype|technology-of-app|container-of-app|threatid|to|dstloc|srcloc|vsys|quarter-hour-of-receive_time|hour-of-receive_time|day-of-receive_time|vsys_name|device_name|data-type|filename|tunnelid|monitortag|imsi|imei|parent_session_id|parent_start_time|http2_connection|tunnel|xff_ip|src_dag|dst_dag|src_edl|dst_edl|src_category|src_profile|src_model|src_vendor|src_osfamily|src_osversion|src_host|src_mac|dst_category|dst_profile|dst_model|dst_vendor|dst_osfamily|dst_osversion|dst_host|dst_mac>
set reports <name> type thsum group-by <serial|time_generated|vsys_name|device_name|app|src|dst|rule|threatid|srcuser|dstuser|srcloc|dstloc|xff_ip|vsys|from|to|dev_serial|dport|action|severity|inbound_if|outbound_if|category|category-of-app|subcategory-of-app|technology-of-app|container-of-app|risk-of-app|parent_session_id|parent_start_time|parent_session_id_64|tunnel|direction|assoc_id|ppid|http2_connection|rule_uuid|threat_name|src_edl|dst_edl|hostid|dynusergroup_name|nssai_sst|cluster_name|http2_connection_64|src_category|src_profile|src_model|src_vendor|src_osfamily|src_osversion|src_host|src_mac|dst_category|dst_profile|dst_model|dst_vendor|dst_osfamily|dst_osversion|dst_host|dst_mac|container_id|pod_namespace|pod_name|src_dag|dst_dag|day-of-receive_time|hour-of-receive_time|quarter-hour-of-receive_time|subtype|tunnelid|imsi|monitortag|imei|category-of-threatid|threat-type>
set reports <name> type traffic group-by <serial|time_generated|src|dst|natsrc|natdst|rule|srcuser|dstuser|srcloc|dstloc|app|vsys|from|to|inbound_if|outbound_if|sport|dport|natsport|natdport|proto|action|tunnel|src_uuid|dst_uuid|rule_uuid|s_encrypted|category-of-app|subcategory-of-app|technology-of-app|container-of-app|risk-of-app|vsys_name|device_name|parent_session_id|parent_start_time|parent_session_id_64|category|session_end_reason|action_source|nssai_sst|nssai_sd|http2_connection|xff_ip|dynusergroup_name|src_edl|dst_edl|hostid|session_owner|policy_id|offloaded|flow_type|cluster_name|http2_connection_64|src_category|src_profile|src_model|src_vendor|src_osfamily|src_osversion|src_host|src_mac|dst_category|dst_profile|dst_model|dst_vendor|dst_osfamily|dst_osversion|dst_host|dst_mac|container_id|pod_namespace|pod_name|src_dag|dst_dag|day-of-receive_time|hour-of-receive_time|quarter-hour-of-receive_time|pbf-s2c|pbf-c2s|decrypt-mirror|threat-type|flag-nat|flag-pcap|captive-portal|flag-proxy|non-std-dport|transaction|sym-return|sessionid|flag-decrypt-fwd|tunnelid|imsi|monitortag|imei>
set reports <name> type urlsum group-by <serial|time_generated|vsys_name|device_name|app|category|src|dst|rule|srcuser|dstuser|srcloc|dstloc|vsys|from|to|dev_serial|inbound_if|outbound_if|dport|action|tunnel|url_domain|user_agent|http_method|http2_connection|http2_connection_64|category-of-app|subcategory-of-app|technology-of-app|container-of-app|risk-of-app|parent_session_id|parent_start_time|parent_session_id_64|rule_uuid|xff_ip|src_edl|dst_edl|hostid|dynusergroup_name|nssai_sst|cluster_name|src_category|src_profile|src_model|src_vendor|src_osfamily|src_osversion|src_host|src_mac|dst_category|dst_profile|dst_model|dst_vendor|dst_osfamily|dst_osversion|dst_host|dst_mac|container_id|pod_namespace|pod_name|url_category_list|src_dag|dst_dag|day-of-receive_time|hour-of-receive_time|quarter-hour-of-receive_time|tunnelid|imsi|monitortag|imei>
set reports <name> type trsum group-by <serial|time_generated|vsys_name|device_name|app|src|dst|xff_ip|rule|srcuser|dstuser|srcloc|dstloc|category|vsys|from|to|dev_serial|dport|action|tunnel|inbound_if|outbound_if|category-of-app|subcategory-of-app|technology-of-app|container-of-app|risk-of-app|parent_session_id|parent_start_time|parent_session_id_64|assoc_id|http2_connection|rule_uuid|src_edl|dst_edl|dynusergroup_name|s_decrypted|s_encrypted|hostid|nssai_sst|cluster_name|flow_type|http2_connection_64|src_category|src_profile|src_model|src_vendor|src_osfamily|src_osversion|src_host|src_mac|dst_category|dst_profile|dst_model|dst_vendor|dst_osfamily|dst_osversion|dst_host|dst_mac|container_id|pod_namespace|pod_name|src_dag|dst_dag|day-of-receive_time|hour-of-receive_time|quarter-hour-of-receive_time|tunnelid|imsi|monitortag|imei|standard-ports-of-app>
set reports <name> type gtp
set reports <name> type gtp aggregate-by [ <aggregate-by1> <aggregate-by2>... ]
set reports <name> type gtp group-by <serial|time_generated|src|dst|natsrc|natdst|rule|srcuser|dstuser|srcloc|dstloc|app|vsys|from|to|inbound_if|outbound_if|sport|dport|natsport|natdport|proto|action|tunnel|src_uuid|dst_uuid|rule_uuid|s_encrypted|category-of-app|subcategory-of-app|technology-of-app|container-of-app|risk-of-app|vsys_name|device_name|parent_session_id|parent_start_time|parent_session_id_64|end_ip_addr|msisdn|nssai_sd|nssai_sst|pdu_session_id|apn|cause_code|mcc|mnc|cell_id|event_code|msg_type|area_code|session_end_reason|action_source|event_type|severity|rat|gtp_interface|remote_user_ip|remote_user_id|src_dag|dst_dag|src_edl|dst_edl|dynusergroup_name|cluster_name|container_id|pod_namespace|pod_name|day-of-receive_time|hour-of-receive_time|quarter-hour-of-receive_time|imei|imsi|sessionid>
set reports <name> type gtp values [ <values1> <values2>... ]
set reports <name> type gtp labels [ <labels1> <labels2>... ]
set reports <name> type gtp sortby <repeatcnt|nunique-of-users|severity>
set reports <name> type gtpsum
set reports <name> type gtpsum aggregate-by [ <aggregate-by1> <aggregate-by2>... ]
set reports <name> type gtpsum group-by <serial|time_generated|vsys_name|device_name|parent_session_id|parent_start_time|parent_session_id_64|app|src|dst|rule|srcloc|dstloc|vsys|dev_serial|msisdn|nssai_sd|nssai_sst|pdu_session_id|apn|cause_code|mcc|mnc|action|event_type|severity|rat|msg_type|tunnel|tunnel_insp_rule|remote_user_ip|remote_user_id|rule_uuid|src_edl|dst_edl|cluster_name|category-of-app|subcategory-of-app|technology-of-app|container-of-app|risk-of-app|container_id|pod_namespace|pod_name|src_dag|dst_dag|day-of-receive_time|hour-of-receive_time|quarter-hour-of-receive_time|imei|imsi>
set reports <name> type gtpsum values [ <values1> <values2>... ]
set reports <name> type gtpsum labels [ <labels1> <labels2>... ]
set reports <name> type gtpsum sortby <repeatcnt|severity>
set reports <name> type sctp
set reports <name> type sctp aggregate-by [ <aggregate-by1> <aggregate-by2>... ]
set reports <name> type sctp group-by <serial|time_generated|src|dst|natsrc|natdst|rule|srcuser|dstuser|srcloc|dstloc|app|vsys|from|to|inbound_if|outbound_if|sport|dport|natsport|natdport|proto|action|tunnel|src_uuid|dst_uuid|rule_uuid|s_encrypted|vsys_name|device_name|ppid|severity|sctp_chunk_type|sctp_event_type|sctp_event_code|verif_tag_1|verif_tag_2|sctp_cause_code|diam_app_id|diam_cmd_code|diam_avp_code|stream_id|op_code|sccp_calling_ssn|sccp_calling_gt|sctp_filter|assoc_end_reason|cluster_name|src_dag|dst_dag|src_edl|dst_edl|container_id|pod_namespace|pod_name|day-of-receive_time|hour-of-receive_time|quarter-hour-of-receive_time|sessionid|assoc_id>
set reports <name> type sctp values [ <values1> <values2>... ]
set reports <name> type sctp labels [ <labels1> <labels2>... ]
set reports <name> type sctp sortby <repeatcnt|chunks|chunks_sent|chunks_received|packets|pkts_sent|pkts_received|severity>
set reports <name> type sctpsum
set reports <name> type sctpsum aggregate-by [ <aggregate-by1> <aggregate-by2>... ]
set reports <name> type sctpsum group-by <serial|time_generated|vsys_name|device_name|src|dst|rule|srcloc|dstloc|action|vsys|dev_serial|assoc_id|ppid|severity|sctp_chunk_type|sctp_event_type|diam_app_id|diam_cmd_code|op_code|sccp_calling_ssn|sctp_filter|rule_uuid|src_edl|dst_edl|cluster_name|container_id|pod_namespace|pod_name|src_dag|dst_dag|day-of-receive_time|hour-of-receive_time|quarter-hour-of-receive_time|app>
set reports <name> type sctpsum values [ <values1> <values2>... ]
set reports <name> type sctpsum labels [ <labels1> <labels2>... ]
set reports <name> type sctpsum sortby <chunks|chunks_sent|chunks_received|packets|pkts_sent|pkts_received|repeatcnt|severity>
set external-list <name> type imsi
set external-list <name> type imsi exception-list [ <exception-list1> <exception-list2>... ]
set external-list <name> type imsi description <value>
set external-list <name> type imsi url <value>
set external-list <name> type imsi certificate-profile <value>|<None>
set external-list <name> type imsi auth
set external-list <name> type imsi auth username <value>
set external-list <name> type imsi auth password <value>
set external-list <name> type imsi recurring
set external-list <name> type imsi recurring five-minute
set external-list <name> type imsi recurring hourly
set external-list <name> type imsi recurring daily
set external-list <name> type imsi recurring daily at <value>
set external-list <name> type imsi recurring weekly
set external-list <name> type imsi recurring weekly day-of-week <sunday|monday|tuesday|wednesday|thursday|friday|saturday>
set external-list <name> type imsi recurring weekly at <value>
set external-list <name> type imsi recurring monthly
set external-list <name> type imsi recurring monthly day-of-month <1-31>
set external-list <name> type imsi recurring monthly at <value>
set external-list <name> type imei
set external-list <name> type imei exception-list [ <exception-list1> <exception-list2>... ]
set external-list <name> type imei description <value>
set external-list <name> type imei url <value>
set external-list <name> type imei certificate-profile <value>|<None>
set external-list <name> type imei auth
set external-list <name> type imei auth username <value>
set external-list <name> type imei auth password <value>
set external-list <name> type imei recurring
set external-list <name> type imei recurring five-minute
set external-list <name> type imei recurring hourly
set external-list <name> type imei recurring daily
set external-list <name> type imei recurring daily at <value>
set external-list <name> type imei recurring weekly
set external-list <name> type imei recurring weekly day-of-week <sunday|monday|tuesday|wednesday|thursday|friday|saturday>
set external-list <name> type imei recurring weekly at <value>
set external-list <name> type imei recurring monthly
set external-list <name> type imei recurring monthly day-of-month <1-31>
set external-list <name> type imei recurring monthly at <value>
set rulebase security rules <name> source-imsi [ <source-imsi1> <source-imsi2>... ]
set rulebase security rules <name> source-imei [ <source-imei1> <source-imei2>... ]
set rulebase security rules <name> source-nw-slice [ <source-nw-slice1> <source-nw-slice2>... ]
set rulebase security rules <name> profile-setting profiles gtp [ <gtp1> <gtp2>... ]
set rulebase security rules <name> profile-setting profiles sctp [ <sctp1> <sctp2>... ]
set rulebase default-security-rules rules <name> profile-setting profiles gtp [ <gtp1> <gtp2>... ]
set rulebase default-security-rules rules <name> profile-setting profiles sctp [ <sctp1> <sctp2>... ]