: Set Commands Introduced in PAN-OS 10.2
Focus
Focus

Set Commands Introduced in PAN-OS 10.2

Table of Contents

Set Commands Introduced in PAN-OS 10.2

Command line interface 'set' commands that are new in PAN-OS 10.2.
The following commands are new in the 10.2 release:
set deviceconfig setting ctd shared-memory-quota-url-cat <0-100> set deviceconfig setting inline-url-setting set deviceconfig setting inline-url-setting max-latency <1-240> set deviceconfig setting inline-url-setting allow-on-max-latency <yes|no> set deviceconfig setting inline-url-setting log-scan <yes|no> set deviceconfig setting inline-spyware-setting set deviceconfig setting inline-spyware-setting max-latency <1-240> set deviceconfig setting inline-spyware-setting allow-on-max-latency <yes|no> set deviceconfig setting inline-spyware-setting log-scan <yes|no> set deviceconfig setting ssl-decrypt zero-window-track <yes|no> set deviceconfig setting session erspan <yes|no> set deviceconfig setting config append-ending-token <yes|no> set deviceconfig setting management wildcard-topdown-match-mode <yes|no> set deviceconfig setting vpn ikev2 security-strength-check <yes|no> set deviceconfig setting iot edge enable-3rd-party <yes|no> set mgt-config password-complexity minimum-length <6-16> set mgt-config password-complexity minimum-length <0-16> set network profiles bfd-profile <name> min-tx-interval <100-10000> set network profiles bfd-profile <name> min-rx-interval <100-10000> set network profiles bfd-profile <name> detection-multiplier <2-255> set network ike crypto-profiles ipsec-crypto-profiles <name> dh-group <no-pfs|group1|group2|group5|group14|group15|group16|group19|group20|group21> set network tunnel gre <name> erspan <yes|no>
set network logical-router <name> vrf <name> admin-dists set network logical-router <name> vrf <name> admin-dists static <1-255> set network logical-router <name> vrf <name> admin-dists static-ipv6 <1-255> set network logical-router <name> vrf <name> admin-dists ospf-inter <1-255> set network logical-router <name> vrf <name> admin-dists ospf-intra <1-255> set network logical-router <name> vrf <name> admin-dists ospf-ext <1-255> set network logical-router <name> vrf <name> admin-dists ospfv3-inter <1-255> set network logical-router <name> vrf <name> admin-dists ospfv3-intra <1-255> set network logical-router <name> vrf <name> admin-dists ospfv3-ext <1-255> set network logical-router <name> vrf <name> admin-dists bgp-internal <1-255> set network logical-router <name> vrf <name> admin-dists bgp-external <1-255> set network logical-router <name> vrf <name> admin-dists bgp-local <1-255> set network logical-router <name> vrf <name> admin-dists rip <1-255> set network logical-router <name> vrf <name> rib-filter set network logical-router <name> vrf <name> rib-filter ipv4 set network logical-router <name> vrf <name> rib-filter ipv4 static set network logical-router <name> vrf <name> rib-filter ipv4 static route-map <value> set network logical-router <name> vrf <name> rib-filter ipv4 bgp set network logical-router <name> vrf <name> rib-filter ipv4 bgp route-map <value> set network logical-router <name> vrf <name> rib-filter ipv4 ospf set network logical-router <name> vrf <name> rib-filter ipv4 ospf route-map <value> set network logical-router <name> vrf <name> rib-filter ipv4 rip set network logical-router <name> vrf <name> rib-filter ipv4 rip route-map <value> set network logical-router <name> vrf <name> rib-filter ipv6 set network logical-router <name> vrf <name> rib-filter ipv6 static set network logical-router <name> vrf <name> rib-filter ipv6 static route-map <value> set network logical-router <name> vrf <name> rib-filter ipv6 bgp set network logical-router <name> vrf <name> rib-filter ipv6 bgp route-map <value> set network logical-router <name> vrf <name> rib-filter ipv6 ospfv3 set network logical-router <name> vrf <name> rib-filter ipv6 ospfv3 route-map <value> set network logical-router <name> vrf <name> bgp local-as <1-4294967295>|<value> set network logical-router <name> vrf <name> bgp install-route <yes|no> set network logical-router <name> vrf <name> bgp default-local-preference <0-4294967295> set network logical-router <name> vrf <name> bgp graceful-shutdown <yes|no> set network logical-router <name> vrf <name> bgp always-advertise-network-route <yes|no> set network logical-router <name> vrf <name> bgp graceful-restart local-restart-time <1-3600> set network logical-router <name> vrf <name> bgp global-bfd set network logical-router <name> vrf <name> bgp global-bfd profile <value>|<None> set network logical-router <name> vrf <name> bgp peer-group <name> address-family ipv4 <value> set network logical-router <name> vrf <name> bgp peer-group <name> address-family ipv6 <value> set network logical-router <name> vrf <name> bgp peer-group <name> filtering-profile set network logical-router <name> vrf <name> bgp peer-group <name> filtering-profile ipv4 <value> set network logical-router <name> vrf <name> bgp peer-group <name> filtering-profile ipv6 <value> set network logical-router <name> vrf <name> bgp peer-group <name> connection-options dampening <value> set network logical-router <name> vrf <name> bgp peer-group <name> peer <name> passive <yes|no> set network logical-router <name> vrf <name> bgp peer-group <name> peer <name> peer-as <1-4294967295>|<value> set network logical-router <name> vrf <name> bgp peer-group <name> peer <name> inherit set network logical-router <name> vrf <name> bgp peer-group <name> peer <name> inherit yes set network logical-router <name> vrf <name> bgp peer-group <name> peer <name> inherit no set network logical-router <name> vrf <name> bgp peer-group <name> peer <name> inherit no address-family set network logical-router <name> vrf <name> bgp peer-group <name> peer <name> inherit no address-family ipv4 <value>|<inherit|none> set network logical-router <name> vrf <name> bgp peer-group <name> peer <name> inherit no address-family ipv6 <value>|<inherit|none> set network logical-router <name> vrf <name> bgp peer-group <name> peer <name> inherit no filtering-profile set network logical-router <name> vrf <name> bgp peer-group <name> peer <name> inherit no filtering-profile ipv4 <value>|<inherit|none> set network logical-router <name> vrf <name> bgp peer-group <name> peer <name> inherit no filtering-profile ipv6 <value>|<inherit|none> set network logical-router <name> vrf <name> bgp peer-group <name> peer <name> peer-address fqdn <value> set network logical-router <name> vrf <name> bgp peer-group <name> peer <name> connection-options dampening <value>|<inherit> set network logical-router <name> vrf <name> bgp peer-group <name> peer <name> bfd set network logical-router <name> vrf <name> bgp peer-group <name> peer <name> bfd profile <value>|<None|Inherit-lr-global-setting> set network logical-router <name> vrf <name> bgp aggregate-routes set network logical-router <name> vrf <name> bgp aggregate-routes <name> set network logical-router <name> vrf <name> bgp aggregate-routes <name> description <value> set network logical-router <name> vrf <name> bgp aggregate-routes <name> enable <yes|no> set network logical-router <name> vrf <name> bgp aggregate-routes <name> summary-only <yes|no> set network logical-router <name> vrf <name> bgp aggregate-routes <name> as-set <yes|no> set network logical-router <name> vrf <name> bgp aggregate-routes <name> same-med <yes|no> set network logical-router <name> vrf <name> bgp aggregate-routes <name> type set network logical-router <name> vrf <name> bgp aggregate-routes <name> type ipv4 set network logical-router <name> vrf <name> bgp aggregate-routes <name> type ipv4 summary-prefix <ip/netmask>|<value> set network logical-router <name> vrf <name> bgp aggregate-routes <name> type ipv4 suppress-map <value> set network logical-router <name> vrf <name> bgp aggregate-routes <name> type ipv4 attribute-map <value> set network logical-router <name> vrf <name> bgp aggregate-routes <name> type ipv6 set network logical-router <name> vrf <name> bgp aggregate-routes <name> type ipv6 summary-prefix <ip/netmask>|<value> set network logical-router <name> vrf <name> bgp aggregate-routes <name> type ipv6 suppress-map <value> set network logical-router <name> vrf <name> bgp aggregate-routes <name> type ipv6 attribute-map <value> set network logical-router <name> vrf <name> bgp redistribution-profile set network logical-router <name> vrf <name> bgp redistribution-profile ipv4 set network logical-router <name> vrf <name> bgp redistribution-profile ipv4 unicast <value> set network logical-router <name> vrf <name> bgp redistribution-profile ipv6 set network logical-router <name> vrf <name> bgp redistribution-profile ipv6 unicast <value> set network logical-router <name> vrf <name> bgp advertise-network set network logical-router <name> vrf <name> bgp advertise-network ipv4 set network logical-router <name> vrf <name> bgp advertise-network ipv4 network set network logical-router <name> vrf <name> bgp advertise-network ipv4 network <name> set network logical-router <name> vrf <name> bgp advertise-network ipv4 network <name> unicast <yes|no> set network logical-router <name> vrf <name> bgp advertise-network ipv4 network <name> multicast <yes|no> set network logical-router <name> vrf <name> bgp advertise-network ipv4 network <name> backdoor <yes|no> set network logical-router <name> vrf <name> bgp advertise-network ipv6 set network logical-router <name> vrf <name> bgp advertise-network ipv6 network set network logical-router <name> vrf <name> bgp advertise-network ipv6 network <name> set network logical-router <name> vrf <name> bgp advertise-network ipv6 network <name> unicast <yes|no> set network logical-router <name> vrf <name> routing-table ip static-route <name> nexthop next-lr <value> set network logical-router <name> vrf <name> routing-table ip static-route <name> nexthop fqdn <value> set network logical-router <name> vrf <name> routing-table ip static-route <name> bfd set network logical-router <name> vrf <name> routing-table ip static-route <name> bfd profile <value>|<None> set network logical-router <name> vrf <name> routing-table ipv6 static-route <name> nexthop fqdn <value> set network logical-router <name> vrf <name> routing-table ipv6 static-route <name> nexthop next-lr <value> set network logical-router <name> vrf <name> routing-table ipv6 static-route <name> bfd set network logical-router <name> vrf <name> routing-table ipv6 static-route <name> bfd profile <value>|<None> set network logical-router <name> vrf <name> ospf set network logical-router <name> vrf <name> ospf router-id <ip/netmask> set network logical-router <name> vrf <name> ospf global-bfd set network logical-router <name> vrf <name> ospf global-bfd profile <value>|<None> set network logical-router <name> vrf <name> ospf enable <yes|no> set network logical-router <name> vrf <name> ospf rfc1583 <yes|no> set network logical-router <name> vrf <name> ospf spf-timer <value> set network logical-router <name> vrf <name> ospf global-if-timer <value> set network logical-router <name> vrf <name> ospf redistribution-profile <value> set network logical-router <name> vrf <name> ospf area set network logical-router <name> vrf <name> ospf area <name> set network logical-router <name> vrf <name> ospf area <name> authentication <value> set network logical-router <name> vrf <name> ospf area <name> type set network logical-router <name> vrf <name> ospf area <name> type normal set network logical-router <name> vrf <name> ospf area <name> type normal abr set network logical-router <name> vrf <name> ospf area <name> type normal abr import-list <value> set network logical-router <name> vrf <name> ospf area <name> type normal abr export-list <value> set network logical-router <name> vrf <name> ospf area <name> type normal abr inbound-filter-list <value> set network logical-router <name> vrf <name> ospf area <name> type normal abr outbound-filter-list <value> set network logical-router <name> vrf <name> ospf area <name> type stub set network logical-router <name> vrf <name> ospf area <name> type stub no-summary <yes|no> set network logical-router <name> vrf <name> ospf area <name> type stub abr set network logical-router <name> vrf <name> ospf area <name> type stub abr import-list <value>|<None> set network logical-router <name> vrf <name> ospf area <name> type stub abr export-list <value> set network logical-router <name> vrf <name> ospf area <name> type stub abr inbound-filter-list <value> set network logical-router <name> vrf <name> ospf area <name> type stub abr outbound-filter-list <value> set network logical-router <name> vrf <name> ospf area <name> type nssa set network logical-router <name> vrf <name> ospf area <name> type nssa no-summary <yes|no> set network logical-router <name> vrf <name> ospf area <name> type nssa default-information-originate set network logical-router <name> vrf <name> ospf area <name> type nssa default-information-originate metric <1-16777214> set network logical-router <name> vrf <name> ospf area <name> type nssa default-information-originate metric-type <type-1|type-2> set network logical-router <name> vrf <name> ospf area <name> type nssa abr set network logical-router <name> vrf <name> ospf area <name> type nssa abr import-list <value> set network logical-router <name> vrf <name> ospf area <name> type nssa abr export-list <value> set network logical-router <name> vrf <name> ospf area <name> type nssa abr inbound-filter-list <value> set network logical-router <name> vrf <name> ospf area <name> type nssa abr outbound-filter-list <value> set network logical-router <name> vrf <name> ospf area <name> type nssa abr nssa-ext-range set network logical-router <name> vrf <name> ospf area <name> type nssa abr nssa-ext-range <name> set network logical-router <name> vrf <name> ospf area <name> type nssa abr nssa-ext-range <name> advertise <yes|no> set network logical-router <name> vrf <name> ospf area <name> range set network logical-router <name> vrf <name> ospf area <name> range <name> set network logical-router <name> vrf <name> ospf area <name> range <name> substitute <ip/netmask> set network logical-router <name> vrf <name> ospf area <name> range <name> advertise <yes|no> set network logical-router <name> vrf <name> ospf area <name> interface set network logical-router <name> vrf <name> ospf area <name> interface <name> set network logical-router <name> vrf <name> ospf area <name> interface <name> enable <yes|no> set network logical-router <name> vrf <name> ospf area <name> interface <name> mtu-ignore <yes|no> set network logical-router <name> vrf <name> ospf area <name> interface <name> passive <yes|no> set network logical-router <name> vrf <name> ospf area <name> interface <name> priority <0-255> set network logical-router <name> vrf <name> ospf area <name> interface <name> link-type set network logical-router <name> vrf <name> ospf area <name> interface <name> link-type broadcast set network logical-router <name> vrf <name> ospf area <name> interface <name> link-type p2p set network logical-router <name> vrf <name> ospf area <name> interface <name> link-type p2mp set network logical-router <name> vrf <name> ospf area <name> interface <name> link-type p2mp neighbor set network logical-router <name> vrf <name> ospf area <name> interface <name> link-type p2mp neighbor <name> set network logical-router <name> vrf <name> ospf area <name> interface <name> link-type p2mp neighbor <name> priority <1-255> set network logical-router <name> vrf <name> ospf area <name> interface <name> metric <1-65535> set network logical-router <name> vrf <name> ospf area <name> interface <name> authentication <value> set network logical-router <name> vrf <name> ospf area <name> interface <name> bfd set network logical-router <name> vrf <name> ospf area <name> interface <name> bfd profile <value>|<None|Inherit-lr-global-setting> set network logical-router <name> vrf <name> ospf area <name> interface <name> timing <value> set network logical-router <name> vrf <name> ospf area <name> virtual-link set network logical-router <name> vrf <name> ospf area <name> virtual-link <name> set network logical-router <name> vrf <name> ospf area <name> virtual-link <name> neighbor-id <ip/netmask> set network logical-router <name> vrf <name> ospf area <name> virtual-link <name> transit-area-id <value> set network logical-router <name> vrf <name> ospf area <name> virtual-link <name> enable <yes|no> set network logical-router <name> vrf <name> ospf area <name> virtual-link <name> instance-id <0-255> set network logical-router <name> vrf <name> ospf area <name> virtual-link <name> timing <value> set network logical-router <name> vrf <name> ospf area <name> virtual-link <name> authentication <value> set network logical-router <name> vrf <name> ospf area <name> virtual-link <name> bfd set network logical-router <name> vrf <name> ospf area <name> virtual-link <name> bfd profile <value>|<None|Inherit-lr-global-setting> set network logical-router <name> vrf <name> ospf graceful-restart set network logical-router <name> vrf <name> ospf graceful-restart enable <yes|no> set network logical-router <name> vrf <name> ospf graceful-restart grace-period <5-1800> set network logical-router <name> vrf <name> ospf graceful-restart helper-enable <yes|no> set network logical-router <name> vrf <name> ospf graceful-restart strict-LSA-checking <yes|no> set network logical-router <name> vrf <name> ospf graceful-restart max-neighbor-restart-time <5-1800> set network logical-router <name> vrf <name> ospfv3 set network logical-router <name> vrf <name> ospfv3 enable <yes|no> set network logical-router <name> vrf <name> ospfv3 router-id <ip/netmask> set network logical-router <name> vrf <name> ospfv3 global-bfd set network logical-router <name> vrf <name> ospfv3 global-bfd profile <value>|<None> set network logical-router <name> vrf <name> ospfv3 disable-transit-traffic <yes|no> set network logical-router <name> vrf <name> ospfv3 spf-timer <value> set network logical-router <name> vrf <name> ospfv3 global-if-timer <value> set network logical-router <name> vrf <name> ospfv3 redistribution-profile <value> set network logical-router <name> vrf <name> ospfv3 area set network logical-router <name> vrf <name> ospfv3 area <name> set network logical-router <name> vrf <name> ospfv3 area <name> authentication <value> set network logical-router <name> vrf <name> ospfv3 area <name> type set network logical-router <name> vrf <name> ospfv3 area <name> type normal set network logical-router <name> vrf <name> ospfv3 area <name> type normal abr set network logical-router <name> vrf <name> ospfv3 area <name> type normal abr import-list <value> set network logical-router <name> vrf <name> ospfv3 area <name> type normal abr export-list <value> set network logical-router <name> vrf <name> ospfv3 area <name> type normal abr inbound-filter-list <value> set network logical-router <name> vrf <name> ospfv3 area <name> type normal abr outbound-filter-list <value> set network logical-router <name> vrf <name> ospfv3 area <name> type stub set network logical-router <name> vrf <name> ospfv3 area <name> type stub no-summary <yes|no> set network logical-router <name> vrf <name> ospfv3 area <name> type stub abr set network logical-router <name> vrf <name> ospfv3 area <name> type stub abr import-list <value> set network logical-router <name> vrf <name> ospfv3 area <name> type stub abr export-list <value> set network logical-router <name> vrf <name> ospfv3 area <name> type stub abr inbound-filter-list <value> set network logical-router <name> vrf <name> ospfv3 area <name> type stub abr outbound-filter-list <value> set network logical-router <name> vrf <name> ospfv3 area <name> type nssa set network logical-router <name> vrf <name> ospfv3 area <name> type nssa no-summary <yes|no> set network logical-router <name> vrf <name> ospfv3 area <name> type nssa default-information-originate set network logical-router <name> vrf <name> ospfv3 area <name> type nssa default-information-originate metric <1-16777214> set network logical-router <name> vrf <name> ospfv3 area <name> type nssa default-information-originate metric-type <type-1|type-2> set network logical-router <name> vrf <name> ospfv3 area <name> type nssa abr set network logical-router <name> vrf <name> ospfv3 area <name> type nssa abr import-list <value> set network logical-router <name> vrf <name> ospfv3 area <name> type nssa abr export-list <value> set network logical-router <name> vrf <name> ospfv3 area <name> type nssa abr inbound-filter-list <value> set network logical-router <name> vrf <name> ospfv3 area <name> type nssa abr outbound-filter-list <value> set network logical-router <name> vrf <name> ospfv3 area <name> type nssa abr nssa-ext-range set network logical-router <name> vrf <name> ospfv3 area <name> type nssa abr nssa-ext-range <name> set network logical-router <name> vrf <name> ospfv3 area <name> type nssa abr nssa-ext-range <name> advertise <yes|no> set network logical-router <name> vrf <name> ospfv3 area <name> range set network logical-router <name> vrf <name> ospfv3 area <name> range <name> set network logical-router <name> vrf <name> ospfv3 area <name> range <name> advertise <yes|no> set network logical-router <name> vrf <name> ospfv3 area <name> interface set network logical-router <name> vrf <name> ospfv3 area <name> interface <name> set network logical-router <name> vrf <name> ospfv3 area <name> interface <name> enable <yes|no> set network logical-router <name> vrf <name> ospfv3 area <name> interface <name> mtu-ignore <yes|no> set network logical-router <name> vrf <name> ospfv3 area <name> interface <name> passive <yes|no> set network logical-router <name> vrf <name> ospfv3 area <name> interface <name> priority <0-255> set network logical-router <name> vrf <name> ospfv3 area <name> interface <name> link-type set network logical-router <name> vrf <name> ospfv3 area <name> interface <name> link-type broadcast set network logical-router <name> vrf <name> ospfv3 area <name> interface <name> link-type p2p set network logical-router <name> vrf <name> ospfv3 area <name> interface <name> link-type p2mp set network logical-router <name> vrf <name> ospfv3 area <name> interface <name> link-type p2mp neighbor set network logical-router <name> vrf <name> ospfv3 area <name> interface <name> link-type p2mp neighbor <name> set network logical-router <name> vrf <name> ospfv3 area <name> interface <name> link-type p2mp neighbor <name> priority <1-255> set network logical-router <name> vrf <name> ospfv3 area <name> interface <name> metric <1-65535> set network logical-router <name> vrf <name> ospfv3 area <name> interface <name> instance-id <0-65535> set network logical-router <name> vrf <name> ospfv3 area <name> interface <name> authentication <value> set network logical-router <name> vrf <name> ospfv3 area <name> interface <name> bfd set network logical-router <name> vrf <name> ospfv3 area <name> interface <name> bfd profile <value>|<None|Inherit-lr-global-setting> set network logical-router <name> vrf <name> ospfv3 area <name> interface <name> timing <value> set network logical-router <name> vrf <name> ospfv3 area <name> virtual-link set network logical-router <name> vrf <name> ospfv3 area <name> virtual-link <name> set network logical-router <name> vrf <name> ospfv3 area <name> virtual-link <name> neighbor-id <ip/netmask> set network logical-router <name> vrf <name> ospfv3 area <name> virtual-link <name> transit-area-id <value> set network logical-router <name> vrf <name> ospfv3 area <name> virtual-link <name> enable <yes|no> set network logical-router <name> vrf <name> ospfv3 area <name> virtual-link <name> instance-id <0-65535> set network logical-router <name> vrf <name> ospfv3 area <name> virtual-link <name> timing <value> set network logical-router <name> vrf <name> ospfv3 area <name> virtual-link <name> authentication <value> set network logical-router <name> vrf <name> ospfv3 graceful-restart set network logical-router <name> vrf <name> ospfv3 graceful-restart enable <yes|no> set network logical-router <name> vrf <name> ospfv3 graceful-restart grace-period <5-1800> set network logical-router <name> vrf <name> ospfv3 graceful-restart helper-enable <yes|no> set network logical-router <name> vrf <name> ospfv3 graceful-restart strict-LSA-checking <yes|no> set network logical-router <name> vrf <name> ospfv3 graceful-restart max-neighbor-restart-time <5-1800> set network logical-router <name> vrf <name> multicast set network logical-router <name> vrf <name> multicast enable <yes|no> set network logical-router <name> vrf <name> multicast static-route set network logical-router <name> vrf <name> multicast static-route <name> set network logical-router <name> vrf <name> multicast static-route <name> destination <value>|<ip/netmask> set network logical-router <name> vrf <name> multicast static-route <name> interface <value> set network logical-router <name> vrf <name> multicast static-route <name> nexthop set network logical-router <name> vrf <name> multicast static-route <name> nexthop ip-address <value>|<ip/netmask> set network logical-router <name> vrf <name> multicast static-route <name> preference <1-255> set network logical-router <name> vrf <name> multicast pim set network logical-router <name> vrf <name> multicast pim enable <yes|no> set network logical-router <name> vrf <name> multicast pim rpf-lookup-mode <mrib-then-urib|mrib-only|urib-only> set network logical-router <name> vrf <name> multicast pim route-ageout-time <210-7200> set network logical-router <name> vrf <name> multicast pim if-timer-global <value> set network logical-router <name> vrf <name> multicast pim group-permission <value>|<None> set network logical-router <name> vrf <name> multicast pim ssm-address-space set network logical-router <name> vrf <name> multicast pim ssm-address-space group-list <value>|<None> set network logical-router <name> vrf <name> multicast pim spt-threshold set network logical-router <name> vrf <name> multicast pim spt-threshold <name> set network logical-router <name> vrf <name> multicast pim spt-threshold <name> threshold <1-4294967295>|<never|0> set network logical-router <name> vrf <name> multicast pim interface set network logical-router <name> vrf <name> multicast pim interface <name> set network logical-router <name> vrf <name> multicast pim interface <name> description <value> set network logical-router <name> vrf <name> multicast pim interface <name> dr-priority <0-4294967295> set network logical-router <name> vrf <name> multicast pim interface <name> send-bsm <yes|no> set network logical-router <name> vrf <name> multicast pim interface <name> if-timer <value> set network logical-router <name> vrf <name> multicast pim interface <name> neighbor-filter <value>|<None> set network logical-router <name> vrf <name> multicast pim rp set network logical-router <name> vrf <name> multicast pim rp local-rp set network logical-router <name> vrf <name> multicast pim rp local-rp static-rp set network logical-router <name> vrf <name> multicast pim rp local-rp static-rp interface <value> set network logical-router <name> vrf <name> multicast pim rp local-rp static-rp address <value> set network logical-router <name> vrf <name> multicast pim rp local-rp static-rp override <yes|no> set network logical-router <name> vrf <name> multicast pim rp local-rp static-rp group-list <value>|<None> set network logical-router <name> vrf <name> multicast pim rp local-rp candidate-rp set network logical-router <name> vrf <name> multicast pim rp local-rp candidate-rp interface <value> set network logical-router <name> vrf <name> multicast pim rp local-rp candidate-rp address <value> set network logical-router <name> vrf <name> multicast pim rp local-rp candidate-rp priority <0-255> set network logical-router <name> vrf <name> multicast pim rp local-rp candidate-rp advertisement-interval <1-26214> set network logical-router <name> vrf <name> multicast pim rp local-rp candidate-rp group-list <value>|<None> set network logical-router <name> vrf <name> multicast pim rp external-rp set network logical-router <name> vrf <name> multicast pim rp external-rp <name> set network logical-router <name> vrf <name> multicast pim rp external-rp <name> group-list <value>|<None> set network logical-router <name> vrf <name> multicast pim rp external-rp <name> override <yes|no> set network logical-router <name> vrf <name> multicast igmp set network logical-router <name> vrf <name> multicast igmp enable <yes|no> set network logical-router <name> vrf <name> multicast igmp dynamic set network logical-router <name> vrf <name> multicast igmp dynamic interface set network logical-router <name> vrf <name> multicast igmp dynamic interface <name> set network logical-router <name> vrf <name> multicast igmp dynamic interface <name> version <2|3> set network logical-router <name> vrf <name> multicast igmp dynamic interface <name> robustness <1|2|3|4|5|6|7> set network logical-router <name> vrf <name> multicast igmp dynamic interface <name> group-filter <value>|<None> set network logical-router <name> vrf <name> multicast igmp dynamic interface <name> max-groups <1-65535>|<unlimited> set network logical-router <name> vrf <name> multicast igmp dynamic interface <name> max-sources <1-65535>|<unlimited> set network logical-router <name> vrf <name> multicast igmp dynamic interface <name> query-profile <value> set network logical-router <name> vrf <name> multicast igmp dynamic interface <name> router-alert-policing <yes|no> set network logical-router <name> vrf <name> multicast igmp static set network logical-router <name> vrf <name> multicast igmp static <name> set network logical-router <name> vrf <name> multicast igmp static <name> interface <value> set network logical-router <name> vrf <name> multicast igmp static <name> group-address <ip/netmask> set network logical-router <name> vrf <name> multicast igmp static <name> source-address <ip/netmask> set network logical-router <name> vrf <name> rip set network logical-router <name> vrf <name> rip enable <yes|no> set network logical-router <name> vrf <name> rip default-information-originate <yes|no> set network logical-router <name> vrf <name> rip global-timer <value> set network logical-router <name> vrf <name> rip auth-profile <value> set network logical-router <name> vrf <name> rip redistribution-profile <value> set network logical-router <name> vrf <name> rip global-bfd set network logical-router <name> vrf <name> rip global-bfd profile <value>|<None> set network logical-router <name> vrf <name> rip global-inbound-distribute-list set network logical-router <name> vrf <name> rip global-inbound-distribute-list access-list <value> set network logical-router <name> vrf <name> rip global-outbound-distribute-list set network logical-router <name> vrf <name> rip global-outbound-distribute-list access-list <value> set network logical-router <name> vrf <name> rip interface set network logical-router <name> vrf <name> rip interface <name> set network logical-router <name> vrf <name> rip interface <name> enable <yes|no> set network logical-router <name> vrf <name> rip interface <name> mode <active|passive|send-only> set network logical-router <name> vrf <name> rip interface <name> split-horizon <split-horizon|no-split-horizon|no-split-horizon-with-poison-reverse> set network logical-router <name> vrf <name> rip interface <name> authentication <value> set network logical-router <name> vrf <name> rip interface <name> bfd set network logical-router <name> vrf <name> rip interface <name> bfd profile <value>|<None|Inherit-lr-global-setting> set network logical-router <name> vrf <name> rip interface <name> interface-inbound-distribute-list set network logical-router <name> vrf <name> rip interface <name> interface-inbound-distribute-list access-list <value> set network logical-router <name> vrf <name> rip interface <name> interface-inbound-distribute-list metric <1-16> set network logical-router <name> vrf <name> rip interface <name> interface-outbound-distribute-list set network logical-router <name> vrf <name> rip interface <name> interface-outbound-distribute-list access-list <value> set network logical-router <name> vrf <name> rip interface <name> interface-outbound-distribute-list metric <1-16> set network routing-profile bgp timer-profile <name> reconnect-retry-interval <1-3600> set network routing-profile bgp timer-profile <name> open-delay-time <0-240> set network routing-profile bgp address-family-profile <name> ipv4 unicast enable <yes|no> set network routing-profile bgp address-family-profile <name> ipv4 unicast soft-reconfig-with-stored-info <yes|no> set network routing-profile bgp address-family-profile <name> ipv4 unicast orf set network routing-profile bgp address-family-profile <name> ipv4 unicast orf orf-prefix-list <none|both|receive|send> set network routing-profile bgp address-family-profile <name> ipv4 unicast default-originate-map <value> set network routing-profile bgp address-family-profile <name> ipv4 multicast set network routing-profile bgp address-family-profile <name> ipv4 multicast enable <yes|no> set network routing-profile bgp address-family-profile <name> ipv4 multicast soft-reconfig-with-stored-info <yes|no> set network routing-profile bgp address-family-profile <name> ipv4 multicast add-path set network routing-profile bgp address-family-profile <name> ipv4 multicast add-path tx-all-paths <yes|no> set network routing-profile bgp address-family-profile <name> ipv4 multicast add-path tx-bestpath-per-AS <yes|no> set network routing-profile bgp address-family-profile <name> ipv4 multicast allowas-in set network routing-profile bgp address-family-profile <name> ipv4 multicast allowas-in origin set network routing-profile bgp address-family-profile <name> ipv4 multicast allowas-in occurrence <1-10> set network routing-profile bgp address-family-profile <name> ipv4 multicast as-override <yes|no> set network routing-profile bgp address-family-profile <name> ipv4 multicast default-originate <yes|no> set network routing-profile bgp address-family-profile <name> ipv4 multicast maximum-prefix set network routing-profile bgp address-family-profile <name> ipv4 multicast maximum-prefix num_prefixes <1-4294967295> set network routing-profile bgp address-family-profile <name> ipv4 multicast maximum-prefix threshold <1-100> set network routing-profile bgp address-family-profile <name> ipv4 multicast maximum-prefix action set network routing-profile bgp address-family-profile <name> ipv4 multicast maximum-prefix action warning-only set network routing-profile bgp address-family-profile <name> ipv4 multicast maximum-prefix action restart set network routing-profile bgp address-family-profile <name> ipv4 multicast maximum-prefix action restart interval <1-65535> set network routing-profile bgp address-family-profile <name> ipv4 multicast next-hop set network routing-profile bgp address-family-profile <name> ipv4 multicast next-hop self set network routing-profile bgp address-family-profile <name> ipv4 multicast next-hop self-force set network routing-profile bgp address-family-profile <name> ipv4 multicast remove-private-AS set network routing-profile bgp address-family-profile <name> ipv4 multicast remove-private-AS all set network routing-profile bgp address-family-profile <name> ipv4 multicast remove-private-AS replace-AS set network routing-profile bgp address-family-profile <name> ipv4 multicast route-reflector-client <yes|no> set network routing-profile bgp address-family-profile <name> ipv4 multicast send-community set network routing-profile bgp address-family-profile <name> ipv4 multicast send-community all set network routing-profile bgp address-family-profile <name> ipv4 multicast send-community both set network routing-profile bgp address-family-profile <name> ipv4 multicast send-community extended set network routing-profile bgp address-family-profile <name> ipv4 multicast send-community large set network routing-profile bgp address-family-profile <name> ipv4 multicast send-community standard set network routing-profile bgp address-family-profile <name> ipv4 multicast orf set network routing-profile bgp address-family-profile <name> ipv4 multicast orf orf-prefix-list <none|both|receive|send> set network routing-profile bgp address-family-profile <name> ipv4 multicast default-originate-map <value> set network routing-profile bgp address-family-profile <name> ipv6 unicast enable <yes|no> set network routing-profile bgp address-family-profile <name> ipv6 unicast soft-reconfig-with-stored-info <yes|no> set network routing-profile bgp address-family-profile <name> ipv6 unicast orf set network routing-profile bgp address-family-profile <name> ipv6 unicast orf orf-prefix-list <none|both|receive|send> set network routing-profile bgp address-family-profile <name> ipv6 unicast default-originate-map <value> set network routing-profile bgp redistribution-profile <name> ipv4 unicast static route-map <value> set network routing-profile bgp redistribution-profile <name> ipv4 unicast connected route-map <value> set network routing-profile bgp redistribution-profile <name> ipv4 unicast ospf set network routing-profile bgp redistribution-profile <name> ipv4 unicast ospf enable <yes|no> set network routing-profile bgp redistribution-profile <name> ipv4 unicast ospf metric <1-65535> set network routing-profile bgp redistribution-profile <name> ipv4 unicast ospf route-map <value> set network routing-profile bgp redistribution-profile <name> ipv4 unicast rip set network routing-profile bgp redistribution-profile <name> ipv4 unicast rip enable <yes|no> set network routing-profile bgp redistribution-profile <name> ipv4 unicast rip metric <1-65535> set network routing-profile bgp redistribution-profile <name> ipv4 unicast rip route-map <value> set network routing-profile bgp redistribution-profile <name> ipv6 unicast static route-map <value> set network routing-profile bgp redistribution-profile <name> ipv6 unicast connected route-map <value> set network routing-profile bgp redistribution-profile <name> ipv6 unicast ospfv3 set network routing-profile bgp redistribution-profile <name> ipv6 unicast ospfv3 enable <yes|no> set network routing-profile bgp redistribution-profile <name> ipv6 unicast ospfv3 metric <1-65535> set network routing-profile bgp redistribution-profile <name> ipv6 unicast ospfv3 route-map <value> set network routing-profile bgp filtering-profile set network routing-profile bgp filtering-profile <name> set network routing-profile bgp filtering-profile <name> description <value> set network routing-profile bgp filtering-profile <name> ipv4 set network routing-profile bgp filtering-profile <name> ipv4 unicast set network routing-profile bgp filtering-profile <name> ipv4 unicast filter-list set network routing-profile bgp filtering-profile <name> ipv4 unicast filter-list inbound <value> set network routing-profile bgp filtering-profile <name> ipv4 unicast filter-list outbound <value> set network routing-profile bgp filtering-profile <name> ipv4 unicast inbound-network-filters set network routing-profile bgp filtering-profile <name> ipv4 unicast inbound-network-filters distribute-list <value> set network routing-profile bgp filtering-profile <name> ipv4 unicast inbound-network-filters prefix-list <value> set network routing-profile bgp filtering-profile <name> ipv4 unicast outbound-network-filters set network routing-profile bgp filtering-profile <name> ipv4 unicast outbound-network-filters distribute-list <value> set network routing-profile bgp filtering-profile <name> ipv4 unicast outbound-network-filters prefix-list <value> set network routing-profile bgp filtering-profile <name> ipv4 unicast route-maps set network routing-profile bgp filtering-profile <name> ipv4 unicast route-maps inbound <value> set network routing-profile bgp filtering-profile <name> ipv4 unicast route-maps outbound <value> set network routing-profile bgp filtering-profile <name> ipv4 unicast conditional-advertisement set network routing-profile bgp filtering-profile <name> ipv4 unicast conditional-advertisement exist set network routing-profile bgp filtering-profile <name> ipv4 unicast conditional-advertisement exist advertise-map <value> set network routing-profile bgp filtering-profile <name> ipv4 unicast conditional-advertisement exist exist-map <value> set network routing-profile bgp filtering-profile <name> ipv4 unicast conditional-advertisement non-exist set network routing-profile bgp filtering-profile <name> ipv4 unicast conditional-advertisement non-exist advertise-map <value> set network routing-profile bgp filtering-profile <name> ipv4 unicast conditional-advertisement non-exist non-exist-map <value> set network routing-profile bgp filtering-profile <name> ipv4 unicast unsuppress-map <value> set network routing-profile bgp filtering-profile <name> ipv4 multicast set network routing-profile bgp filtering-profile <name> ipv4 multicast inherit <yes|no> set network routing-profile bgp filtering-profile <name> ipv4 multicast filter-list set network routing-profile bgp filtering-profile <name> ipv4 multicast filter-list inbound <value> set network routing-profile bgp filtering-profile <name> ipv4 multicast filter-list outbound <value> set network routing-profile bgp filtering-profile <name> ipv4 multicast inbound-network-filters set network routing-profile bgp filtering-profile <name> ipv4 multicast inbound-network-filters distribute-list <value> set network routing-profile bgp filtering-profile <name> ipv4 multicast inbound-network-filters prefix-list <value> set network routing-profile bgp filtering-profile <name> ipv4 multicast outbound-network-filters set network routing-profile bgp filtering-profile <name> ipv4 multicast outbound-network-filters distribute-list <value> set network routing-profile bgp filtering-profile <name> ipv4 multicast outbound-network-filters prefix-list <value> set network routing-profile bgp filtering-profile <name> ipv4 multicast route-maps set network routing-profile bgp filtering-profile <name> ipv4 multicast route-maps inbound <value> set network routing-profile bgp filtering-profile <name> ipv4 multicast route-maps outbound <value> set network routing-profile bgp filtering-profile <name> ipv4 multicast conditional-advertisement set network routing-profile bgp filtering-profile <name> ipv4 multicast conditional-advertisement exist set network routing-profile bgp filtering-profile <name> ipv4 multicast conditional-advertisement exist advertise-map <value> set network routing-profile bgp filtering-profile <name> ipv4 multicast conditional-advertisement exist exist-map <value> set network routing-profile bgp filtering-profile <name> ipv4 multicast conditional-advertisement non-exist set network routing-profile bgp filtering-profile <name> ipv4 multicast conditional-advertisement non-exist advertise-map <value> set network routing-profile bgp filtering-profile <name> ipv4 multicast conditional-advertisement non-exist non-exist-map <value> set network routing-profile bgp filtering-profile <name> ipv4 multicast unsuppress-map <value> set network routing-profile bgp filtering-profile <name> ipv6 set network routing-profile bgp filtering-profile <name> ipv6 unicast set network routing-profile bgp filtering-profile <name> ipv6 unicast filter-list set network routing-profile bgp filtering-profile <name> ipv6 unicast filter-list inbound <value> set network routing-profile bgp filtering-profile <name> ipv6 unicast filter-list outbound <value> set network routing-profile bgp filtering-profile <name> ipv6 unicast inbound-network-filters set network routing-profile bgp filtering-profile <name> ipv6 unicast inbound-network-filters distribute-list <value> set network routing-profile bgp filtering-profile <name> ipv6 unicast inbound-network-filters prefix-list <value> set network routing-profile bgp filtering-profile <name> ipv6 unicast outbound-network-filters set network routing-profile bgp filtering-profile <name> ipv6 unicast outbound-network-filters distribute-list <value> set network routing-profile bgp filtering-profile <name> ipv6 unicast outbound-network-filters prefix-list <value> set network routing-profile bgp filtering-profile <name> ipv6 unicast route-maps set network routing-profile bgp filtering-profile <name> ipv6 unicast route-maps inbound <value> set network routing-profile bgp filtering-profile <name> ipv6 unicast route-maps outbound <value> set network routing-profile bgp filtering-profile <name> ipv6 unicast conditional-advertisement set network routing-profile bgp filtering-profile <name> ipv6 unicast conditional-advertisement exist set network routing-profile bgp filtering-profile <name> ipv6 unicast conditional-advertisement exist advertise-map <value> set network routing-profile bgp filtering-profile <name> ipv6 unicast conditional-advertisement exist exist-map <value> set network routing-profile bgp filtering-profile <name> ipv6 unicast conditional-advertisement non-exist set network routing-profile bgp filtering-profile <name> ipv6 unicast conditional-advertisement non-exist advertise-map <value> set network routing-profile bgp filtering-profile <name> ipv6 unicast conditional-advertisement non-exist non-exist-map <value> set network routing-profile bgp filtering-profile <name> ipv6 unicast unsuppress-map <value> set network routing-profile bgp dampening-profile set network routing-profile bgp dampening-profile <name> set network routing-profile bgp dampening-profile <name> description <value> set network routing-profile bgp dampening-profile <name> half-life <1-45> set network routing-profile bgp dampening-profile <name> reuse-limit <1-20000> set network routing-profile bgp dampening-profile <name> suppress-limit <1-20000> set network routing-profile bgp dampening-profile <name> max-suppress-limit <1-255> set network routing-profile ospf set network routing-profile ospf auth-profile set network routing-profile ospf auth-profile <name> set network routing-profile ospf auth-profile <name> password <value> set network routing-profile ospf auth-profile <name> md5 set network routing-profile ospf auth-profile <name> md5 <name> set network routing-profile ospf auth-profile <name> md5 <name> key <value> set network routing-profile ospf auth-profile <name> md5 <name> preferred <yes|no> set network routing-profile ospf if-timer-profile set network routing-profile ospf if-timer-profile <name> set network routing-profile ospf if-timer-profile <name> hello-interval <1-3600> set network routing-profile ospf if-timer-profile <name> dead-counts <3-20> set network routing-profile ospf if-timer-profile <name> retransmit-interval <1-1800> set network routing-profile ospf if-timer-profile <name> transit-delay <1-1800> set network routing-profile ospf if-timer-profile <name> gr-delay <1-10> set network routing-profile ospf spf-timer-profile set network routing-profile ospf spf-timer-profile <name> set network routing-profile ospf spf-timer-profile <name> lsa-interval <1-10> set network routing-profile ospf spf-timer-profile <name> spf-calculation-delay <0-600> set network routing-profile ospf spf-timer-profile <name> initial-hold-time <0-600> set network routing-profile ospf spf-timer-profile <name> max-hold-time <0-600> set network routing-profile ospf redistribution-profile set network routing-profile ospf redistribution-profile <name> set network routing-profile ospf redistribution-profile <name> static set network routing-profile ospf redistribution-profile <name> static enable <yes|no> set network routing-profile ospf redistribution-profile <name> static metric <1-65535> set network routing-profile ospf redistribution-profile <name> static metric-type <type-1|type-2> set network routing-profile ospf redistribution-profile <name> static route-map <value> set network routing-profile ospf redistribution-profile <name> connected set network routing-profile ospf redistribution-profile <name> connected enable <yes|no> set network routing-profile ospf redistribution-profile <name> connected metric <1-65535> set network routing-profile ospf redistribution-profile <name> connected metric-type <type-1|type-2> set network routing-profile ospf redistribution-profile <name> connected route-map <value> set network routing-profile ospf redistribution-profile <name> bgp set network routing-profile ospf redistribution-profile <name> bgp enable <yes|no> set network routing-profile ospf redistribution-profile <name> bgp metric <0-4294967295> set network routing-profile ospf redistribution-profile <name> bgp metric-type <type-1|type-2> set network routing-profile ospf redistribution-profile <name> bgp route-map <value> set network routing-profile ospf redistribution-profile <name> default-route set network routing-profile ospf redistribution-profile <name> default-route always <yes|no> set network routing-profile ospf redistribution-profile <name> default-route enable <yes|no> set network routing-profile ospf redistribution-profile <name> default-route metric <0-4294967295> set network routing-profile ospf redistribution-profile <name> default-route metric-type <type-1|type-2> set network routing-profile ospf redistribution-profile <name> rip set network routing-profile ospf redistribution-profile <name> rip enable <yes|no> set network routing-profile ospf redistribution-profile <name> rip metric <0-4294967295> set network routing-profile ospf redistribution-profile <name> rip metric-type <type-1|type-2> set network routing-profile ospf redistribution-profile <name> rip route-map <value> set network routing-profile ospfv3 set network routing-profile ospfv3 auth-profile set network routing-profile ospfv3 auth-profile <name> set network routing-profile ospfv3 auth-profile <name> spi <value> set network routing-profile ospfv3 auth-profile <name> esp set network routing-profile ospfv3 auth-profile <name> esp authentication set network routing-profile ospfv3 auth-profile <name> esp authentication md5 set network routing-profile ospfv3 auth-profile <name> esp authentication md5 key <value> set network routing-profile ospfv3 auth-profile <name> esp authentication sha1 set network routing-profile ospfv3 auth-profile <name> esp authentication sha1 key <value> set network routing-profile ospfv3 auth-profile <name> esp authentication sha256 set network routing-profile ospfv3 auth-profile <name> esp authentication sha256 key <value> set network routing-profile ospfv3 auth-profile <name> esp authentication sha384 set network routing-profile ospfv3 auth-profile <name> esp authentication sha384 key <value> set network routing-profile ospfv3 auth-profile <name> esp authentication sha512 set network routing-profile ospfv3 auth-profile <name> esp authentication sha512 key <value> set network routing-profile ospfv3 auth-profile <name> esp authentication none set network routing-profile ospfv3 auth-profile <name> esp encryption set network routing-profile ospfv3 auth-profile <name> esp encryption algorithm <3des|aes-128-cbc|aes-192-cbc|aes-256-cbc|null> set network routing-profile ospfv3 auth-profile <name> esp encryption key <value> set network routing-profile ospfv3 auth-profile <name> ah set network routing-profile ospfv3 auth-profile <name> ah md5 set network routing-profile ospfv3 auth-profile <name> ah md5 key <value> set network routing-profile ospfv3 auth-profile <name> ah sha1 set network routing-profile ospfv3 auth-profile <name> ah sha1 key <value> set network routing-profile ospfv3 auth-profile <name> ah sha256 set network routing-profile ospfv3 auth-profile <name> ah sha256 key <value> set network routing-profile ospfv3 auth-profile <name> ah sha384 set network routing-profile ospfv3 auth-profile <name> ah sha384 key <value> set network routing-profile ospfv3 auth-profile <name> ah sha512 set network routing-profile ospfv3 auth-profile <name> ah sha512 key <value> set network routing-profile ospfv3 if-timer-profile set network routing-profile ospfv3 if-timer-profile <name> set network routing-profile ospfv3 if-timer-profile <name> hello-interval <1-3600> set network routing-profile ospfv3 if-timer-profile <name> dead-counts <3-20> set network routing-profile ospfv3 if-timer-profile <name> retransmit-interval <1-1800> set network routing-profile ospfv3 if-timer-profile <name> transit-delay <1-1800> set network routing-profile ospfv3 if-timer-profile <name> gr-delay <1-10> set network routing-profile ospfv3 spf-timer-profile set network routing-profile ospfv3 spf-timer-profile <name> set network routing-profile ospfv3 spf-timer-profile <name> lsa-interval <1-10> set network routing-profile ospfv3 spf-timer-profile <name> spf-calculation-delay <0-600> set network routing-profile ospfv3 spf-timer-profile <name> initial-hold-time <0-600> set network routing-profile ospfv3 spf-timer-profile <name> max-hold-time <0-600> set network routing-profile ospfv3 redistribution-profile set network routing-profile ospfv3 redistribution-profile <name> set network routing-profile ospfv3 redistribution-profile <name> static set network routing-profile ospfv3 redistribution-profile <name> static enable <yes|no> set network routing-profile ospfv3 redistribution-profile <name> static metric <1-65535> set network routing-profile ospfv3 redistribution-profile <name> static metric-type <type-1|type-2> set network routing-profile ospfv3 redistribution-profile <name> static route-map <value> set network routing-profile ospfv3 redistribution-profile <name> connected set network routing-profile ospfv3 redistribution-profile <name> connected enable <yes|no> set network routing-profile ospfv3 redistribution-profile <name> connected metric <1-65535> set network routing-profile ospfv3 redistribution-profile <name> connected metric-type <type-1|type-2> set network routing-profile ospfv3 redistribution-profile <name> connected route-map <value> set network routing-profile ospfv3 redistribution-profile <name> bgp set network routing-profile ospfv3 redistribution-profile <name> bgp enable <yes|no> set network routing-profile ospfv3 redistribution-profile <name> bgp metric <0-4294967295> set network routing-profile ospfv3 redistribution-profile <name> bgp metric-type <type-1|type-2> set network routing-profile ospfv3 redistribution-profile <name> bgp route-map <value> set network routing-profile ospfv3 redistribution-profile <name> default-route set network routing-profile ospfv3 redistribution-profile <name> default-route always <yes|no> set network routing-profile ospfv3 redistribution-profile <name> default-route enable <yes|no> set network routing-profile ospfv3 redistribution-profile <name> default-route metric <0-4294967295> set network routing-profile ospfv3 redistribution-profile <name> default-route metric-type <type-1|type-2> set network routing-profile filters set network routing-profile filters access-list set network routing-profile filters access-list <name> set network routing-profile filters access-list <name> description <value> set network routing-profile filters access-list <name> type set network routing-profile filters access-list <name> type ipv4 set network routing-profile filters access-list <name> type ipv4 ipv4-entry set network routing-profile filters access-list <name> type ipv4 ipv4-entry <name> set network routing-profile filters access-list <name> type ipv4 ipv4-entry <name> action <deny|permit> set network routing-profile filters access-list <name> type ipv4 ipv4-entry <name> source-address set network routing-profile filters access-list <name> type ipv4 ipv4-entry <name> source-address address <any> set network routing-profile filters access-list <name> type ipv4 ipv4-entry <name> source-address entry set network routing-profile filters access-list <name> type ipv4 ipv4-entry <name> source-address entry address <ip/netmask>|<validate>|<value> set network routing-profile filters access-list <name> type ipv4 ipv4-entry <name> source-address entry wildcard <ip/netmask>|<validate>|<value> set network routing-profile filters access-list <name> type ipv4 ipv4-entry <name> destination-address set network routing-profile filters access-list <name> type ipv4 ipv4-entry <name> destination-address address <any> set network routing-profile filters access-list <name> type ipv4 ipv4-entry <name> destination-address entry set network routing-profile filters access-list <name> type ipv4 ipv4-entry <name> destination-address entry address <ip/netmask>|<validate>|<value> set network routing-profile filters access-list <name> type ipv4 ipv4-entry <name> destination-address entry wildcard <ip/netmask>|<validate>|<value> set network routing-profile filters access-list <name> type ipv6 set network routing-profile filters access-list <name> type ipv6 ipv6-entry set network routing-profile filters access-list <name> type ipv6 ipv6-entry <name> set network routing-profile filters access-list <name> type ipv6 ipv6-entry <name> action <deny|permit> set network routing-profile filters access-list <name> type ipv6 ipv6-entry <name> source-address set network routing-profile filters access-list <name> type ipv6 ipv6-entry <name> source-address address <any> set network routing-profile filters access-list <name> type ipv6 ipv6-entry <name> source-address entry set network routing-profile filters access-list <name> type ipv6 ipv6-entry <name> source-address entry address <ip/netmask>|<value> set network routing-profile filters access-list <name> type ipv6 ipv6-entry <name> source-address entry exact-match <yes|no> set network routing-profile filters prefix-list set network routing-profile filters prefix-list <name> set network routing-profile filters prefix-list <name> description <value> set network routing-profile filters prefix-list <name> type set network routing-profile filters prefix-list <name> type ipv4 set network routing-profile filters prefix-list <name> type ipv4 ipv4-entry set network routing-profile filters prefix-list <name> type ipv4 ipv4-entry <name> set network routing-profile filters prefix-list <name> type ipv4 ipv4-entry <name> action <deny|permit> set network routing-profile filters prefix-list <name> type ipv4 ipv4-entry <name> prefix set network routing-profile filters prefix-list <name> type ipv4 ipv4-entry <name> prefix network <any> set network routing-profile filters prefix-list <name> type ipv4 ipv4-entry <name> prefix entry set network routing-profile filters prefix-list <name> type ipv4 ipv4-entry <name> prefix entry network <ip/netmask>|<value> set network routing-profile filters prefix-list <name> type ipv4 ipv4-entry <name> prefix entry greater-than-or-equal <0-32> set network routing-profile filters prefix-list <name> type ipv4 ipv4-entry <name> prefix entry less-than-or-equal <0-32> set network routing-profile filters prefix-list <name> type ipv6 set network routing-profile filters prefix-list <name> type ipv6 ipv6-entry set network routing-profile filters prefix-list <name> type ipv6 ipv6-entry <name> set network routing-profile filters prefix-list <name> type ipv6 ipv6-entry <name> action <deny|permit> set network routing-profile filters prefix-list <name> type ipv6 ipv6-entry <name> prefix set network routing-profile filters prefix-list <name> type ipv6 ipv6-entry <name> prefix network <any> set network routing-profile filters prefix-list <name> type ipv6 ipv6-entry <name> prefix entry set network routing-profile filters prefix-list <name> type ipv6 ipv6-entry <name> prefix entry network <ip/netmask>|<value> set network routing-profile filters prefix-list <name> type ipv6 ipv6-entry <name> prefix entry greater-than-or-equal <0-128> set network routing-profile filters prefix-list <name> type ipv6 ipv6-entry <name> prefix entry less-than-or-equal <0-128> set network routing-profile filters as-path-access-list set network routing-profile filters as-path-access-list <name> set network routing-profile filters as-path-access-list <name> description <value> set network routing-profile filters as-path-access-list <name> aspath-entry set network routing-profile filters as-path-access-list <name> aspath-entry <name> set network routing-profile filters as-path-access-list <name> aspath-entry <name> action <deny|permit> set network routing-profile filters as-path-access-list <name> aspath-entry <name> aspath-regex <value> set network routing-profile filters community-list set network routing-profile filters community-list <name> set network routing-profile filters community-list <name> description <value> set network routing-profile filters community-list <name> type set network routing-profile filters community-list <name> type regular set network routing-profile filters community-list <name> type regular regular-entry set network routing-profile filters community-list <name> type regular regular-entry <name> set network routing-profile filters community-list <name> type regular regular-entry <name> action <deny|permit> set network routing-profile filters community-list <name> type regular regular-entry <name> community [ <community1> <community2>... ] set network routing-profile filters community-list <name> type large set network routing-profile filters community-list <name> type large large-entry set network routing-profile filters community-list <name> type large large-entry <name> set network routing-profile filters community-list <name> type large large-entry <name> action <deny|permit> set network routing-profile filters community-list <name> type large large-entry <name> lc-regex [ <lc-regex1> <lc-regex2>... ] set network routing-profile filters community-list <name> type extended set network routing-profile filters community-list <name> type extended extended-entry set network routing-profile filters community-list <name> type extended extended-entry <name> set network routing-profile filters community-list <name> type extended extended-entry <name> action <deny|permit> set network routing-profile filters community-list <name> type extended extended-entry <name> ec-regex [ <ec-regex1> <ec-regex2>... ] set network routing-profile filters route-maps set network routing-profile filters route-maps bgp set network routing-profile filters route-maps bgp bgp-entry set network routing-profile filters route-maps bgp bgp-entry <name> set network routing-profile filters route-maps bgp bgp-entry <name> description <value> set network routing-profile filters route-maps bgp bgp-entry <name> route-map set network routing-profile filters route-maps bgp bgp-entry <name> route-map <name> set network routing-profile filters route-maps bgp bgp-entry <name> route-map <name> action <deny|permit> set network routing-profile filters route-maps bgp bgp-entry <name> route-map <name> description <value> set network routing-profile filters route-maps bgp bgp-entry <name> route-map <name> match set network routing-profile filters route-maps bgp bgp-entry <name> route-map <name> match as-path-access-list <value> set network routing-profile filters route-maps bgp bgp-entry <name> route-map <name> match regular-community <value> set network routing-profile filters route-maps bgp bgp-entry <name> route-map <name> match large-community <value> set network routing-profile filters route-maps bgp bgp-entry <name> route-map <name> match extended-community <value> set network routing-profile filters route-maps bgp bgp-entry <name> route-map <name> match interface <value> set network routing-profile filters route-maps bgp bgp-entry <name> route-map <name> match origin <none|egp|igp|incomplete> set network routing-profile filters route-maps bgp bgp-entry <name> route-map <name> match metric <0-4294967295> set network routing-profile filters route-maps bgp bgp-entry <name> route-map <name> match tag <1-4294967295> set network routing-profile filters route-maps bgp bgp-entry <name> route-map <name> match local-preference <0-4294967295> set network routing-profile filters route-maps bgp bgp-entry <name> route-map <name> match peer <value>|<none|local> set network routing-profile filters route-maps bgp bgp-entry <name> route-map <name> match ipv4 set network routing-profile filters route-maps bgp bgp-entry <name> route-map <name> match ipv4 address set network routing-profile filters route-maps bgp bgp-entry <name> route-map <name> match ipv4 address access-list <value> set network routing-profile filters route-maps bgp bgp-entry <name> route-map <name> match ipv4 address prefix-list <value> set network routing-profile filters route-maps bgp bgp-entry <name> route-map <name> match ipv4 next-hop set network routing-profile filters route-maps bgp bgp-entry <name> route-map <name> match ipv4 next-hop access-list <value> set network routing-profile filters route-maps bgp bgp-entry <name> route-map <name> match ipv4 next-hop prefix-list <value> set network routing-profile filters route-maps bgp bgp-entry <name> route-map <name> match ipv4 route-source set network routing-profile filters route-maps bgp bgp-entry <name> route-map <name> match ipv4 route-source access-list <value> set network routing-profile filters route-maps bgp bgp-entry <name> route-map <name> match ipv4 route-source prefix-list <value> set network routing-profile filters route-maps bgp bgp-entry <name> route-map <name> match ipv6 set network routing-profile filters route-maps bgp bgp-entry <name> route-map <name> match ipv6 address set network routing-profile filters route-maps bgp bgp-entry <name> route-map <name> match ipv6 address access-list <value> set network routing-profile filters route-maps bgp bgp-entry <name> route-map <name> match ipv6 address prefix-list <value> set network routing-profile filters route-maps bgp bgp-entry <name> route-map <name> match ipv6 next-hop set network routing-profile filters route-maps bgp bgp-entry <name> route-map <name> match ipv6 next-hop access-list <value> set network routing-profile filters route-maps bgp bgp-entry <name> route-map <name> match ipv6 next-hop prefix-list <value> set network routing-profile filters route-maps bgp bgp-entry <name> route-map <name> set set network routing-profile filters route-maps bgp bgp-entry <name> route-map <name> set aggregator set network routing-profile filters route-maps bgp bgp-entry <name> route-map <name> set aggregator as <1-4294967295> set network routing-profile filters route-maps bgp bgp-entry <name> route-map <name> set aggregator router-id <ip/netmask> set network routing-profile filters route-maps bgp bgp-entry <name> route-map <name> set tag <1-4294967295> set network routing-profile filters route-maps bgp bgp-entry <name> route-map <name> set local-preference <0-4294967295> set network routing-profile filters route-maps bgp bgp-entry <name> route-map <name> set weight <0-4294967295> set network routing-profile filters route-maps bgp bgp-entry <name> route-map <name> set origin <none|egp|igp|incomplete> set network routing-profile filters route-maps bgp bgp-entry <name> route-map <name> set atomic-aggregate <yes|no> set network routing-profile filters route-maps bgp bgp-entry <name> route-map <name> set metric set network routing-profile filters route-maps bgp bgp-entry <name> route-map <name> set metric value <0-4294967295> set network routing-profile filters route-maps bgp bgp-entry <name> route-map <name> set metric action <set|add|subtract> set network routing-profile filters route-maps bgp bgp-entry <name> route-map <name> set originator-id <ip/netmask> set network routing-profile filters route-maps bgp bgp-entry <name> route-map <name> set aspath-prepend [ <aspath-prepend1> <aspath-prepend2>... ] set network routing-profile filters route-maps bgp bgp-entry <name> route-map <name> set regular-community [ <regular-community1> <regular-community2>... ] set network routing-profile filters route-maps bgp bgp-entry <name> route-map <name> set large-community [ <large-community1> <large-community2>... ] set network routing-profile filters route-maps bgp bgp-entry <name> route-map <name> set ipv4 set network routing-profile filters route-maps bgp bgp-entry <name> route-map <name> set ipv4 source-address <value> set network routing-profile filters route-maps bgp bgp-entry <name> route-map <name> set ipv4 next-hop <ip/netmask>|<validate>|<none|unchanged|peer-address> set network routing-profile filters route-maps bgp bgp-entry <name> route-map <name> set ipv6 set network routing-profile filters route-maps bgp bgp-entry <name> route-map <name> set ipv6 source-address <value> set network routing-profile filters route-maps bgp bgp-entry <name> route-map <name> set ipv6 next-hop <ip/netmask>|<validate>|<none|peer-address> set network routing-profile filters route-maps bgp bgp-entry <name> route-map <name> set ipv6-nexthop-prefer-global <yes|no> set network routing-profile filters route-maps bgp bgp-entry <name> route-map <name> set aspath-exclude [ <aspath-exclude1> <aspath-exclude2>... ] set network routing-profile filters route-maps bgp bgp-entry <name> route-map <name> set overwrite-regular-community <yes|no> set network routing-profile filters route-maps bgp bgp-entry <name> route-map <name> set overwrite-large-community <yes|no> set network routing-profile filters route-maps bgp bgp-entry <name> route-map <name> set remove-regular-community <value> set network routing-profile filters route-maps bgp bgp-entry <name> route-map <name> set remove-large-community <value> set network routing-profile filters route-maps redistribution set network routing-profile filters route-maps redistribution redist-entry set network routing-profile filters route-maps redistribution redist-entry <name> set network routing-profile filters route-maps redistribution redist-entry <name> description <value> set network routing-profile filters route-maps redistribution redist-entry <name> bgp set network routing-profile filters route-maps redistribution redist-entry <name> bgp ospf set network routing-profile filters route-maps redistribution redist-entry <name> bgp ospf route-map set network routing-profile filters route-maps redistribution redist-entry <name> bgp ospf route-map <name> set network routing-profile filters route-maps redistribution redist-entry <name> bgp ospf route-map <name> action <deny|permit> set network routing-profile filters route-maps redistribution redist-entry <name> bgp ospf route-map <name> description <value> set network routing-profile filters route-maps redistribution redist-entry <name> bgp ospf route-map <name> match set network routing-profile filters route-maps redistribution redist-entry <name> bgp ospf route-map <name> match as-path-access-list <value> set network routing-profile filters route-maps redistribution redist-entry <name> bgp ospf route-map <name> match regular-community <value> set network routing-profile filters route-maps redistribution redist-entry <name> bgp ospf route-map <name> match large-community <value> set network routing-profile filters route-maps redistribution redist-entry <name> bgp ospf route-map <name> match extended-community <value> set network routing-profile filters route-maps redistribution redist-entry <name> bgp ospf route-map <name> match interface <value> set network routing-profile filters route-maps redistribution redist-entry <name> bgp ospf route-map <name> match origin <none|egp|igp|incomplete> set network routing-profile filters route-maps redistribution redist-entry <name> bgp ospf route-map <name> match metric <0-4294967295> set network routing-profile filters route-maps redistribution redist-entry <name> bgp ospf route-map <name> match tag <1-4294967295> set network routing-profile filters route-maps redistribution redist-entry <name> bgp ospf route-map <name> match local-preference <0-4294967295> set network routing-profile filters route-maps redistribution redist-entry <name> bgp ospf route-map <name> match peer <value>|<none|local> set network routing-profile filters route-maps redistribution redist-entry <name> bgp ospf route-map <name> match ipv4 set network routing-profile filters route-maps redistribution redist-entry <name> bgp ospf route-map <name> match ipv4 address set network routing-profile filters route-maps redistribution redist-entry <name> bgp ospf route-map <name> match ipv4 address access-list <value> set network routing-profile filters route-maps redistribution redist-entry <name> bgp ospf route-map <name> match ipv4 address prefix-list <value> set network routing-profile filters route-maps redistribution redist-entry <name> bgp ospf route-map <name> match ipv4 next-hop set network routing-profile filters route-maps redistribution redist-entry <name> bgp ospf route-map <name> match ipv4 next-hop access-list <value> set network routing-profile filters route-maps redistribution redist-entry <name> bgp ospf route-map <name> match ipv4 next-hop prefix-list <value> set network routing-profile filters route-maps redistribution redist-entry <name> bgp ospf route-map <name> match ipv4 route-source set network routing-profile filters route-maps redistribution redist-entry <name> bgp ospf route-map <name> match ipv4 route-source access-list <value> set network routing-profile filters route-maps redistribution redist-entry <name> bgp ospf route-map <name> match ipv4 route-source prefix-list <value> set network routing-profile filters route-maps redistribution redist-entry <name> bgp ospf route-map <name> set set network routing-profile filters route-maps redistribution redist-entry <name> bgp ospf route-map <name> set metric set network routing-profile filters route-maps redistribution redist-entry <name> bgp ospf route-map <name> set metric value <0-4294967295> set network routing-profile filters route-maps redistribution redist-entry <name> bgp ospf route-map <name> set metric action <set|add|subtract> set network routing-profile filters route-maps redistribution redist-entry <name> bgp ospf route-map <name> set metric-type <type-1|type-2> set network routing-profile filters route-maps redistribution redist-entry <name> bgp ospf route-map <name> set tag <1-4294967295> set network routing-profile filters route-maps redistribution redist-entry <name> bgp ospfv3 set network routing-profile filters route-maps redistribution redist-entry <name> bgp ospfv3 route-map set network routing-profile filters route-maps redistribution redist-entry <name> bgp ospfv3 route-map <name> set network routing-profile filters route-maps redistribution redist-entry <name> bgp ospfv3 route-map <name> action <deny|permit> set network routing-profile filters route-maps redistribution redist-entry <name> bgp ospfv3 route-map <name> description <value> set network routing-profile filters route-maps redistribution redist-entry <name> bgp ospfv3 route-map <name> match set network routing-profile filters route-maps redistribution redist-entry <name> bgp ospfv3 route-map <name> match as-path-access-list <value> set network routing-profile filters route-maps redistribution redist-entry <name> bgp ospfv3 route-map <name> match regular-community <value> set network routing-profile filters route-maps redistribution redist-entry <name> bgp ospfv3 route-map <name> match large-community <value> set network routing-profile filters route-maps redistribution redist-entry <name> bgp ospfv3 route-map <name> match extended-community <value> set network routing-profile filters route-maps redistribution redist-entry <name> bgp ospfv3 route-map <name> match interface <value> set network routing-profile filters route-maps redistribution redist-entry <name> bgp ospfv3 route-map <name> match origin <none|egp|igp|incomplete> set network routing-profile filters route-maps redistribution redist-entry <name> bgp ospfv3 route-map <name> match metric <0-4294967295> set network routing-profile filters route-maps redistribution redist-entry <name> bgp ospfv3 route-map <name> match tag <1-4294967295> set network routing-profile filters route-maps redistribution redist-entry <name> bgp ospfv3 route-map <name> match local-preference <0-4294967295> set network routing-profile filters route-maps redistribution redist-entry <name> bgp ospfv3 route-map <name> match peer <value>|<none|local> set network routing-profile filters route-maps redistribution redist-entry <name> bgp ospfv3 route-map <name> match ipv6 set network routing-profile filters route-maps redistribution redist-entry <name> bgp ospfv3 route-map <name> match ipv6 address set network routing-profile filters route-maps redistribution redist-entry <name> bgp ospfv3 route-map <name> match ipv6 address access-list <value> set network routing-profile filters route-maps redistribution redist-entry <name> bgp ospfv3 route-map <name> match ipv6 address prefix-list <value> set network routing-profile filters route-maps redistribution redist-entry <name> bgp ospfv3 route-map <name> match ipv6 next-hop set network routing-profile filters route-maps redistribution redist-entry <name> bgp ospfv3 route-map <name> match ipv6 next-hop access-list <value> set network routing-profile filters route-maps redistribution redist-entry <name> bgp ospfv3 route-map <name> match ipv6 next-hop prefix-list <value> set network routing-profile filters route-maps redistribution redist-entry <name> bgp ospfv3 route-map <name> set set network routing-profile filters route-maps redistribution redist-entry <name> bgp ospfv3 route-map <name> set metric set network routing-profile filters route-maps redistribution redist-entry <name> bgp ospfv3 route-map <name> set metric value <0-4294967295> set network routing-profile filters route-maps redistribution redist-entry <name> bgp ospfv3 route-map <name> set metric action <set|add|subtract> set network routing-profile filters route-maps redistribution redist-entry <name> bgp ospfv3 route-map <name> set metric-type <type-1|type-2> set network routing-profile filters route-maps redistribution redist-entry <name> bgp ospfv3 route-map <name> set tag <1-4294967295> set network routing-profile filters route-maps redistribution redist-entry <name> bgp rip set network routing-profile filters route-maps redistribution redist-entry <name> bgp rip route-map set network routing-profile filters route-maps redistribution redist-entry <name> bgp rip route-map <name> set network routing-profile filters route-maps redistribution redist-entry <name> bgp rip route-map <name> action <deny|permit> set network routing-profile filters route-maps redistribution redist-entry <name> bgp rip route-map <name> description <value> set network routing-profile filters route-maps redistribution redist-entry <name> bgp rip route-map <name> match set network routing-profile filters route-maps redistribution redist-entry <name> bgp rip route-map <name> match as-path-access-list <value> set network routing-profile filters route-maps redistribution redist-entry <name> bgp rip route-map <name> match regular-community <value> set network routing-profile filters route-maps redistribution redist-entry <name> bgp rip route-map <name> match large-community <value> set network routing-profile filters route-maps redistribution redist-entry <name> bgp rip route-map <name> match extended-community <value> set network routing-profile filters route-maps redistribution redist-entry <name> bgp rip route-map <name> match interface <value> set network routing-profile filters route-maps redistribution redist-entry <name> bgp rip route-map <name> match origin <none|egp|igp|incomplete> set network routing-profile filters route-maps redistribution redist-entry <name> bgp rip route-map <name> match metric <0-4294967295> set network routing-profile filters route-maps redistribution redist-entry <name> bgp rip route-map <name> match tag <1-4294967295> set network routing-profile filters route-maps redistribution redist-entry <name> bgp rip route-map <name> match local-preference <0-4294967295> set network routing-profile filters route-maps redistribution redist-entry <name> bgp rip route-map <name> match peer <value>|<none|local> set network routing-profile filters route-maps redistribution redist-entry <name> bgp rip route-map <name> match ipv4 set network routing-profile filters route-maps redistribution redist-entry <name> bgp rip route-map <name> match ipv4 address set network routing-profile filters route-maps redistribution redist-entry <name> bgp rip route-map <name> match ipv4 address access-list <value> set network routing-profile filters route-maps redistribution redist-entry <name> bgp rip route-map <name> match ipv4 address prefix-list <value> set network routing-profile filters route-maps redistribution redist-entry <name> bgp rip route-map <name> match ipv4 next-hop set network routing-profile filters route-maps redistribution redist-entry <name> bgp rip route-map <name> match ipv4 next-hop access-list <value> set network routing-profile filters route-maps redistribution redist-entry <name> bgp rip route-map <name> match ipv4 next-hop prefix-list <value> set network routing-profile filters route-maps redistribution redist-entry <name> bgp rip route-map <name> match ipv4 route-source set network routing-profile filters route-maps redistribution redist-entry <name> bgp rip route-map <name> match ipv4 route-source access-list <value> set network routing-profile filters route-maps redistribution redist-entry <name> bgp rip route-map <name> match ipv4 route-source prefix-list <value> set network routing-profile filters route-maps redistribution redist-entry <name> bgp rip route-map <name> set set network routing-profile filters route-maps redistribution redist-entry <name> bgp rip route-map <name> set metric set network routing-profile filters route-maps redistribution redist-entry <name> bgp rip route-map <name> set metric value <0-16> set network routing-profile filters route-maps redistribution redist-entry <name> bgp rip route-map <name> set metric action <set|add|subtract> set network routing-profile filters route-maps redistribution redist-entry <name> bgp rip route-map <name> set next-hop <ip/netmask>|<validate>|<none|unchanged> set network routing-profile filters route-maps redistribution redist-entry <name> bgp rip route-map <name> set tag <1-4294967295> set network routing-profile filters route-maps redistribution redist-entry <name> bgp rib set network routing-profile filters route-maps redistribution redist-entry <name> bgp rib route-map set network routing-profile filters route-maps redistribution redist-entry <name> bgp rib route-map <name> set network routing-profile filters route-maps redistribution redist-entry <name> bgp rib route-map <name> action <deny|permit> set network routing-profile filters route-maps redistribution redist-entry <name> bgp rib route-map <name> description <value> set network routing-profile filters route-maps redistribution redist-entry <name> bgp rib route-map <name> match set network routing-profile filters route-maps redistribution redist-entry <name> bgp rib route-map <name> match as-path-access-list <value> set network routing-profile filters route-maps redistribution redist-entry <name> bgp rib route-map <name> match regular-community <value> set network routing-profile filters route-maps redistribution redist-entry <name> bgp rib route-map <name> match large-community <value> set network routing-profile filters route-maps redistribution redist-entry <name> bgp rib route-map <name> match extended-community <value> set network routing-profile filters route-maps redistribution redist-entry <name> bgp rib route-map <name> match interface <value> set network routing-profile filters route-maps redistribution redist-entry <name> bgp rib route-map <name> match origin <none|egp|igp|incomplete> set network routing-profile filters route-maps redistribution redist-entry <name> bgp rib route-map <name> match metric <0-4294967295> set network routing-profile filters route-maps redistribution redist-entry <name> bgp rib route-map <name> match tag <1-4294967295> set network routing-profile filters route-maps redistribution redist-entry <name> bgp rib route-map <name> match local-preference <0-4294967295> set network routing-profile filters route-maps redistribution redist-entry <name> bgp rib route-map <name> match peer <value>|<none|local> set network routing-profile filters route-maps redistribution redist-entry <name> bgp rib route-map <name> match ipv4 set network routing-profile filters route-maps redistribution redist-entry <name> bgp rib route-map <name> match ipv4 address set network routing-profile filters route-maps redistribution redist-entry <name> bgp rib route-map <name> match ipv4 address access-list <value> set network routing-profile filters route-maps redistribution redist-entry <name> bgp rib route-map <name> match ipv4 address prefix-list <value> set network routing-profile filters route-maps redistribution redist-entry <name> bgp rib route-map <name> match ipv4 next-hop set network routing-profile filters route-maps redistribution redist-entry <name> bgp rib route-map <name> match ipv4 next-hop access-list <value> set network routing-profile filters route-maps redistribution redist-entry <name> bgp rib route-map <name> match ipv4 next-hop prefix-list <value> set network routing-profile filters route-maps redistribution redist-entry <name> bgp rib route-map <name> match ipv4 route-source set network routing-profile filters route-maps redistribution redist-entry <name> bgp rib route-map <name> match ipv4 route-source access-list <value> set network routing-profile filters route-maps redistribution redist-entry <name> bgp rib route-map <name> match ipv4 route-source prefix-list <value> set network routing-profile filters route-maps redistribution redist-entry <name> bgp rib route-map <name> match ipv6 set network routing-profile filters route-maps redistribution redist-entry <name> bgp rib route-map <name> match ipv6 address set network routing-profile filters route-maps redistribution redist-entry <name> bgp rib route-map <name> match ipv6 address access-list <value> set network routing-profile filters route-maps redistribution redist-entry <name> bgp rib route-map <name> match ipv6 address prefix-list <value> set network routing-profile filters route-maps redistribution redist-entry <name> bgp rib route-map <name> match ipv6 next-hop set network routing-profile filters route-maps redistribution redist-entry <name> bgp rib route-map <name> match ipv6 next-hop access-list <value> set network routing-profile filters route-maps redistribution redist-entry <name> bgp rib route-map <name> match ipv6 next-hop prefix-list <value> set network routing-profile filters route-maps redistribution redist-entry <name> bgp rib route-map <name> set set network routing-profile filters route-maps redistribution redist-entry <name> bgp rib route-map <name> set source-address <value> set network routing-profile filters route-maps redistribution redist-entry <name> ospf set network routing-profile filters route-maps redistribution redist-entry <name> ospf bgp set network routing-profile filters route-maps redistribution redist-entry <name> ospf bgp route-map set network routing-profile filters route-maps redistribution redist-entry <name> ospf bgp route-map <name> set network routing-profile filters route-maps redistribution redist-entry <name> ospf bgp route-map <name> action <deny|permit> set network routing-profile filters route-maps redistribution redist-entry <name> ospf bgp route-map <name> description <value> set network routing-profile filters route-maps redistribution redist-entry <name> ospf bgp route-map <name> match set network routing-profile filters route-maps redistribution redist-entry <name> ospf bgp route-map <name> match interface <value> set network routing-profile filters route-maps redistribution redist-entry <name> ospf bgp route-map <name> match metric <0-4294967295> set network routing-profile filters route-maps redistribution redist-entry <name> ospf bgp route-map <name> match tag <1-4294967295> set network routing-profile filters route-maps redistribution redist-entry <name> ospf bgp route-map <name> match address set network routing-profile filters route-maps redistribution redist-entry <name> ospf bgp route-map <name> match address access-list <value> set network routing-profile filters route-maps redistribution redist-entry <name> ospf bgp route-map <name> match address prefix-list <value> set network routing-profile filters route-maps redistribution redist-entry <name> ospf bgp route-map <name> match next-hop set network routing-profile filters route-maps redistribution redist-entry <name> ospf bgp route-map <name> match next-hop access-list <value> set network routing-profile filters route-maps redistribution redist-entry <name> ospf bgp route-map <name> match next-hop prefix-list <value> set network routing-profile filters route-maps redistribution redist-entry <name> ospf bgp route-map <name> set set network routing-profile filters route-maps redistribution redist-entry <name> ospf bgp route-map <name> set aggregator set network routing-profile filters route-maps redistribution redist-entry <name> ospf bgp route-map <name> set aggregator as <1-4294967295> set network routing-profile filters route-maps redistribution redist-entry <name> ospf bgp route-map <name> set aggregator router-id <ip/netmask> set network routing-profile filters route-maps redistribution redist-entry <name> ospf bgp route-map <name> set tag <1-4294967295> set network routing-profile filters route-maps redistribution redist-entry <name> ospf bgp route-map <name> set local-preference <0-4294967295> set network routing-profile filters route-maps redistribution redist-entry <name> ospf bgp route-map <name> set weight <0-4294967295> set network routing-profile filters route-maps redistribution redist-entry <name> ospf bgp route-map <name> set origin <none|egp|igp|incomplete> set network routing-profile filters route-maps redistribution redist-entry <name> ospf bgp route-map <name> set atomic-aggregate <yes|no> set network routing-profile filters route-maps redistribution redist-entry <name> ospf bgp route-map <name> set metric set network routing-profile filters route-maps redistribution redist-entry <name> ospf bgp route-map <name> set metric value <0-4294967295> set network routing-profile filters route-maps redistribution redist-entry <name> ospf bgp route-map <name> set metric action <set|add|subtract> set network routing-profile filters route-maps redistribution redist-entry <name> ospf bgp route-map <name> set originator-id <ip/netmask> set network routing-profile filters route-maps redistribution redist-entry <name> ospf bgp route-map <name> set aspath-prepend [ <aspath-prepend1> <aspath-prepend2>... ] set network routing-profile filters route-maps redistribution redist-entry <name> ospf bgp route-map <name> set regular-community [ <regular-community1> <regular-community2>... ] set network routing-profile filters route-maps redistribution redist-entry <name> ospf bgp route-map <name> set large-community [ <large-community1> <large-community2>... ] set network routing-profile filters route-maps redistribution redist-entry <name> ospf bgp route-map <name> set ipv4 set network routing-profile filters route-maps redistribution redist-entry <name> ospf bgp route-map <name> set ipv4 source-address <value> set network routing-profile filters route-maps redistribution redist-entry <name> ospf bgp route-map <name> set ipv4 next-hop <ip/netmask>|<validate>|<none|unchanged|peer-address> set network routing-profile filters route-maps redistribution redist-entry <name> ospf rip set network routing-profile filters route-maps redistribution redist-entry <name> ospf rip route-map set network routing-profile filters route-maps redistribution redist-entry <name> ospf rip route-map <name> set network routing-profile filters route-maps redistribution redist-entry <name> ospf rip route-map <name> action <deny|permit> set network routing-profile filters route-maps redistribution redist-entry <name> ospf rip route-map <name> description <value> set network routing-profile filters route-maps redistribution redist-entry <name> ospf rip route-map <name> match set network routing-profile filters route-maps redistribution redist-entry <name> ospf rip route-map <name> match interface <value> set network routing-profile filters route-maps redistribution redist-entry <name> ospf rip route-map <name> match metric <0-4294967295> set network routing-profile filters route-maps redistribution redist-entry <name> ospf rip route-map <name> match tag <1-4294967295> set network routing-profile filters route-maps redistribution redist-entry <name> ospf rip route-map <name> match address set network routing-profile filters route-maps redistribution redist-entry <name> ospf rip route-map <name> match address access-list <value> set network routing-profile filters route-maps redistribution redist-entry <name> ospf rip route-map <name> match address prefix-list <value> set network routing-profile filters route-maps redistribution redist-entry <name> ospf rip route-map <name> match next-hop set network routing-profile filters route-maps redistribution redist-entry <name> ospf rip route-map <name> match next-hop access-list <value> set network routing-profile filters route-maps redistribution redist-entry <name> ospf rip route-map <name> match next-hop prefix-list <value> set network routing-profile filters route-maps redistribution redist-entry <name> ospf rip route-map <name> set set network routing-profile filters route-maps redistribution redist-entry <name> ospf rip route-map <name> set metric set network routing-profile filters route-maps redistribution redist-entry <name> ospf rip route-map <name> set metric value <0-16> set network routing-profile filters route-maps redistribution redist-entry <name> ospf rip route-map <name> set metric action <set|add|subtract> set network routing-profile filters route-maps redistribution redist-entry <name> ospf rip route-map <name> set next-hop <ip/netmask>|<validate>|<none|unchanged> set network routing-profile filters route-maps redistribution redist-entry <name> ospf rip route-map <name> set tag <1-4294967295> set network routing-profile filters route-maps redistribution redist-entry <name> ospf rib set network routing-profile filters route-maps redistribution redist-entry <name> ospf rib route-map set network routing-profile filters route-maps redistribution redist-entry <name> ospf rib route-map <name> set network routing-profile filters route-maps redistribution redist-entry <name> ospf rib route-map <name> action <deny|permit> set network routing-profile filters route-maps redistribution redist-entry <name> ospf rib route-map <name> description <value> set network routing-profile filters route-maps redistribution redist-entry <name> ospf rib route-map <name> match set network routing-profile filters route-maps redistribution redist-entry <name> ospf rib route-map <name> match interface <value> set network routing-profile filters route-maps redistribution redist-entry <name> ospf rib route-map <name> match metric <0-4294967295> set network routing-profile filters route-maps redistribution redist-entry <name> ospf rib route-map <name> match tag <1-4294967295> set network routing-profile filters route-maps redistribution redist-entry <name> ospf rib route-map <name> match address set network routing-profile filters route-maps redistribution redist-entry <name> ospf rib route-map <name> match address access-list <value> set network routing-profile filters route-maps redistribution redist-entry <name> ospf rib route-map <name> match address prefix-list <value> set network routing-profile filters route-maps redistribution redist-entry <name> ospf rib route-map <name> match next-hop set network routing-profile filters route-maps redistribution redist-entry <name> ospf rib route-map <name> match next-hop access-list <value> set network routing-profile filters route-maps redistribution redist-entry <name> ospf rib route-map <name> match next-hop prefix-list <value> set network routing-profile filters route-maps redistribution redist-entry <name> ospf rib route-map <name> set set network routing-profile filters route-maps redistribution redist-entry <name> ospf rib route-map <name> set source-address <value> set network routing-profile filters route-maps redistribution redist-entry <name> ospfv3 set network routing-profile filters route-maps redistribution redist-entry <name> ospfv3 bgp set network routing-profile filters route-maps redistribution redist-entry <name> ospfv3 bgp route-map set network routing-profile filters route-maps redistribution redist-entry <name> ospfv3 bgp route-map <name> set network routing-profile filters route-maps redistribution redist-entry <name> ospfv3 bgp route-map <name> action <deny|permit> set network routing-profile filters route-maps redistribution redist-entry <name> ospfv3 bgp route-map <name> description <value> set network routing-profile filters route-maps redistribution redist-entry <name> ospfv3 bgp route-map <name> match set network routing-profile filters route-maps redistribution redist-entry <name> ospfv3 bgp route-map <name> match interface <value> set network routing-profile filters route-maps redistribution redist-entry <name> ospfv3 bgp route-map <name> match metric <0-4294967295> set network routing-profile filters route-maps redistribution redist-entry <name> ospfv3 bgp route-map <name> match tag <1-4294967295> set network routing-profile filters route-maps redistribution redist-entry <name> ospfv3 bgp route-map <name> match address set network routing-profile filters route-maps redistribution redist-entry <name> ospfv3 bgp route-map <name> match address prefix-list <value> set network routing-profile filters route-maps redistribution redist-entry <name> ospfv3 bgp route-map <name> match address access-list <value> set network routing-profile filters route-maps redistribution redist-entry <name> ospfv3 bgp route-map <name> match next-hop set network routing-profile filters route-maps redistribution redist-entry <name> ospfv3 bgp route-map <name> match next-hop access-list <value> set network routing-profile filters route-maps redistribution redist-entry <name> ospfv3 bgp route-map <name> match next-hop prefix-list <value> set network routing-profile filters route-maps redistribution redist-entry <name> ospfv3 bgp route-map <name> set set network routing-profile filters route-maps redistribution redist-entry <name> ospfv3 bgp route-map <name> set aggregator set network routing-profile filters route-maps redistribution redist-entry <name> ospfv3 bgp route-map <name> set aggregator as <1-4294967295> set network routing-profile filters route-maps redistribution redist-entry <name> ospfv3 bgp route-map <name> set aggregator router-id <ip/netmask> set network routing-profile filters route-maps redistribution redist-entry <name> ospfv3 bgp route-map <name> set tag <1-4294967295> set network routing-profile filters route-maps redistribution redist-entry <name> ospfv3 bgp route-map <name> set local-preference <0-4294967295> set network routing-profile filters route-maps redistribution redist-entry <name> ospfv3 bgp route-map <name> set weight <0-4294967295> set network routing-profile filters route-maps redistribution redist-entry <name> ospfv3 bgp route-map <name> set origin <none|egp|igp|incomplete> set network routing-profile filters route-maps redistribution redist-entry <name> ospfv3 bgp route-map <name> set atomic-aggregate <yes|no> set network routing-profile filters route-maps redistribution redist-entry <name> ospfv3 bgp route-map <name> set metric set network routing-profile filters route-maps redistribution redist-entry <name> ospfv3 bgp route-map <name> set metric value <0-4294967295> set network routing-profile filters route-maps redistribution redist-entry <name> ospfv3 bgp route-map <name> set metric action <set|add|subtract> set network routing-profile filters route-maps redistribution redist-entry <name> ospfv3 bgp route-map <name> set originator-id <ip/netmask> set network routing-profile filters route-maps redistribution redist-entry <name> ospfv3 bgp route-map <name> set aspath-prepend [ <aspath-prepend1> <aspath-prepend2>... ] set network routing-profile filters route-maps redistribution redist-entry <name> ospfv3 bgp route-map <name> set regular-community [ <regular-community1> <regular-community2>... ] set network routing-profile filters route-maps redistribution redist-entry <name> ospfv3 bgp route-map <name> set large-community [ <large-community1> <large-community2>... ] set network routing-profile filters route-maps redistribution redist-entry <name> ospfv3 bgp route-map <name> set ipv6 set network routing-profile filters route-maps redistribution redist-entry <name> ospfv3 bgp route-map <name> set ipv6 source-address <value> set network routing-profile filters route-maps redistribution redist-entry <name> ospfv3 bgp route-map <name> set ipv6 next-hop <ip/netmask>|<validate>|<none|peer-address> set network routing-profile filters route-maps redistribution redist-entry <name> ospfv3 rib set network routing-profile filters route-maps redistribution redist-entry <name> ospfv3 rib route-map set network routing-profile filters route-maps redistribution redist-entry <name> ospfv3 rib route-map <name> set network routing-profile filters route-maps redistribution redist-entry <name> ospfv3 rib route-map <name> action <deny|permit> set network routing-profile filters route-maps redistribution redist-entry <name> ospfv3 rib route-map <name> description <value> set network routing-profile filters route-maps redistribution redist-entry <name> ospfv3 rib route-map <name> match set network routing-profile filters route-maps redistribution redist-entry <name> ospfv3 rib route-map <name> match interface <value> set network routing-profile filters route-maps redistribution redist-entry <name> ospfv3 rib route-map <name> match metric <0-4294967295> set network routing-profile filters route-maps redistribution redist-entry <name> ospfv3 rib route-map <name> match tag <1-4294967295> set network routing-profile filters route-maps redistribution redist-entry <name> ospfv3 rib route-map <name> match address set network routing-profile filters route-maps redistribution redist-entry <name> ospfv3 rib route-map <name> match address prefix-list <value> set network routing-profile filters route-maps redistribution redist-entry <name> ospfv3 rib route-map <name> match address access-list <value> set network routing-profile filters route-maps redistribution redist-entry <name> ospfv3 rib route-map <name> match next-hop set network routing-profile filters route-maps redistribution redist-entry <name> ospfv3 rib route-map <name> match next-hop access-list <value> set network routing-profile filters route-maps redistribution redist-entry <name> ospfv3 rib route-map <name> match next-hop prefix-list <value> set network routing-profile filters route-maps redistribution redist-entry <name> ospfv3 rib route-map <name> set set network routing-profile filters route-maps redistribution redist-entry <name> ospfv3 rib route-map <name> set source-address <value> set network routing-profile filters route-maps redistribution redist-entry <name> rip set network routing-profile filters route-maps redistribution redist-entry <name> rip bgp set network routing-profile filters route-maps redistribution redist-entry <name> rip bgp route-map set network routing-profile filters route-maps redistribution redist-entry <name> rip bgp route-map <name> set network routing-profile filters route-maps redistribution redist-entry <name> rip bgp route-map <name> action <deny|permit> set network routing-profile filters route-maps redistribution redist-entry <name> rip bgp route-map <name> description <value> set network routing-profile filters route-maps redistribution redist-entry <name> rip bgp route-map <name> match set network routing-profile filters route-maps redistribution redist-entry <name> rip bgp route-map <name> match interface <value> set network routing-profile filters route-maps redistribution redist-entry <name> rip bgp route-map <name> match metric <0-16> set network routing-profile filters route-maps redistribution redist-entry <name> rip bgp route-map <name> match tag <1-4294967295> set network routing-profile filters route-maps redistribution redist-entry <name> rip bgp route-map <name> match address set network routing-profile filters route-maps redistribution redist-entry <name> rip bgp route-map <name> match address access-list <value> set network routing-profile filters route-maps redistribution redist-entry <name> rip bgp route-map <name> match address prefix-list <value> set network routing-profile filters route-maps redistribution redist-entry <name> rip bgp route-map <name> match next-hop set network routing-profile filters route-maps redistribution redist-entry <name> rip bgp route-map <name> match next-hop access-list <value> set network routing-profile filters route-maps redistribution redist-entry <name> rip bgp route-map <name> match next-hop prefix-list <value> set network routing-profile filters route-maps redistribution redist-entry <name> rip bgp route-map <name> set set network routing-profile filters route-maps redistribution redist-entry <name> rip bgp route-map <name> set aggregator set network routing-profile filters route-maps redistribution redist-entry <name> rip bgp route-map <name> set aggregator as <1-4294967295> set network routing-profile filters route-maps redistribution redist-entry <name> rip bgp route-map <name> set aggregator router-id <ip/netmask> set network routing-profile filters route-maps redistribution redist-entry <name> rip bgp route-map <name> set tag <1-4294967295> set network routing-profile filters route-maps redistribution redist-entry <name> rip bgp route-map <name> set local-preference <0-4294967295> set network routing-profile filters route-maps redistribution redist-entry <name> rip bgp route-map <name> set weight <0-4294967295> set network routing-profile filters route-maps redistribution redist-entry <name> rip bgp route-map <name> set origin <none|egp|igp|incomplete> set network routing-profile filters route-maps redistribution redist-entry <name> rip bgp route-map <name> set atomic-aggregate <yes|no> set network routing-profile filters route-maps redistribution redist-entry <name> rip bgp route-map <name> set metric set network routing-profile filters route-maps redistribution redist-entry <name> rip bgp route-map <name> set metric value <0-4294967295> set network routing-profile filters route-maps redistribution redist-entry <name> rip bgp route-map <name> set metric action <set|add|subtract> set network routing-profile filters route-maps redistribution redist-entry <name> rip bgp route-map <name> set originator-id <ip/netmask> set network routing-profile filters route-maps redistribution redist-entry <name> rip bgp route-map <name> set aspath-prepend [ <aspath-prepend1> <aspath-prepend2>... ] set network routing-profile filters route-maps redistribution redist-entry <name> rip bgp route-map <name> set regular-community [ <regular-community1> <regular-community2>... ] set network routing-profile filters route-maps redistribution redist-entry <name> rip bgp route-map <name> set large-community [ <large-community1> <large-community2>... ] set network routing-profile filters route-maps redistribution redist-entry <name> rip bgp route-map <name> set ipv4 set network routing-profile filters route-maps redistribution redist-entry <name> rip bgp route-map <name> set ipv4 source-address <value> set network routing-profile filters route-maps redistribution redist-entry <name> rip bgp route-map <name> set ipv4 next-hop <ip/netmask>|<validate>|<none|unchanged|peer-address> set network routing-profile filters route-maps redistribution redist-entry <name> rip ospf set network routing-profile filters route-maps redistribution redist-entry <name> rip ospf route-map set network routing-profile filters route-maps redistribution redist-entry <name> rip ospf route-map <name> set network routing-profile filters route-maps redistribution redist-entry <name> rip ospf route-map <name> action <deny|permit> set network routing-profile filters route-maps redistribution redist-entry <name> rip ospf route-map <name> description <value> set network routing-profile filters route-maps redistribution redist-entry <name> rip ospf route-map <name> match set network routing-profile filters route-maps redistribution redist-entry <name> rip ospf route-map <name> match interface <value> set network routing-profile filters route-maps redistribution redist-entry <name> rip ospf route-map <name> match metric <0-16> set network routing-profile filters route-maps redistribution redist-entry <name> rip ospf route-map <name> match tag <1-4294967295> set network routing-profile filters route-maps redistribution redist-entry <name> rip ospf route-map <name> match address set network routing-profile filters route-maps redistribution redist-entry <name> rip ospf route-map <name> match address access-list <value> set network routing-profile filters route-maps redistribution redist-entry <name> rip ospf route-map <name> match address prefix-list <value> set network routing-profile filters route-maps redistribution redist-entry <name> rip ospf route-map <name> match next-hop set network routing-profile filters route-maps redistribution redist-entry <name> rip ospf route-map <name> match next-hop access-list <value> set network routing-profile filters route-maps redistribution redist-entry <name> rip ospf route-map <name> match next-hop prefix-list <value> set network routing-profile filters route-maps redistribution redist-entry <name> rip ospf route-map <name> set set network routing-profile filters route-maps redistribution redist-entry <name> rip ospf route-map <name> set metric set network routing-profile filters route-maps redistribution redist-entry <name> rip ospf route-map <name> set metric value <0-4294967295> set network routing-profile filters route-maps redistribution redist-entry <name> rip ospf route-map <name> set metric action <set|add|subtract> set network routing-profile filters route-maps redistribution redist-entry <name> rip ospf route-map <name> set metric-type <type-1|type-2> set network routing-profile filters route-maps redistribution redist-entry <name> rip ospf route-map <name> set tag <1-4294967295> set network routing-profile filters route-maps redistribution redist-entry <name> rip rib set network routing-profile filters route-maps redistribution redist-entry <name> rip rib route-map set network routing-profile filters route-maps redistribution redist-entry <name> rip rib route-map <name> set network routing-profile filters route-maps redistribution redist-entry <name> rip rib route-map <name> action <deny|permit> set network routing-profile filters route-maps redistribution redist-entry <name> rip rib route-map <name> description <value> set network routing-profile filters route-maps redistribution redist-entry <name> rip rib route-map <name> match set network routing-profile filters route-maps redistribution redist-entry <name> rip rib route-map <name> match interface <value> set network routing-profile filters route-maps redistribution redist-entry <name> rip rib route-map <name> match metric <0-16> set network routing-profile filters route-maps redistribution redist-entry <name> rip rib route-map <name> match tag <1-4294967295> set network routing-profile filters route-maps redistribution redist-entry <name> rip rib route-map <name> match address set network routing-profile filters route-maps redistribution redist-entry <name> rip rib route-map <name> match address access-list <value> set network routing-profile filters route-maps redistribution redist-entry <name> rip rib route-map <name> match address prefix-list <value> set network routing-profile filters route-maps redistribution redist-entry <name> rip rib route-map <name> match next-hop set network routing-profile filters route-maps redistribution redist-entry <name> rip rib route-map <name> match next-hop access-list <value> set network routing-profile filters route-maps redistribution redist-entry <name> rip rib route-map <name> match next-hop prefix-list <value> set network routing-profile filters route-maps redistribution redist-entry <name> rip rib route-map <name> set set network routing-profile filters route-maps redistribution redist-entry <name> rip rib route-map <name> set source-address <value> set network routing-profile filters route-maps redistribution redist-entry <name> connected-static set network routing-profile filters route-maps redistribution redist-entry <name> connected-static bgp set network routing-profile filters route-maps redistribution redist-entry <name> connected-static bgp route-map set network routing-profile filters route-maps redistribution redist-entry <name> connected-static bgp route-map <name> set network routing-profile filters route-maps redistribution redist-entry <name> connected-static bgp route-map <name> action <deny|permit> set network routing-profile filters route-maps redistribution redist-entry <name> connected-static bgp route-map <name> description <value> set network routing-profile filters route-maps redistribution redist-entry <name> connected-static bgp route-map <name> match set network routing-profile filters route-maps redistribution redist-entry <name> connected-static bgp route-map <name> match interface <value> set network routing-profile filters route-maps redistribution redist-entry <name> connected-static bgp route-map <name> match metric <0-4294967295> set network routing-profile filters route-maps redistribution redist-entry <name> connected-static bgp route-map <name> match ipv4 set network routing-profile filters route-maps redistribution redist-entry <name> connected-static bgp route-map <name> match ipv4 address set network routing-profile filters route-maps redistribution redist-entry <name> connected-static bgp route-map <name> match ipv4 address access-list <value> set network routing-profile filters route-maps redistribution redist-entry <name> connected-static bgp route-map <name> match ipv4 address prefix-list <value> set network routing-profile filters route-maps redistribution redist-entry <name> connected-static bgp route-map <name> match ipv4 next-hop set network routing-profile filters route-maps redistribution redist-entry <name> connected-static bgp route-map <name> match ipv4 next-hop access-list <value> set network routing-profile filters route-maps redistribution redist-entry <name> connected-static bgp route-map <name> match ipv4 next-hop prefix-list <value> set network routing-profile filters route-maps redistribution redist-entry <name> connected-static bgp route-map <name> match ipv6 set network routing-profile filters route-maps redistribution redist-entry <name> connected-static bgp route-map <name> match ipv6 address set network routing-profile filters route-maps redistribution redist-entry <name> connected-static bgp route-map <name> match ipv6 address access-list <value> set network routing-profile filters route-maps redistribution redist-entry <name> connected-static bgp route-map <name> match ipv6 address prefix-list <value> set network routing-profile filters route-maps redistribution redist-entry <name> connected-static bgp route-map <name> match ipv6 next-hop set network routing-profile filters route-maps redistribution redist-entry <name> connected-static bgp route-map <name> match ipv6 next-hop access-list <value> set network routing-profile filters route-maps redistribution redist-entry <name> connected-static bgp route-map <name> match ipv6 next-hop prefix-list <value> set network routing-profile filters route-maps redistribution redist-entry <name> connected-static bgp route-map <name> set set network routing-profile filters route-maps redistribution redist-entry <name> connected-static bgp route-map <name> set aggregator set network routing-profile filters route-maps redistribution redist-entry <name> connected-static bgp route-map <name> set aggregator as <1-4294967295> set network routing-profile filters route-maps redistribution redist-entry <name> connected-static bgp route-map <name> set aggregator router-id <ip/netmask> set network routing-profile filters route-maps redistribution redist-entry <name> connected-static bgp route-map <name> set tag <1-4294967295> set network routing-profile filters route-maps redistribution redist-entry <name> connected-static bgp route-map <name> set local-preference <0-4294967295> set network routing-profile filters route-maps redistribution redist-entry <name> connected-static bgp route-map <name> set weight <0-4294967295> set network routing-profile filters route-maps redistribution redist-entry <name> connected-static bgp route-map <name> set origin <none|egp|igp|incomplete> set network routing-profile filters route-maps redistribution redist-entry <name> connected-static bgp route-map <name> set atomic-aggregate <yes|no> set network routing-profile filters route-maps redistribution redist-entry <name> connected-static bgp route-map <name> set metric set network routing-profile filters route-maps redistribution redist-entry <name> connected-static bgp route-map <name> set metric value <0-4294967295> set network routing-profile filters route-maps redistribution redist-entry <name> connected-static bgp route-map <name> set metric action <set|add|subtract> set network routing-profile filters route-maps redistribution redist-entry <name> connected-static bgp route-map <name> set originator-id <ip/netmask> set network routing-profile filters route-maps redistribution redist-entry <name> connected-static bgp route-map <name> set aspath-prepend [ <aspath-prepend1> <aspath-prepend2>... ] set network routing-profile filters route-maps redistribution redist-entry <name> connected-static bgp route-map <name> set regular-community [ <regular-community1> <regular-community2>... ] set network routing-profile filters route-maps redistribution redist-entry <name> connected-static bgp route-map <name> set large-community [ <large-community1> <large-community2>... ] set network routing-profile filters route-maps redistribution redist-entry <name> connected-static bgp route-map <name> set ipv4 set network routing-profile filters route-maps redistribution redist-entry <name> connected-static bgp route-map <name> set ipv4 source-address <value> set network routing-profile filters route-maps redistribution redist-entry <name> connected-static bgp route-map <name> set ipv4 next-hop <ip/netmask>|<validate>|<none|unchanged|peer-address> set network routing-profile filters route-maps redistribution redist-entry <name> connected-static bgp route-map <name> set ipv6 set network routing-profile filters route-maps redistribution redist-entry <name> connected-static bgp route-map <name> set ipv6 source-address <value> set network routing-profile filters route-maps redistribution redist-entry <name> connected-static bgp route-map <name> set ipv6 next-hop <ip/netmask>|<validate>|<none|peer-address> set network routing-profile filters route-maps redistribution redist-entry <name> connected-static ospf set network routing-profile filters route-maps redistribution redist-entry <name> connected-static ospf route-map set network routing-profile filters route-maps redistribution redist-entry <name> connected-static ospf route-map <name> set network routing-profile filters route-maps redistribution redist-entry <name> connected-static ospf route-map <name> action <deny|permit> set network routing-profile filters route-maps redistribution redist-entry <name> connected-static ospf route-map <name> description <value> set network routing-profile filters route-maps redistribution redist-entry <name> connected-static ospf route-map <name> match set network routing-profile filters route-maps redistribution redist-entry <name> connected-static ospf route-map <name> match interface <value> set network routing-profile filters route-maps redistribution redist-entry <name> connected-static ospf route-map <name> match metric <0-4294967295> set network routing-profile filters route-maps redistribution redist-entry <name> connected-static ospf route-map <name> match ipv4 set network routing-profile filters route-maps redistribution redist-entry <name> connected-static ospf route-map <name> match ipv4 address set network routing-profile filters route-maps redistribution redist-entry <name> connected-static ospf route-map <name> match ipv4 address access-list <value> set network routing-profile filters route-maps redistribution redist-entry <name> connected-static ospf route-map <name> match ipv4 address prefix-list <value> set network routing-profile filters route-maps redistribution redist-entry <name> connected-static ospf route-map <name> match ipv4 next-hop set network routing-profile filters route-maps redistribution redist-entry <name> connected-static ospf route-map <name> match ipv4 next-hop access-list <value> set network routing-profile filters route-maps redistribution redist-entry <name> connected-static ospf route-map <name> match ipv4 next-hop prefix-list <value> set network routing-profile filters route-maps redistribution redist-entry <name> connected-static ospf route-map <name> set set network routing-profile filters route-maps redistribution redist-entry <name> connected-static ospf route-map <name> set metric set network routing-profile filters route-maps redistribution redist-entry <name> connected-static ospf route-map <name> set metric value <0-4294967295> set network routing-profile filters route-maps redistribution redist-entry <name> connected-static ospf route-map <name> set metric action <set|add|subtract> set network routing-profile filters route-maps redistribution redist-entry <name> connected-static ospf route-map <name> set metric-type <type-1|type-2> set network routing-profile filters route-maps redistribution redist-entry <name> connected-static ospf route-map <name> set tag <1-4294967295> set network routing-profile filters route-maps redistribution redist-entry <name> connected-static ospfv3 set network routing-profile filters route-maps redistribution redist-entry <name> connected-static ospfv3 route-map set network routing-profile filters route-maps redistribution redist-entry <name> connected-static ospfv3 route-map <name> set network routing-profile filters route-maps redistribution redist-entry <name> connected-static ospfv3 route-map <name> action <deny|permit> set network routing-profile filters route-maps redistribution redist-entry <name> connected-static ospfv3 route-map <name> description <value> set network routing-profile filters route-maps redistribution redist-entry <name> connected-static ospfv3 route-map <name> match set network routing-profile filters route-maps redistribution redist-entry <name> connected-static ospfv3 route-map <name> match interface <value> set network routing-profile filters route-maps redistribution redist-entry <name> connected-static ospfv3 route-map <name> match metric <0-4294967295> set network routing-profile filters route-maps redistribution redist-entry <name> connected-static ospfv3 route-map <name> match ipv6 set network routing-profile filters route-maps redistribution redist-entry <name> connected-static ospfv3 route-map <name> match ipv6 address set network routing-profile filters route-maps redistribution redist-entry <name> connected-static ospfv3 route-map <name> match ipv6 address access-list <value> set network routing-profile filters route-maps redistribution redist-entry <name> connected-static ospfv3 route-map <name> match ipv6 address prefix-list <value> set network routing-profile filters route-maps redistribution redist-entry <name> connected-static ospfv3 route-map <name> match ipv6 next-hop set network routing-profile filters route-maps redistribution redist-entry <name> connected-static ospfv3 route-map <name> match ipv6 next-hop access-list <value> set network routing-profile filters route-maps redistribution redist-entry <name> connected-static ospfv3 route-map <name> match ipv6 next-hop prefix-list <value> set network routing-profile filters route-maps redistribution redist-entry <name> connected-static ospfv3 route-map <name> set set network routing-profile filters route-maps redistribution redist-entry <name> connected-static ospfv3 route-map <name> set metric set network routing-profile filters route-maps redistribution redist-entry <name> connected-static ospfv3 route-map <name> set metric value <0-4294967295> set network routing-profile filters route-maps redistribution redist-entry <name> connected-static ospfv3 route-map <name> set metric action <set|add|subtract> set network routing-profile filters route-maps redistribution redist-entry <name> connected-static ospfv3 route-map <name> set metric-type <type-1|type-2> set network routing-profile filters route-maps redistribution redist-entry <name> connected-static ospfv3 route-map <name> set tag <1-4294967295> set network routing-profile filters route-maps redistribution redist-entry <name> connected-static rip set network routing-profile filters route-maps redistribution redist-entry <name> connected-static rip route-map set network routing-profile filters route-maps redistribution redist-entry <name> connected-static rip route-map <name> set network routing-profile filters route-maps redistribution redist-entry <name> connected-static rip route-map <name> action <deny|permit> set network routing-profile filters route-maps redistribution redist-entry <name> connected-static rip route-map <name> description <value> set network routing-profile filters route-maps redistribution redist-entry <name> connected-static rip route-map <name> match set network routing-profile filters route-maps redistribution redist-entry <name> connected-static rip route-map <name> match interface <value> set network routing-profile filters route-maps redistribution redist-entry <name> connected-static rip route-map <name> match metric <0-4294967295> set network routing-profile filters route-maps redistribution redist-entry <name> connected-static rip route-map <name> match ipv4 set network routing-profile filters route-maps redistribution redist-entry <name> connected-static rip route-map <name> match ipv4 address set network routing-profile filters route-maps redistribution redist-entry <name> connected-static rip route-map <name> match ipv4 address access-list <value> set network routing-profile filters route-maps redistribution redist-entry <name> connected-static rip route-map <name> match ipv4 address prefix-list <value> set network routing-profile filters route-maps redistribution redist-entry <name> connected-static rip route-map <name> match ipv4 next-hop set network routing-profile filters route-maps redistribution redist-entry <name> connected-static rip route-map <name> match ipv4 next-hop access-list <value> set network routing-profile filters route-maps redistribution redist-entry <name> connected-static rip route-map <name> match ipv4 next-hop prefix-list <value> set network routing-profile filters route-maps redistribution redist-entry <name> connected-static rip route-map <name> set set network routing-profile filters route-maps redistribution redist-entry <name> connected-static rip route-map <name> set metric set network routing-profile filters route-maps redistribution redist-entry <name> connected-static rip route-map <name> set metric value <0-16> set network routing-profile filters route-maps redistribution redist-entry <name> connected-static rip route-map <name> set metric action <set|add|subtract> set network routing-profile filters route-maps redistribution redist-entry <name> connected-static rip route-map <name> set next-hop <ip/netmask>|<validate>|<none|unchanged> set network routing-profile filters route-maps redistribution redist-entry <name> connected-static rip route-map <name> set tag <1-4294967295> set network routing-profile filters route-maps redistribution redist-entry <name> connected-static rib set network routing-profile filters route-maps redistribution redist-entry <name> connected-static rib route-map set network routing-profile filters route-maps redistribution redist-entry <name> connected-static rib route-map <name> set network routing-profile filters route-maps redistribution redist-entry <name> connected-static rib route-map <name> action <deny|permit> set network routing-profile filters route-maps redistribution redist-entry <name> connected-static rib route-map <name> description <value> set network routing-profile filters route-maps redistribution redist-entry <name> connected-static rib route-map <name> match set network routing-profile filters route-maps redistribution redist-entry <name> connected-static rib route-map <name> match interface <value> set network routing-profile filters route-maps redistribution redist-entry <name> connected-static rib route-map <name> match metric <0-4294967295> set network routing-profile filters route-maps redistribution redist-entry <name> connected-static rib route-map <name> match ipv4 set network routing-profile filters route-maps redistribution redist-entry <name> connected-static rib route-map <name> match ipv4 address set network routing-profile filters route-maps redistribution redist-entry <name> connected-static rib route-map <name> match ipv4 address access-list <value> set network routing-profile filters route-maps redistribution redist-entry <name> connected-static rib route-map <name> match ipv4 address prefix-list <value> set network routing-profile filters route-maps redistribution redist-entry <name> connected-static rib route-map <name> match ipv4 next-hop set network routing-profile filters route-maps redistribution redist-entry <name> connected-static rib route-map <name> match ipv4 next-hop access-list <value> set network routing-profile filters route-maps redistribution redist-entry <name> connected-static rib route-map <name> match ipv4 next-hop prefix-list <value> set network routing-profile filters route-maps redistribution redist-entry <name> connected-static rib route-map <name> match ipv6 set network routing-profile filters route-maps redistribution redist-entry <name> connected-static rib route-map <name> match ipv6 address set network routing-profile filters route-maps redistribution redist-entry <name> connected-static rib route-map <name> match ipv6 address access-list <value> set network routing-profile filters route-maps redistribution redist-entry <name> connected-static rib route-map <name> match ipv6 address prefix-list <value> set network routing-profile filters route-maps redistribution redist-entry <name> connected-static rib route-map <name> match ipv6 next-hop set network routing-profile filters route-maps redistribution redist-entry <name> connected-static rib route-map <name> match ipv6 next-hop access-list <value> set network routing-profile filters route-maps redistribution redist-entry <name> connected-static rib route-map <name> match ipv6 next-hop prefix-list <value> set network routing-profile filters route-maps redistribution redist-entry <name> connected-static rib route-map <name> set set network routing-profile filters route-maps redistribution redist-entry <name> connected-static rib route-map <name> set source-address <value>
set network routing-profile bfd set network routing-profile bfd<name> set network routing-profile bfd <name> mode <active|passive> set network routing-profile bfd <name> min-tx-interval <100-10000> set network routing-profile bfd <name> min-rx-interval <100-10000> set network routing-profile bfd <name> detection-multiplier <2-255> set network routing-profile bfd <name> hold-time <0-120000> set network routing-profile bfd <name> multihop set network routing-profile bfd <name> multihop min-received-ttl <1-254> set network routing-profile multicast set network routing-profile multicast pim-interface-timer-profile set network routing-profile multicast pim-interface-timer-profile <name> set network routing-profile multicast pim-interface-timer-profile <name> assert-interval <0-65534> set network routing-profile multicast pim-interface-timer-profile <name> hello-interval <1-180> set network routing-profile multicast pim-interface-timer-profile <name> join-prune-interval <60-600> set network routing-profile multicast igmp-interface-query-profile set network routing-profile multicast igmp-interface-query-profile <name> set network routing-profile multicast igmp-interface-query-profile <name> max-query-response-time <1-25> set network routing-profile multicast igmp-interface-query-profile <name> query-interval <1-1800> set network routing-profile multicast igmp-interface-query-profile <name> last-member-query-interval <1-25> set network routing-profile multicast igmp-interface-query-profile <name> immediate-leave <yes|no> set network routing-profile rip set network routing-profile rip auth-profile set network routing-profile rip auth-profile <name> set network routing-profile rip auth-profile <name> password <value> set network routing-profile rip auth-profile <name> md5 set network routing-profile rip auth-profile <name> md5 <name> set network routing-profile rip auth-profile <name> md5 <name> key <value> set network routing-profile rip auth-profile <name> md5 <name> preferred <yes|no> set network routing-profile rip global-timer-profile set network routing-profile rip global-timer-profile <name> set network routing-profile rip global-timer-profile <name> update-intervals <5-2147483647> set network routing-profile rip global-timer-profile <name> expire-intervals <5-2147483647> set network routing-profile rip global-timer-profile <name> delete-intervals <5-2147483647> set network routing-profile rip redistribution-profile set network routing-profile rip redistribution-profile <name> set network routing-profile rip redistribution-profile <name> static set network routing-profile rip redistribution-profile <name> static enable <yes|no> set network routing-profile rip redistribution-profile <name> static metric <1-65535> set network routing-profile rip redistribution-profile <name> static route-map <value> set network routing-profile rip redistribution-profile <name> connected set network routing-profile rip redistribution-profile <name> connected enable <yes|no> set network routing-profile rip redistribution-profile <name> connected metric <1-65535> set network routing-profile rip redistribution-profile <name> connected route-map <value> set network routing-profile rip redistribution-profile <name> bgp set network routing-profile rip redistribution-profile <name> bgp enable <yes|no> set network routing-profile rip redistribution-profile <name> bgp metric <0-4294967295> set network routing-profile rip redistribution-profile <name> bgp route-map <value> set network routing-profile rip redistribution-profile <name> ospf set network routing-profile rip redistribution-profile <name> ospf enable <yes|no> set network routing-profile rip redistribution-profile <name> ospf metric <0-4294967295> set network routing-profile rip redistribution-profile <name> ospf route-map <value> set shared reports <name> type threat group-by <serial|time_generated|src|dst|natsrc|natdst|rule|srcuser|dstuser|srcloc|dstloc|app|vsys|from|to|inbound_if|outbound_if|sport|dport|natsport|natdport|proto|action|tunnel|rule_uuid|s_encrypted|category-of-app|subcategory-of-app|technology-of-app|container-of-app|risk-of-app|vsys_name|device_name|parent_session_id|parent_start_time|threatid|category|severity|direction|http_method|nssai_sst|filedigest|filetype|http2_connection|xff_ip|threat_name|src_edl|dst_edl|dynusergroup_name|hostid|partial_hash|cloud_reportid|src_category|src_profile|src_model|src_vendor|src_osfamily|src_osversion|src_host|src_mac|dst_category|dst_profile|dst_model|dst_vendor|dst_osfamily|dst_osversion|dst_host|dst_mac|container_id|pod_namespace|pod_name|misc|src_dag|dst_dag|day-of-receive_time|hour-of-receive_time|quarter-hour-of-receive_time|pbf-s2c|pbf-c2s|flag-nat|flag-pcap|subtype|transaction|captive-portal|flag-proxy|non-std-dport|tunnelid|monitortag|users|category-of-threatid|threat-type> set shared reports <name> type url group-by <action|app|category|category-of-app|direction|dport|dst|dstuser|from|inbound_if|misc|http_headers|natdport|natdst|natsport|natsrc|outbound_if|proto|risk-of-app|rule|rule_uuid|severity|sport|src|srcuser|subcategory-of-app|technology-of-app|container-of-app|to|dstloc|srcloc|vsys|quarter-hour-of-receive_time|hour-of-receive_time|day-of-receive_time|contenttype|user_agent|device_name|vsys_name|url|tunnelid|monitortag|parent_session_id|parent_start_time|http2_connection|tunnel|http_method|url_category_list|xff_ip|container_id|pod_namespace|pod_name|src_dag|dst_dag|src_edl|dst_edl|src_category|src_profile|src_model|src_vendor|src_osfamily|src_osversion|src_host|src_mac|dst_category|dst_profile|dst_model|dst_vendor|dst_osfamily|dst_osversion|dst_host|dst_mac|cloud_reportid>
set shared server-profile scp set shared server-profile scp <name> set shared server-profile scp <name> server <value> set shared server-profile scp <name> port <1-65535> set shared server-profile scp <name> username <value> set shared server-profile scp <name> password <value> set shared server-profile scp <name> path <value> set shared server-profile scp <name> fingerprint <value> set shared admin-role <name> role device webui network routing routing-profiles bfd <enable|read-only|disable> set shared admin-role <name> role device webui network routing routing-profiles ospf <enable|read-only|disable> set shared admin-role <name> role device webui network routing routing-profiles ospfv3 <enable|read-only|disable> set shared admin-role <name> role device webui network routing routing-profiles ripv2 <enable|read-only|disable> set shared admin-role <name> role device webui network routing routing-profiles filters <enable|read-only|disable> set shared admin-role <name> role device webui network routing routing-profiles multicast <enable|read-only|disable> set shared admin-role <name> role device webui device server-profile scp <enable|read-only|disable> set shared admin-role <name> role device webui operations download-pcap-files <enable|disable> set shared admin-role <name> role device restapi device snmp-trap-server-profiles <enable|read-only|disable> set shared admin-role <name> role device restapi device syslog-server-profiles <enable|read-only|disable> set shared admin-role <name> role device restapi device email-server-profiles <enable|read-only|disable> set shared admin-role <name> role device restapi device http-server-profiles <enable|read-only|disable> set shared admin-role <name> role device restapi device ldap-server-profiles <enable|read-only|disable> set display-name <value>
There are 6 new set setting commands.
set setting set setting nat set setting nat reserve-ip<yes|no> set setting nat reserve-time <1-604800> set setting ssl-decrypt set setting ssl-decrypt allow-forward-decrypted-content <yes|no>
There are 21 new set import commands.
set import set import dns-proxy<value> set import network set import network interface [ <interface1> <interface2>... ] set import network virtual-wire [ <virtual-wire1> <virtual-wire2>... ] set import network vlan [ <vlan1> <vlan2>... ] set import network virtual-router [ <virtual-router1> <virtual-router2>... ] set import network logical-router [ <logical-router1> <logical-router2>... ] set import resource set import resource max-sessions <1-4194290> set import resource max-site-to-site-vpn-tunnels <0-10000> set import resource max-concurrent-ssl-vpn-tunnels <0-65535> set import resource max-security-rules <0-65000> set import resource max-nat-rules <0-16000> set import resource max-ssl-decryption-rules <0-5000> set import resource max-qos-rules <0-8000> set import resource max-application-override-rules <0-4000> set import resource max-pbf-rules <0-2000> set import resource max-auth-rules <0-8000> set import resource max-dos-rules <0-2000> set import resource max-sdwan-rules <0-2000>
There are 9 new set route commands.
set route set route service set route service<name> set route service <name> source set route service <name> source interface <value> set route service <name> source address <value> set route service <name> source-v6 set route service <name> source-v6 interface <value> set route service <name> source-v6 address <value>
There are 27 new set dns-proxy commands.
set dns-proxy set dns-proxy<name> set dns-proxy <name> enabled <yes|no> set dns-proxy <name> interface [ <interface1> <interface2>... ] set dns-proxy <name> server-profile <value> set dns-proxy <name> domain-servers set dns-proxy <name> domain-servers <name> set dns-proxy <name> domain-servers <name> cacheable <yes|no> set dns-proxy <name> domain-servers <name> domain-name [ <domain-name1> <domain-name2>... ] set dns-proxy <name> domain-servers <name> server-profile <value> set dns-proxy <name> cache set dns-proxy <name> cache enabled <yes|no> set dns-proxy <name> cache cache-edns <yes|no> set dns-proxy <name> cache max-ttl set dns-proxy <name> cache max-ttl enabled <yes|no> set dns-proxy <name> cache max-ttl time-to-live <60-86400> set dns-proxy <name> static-entries set dns-proxy <name> static-entries <name> set dns-proxy <name> static-entries <name> domain <value> set dns-proxy <name> static-entries <name> address [ <address1> <address2>... ] set dns-proxy <name> tcp-queries set dns-proxy <name> tcp-queries enabled <yes|no> set dns-proxy <name> tcp-queries max-pending-requests <64-256> set dns-proxy <name> udp-queries set dns-proxy <name> udp-queries retries set dns-proxy <name> udp-queries retries interval <1-30> set dns-proxy <name> udp-queries retries attempts <1-30> set url-content-types [ <url-content-types1> <url-content-types2>... ]
There are 6 new set ts-agent commands.
set ts-agent set ts-agent<name> set ts-agent <name> host <ip/netmask>|<value> set ts-agent <name> port <1-65535> set ts-agent <name> ip-list [ <ip-list1> <ip-list2>... ] set ts-agent <name> disabled <yes|no>
There are 15 new set redistribution-agent commands.
set redistribution-agent set redistribution-agent<name> set redistribution-agent <name> serial-number <value> set redistribution-agent <name> host-port set redistribution-agent <name> host-port host <ip/netmask>|<value> set redistribution-agent <name> host-port ldap-proxy <yes|no> set redistribution-agent <name> host-port port <1-65535> set redistribution-agent <name> host-port collectorname <value> set redistribution-agent <name> host-port secret <value> set redistribution-agent <name> disabled <yes|no> set redistribution-agent <name> ip-user-mappings <yes|no> set redistribution-agent <name> ip-tags <yes|no> set redistribution-agent <name> user-tags <yes|no> set redistribution-agent <name> hip <yes|no> set redistribution-agent <name> quarantine-list <yes|no>
There are 6 new set ipuser-include-exclude-list commands.
set ipuser-include-exclude-list set ipuser-include-exclude-list include-exclude-network set ipuser-include-exclude-list include-exclude-network<name> set ipuser-include-exclude-list include-exclude-network <name> disabled <yes|no> set ipuser-include-exclude-list include-exclude-network <name> discovery <include|exclude> set ipuser-include-exclude-list include-exclude-network <name> network-address <ip/netmask>
There are 6 new set iptag-include-exclude-list commands.
set iptag-include-exclude-list set iptag-include-exclude-list include-exclude-network set iptag-include-exclude-list include-exclude-network<name> set iptag-include-exclude-list include-exclude-network <name> disabled <yes|no> set iptag-include-exclude-list include-exclude-network <name> discovery <include|exclude> set iptag-include-exclude-list include-exclude-network <name> network-address <ip/netmask>
There are 4 new set redistribution-collector commands.
set redistribution-collector set redistribution-collector setting set redistribution-collector setting collectorname<value> set redistribution-collector setting secret <value>
There are 2 new set user-id-ssl-auth commands.
set user-id-ssl-auth set user-id-ssl-auth certificate-profile<value>
There are 44 new set vm-info-source commands.
set vm-info-source set vm-info-source<name> set vm-info-source <name> AWS-VPC set vm-info-source <name> AWS-VPC description <value> set vm-info-source <name> AWS-VPC disabled <yes|no> set vm-info-source <name> AWS-VPC source <value> set vm-info-source <name> AWS-VPC access-key-id <value> set vm-info-source <name> AWS-VPC secret-access-key <value> set vm-info-source <name> AWS-VPC update-interval <60-1200> set vm-info-source <name> AWS-VPC vm-info-timeout-enable <yes|no> set vm-info-source <name> AWS-VPC vm-info-timeout <2-10> set vm-info-source <name> AWS-VPC vpc-id <value> set vm-info-source <name> Google-Compute-Engine set vm-info-source <name> Google-Compute-Engine description <value> set vm-info-source <name> Google-Compute-Engine disabled <yes|no> set vm-info-source <name> Google-Compute-Engine service-auth-type set vm-info-source <name> Google-Compute-Engine service-auth-type service-in-gce set vm-info-source <name> Google-Compute-Engine service-auth-type service-account set vm-info-source <name> Google-Compute-Engine service-auth-type service-account service-account-cred <value> set vm-info-source <name> Google-Compute-Engine project-id <value> set vm-info-source <name> Google-Compute-Engine zone-name <value> set vm-info-source <name> Google-Compute-Engine update-interval <60-1200> set vm-info-source <name> Google-Compute-Engine vm-info-timeout-enable <yes|no> set vm-info-source <name> Google-Compute-Engine vm-info-timeout <2-10> set vm-info-source <name> VMware-ESXi set vm-info-source <name> VMware-ESXi description <value> set vm-info-source <name> VMware-ESXi port <1-65535> set vm-info-source <name> VMware-ESXi disabled <yes|no> set vm-info-source <name> VMware-ESXi vm-info-timeout-enable <yes|no> set vm-info-source <name> VMware-ESXi vm-info-timeout <2-10> set vm-info-source <name> VMware-ESXi source <ip/netmask>|<value> set vm-info-source <name> VMware-ESXi username <value> set vm-info-source <name> VMware-ESXi password <value> set vm-info-source <name> VMware-ESXi update-interval <5-600> set vm-info-source <name> VMware-vCenter set vm-info-source <name> VMware-vCenter description <value> set vm-info-source <name> VMware-vCenter port <1-65535> set vm-info-source <name> VMware-vCenter disabled <yes|no> set vm-info-source <name> VMware-vCenter vm-info-timeout-enable <yes|no> set vm-info-source <name> VMware-vCenter vm-info-timeout <2-10> set vm-info-source <name> VMware-vCenter source <ip/netmask>|<value> set vm-info-source <name> VMware-vCenter username <value> set vm-info-source <name> VMware-vCenter password <value> set vm-info-source <name> VMware-vCenter update-interval <5-600>
There are 28 new set group-mapping commands.
set group-mapping set group-mapping<name> set group-mapping <name> server-profile <value> set group-mapping <name> disabled <yes|no> set group-mapping <name> use-ldap-for-serialno-check <yes|no> set group-mapping <name> use-modify-timestamp <yes|no> set group-mapping <name> limited-group-search <yes|no> set group-mapping <name> nested-group-level <1-20> set group-mapping <name> group-filter <value> set group-mapping <name> user-filter <value> set group-mapping <name> domain <value> set group-mapping <name> update-interval <60-86400> set group-mapping <name> group-object [ <group-object1> <group-object2>... ] set group-mapping <name> group-member [ <group-member1> <group-member2>... ] set group-mapping <name> group-name [ <group-name1> <group-name2>... ] set group-mapping <name> user-object [ <user-object1> <user-object2>... ] set group-mapping <name> user-name [ <user-name1> <user-name2>... ] set group-mapping <name> user-email [ <user-email1> <user-email2>... ] set group-mapping <name> group-email [ <group-email1> <group-email2>... ] set group-mapping <name> alternate-user-name-1 [ <alternate-user-name-11> <alternate-user-name-12>... ] set group-mapping <name> alternate-user-name-2 [ <alternate-user-name-21> <alternate-user-name-22>... ] set group-mapping <name> alternate-user-name-3 [ <alternate-user-name-31> <alternate-user-name-32>... ] set group-mapping <name> container-object [ <container-object1> <container-object2>... ] set group-mapping <name> last-modify-attr [ <last-modify-attr1> <last-modify-attr2>... ] set group-mapping <name> group-include-list [ <group-include-list1> <group-include-list2>... ] set group-mapping <name> custom-group set group-mapping <name> custom-group <name> set group-mapping <name> custom-group <name> ldap-filter <value>
There are 15 new set cloud-identity-engine commands.
set cloud-identity-engine set cloud-identity-engine<name> set cloud-identity-engine <name> region <value> set cloud-identity-engine <name> cloud-identity-engine-instance <value> set cloud-identity-engine <name> domain <value> set cloud-identity-engine <name> update-interval <5-1440> set cloud-identity-engine <name> enabled <yes|no> set cloud-identity-engine <name> primary-user <value> set cloud-identity-engine <name> user-email <value> set cloud-identity-engine <name> alt-username-1 <value> set cloud-identity-engine <name> alt-username-2 <value> set cloud-identity-engine <name> alt-username-3 <value> set cloud-identity-engine <name> group-name <value> set cloud-identity-engine <name> group-email <value> set cloud-identity-engine <name> endpoint-serial-number <value>
There are 16 new set captive-portal commands.
set captive-portal set captive-portal enable-captive-portal<yes|no> set captive-portal idle-timer <1-1440> set captive-portal timer <1-1440> set captive-portal redirect-host <ip/netmask>|<value> set captive-portal ssl-tls-service-profile <value> set captive-portal gp-udp-port <1-65535> set captive-portal mode set captive-portal mode transparent set captive-portal mode redirect set captive-portal mode redirect session-cookie set captive-portal mode redirect session-cookie enable <yes|no> set captive-portal mode redirect session-cookie timeout <60-10080> set captive-portal mode redirect session-cookie roaming <yes|no> set captive-portal authentication-profile <value> set captive-portal certificate-profile <value>
There are 58 new set user-id-collector commands.
set user-id-collector set user-id-collector setting set user-id-collector setting wmi-account<value> set user-id-collector setting wmi-password <value> set user-id-collector setting domain-name <value> set user-id-collector setting server-profile <value> set user-id-collector setting enable-security-log <yes|no> set user-id-collector setting security-log-interval <1-3600> set user-id-collector setting enable-session <yes|no> set user-id-collector setting session-interval <1-3600> set user-id-collector setting edirectory-query-interval <1-3600> set user-id-collector setting enable-probing <yes|no> set user-id-collector setting client-probing-interval <1-1440> set user-id-collector setting enable-mapping-timeout <yes|no> set user-id-collector setting ip-user-mapping-timeout <1-1440> set user-id-collector setting enable-user-match <yes|no> set user-id-collector setting syslog-service-profile <value> set user-id-collector syslog-parse-profile set user-id-collector syslog-parse-profile <name> set user-id-collector syslog-parse-profile <name> description <value> set user-id-collector syslog-parse-profile <name> regex-identifier set user-id-collector syslog-parse-profile <name> regex-identifier event-regex <value> set user-id-collector syslog-parse-profile <name> regex-identifier username-regex <value> set user-id-collector syslog-parse-profile <name> regex-identifier address-regex <value> set user-id-collector syslog-parse-profile <name> field-identifier set user-id-collector syslog-parse-profile <name> field-identifier event-string <value> set user-id-collector syslog-parse-profile <name> field-identifier username-prefix <value> set user-id-collector syslog-parse-profile <name> field-identifier username-delimiter <value> set user-id-collector syslog-parse-profile <name> field-identifier address-prefix <value> set user-id-collector syslog-parse-profile <name> field-identifier address-delimiter <value> set user-id-collector syslog-parse-profile <name> field-identifier address-per-log <1-3> set user-id-collector server-monitor set user-id-collector server-monitor <name> set user-id-collector server-monitor <name> description <value> set user-id-collector server-monitor <name> disabled <yes|no> set user-id-collector server-monitor <name> active-directory set user-id-collector server-monitor <name> active-directory type <WMI|WinRM-HTTP|WinRM-HTTPS> set user-id-collector server-monitor <name> active-directory host <ip/netmask>|<value> set user-id-collector server-monitor <name> exchange set user-id-collector server-monitor <name> exchange type <WMI|WinRM-HTTP|WinRM-HTTPS> set user-id-collector server-monitor <name> exchange host <ip/netmask>|<value> set user-id-collector server-monitor <name> e-directory set user-id-collector server-monitor <name> e-directory server-profile <value> set user-id-collector server-monitor <name> syslog set user-id-collector server-monitor <name> syslog address <ip/netmask> set user-id-collector server-monitor <name> syslog connection-type <udp|ssl> set user-id-collector server-monitor <name> syslog syslog-parse-profile set user-id-collector server-monitor <name> syslog syslog-parse-profile <name> set user-id-collector server-monitor <name> syslog syslog-parse-profile <name> event-type <login|logout> set user-id-collector server-monitor <name> syslog default-domain-name <value> set user-id-collector include-exclude-network set user-id-collector include-exclude-network <name> set user-id-collector include-exclude-network <name> disabled <yes|no> set user-id-collector include-exclude-network <name> discovery <include|exclude> set user-id-collector include-exclude-network <name> network-address <ip/netmask> set user-id-collector include-exclude-network-sequence set user-id-collector include-exclude-network-sequence include-exclude-network [ <include-exclude-network1> <include-exclude-network2>... ] set user-id-collector ignore-user [ <ignore-user1> <ignore-user2>... ]
There are 7 new set url-admin-override commands.
set url-admin-override set url-admin-override password<value> set url-admin-override ssl-tls-service-profile <value> set url-admin-override mode set url-admin-override mode transparent set url-admin-override mode redirect set url-admin-override mode redirect address <ip/netmask>|<value>
There are 19 new set zone commands.
set zone set zone<name> set zone <name> enable-user-identification <yes|no> set zone <name> enable-device-identification <yes|no> set zone <name> network set zone <name> network zone-protection-profile <value> set zone <name> network enable-packet-buffer-protection <yes|no> set zone <name> network log-setting <value> set zone <name> network tap [ <tap1> <tap2>... ] set zone <name> network virtual-wire [ <virtual-wire1> <virtual-wire2>... ] set zone <name> network layer2 [ <layer21> <layer22>... ] set zone <name> network layer3 [ <layer31> <layer32>... ] set zone <name> network tunnel set zone <name> user-acl set zone <name> user-acl include-list [ <include-list1> <include-list2>... ] set zone <name> user-acl exclude-list [ <exclude-list1> <exclude-list2>... ] set zone <name> device-acl set zone <name> device-acl include-list [ <include-list1> <include-list2>... ] set zone <name> device-acl exclude-list [ <exclude-list1> <exclude-list2>... ]
There are 14 new set sdwan-interface-profile commands.
set sdwan-interface-profile set sdwan-interface-profile<name> set sdwan-interface-profile <name> link-tag <value> set sdwan-interface-profile <name> link-type <ADSL/DSL|Cablemodem|Ethernet|Fiber|LTE/3G/4G/5G|MPLS|Microwave/Radio|Satellite|WiFi|Other> set sdwan-interface-profile <name> vpn-data-tunnel-support <yes|no> set sdwan-interface-profile <name> maximum-download <float> set sdwan-interface-profile <name> maximum-upload <float> set sdwan-interface-profile <name> error-correction <yes|no> set sdwan-interface-profile <name> path-monitoring <Aggressive|Relaxed> set sdwan-interface-profile <name> vpn-failover-metric <1-65535> set sdwan-interface-profile <name> probe-frequency <1-5> set sdwan-interface-profile <name> probe-idle-time <1-86400> set sdwan-interface-profile <name> failback-hold-time <20-120> set sdwan-interface-profile <name> comment <value> set disable-inspect <yes|no>
There are 3 new set x-authenticated-user commands.
set x-authenticated-user set x-authenticated-user enabled<yes|no> set x-authenticated-user source [ <source1> <source2>... ]
There are 331 new set global-protect commands.
set global-protect set global-protect global-protect-portal set global-protect global-protect-portal<name> set global-protect global-protect-portal <name> portal-config set global-protect global-protect-portal <name> portal-config local-address set global-protect global-protect-portal <name> portal-config local-address ip-address-family <ipv4|ipv6|ipv4_ipv6> set global-protect global-protect-portal <name> portal-config local-address interface <value> set global-protect global-protect-portal <name> portal-config local-address ip set global-protect global-protect-portal <name> portal-config local-address ip ipv4 <value> set global-protect global-protect-portal <name> portal-config local-address ip ipv6 <value> set global-protect global-protect-portal <name> portal-config local-address floating-ip set global-protect global-protect-portal <name> portal-config local-address floating-ip ipv4 <value> set global-protect global-protect-portal <name> portal-config local-address floating-ip ipv6 <value> set global-protect global-protect-portal <name> portal-config ssl-tls-service-profile <value> set global-protect global-protect-portal <name> portal-config client-auth set global-protect global-protect-portal <name> portal-config client-auth <name> set global-protect global-protect-portal <name> portal-config client-auth <name> os <value>|<Any|Browser|Satellite> set global-protect global-protect-portal <name> portal-config client-auth <name> authentication-profile <value> set global-protect global-protect-portal <name> portal-config client-auth <name> auto-retrieve-passcode <yes|no> set global-protect global-protect-portal <name> portal-config client-auth <name> username-label <value> set global-protect global-protect-portal <name> portal-config client-auth <name> password-label <value> set global-protect global-protect-portal <name> portal-config client-auth <name> authentication-message <value> set global-protect global-protect-portal <name> portal-config client-auth <name> user-credential-or-client-cert-required <no|yes> set global-protect global-protect-portal <name> portal-config certificate-profile <value> set global-protect global-protect-portal <name> portal-config custom-login-page <value> set global-protect global-protect-portal <name> portal-config custom-home-page <value> set global-protect global-protect-portal <name> portal-config custom-help-page <value> set global-protect global-protect-portal <name> portal-config log-success <yes|no> set global-protect global-protect-portal <name> portal-config log-fail <yes|no> set global-protect global-protect-portal <name> portal-config log-setting <value> set global-protect global-protect-portal <name> portal-config config-selection set global-protect global-protect-portal <name> portal-config config-selection certificate-profile <value> set global-protect global-protect-portal <name> portal-config config-selection custom-checks set global-protect global-protect-portal <name> portal-config config-selection custom-checks windows set global-protect global-protect-portal <name> portal-config config-selection custom-checks windows registry-key set global-protect global-protect-portal <name> portal-config config-selection custom-checks windows registry-key <name> set global-protect global-protect-portal <name> portal-config config-selection custom-checks windows registry-key <name> registry-value [ <registry-value1> <registry-value2>... ] set global-protect global-protect-portal <name> portal-config config-selection custom-checks mac-os set global-protect global-protect-portal <name> portal-config config-selection custom-checks mac-os plist set global-protect global-protect-portal <name> portal-config config-selection custom-checks mac-os plist <name> set global-protect global-protect-portal <name> portal-config config-selection custom-checks mac-os plist <name> key [ <key1> <key2>... ] set global-protect global-protect-portal <name> clientless-vpn set global-protect global-protect-portal <name> clientless-vpn hostname <value> set global-protect global-protect-portal <name> clientless-vpn security-zone <value> set global-protect global-protect-portal <name> clientless-vpn login-lifetime set global-protect global-protect-portal <name> clientless-vpn login-lifetime minutes <60-1440> set global-protect global-protect-portal <name> clientless-vpn login-lifetime hours <1-24> set global-protect global-protect-portal <name> clientless-vpn inactivity-logout set global-protect global-protect-portal <name> clientless-vpn inactivity-logout minutes <5-1440> set global-protect global-protect-portal <name> clientless-vpn inactivity-logout hours <1-24> set global-protect global-protect-portal <name> clientless-vpn max-user <1-30000> set global-protect global-protect-portal <name> clientless-vpn dns-proxy <value> set global-protect global-protect-portal <name> clientless-vpn crypto-settings set global-protect global-protect-portal <name> clientless-vpn crypto-settings ssl-protocol set global-protect global-protect-portal <name> clientless-vpn crypto-settings ssl-protocol min-version <sslv3|tls1-0|tls1-1|tls1-2> set global-protect global-protect-portal <name> clientless-vpn crypto-settings ssl-protocol max-version <sslv3|tls1-0|tls1-1|tls1-2|max> set global-protect global-protect-portal <name> clientless-vpn crypto-settings ssl-protocol keyxchg-algo-rsa <yes|no> set global-protect global-protect-portal <name> clientless-vpn crypto-settings ssl-protocol keyxchg-algo-dhe <yes|no> set global-protect global-protect-portal <name> clientless-vpn crypto-settings ssl-protocol keyxchg-algo-ecdhe <yes|no> set global-protect global-protect-portal <name> clientless-vpn crypto-settings ssl-protocol enc-algo-3des <yes|no> set global-protect global-protect-portal <name> clientless-vpn crypto-settings ssl-protocol enc-algo-rc4 <yes|no> set global-protect global-protect-portal <name> clientless-vpn crypto-settings ssl-protocol enc-algo-aes-128-cbc <yes|no> set global-protect global-protect-portal <name> clientless-vpn crypto-settings ssl-protocol enc-algo-aes-256-cbc <yes|no> set global-protect global-protect-portal <name> clientless-vpn crypto-settings ssl-protocol enc-algo-aes-128-gcm <yes|no> set global-protect global-protect-portal <name> clientless-vpn crypto-settings ssl-protocol enc-algo-aes-256-gcm <yes|no> set global-protect global-protect-portal <name> clientless-vpn crypto-settings ssl-protocol auth-algo-md5 <yes|no> set global-protect global-protect-portal <name> clientless-vpn crypto-settings ssl-protocol auth-algo-sha1 <yes|no> set global-protect global-protect-portal <name> clientless-vpn crypto-settings ssl-protocol auth-algo-sha256 <yes|no> set global-protect global-protect-portal <name> clientless-vpn crypto-settings ssl-protocol auth-algo-sha384 <yes|no> set global-protect global-protect-portal <name> clientless-vpn crypto-settings server-cert-verification set global-protect global-protect-portal <name> clientless-vpn crypto-settings server-cert-verification block-expired-certificate <yes|no> set global-protect global-protect-portal <name> clientless-vpn crypto-settings server-cert-verification block-untrusted-issuer <yes|no> set global-protect global-protect-portal <name> clientless-vpn crypto-settings server-cert-verification block-unknown-cert <yes|no> set global-protect global-protect-portal <name> clientless-vpn crypto-settings server-cert-verification block-timeout-cert <yes|no> set global-protect global-protect-portal <name> clientless-vpn rewrite-exclude-domain-list [ <rewrite-exclude-domain-list1> <rewrite-exclude-domain-list2>... ] set global-protect global-protect-portal <name> clientless-vpn apps-to-user-mapping set global-protect global-protect-portal <name> clientless-vpn apps-to-user-mapping <name> set global-protect global-protect-portal <name> clientless-vpn apps-to-user-mapping <name> source-user [ <source-user1> <source-user2>... ] set global-protect global-protect-portal <name> clientless-vpn apps-to-user-mapping <name> applications [ <applications1> <applications2>... ] set global-protect global-protect-portal <name> clientless-vpn apps-to-user-mapping <name> enable-custom-app-URL-address-bar <yes|no> set global-protect global-protect-portal <name> clientless-vpn apps-to-user-mapping <name> display-global-protect-agent-download-link <yes|no> set global-protect global-protect-portal <name> clientless-vpn proxy-server-setting set global-protect global-protect-portal <name> clientless-vpn proxy-server-setting <name> set global-protect global-protect-portal <name> clientless-vpn proxy-server-setting <name> domains [ <domains1> <domains2>... ] set global-protect global-protect-portal <name> clientless-vpn proxy-server-setting <name> use-proxy <yes|no> set global-protect global-protect-portal <name> clientless-vpn proxy-server-setting <name> proxy-server set global-protect global-protect-portal <name> clientless-vpn proxy-server-setting <name> proxy-server server <value> set global-protect global-protect-portal <name> clientless-vpn proxy-server-setting <name> proxy-server port <1-65535> set global-protect global-protect-portal <name> clientless-vpn proxy-server-setting <name> proxy-server user <value> set global-protect global-protect-portal <name> clientless-vpn proxy-server-setting <name> proxy-server password <value> set global-protect global-protect-portal <name> client-config set global-protect global-protect-portal <name> client-config root-ca set global-protect global-protect-portal <name> client-config root-ca <name> set global-protect global-protect-portal <name> client-config root-ca <name> install-in-cert-store <yes|no> set global-protect global-protect-portal <name> client-config agent-user-override-key <value> set global-protect global-protect-portal <name> client-config configs set global-protect global-protect-portal <name> client-config configs <name> set global-protect global-protect-portal <name> client-config configs <name> save-user-credentials <0|1|2|3> set global-protect global-protect-portal <name> client-config configs <name> portal-2fa <yes|no> set global-protect global-protect-portal <name> client-config configs <name> internal-gateway-2fa <yes|no> set global-protect global-protect-portal <name> client-config configs <name> auto-discovery-external-gateway-2fa <yes|no> set global-protect global-protect-portal <name> client-config configs <name> manual-only-gateway-2fa <yes|no> set global-protect global-protect-portal <name> client-config configs <name> source-user [ <source-user1> <source-user2>... ] set global-protect global-protect-portal <name> client-config configs <name> certificate set global-protect global-protect-portal <name> client-config configs <name> certificate criteria set global-protect global-protect-portal <name> client-config configs <name> certificate criteria certificate-profile <value> set global-protect global-protect-portal <name> client-config configs <name> custom-checks set global-protect global-protect-portal <name> client-config configs <name> custom-checks criteria set global-protect global-protect-portal <name> client-config configs <name> custom-checks criteria registry-key set global-protect global-protect-portal <name> client-config configs <name> custom-checks criteria registry-key <name> set global-protect global-protect-portal <name> client-config configs <name> custom-checks criteria registry-key <name> default-value-data <value> set global-protect global-protect-portal <name> client-config configs <name> custom-checks criteria registry-key <name> negate <yes|no> set global-protect global-protect-portal <name> client-config configs <name> custom-checks criteria registry-key <name> registry-value set global-protect global-protect-portal <name> client-config configs <name> custom-checks criteria registry-key <name> registry-value <name> set global-protect global-protect-portal <name> client-config configs <name> custom-checks criteria registry-key <name> registry-value <name> value-data <value> set global-protect global-protect-portal <name> client-config configs <name> custom-checks criteria registry-key <name> registry-value <name> negate <yes|no> set global-protect global-protect-portal <name> client-config configs <name> custom-checks criteria plist set global-protect global-protect-portal <name> client-config configs <name> custom-checks criteria plist <name> set global-protect global-protect-portal <name> client-config configs <name> custom-checks criteria plist <name> negate <yes|no> set global-protect global-protect-portal <name> client-config configs <name> custom-checks criteria plist <name> key set global-protect global-protect-portal <name> client-config configs <name> custom-checks criteria plist <name> key <name> set global-protect global-protect-portal <name> client-config configs <name> custom-checks criteria plist <name> key <name> value <value> set global-protect global-protect-portal <name> client-config configs <name> custom-checks criteria plist <name> key <name> negate <yes|no> set global-protect global-protect-portal <name> client-config configs <name> machine-account-exists-with-serialno set global-protect global-protect-portal <name> client-config configs <name> machine-account-exists-with-serialno no set global-protect global-protect-portal <name> client-config configs <name> machine-account-exists-with-serialno yes set global-protect global-protect-portal <name> client-config configs <name> refresh-config <yes|no> set global-protect global-protect-portal <name> client-config configs <name> gateways set global-protect global-protect-portal <name> client-config configs <name> gateways internal set global-protect global-protect-portal <name> client-config configs <name> gateways internal list set global-protect global-protect-portal <name> client-config configs <name> gateways internal list <name> set global-protect global-protect-portal <name> client-config configs <name> gateways internal list <name> fqdn <value> set global-protect global-protect-portal <name> client-config configs <name> gateways internal list <name> ip set global-protect global-protect-portal <name> client-config configs <name> gateways internal list <name> ip ipv4 <value> set global-protect global-protect-portal <name> client-config configs <name> gateways internal list <name> ip ipv6 <value> set global-protect global-protect-portal <name> client-config configs <name> gateways internal list <name> source-ip [ <source-ip1> <source-ip2>... ] set global-protect global-protect-portal <name> client-config configs <name> gateways internal dhcp-option-code [ <dhcp-option-code1> <dhcp-option-code2>... ] set global-protect global-protect-portal <name> client-config configs <name> gateways external set global-protect global-protect-portal <name> client-config configs <name> gateways external cutoff-time <0-10> set global-protect global-protect-portal <name> client-config configs <name> gateways external list set global-protect global-protect-portal <name> client-config configs <name> gateways external list <name> set global-protect global-protect-portal <name> client-config configs <name> gateways external list <name> fqdn <value> set global-protect global-protect-portal <name> client-config configs <name> gateways external list <name> ip set global-protect global-protect-portal <name> client-config configs <name> gateways external list <name> ip ipv4 <value> set global-protect global-protect-portal <name> client-config configs <name> gateways external list <name> ip ipv6 <value> set global-protect global-protect-portal <name> client-config configs <name> gateways external list <name> priority-rule set global-protect global-protect-portal <name> client-config configs <name> gateways external list <name> priority-rule <name> set global-protect global-protect-portal <name> client-config configs <name> gateways external list <name> priority-rule <name> priority <0|1|2|3|4|5> set global-protect global-protect-portal <name> client-config configs <name> gateways external list <name> manual <yes|no> set global-protect global-protect-portal <name> client-config configs <name> internal-host-detection set global-protect global-protect-portal <name> client-config configs <name> internal-host-detection ip-address <ip/netmask> set global-protect global-protect-portal <name> client-config configs <name> internal-host-detection hostname <value> set global-protect global-protect-portal <name> client-config configs <name> internal-host-detection-v6 set global-protect global-protect-portal <name> client-config configs <name> internal-host-detection-v6 ip-address <ip/netmask> set global-protect global-protect-portal <name> client-config configs <name> internal-host-detection-v6 hostname <value> set global-protect global-protect-portal <name> client-config configs <name> agent-ui set global-protect global-protect-portal <name> client-config configs <name> agent-ui passcode <value> set global-protect global-protect-portal <name> client-config configs <name> agent-ui uninstall-password <value> set global-protect global-protect-portal <name> client-config configs <name> agent-ui agent-user-override-timeout <0-65535> set global-protect global-protect-portal <name> client-config configs <name> agent-ui max-agent-user-overrides <0-65535> set global-protect global-protect-portal <name> client-config configs <name> agent-ui welcome-page set global-protect global-protect-portal <name> client-config configs <name> agent-ui welcome-page page <value> set global-protect global-protect-portal <name> client-config configs <name> hip-collection set global-protect global-protect-portal <name> client-config configs <name> hip-collection certificate-profile <value> set global-protect global-protect-portal <name> client-config configs <name> hip-collection exclusion set global-protect global-protect-portal <name> client-config configs <name> hip-collection exclusion category set global-protect global-protect-portal <name> client-config configs <name> hip-collection exclusion category <name> set global-protect global-protect-portal <name> client-config configs <name> hip-collection exclusion category <name> vendor set global-protect global-protect-portal <name> client-config configs <name> hip-collection exclusion category <name> vendor <name> set global-protect global-protect-portal <name> client-config configs <name> hip-collection exclusion category <name> vendor <name> product [ <product1> <product2>... ] set global-protect global-protect-portal <name> client-config configs <name> hip-collection custom-checks set global-protect global-protect-portal <name> client-config configs <name> hip-collection custom-checks windows set global-protect global-protect-portal <name> client-config configs <name> hip-collection custom-checks windows registry-key set global-protect global-protect-portal <name> client-config configs <name> hip-collection custom-checks windows registry-key <name> set global-protect global-protect-portal <name> client-config configs <name> hip-collection custom-checks windows registry-key <name> registry-value [ <registry-value1> <registry-value2>... ] set global-protect global-protect-portal <name> client-config configs <name> hip-collection custom-checks windows process-list [ <process-list1> <process-list2>... ] set global-protect global-protect-portal <name> client-config configs <name> hip-collection custom-checks mac-os set global-protect global-protect-portal <name> client-config configs <name> hip-collection custom-checks mac-os plist set global-protect global-protect-portal <name> client-config configs <name> hip-collection custom-checks mac-os plist <name> set global-protect global-protect-portal <name> client-config configs <name> hip-collection custom-checks mac-os plist <name> key [ <key1> <key2>... ] set global-protect global-protect-portal <name> client-config configs <name> hip-collection custom-checks mac-os process-list [ <process-list1> <process-list2>... ] set global-protect global-protect-portal <name> client-config configs <name> hip-collection custom-checks linux set global-protect global-protect-portal <name> client-config configs <name> hip-collection custom-checks linux process-list [ <process-list1> <process-list2>... ] set global-protect global-protect-portal <name> client-config configs <name> hip-collection max-wait-time <10-60> set global-protect global-protect-portal <name> client-config configs <name> hip-collection collect-hip-data <yes|no> set global-protect global-protect-portal <name> client-config configs <name> third-party-vpn-clients [ <third-party-vpn-clients1> <third-party-vpn-clients2>... ] set global-protect global-protect-portal <name> client-config configs <name> agent-config set global-protect global-protect-portal <name> client-config configs <name> gp-app-config set global-protect global-protect-portal <name> client-config configs <name> gp-app-config config set global-protect global-protect-portal <name> client-config configs <name> gp-app-config config <name> set global-protect global-protect-portal <name> client-config configs <name> gp-app-config config <name> value [ <value1> <value2>... ] set global-protect global-protect-portal <name> client-config configs <name> os [ <os1> <os2>... ] set global-protect global-protect-portal <name> client-config configs <name> mdm-address <value> set global-protect global-protect-portal <name> client-config configs <name> mdm-enrollment-port <443|7443|8443> set global-protect global-protect-portal <name> client-config configs <name> client-certificate set global-protect global-protect-portal <name> client-config configs <name> client-certificate local <value> set global-protect global-protect-portal <name> client-config configs <name> client-certificate scep <value> set global-protect global-protect-portal <name> client-config configs <name> authentication-override set global-protect global-protect-portal <name> client-config configs <name> authentication-override generate-cookie <yes|no> set global-protect global-protect-portal <name> client-config configs <name> authentication-override accept-cookie set global-protect global-protect-portal <name> client-config configs <name> authentication-override accept-cookie cookie-lifetime set global-protect global-protect-portal <name> client-config configs <name> authentication-override accept-cookie cookie-lifetime lifetime-in-days <1-365> set global-protect global-protect-portal <name> client-config configs <name> authentication-override accept-cookie cookie-lifetime lifetime-in-hours <1-72> set global-protect global-protect-portal <name> client-config configs <name> authentication-override accept-cookie cookie-lifetime lifetime-in-minutes <1-59> set global-protect global-protect-portal <name> client-config configs <name> authentication-override cookie-encrypt-decrypt-cert <value> set global-protect global-protect-portal <name> satellite-config set global-protect global-protect-portal <name> satellite-config root-ca [ <root-ca1> <root-ca2>... ] set global-protect global-protect-portal <name> satellite-config client-certificate set global-protect global-protect-portal <name> satellite-config client-certificate local set global-protect global-protect-portal <name> satellite-config client-certificate local issuing-certificate <value> set global-protect global-protect-portal <name> satellite-config client-certificate local ocsp-responder <value> set global-protect global-protect-portal <name> satellite-config client-certificate local certificate-life-time <7-365> set global-protect global-protect-portal <name> satellite-config client-certificate local certificate-renewal-period <3-30> set global-protect global-protect-portal <name> satellite-config client-certificate scep set global-protect global-protect-portal <name> satellite-config client-certificate scep scep <value> set global-protect global-protect-portal <name> satellite-config client-certificate scep certificate-renewal-period <3-30> set global-protect global-protect-portal <name> satellite-config configs set global-protect global-protect-portal <name> satellite-config configs <name> set global-protect global-protect-portal <name> satellite-config configs <name> devices [ <devices1> <devices2>... ] set global-protect global-protect-portal <name> satellite-config configs <name> source-user [ <source-user1> <source-user2>... ] set global-protect global-protect-portal <name> satellite-config configs <name> gateways set global-protect global-protect-portal <name> satellite-config configs <name> gateways <name> set global-protect global-protect-portal <name> satellite-config configs <name> gateways <name> fqdn <value> set global-protect global-protect-portal <name> satellite-config configs <name> gateways <name> ip set global-protect global-protect-portal <name> satellite-config configs <name> gateways <name> ip ipv4 <value> set global-protect global-protect-portal <name> satellite-config configs <name> gateways <name> ip ipv6 <value> set global-protect global-protect-portal <name> satellite-config configs <name> gateways <name> ipv6-preferred <yes|no> set global-protect global-protect-portal <name> satellite-config configs <name> gateways <name> priority <1-25> set global-protect global-protect-portal <name> satellite-config configs <name> config-refresh-interval <1-48> set global-protect global-protect-gateway set global-protect global-protect-gateway <name> set global-protect global-protect-gateway <name> remote-user-tunnel <value> set global-protect global-protect-gateway <name> remote-user-tunnel-configs set global-protect global-protect-gateway <name> remote-user-tunnel-configs <name> set global-protect global-protect-gateway <name> remote-user-tunnel-configs <name> source-user [ <source-user1> <source-user2>... ] set global-protect global-protect-gateway <name> remote-user-tunnel-configs <name> authentication-override set global-protect global-protect-gateway <name> remote-user-tunnel-configs <name> authentication-override generate-cookie <yes|no> set global-protect global-protect-gateway <name> remote-user-tunnel-configs <name> authentication-override accept-cookie set global-protect global-protect-gateway <name> remote-user-tunnel-configs <name> authentication-override accept-cookie cookie-lifetime set global-protect global-protect-gateway <name> remote-user-tunnel-configs <name> authentication-override accept-cookie cookie-lifetime lifetime-in-days <1-365> set global-protect global-protect-gateway <name> remote-user-tunnel-configs <name> authentication-override accept-cookie cookie-lifetime lifetime-in-hours <1-72> set global-protect global-protect-gateway <name> remote-user-tunnel-configs <name> authentication-override accept-cookie cookie-lifetime lifetime-in-minutes <1-59> set global-protect global-protect-gateway <name> remote-user-tunnel-configs <name> authentication-override cookie-encrypt-decrypt-cert <value> set global-protect global-protect-gateway <name> remote-user-tunnel-configs <name> os [ <os1> <os2>... ] set global-protect global-protect-gateway <name> remote-user-tunnel-configs <name> source-address set global-protect global-protect-gateway <name> remote-user-tunnel-configs <name> source-address region [ <region1> <region2>... ] set global-protect global-protect-gateway <name> remote-user-tunnel-configs <name> source-address ip-address [ <ip-address1> <ip-address2>... ] set global-protect global-protect-gateway <name> remote-user-tunnel-configs <name> dns-server [ <dns-server1> <dns-server2>... ] set global-protect global-protect-gateway <name> remote-user-tunnel-configs <name> dns-suffix [ <dns-suffix1> <dns-suffix2>... ] set global-protect global-protect-gateway <name> remote-user-tunnel-configs <name> ip-pool [ <ip-pool1> <ip-pool2>... ] set global-protect global-protect-gateway <name> remote-user-tunnel-configs <name> split-tunneling set global-protect global-protect-gateway <name> remote-user-tunnel-configs <name> split-tunneling access-route [ <access-route1> <access-route2>... ] set global-protect global-protect-gateway <name> remote-user-tunnel-configs <name> split-tunneling exclude-access-route [ <exclude-access-route1> <exclude-access-route2>... ] set global-protect global-protect-gateway <name> remote-user-tunnel-configs <name> split-tunneling include-applications [ <include-applications1> <include-applications2>... ] set global-protect global-protect-gateway <name> remote-user-tunnel-configs <name> split-tunneling include-domains set global-protect global-protect-gateway <name> remote-user-tunnel-configs <name> split-tunneling include-domains list set global-protect global-protect-gateway <name> remote-user-tunnel-configs <name> split-tunneling include-domains list <name> set global-protect global-protect-gateway <name> remote-user-tunnel-configs <name> split-tunneling include-domains list <name> ports [ <ports1> <ports2>... ] set global-protect global-protect-gateway <name> remote-user-tunnel-configs <name> split-tunneling exclude-applications [ <exclude-applications1> <exclude-applications2>... ] set global-protect global-protect-gateway <name> remote-user-tunnel-configs <name> split-tunneling exclude-domains set global-protect global-protect-gateway <name> remote-user-tunnel-configs <name> split-tunneling exclude-domains list set global-protect global-protect-gateway <name> remote-user-tunnel-configs <name> split-tunneling exclude-domains list <name> set global-protect global-protect-gateway <name> remote-user-tunnel-configs <name> split-tunneling exclude-domains list <name> ports [ <ports1> <ports2>... ] set global-protect global-protect-gateway <name> remote-user-tunnel-configs <name> no-direct-access-to-local-network <yes|no> set global-protect global-protect-gateway <name> remote-user-tunnel-configs <name> retrieve-framed-ip-address <yes|no> set global-protect global-protect-gateway <name> remote-user-tunnel-configs <name> authentication-server-ip-pool [ <authentication-server-ip-pool1> <authentication-server-ip-pool2>... ] set global-protect global-protect-gateway <name> ssl-tls-service-profile <value> set global-protect global-protect-gateway <name> client-auth set global-protect global-protect-gateway <name> client-auth <name> set global-protect global-protect-gateway <name> client-auth <name> os <value>|<Any|Satellite|X-Auth> set global-protect global-protect-gateway <name> client-auth <name> authentication-profile <value> set global-protect global-protect-gateway <name> client-auth <name> auto-retrieve-passcode <yes|no> set global-protect global-protect-gateway <name> client-auth <name> username-label <value> set global-protect global-protect-gateway <name> client-auth <name> password-label <value> set global-protect global-protect-gateway <name> client-auth <name> authentication-message <value> set global-protect global-protect-gateway <name> client-auth <name> user-credential-or-client-cert-required <no|yes> set global-protect global-protect-gateway <name> certificate-profile <value> set global-protect global-protect-gateway <name> satellite-tunnel <value> set global-protect global-protect-gateway <name> tunnel-mode <yes|no> set global-protect global-protect-gateway <name> local-address set global-protect global-protect-gateway <name> local-address ip-address-family <ipv4|ipv6|ipv4_ipv6> set global-protect global-protect-gateway <name> local-address interface <value> set global-protect global-protect-gateway <name> local-address ip set global-protect global-protect-gateway <name> local-address ip ipv4 <value> set global-protect global-protect-gateway <name> local-address ip ipv6 <value> set global-protect global-protect-gateway <name> local-address floating-ip set global-protect global-protect-gateway <name> local-address floating-ip ipv4 <value> set global-protect global-protect-gateway <name> local-address floating-ip ipv6 <value> set global-protect global-protect-gateway <name> security-restrictions set global-protect global-protect-gateway <name> security-restrictions disallow-automatic-restoration <yes|no> set global-protect global-protect-gateway <name> security-restrictions source-ip-enforcement set global-protect global-protect-gateway <name> security-restrictions source-ip-enforcement enable <yes|no> set global-protect global-protect-gateway <name> security-restrictions source-ip-enforcement default set global-protect global-protect-gateway <name> security-restrictions source-ip-enforcement custom set global-protect global-protect-gateway <name> security-restrictions source-ip-enforcement custom source-ipv4-netmask <0-32> set global-protect global-protect-gateway <name> security-restrictions source-ip-enforcement custom source-ipv6-netmask <0-128> set global-protect global-protect-gateway <name> block-quarantined-devices <yes|no> set global-protect global-protect-gateway <name> roles set global-protect global-protect-gateway <name> roles <name> set global-protect global-protect-gateway <name> roles <name> login-lifetime set global-protect global-protect-gateway <name> roles <name> login-lifetime minutes <120-43200> set global-protect global-protect-gateway <name> roles <name> login-lifetime hours <2-720> set global-protect global-protect-gateway <name> roles <name> login-lifetime days <1-30> set global-protect global-protect-gateway <name> roles <name> inactivity-logout <5-43200> set global-protect global-protect-gateway <name> hip-notification set global-protect global-protect-gateway <name> hip-notification <name> set global-protect global-protect-gateway <name> hip-notification <name> match-message set global-protect global-protect-gateway <name> hip-notification <name> match-message include-app-list <yes|no> set global-protect global-protect-gateway <name> hip-notification <name> match-message show-notification-as <system-tray-balloon|pop-up-message> set global-protect global-protect-gateway <name> hip-notification <name> match-message message <value> set global-protect global-protect-gateway <name> hip-notification <name> not-match-message set global-protect global-protect-gateway <name> hip-notification <name> not-match-message show-notification-as <system-tray-balloon|pop-up-message> set global-protect global-protect-gateway <name> hip-notification <name> not-match-message message <value> set global-protect global-protect-gateway <name> log-success <yes|no> set global-protect global-protect-gateway <name> log-fail <yes|no> set global-protect global-protect-gateway <name> log-setting <value> set global-protect global-protect-mdm set global-protect global-protect-mdm <name> set global-protect global-protect-mdm <name> disabled <yes|no> set global-protect global-protect-mdm <name> host <value> set global-protect global-protect-mdm <name> port <1-65535> set global-protect global-protect-mdm <name> root-ca [ <root-ca1> <root-ca2>... ] set global-protect global-protect-mdm <name> client-certificate <value> set global-protect clientless-app set global-protect clientless-app <name> set global-protect clientless-app <name> application-home-url <value> set global-protect clientless-app <name> description <value> set global-protect clientless-app <name> app-icon <value> set global-protect clientless-app-group set global-protect clientless-app-group <name> set global-protect clientless-app-group <name> members [ <members1> <members2>... ]
There are 612 new set profiles commands.
set profiles set profiles hip-objects set profiles hip-objects<name> set profiles hip-objects <name> description <value> set profiles hip-objects <name> host-info set profiles hip-objects <name> host-info criteria set profiles hip-objects <name> host-info criteria domain set profiles hip-objects <name> host-info criteria domain contains <value> set profiles hip-objects <name> host-info criteria domain is <value> set profiles hip-objects <name> host-info criteria domain is-not <value> set profiles hip-objects <name> host-info criteria os set profiles hip-objects <name> host-info criteria os contains set profiles hip-objects <name> host-info criteria os contains Microsoft <value> set profiles hip-objects <name> host-info criteria os contains Apple <value> set profiles hip-objects <name> host-info criteria os contains Google <value> set profiles hip-objects <name> host-info criteria os contains Linux <value> set profiles hip-objects <name> host-info criteria os contains Other <value> set profiles hip-objects <name> host-info criteria client-version set profiles hip-objects <name> host-info criteria client-version contains <value> set profiles hip-objects <name> host-info criteria client-version is <value> set profiles hip-objects <name> host-info criteria client-version is-not <value> set profiles hip-objects <name> host-info criteria host-name set profiles hip-objects <name> host-info criteria host-name contains <value> set profiles hip-objects <name> host-info criteria host-name is <value> set profiles hip-objects <name> host-info criteria host-name is-not <value> set profiles hip-objects <name> host-info criteria host-id set profiles hip-objects <name> host-info criteria host-id contains <value> set profiles hip-objects <name> host-info criteria host-id is <value> set profiles hip-objects <name> host-info criteria host-id is-not <value> set profiles hip-objects <name> host-info criteria managed <no|yes> set profiles hip-objects <name> host-info criteria serial-number set profiles hip-objects <name> host-info criteria serial-number contains <value> set profiles hip-objects <name> host-info criteria serial-number is <value> set profiles hip-objects <name> host-info criteria serial-number is-not <value> set profiles hip-objects <name> network-info set profiles hip-objects <name> network-info criteria set profiles hip-objects <name> network-info criteria network set profiles hip-objects <name> network-info criteria network is set profiles hip-objects <name> network-info criteria network is wifi set profiles hip-objects <name> network-info criteria network is wifi ssid <value> set profiles hip-objects <name> network-info criteria network is mobile set profiles hip-objects <name> network-info criteria network is mobile carrier <value> set profiles hip-objects <name> network-info criteria network is unknown set profiles hip-objects <name> network-info criteria network is-not set profiles hip-objects <name> network-info criteria network is-not wifi set profiles hip-objects <name> network-info criteria network is-not wifi ssid <value> set profiles hip-objects <name> network-info criteria network is-not mobile set profiles hip-objects <name> network-info criteria network is-not mobile carrier <value> set profiles hip-objects <name> network-info criteria network is-not ethernet set profiles hip-objects <name> network-info criteria network is-not unknown set profiles hip-objects <name> patch-management set profiles hip-objects <name> patch-management criteria set profiles hip-objects <name> patch-management criteria is-installed <yes|no> set profiles hip-objects <name> patch-management criteria is-enabled <no|yes|not-available> set profiles hip-objects <name> patch-management criteria missing-patches set profiles hip-objects <name> patch-management criteria missing-patches severity set profiles hip-objects <name> patch-management criteria missing-patches severity greater-equal <0-100000> set profiles hip-objects <name> patch-management criteria missing-patches severity greater-than <0-100000> set profiles hip-objects <name> patch-management criteria missing-patches severity is <0-100000> set profiles hip-objects <name> patch-management criteria missing-patches severity is-not <0-100000> set profiles hip-objects <name> patch-management criteria missing-patches severity less-equal <0-100000> set profiles hip-objects <name> patch-management criteria missing-patches severity less-than <0-100000> set profiles hip-objects <name> patch-management criteria missing-patches patches [ <patches1> <patches2>... ] set profiles hip-objects <name> patch-management criteria missing-patches check <has-any|has-none|has-all> set profiles hip-objects <name> patch-management vendor set profiles hip-objects <name> patch-management vendor <name> set profiles hip-objects <name> patch-management vendor <name> product [ <product1> <product2>... ] set profiles hip-objects <name> patch-management exclude-vendor <yes|no> set profiles hip-objects <name> data-loss-prevention set profiles hip-objects <name> data-loss-prevention criteria set profiles hip-objects <name> data-loss-prevention criteria is-installed <yes|no> set profiles hip-objects <name> data-loss-prevention criteria is-enabled <no|yes|not-available> set profiles hip-objects <name> data-loss-prevention vendor set profiles hip-objects <name> data-loss-prevention vendor <name> set profiles hip-objects <name> data-loss-prevention vendor <name> product [ <product1> <product2>... ] set profiles hip-objects <name> data-loss-prevention exclude-vendor <yes|no> set profiles hip-objects <name> firewall set profiles hip-objects <name> firewall criteria set profiles hip-objects <name> firewall criteria is-installed <yes|no> set profiles hip-objects <name> firewall criteria is-enabled <no|yes|not-available> set profiles hip-objects <name> firewall vendor set profiles hip-objects <name> firewall vendor <name> set profiles hip-objects <name> firewall vendor <name> product [ <product1> <product2>... ] set profiles hip-objects <name> firewall exclude-vendor <yes|no> set profiles hip-objects <name> anti-malware set profiles hip-objects <name> anti-malware criteria set profiles hip-objects <name> anti-malware criteria virdef-version set profiles hip-objects <name> anti-malware criteria virdef-version within set profiles hip-objects <name> anti-malware criteria virdef-version within days <1-65535> set profiles hip-objects <name> anti-malware criteria virdef-version within versions <1-65535> set profiles hip-objects <name> anti-malware criteria virdef-version not-within set profiles hip-objects <name> anti-malware criteria virdef-version not-within days <1-65535> set profiles hip-objects <name> anti-malware criteria virdef-version not-within versions <1-65535> set profiles hip-objects <name> anti-malware criteria product-version set profiles hip-objects <name> anti-malware criteria product-version greater-equal <value> set profiles hip-objects <name> anti-malware criteria product-version greater-than <value> set profiles hip-objects <name> anti-malware criteria product-version is <value> set profiles hip-objects <name> anti-malware criteria product-version is-not <value> set profiles hip-objects <name> anti-malware criteria product-version less-equal <value> set profiles hip-objects <name> anti-malware criteria product-version less-than <value> set profiles hip-objects <name> anti-malware criteria product-version contains <value> set profiles hip-objects <name> anti-malware criteria product-version within set profiles hip-objects <name> anti-malware criteria product-version within versions <1-1> set profiles hip-objects <name> anti-malware criteria product-version not-within set profiles hip-objects <name> anti-malware criteria product-version not-within versions <1-1> set profiles hip-objects <name> anti-malware criteria is-installed <yes|no> set profiles hip-objects <name> anti-malware criteria real-time-protection <no|yes|not-available> set profiles hip-objects <name> anti-malware criteria last-scan-time set profiles hip-objects <name> anti-malware criteria last-scan-time not-available set profiles hip-objects <name> anti-malware criteria last-scan-time within set profiles hip-objects <name> anti-malware criteria last-scan-time within days <1-65535> set profiles hip-objects <name> anti-malware criteria last-scan-time within hours <1-65535> set profiles hip-objects <name> anti-malware criteria last-scan-time not-within set profiles hip-objects <name> anti-malware criteria last-scan-time not-within days <1-65535> set profiles hip-objects <name> anti-malware criteria last-scan-time not-within hours <1-65535> set profiles hip-objects <name> anti-malware vendor set profiles hip-objects <name> anti-malware vendor <name> set profiles hip-objects <name> anti-malware vendor <name> product [ <product1> <product2>... ] set profiles hip-objects <name> anti-malware exclude-vendor <yes|no> set profiles hip-objects <name> disk-backup set profiles hip-objects <name> disk-backup criteria set profiles hip-objects <name> disk-backup criteria is-installed <yes|no> set profiles hip-objects <name> disk-backup criteria last-backup-time set profiles hip-objects <name> disk-backup criteria last-backup-time not-available set profiles hip-objects <name> disk-backup criteria last-backup-time within set profiles hip-objects <name> disk-backup criteria last-backup-time within days <1-65535> set profiles hip-objects <name> disk-backup criteria last-backup-time within hours <1-65535> set profiles hip-objects <name> disk-backup criteria last-backup-time not-within set profiles hip-objects <name> disk-backup criteria last-backup-time not-within days <1-65535> set profiles hip-objects <name> disk-backup criteria last-backup-time not-within hours <1-65535> set profiles hip-objects <name> disk-backup vendor set profiles hip-objects <name> disk-backup vendor <name> set profiles hip-objects <name> disk-backup vendor <name> product [ <product1> <product2>... ] set profiles hip-objects <name> disk-backup exclude-vendor <yes|no> set profiles hip-objects <name> disk-encryption set profiles hip-objects <name> disk-encryption criteria set profiles hip-objects <name> disk-encryption criteria is-installed <yes|no> set profiles hip-objects <name> disk-encryption criteria encrypted-locations set profiles hip-objects <name> disk-encryption criteria encrypted-locations <name> set profiles hip-objects <name> disk-encryption criteria encrypted-locations <name> encryption-state set profiles hip-objects <name> disk-encryption criteria encrypted-locations <name> encryption-state is <encrypted|unencrypted|partial|unknown> set profiles hip-objects <name> disk-encryption criteria encrypted-locations <name> encryption-state is-not <encrypted|unencrypted|partial|unknown> set profiles hip-objects <name> disk-encryption vendor set profiles hip-objects <name> disk-encryption vendor <name> set profiles hip-objects <name> disk-encryption vendor <name> product [ <product1> <product2>... ] set profiles hip-objects <name> disk-encryption exclude-vendor <yes|no> set profiles hip-objects <name> custom-checks set profiles hip-objects <name> custom-checks criteria set profiles hip-objects <name> custom-checks criteria process-list set profiles hip-objects <name> custom-checks criteria process-list <name> set profiles hip-objects <name> custom-checks criteria process-list <name> running <yes|no> set profiles hip-objects <name> custom-checks criteria registry-key set profiles hip-objects <name> custom-checks criteria registry-key <name> set profiles hip-objects <name> custom-checks criteria registry-key <name> default-value-data <value> set profiles hip-objects <name> custom-checks criteria registry-key <name> negate <yes|no> set profiles hip-objects <name> custom-checks criteria registry-key <name> registry-value set profiles hip-objects <name> custom-checks criteria registry-key <name> registry-value <name> set profiles hip-objects <name> custom-checks criteria registry-key <name> registry-value <name> value-data <value> set profiles hip-objects <name> custom-checks criteria registry-key <name> registry-value <name> negate <yes|no> set profiles hip-objects <name> custom-checks criteria plist set profiles hip-objects <name> custom-checks criteria plist <name> set profiles hip-objects <name> custom-checks criteria plist <name> negate <yes|no> set profiles hip-objects <name> custom-checks criteria plist <name> key set profiles hip-objects <name> custom-checks criteria plist <name> key <name> set profiles hip-objects <name> custom-checks criteria plist <name> key <name> value <value> set profiles hip-objects <name> custom-checks criteria plist <name> key <name> negate <yes|no> set profiles hip-objects <name> mobile-device set profiles hip-objects <name> mobile-device criteria set profiles hip-objects <name> mobile-device criteria jailbroken <no|yes> set profiles hip-objects <name> mobile-device criteria disk-encrypted <no|yes> set profiles hip-objects <name> mobile-device criteria passcode-set <no|yes> set profiles hip-objects <name> mobile-device criteria last-checkin-time set profiles hip-objects <name> mobile-device criteria last-checkin-time within set profiles hip-objects <name> mobile-device criteria last-checkin-time within days <1-365> set profiles hip-objects <name> mobile-device criteria last-checkin-time not-within set profiles hip-objects <name> mobile-device criteria last-checkin-time not-within days <1-365> set profiles hip-objects <name> mobile-device criteria imei set profiles hip-objects <name> mobile-device criteria imei contains <value> set profiles hip-objects <name> mobile-device criteria imei is <value> set profiles hip-objects <name> mobile-device criteria imei is-not <value> set profiles hip-objects <name> mobile-device criteria model set profiles hip-objects <name> mobile-device criteria model contains <value> set profiles hip-objects <name> mobile-device criteria model is <value> set profiles hip-objects <name> mobile-device criteria model is-not <value> set profiles hip-objects <name> mobile-device criteria phone-number set profiles hip-objects <name> mobile-device criteria phone-number contains <value> set profiles hip-objects <name> mobile-device criteria phone-number is <value> set profiles hip-objects <name> mobile-device criteria phone-number is-not <value> set profiles hip-objects <name> mobile-device criteria tag set profiles hip-objects <name> mobile-device criteria tag contains <value> set profiles hip-objects <name> mobile-device criteria tag is <value> set profiles hip-objects <name> mobile-device criteria tag is-not <value> set profiles hip-objects <name> mobile-device criteria applications set profiles hip-objects <name> mobile-device criteria applications has-malware set profiles hip-objects <name> mobile-device criteria applications has-malware no set profiles hip-objects <name> mobile-device criteria applications has-malware yes set profiles hip-objects <name> mobile-device criteria applications has-malware yes excludes set profiles hip-objects <name> mobile-device criteria applications has-malware yes excludes <name> set profiles hip-objects <name> mobile-device criteria applications has-malware yes excludes <name> package <value> set profiles hip-objects <name> mobile-device criteria applications has-malware yes excludes <name> hash <value> set profiles hip-objects <name> mobile-device criteria applications has-unmanaged-app <no|yes> set profiles hip-objects <name> mobile-device criteria applications includes set profiles hip-objects <name> mobile-device criteria applications includes <name> set profiles hip-objects <name> mobile-device criteria applications includes <name> package <value> set profiles hip-objects <name> mobile-device criteria applications includes <name> hash <value> set profiles hip-objects <name> certificate set profiles hip-objects <name> certificate criteria set profiles hip-objects <name> certificate criteria certificate-profile <value> set profiles hip-objects <name> certificate criteria certificate-attributes set profiles hip-objects <name> certificate criteria certificate-attributes <name> set profiles hip-objects <name> certificate criteria certificate-attributes <name> value <value> set profiles virus set profiles virus <name> set profiles virus <name> description <value> set profiles virus <name> packet-capture <yes|no> set profiles virus <name> mlav-engine-filebased-enabled set profiles virus <name> mlav-engine-filebased-enabled <name> set profiles virus <name> mlav-engine-filebased-enabled <name> mlav-policy-action <enable|enable(alert-only)|disable> set profiles virus <name> decoder set profiles virus <name> decoder <name> set profiles virus <name> decoder <name> action <default|allow|alert|drop|reset-client|reset-server|reset-both> set profiles virus <name> decoder <name> wildfire-action <default|allow|alert|drop|reset-client|reset-server|reset-both> set profiles virus <name> decoder <name> mlav-action <default|allow|alert|drop|reset-client|reset-server|reset-both> set profiles virus <name> application set profiles virus <name> application <name> set profiles virus <name> application <name> action <default|allow|alert|drop|reset-client|reset-server|reset-both> set profiles virus <name> threat-exception set profiles virus <name> threat-exception <name> set profiles virus <name> mlav-exception set profiles virus <name> mlav-exception <name> set profiles virus <name> mlav-exception <name> filename <value> set profiles virus <name> mlav-exception <name> description <value> set profiles spyware set profiles spyware <name> set profiles spyware <name> description <value> set profiles spyware <name> botnet-domains set profiles spyware <name> botnet-domains lists set profiles spyware <name> botnet-domains lists <name> set profiles spyware <name> botnet-domains lists <name> action set profiles spyware <name> botnet-domains lists <name> action alert set profiles spyware <name> botnet-domains lists <name> action allow set profiles spyware <name> botnet-domains lists <name> action block set profiles spyware <name> botnet-domains lists <name> action sinkhole set profiles spyware <name> botnet-domains lists <name> packet-capture <disable|single-packet|extended-capture> set profiles spyware <name> botnet-domains dns-security-categories set profiles spyware <name> botnet-domains dns-security-categories <name> set profiles spyware <name> botnet-domains dns-security-categories <name> action <default|allow|block|sinkhole> set profiles spyware <name> botnet-domains dns-security-categories <name> log-level <default|none|low|informational|medium|high|critical> set profiles spyware <name> botnet-domains dns-security-categories <name> packet-capture <disable|single-packet|extended-capture> set profiles spyware <name> botnet-domains whitelist set profiles spyware <name> botnet-domains whitelist <name> set profiles spyware <name> botnet-domains whitelist <name> description <value> set profiles spyware <name> botnet-domains sinkhole set profiles spyware <name> botnet-domains sinkhole ipv4-address <value>|<127.0.0.1|pan-sinkhole-default-ip> set profiles spyware <name> botnet-domains sinkhole ipv6-address <ip/netmask>|<::1> set profiles spyware <name> botnet-domains threat-exception set profiles spyware <name> botnet-domains threat-exception <name> set profiles spyware <name> rules set profiles spyware <name> rules <name> set profiles spyware <name> rules <name> threat-name <value>|<any> set profiles spyware <name> rules <name> category <value>|<any> set profiles spyware <name> rules <name> severity [ <severity1> <severity2>... ] set profiles spyware <name> rules <name> action set profiles spyware <name> rules <name> action default set profiles spyware <name> rules <name> action allow set profiles spyware <name> rules <name> action alert set profiles spyware <name> rules <name> action drop set profiles spyware <name> rules <name> action reset-client set profiles spyware <name> rules <name> action reset-server set profiles spyware <name> rules <name> action reset-both set profiles spyware <name> rules <name> action block-ip set profiles spyware <name> rules <name> action block-ip track-by <source|source-and-destination> set profiles spyware <name> rules <name> action block-ip duration <1-3600> set profiles spyware <name> rules <name> packet-capture <disable|single-packet|extended-capture> set profiles spyware <name> threat-exception set profiles spyware <name> threat-exception <name> set profiles spyware <name> threat-exception <name> packet-capture <disable|single-packet|extended-capture> set profiles spyware <name> threat-exception <name> action set profiles spyware <name> threat-exception <name> action default set profiles spyware <name> threat-exception <name> action allow set profiles spyware <name> threat-exception <name> action alert set profiles spyware <name> threat-exception <name> action drop set profiles spyware <name> threat-exception <name> action reset-both set profiles spyware <name> threat-exception <name> action reset-client set profiles spyware <name> threat-exception <name> action reset-server set profiles spyware <name> threat-exception <name> action block-ip set profiles spyware <name> threat-exception <name> action block-ip track-by <source|source-and-destination> set profiles spyware <name> threat-exception <name> action block-ip duration <1-3600> set profiles spyware <name> threat-exception <name> exempt-ip set profiles spyware <name> threat-exception <name> exempt-ip <name> set profiles spyware <name> cloud-inline-analysis <yes|no> set profiles spyware <name> mica-engine-spyware-enabled set profiles spyware <name> mica-engine-spyware-enabled <name> set profiles spyware <name> mica-engine-spyware-enabled <name> inline-policy-action <drop|alert|allow|reset-both|reset-client|reset-server> set profiles spyware <name> inline-exception-edl-url [ <inline-exception-edl-url1> <inline-exception-edl-url2>... ] set profiles spyware <name> inline-exception-ip-address [ <inline-exception-ip-address1> <inline-exception-ip-address2>... ] set profiles vulnerability set profiles vulnerability <name> set profiles vulnerability <name> description <value> set profiles vulnerability <name> rules set profiles vulnerability <name> rules <name> set profiles vulnerability <name> rules <name> threat-name <value>|<any> set profiles vulnerability <name> rules <name> cve [ <cve1> <cve2>... ] set profiles vulnerability <name> rules <name> host <any|client|server> set profiles vulnerability <name> rules <name> vendor-id [ <vendor-id1> <vendor-id2>... ] set profiles vulnerability <name> rules <name> severity [ <severity1> <severity2>... ] set profiles vulnerability <name> rules <name> category <value>|<any> set profiles vulnerability <name> rules <name> action set profiles vulnerability <name> rules <name> action default set profiles vulnerability <name> rules <name> action allow set profiles vulnerability <name> rules <name> action alert set profiles vulnerability <name> rules <name> action drop set profiles vulnerability <name> rules <name> action reset-client set profiles vulnerability <name> rules <name> action reset-server set profiles vulnerability <name> rules <name> action reset-both set profiles vulnerability <name> rules <name> action block-ip set profiles vulnerability <name> rules <name> action block-ip track-by <source|source-and-destination> set profiles vulnerability <name> rules <name> action block-ip duration <1-3600> set profiles vulnerability <name> rules <name> packet-capture <disable|single-packet|extended-capture> set profiles vulnerability <name> threat-exception set profiles vulnerability <name> threat-exception <name> set profiles vulnerability <name> threat-exception <name> packet-capture <disable|single-packet|extended-capture> set profiles vulnerability <name> threat-exception <name> action set profiles vulnerability <name> threat-exception <name> action default set profiles vulnerability <name> threat-exception <name> action allow set profiles vulnerability <name> threat-exception <name> action alert set profiles vulnerability <name> threat-exception <name> action drop set profiles vulnerability <name> threat-exception <name> action reset-client set profiles vulnerability <name> threat-exception <name> action reset-server set profiles vulnerability <name> threat-exception <name> action reset-both set profiles vulnerability <name> threat-exception <name> action block-ip set profiles vulnerability <name> threat-exception <name> action block-ip track-by <source|source-and-destination> set profiles vulnerability <name> threat-exception <name> action block-ip duration <1-3600> set profiles vulnerability <name> threat-exception <name> time-attribute set profiles vulnerability <name> threat-exception <name> time-attribute interval <1-3600> set profiles vulnerability <name> threat-exception <name> time-attribute threshold <1-65535> set profiles vulnerability <name> threat-exception <name> time-attribute track-by <source|destination|source-and-destination> set profiles vulnerability <name> threat-exception <name> exempt-ip set profiles vulnerability <name> threat-exception <name> exempt-ip <name> set profiles url-filtering set profiles url-filtering <name> set profiles url-filtering <name> description <value> set profiles url-filtering <name> allow [ <allow1> <allow2>... ] set profiles url-filtering <name> alert [ <alert1> <alert2>... ] set profiles url-filtering <name> block [ <block1> <block2>... ] set profiles url-filtering <name> continue [ <continue1> <continue2>... ] set profiles url-filtering <name> override [ <override1> <override2>... ] set profiles url-filtering <name> credential-enforcement set profiles url-filtering <name> credential-enforcement mode set profiles url-filtering <name> credential-enforcement mode disabled set profiles url-filtering <name> credential-enforcement mode ip-user set profiles url-filtering <name> credential-enforcement mode domain-credentials set profiles url-filtering <name> credential-enforcement mode group-mapping <value> set profiles url-filtering <name> credential-enforcement log-severity <value> set profiles url-filtering <name> credential-enforcement allow [ <allow1> <allow2>... ] set profiles url-filtering <name> credential-enforcement alert [ <alert1> <alert2>... ] set profiles url-filtering <name> credential-enforcement block [ <block1> <block2>... ] set profiles url-filtering <name> credential-enforcement continue [ <continue1> <continue2>... ] set profiles url-filtering <name> enable-container-page <yes|no> set profiles url-filtering <name> log-container-page-only <yes|no> set profiles url-filtering <name> safe-search-enforcement <yes|no> set profiles url-filtering <name> log-http-hdr-xff <yes|no> set profiles url-filtering <name> log-http-hdr-user-agent <yes|no> set profiles url-filtering <name> log-http-hdr-referer <yes|no> set profiles url-filtering <name> http-header-insertion set profiles url-filtering <name> http-header-insertion <name> set profiles url-filtering <name> http-header-insertion <name> type set profiles url-filtering <name> http-header-insertion <name> type <name> set profiles url-filtering <name> http-header-insertion <name> type <name> headers set profiles url-filtering <name> http-header-insertion <name> type <name> headers <name> set profiles url-filtering <name> http-header-insertion <name> type <name> headers <name> header <value> set profiles url-filtering <name> http-header-insertion <name> type <name> headers <name> value <value> set profiles url-filtering <name> http-header-insertion <name> type <name> headers <name> log <yes|no> set profiles url-filtering <name> http-header-insertion <name> type <name> domains [ <domains1> <domains2>... ] set profiles url-filtering <name> local-inline-cat <yes|no> set profiles url-filtering <name> cloud-inline-cat <yes|no> set profiles url-filtering <name> mlav-category-exception [ <mlav-category-exception1> <mlav-category-exception2>... ] set profiles file-blocking set profiles file-blocking <name> set profiles file-blocking <name> description <value> set profiles file-blocking <name> rules set profiles file-blocking <name> rules <name> set profiles file-blocking <name> rules <name> application [ <application1> <application2>... ] set profiles file-blocking <name> rules <name> file-type [ <file-type1> <file-type2>... ] set profiles file-blocking <name> rules <name> direction <upload|download|both> set profiles file-blocking <name> rules <name> action <alert|block|continue> set profiles wildfire-analysis set profiles wildfire-analysis <name> set profiles wildfire-analysis <name> description <value> set profiles wildfire-analysis <name> rules set profiles wildfire-analysis <name> rules <name> set profiles wildfire-analysis <name> rules <name> application [ <application1> <application2>... ] set profiles wildfire-analysis <name> rules <name> file-type [ <file-type1> <file-type2>... ] set profiles wildfire-analysis <name> rules <name> direction <upload|download|both> set profiles wildfire-analysis <name> rules <name> analysis <public-cloud|private-cloud> set profiles custom-url-category set profiles custom-url-category <name> set profiles custom-url-category <name> description <value> set profiles custom-url-category <name> list [ <list1> <list2>... ] set profiles custom-url-category <name> type <value> set profiles data-objects set profiles data-objects <name> set profiles data-objects <name> description <value> set profiles data-objects <name> pattern-type set profiles data-objects <name> pattern-type predefined set profiles data-objects <name> pattern-type predefined pattern set profiles data-objects <name> pattern-type predefined pattern <name> set profiles data-objects <name> pattern-type predefined pattern <name> file-type [ <file-type1> <file-type2>... ] set profiles data-objects <name> pattern-type regex set profiles data-objects <name> pattern-type regex pattern set profiles data-objects <name> pattern-type regex pattern <name> set profiles data-objects <name> pattern-type regex pattern <name> file-type [ <file-type1> <file-type2>... ] set profiles data-objects <name> pattern-type regex pattern <name> regex <value> set profiles data-objects <name> pattern-type file-properties set profiles data-objects <name> pattern-type file-properties pattern set profiles data-objects <name> pattern-type file-properties pattern <name> set profiles data-objects <name> pattern-type file-properties pattern <name> file-type <value> set profiles data-objects <name> pattern-type file-properties pattern <name> file-property <value> set profiles data-objects <name> pattern-type file-properties pattern <name> property-value <value> set profiles data-filtering set profiles data-filtering <name> set profiles data-filtering <name> description <value> set profiles data-filtering <name> data-capture <yes|no> set profiles data-filtering <name> rules set profiles data-filtering <name> rules <name> set profiles data-filtering <name> rules <name> data-object <value> set profiles data-filtering <name> rules <name> application [ <application1> <application2>... ] set profiles data-filtering <name> rules <name> file-type [ <file-type1> <file-type2>... ] set profiles data-filtering <name> rules <name> direction <upload|download|both> set profiles data-filtering <name> rules <name> alert-threshold <0-65535> set profiles data-filtering <name> rules <name> block-threshold <0-65535> set profiles data-filtering <name> rules <name> log-severity <value> set profiles hip-profiles set profiles hip-profiles <name> set profiles hip-profiles <name> description <value> set profiles hip-profiles <name> match <value> set profiles dos-protection set profiles dos-protection <name> set profiles dos-protection <name> type <aggregate|classified> set profiles dos-protection <name> description <value> set profiles dos-protection <name> flood set profiles dos-protection <name> flood tcp-syn set profiles dos-protection <name> flood tcp-syn enable <yes|no> set profiles dos-protection <name> flood tcp-syn red set profiles dos-protection <name> flood tcp-syn red alarm-rate <0-2000000> set profiles dos-protection <name> flood tcp-syn red activate-rate <1-2000000> set profiles dos-protection <name> flood tcp-syn red maximal-rate <1-2000000> set profiles dos-protection <name> flood tcp-syn red block set profiles dos-protection <name> flood tcp-syn red block duration <1-21600> set profiles dos-protection <name> flood tcp-syn syn-cookies set profiles dos-protection <name> flood tcp-syn syn-cookies alarm-rate <0-2000000> set profiles dos-protection <name> flood tcp-syn syn-cookies activate-rate <0-2000000> set profiles dos-protection <name> flood tcp-syn syn-cookies maximal-rate <1-2000000> set profiles dos-protection <name> flood tcp-syn syn-cookies block set profiles dos-protection <name> flood tcp-syn syn-cookies block duration <1-21600> set profiles dos-protection <name> flood udp set profiles dos-protection <name> flood udp enable <yes|no> set profiles dos-protection <name> flood udp red set profiles dos-protection <name> flood udp red alarm-rate <0-2000000> set profiles dos-protection <name> flood udp red activate-rate <1-2000000> set profiles dos-protection <name> flood udp red maximal-rate <1-2000000> set profiles dos-protection <name> flood udp red block set profiles dos-protection <name> flood udp red block duration <1-21600> set profiles dos-protection <name> flood icmp set profiles dos-protection <name> flood icmp enable <yes|no> set profiles dos-protection <name> flood icmp red set profiles dos-protection <name> flood icmp red alarm-rate <0-2000000> set profiles dos-protection <name> flood icmp red activate-rate <1-2000000> set profiles dos-protection <name> flood icmp red maximal-rate <1-2000000> set profiles dos-protection <name> flood icmp red block set profiles dos-protection <name> flood icmp red block duration <1-21600> set profiles dos-protection <name> flood icmpv6 set profiles dos-protection <name> flood icmpv6 enable <yes|no> set profiles dos-protection <name> flood icmpv6 red set profiles dos-protection <name> flood icmpv6 red alarm-rate <0-2000000> set profiles dos-protection <name> flood icmpv6 red activate-rate <1-2000000> set profiles dos-protection <name> flood icmpv6 red maximal-rate <1-2000000> set profiles dos-protection <name> flood icmpv6 red block set profiles dos-protection <name> flood icmpv6 red block duration <1-21600> set profiles dos-protection <name> flood other-ip set profiles dos-protection <name> flood other-ip enable <yes|no> set profiles dos-protection <name> flood other-ip red set profiles dos-protection <name> flood other-ip red alarm-rate <0-2000000> set profiles dos-protection <name> flood other-ip red activate-rate <1-2000000> set profiles dos-protection <name> flood other-ip red maximal-rate <1-2000000> set profiles dos-protection <name> flood other-ip red block set profiles dos-protection <name> flood other-ip red block duration <1-21600> set profiles dos-protection <name> resource set profiles dos-protection <name> resource sessions set profiles dos-protection <name> resource sessions enabled <yes|no> set profiles dos-protection <name> resource sessions max-concurrent-limit <1-4194304> set profiles sdwan-path-quality set profiles sdwan-path-quality <name> set profiles sdwan-path-quality <name> metric set profiles sdwan-path-quality <name> metric latency set profiles sdwan-path-quality <name> metric latency threshold <10-3000> set profiles sdwan-path-quality <name> metric latency sensitivity <low|medium|high> set profiles sdwan-path-quality <name> metric pkt-loss set profiles sdwan-path-quality <name> metric pkt-loss threshold <1-100> set profiles sdwan-path-quality <name> metric pkt-loss sensitivity <low|medium|high> set profiles sdwan-path-quality <name> metric jitter set profiles sdwan-path-quality <name> metric jitter threshold <10-2000> set profiles sdwan-path-quality <name> metric jitter sensitivity <low|medium|high> set profiles sdwan-traffic-distribution set profiles sdwan-traffic-distribution <name> set profiles sdwan-traffic-distribution <name> traffic-distribution <Best Available Path|Top Down Priority|Weighted Session Distribution> set profiles sdwan-traffic-distribution <name> link-tags set profiles sdwan-traffic-distribution <name> link-tags <name> set profiles sdwan-traffic-distribution <name> link-tags <name> weight <0-100> set profiles sdwan-saas-quality set profiles sdwan-saas-quality <name> set profiles sdwan-saas-quality <name> monitor-mode set profiles sdwan-saas-quality <name> monitor-mode adaptive set profiles sdwan-saas-quality <name> monitor-mode static-ip set profiles sdwan-saas-quality <name> monitor-mode static-ip ip-address set profiles sdwan-saas-quality <name> monitor-mode static-ip ip-address <name> set profiles sdwan-saas-quality <name> monitor-mode static-ip ip-address <name> probe-interval <1-60> set profiles sdwan-saas-quality <name> monitor-mode static-ip fqdn set profiles sdwan-saas-quality <name> monitor-mode static-ip fqdn fqdn-name <value> set profiles sdwan-saas-quality <name> monitor-mode static-ip fqdn probe-interval <1-60> set profiles sdwan-saas-quality <name> monitor-mode http-https set profiles sdwan-saas-quality <name> monitor-mode http-https monitored-url <value> set profiles sdwan-saas-quality <name> monitor-mode http-https probe-interval <3-60> set profiles sdwan-error-correction set profiles sdwan-error-correction <name> set profiles sdwan-error-correction <name> activation-threshold <1-99> set profiles sdwan-error-correction <name> mode set profiles sdwan-error-correction <name> mode forward-error-correction set profiles sdwan-error-correction <name> mode forward-error-correction ratio <10% (20:2)|20% (20:4)|30% (20:6)|40% (20:8)|50% (20:10)> set profiles sdwan-error-correction <name> mode forward-error-correction recovery-duration <1-5000> set profiles sdwan-error-correction <name> mode packet-duplication set profiles sdwan-error-correction <name> mode packet-duplication recovery-duration-pd <1-5000> set profiles decryption set profiles decryption <name> set profiles decryption <name> interface <value> set profiles decryption <name> forwarded-only <yes|no> set profiles decryption <name> ssl-forward-proxy set profiles decryption <name> ssl-forward-proxy block-expired-certificate <yes|no> set profiles decryption <name> ssl-forward-proxy block-untrusted-issuer <yes|no> set profiles decryption <name> ssl-forward-proxy block-tls13-downgrade-no-resource <yes|no> set profiles decryption <name> ssl-forward-proxy restrict-cert-exts <yes|no> set profiles decryption <name> ssl-forward-proxy block-unsupported-version <yes|no> set profiles decryption <name> ssl-forward-proxy block-unsupported-cipher <yes|no> set profiles decryption <name> ssl-forward-proxy block-client-cert <yes|no> set profiles decryption <name> ssl-forward-proxy block-if-no-resource <yes|no> set profiles decryption <name> ssl-forward-proxy block-if-hsm-unavailable <yes|no> set profiles decryption <name> ssl-forward-proxy block-unknown-cert <yes|no> set profiles decryption <name> ssl-forward-proxy block-timeout-cert <yes|no> set profiles decryption <name> ssl-forward-proxy auto-include-altname <yes|no> set profiles decryption <name> ssl-forward-proxy strip-alpn <yes|no> set profiles decryption <name> ssl-inbound-proxy set profiles decryption <name> ssl-inbound-proxy block-unsupported-version <yes|no> set profiles decryption <name> ssl-inbound-proxy block-unsupported-cipher <yes|no> set profiles decryption <name> ssl-inbound-proxy block-if-no-resource <yes|no> set profiles decryption <name> ssl-inbound-proxy block-tls13-downgrade-no-resource <yes|no> set profiles decryption <name> ssl-inbound-proxy block-if-hsm-unavailable <yes|no> set profiles decryption <name> ssl-protocol-settings set profiles decryption <name> ssl-protocol-settings min-version <sslv3|tls1-0|tls1-1|tls1-2|tls1-3> set profiles decryption <name> ssl-protocol-settings max-version <sslv3|tls1-0|tls1-1|tls1-2|tls1-3|max> set profiles decryption <name> ssl-protocol-settings keyxchg-algo-rsa <yes|no> set profiles decryption <name> ssl-protocol-settings keyxchg-algo-dhe <yes|no> set profiles decryption <name> ssl-protocol-settings keyxchg-algo-ecdhe <yes|no> set profiles decryption <name> ssl-protocol-settings enc-algo-3des <yes|no> set profiles decryption <name> ssl-protocol-settings enc-algo-rc4 <yes|no> set profiles decryption <name> ssl-protocol-settings enc-algo-aes-128-cbc <yes|no> set profiles decryption <name> ssl-protocol-settings enc-algo-aes-256-cbc <yes|no> set profiles decryption <name> ssl-protocol-settings enc-algo-aes-128-gcm <yes|no> set profiles decryption <name> ssl-protocol-settings enc-algo-aes-256-gcm <yes|no> set profiles decryption <name> ssl-protocol-settings enc-algo-chacha20-poly1305 <yes|no> set profiles decryption <name> ssl-protocol-settings auth-algo-md5 <yes|no> set profiles decryption <name> ssl-protocol-settings auth-algo-sha1 <yes|no> set profiles decryption <name> ssl-protocol-settings auth-algo-sha256 <yes|no> set profiles decryption <name> ssl-protocol-settings auth-algo-sha384 <yes|no> set profiles decryption <name> ssl-no-proxy set profiles decryption <name> ssl-no-proxy block-expired-certificate <yes|no> set profiles decryption <name> ssl-no-proxy block-untrusted-issuer <yes|no> set profiles decryption <name> ssh-proxy set profiles decryption <name> ssh-proxy block-unsupported-version <yes|no> set profiles decryption <name> ssh-proxy block-unsupported-alg <yes|no> set profiles decryption <name> ssh-proxy block-ssh-errors <yes|no> set profiles decryption <name> ssh-proxy block-if-no-resource <yes|no> set profiles packet-broker set profiles packet-broker <name> set profiles packet-broker <name> description <value> set profiles packet-broker <name> interface-primary <value> set profiles packet-broker <name> interface-secondary <value> set profiles packet-broker <name> flow <unidirectional|bidirectional> set profiles packet-broker <name> transparent set profiles packet-broker <name> transparent enable-ipv6 <yes|no> set profiles packet-broker <name> routed set profiles packet-broker <name> routed security-chain set profiles packet-broker <name> routed security-chain <name> set profiles packet-broker <name> routed security-chain <name> enable <yes|no> set profiles packet-broker <name> routed security-chain <name> first-device <ip/netmask> set profiles packet-broker <name> routed security-chain <name> first-device-description <value> set profiles packet-broker <name> routed security-chain <name> last-device <ip/netmask> set profiles packet-broker <name> routed security-chain <name> last-device-description <value> set profiles packet-broker <name> routed distribution <round-robin|ip-modulo|ip-hash|lowest-latency> set profiles packet-broker <name> health-check set profiles packet-broker <name> health-check failure-action <bypass|block> set profiles packet-broker <name> health-check failure-condition <any|all> set profiles packet-broker <name> health-check path-enable <yes|no> set profiles packet-broker <name> health-check path-count <1-10> set profiles packet-broker <name> health-check path-interval-s <1-60> set profiles packet-broker <name> health-check path-recovery-hold-s <0-65535> set profiles packet-broker <name> health-check http-enable <yes|no> set profiles packet-broker <name> health-check http-count <1-10> set profiles packet-broker <name> health-check http-interval-s <1-60> set profiles packet-broker <name> health-check http-latency-enable <yes|no> set profiles packet-broker <name> health-check http-latency-maximum-ms <10-65535> set profiles packet-broker <name> health-check http-latency-duration-s <1-65535> set profiles packet-broker <name> health-check http-latency-log-exceeded <yes|no>
There are 9 new set profile-group commands.
set profile-group set profile-group<name> set profile-group <name> virus [ <virus1> <virus2>... ] set profile-group <name> spyware [ <spyware1> <spyware2>... ] set profile-group <name> vulnerability [ <vulnerability1> <vulnerability2>... ] set profile-group <name> url-filtering [ <url-filtering1> <url-filtering2>... ] set profile-group <name> file-blocking [ <file-blocking1> <file-blocking2>... ] set profile-group <name> wildfire-analysis [ <wildfire-analysis1> <wildfire-analysis2>... ] set profile-group <name> data-filtering [ <data-filtering1> <data-filtering2>... ]
There are 25 new set service commands.
set service set service<name> set service <name> description <value> set service <name> protocol set service <name> protocol tcp set service <name> protocol tcp port <0-65535,...> set service <name> protocol tcp source-port <0-65535,...> set service <name> protocol tcp override set service <name> protocol tcp override no set service <name> protocol tcp override yes set service <name> protocol tcp override yes timeout <1-604800> set service <name> protocol tcp override yes halfclose-timeout <1-604800> set service <name> protocol tcp override yes timewait-timeout <1-600> set service <name> protocol udp set service <name> protocol udp port <0-65535,...> set service <name> protocol udp source-port <0-65535,...> set service <name> protocol udp override set service <name> protocol udp override no set service <name> protocol udp override yes set service <name> protocol udp override yes timeout <1-604800> set service <name> tag [ <tag1> <tag2>... ]
There are 4 new set service-group commands.
set service-group set service-group<name> set service-group <name> members [ <members1> <members2>... ] set service-group <name> tag [ <tag1> <tag2>... ]
There are 116 new set reports commands.
set reports set reports<name> set reports <name> description <value> set reports <name> disabled <yes|no> set reports <name> query <value> set reports <name> caption <value> set reports <name> frequency <daily> set reports <name> start-time <value> set reports <name> end-time <value> set reports <name> period <last-15-minutes|last-hour|last-6-hrs|last-12-hrs|last-24-hrs|last-calendar-day|last-7-days|last-7-calendar-days|last-calendar-week|last-30-days|last-30-calendar-days|last-60-days|last-60-calendar-days|last-90-days|last-90-calendar-days|last-calendar-month> set reports <name> topn <1-10000> set reports <name> topm <1-50> set reports <name> type set reports <name> type appstat set reports <name> type appstat aggregate-by [ <aggregate-by1> <aggregate-by2>... ] set reports <name> type appstat group-by <serial|vsys_name|device_name|vsys|name|risk|day-of-receive_time|hour-of-receive_time|quarter-hour-of-receive_time|subcategory-of-name|category-of-name|risk-of-name|container-of-name|technology-of-name> set reports <name> type appstat values [ <values1> <values2>... ] set reports <name> type appstat labels [ <labels1> <labels2>... ] set reports <name> type appstat sortby <nbytes|nsess|npkts|nthreats> set reports <name> type decryption set reports <name> type decryption aggregate-by [ <aggregate-by1> <aggregate-by2>... ] set reports <name> type decryption group-by <serial|time_generated|src|dst|natsrc|natdst|rule|srcuser|dstuser|srcloc|dstloc|app|vsys|from|to|inbound_if|outbound_if|sport|dport|natsport|natdport|proto|action|tunnel|rule_uuid|s_encrypted|category-of-app|subcategory-of-app|technology-of-app|container-of-app|risk-of-app|vsys_name|device_name|tls_version|tls_keyxchg|tls_enc|tls_auth|ec_curve|err_index|root_status|proxy_type|policy_name|cn|issuer_cn|root_cn|sni|error|src_dag|dst_dag|src_edl|dst_edl|container_id|pod_namespace|pod_name|src_category|src_profile|src_model|src_vendor|src_osfamily|src_osversion|src_host|src_mac|dst_category|dst_profile|dst_model|dst_vendor|dst_osfamily|dst_osversion|dst_host|dst_mac|day-of-receive_time|hour-of-receive_time|quarter-hour-of-receive_time> set reports <name> type decryption values [ <values1> <values2>... ] set reports <name> type decryption labels [ <labels1> <labels2>... ] set reports <name> type decryption sortby <repeatcnt|nunique-of-src_profile|nunique-of-dst_profile> set reports <name> type desum set reports <name> type desum aggregate-by [ <aggregate-by1> <aggregate-by2>... ] set reports <name> type desum group-by <serial|time_generated|vsys_name|device_name|category-of-app|subcategory-of-app|technology-of-app|container-of-app|risk-of-app|app|src|dst|srcuser|dstuser|vsys|tls_version|tls_keyxchg|tls_enc|tls_auth|sni|error|err_index|src_edl|dst_edl|container_id|pod_namespace|pod_name|src_category|src_profile|src_model|src_vendor|src_osfamily|src_osversion|src_host|src_mac|dst_category|dst_profile|dst_model|dst_vendor|dst_osfamily|dst_osversion|dst_host|dst_mac|src_dag|dst_dag|day-of-receive_time|hour-of-receive_time|quarter-hour-of-receive_time> set reports <name> type desum values [ <values1> <values2>... ] set reports <name> type desum labels [ <labels1> <labels2>... ] set reports <name> type desum sortby <repeatcnt|nunique-of-src_profile|nunique-of-dst_profile> set reports <name> type threat set reports <name> type threat aggregate-by [ <aggregate-by1> <aggregate-by2>... ] set reports <name> type threat group-by <serial|time_generated|src|dst|natsrc|natdst|rule|srcuser|dstuser|srcloc|dstloc|app|vsys|from|to|inbound_if|outbound_if|sport|dport|natsport|natdport|proto|action|tunnel|rule_uuid|s_encrypted|category-of-app|subcategory-of-app|technology-of-app|container-of-app|risk-of-app|vsys_name|device_name|parent_session_id|parent_start_time|threatid|category|severity|direction|http_method|nssai_sst|filedigest|filetype|http2_connection|xff_ip|threat_name|src_edl|dst_edl|dynusergroup_name|hostid|partial_hash|cloud_reportid|src_category|src_profile|src_model|src_vendor|src_osfamily|src_osversion|src_host|src_mac|dst_category|dst_profile|dst_model|dst_vendor|dst_osfamily|dst_osversion|dst_host|dst_mac|container_id|pod_namespace|pod_name|misc|src_dag|dst_dag|day-of-receive_time|hour-of-receive_time|quarter-hour-of-receive_time|pbf-s2c|pbf-c2s|flag-nat|flag-pcap|subtype|transaction|captive-portal|flag-proxy|non-std-dport|tunnelid|monitortag|users|category-of-threatid|threat-type> set reports <name> type threat values [ <values1> <values2>... ] set reports <name> type threat labels [ <labels1> <labels2>... ] set reports <name> type threat sortby <repeatcnt|nunique-of-users|nunique-of-src_profile|nunique-of-dst_profile> set reports <name> type url set reports <name> type url aggregate-by [ <aggregate-by1> <aggregate-by2>... ] set reports <name> type url group-by <action|app|category|category-of-app|direction|dport|dst|dstuser|from|inbound_if|misc|http_headers|natdport|natdst|natsport|natsrc|outbound_if|proto|risk-of-app|rule|rule_uuid|severity|sport|src|srcuser|subcategory-of-app|technology-of-app|container-of-app|to|dstloc|srcloc|vsys|quarter-hour-of-receive_time|hour-of-receive_time|day-of-receive_time|contenttype|user_agent|device_name|vsys_name|url|tunnelid|monitortag|parent_session_id|parent_start_time|http2_connection|tunnel|http_method|url_category_list|xff_ip|container_id|pod_namespace|pod_name|src_dag|dst_dag|src_edl|dst_edl|src_category|src_profile|src_model|src_vendor|src_osfamily|src_osversion|src_host|src_mac|dst_category|dst_profile|dst_model|dst_vendor|dst_osfamily|dst_osversion|dst_host|dst_mac|cloud_reportid> set reports <name> type url values [ <values1> <values2>... ] set reports <name> type url labels [ <labels1> <labels2>... ] set reports <name> type url sortby <repeatcnt|nunique-of-users> set reports <name> type wildfire set reports <name> type wildfire aggregate-by [ <aggregate-by1> <aggregate-by2>... ] set reports <name> type wildfire group-by <app|category|category-of-app|dport|dst|dstuser|from|inbound_if|misc|natdport|natdst|natsport|natsrc|outbound_if|proto|risk-of-app|rule|rule_uuid|sport|src|srcuser|subcategory-of-app|technology-of-app|container-of-app|to|dstloc|srcloc|vsys|quarter-hour-of-receive_time|hour-of-receive_time|day-of-receive_time|vsys_name|device_name|filetype|filename|filedigest|tunnelid|monitortag|parent_session_id|parent_start_time|http2_connection|tunnel|xff_ip|src_dag|dst_dag|src_edl|dst_edl> set reports <name> type wildfire values [ <values1> <values2>... ] set reports <name> type wildfire labels [ <labels1> <labels2>... ] set reports <name> type wildfire sortby <repeatcnt|nunique-of-users> set reports <name> type data set reports <name> type data aggregate-by [ <aggregate-by1> <aggregate-by2>... ] set reports <name> type data group-by <action|app|category-of-app|direction|dport|dst|dstuser|from|inbound_if|misc|natdport|natdst|natsport|natsrc|outbound_if|proto|risk-of-app|rule|rule_uuid|severity|sport|src|srcuser|subcategory-of-app|subtype|technology-of-app|container-of-app|threatid|to|dstloc|srcloc|vsys|quarter-hour-of-receive_time|hour-of-receive_time|day-of-receive_time|vsys_name|device_name|data-type|filename|tunnelid|monitortag|parent_session_id|parent_start_time|http2_connection|tunnel|xff_ip|src_dag|dst_dag|src_edl|dst_edl|src_category|src_profile|src_model|src_vendor|src_osfamily|src_osversion|src_host|src_mac|dst_category|dst_profile|dst_model|dst_vendor|dst_osfamily|dst_osversion|dst_host|dst_mac> set reports <name> type data values [ <values1> <values2>... ] set reports <name> type data labels [ <labels1> <labels2>... ] set reports <name> type data sortby <repeatcnt|nunique-of-users> set reports <name> type thsum set reports <name> type thsum aggregate-by [ <aggregate-by1> <aggregate-by2>... ] set reports <name> type thsum group-by <serial|time_generated|vsys_name|device_name|app|src|dst|rule|threatid|srcuser|dstuser|srcloc|dstloc|xff_ip|vsys|from|to|dev_serial|dport|action|severity|inbound_if|outbound_if|category|category-of-app|subcategory-of-app|technology-of-app|container-of-app|risk-of-app|parent_session_id|parent_start_time|tunnel|direction|assoc_id|ppid|http2_connection|rule_uuid|threat_name|src_edl|dst_edl|hostid|dynusergroup_name|nssai_sst|src_category|src_profile|src_model|src_vendor|src_osfamily|src_osversion|src_host|src_mac|dst_category|dst_profile|dst_model|dst_vendor|dst_osfamily|dst_osversion|dst_host|dst_mac|container_id|pod_namespace|pod_name|src_dag|dst_dag|day-of-receive_time|hour-of-receive_time|quarter-hour-of-receive_time|subtype|tunnelid|monitortag|category-of-threatid|threat-type> set reports <name> type thsum values [ <values1> <values2>... ] set reports <name> type thsum labels [ <labels1> <labels2>... ] set reports <name> type thsum sortby <sessions|count|nunique-of-apps|nunique-of-users|nunique-of-src_profile|nunique-of-dst_profile> set reports <name> type traffic set reports <name> type traffic aggregate-by [ <aggregate-by1> <aggregate-by2>... ] set reports <name> type traffic group-by <serial|time_generated|src|dst|natsrc|natdst|rule|srcuser|dstuser|srcloc|dstloc|app|vsys|from|to|inbound_if|outbound_if|sport|dport|natsport|natdport|proto|action|tunnel|rule_uuid|s_encrypted|category-of-app|subcategory-of-app|technology-of-app|container-of-app|risk-of-app|vsys_name|device_name|parent_session_id|parent_start_time|category|session_end_reason|action_source|nssai_sst|nssai_sd|http2_connection|xff_ip|dynusergroup_name|src_edl|dst_edl|hostid|session_owner|policy_id|offloaded|src_category|src_profile|src_model|src_vendor|src_osfamily|src_osversion|src_host|src_mac|dst_category|dst_profile|dst_model|dst_vendor|dst_osfamily|dst_osversion|dst_host|dst_mac|container_id|pod_namespace|pod_name|src_dag|dst_dag|day-of-receive_time|hour-of-receive_time|quarter-hour-of-receive_time|pbf-s2c|pbf-c2s|decrypt-mirror|threat-type|flag-nat|flag-pcap|captive-portal|flag-proxy|non-std-dport|transaction|sym-return|sessionid|flag-decrypt-fwd|tunnelid|monitortag> set reports <name> type traffic values [ <values1> <values2>... ] set reports <name> type traffic labels [ <labels1> <labels2>... ] set reports <name> type traffic sortby <repeatcnt|bytes|bytes_sent|bytes_received|packets|pkts_sent|pkts_received|chunks|chunks_sent|chunks_received|nunique-of-users|elapsed|nunique-of-src_profile|nunique-of-dst_profile> set reports <name> type urlsum set reports <name> type urlsum aggregate-by [ <aggregate-by1> <aggregate-by2>... ] set reports <name> type urlsum group-by <serial|time_generated|vsys_name|device_name|app|category|src|dst|rule|srcuser|dstuser|srcloc|dstloc|vsys|from|to|dev_serial|inbound_if|outbound_if|dport|action|tunnel|url_domain|user_agent|http_method|http2_connection|category-of-app|subcategory-of-app|technology-of-app|container-of-app|risk-of-app|parent_session_id|parent_start_time|rule_uuid|xff_ip|src_edl|dst_edl|hostid|dynusergroup_name|nssai_sst|src_category|src_profile|src_model|src_vendor|src_osfamily|src_osversion|src_host|src_mac|dst_category|dst_profile|dst_model|dst_vendor|dst_osfamily|dst_osversion|dst_host|dst_mac|container_id|pod_namespace|pod_name|url_category_list|src_dag|dst_dag|day-of-receive_time|hour-of-receive_time|quarter-hour-of-receive_time|tunnelid|monitortag> set reports <name> type urlsum values [ <values1> <values2>... ] set reports <name> type urlsum labels [ <labels1> <labels2>... ] set reports <name> type urlsum sortby <repeatcnt|nunique-of-users|nunique-of-src_profile|nunique-of-dst_profile> set reports <name> type trsum set reports <name> type trsum aggregate-by [ <aggregate-by1> <aggregate-by2>... ] set reports <name> type trsum group-by <serial|time_generated|vsys_name|device_name|app|src|dst|xff_ip|rule|srcuser|dstuser|srcloc|dstloc|category|vsys|from|to|dev_serial|dport|action|tunnel|inbound_if|outbound_if|category-of-app|subcategory-of-app|technology-of-app|container-of-app|risk-of-app|parent_session_id|parent_start_time|assoc_id|http2_connection|rule_uuid|src_edl|dst_edl|dynusergroup_name|s_decrypted|s_encrypted|hostid|nssai_sst|src_category|src_profile|src_model|src_vendor|src_osfamily|src_osversion|src_host|src_mac|dst_category|dst_profile|dst_model|dst_vendor|dst_osfamily|dst_osversion|dst_host|dst_mac|container_id|pod_namespace|pod_name|src_dag|dst_dag|day-of-receive_time|hour-of-receive_time|quarter-hour-of-receive_time|tunnelid|monitortag|standard-ports-of-app> set reports <name> type trsum values [ <values1> <values2>... ] set reports <name> type trsum labels [ <labels1> <labels2>... ] set reports <name> type trsum sortby <bytes|sessions|bytes_sent|bytes_received|nthreats|nftrans|ndpmatches|nurlcount|chunks|chunks_sent|chunks_received|ncontent|nunique-of-apps|nunique-of-users|nunique-of-src_profile|nunique-of-dst_profile> set reports <name> type tunnel set reports <name> type tunnel aggregate-by [ <aggregate-by1> <aggregate-by2>... ] set reports <name> type tunnel group-by <action|app|category-of-app|dport|dst|dstuser|from|inbound_if|natdport|natdst|natsport|natsrc|outbound_if|proto|risk-of-app|rule|rule_uuid|sessionid|sport|src|srcuser|subcategory-of-app|technology-of-app|container-of-app|to|dstloc|srcloc|vsys|quarter-hour-of-receive_time|hour-of-receive_time|day-of-receive_time|vsys_name|device_name|tunnelid|monitortag|parent_session_id|parent_start_time|session_end_reason|action_source|tunnel|tunnel_insp_rule|src_dag|dst_dag|src_edl|dst_edl> set reports <name> type tunnel values [ <values1> <values2>... ] set reports <name> type tunnel labels [ <labels1> <labels2>... ] set reports <name> type tunnel sortby <repeatcnt|bytes|bytes_sent|bytes_received|packets|pkts_sent|pkts_received|max_encap|unknown_proto|strict_check|tunnel_fragment|sessions_created|sessions_closed|nunique-of-users> set reports <name> type tunnelsum set reports <name> type tunnelsum aggregate-by [ <aggregate-by1> <aggregate-by2>... ] set reports <name> type tunnelsum group-by <action|app|category-of-app|dst|risk-of-app|rule|rule_uuid|src|subcategory-of-app|technology-of-app|container-of-app|dstloc|srcloc|vsys|quarter-hour-of-receive_time|hour-of-receive_time|day-of-receive_time|serial|vsys_name|device_name|tunnelid|monitortag|parent_session_id|parent_start_time|tunnel|tunnel_insp_rule|src_dag|dst_dag|src_edl|dst_edl> set reports <name> type tunnelsum values [ <values1> <values2>... ] set reports <name> type tunnelsum labels [ <labels1> <labels2>... ] set reports <name> type tunnelsum sortby <repeatcnt|bytes|bytes_sent|bytes_received> set reports <name> type userid set reports <name> type userid aggregate-by [ <aggregate-by1> <aggregate-by2>... ] set reports <name> type userid group-by <serial|time_generated|vsys_name|device_name|vsys|ip|user|datasourcename|beginport|endport|datasource|datasourcetype|factortype|factorcompletiontime|factorno|tag_name|day-of-receive_time|hour-of-receive_time|quarter-hour-of-receive_time|subtype> set reports <name> type userid values [ <values1> <values2>... ] set reports <name> type userid labels [ <labels1> <labels2>... ] set reports <name> type userid sortby <repeatcnt|factortype|factorcompletiontime> set reports <name> type auth set reports <name> type auth aggregate-by [ <aggregate-by1> <aggregate-by2>... ] set reports <name> type auth group-by <serial|time_generated|vsys_name|device_name|vsys|ip|user|normalize_user|object|authpolicy|authid|vendor|clienttype|event|factorno|authproto|rule_uuid|src_category|src_profile|src_model|src_vendor|src_osfamily|src_osversion|src_host|src_mac|day-of-receive_time|hour-of-receive_time|quarter-hour-of-receive_time|serverprofile|desc> set reports <name> type auth values [ <values1> <values2>... ] set reports <name> type auth labels [ <labels1> <labels2>... ] set reports <name> type auth sortby <repeatcnt|time_generated|vendor> set reports <name> type iptag set reports <name> type iptag aggregate-by [ <aggregate-by1> <aggregate-by2>... ] set reports <name> type iptag group-by <serial|time_generated|vsys_name|device_name|vsys|ip|tag_name|event_id|datasourcename|datasource_type|datasource_subtype|day-of-receive_time|hour-of-receive_time|quarter-hour-of-receive_time> set reports <name> type iptag values [ <values1> <values2>... ] set reports <name> type iptag labels [ <labels1> <labels2>... ] set reports <name> type iptag sortby <repeatcnt|time_generated> set reports <name> type hipmatch set reports <name> type hipmatch aggregate-by [ <aggregate-by1> <aggregate-by2>... ] set reports <name> type hipmatch group-by <serial|time_generated|vsys_name|device_name|srcuser|vsys|machinename|src|matchname|os|matchtype|srcipv6|hostid|mac|day-of-receive_time|hour-of-receive_time|quarter-hour-of-receive_time> set reports <name> type hipmatch values [ <values1> <values2>... ] set reports <name> type hipmatch labels [ <labels1> <labels2>... ] set reports <name> type hipmatch sortby <repeatcnt> set reports <name> type hipmatch last-match-by <>
There are 25 new set report-group commands.
set report-group set report-group<name> set report-group <name> title-page <yes|no> set report-group <name> predefined <user-activity-report|saas-application-usage-report> set report-group <name> custom-widget set report-group <name> custom-widget <name> set report-group <name> custom-widget <name> custom-report <value> set report-group <name> custom-widget <name> pdf-summary-report <value> set report-group <name> custom-widget <name> log-view <value> set report-group <name> custom-widget <name> csv <value> set report-group <name> all set report-group <name> all entry set report-group <name> all entry include-user-groups-info <yes|no> set report-group <name> all entry user-groups [ <user-groups1> <user-groups2>... ] set report-group <name> selected-zone set report-group <name> selected-zone entry set report-group <name> selected-zone entry include-user-groups-info <yes|no> set report-group <name> selected-zone entry user-groups [ <user-groups1> <user-groups2>... ] set report-group <name> selected-zone entry zone <value> set report-group <name> selected-user-group set report-group <name> selected-user-group entry set report-group <name> selected-user-group entry user-group <value> set report-group <name> variable set report-group <name> variable <name> set report-group <name> variable <name> value <value>
There are 11 new set pdf-summary-report commands.
set pdf-summary-report set pdf-summary-report<name> set pdf-summary-report <name> header set pdf-summary-report <name> header caption <value> set pdf-summary-report <name> footer set pdf-summary-report <name> footer note <value> set pdf-summary-report <name> custom-widget set pdf-summary-report <name> custom-widget <name> set pdf-summary-report <name> custom-widget <name> chart-type <pie|line|bar|table> set pdf-summary-report <name> custom-widget <name> row <1-6> set pdf-summary-report <name> custom-widget <name> column <1-3>
There are 10 new set email-scheduler commands.
set email-scheduler set email-scheduler<name> set email-scheduler <name> report-group <value> set email-scheduler <name> email-profile <value> set email-scheduler <name> recipient-emails <value> set email-scheduler <name> recurring set email-scheduler <name> recurring disabled set email-scheduler <name> recurring daily set email-scheduler <name> recurring weekly <sunday|monday|tuesday|wednesday|thursday|friday|saturday> set email-scheduler <name> recurring monthly <1-31>
There are 69 new set external-list commands.
set external-list set external-list<name> set external-list <name> type set external-list <name> type predefined-ip set external-list <name> type predefined-ip exception-list [ <exception-list1> <exception-list2>... ] set external-list <name> type predefined-ip description <value> set external-list <name> type predefined-ip url <value> set external-list <name> type predefined-url set external-list <name> type predefined-url exception-list [ <exception-list1> <exception-list2>... ] set external-list <name> type predefined-url description <value> set external-list <name> type predefined-url url <value> set external-list <name> type ip set external-list <name> type ip exception-list [ <exception-list1> <exception-list2>... ] set external-list <name> type ip description <value> set external-list <name> type ip url <value> set external-list <name> type ip certificate-profile <value>|<None> set external-list <name> type ip auth set external-list <name> type ip auth username <value> set external-list <name> type ip auth password <value> set external-list <name> type ip recurring set external-list <name> type ip recurring five-minute set external-list <name> type ip recurring hourly set external-list <name> type ip recurring daily set external-list <name> type ip recurring daily at <value> set external-list <name> type ip recurring weekly set external-list <name> type ip recurring weekly day-of-week <sunday|monday|tuesday|wednesday|thursday|friday|saturday> set external-list <name> type ip recurring weekly at <value> set external-list <name> type ip recurring monthly set external-list <name> type ip recurring monthly day-of-month <1-31> set external-list <name> type ip recurring monthly at <value> set external-list <name> type domain set external-list <name> type domain exception-list [ <exception-list1> <exception-list2>... ] set external-list <name> type domain description <value> set external-list <name> type domain url <value> set external-list <name> type domain certificate-profile <value>|<None> set external-list <name> type domain auth set external-list <name> type domain auth username <value> set external-list <name> type domain auth password <value> set external-list <name> type domain recurring set external-list <name> type domain recurring hourly set external-list <name> type domain recurring five-minute set external-list <name> type domain recurring daily set external-list <name> type domain recurring daily at <value> set external-list <name> type domain recurring weekly set external-list <name> type domain recurring weekly day-of-week <sunday|monday|tuesday|wednesday|thursday|friday|saturday> set external-list <name> type domain recurring weekly at <value> set external-list <name> type domain recurring monthly set external-list <name> type domain recurring monthly day-of-month <1-31> set external-list <name> type domain recurring monthly at <value> set external-list <name> type domain expand-domain <yes|no> set external-list <name> type url set external-list <name> type url exception-list [ <exception-list1> <exception-list2>... ] set external-list <name> type url description <value> set external-list <name> type url url <value> set external-list <name> type url certificate-profile <value>|<None> set external-list <name> type url auth set external-list <name> type url auth username <value> set external-list <name> type url auth password <value> set external-list <name> type url recurring set external-list <name> type url recurring hourly set external-list <name> type url recurring five-minute set external-list <name> type url recurring daily set external-list <name> type url recurring daily at <value> set external-list <name> type url recurring weekly set external-list <name> type url recurring weekly day-of-week <sunday|monday|tuesday|wednesday|thursday|friday|saturday> set external-list <name> type url recurring weekly at <value> set external-list <name> type url recurring monthly set external-list <name> type url recurring monthly day-of-month <1-31> set external-list <name> type url recurring monthly at <value>
There are 15 new set address commands.
set address set address<name> set address <name> description <value> set address <name> ip-netmask <ip/netmask> set address <name> ip-range <ip-range> set address <name> ip-wildcard <ipdiscontmask> set address <name> fqdn <value> set address <name> tag [ <tag1> <tag2>... ]
There are 7 new set address-group commands.
set address-group set address-group<name> set address-group <name> description <value> set address-group <name> static [ <static1> <static2>... ] set address-group <name> dynamic set address-group <name> dynamic filter <value> set address-group <name> tag [ <tag1> <tag2>... ]
There are 5 new set dynamic-user-group commands.
set dynamic-user-group set dynamic-user-group<name> set dynamic-user-group <name> description <value> set dynamic-user-group <name> filter <value> set dynamic-user-group <name> tag [ <tag1> <tag2>... ]
There are 14 new set schedule commands.
set schedule set schedule<name> set schedule <name> schedule-type set schedule <name> schedule-type recurring set schedule <name> schedule-type recurring weekly set schedule <name> schedule-type recurring weekly sunday [ <sunday1> <sunday2>... ] set schedule <name> schedule-type recurring weekly monday [ <monday1> <monday2>... ] set schedule <name> schedule-type recurring weekly tuesday [ <tuesday1> <tuesday2>... ] set schedule <name> schedule-type recurring weekly wednesday [ <wednesday1> <wednesday2>... ] set schedule <name> schedule-type recurring weekly thursday [ <thursday1> <thursday2>... ] set schedule <name> schedule-type recurring weekly friday [ <friday1> <friday2>... ] set schedule <name> schedule-type recurring weekly saturday [ <saturday1> <saturday2>... ] set schedule <name> schedule-type recurring daily [ <daily1> <daily2>... ] set schedule <name> schedule-type non-recurring [ <non-recurring1> <non-recurring2>... ]
There are 138 new set threats commands.
set threats set threats vulnerability set threats vulnerability<name> set threats vulnerability <name> threatname <value> set threats vulnerability <name> affected-host set threats vulnerability <name> affected-host client <yes|no> set threats vulnerability <name> affected-host server <yes|no> set threats vulnerability <name> comment <value> set threats vulnerability <name> severity <value> set threats vulnerability <name> direction <value> set threats vulnerability <name> default-action set threats vulnerability <name> default-action alert set threats vulnerability <name> default-action drop set threats vulnerability <name> default-action reset-client set threats vulnerability <name> default-action reset-server set threats vulnerability <name> default-action reset-both set threats vulnerability <name> default-action block-ip set threats vulnerability <name> default-action block-ip track-by <source|source-and-destination> set threats vulnerability <name> default-action block-ip duration <1-3600> set threats vulnerability <name> default-action allow set threats vulnerability <name> cve [ <cve1> <cve2>... ] set threats vulnerability <name> bugtraq [ <bugtraq1> <bugtraq2>... ] set threats vulnerability <name> vendor [ <vendor1> <vendor2>... ] set threats vulnerability <name> reference [ <reference1> <reference2>... ] set threats vulnerability <name> signature set threats vulnerability <name> signature standard set threats vulnerability <name> signature standard <name> set threats vulnerability <name> signature standard <name> comment <value> set threats vulnerability <name> signature standard <name> scope <protocol-data-unit|session> set threats vulnerability <name> signature standard <name> order-free <yes|no> set threats vulnerability <name> signature standard <name> and-condition set threats vulnerability <name> signature standard <name> and-condition <name> set threats vulnerability <name> signature standard <name> and-condition <name> or-condition set threats vulnerability <name> signature standard <name> and-condition <name> or-condition <name> set threats vulnerability <name> signature standard <name> and-condition <name> or-condition <name> operator set threats vulnerability <name> signature standard <name> and-condition <name> or-condition <name> operator less-than set threats vulnerability <name> signature standard <name> and-condition <name> or-condition <name> operator less-than context <value> set threats vulnerability <name> signature standard <name> and-condition <name> or-condition <name> operator less-than value <0-4294967295> set threats vulnerability <name> signature standard <name> and-condition <name> or-condition <name> operator less-than qualifier set threats vulnerability <name> signature standard <name> and-condition <name> or-condition <name> operator less-than qualifier <name> set threats vulnerability <name> signature standard <name> and-condition <name> or-condition <name> operator less-than qualifier <name> value <1-127>|<value> set threats vulnerability <name> signature standard <name> and-condition <name> or-condition <name> operator equal-to set threats vulnerability <name> signature standard <name> and-condition <name> or-condition <name> operator equal-to context <value> set threats vulnerability <name> signature standard <name> and-condition <name> or-condition <name> operator equal-to value <0-4294967295> set threats vulnerability <name> signature standard <name> and-condition <name> or-condition <name> operator equal-to qualifier set threats vulnerability <name> signature standard <name> and-condition <name> or-condition <name> operator equal-to qualifier <name> set threats vulnerability <name> signature standard <name> and-condition <name> or-condition <name> operator equal-to qualifier <name> value <1-127>|<value> set threats vulnerability <name> signature standard <name> and-condition <name> or-condition <name> operator greater-than set threats vulnerability <name> signature standard <name> and-condition <name> or-condition <name> operator greater-than context <value> set threats vulnerability <name> signature standard <name> and-condition <name> or-condition <name> operator greater-than value <0-4294967295> set threats vulnerability <name> signature standard <name> and-condition <name> or-condition <name> operator greater-than qualifier set threats vulnerability <name> signature standard <name> and-condition <name> or-condition <name> operator greater-than qualifier <name> set threats vulnerability <name> signature standard <name> and-condition <name> or-condition <name> operator greater-than qualifier <name> value <1-127>|<value> set threats vulnerability <name> signature standard <name> and-condition <name> or-condition <name> operator pattern-match set threats vulnerability <name> signature standard <name> and-condition <name> or-condition <name> operator pattern-match context <value> set threats vulnerability <name> signature standard <name> and-condition <name> or-condition <name> operator pattern-match pattern <value> set threats vulnerability <name> signature standard <name> and-condition <name> or-condition <name> operator pattern-match negate <yes|no> set threats vulnerability <name> signature standard <name> and-condition <name> or-condition <name> operator pattern-match qualifier set threats vulnerability <name> signature standard <name> and-condition <name> or-condition <name> operator pattern-match qualifier <name> set threats vulnerability <name> signature standard <name> and-condition <name> or-condition <name> operator pattern-match qualifier <name> value <1-127>|<value> set threats vulnerability <name> signature combination set threats vulnerability <name> signature combination time-attribute set threats vulnerability <name> signature combination time-attribute interval <1-3600> set threats vulnerability <name> signature combination time-attribute threshold <1-255> set threats vulnerability <name> signature combination time-attribute track-by <source|destination|source-and-destination> set threats vulnerability <name> signature combination order-free <yes|no> set threats vulnerability <name> signature combination and-condition set threats vulnerability <name> signature combination and-condition <name> set threats vulnerability <name> signature combination and-condition <name> or-condition set threats vulnerability <name> signature combination and-condition <name> or-condition <name> set threats vulnerability <name> signature combination and-condition <name> or-condition <name> threat-id <value> set threats spyware set threats spyware <name> set threats spyware <name> threatname <value> set threats spyware <name> comment <value> set threats spyware <name> severity <value> set threats spyware <name> direction <value> set threats spyware <name> default-action set threats spyware <name> default-action alert set threats spyware <name> default-action drop set threats spyware <name> default-action reset-client set threats spyware <name> default-action reset-server set threats spyware <name> default-action reset-both set threats spyware <name> default-action block-ip set threats spyware <name> default-action block-ip track-by <source|source-and-destination> set threats spyware <name> default-action block-ip duration <1-3600> set threats spyware <name> default-action allow set threats spyware <name> cve [ <cve1> <cve2>... ] set threats spyware <name> bugtraq [ <bugtraq1> <bugtraq2>... ] set threats spyware <name> vendor [ <vendor1> <vendor2>... ] set threats spyware <name> reference [ <reference1> <reference2>... ] set threats spyware <name> signature set threats spyware <name> signature standard set threats spyware <name> signature standard <name> set threats spyware <name> signature standard <name> comment <value> set threats spyware <name> signature standard <name> scope <protocol-data-unit|session> set threats spyware <name> signature standard <name> order-free <yes|no> set threats spyware <name> signature standard <name> and-condition set threats spyware <name> signature standard <name> and-condition <name> set threats spyware <name> signature standard <name> and-condition <name> or-condition set threats spyware <name> signature standard <name> and-condition <name> or-condition <name> set threats spyware <name> signature standard <name> and-condition <name> or-condition <name> operator set threats spyware <name> signature standard <name> and-condition <name> or-condition <name> operator less-than set threats spyware <name> signature standard <name> and-condition <name> or-condition <name> operator less-than value <0-4294967295> set threats spyware <name> signature standard <name> and-condition <name> or-condition <name> operator less-than context <value> set threats spyware <name> signature standard <name> and-condition <name> or-condition <name> operator less-than qualifier set threats spyware <name> signature standard <name> and-condition <name> or-condition <name> operator less-than qualifier <name> set threats spyware <name> signature standard <name> and-condition <name> or-condition <name> operator less-than qualifier <name> value <1-127>|<value> set threats spyware <name> signature standard <name> and-condition <name> or-condition <name> operator equal-to set threats spyware <name> signature standard <name> and-condition <name> or-condition <name> operator equal-to value <0-4294967295> set threats spyware <name> signature standard <name> and-condition <name> or-condition <name> operator equal-to context <value> set threats spyware <name> signature standard <name> and-condition <name> or-condition <name> operator equal-to qualifier set threats spyware <name> signature standard <name> and-condition <name> or-condition <name> operator equal-to qualifier <name> set threats spyware <name> signature standard <name> and-condition <name> or-condition <name> operator equal-to qualifier <name> value <1-127>|<value> set threats spyware <name> signature standard <name> and-condition <name> or-condition <name> operator greater-than set threats spyware <name> signature standard <name> and-condition <name> or-condition <name> operator greater-than value <0-4294967295> set threats spyware <name> signature standard <name> and-condition <name> or-condition <name> operator greater-than context <value> set threats spyware <name> signature standard <name> and-condition <name> or-condition <name> operator greater-than qualifier set threats spyware <name> signature standard <name> and-condition <name> or-condition <name> operator greater-than qualifier <name> set threats spyware <name> signature standard <name> and-condition <name> or-condition <name> operator greater-than qualifier <name> value <1-127>|<value> set threats spyware <name> signature standard <name> and-condition <name> or-condition <name> operator pattern-match set threats spyware <name> signature standard <name> and-condition <name> or-condition <name> operator pattern-match context <value> set threats spyware <name> signature standard <name> and-condition <name> or-condition <name> operator pattern-match pattern <value> set threats spyware <name> signature standard <name> and-condition <name> or-condition <name> operator pattern-match negate <yes|no> set threats spyware <name> signature standard <name> and-condition <name> or-condition <name> operator pattern-match qualifier set threats spyware <name> signature standard <name> and-condition <name> or-condition <name> operator pattern-match qualifier <name> set threats spyware <name> signature standard <name> and-condition <name> or-condition <name> operator pattern-match qualifier <name> value <1-127>|<value> set threats spyware <name> signature combination set threats spyware <name> signature combination time-attribute set threats spyware <name> signature combination time-attribute interval <1-3600> set threats spyware <name> signature combination time-attribute threshold <1-255> set threats spyware <name> signature combination time-attribute track-by <source|destination|source-and-destination> set threats spyware <name> signature combination order-free <yes|no> set threats spyware <name> signature combination and-condition set threats spyware <name> signature combination and-condition <name> set threats spyware <name> signature combination and-condition <name> or-condition set threats spyware <name> signature combination and-condition <name> or-condition <name> set threats spyware <name> signature combination and-condition <name> or-condition <name> threat-id <value>
There are 97 new set application commands.
set application set application<name> set application <name> default set application <name> default port [ <port1> <port2>... ] set application <name> default ident-by-ip-protocol <0-255,...> set application <name> default ident-by-icmp-type set application <name> default ident-by-icmp-type type <0-255,...> set application <name> default ident-by-icmp-type code <0-255,...> set application <name> default ident-by-icmp6-type set application <name> default ident-by-icmp6-type type <0-255,...> set application <name> default ident-by-icmp6-type code <0-255,...> set application <name> category <value> set application <name> subcategory <value> set application <name> technology <value> set application <name> description <value> set application <name> timeout <0-604800> set application <name> tcp-timeout <0-604800> set application <name> udp-timeout <0-604800> set application <name> tcp-half-closed-timeout <1-604800> set application <name> tcp-time-wait-timeout <1-600> set application <name> risk <1-5> set application <name> evasive-behavior <yes|no> set application <name> consume-big-bandwidth <yes|no> set application <name> used-by-malware <yes|no> set application <name> able-to-transfer-file <yes|no> set application <name> has-known-vulnerability <yes|no> set application <name> tunnel-other-application <yes|no> set application <name> tunnel-applications <yes|no> set application <name> prone-to-misuse <yes|no> set application <name> pervasive-use <yes|no> set application <name> file-type-ident <yes|no> set application <name> virus-ident <yes|no> set application <name> data-ident <yes|no> set application <name> no-appid-caching <yes|no> set application <name> alg-disable-capability <value> set application <name> parent-app <value> set application <name> signature set application <name> signature <name> set application <name> signature <name> comment <value> set application <name> signature <name> scope <protocol-data-unit|session> set application <name> signature <name> order-free <yes|no> set application <name> signature <name> and-condition set application <name> signature <name> and-condition <name> set application <name> signature <name> and-condition <name> or-condition set application <name> signature <name> and-condition <name> or-condition <name> set application <name> signature <name> and-condition <name> or-condition <name> operator set application <name> signature <name> and-condition <name> or-condition <name> operator pattern-match set application <name> signature <name> and-condition <name> or-condition <name> operator pattern-match context <value> set application <name> signature <name> and-condition <name> or-condition <name> operator pattern-match pattern <value> set application <name> signature <name> and-condition <name> or-condition <name> operator pattern-match qualifier set application <name> signature <name> and-condition <name> or-condition <name> operator pattern-match qualifier <name> set application <name> signature <name> and-condition <name> or-condition <name> operator pattern-match qualifier <name> value <1-127>|<value> set application <name> signature <name> and-condition <name> or-condition <name> operator greater-than set application <name> signature <name> and-condition <name> or-condition <name> operator greater-than context <value> set application <name> signature <name> and-condition <name> or-condition <name> operator greater-than value <0-4294967295> set application <name> signature <name> and-condition <name> or-condition <name> operator greater-than qualifier set application <name> signature <name> and-condition <name> or-condition <name> operator greater-than qualifier <name> set application <name> signature <name> and-condition <name> or-condition <name> operator greater-than qualifier <name> value <1-127>|<value> set application <name> signature <name> and-condition <name> or-condition <name> operator less-than set application <name> signature <name> and-condition <name> or-condition <name> operator less-than context <value> set application <name> signature <name> and-condition <name> or-condition <name> operator less-than value <0-4294967295> set application <name> signature <name> and-condition <name> or-condition <name> operator less-than qualifier set application <name> signature <name> and-condition <name> or-condition <name> operator less-than qualifier <name> set application <name> signature <name> and-condition <name> or-condition <name> operator less-than qualifier <name> value <1-127>|<value> set application <name> signature <name> and-condition <name> or-condition <name> operator equal-to set application <name> signature <name> and-condition <name> or-condition <name> operator equal-to context <value>|<unknown-req-tcp|unknown-rsp-tcp|unknown-req-udp|unknown-rsp-udp> set application <name> signature <name> and-condition <name> or-condition <name> operator equal-to position <value> set application <name> signature <name> and-condition <name> or-condition <name> operator equal-to mask <value> set application <name> signature <name> and-condition <name> or-condition <name> operator equal-to value <value>
There are 3 new set application-tag commands.
set application-tag set application-tag<name> set application-tag <name> tag [ <tag1> <tag2>... ]
There are 22 new set application-filter commands.
set application-filter set application-filter<name> set application-filter <name> category [ <category1> <category2>... ] set application-filter <name> subcategory [ <subcategory1> <subcategory2>... ] set application-filter <name> technology [ <technology1> <technology2>... ] set application-filter <name> evasive <yes> set application-filter <name> excessive-bandwidth-use <yes> set application-filter <name> used-by-malware <yes> set application-filter <name> transfers-files <yes> set application-filter <name> has-known-vulnerabilities <yes> set application-filter <name> tunnels-other-apps <yes> set application-filter <name> prone-to-misuse <yes> set application-filter <name> pervasive <yes> set application-filter <name> is-saas <yes> set application-filter <name> new-appid <yes> set application-filter <name> risk [ <risk1> <risk2>... ] set application-filter <name> saas-certifications [ <saas-certifications1> <saas-certifications2>... ] set application-filter <name> saas-risk [ <saas-risk1> <saas-risk2>... ] set application-filter <name> tagging set application-filter <name> tagging no-tag <yes> set application-filter <name> tagging tag [ <tag1> <tag2>... ] set application-filter <name> exclude [ <exclude1> <exclude2>... ]
There are 3 new set application-group commands.
set application-group set application-group<name> set application-group <name> members [ <members1> <members2>... ]
There are 9 new set device-object commands.
set device-object set device-object<name> set device-object <name> description <value> set device-object <name> category [ <category1> <category2>... ] set device-object <name> profile [ <profile1> <profile2>... ] set device-object <name> osfamily [ <osfamily1> <osfamily2>... ] set device-object <name> os [ <os1> <os2>... ] set device-object <name> model [ <model1> <model2>... ] set device-object <name> vendor [ <vendor1> <vendor2>... ]
There are 6 new set region commands.
set region set region<name> set region <name> geo-location set region <name> geo-location latitude <float> set region <name> geo-location longitude <float> set region <name> address [ <address1> <address2>... ]
There are 17 new set tag commands.
set tag set tag<name> set tag <name> color <color1|color2|color3|color4|color5|color6|color7|color8|color9|color10|color11|color12|color13|color14|color15|color16|color17|color19|color20|color21|color22|color23|color24|color25|color26|color27|color28|color29|color30|color31|color32|color33|color34|color35|color36|color37|color38|color39|color40|color41|color42> set tag <name> comments <value>
There are 5 new set authentication-object commands.
set authentication-object set authentication-object<name> set authentication-object <name> authentication-method <web-form|no-captive-portal|browser-challenge> set authentication-object <name> authentication-profile <value> set authentication-object <name> message <value>
There are 361 new set rulebase commands.
set rulebase set rulebase security set rulebase security rules set rulebase security rules<name> set rulebase security rules <name> from [ <from1> <from2>... ] set rulebase security rules <name> to [ <to1> <to2>... ] set rulebase security rules <name> source [ <source1> <source2>... ] set rulebase security rules <name> source-user [ <source-user1> <source-user2>... ] set rulebase security rules <name> destination [ <destination1> <destination2>... ] set rulebase security rules <name> service [ <service1> <service2>... ] set rulebase security rules <name> category [ <category1> <category2>... ] set rulebase security rules <name> application [ <application1> <application2>... ] set rulebase security rules <name> source-hip [ <source-hip1> <source-hip2>... ] set rulebase security rules <name> destination-hip [ <destination-hip1> <destination-hip2>... ] set rulebase security rules <name> schedule <value> set rulebase security rules <name> tag [ <tag1> <tag2>... ] set rulebase security rules <name> negate-source <yes|no> set rulebase security rules <name> negate-destination <yes|no> set rulebase security rules <name> disabled <yes|no> set rulebase security rules <name> description <value> set rulebase security rules <name> group-tag <value> set rulebase security rules <name> action <deny|allow|drop|reset-client|reset-server|reset-both> set rulebase security rules <name> icmp-unreachable <yes|no> set rulebase security rules <name> disable-inspect <yes|no> set rulebase security rules <name> rule-type <universal|intrazone|interzone> set rulebase security rules <name> option set rulebase security rules <name> option disable-server-response-inspection <yes|no> set rulebase security rules <name> log-setting <value> set rulebase security rules <name> log-start <yes|no> set rulebase security rules <name> log-end <yes|no> set rulebase security rules <name> profile-setting set rulebase security rules <name> profile-setting profiles set rulebase security rules <name> profile-setting profiles url-filtering [ <url-filtering1> <url-filtering2>... ] set rulebase security rules <name> profile-setting profiles data-filtering [ <data-filtering1> <data-filtering2>... ] set rulebase security rules <name> profile-setting profiles file-blocking [ <file-blocking1> <file-blocking2>... ] set rulebase security rules <name> profile-setting profiles wildfire-analysis [ <wildfire-analysis1> <wildfire-analysis2>... ] set rulebase security rules <name> profile-setting profiles virus [ <virus1> <virus2>... ] set rulebase security rules <name> profile-setting profiles spyware [ <spyware1> <spyware2>... ] set rulebase security rules <name> profile-setting profiles vulnerability [ <vulnerability1> <vulnerability2>... ] set rulebase security rules <name> profile-setting group [ <group1> <group2>... ] set rulebase security rules <name> qos set rulebase security rules <name> qos marking set rulebase security rules <name> qos marking ip-dscp <value>|<ef|af11|af12|af13|af21|af22|af23|af31|af32|af33|af41|af42|af43|cs0|cs1|cs2|cs3|cs4|cs5|cs6|cs7> set rulebase security rules <name> qos marking ip-precedence <value>|<cs0|cs1|cs2|cs3|cs4|cs5|cs6|cs7> set rulebase security rules <name> qos marking follow-c2s-flow set rulebase default-security-rules set rulebase default-security-rules rules set rulebase default-security-rules rules <name> set rulebase default-security-rules rules <name> tag [ <tag1> <tag2>... ] set rulebase default-security-rules rules <name> log-setting <value> set rulebase default-security-rules rules <name> log-start <yes|no> set rulebase default-security-rules rules <name> log-end <yes|no> set rulebase default-security-rules rules <name> profile-setting set rulebase default-security-rules rules <name> profile-setting profiles set rulebase default-security-rules rules <name> profile-setting profiles url-filtering [ <url-filtering1> <url-filtering2>... ] set rulebase default-security-rules rules <name> profile-setting profiles data-filtering [ <data-filtering1> <data-filtering2>... ] set rulebase default-security-rules rules <name> profile-setting profiles file-blocking [ <file-blocking1> <file-blocking2>... ] set rulebase default-security-rules rules <name> profile-setting profiles wildfire-analysis [ <wildfire-analysis1> <wildfire-analysis2>... ] set rulebase default-security-rules rules <name> profile-setting profiles virus [ <virus1> <virus2>... ] set rulebase default-security-rules rules <name> profile-setting profiles spyware [ <spyware1> <spyware2>... ] set rulebase default-security-rules rules <name> profile-setting profiles vulnerability [ <vulnerability1> <vulnerability2>... ] set rulebase default-security-rules rules <name> profile-setting group [ <group1> <group2>... ] set rulebase default-security-rules rules <name> group-tag <value> set rulebase default-security-rules rules <name> action <deny|allow|drop|reset-client|reset-server|reset-both> set rulebase default-security-rules rules <name> icmp-unreachable <yes|no> set rulebase application-override set rulebase application-override rules set rulebase application-override rules <name> set rulebase application-override rules <name> from [ <from1> <from2>... ] set rulebase application-override rules <name> to [ <to1> <to2>... ] set rulebase application-override rules <name> source [ <source1> <source2>... ] set rulebase application-override rules <name> source-user [ <source-user1> <source-user2>... ] set rulebase application-override rules <name> destination [ <destination1> <destination2>... ] set rulebase application-override rules <name> tag [ <tag1> <tag2>... ] set rulebase application-override rules <name> negate-source <yes|no> set rulebase application-override rules <name> negate-destination <yes|no> set rulebase application-override rules <name> disabled <yes|no> set rulebase application-override rules <name> description <value> set rulebase application-override rules <name> group-tag <value> set rulebase application-override rules <name> protocol <tcp|udp> set rulebase application-override rules <name> port <0-65535,...> set rulebase application-override rules <name> application <value> set rulebase decryption set rulebase decryption rules set rulebase decryption rules <name> set rulebase decryption rules <name> from [ <from1> <from2>... ] set rulebase decryption rules <name> to [ <to1> <to2>... ] set rulebase decryption rules <name> source [ <source1> <source2>... ] set rulebase decryption rules <name> source-user [ <source-user1> <source-user2>... ] set rulebase decryption rules <name> destination [ <destination1> <destination2>... ] set rulebase decryption rules <name> tag [ <tag1> <tag2>... ] set rulebase decryption rules <name> negate-source <yes|no> set rulebase decryption rules <name> negate-destination <yes|no> set rulebase decryption rules <name> disabled <yes|no> set rulebase decryption rules <name> description <value> set rulebase decryption rules <name> group-tag <value> set rulebase decryption rules <name> source-hip [ <source-hip1> <source-hip2>... ] set rulebase decryption rules <name> destination-hip [ <destination-hip1> <destination-hip2>... ] set rulebase decryption rules <name> service [ <service1> <service2>... ] set rulebase decryption rules <name> category [ <category1> <category2>... ] set rulebase decryption rules <name> action <no-decrypt|decrypt> set rulebase decryption rules <name> type set rulebase decryption rules <name> type ssl-forward-proxy set rulebase decryption rules <name> type ssh-proxy set rulebase decryption rules <name> type ssl-inbound-inspection set rulebase decryption rules <name> type ssl-inbound-inspection certificates [ <certificates1> <certificates2>... ] set rulebase decryption rules <name> profile <value> set rulebase decryption rules <name> log-success <yes|no> set rulebase decryption rules <name> log-fail <yes|no> set rulebase decryption rules <name> log-setting <value> set rulebase authentication set rulebase authentication rules set rulebase authentication rules <name> set rulebase authentication rules <name> from [ <from1> <from2>... ] set rulebase authentication rules <name> to [ <to1> <to2>... ] set rulebase authentication rules <name> source [ <source1> <source2>... ] set rulebase authentication rules <name> source-user [ <source-user1> <source-user2>... ] set rulebase authentication rules <name> destination [ <destination1> <destination2>... ] set rulebase authentication rules <name> source-hip [ <source-hip1> <source-hip2>... ] set rulebase authentication rules <name> destination-hip [ <destination-hip1> <destination-hip2>... ] set rulebase authentication rules <name> tag [ <tag1> <tag2>... ] set rulebase authentication rules <name> negate-source <yes|no> set rulebase authentication rules <name> negate-destination <yes|no> set rulebase authentication rules <name> disabled <yes|no> set rulebase authentication rules <name> description <value> set rulebase authentication rules <name> group-tag <value> set rulebase authentication rules <name> service [ <service1> <service2>... ] set rulebase authentication rules <name> category [ <category1> <category2>... ] set rulebase authentication rules <name> authentication-enforcement <value> set rulebase authentication rules <name> log-setting <value> set rulebase authentication rules <name> timeout <1-1440> set rulebase authentication rules <name> log-authentication-timeout <yes|no> set rulebase tunnel-inspect set rulebase tunnel-inspect rules set rulebase tunnel-inspect rules <name> set rulebase tunnel-inspect rules <name> from [ <from1> <from2>... ] set rulebase tunnel-inspect rules <name> to [ <to1> <to2>... ] set rulebase tunnel-inspect rules <name> source [ <source1> <source2>... ] set rulebase tunnel-inspect rules <name> source-user [ <source-user1> <source-user2>... ] set rulebase tunnel-inspect rules <name> destination [ <destination1> <destination2>... ] set rulebase tunnel-inspect rules <name> tag [ <tag1> <tag2>... ] set rulebase tunnel-inspect rules <name> negate-source <yes|no> set rulebase tunnel-inspect rules <name> negate-destination <yes|no> set rulebase tunnel-inspect rules <name> disabled <yes|no> set rulebase tunnel-inspect rules <name> description <value> set rulebase tunnel-inspect rules <name> group-tag <value> set rulebase tunnel-inspect rules <name> application [ <application1> <application2>... ] set rulebase tunnel-inspect rules <name> tunnel-id set rulebase tunnel-inspect rules <name> tunnel-id vni set rulebase tunnel-inspect rules <name> tunnel-id vni <name> set rulebase tunnel-inspect rules <name> tunnel-id vni <name> id <0-16777215,...> set rulebase tunnel-inspect rules <name> inspect-options set rulebase tunnel-inspect rules <name> inspect-options max-level-inspection <1|2> set rulebase tunnel-inspect rules <name> inspect-options drop-over-max <yes|no> set rulebase tunnel-inspect rules <name> inspect-options drop-unknown-protocol <yes|no> set rulebase tunnel-inspect rules <name> inspect-options drop-strict-checking <yes|no> set rulebase tunnel-inspect rules <name> inspect-options return-vxlan-to-source <yes|no> set rulebase tunnel-inspect rules <name> zone-assign set rulebase tunnel-inspect rules <name> zone-assign source [ <source1> <source2>... ] set rulebase tunnel-inspect rules <name> zone-assign destination [ <destination1> <destination2>... ] set rulebase tunnel-inspect rules <name> monitor-options set rulebase tunnel-inspect rules <name> monitor-options monitor-name <value> set rulebase tunnel-inspect rules <name> monitor-options monitor-id <1-16777215> set rulebase tunnel-inspect rules <name> monitor-options log-setting-override set rulebase tunnel-inspect rules <name> monitor-options log-setting-override enable <yes|no> set rulebase tunnel-inspect rules <name> monitor-options log-setting-override log-setting <value> set rulebase tunnel-inspect rules <name> monitor-options log-setting-override log-start <yes|no> set rulebase tunnel-inspect rules <name> monitor-options log-setting-override log-end <yes|no> set rulebase nat set rulebase nat rules set rulebase nat rules <name> set rulebase nat rules <name> from [ <from1> <from2>... ] set rulebase nat rules <name> to [ <to1> <to2>... ] set rulebase nat rules <name> source [ <source1> <source2>... ] set rulebase nat rules <name> destination [ <destination1> <destination2>... ] set rulebase nat rules <name> service <value> set rulebase nat rules <name> nat-type <ipv4|nat64|nptv6> set rulebase nat rules <name> to-interface <value>|<any> set rulebase nat rules <name> source-translation set rulebase nat rules <name> source-translation dynamic-ip-and-port set rulebase nat rules <name> source-translation dynamic-ip-and-port translated-address [ <translated-address1> <translated-address2>... ] set rulebase nat rules <name> source-translation dynamic-ip-and-port interface-address set rulebase nat rules <name> source-translation dynamic-ip-and-port interface-address interface <value> set rulebase nat rules <name> source-translation dynamic-ip-and-port interface-address ip <value> set rulebase nat rules <name> source-translation dynamic-ip-and-port interface-address floating-ip <value> set rulebase nat rules <name> source-translation dynamic-ip set rulebase nat rules <name> source-translation dynamic-ip translated-address [ <translated-address1> <translated-address2>... ] set rulebase nat rules <name> source-translation dynamic-ip fallback set rulebase nat rules <name> source-translation dynamic-ip fallback translated-address [ <translated-address1> <translated-address2>... ] set rulebase nat rules <name> source-translation dynamic-ip fallback interface-address set rulebase nat rules <name> source-translation dynamic-ip fallback interface-address interface <value> set rulebase nat rules <name> source-translation dynamic-ip fallback interface-address ip <value> set rulebase nat rules <name> source-translation dynamic-ip fallback interface-address floating-ip <value> set rulebase nat rules <name> source-translation static-ip set rulebase nat rules <name> source-translation static-ip translated-address <value>|<ip/netmask>|<ip-range> set rulebase nat rules <name> source-translation static-ip bi-directional <yes|no> set rulebase nat rules <name> destination-translation set rulebase nat rules <name> destination-translation translated-address <value>|<ip/netmask>|<ip-range> set rulebase nat rules <name> destination-translation translated-port <1-65535> set rulebase nat rules <name> destination-translation dns-rewrite set rulebase nat rules <name> destination-translation dns-rewrite direction <reverse|forward> set rulebase nat rules <name> dynamic-destination-translation set rulebase nat rules <name> dynamic-destination-translation translated-address <value>|<ip/netmask>|<ip-range> set rulebase nat rules <name> dynamic-destination-translation translated-port <1-65535> set rulebase nat rules <name> dynamic-destination-translation distribution <round-robin|source-ip-hash|ip-modulo|ip-hash|least-sessions> set rulebase nat rules <name> active-active-device-binding <primary|both|0|1> set rulebase nat rules <name> tag [ <tag1> <tag2>... ] set rulebase nat rules <name> disabled <yes|no> set rulebase nat rules <name> description <value> set rulebase nat rules <name> group-tag <value> set rulebase qos set rulebase qos rules set rulebase qos rules <name> set rulebase qos rules <name> from [ <from1> <from2>... ] set rulebase qos rules <name> to [ <to1> <to2>... ] set rulebase qos rules <name> source [ <source1> <source2>... ] set rulebase qos rules <name> source-user [ <source-user1> <source-user2>... ] set rulebase qos rules <name> destination [ <destination1> <destination2>... ] set rulebase qos rules <name> service [ <service1> <service2>... ] set rulebase qos rules <name> category [ <category1> <category2>... ] set rulebase qos rules <name> application [ <application1> <application2>... ] set rulebase qos rules <name> source-hip [ <source-hip1> <source-hip2>... ] set rulebase qos rules <name> destination-hip [ <destination-hip1> <destination-hip2>... ] set rulebase qos rules <name> schedule <value> set rulebase qos rules <name> tag [ <tag1> <tag2>... ] set rulebase qos rules <name> negate-source <yes|no> set rulebase qos rules <name> negate-destination <yes|no> set rulebase qos rules <name> disabled <yes|no> set rulebase qos rules <name> description <value> set rulebase qos rules <name> group-tag <value> set rulebase qos rules <name> dscp-tos set rulebase qos rules <name> dscp-tos any set rulebase qos rules <name> dscp-tos codepoints set rulebase qos rules <name> dscp-tos codepoints <name> set rulebase qos rules <name> dscp-tos codepoints <name> ef set rulebase qos rules <name> dscp-tos codepoints <name> ef codepoint <ef> set rulebase qos rules <name> dscp-tos codepoints <name> af set rulebase qos rules <name> dscp-tos codepoints <name> af codepoint <af11|af12|af13|af21|af22|af23|af31|af32|af33|af41|af42|af43> set rulebase qos rules <name> dscp-tos codepoints <name> cs set rulebase qos rules <name> dscp-tos codepoints <name> cs codepoint <cs0|cs1|cs2|cs3|cs4|cs5|cs6|cs7> set rulebase qos rules <name> dscp-tos codepoints <name> tos set rulebase qos rules <name> dscp-tos codepoints <name> tos codepoint <cs0|cs1|cs2|cs3|cs4|cs5|cs6|cs7> set rulebase qos rules <name> dscp-tos codepoints <name> custom set rulebase qos rules <name> dscp-tos codepoints <name> custom codepoint set rulebase qos rules <name> dscp-tos codepoints <name> custom codepoint name <value> set rulebase qos rules <name> dscp-tos codepoints <name> custom codepoint value <value> set rulebase qos rules <name> action set rulebase qos rules <name> action class <1|2|3|4|5|6|7|8> set rulebase pbf set rulebase pbf rules set rulebase pbf rules <name> set rulebase pbf rules <name> from set rulebase pbf rules <name> from zone [ <zone1> <zone2>... ] set rulebase pbf rules <name> from interface [ <interface1> <interface2>... ] set rulebase pbf rules <name> source [ <source1> <source2>... ] set rulebase pbf rules <name> source-user [ <source-user1> <source-user2>... ] set rulebase pbf rules <name> destination [ <destination1> <destination2>... ] set rulebase pbf rules <name> service [ <service1> <service2>... ] set rulebase pbf rules <name> schedule <value> set rulebase pbf rules <name> tag [ <tag1> <tag2>... ] set rulebase pbf rules <name> negate-source <yes|no> set rulebase pbf rules <name> negate-destination <yes|no> set rulebase pbf rules <name> disabled <yes|no> set rulebase pbf rules <name> description <value> set rulebase pbf rules <name> group-tag <value> set rulebase pbf rules <name> application [ <application1> <application2>... ] set rulebase pbf rules <name> action set rulebase pbf rules <name> action forward set rulebase pbf rules <name> action forward egress-interface <value> set rulebase pbf rules <name> action forward nexthop set rulebase pbf rules <name> action forward nexthop ip-address <value>|<ip/netmask> set rulebase pbf rules <name> action forward nexthop fqdn <value> set rulebase pbf rules <name> action forward monitor set rulebase pbf rules <name> action forward monitor profile <value> set rulebase pbf rules <name> action forward monitor disable-if-unreachable <yes|no> set rulebase pbf rules <name> action forward monitor ip-address <ip/netmask> set rulebase pbf rules <name> action discard set rulebase pbf rules <name> action no-pbf set rulebase pbf rules <name> enforce-symmetric-return set rulebase pbf rules <name> enforce-symmetric-return enabled <yes|no> set rulebase pbf rules <name> enforce-symmetric-return nexthop-address-list set rulebase pbf rules <name> enforce-symmetric-return nexthop-address-list <name> set rulebase pbf rules <name> active-active-device-binding <both|0|1> set rulebase sdwan set rulebase sdwan rules set rulebase sdwan rules <name> set rulebase sdwan rules <name> from [ <from1> <from2>... ] set rulebase sdwan rules <name> to [ <to1> <to2>... ] set rulebase sdwan rules <name> source [ <source1> <source2>... ] set rulebase sdwan rules <name> source-user [ <source-user1> <source-user2>... ] set rulebase sdwan rules <name> destination [ <destination1> <destination2>... ] set rulebase sdwan rules <name> application [ <application1> <application2>... ] set rulebase sdwan rules <name> service [ <service1> <service2>... ] set rulebase sdwan rules <name> tag [ <tag1> <tag2>... ] set rulebase sdwan rules <name> negate-source <yes|no> set rulebase sdwan rules <name> negate-destination <yes|no> set rulebase sdwan rules <name> disabled <yes|no> set rulebase sdwan rules <name> description <value> set rulebase sdwan rules <name> group-tag <value> set rulebase sdwan rules <name> path-quality-profile <value> set rulebase sdwan rules <name> saas-quality-profile <value> set rulebase sdwan rules <name> error-correction-profile <value> set rulebase sdwan rules <name> action set rulebase sdwan rules <name> action traffic-distribution-profile <value> set rulebase sdwan rules <name> action app-failover-for-nat-sessions <keep-existing-link|failover-to-better-path> set rulebase dos set rulebase dos rules set rulebase dos rules <name> set rulebase dos rules <name> from set rulebase dos rules <name> from zone [ <zone1> <zone2>... ] set rulebase dos rules <name> from interface [ <interface1> <interface2>... ] set rulebase dos rules <name> to set rulebase dos rules <name> to zone [ <zone1> <zone2>... ] set rulebase dos rules <name> to interface [ <interface1> <interface2>... ] set rulebase dos rules <name> source [ <source1> <source2>... ] set rulebase dos rules <name> source-user [ <source-user1> <source-user2>... ] set rulebase dos rules <name> destination [ <destination1> <destination2>... ] set rulebase dos rules <name> service [ <service1> <service2>... ] set rulebase dos rules <name> schedule <value> set rulebase dos rules <name> tag [ <tag1> <tag2>... ] set rulebase dos rules <name> negate-source <yes|no> set rulebase dos rules <name> negate-destination <yes|no> set rulebase dos rules <name> disabled <yes|no> set rulebase dos rules <name> description <value> set rulebase dos rules <name> group-tag <value> set rulebase dos rules <name> protection set rulebase dos rules <name> protection aggregate set rulebase dos rules <name> protection aggregate profile <value> set rulebase dos rules <name> protection classified set rulebase dos rules <name> protection classified profile <value> set rulebase dos rules <name> protection classified classification-criteria set rulebase dos rules <name> protection classified classification-criteria address <source-ip-only|destination-ip-only|src-dest-ip-both> set rulebase dos rules <name> action set rulebase dos rules <name> action deny set rulebase dos rules <name> action allow set rulebase dos rules <name> action protect set rulebase dos rules <name> log-setting <value> set rulebase network-packet-broker set rulebase network-packet-broker rules set rulebase network-packet-broker rules <name> set rulebase network-packet-broker rules <name> from [ <from1> <from2>... ] set rulebase network-packet-broker rules <name> to [ <to1> <to2>... ] set rulebase network-packet-broker rules <name> source [ <source1> <source2>... ] set rulebase network-packet-broker rules <name> source-user [ <source-user1> <source-user2>... ] set rulebase network-packet-broker rules <name> destination [ <destination1> <destination2>... ] set rulebase network-packet-broker rules <name> application [ <application1> <application2>... ] set rulebase network-packet-broker rules <name> service [ <service1> <service2>... ] set rulebase network-packet-broker rules <name> tag [ <tag1> <tag2>... ] set rulebase network-packet-broker rules <name> negate-source <yes|no> set rulebase network-packet-broker rules <name> negate-destination <yes|no> set rulebase network-packet-broker rules <name> disabled <yes|no> set rulebase network-packet-broker rules <name> description <value> set rulebase network-packet-broker rules <name> group-tag <value> set rulebase network-packet-broker rules <name> source-hip [ <source-hip1> <source-hip2>... ] set rulebase network-packet-broker rules <name> destination-hip [ <destination-hip1> <destination-hip2>... ] set rulebase network-packet-broker rules <name> traffic-type set rulebase network-packet-broker rules <name> traffic-type tls-decrypted <yes|no> set rulebase network-packet-broker rules <name> traffic-type tls-encrypted <yes|no> set rulebase network-packet-broker rules <name> traffic-type non-tls <yes|no> set rulebase network-packet-broker rules <name> action set rulebase network-packet-broker rules <name> action packet-broker-profile <value>