batfish / batfish

Batfish is a network configuration analysis tool that can find bugs and guarantee the correctness of (planned or current) network configurations. It enables network engineers to rapidly and safely evolve their network, without fear of outages or security breaches.

Home Page:http://www.batfish.org

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Does Batfish support Palo (individual devices)

mthomati opened this issue · comments

Hi. I’m looking into including Palo Alto network configs with our snapshot, however, I don’t see a lot of use cases and the documentation isn’t correct.

Based on the documentation (https://batfish.readthedocs.io/en/latest/formats.html#palo-alto-networks) for including Palo Alto individual config, the following commands are operational commands, not configuration commands:

show config pushed-shared-policy
show config pushed-shared-policy vsys <value> // run for each vsys
show config merged

Those provided commands will only be displayed in XML. Please advise on the correct commands and instructions to build the necessary config from an individual Palo Alto device. Thanks!

Hi, I could get a parsable configuration with the following commands, on a PAN-OS 10.x box:

set cli config-output-format set
set cli pager off
configure
show