show ip-defense status
Verify that Cloud connection shows Connected and
Last Result shows Good.
admin@PA-XXXX> show ip-defense status
Advanced IP Defense cloud
License: Valid
Configurations: Enabled
Current cloud server: api.prod.aipd.service.paloaltonetworks.com
Cloud connection: Connected
Last Result: Good ( 14 sec ago )
Allowlist Refresh: Interval 1800 sec ( Due 944 sec )
Last up time: 2026/08/21 15:22:39 to now
Last down time: N/A
Cookies Information :
Region state: Assigned
Region ID: us-central1
Region timestamp: 2026/08/21 15:22:39
TSG state: Assigned
TSG ID: 1234567890
TSG timestamp: 2026/08/21 15:22:39
Certificate Information :
Thermite : Available
Subject : CN = 00XXXXXXXXXXX, O = Palo Alto Networks, L = Santa Clara, ST = CA, C = US
Issuer : CN = USC-Client-Issuing-CA2-G5, O = Palo-Alto-Networks-Inc., C = US
CA : no
Not-valid-before : Aug 17 23:03:01 2026 GMT
Not-valid-after : Nov 15 23:03:00 2026 GMT
Key fields to check:
- License—Must show Valid. If not, verify your license
activation in the Customer Support Portal.
- Cloud connection—Must show Connected. If disconnected,
check network connectivity to Advanced IP Defense endpoints on TCP
443.
- Allowlist Refresh—Shows the refresh interval and time until the next
pull. Confirms the enforcement point is actively retrieving allow list
updates.
- Region state—Must show Assigned. Indicates the
enforcement point has been assigned to a regional cloud endpoint.