CLI
Focus
Focus
Prisma AIRS

CLI

Table of Contents


CLI

Configure DPU traffic steering rules for your NVIDIA BlueField-3 embedded Prisma AIRS firewalls using PAN-OS CLI commands.
  1. Enter configuration mode on the firewall to define steering flow rules using the following syntax:
    set deviceconfig plugins vm_series steering-flow <rule-name> action <inspect|allow|drop> in-port <port-name> priority <2-65535> match [ source-subnet <CIDR> ] [ destination-subnet <CIDR> ] [ protocol <any|tcp|udp|icmp> ] [ source-port <0-65535> ] [ destination-port <0-65535> ]
  2. Configure steering rules for your traffic types. Use the following examples as a reference:
    Inspect HTTPS traffic from a host subnet:
    set deviceconfig plugins vm_series steering-flow test1 action inspect in-port p0 priority 100 match source-subnet 10.1.1.0/24 destination-subnet 10.2.0.0/24 protocol tcp destination-port 443 commit
    Inspect all TCP traffic from a specific host IP:
    set deviceconfig plugins vm_series steering-flow inspect-tcp-10-4-50-89 action inspect in-port p0 priority 50 match source-subnet 10.4.50.89/32 protocol tcp commit
  3. Verify the active steering flow rules:
    admin@PA-VMARM> show plugins vm_series steering-flow
    The output lists all configured steering rules with their name, enabled state, in-port, priority, action, protocol, source subnet, destination subnet, and port values. Example output:
    Steering Flow Rules (501 configured): Name Enable In-Port Priority Action Protocol Source Subnet Dest Subnet SPort DPort --------------------------------------------------------------------------------------------------------- SteeringRule-CPT yes p0 100 inspect any 174.1.0.0/24 174.2.0.0/24 0 0 SteeringRule1 yes p0 101 inspect any 1.1.1.5 2.2.2.0/24 0 0 SteeringRule2 yes p0 102 inspect any 1.1.1.6 2.2.2.0/24 0 0 SteeringRule3 yes p0 103 inspect any 1.1.1.7 2.2.2.0/24 0 0
  4. Verify traffic statistics and packet counts:
    admin@PA-VMARM> show plugins vm_series steering-flow-stats