Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Gongya_Yu
Contributor

Anyway I can show all the rules for a section?

Is there anyway I can show all the rules under a specific section ?

 

thanks !!

0 Kudos
10 Replies
the_rock
Legend
Legend

I assume you mean via mgmt_cli/api method?

Andy

0 Kudos
Gongya_Yu
Contributor

Yes.  I showed rule-based to get all the sections based on the suggestion I got from the community. Now I moved to display all the rules in a specific section. I am wondering whether I can specify the section to search the rule base. Now I get the From and To for a section via show rule-based.  then use them as offset and limit. It works. but I am wondering whether I can save the first step to get the From and To for a section.

 

thanks !!

0 Kudos
the_rock
Legend
Legend

Not sure until I can test it in the lab tomorrow. Whats the command you did? If you can give an example here, I can try it myself in R81.20 lab

Andy

0 Kudos
Gongya_Yu
Contributor

First I use the following to get the rule range
show access-rulebase name ' security_package' limit 1200 | grep -A 3 'section'

Then I use the following to get the rules

show access-rulebase name 'security_package' limit " + str(limit) + " offset " + str(offset)

to get the range of rules.

Wondering whether I can combine these 2 into one.

thanks !!

0 Kudos
the_rock
Legend
Legend

Sorry, was busy today, had to do bunch of Fortigate stuff, but will try tomorrow, promise.

Cheers,

Andy

0 Kudos
Gongya_Yu
Contributor

thanks !!

the_rock
Legend
Legend

For you, no charge....EXCEPT iphone charge ; - )

0 Kudos
the_rock
Legend
Legend

Sorry for the delay, had another CP major ospf issue...NOT my favorite subject lol

Anyway, I ran the commands you gave, but so far, I cant logically see a way of combining them, but will keep trying.

Andy

0 Kudos
Gongya_Yu
Contributor

thanks so much !!

0 Kudos
PhoneBoy
Admin
Admin

Note that using a limit of greater than 500 with show access-rulebase will produce inconsistent results (namely, all the requested results may not be returned).
For this many rules, you will need to use multiple API calls with limit/offset to page through the results.
Bottom line: this operation cannot be done in a single operation and will probably have to be turned into a script.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events