{"resources":{"asset":{"id":"asset","name":"asset","fields":{"purl":{"name":"purl","type":"\u0007","title":"Package URL (purl) identifying the PAN-OS platform of this asset","provider":"go.mondoo.com/cnquery/providers/panos"}},"is_extension":true,"provider":"go.mondoo.com/cnquery/providers/panos"},"panos":{"id":"panos","name":"panos","fields":{"aggregateInterfaces":{"name":"aggregateInterfaces","type":"\u0019\u001bpanos.network.aggregateInterface","title":"Aggregate interfaces (firewall only)","desc":"Link-aggregation (LACP) bundle interfaces (for example ae1) that combine several physical ethernet interfaces for bandwidth and redundancy, with their LACP configuration, addressing, and runtime state. Resolves to null on Panorama.","provider":"go.mondoo.com/cnquery/providers/panos"},"authenticationProfiles":{"name":"authenticationProfiles","type":"\u0019\u001bpanos.device.authenticationProfile","title":"Authentication profiles","desc":"Profiles that bind an authentication method (local database, RADIUS, LDAP, Kerberos, TACACS+, or SAML) to lockout and MFA settings for administrator and end-user logins.","provider":"go.mondoo.com/cnquery/providers/panos"},"certificate":{"name":"certificate","type":"\u001bpanos.certificate","title":"PAN-OS certificate entry","desc":"A certificate held in the device configuration, whether an end-entity certificate or a CA. Exposes the subject and issuer, signing algorithm, validity window, and revocation status. Useful for finding expired or soon-to-expire certificates, non-CA certificates signed with weak algorithms, or CA certificates. Selected by `name` within the certificates collection.","provider":"go.mondoo.com/cnquery/providers/panos","is_implicit_resource":true},"certificates":{"name":"certificates","type":"\u0019\u001bpanos.certificate","title":"Certificates installed on the device","desc":"Device and CA certificates in the configuration, with subject, issuer, signing algorithm, validity window, and revocation status. Useful for finding expired certificates or weak signing algorithms across the device, for example `panos.certificates.where(status == \"revoked\")`.","provider":"go.mondoo.com/cnquery/providers/panos"},"decryption":{"name":"decryption","type":"\u001bpanos.decryption","provider":"go.mondoo.com/cnquery/providers/panos","is_implicit_resource":true},"decryptionRules":{"name":"decryptionRules","type":"\u0019\u001bpanos.decryption.rule","title":"Decryption policy rules (firewall only)","desc":"Ordered decryption rulebase governing which TLS/SSH sessions are decrypted for inspection, the decryption type, and the certificate and profile applied. Useful for auditing decryption coverage. Resolves to null on Panorama.","provider":"go.mondoo.com/cnquery/providers/panos"},"device":{"name":"device","type":"\u001bpanos.device","provider":"go.mondoo.com/cnquery/providers/panos","is_implicit_resource":true},"dhcpInterfaces":{"name":"dhcpInterfaces","type":"\u0019\u001bpanos.network.dhcpInterface","title":"DHCP interface configurations (firewall only)","desc":"Per-interface DHCP relay configuration for IPv4 and IPv6. Resolves to null on Panorama.","provider":"go.mondoo.com/cnquery/providers/panos"},"ethernetInterfaces":{"name":"ethernetInterfaces","type":"\u0019\u001bpanos.network.ethernetInterface","title":"Ethernet interfaces (firewall only)","desc":"Physical ethernet interfaces (for example ethernet1/1) with their configured mode, addressing, MTU, LLDP/LACP settings, and runtime operational state (link status, speed, duplex, assigned zone). Interfaces in `ha` or `aggregate-group` mode are excluded (the latter appear under aggregateInterfaces). Resolves to null on Panorama.","provider":"go.mondoo.com/cnquery/providers/panos"},"generalSettings":{"name":"generalSettings","type":"\u001bpanos.device.generalSettings","title":"General device settings (firewall only)","desc":"Management-plane settings such as hostname, management addressing, DNS and NTP servers, update server, login banner, and Panorama connection. Resolves to null on Panorama.","provider":"go.mondoo.com/cnquery/providers/panos"},"ha":{"name":"ha","type":"\u001bpanos.ha","title":"High availability configuration (firewall only)","desc":"Active-passive or active-active HA settings, including peer control-link (HA1) addresses, configuration and state (HA2) synchronization, election priority and preemption, and link monitoring. Resolves to null on Panorama; on a firewall with HA not configured it is still returned with `enabled` false so audits can assert HA is or is not in use.","provider":"go.mondoo.com/cnquery/providers/panos"},"ikeGateways":{"name":"ikeGateways","type":"\u0019\u001bpanos.network.ikeGateway","title":"IKE gateways (firewall only)","desc":"IKE (Internet Key Exchange) gateway definitions for site-to-site VPN, including IKE version, peer addressing, authentication method, and crypto profiles. Useful for auditing VPN authentication strength. Resolves to null on Panorama.","provider":"go.mondoo.com/cnquery/providers/panos"},"ipsecTunnels":{"name":"ipsecTunnels","type":"\u0019\u001bpanos.network.ipsecTunnel","title":"IPsec tunnels (firewall only)","desc":"IPsec tunnel definitions binding a tunnel interface to an IKE gateway and IPsec crypto profile, with tunnel-monitoring settings. Resolves to null on Panorama.","provider":"go.mondoo.com/cnquery/providers/panos"},"kerberosProfiles":{"name":"kerberosProfiles","type":"\u0019\u001bpanos.device.kerberosProfile","title":"Kerberos server profiles","desc":"Kerberos authentication profiles configured on the device.","provider":"go.mondoo.com/cnquery/providers/panos"},"ldapProfiles":{"name":"ldapProfiles","type":"\u0019\u001bpanos.device.ldapProfile","title":"LDAP server profiles","desc":"LDAP directory connection profiles, including directory type, SSL/TLS use, certificate verification, and search parameters. Useful for auditing that directory connections are encrypted and verified.","provider":"go.mondoo.com/cnquery/providers/panos"},"license":{"name":"license","type":"\u001bpanos.license","title":"PAN-OS license entry","desc":"A single activated subscription or capability on the device (for example Threat Prevention, WildFire, URL Filtering, GlobalProtect, or the base support license), with its issue and expiry dates and current expired flag. Filter by `feature` to check a specific subscription, or by `expired` to surface lapsed entitlements.","provider":"go.mondoo.com/cnquery/providers/panos","is_implicit_resource":true},"licenses":{"name":"licenses","type":"\u0019\u001bpanos.license","title":"Licenses installed on the device","desc":"Each entry describes an activated PAN-OS subscription or capability (for example Threat Prevention, WildFire, URL Filtering, GlobalProtect, or the base support license) with its issue and expiry dates. Useful for auditing expired or soon-to-expire subscriptions, for example `panos.licenses.where(expired == \"yes\")`.","provider":"go.mondoo.com/cnquery/providers/panos"},"localUserGroups":{"name":"localUserGroups","type":"\u0019\u001bpanos.device.localUserGroup","title":"Local user database groups","desc":"Groups defined in the device's local authentication database and their member users.","provider":"go.mondoo.com/cnquery/providers/panos"},"localUsers":{"name":"localUsers","type":"\u0019\u001bpanos.device.localUser","title":"Local user database users","desc":"Users defined in the device's local authentication database, with their enabled/disabled state.","provider":"go.mondoo.com/cnquery/providers/panos"},"loopbackInterfaces":{"name":"loopbackInterfaces","type":"\u0019\u001bpanos.network.loopbackInterface","title":"Loopback interfaces (firewall only)","desc":"Logical loopback interfaces (for example loopback.1) with their addressing, management profile, and assigned zone. Resolves to null on Panorama.","provider":"go.mondoo.com/cnquery/providers/panos"},"nat":{"name":"nat","type":"\u001bpanos.nat","provider":"go.mondoo.com/cnquery/providers/panos","is_implicit_resource":true},"natRules":{"name":"natRules","type":"\u0019\u001bpanos.nat.rule","title":"NAT policy rules (firewall only)","desc":"Ordered NAT rulebase describing source and destination address translation applied to matching traffic. Resolves to null on Panorama.","provider":"go.mondoo.com/cnquery/providers/panos"},"network":{"name":"network","type":"\u001bpanos.network","provider":"go.mondoo.com/cnquery/providers/panos","is_implicit_resource":true},"pbf":{"name":"pbf","type":"\u001bpanos.pbf","provider":"go.mondoo.com/cnquery/providers/panos","is_implicit_resource":true},"pbfRules":{"name":"pbfRules","type":"\u0019\u001bpanos.pbf.rule","title":"Policy-based forwarding rules (firewall only)","desc":"Ordered policy-based-forwarding rulebase that overrides the routing table to steer matching traffic to a specific egress interface or next hop. Resolves to null on Panorama.","provider":"go.mondoo.com/cnquery/providers/panos"},"radiusProfiles":{"name":"radiusProfiles","type":"\u0019\u001bpanos.device.radiusProfile","title":"RADIUS server profiles","desc":"RADIUS connection profiles with their timeout and retry settings.","provider":"go.mondoo.com/cnquery/providers/panos"},"samlProfiles":{"name":"samlProfiles","type":"\u0019\u001bpanos.device.samlProfile","title":"SAML identity provider profiles","desc":"SAML identity-provider profiles used for administrator and user single sign-on, including the IdP entity ID, SSO/SLO endpoints, certificate validation, and message-signing settings.","provider":"go.mondoo.com/cnquery/providers/panos"},"security":{"name":"security","type":"\u001bpanos.security","provider":"go.mondoo.com/cnquery/providers/panos","is_implicit_resource":true},"securityRules":{"name":"securityRules","type":"\u0019\u001bpanos.security.rule","title":"Security policy rules (firewall only)","desc":"Ordered security policy rulebase controlling which traffic is allowed or denied between zones, along with the security profiles applied to matching sessions. Central to firewall posture audits, for example finding permissive rules with `panos.securityRules.where(action == \"allow\")`. Resolves to null on Panorama.","provider":"go.mondoo.com/cnquery/providers/panos"},"service":{"name":"service","type":"\u001bpanos.service","title":"PAN-OS service object","desc":"A named Layer-4 service (protocol plus source and destination port ranges) referenced by security, NAT, and policy-based-forwarding rules. May optionally override the protocol's default session timeouts. Select one directly by name, for example `panos.service(\"service-https\")`. The port fields are free-form strings holding a single port, a comma-separated list, or a range (e.g., \"443\", \"80,443\", \"1024-65535\").","provider":"go.mondoo.com/cnquery/providers/panos","is_implicit_resource":true},"serviceGroup":{"name":"serviceGroup","type":"\u001bpanos.serviceGroup","title":"PAN-OS service group","desc":"A named group of service objects referenced by policy as a single unit. Select one directly by name, for example `panos.serviceGroup(\"web-services\")`. The `services` field lists the member names, which may be service objects or other nested service groups.","provider":"go.mondoo.com/cnquery/providers/panos","is_implicit_resource":true},"serviceGroups":{"name":"serviceGroups","type":"\u0019\u001bpanos.serviceGroup","title":"Service groups (firewall only)","desc":"Named groups of service objects referenced by policy. Select one by name, for example `panos.serviceGroups(\"web-services\")`. Resolves to null on Panorama.","provider":"go.mondoo.com/cnquery/providers/panos"},"services":{"name":"services","type":"\u0019\u001bpanos.service","title":"Service objects (firewall only)","desc":"Named TCP/UDP service objects (protocol plus port ranges) referenced by security and NAT policy. Select one by name, for example `panos.services(\"service-https\")`. Resolves to null on Panorama.","provider":"go.mondoo.com/cnquery/providers/panos"},"sslDecrypt":{"name":"sslDecrypt","type":"\u001bpanos.device.sslDecrypt","title":"SSL decryption settings (firewall only)","desc":"Forward-trust and forward-untrust certificates and trusted root CA configuration used by SSL forward-proxy decryption. Resolves to null on Panorama.","provider":"go.mondoo.com/cnquery/providers/panos"},"sslTlsProfiles":{"name":"sslTlsProfiles","type":"\u0019\u001bpanos.device.sslTlsProfile","title":"SSL/TLS service profiles","desc":"Profiles that constrain the TLS versions, key-exchange algorithms, ciphers, and authentication algorithms offered by device services. Useful for auditing that weak protocols and ciphers are disabled.","provider":"go.mondoo.com/cnquery/providers/panos"},"syslogProfiles":{"name":"syslogProfiles","type":"\u0019\u001bpanos.device.syslogProfile","title":"Syslog server profiles","desc":"Named profiles grouping the syslog servers that logs are forwarded to, with their transport, port, and format. Useful for confirming logging is exported off-box.","provider":"go.mondoo.com/cnquery/providers/panos"},"system":{"name":"system","type":"\u001bpanos.system","title":"System information about the connected PAN-OS device","desc":"Hostname, model, serial number, software and content (App-ID, antivirus, threat, WildFire) versions, management-interface addressing, uptime, and mode flags such as whether the device is a VM or runs in FIPS-CC mode. Commonly used to assert on the running PAN-OS version or confirm FIPS mode via `panos.system`.","provider":"go.mondoo.com/cnquery/providers/panos"},"systemInfo":{"name":"systemInfo","type":"\n","title":"Raw system information map for the connected PAN-OS device","desc":"Deprecated, please use `system` instead. Returns the unparsed key/value map from the device's show-system-info operational command (keys such as hostname, sw-version, serial); the system resource exposes the same data with named, structured fields.","provider":"go.mondoo.com/cnquery/providers/panos","maturity":"deprecated"},"tacacsPlusProfiles":{"name":"tacacsPlusProfiles","type":"\u0019\u001bpanos.device.tacacsPlusProfile","title":"TACACS+ server profiles","desc":"TACACS+ connection profiles with their timeout and single-connection settings.","provider":"go.mondoo.com/cnquery/providers/panos"},"telemetry":{"name":"telemetry","type":"\u001bpanos.device.telemetry","title":"Telemetry settings (firewall only)","desc":"Which categories of telemetry and threat data the device shares with Palo Alto Networks. Resolves to null on Panorama.","provider":"go.mondoo.com/cnquery/providers/panos"},"tunnelInterfaces":{"name":"tunnelInterfaces","type":"\u0019\u001bpanos.network.tunnelInterface","title":"Tunnel interfaces (firewall only)","desc":"Logical tunnel interfaces (for example tunnel.1) used as the termination point for IPsec and other tunnels. Resolves to null on Panorama.","provider":"go.mondoo.com/cnquery/providers/panos"},"virtualRouters":{"name":"virtualRouters","type":"\u0019\u001bpanos.network.virtualRouter","title":"Virtual routers (firewall only)","desc":"Layer-3 routing instances, each with its interface membership, administrative distances, ECMP settings, static routes, and dynamic routing (BGP and OSPF) configuration. Resolves to null on Panorama.","provider":"go.mondoo.com/cnquery/providers/panos"},"vlanInterfaces":{"name":"vlanInterfaces","type":"\u0019\u001bpanos.network.vlanInterface","title":"VLAN interfaces (firewall only)","desc":"Logical VLAN interfaces (for example vlan.100) with their addressing and assigned zone. Resolves to null on Panorama.","provider":"go.mondoo.com/cnquery/providers/panos"},"zones":{"name":"zones","type":"\u0019\u001bpanos.network.zone","title":"Security zones (firewall only)","desc":"Network security zones and their member interfaces, zone-protection profile, User-ID and device-identification settings. Zones are the source and destination selectors of security policy. Resolves to null on Panorama.","provider":"go.mondoo.com/cnquery/providers/panos"}},"title":"Palo Alto Networks PAN-OS","desc":"Root of the PAN-OS provider, exposing the configuration and operational state of a connected Palo Alto Networks next-generation firewall or Panorama management appliance. From here you can reach system and license details, installed certificates, network interfaces and routing, security, NAT, decryption and policy-based-forwarding rules, security zones, VPN (IKE/IPsec) settings, device management and authentication profiles, and high-availability configuration. Many collections are firewall-only: on a Panorama connection they resolve to null rather than an error, so audits can branch on device type. Fields that require configuration-read access also resolve to null (with a warning) when the API user's role lacks the Configuration permission granted under Device \u003e Admin Roles.","provider":"go.mondoo.com/cnquery/providers/panos"},"panos.certificate":{"id":"panos.certificate","name":"panos.certificate","fields":{"algorithm":{"name":"algorithm","type":"\u0007","is_mandatory":true,"title":"Certificate key algorithm","desc":"Public-key algorithm of the certificate, for example \"RSA\" or \"EC\" (Elliptic Curve).","provider":"go.mondoo.com/cnquery/providers/panos"},"ca":{"name":"ca","type":"\u0004","is_mandatory":true,"title":"Whether this is a CA certificate","desc":"True when the certificate is a certificate authority that can sign other certificates (for example a forward-trust or root CA), false for an end-entity certificate.","provider":"go.mondoo.com/cnquery/providers/panos"},"commonName":{"name":"commonName","type":"\u0007","is_mandatory":true,"title":"Common name (CN) of the certificate subject","provider":"go.mondoo.com/cnquery/providers/panos"},"csr":{"name":"csr","type":"\u0007","is_mandatory":true,"title":"Certificate signing request in PEM form, when present","provider":"go.mondoo.com/cnquery/providers/panos"},"expiryEpoch":{"name":"expiryEpoch","type":"\u0007","is_mandatory":true,"title":"Expiry time as a Unix epoch timestamp string","provider":"go.mondoo.com/cnquery/providers/panos"},"issuer":{"name":"issuer","type":"\u0007","is_mandatory":true,"title":"Full distinguished name of the certificate issuer","provider":"go.mondoo.com/cnquery/providers/panos"},"issuerHash":{"name":"issuerHash","type":"\u0007","is_mandatory":true,"title":"Hash of the issuer","provider":"go.mondoo.com/cnquery/providers/panos"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Certificate name (the configuration object name)","provider":"go.mondoo.com/cnquery/providers/panos"},"notValidAfter":{"name":"notValidAfter","type":"\u0007","is_mandatory":true,"title":"Not-valid-after date (device-formatted string)","provider":"go.mondoo.com/cnquery/providers/panos"},"notValidBefore":{"name":"notValidBefore","type":"\u0007","is_mandatory":true,"title":"Not-valid-before date (device-formatted string)","provider":"go.mondoo.com/cnquery/providers/panos"},"privateKeyOnHsm":{"name":"privateKeyOnHsm","type":"\u0004","is_mandatory":true,"title":"Whether the private key is stored on a hardware security module (HSM)","provider":"go.mondoo.com/cnquery/providers/panos"},"revokeDateEpoch":{"name":"revokeDateEpoch","type":"\u0007","is_mandatory":true,"title":"Revocation date as a Unix epoch timestamp string, when revoked","provider":"go.mondoo.com/cnquery/providers/panos"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Certificate status","desc":"One of \"valid\" or \"revoked\".","provider":"go.mondoo.com/cnquery/providers/panos"},"subject":{"name":"subject","type":"\u0007","is_mandatory":true,"title":"Full distinguished name of the certificate subject","provider":"go.mondoo.com/cnquery/providers/panos"},"subjectHash":{"name":"subjectHash","type":"\u0007","is_mandatory":true,"title":"Hash of the subject, used internally to identify the certificate","provider":"go.mondoo.com/cnquery/providers/panos"}},"title":"PAN-OS certificate entry","desc":"A certificate held in the device configuration, whether an end-entity certificate or a CA. Exposes the subject and issuer, signing algorithm, validity window, and revocation status. Useful for finding expired or soon-to-expire certificates, non-CA certificates signed with weak algorithms, or CA certificates. Selected by `name` within the certificates collection.","defaults":"name status notValidAfter","provider":"go.mondoo.com/cnquery/providers/panos"},"panos.decryption":{"id":"panos.decryption","fields":{"rule":{"name":"rule","type":"\u001bpanos.decryption.rule","title":"PAN-OS decryption policy rule","desc":"A single rule in the decryption rulebase deciding which TLS/SSL and SSH sessions the firewall decrypts for inspection. `action` is one of decrypt, no-decrypt, or decrypt-and-forward (decrypt-and-forward requires PAN-OS 8.1+); `decryptionType` selects the method (ssl-forward-proxy, ssl-inbound-inspection, or ssh-proxy) and pairs with the certificate in sslCertificate and the profile in decryptionProfile. Matching narrows on source and destination zones, addresses, users, services, and URL categories. Rules are evaluated top-down and the first match wins, so order matters. Useful for auditing decryption coverage and finding no-decrypt exceptions, for example `panos.decryptionRules.where(action == \"no-decrypt\")`. Selected by `name`.","provider":"go.mondoo.com/cnquery/providers/panos","is_implicit_resource":true}},"is_extension":true},"panos.decryption.rule":{"id":"panos.decryption.rule","name":"panos.decryption.rule","fields":{"action":{"name":"action","type":"\u0007","is_mandatory":true,"title":"Decryption action","desc":"One of decrypt (decrypt and inspect the session), no-decrypt (allow the session to pass encrypted without inspection), or decrypt-and-forward (decrypt, inspect, then mirror to a decryption port for an external tool; PAN-OS 8.1+).","provider":"go.mondoo.com/cnquery/providers/panos"},"decryptionProfile":{"name":"decryptionProfile","type":"\u0007","is_mandatory":true,"title":"Name of the decryption profile enforcing protocol versions, cipher","desc":"suites, and certificate checks on matching sessions","provider":"go.mondoo.com/cnquery/providers/panos"},"decryptionType":{"name":"decryptionType","type":"\u0007","is_mandatory":true,"title":"Decryption type","desc":"Method used when the action decrypts. One of ssl-forward-proxy (decrypt outbound TLS by re-signing with a forward-trust CA), ssl-inbound-inspection (decrypt inbound TLS to an internal server whose certificate the firewall holds), or ssh-proxy (decrypt SSH to detect port forwarding).","provider":"go.mondoo.com/cnquery/providers/panos"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Rule description","provider":"go.mondoo.com/cnquery/providers/panos"},"destinationAddresses":{"name":"destinationAddresses","type":"\u0019\u0007","is_mandatory":true,"title":"Destination addresses the rule matches (address objects, groups, or \"any\")","provider":"go.mondoo.com/cnquery/providers/panos"},"destinationZones":{"name":"destinationZones","type":"\u0019\u0007","is_mandatory":true,"title":"Destination zones the rule matches, or \"any\"","provider":"go.mondoo.com/cnquery/providers/panos"},"disabled":{"name":"disabled","type":"\u0004","is_mandatory":true,"title":"Whether the rule is disabled and skipped during evaluation","provider":"go.mondoo.com/cnquery/providers/panos"},"groupTag":{"name":"groupTag","type":"\u0007","is_mandatory":true,"title":"Group tag used to visually group rules in the rulebase (PAN-OS 9.0+)","provider":"go.mondoo.com/cnquery/providers/panos"},"logFailedTlsHandshakes":{"name":"logFailedTlsHandshakes","type":"\u0004","is_mandatory":true,"title":"Whether the firewall logs failed TLS handshakes for matching","desc":"sessions (PAN-OS 10.0+)","provider":"go.mondoo.com/cnquery/providers/panos"},"logSetting":{"name":"logSetting","type":"\u0007","is_mandatory":true,"title":"Name of the log-forwarding profile applied to matching sessions,","desc":"empty when logs are not forwarded (PAN-OS 10.0+)","provider":"go.mondoo.com/cnquery/providers/panos"},"logSuccessfulTlsHandshakes":{"name":"logSuccessfulTlsHandshakes","type":"\u0004","is_mandatory":true,"title":"Whether the firewall logs successful TLS handshakes for matching","desc":"sessions (PAN-OS 10.0+)","provider":"go.mondoo.com/cnquery/providers/panos"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Rule name","provider":"go.mondoo.com/cnquery/providers/panos"},"negateDestination":{"name":"negateDestination","type":"\u0004","is_mandatory":true,"title":"Whether the destination address match is inverted","provider":"go.mondoo.com/cnquery/providers/panos"},"negateSource":{"name":"negateSource","type":"\u0004","is_mandatory":true,"title":"Whether the source address match is inverted","provider":"go.mondoo.com/cnquery/providers/panos"},"services":{"name":"services","type":"\u0019\u0007","is_mandatory":true,"title":"Services and ports the rule matches, or \"any\"","provider":"go.mondoo.com/cnquery/providers/panos"},"sourceAddresses":{"name":"sourceAddresses","type":"\u0019\u0007","is_mandatory":true,"title":"Source addresses the rule matches (address objects, groups, or \"any\")","provider":"go.mondoo.com/cnquery/providers/panos"},"sourceUsers":{"name":"sourceUsers","type":"\u0019\u0007","is_mandatory":true,"title":"Source users or user groups the rule matches, or \"any\"","provider":"go.mondoo.com/cnquery/providers/panos"},"sourceZones":{"name":"sourceZones","type":"\u0019\u0007","is_mandatory":true,"title":"Source zones the rule matches, or \"any\"","provider":"go.mondoo.com/cnquery/providers/panos"},"sslCertificate":{"name":"sslCertificate","type":"\u0007","is_mandatory":true,"title":"Name of the server certificate the firewall presents for","desc":"ssl-inbound-inspection decryption, empty for other decryption types","provider":"go.mondoo.com/cnquery/providers/panos"},"tags":{"name":"tags","type":"\u0019\u0007","is_mandatory":true,"title":"Administrative tags applied to this rule","provider":"go.mondoo.com/cnquery/providers/panos"},"urlCategories":{"name":"urlCategories","type":"\u0019\u0007","is_mandatory":true,"title":"URL categories the rule matches, or \"any\"","provider":"go.mondoo.com/cnquery/providers/panos"},"uuid":{"name":"uuid","type":"\u0007","is_mandatory":true,"title":"Rule UUID, a stable identifier PAN-OS 9.0+ assigns to each rule","provider":"go.mondoo.com/cnquery/providers/panos"}},"title":"PAN-OS decryption policy rule","desc":"A single rule in the decryption rulebase deciding which TLS/SSL and SSH sessions the firewall decrypts for inspection. `action` is one of decrypt, no-decrypt, or decrypt-and-forward (decrypt-and-forward requires PAN-OS 8.1+); `decryptionType` selects the method (ssl-forward-proxy, ssl-inbound-inspection, or ssh-proxy) and pairs with the certificate in sslCertificate and the profile in decryptionProfile. Matching narrows on source and destination zones, addresses, users, services, and URL categories. Rules are evaluated top-down and the first match wins, so order matters. Useful for auditing decryption coverage and finding no-decrypt exceptions, for example `panos.decryptionRules.where(action == \"no-decrypt\")`. Selected by `name`.","defaults":"name action decryptionType disabled","provider":"go.mondoo.com/cnquery/providers/panos"},"panos.device":{"id":"panos.device","fields":{"authenticationProfile":{"name":"authenticationProfile","type":"\u001bpanos.device.authenticationProfile","title":"PAN-OS authentication profile","desc":"A profile binding an authentication backend to account-lockout and multi-factor settings for administrator and end-user logins. The `type` field selects the backend and, for the external backends (radius, ldap, kerberos, tacacs-plus, saml), `serverProfile` names the server-connection profile that backend uses. Central to auditing account-lockout thresholds and MFA enforcement on the management plane. Select one by name, for example `panos.device.authenticationProfile(\"admin-mfa\")`.","provider":"go.mondoo.com/cnquery/providers/panos","is_implicit_resource":true},"generalSettings":{"name":"generalSettings","type":"\u001bpanos.device.generalSettings","title":"PAN-OS general device settings","desc":"Management-plane configuration of the firewall: hostname and management interface addressing, DNS and NTP servers (including per-server NTP authentication type), the content update server and whether its identity certificate is verified, the login banner, and the primary and secondary Panorama servers the device reports to. Useful for asserting hardening baselines such as NTP authentication being enabled, update-server identity verification, and presence of a login banner.","provider":"go.mondoo.com/cnquery/providers/panos","is_implicit_resource":true},"kerberosProfile":{"name":"kerberosProfile","type":"\u001bpanos.device.kerberosProfile","title":"PAN-OS Kerberos server profile","desc":"A Kerberos authentication profile referenced by authentication profiles. Available in PAN-OS 7.0+. Only the profile name is exposed here; use it to enumerate which Kerberos profiles exist and which authentication profiles bind to them. Select one by name, for example `panos.device.kerberosProfile(\"kdc-corp\")`.","provider":"go.mondoo.com/cnquery/providers/panos","is_implicit_resource":true},"ldapProfile":{"name":"ldapProfile","type":"\u001bpanos.device.ldapProfile","title":"PAN-OS LDAP server profile","desc":"An LDAP directory connection profile referenced by authentication profiles. The `ssl` and `verifyServerCertificate` flags reveal whether the directory connection is encrypted and its certificate validated, making this central to auditing that directory authentication is not carried in plaintext or vulnerable to man-in-the-middle. Available in PAN-OS 7.0+. Select one by name, for example `panos.device.ldapProfile(\"corp-ad\")`.","provider":"go.mondoo.com/cnquery/providers/panos","is_implicit_resource":true},"localUser":{"name":"localUser","type":"\u001bpanos.device.localUser","title":"PAN-OS local user database user","desc":"A user account defined in the device's built-in local authentication database, with its enabled/disabled state. Useful for surfacing active local accounts, for example `panos.localUsers.where(disabled == false)`.","provider":"go.mondoo.com/cnquery/providers/panos","is_implicit_resource":true},"localUserGroup":{"name":"localUserGroup","type":"\u001bpanos.device.localUserGroup","title":"PAN-OS local user database group","desc":"A group defined in the device's local authentication database and the usernames that belong to it, used to reference sets of local users in policy.","provider":"go.mondoo.com/cnquery/providers/panos","is_implicit_resource":true},"radiusProfile":{"name":"radiusProfile","type":"\u001bpanos.device.radiusProfile","title":"PAN-OS RADIUS server profile","desc":"A RADIUS connection profile referenced by authentication profiles, with its response timeout and failover-retry behavior. Available in PAN-OS 7.0+. Select one by name, for example `panos.device.radiusProfile(\"radius-corp\")`.","provider":"go.mondoo.com/cnquery/providers/panos","is_implicit_resource":true},"samlProfile":{"name":"samlProfile","type":"\u001bpanos.device.samlProfile","title":"PAN-OS SAML identity provider profile","desc":"A SAML identity-provider profile used for administrator and end-user single sign-on. Exposes the IdP entity ID, the SSO and SLO endpoints and their HTTP bindings, and the security flags that control validating the IdP certificate and signing outbound SAML messages. Central to auditing that certificate validation and request signing are enabled so assertions cannot be forged. Available in PAN-OS 8.0+. Select one by name, for example `panos.device.samlProfile(\"okta\")`.","provider":"go.mondoo.com/cnquery/providers/panos","is_implicit_resource":true},"sslDecrypt":{"name":"sslDecrypt","type":"\u001bpanos.device.sslDecrypt","title":"PAN-OS SSL forward-proxy decryption certificates","desc":"Device-wide certificate settings supporting SSL forward-proxy decryption: the forward-trust certificates (RSA and ECDSA) the firewall uses to re-sign sessions to servers it trusts, the forward-untrust certificates (RSA and ECDSA) presented for sessions to servers with untrusted certificates, the trusted root CA list the firewall recognizes, and any root CAs excluded from decryption. Useful for confirming both a trust and an untrust certificate are configured so users see an untrusted-site warning rather than a firewall-signed valid certificate.","provider":"go.mondoo.com/cnquery/providers/panos","is_implicit_resource":true},"sslTlsProfile":{"name":"sslTlsProfile","type":"\u001bpanos.device.sslTlsProfile","title":"PAN-OS SSL/TLS service profile","desc":"A profile constraining the TLS parameters device services offer, applied to the management web interface, GlobalProtect portals and gateways, the captive/authentication portal, and URL admin override. It pins the certificate presented, the minimum and maximum TLS versions, and the permitted key-exchange, encryption, and authentication (HMAC) algorithms. Each `allow*` flag toggles one algorithm, so audits can flag profiles that still permit weak options such as `minVersion` below tls1-2, `allowAlgorithmRc4`, or `allowAlgorithm3des`. Selected by `name`.","provider":"go.mondoo.com/cnquery/providers/panos","is_implicit_resource":true},"syslogProfile":{"name":"syslogProfile","type":"\u001bpanos.device.syslogProfile","title":"PAN-OS syslog server profile","desc":"A named profile grouping one or more syslog servers that logs are forwarded to. Referenced by log-forwarding settings across the device (traffic, threat, system, and other log types). Useful for confirming logs are exported off-box and, via the servers, that a secure transport is used. Selected by `name`.","provider":"go.mondoo.com/cnquery/providers/panos","is_implicit_resource":true},"syslogServer":{"name":"syslogServer","type":"\u001bpanos.device.syslogServer","title":"PAN-OS syslog server destination","desc":"A single syslog destination within a profile, with its address, transport, port, message format, and facility. Check `transport` to confirm encrypted delivery (SSL) rather than plaintext UDP or TCP.","provider":"go.mondoo.com/cnquery/providers/panos","is_implicit_resource":true},"tacacsPlusProfile":{"name":"tacacsPlusProfile","type":"\u001bpanos.device.tacacsPlusProfile","title":"PAN-OS TACACS+ server profile","desc":"A TACACS+ connection profile referenced by authentication profiles, with its response timeout and connection-reuse setting. Available in PAN-OS 7.0+. Select one by name, for example `panos.device.tacacsPlusProfile(\"tacacs-corp\")`.","provider":"go.mondoo.com/cnquery/providers/panos","is_implicit_resource":true},"telemetry":{"name":"telemetry","type":"\u001bpanos.device.telemetry","title":"PAN-OS telemetry settings","desc":"Categories of device, threat, and usage data shared with Palo Alto Networks for the Telemetry program, each an independent on/off toggle. Useful for verifying an organization's data-sharing policy is applied consistently, for example asserting that all sharing toggles are false where telemetry is prohibited.","provider":"go.mondoo.com/cnquery/providers/panos","is_implicit_resource":true}},"is_extension":true},"panos.device.authenticationProfile":{"id":"panos.device.authenticationProfile","name":"panos.device.authenticationProfile","fields":{"allowList":{"name":"allowList","type":"\u0019\u0007","is_mandatory":true,"title":"Users or user groups permitted to authenticate with this profile","desc":"Restricts which accounts the profile applies to. An empty list (or the special value \"all\") allows every user the backend can authenticate.","provider":"go.mondoo.com/cnquery/providers/panos"},"lockoutFailedAttempts":{"name":"lockoutFailedAttempts","type":"\u0007","is_mandatory":true,"title":"Consecutive failed login attempts before the account is locked out","desc":"Held as a string. \"0\" disables lockout (attempts are never counted); otherwise the configurable maximum is 10. Combined with lockoutTime, this drives brute-force lockout auditing.","provider":"go.mondoo.com/cnquery/providers/panos"},"lockoutTime":{"name":"lockoutTime","type":"\u0005","is_mandatory":true,"title":"Lockout duration in minutes after the failed-attempt threshold is hit","desc":"Range 0 to 60. A value of 0 locks the account until an administrator manually unlocks it, rather than auto-releasing after a delay.","provider":"go.mondoo.com/cnquery/providers/panos"},"mfaEnabled":{"name":"mfaEnabled","type":"\u0004","is_mandatory":true,"title":"Whether an additional multi-factor authentication factor is enforced","desc":"Reflects the profile's multi-factor authentication being enabled (PAN-OS 8.0+). False means the primary backend is the only check.","provider":"go.mondoo.com/cnquery/providers/panos"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Profile name","provider":"go.mondoo.com/cnquery/providers/panos"},"serverProfile":{"name":"serverProfile","type":"\u0007","is_mandatory":true,"title":"Server-connection profile name for the selected external backend","desc":"The radius, ldap, kerberos, tacacs-plus, or saml server profile this authentication profile authenticates against. Empty for the none and local-database types.","provider":"go.mondoo.com/cnquery/providers/panos"},"type":{"name":"type","type":"\u0007","is_mandatory":true,"title":"Authentication backend type","desc":"One of none, local-database, radius, ldap, kerberos, tacacs-plus, or saml. \"none\" allows login with no authentication challenge (audit finding); \"local-database\" uses the firewall's built-in user database; the rest delegate to the external server named by serverProfile.","provider":"go.mondoo.com/cnquery/providers/panos"},"userDomain":{"name":"userDomain","type":"\u0007","is_mandatory":true,"title":"Default user domain prepended or appended to logins that omit one","provider":"go.mondoo.com/cnquery/providers/panos"},"usernameModifier":{"name":"usernameModifier","type":"\u0007","is_mandatory":true,"title":"Transformation applied to the entered username before authentication","desc":"Controls domain/username handling. Values are the PAN-OS macros %USERINPUT% (send the name as typed), %USERINPUT%@%USERDOMAIN% (append the domain as a UPN suffix), or %USERDOMAIN%\\%USERINPUT% (prepend the domain, down-level style).","provider":"go.mondoo.com/cnquery/providers/panos"}},"title":"PAN-OS authentication profile","desc":"A profile binding an authentication backend to account-lockout and multi-factor settings for administrator and end-user logins. The `type` field selects the backend and, for the external backends (radius, ldap, kerberos, tacacs-plus, saml), `serverProfile` names the server-connection profile that backend uses. Central to auditing account-lockout thresholds and MFA enforcement on the management plane. Select one by name, for example `panos.device.authenticationProfile(\"admin-mfa\")`.","defaults":"name type","provider":"go.mondoo.com/cnquery/providers/panos"},"panos.device.generalSettings":{"id":"panos.device.generalSettings","name":"panos.device.generalSettings","fields":{"dnsPrimary":{"name":"dnsPrimary","type":"\u0007","is_mandatory":true,"title":"Primary DNS server address","provider":"go.mondoo.com/cnquery/providers/panos"},"dnsSecondary":{"name":"dnsSecondary","type":"\u0007","is_mandatory":true,"title":"Secondary DNS server address","provider":"go.mondoo.com/cnquery/providers/panos"},"domain":{"name":"domain","type":"\u0007","is_mandatory":true,"title":"DNS domain name appended to unqualified hostnames","provider":"go.mondoo.com/cnquery/providers/panos"},"gateway":{"name":"gateway","type":"\u0007","is_mandatory":true,"title":"Default gateway for the management interface","provider":"go.mondoo.com/cnquery/providers/panos"},"hostname":{"name":"hostname","type":"\u0007","is_mandatory":true,"title":"Device hostname","provider":"go.mondoo.com/cnquery/providers/panos"},"ipAddress":{"name":"ipAddress","type":"\u0007","is_mandatory":true,"title":"Management interface IPv4 address","provider":"go.mondoo.com/cnquery/providers/panos"},"loginBanner":{"name":"loginBanner","type":"\u0007","is_mandatory":true,"title":"Login banner text shown before authentication, empty when unset","provider":"go.mondoo.com/cnquery/providers/panos"},"netmask":{"name":"netmask","type":"\u0007","is_mandatory":true,"title":"Management interface netmask","provider":"go.mondoo.com/cnquery/providers/panos"},"ntpPrimaryAddress":{"name":"ntpPrimaryAddress","type":"\u0007","is_mandatory":true,"title":"Primary NTP server address, empty when no NTP server is configured","provider":"go.mondoo.com/cnquery/providers/panos"},"ntpPrimaryAuthType":{"name":"ntpPrimaryAuthType","type":"\u0007","is_mandatory":true,"title":"Primary NTP authentication type","desc":"One of none (no authentication), autokey (public-key autokey), or symmetric-key (shared symmetric key). Anything other than none means the primary NTP exchange is authenticated.","provider":"go.mondoo.com/cnquery/providers/panos"},"ntpSecondaryAddress":{"name":"ntpSecondaryAddress","type":"\u0007","is_mandatory":true,"title":"Secondary NTP server address, empty when no secondary is configured","provider":"go.mondoo.com/cnquery/providers/panos"},"ntpSecondaryAuthType":{"name":"ntpSecondaryAuthType","type":"\u0007","is_mandatory":true,"title":"Secondary NTP authentication type","desc":"One of none, autokey, or symmetric-key, with the same meaning as ntpPrimaryAuthType.","provider":"go.mondoo.com/cnquery/providers/panos"},"panoramaPrimary":{"name":"panoramaPrimary","type":"\u0007","is_mandatory":true,"title":"Primary Panorama management server address the device connects to,","desc":"empty when the device is not Panorama-managed","provider":"go.mondoo.com/cnquery/providers/panos"},"panoramaSecondary":{"name":"panoramaSecondary","type":"\u0007","is_mandatory":true,"title":"Secondary Panorama management server address for failover","provider":"go.mondoo.com/cnquery/providers/panos"},"timezone":{"name":"timezone","type":"\u0007","is_mandatory":true,"title":"Device timezone (for example \"US/Pacific\" or \"UTC\")","provider":"go.mondoo.com/cnquery/providers/panos"},"updateServer":{"name":"updateServer","type":"\u0007","is_mandatory":true,"title":"Content update server hostname, defaults to","desc":"updates.paloaltonetworks.com","provider":"go.mondoo.com/cnquery/providers/panos"},"verifyUpdateServer":{"name":"verifyUpdateServer","type":"\u0004","is_mandatory":true,"title":"Whether the device verifies the update server's identity certificate","desc":"when downloading content and software updates","provider":"go.mondoo.com/cnquery/providers/panos"}},"title":"PAN-OS general device settings","desc":"Management-plane configuration of the firewall: hostname and management interface addressing, DNS and NTP servers (including per-server NTP authentication type), the content update server and whether its identity certificate is verified, the login banner, and the primary and secondary Panorama servers the device reports to. Useful for asserting hardening baselines such as NTP authentication being enabled, update-server identity verification, and presence of a login banner.","defaults":"hostname timezone","provider":"go.mondoo.com/cnquery/providers/panos"},"panos.device.kerberosProfile":{"id":"panos.device.kerberosProfile","name":"panos.device.kerberosProfile","fields":{"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Profile name","provider":"go.mondoo.com/cnquery/providers/panos"}},"title":"PAN-OS Kerberos server profile","desc":"A Kerberos authentication profile referenced by authentication profiles. Available in PAN-OS 7.0+. Only the profile name is exposed here; use it to enumerate which Kerberos profiles exist and which authentication profiles bind to them. Select one by name, for example `panos.device.kerberosProfile(\"kdc-corp\")`.","defaults":"name","provider":"go.mondoo.com/cnquery/providers/panos"},"panos.device.ldapProfile":{"id":"panos.device.ldapProfile","name":"panos.device.ldapProfile","fields":{"baseDn":{"name":"baseDn","type":"\u0007","is_mandatory":true,"title":"Base distinguished name that scopes directory searches","provider":"go.mondoo.com/cnquery/providers/panos"},"bindDn":{"name":"bindDn","type":"\u0007","is_mandatory":true,"title":"Bind distinguished name used to authenticate the firewall to the directory","provider":"go.mondoo.com/cnquery/providers/panos"},"bindTimeout":{"name":"bindTimeout","type":"\u0005","is_mandatory":true,"title":"Seconds to wait for the initial bind before failing","provider":"go.mondoo.com/cnquery/providers/panos"},"disabled":{"name":"disabled","type":"\u0004","is_mandatory":true,"title":"Whether the profile is disabled and unavailable for authentication","provider":"go.mondoo.com/cnquery/providers/panos"},"ldapType":{"name":"ldapType","type":"\u0007","is_mandatory":true,"title":"Directory server type","desc":"One of active-directory, e-directory (Novell/NetIQ), sun (Sun/Oracle Directory Server), or other. Determines the default attribute schema PAN-OS uses when querying users and groups.","provider":"go.mondoo.com/cnquery/providers/panos"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Profile name","provider":"go.mondoo.com/cnquery/providers/panos"},"retryInterval":{"name":"retryInterval","type":"\u0005","is_mandatory":true,"title":"Seconds between attempts to reconnect to an unreachable LDAP server","provider":"go.mondoo.com/cnquery/providers/panos"},"searchTimeout":{"name":"searchTimeout","type":"\u0005","is_mandatory":true,"title":"Seconds to wait for a directory search to return before failing","provider":"go.mondoo.com/cnquery/providers/panos"},"ssl":{"name":"ssl","type":"\u0004","is_mandatory":true,"title":"Whether SSL/TLS secures the LDAP connection (LDAPS or StartTLS)","provider":"go.mondoo.com/cnquery/providers/panos"},"verifyServerCertificate":{"name":"verifyServerCertificate","type":"\u0004","is_mandatory":true,"title":"Whether the LDAP server's certificate is validated during the TLS handshake","desc":"Only meaningful when ssl is true. When false, an encrypted connection is still trusted without verifying the server identity, leaving it open to man-in-the-middle attacks.","provider":"go.mondoo.com/cnquery/providers/panos"}},"title":"PAN-OS LDAP server profile","desc":"An LDAP directory connection profile referenced by authentication profiles. The `ssl` and `verifyServerCertificate` flags reveal whether the directory connection is encrypted and its certificate validated, making this central to auditing that directory authentication is not carried in plaintext or vulnerable to man-in-the-middle. Available in PAN-OS 7.0+. Select one by name, for example `panos.device.ldapProfile(\"corp-ad\")`.","defaults":"name ldapType ssl","provider":"go.mondoo.com/cnquery/providers/panos"},"panos.device.localUser":{"id":"panos.device.localUser","name":"panos.device.localUser","fields":{"disabled":{"name":"disabled","type":"\u0004","is_mandatory":true,"title":"Whether the user account is disabled and cannot authenticate","provider":"go.mondoo.com/cnquery/providers/panos"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Username","provider":"go.mondoo.com/cnquery/providers/panos"}},"title":"PAN-OS local user database user","desc":"A user account defined in the device's built-in local authentication database, with its enabled/disabled state. Useful for surfacing active local accounts, for example `panos.localUsers.where(disabled == false)`.","defaults":"name disabled","provider":"go.mondoo.com/cnquery/providers/panos"},"panos.device.localUserGroup":{"id":"panos.device.localUserGroup","name":"panos.device.localUserGroup","fields":{"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Group name","provider":"go.mondoo.com/cnquery/providers/panos"},"users":{"name":"users","type":"\u0019\u0007","is_mandatory":true,"title":"Usernames that are members of this group","provider":"go.mondoo.com/cnquery/providers/panos"}},"title":"PAN-OS local user database group","desc":"A group defined in the device's local authentication database and the usernames that belong to it, used to reference sets of local users in policy.","defaults":"name","provider":"go.mondoo.com/cnquery/providers/panos"},"panos.device.radiusProfile":{"id":"panos.device.radiusProfile","name":"panos.device.radiusProfile","fields":{"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Profile name","provider":"go.mondoo.com/cnquery/providers/panos"},"retries":{"name":"retries","type":"\u0005","is_mandatory":true,"title":"Number of retries before the profile fails over to the next server","provider":"go.mondoo.com/cnquery/providers/panos"},"timeout":{"name":"timeout","type":"\u0005","is_mandatory":true,"title":"Seconds to wait for a RADIUS server response before retrying","provider":"go.mondoo.com/cnquery/providers/panos"}},"title":"PAN-OS RADIUS server profile","desc":"A RADIUS connection profile referenced by authentication profiles, with its response timeout and failover-retry behavior. Available in PAN-OS 7.0+. Select one by name, for example `panos.device.radiusProfile(\"radius-corp\")`.","defaults":"name","provider":"go.mondoo.com/cnquery/providers/panos"},"panos.device.samlProfile":{"id":"panos.device.samlProfile","name":"panos.device.samlProfile","fields":{"identityProviderCertificate":{"name":"identityProviderCertificate","type":"\u0007","is_mandatory":true,"title":"Identity provider signing certificate used to validate SAML assertions","provider":"go.mondoo.com/cnquery/providers/panos"},"identityProviderId":{"name":"identityProviderId","type":"\u0007","is_mandatory":true,"title":"Identity provider entity ID (SAML issuer)","provider":"go.mondoo.com/cnquery/providers/panos"},"maxClockSkew":{"name":"maxClockSkew","type":"\u0005","is_mandatory":true,"title":"Maximum tolerated clock skew in seconds between the firewall and the IdP","desc":"Assertions whose timestamps fall outside this window are rejected.","provider":"go.mondoo.com/cnquery/providers/panos"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Profile name","provider":"go.mondoo.com/cnquery/providers/panos"},"signSamlMessage":{"name":"signSamlMessage","type":"\u0004","is_mandatory":true,"title":"Whether the firewall signs outbound SAML request messages","provider":"go.mondoo.com/cnquery/providers/panos"},"sloBinding":{"name":"sloBinding","type":"\u0007","is_mandatory":true,"title":"HTTP binding for the SLO request","desc":"Either post (HTTP-POST) or redirect (HTTP-Redirect).","provider":"go.mondoo.com/cnquery/providers/panos"},"sloUrl":{"name":"sloUrl","type":"\u0007","is_mandatory":true,"title":"Single logout (SLO) URL at the identity provider","provider":"go.mondoo.com/cnquery/providers/panos"},"ssoBinding":{"name":"ssoBinding","type":"\u0007","is_mandatory":true,"title":"HTTP binding for the SSO request","desc":"Either post (HTTP-POST) or redirect (HTTP-Redirect).","provider":"go.mondoo.com/cnquery/providers/panos"},"ssoUrl":{"name":"ssoUrl","type":"\u0007","is_mandatory":true,"title":"Single sign-on (SSO) URL at the identity provider","provider":"go.mondoo.com/cnquery/providers/panos"},"validateIdentityProviderCertificate":{"name":"validateIdentityProviderCertificate","type":"\u0004","is_mandatory":true,"title":"Whether the IdP certificate is validated on inbound SAML messages","desc":"When false, assertions are accepted without verifying the IdP's signing certificate, allowing forged responses (audit finding).","provider":"go.mondoo.com/cnquery/providers/panos"}},"title":"PAN-OS SAML identity provider profile","desc":"A SAML identity-provider profile used for administrator and end-user single sign-on. Exposes the IdP entity ID, the SSO and SLO endpoints and their HTTP bindings, and the security flags that control validating the IdP certificate and signing outbound SAML messages. Central to auditing that certificate validation and request signing are enabled so assertions cannot be forged. Available in PAN-OS 8.0+. Select one by name, for example `panos.device.samlProfile(\"okta\")`.","defaults":"name identityProviderId","provider":"go.mondoo.com/cnquery/providers/panos"},"panos.device.sslDecrypt":{"id":"panos.device.sslDecrypt","name":"panos.device.sslDecrypt","fields":{"forwardTrustCertificateEcdsa":{"name":"forwardTrustCertificateEcdsa","type":"\u0007","is_mandatory":true,"title":"Name of the ECDSA certificate used as the forward-trust CA","provider":"go.mondoo.com/cnquery/providers/panos"},"forwardTrustCertificateRsa":{"name":"forwardTrustCertificateRsa","type":"\u0007","is_mandatory":true,"title":"Name of the RSA certificate used as the forward-trust CA for servers","desc":"with certificates the firewall trusts","provider":"go.mondoo.com/cnquery/providers/panos"},"forwardUntrustCertificateEcdsa":{"name":"forwardUntrustCertificateEcdsa","type":"\u0007","is_mandatory":true,"title":"Name of the ECDSA certificate presented as the forward-untrust CA","provider":"go.mondoo.com/cnquery/providers/panos"},"forwardUntrustCertificateRsa":{"name":"forwardUntrustCertificateRsa","type":"\u0007","is_mandatory":true,"title":"Name of the RSA certificate presented as the forward-untrust CA for","desc":"servers with untrusted certificates","provider":"go.mondoo.com/cnquery/providers/panos"},"rootCaExcludes":{"name":"rootCaExcludes","type":"\u0019\u0007","is_mandatory":true,"title":"Server certificates excluded from decryption, so matching sessions","desc":"pass through encrypted","provider":"go.mondoo.com/cnquery/providers/panos"},"trustedRootCas":{"name":"trustedRootCas","type":"\u0019\u0007","is_mandatory":true,"title":"Trusted root CA certificates the firewall recognizes when validating","desc":"decrypted server certificates","provider":"go.mondoo.com/cnquery/providers/panos"}},"title":"PAN-OS SSL forward-proxy decryption certificates","desc":"Device-wide certificate settings supporting SSL forward-proxy decryption: the forward-trust certificates (RSA and ECDSA) the firewall uses to re-sign sessions to servers it trusts, the forward-untrust certificates (RSA and ECDSA) presented for sessions to servers with untrusted certificates, the trusted root CA list the firewall recognizes, and any root CAs excluded from decryption. Useful for confirming both a trust and an untrust certificate are configured so users see an untrusted-site warning rather than a firewall-signed valid certificate.","defaults":"forwardTrustCertificateRsa","provider":"go.mondoo.com/cnquery/providers/panos"},"panos.device.sslTlsProfile":{"id":"panos.device.sslTlsProfile","name":"panos.device.sslTlsProfile","fields":{"allowAlgorithm3des":{"name":"allowAlgorithm3des","type":"\u0004","is_mandatory":true,"title":"Whether 3DES encryption is allowed (weak, avoid)","provider":"go.mondoo.com/cnquery/providers/panos"},"allowAlgorithmAes128Cbc":{"name":"allowAlgorithmAes128Cbc","type":"\u0004","is_mandatory":true,"title":"Whether AES-128-CBC encryption is allowed","provider":"go.mondoo.com/cnquery/providers/panos"},"allowAlgorithmAes128Gcm":{"name":"allowAlgorithmAes128Gcm","type":"\u0004","is_mandatory":true,"title":"Whether AES-128-GCM encryption is allowed","provider":"go.mondoo.com/cnquery/providers/panos"},"allowAlgorithmAes256Cbc":{"name":"allowAlgorithmAes256Cbc","type":"\u0004","is_mandatory":true,"title":"Whether AES-256-CBC encryption is allowed","provider":"go.mondoo.com/cnquery/providers/panos"},"allowAlgorithmAes256Gcm":{"name":"allowAlgorithmAes256Gcm","type":"\u0004","is_mandatory":true,"title":"Whether AES-256-GCM encryption is allowed","provider":"go.mondoo.com/cnquery/providers/panos"},"allowAlgorithmDhe":{"name":"allowAlgorithmDhe","type":"\u0004","is_mandatory":true,"title":"Whether DHE (ephemeral Diffie-Hellman) key exchange is allowed","provider":"go.mondoo.com/cnquery/providers/panos"},"allowAlgorithmEcdhe":{"name":"allowAlgorithmEcdhe","type":"\u0004","is_mandatory":true,"title":"Whether ECDHE (elliptic-curve ephemeral Diffie-Hellman) key exchange","desc":"is allowed","provider":"go.mondoo.com/cnquery/providers/panos"},"allowAlgorithmRc4":{"name":"allowAlgorithmRc4","type":"\u0004","is_mandatory":true,"title":"Whether RC4 encryption is allowed (weak, avoid)","provider":"go.mondoo.com/cnquery/providers/panos"},"allowAlgorithmRsa":{"name":"allowAlgorithmRsa","type":"\u0004","is_mandatory":true,"title":"Whether RSA key exchange is allowed","provider":"go.mondoo.com/cnquery/providers/panos"},"allowAuthenticationSha1":{"name":"allowAuthenticationSha1","type":"\u0004","is_mandatory":true,"title":"Whether SHA1 HMAC authentication is allowed (weak, avoid)","provider":"go.mondoo.com/cnquery/providers/panos"},"allowAuthenticationSha256":{"name":"allowAuthenticationSha256","type":"\u0004","is_mandatory":true,"title":"Whether SHA256 HMAC authentication is allowed","provider":"go.mondoo.com/cnquery/providers/panos"},"allowAuthenticationSha384":{"name":"allowAuthenticationSha384","type":"\u0004","is_mandatory":true,"title":"Whether SHA384 HMAC authentication is allowed","provider":"go.mondoo.com/cnquery/providers/panos"},"certificate":{"name":"certificate","type":"\u0007","is_mandatory":true,"title":"Name of the certificate presented by services using this profile","provider":"go.mondoo.com/cnquery/providers/panos"},"maxVersion":{"name":"maxVersion","type":"\u0007","is_mandatory":true,"title":"Maximum TLS version accepted","desc":"One of tls1-0, tls1-1, tls1-2, tls1-3, or \"max\" (no upper bound, negotiate the highest version both sides support).","provider":"go.mondoo.com/cnquery/providers/panos"},"minVersion":{"name":"minVersion","type":"\u0007","is_mandatory":true,"title":"Minimum TLS version accepted","desc":"One of tls1-0, tls1-1, tls1-2, or tls1-3. tls1-3 is supported only for management access and GlobalProtect portals/gateways.","provider":"go.mondoo.com/cnquery/providers/panos"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Profile name","provider":"go.mondoo.com/cnquery/providers/panos"}},"title":"PAN-OS SSL/TLS service profile","desc":"A profile constraining the TLS parameters device services offer, applied to the management web interface, GlobalProtect portals and gateways, the captive/authentication portal, and URL admin override. It pins the certificate presented, the minimum and maximum TLS versions, and the permitted key-exchange, encryption, and authentication (HMAC) algorithms. Each `allow*` flag toggles one algorithm, so audits can flag profiles that still permit weak options such as `minVersion` below tls1-2, `allowAlgorithmRc4`, or `allowAlgorithm3des`. Selected by `name`.","defaults":"name minVersion maxVersion","provider":"go.mondoo.com/cnquery/providers/panos"},"panos.device.syslogProfile":{"id":"panos.device.syslogProfile","name":"panos.device.syslogProfile","fields":{"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Profile name","provider":"go.mondoo.com/cnquery/providers/panos"},"servers":{"name":"servers","type":"\u0019\u001bpanos.device.syslogServer","is_mandatory":true,"title":"Syslog server destinations configured in this profile","provider":"go.mondoo.com/cnquery/providers/panos"}},"title":"PAN-OS syslog server profile","desc":"A named profile grouping one or more syslog servers that logs are forwarded to. Referenced by log-forwarding settings across the device (traffic, threat, system, and other log types). Useful for confirming logs are exported off-box and, via the servers, that a secure transport is used. Selected by `name`.","defaults":"name","provider":"go.mondoo.com/cnquery/providers/panos"},"panos.device.syslogServer":{"id":"panos.device.syslogServer","name":"panos.device.syslogServer","fields":{"facility":{"name":"facility","type":"\u0007","is_mandatory":true,"title":"Syslog facility","desc":"One of LOG_USER or LOG_LOCAL0 through LOG_LOCAL7, tagging forwarded messages so the receiver can categorize them.","provider":"go.mondoo.com/cnquery/providers/panos"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Server entry name","provider":"go.mondoo.com/cnquery/providers/panos"},"port":{"name":"port","type":"\u0005","is_mandatory":true,"title":"Destination port","provider":"go.mondoo.com/cnquery/providers/panos"},"profile":{"name":"profile","type":"\u0007","is_mandatory":true,"title":"Name of the syslog profile this server belongs to","provider":"go.mondoo.com/cnquery/providers/panos"},"server":{"name":"server","type":"\u0007","is_mandatory":true,"title":"Server IP address or hostname","provider":"go.mondoo.com/cnquery/providers/panos"},"syslogFormat":{"name":"syslogFormat","type":"\u0007","is_mandatory":true,"title":"Syslog message format, one of BSD (RFC 3164) or IETF (RFC 5424)","provider":"go.mondoo.com/cnquery/providers/panos"},"transport":{"name":"transport","type":"\u0007","is_mandatory":true,"title":"Transport protocol, one of UDP, TCP, or SSL (SSL encrypts delivery)","provider":"go.mondoo.com/cnquery/providers/panos"}},"title":"PAN-OS syslog server destination","desc":"A single syslog destination within a profile, with its address, transport, port, message format, and facility. Check `transport` to confirm encrypted delivery (SSL) rather than plaintext UDP or TCP.","defaults":"name server transport","provider":"go.mondoo.com/cnquery/providers/panos"},"panos.device.tacacsPlusProfile":{"id":"panos.device.tacacsPlusProfile","name":"panos.device.tacacsPlusProfile","fields":{"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Profile name","provider":"go.mondoo.com/cnquery/providers/panos"},"timeout":{"name":"timeout","type":"\u0005","is_mandatory":true,"title":"Seconds to wait for a TACACS+ server response before failing","provider":"go.mondoo.com/cnquery/providers/panos"},"useSingleConnection":{"name":"useSingleConnection","type":"\u0004","is_mandatory":true,"title":"Whether a single TCP connection is reused for multiple TACACS+ requests","desc":"When true, authentication, authorization, and accounting share one connection instead of opening a new one per request.","provider":"go.mondoo.com/cnquery/providers/panos"}},"title":"PAN-OS TACACS+ server profile","desc":"A TACACS+ connection profile referenced by authentication profiles, with its response timeout and connection-reuse setting. Available in PAN-OS 7.0+. Select one by name, for example `panos.device.tacacsPlusProfile(\"tacacs-corp\")`.","defaults":"name","provider":"go.mondoo.com/cnquery/providers/panos"},"panos.device.telemetry":{"id":"panos.device.telemetry","name":"panos.device.telemetry","fields":{"applicationReports":{"name":"applicationReports","type":"\u0004","is_mandatory":true,"title":"Whether application-usage reports are shared","provider":"go.mondoo.com/cnquery/providers/panos"},"fileTypeIdentificationReports":{"name":"fileTypeIdentificationReports","type":"\u0004","is_mandatory":true,"title":"Whether file-type identification reports are shared","provider":"go.mondoo.com/cnquery/providers/panos"},"passiveDnsMonitoring":{"name":"passiveDnsMonitoring","type":"\u0004","is_mandatory":true,"title":"Whether passive DNS query/response monitoring data is shared","provider":"go.mondoo.com/cnquery/providers/panos"},"productUsageStats":{"name":"productUsageStats","type":"\u0004","is_mandatory":true,"title":"Whether product-usage statistics are shared","provider":"go.mondoo.com/cnquery/providers/panos"},"threatPreventionData":{"name":"threatPreventionData","type":"\u0004","is_mandatory":true,"title":"Whether raw threat-prevention data (payloads such as malicious URLs","desc":"and IPs) is shared","provider":"go.mondoo.com/cnquery/providers/panos"},"threatPreventionPacketCaptures":{"name":"threatPreventionPacketCaptures","type":"\u0004","is_mandatory":true,"title":"Whether packet captures associated with threat-prevention events are","desc":"shared","provider":"go.mondoo.com/cnquery/providers/panos"},"threatPreventionReports":{"name":"threatPreventionReports","type":"\u0004","is_mandatory":true,"title":"Whether threat-prevention reports are shared","provider":"go.mondoo.com/cnquery/providers/panos"},"urlReports":{"name":"urlReports","type":"\u0004","is_mandatory":true,"title":"Whether URL-filtering reports are shared","provider":"go.mondoo.com/cnquery/providers/panos"}},"title":"PAN-OS telemetry settings","desc":"Categories of device, threat, and usage data shared with Palo Alto Networks for the Telemetry program, each an independent on/off toggle. Useful for verifying an organization's data-sharing policy is applied consistently, for example asserting that all sharing toggles are false where telemetry is prohibited.","defaults":"applicationReports threatPreventionReports","provider":"go.mondoo.com/cnquery/providers/panos"},"panos.ha":{"id":"panos.ha","name":"panos.ha","fields":{"backupPeerHa1IpAddress":{"name":"backupPeerHa1IpAddress","type":"\u0007","is_mandatory":true,"title":"Backup peer control-link (HA1) IP address","provider":"go.mondoo.com/cnquery/providers/panos"},"configSyncEnabled":{"name":"configSyncEnabled","type":"\u0004","is_mandatory":true,"title":"Whether configuration synchronization to the peer is enabled","provider":"go.mondoo.com/cnquery/providers/panos"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"HA description","provider":"go.mondoo.com/cnquery/providers/panos"},"deviceId":{"name":"deviceId","type":"\u0007","is_mandatory":true,"title":"Device ID for active-active mode (typically \"0\" or \"1\")","provider":"go.mondoo.com/cnquery/providers/panos"},"electionDevicePriority":{"name":"electionDevicePriority","type":"\u0007","is_mandatory":true,"title":"Device priority used in active election (lower wins)","provider":"go.mondoo.com/cnquery/providers/panos"},"electionHeartBeatBackup":{"name":"electionHeartBeatBackup","type":"\u0004","is_mandatory":true,"title":"Whether heartbeat backup is enabled for election","provider":"go.mondoo.com/cnquery/providers/panos"},"electionPreemptive":{"name":"electionPreemptive","type":"\u0004","is_mandatory":true,"title":"Whether preemptive election is enabled","desc":"When true, a recovered higher-priority peer reclaims the active role.","provider":"go.mondoo.com/cnquery/providers/panos"},"electionTimersMode":{"name":"electionTimersMode","type":"\u0007","is_mandatory":true,"title":"Election timers mode","desc":"Preset governing failover-detection timers. One of \"recommended\", \"aggressive\" (faster detection, higher flap risk), or \"advanced\" (individually tuned timers).","provider":"go.mondoo.com/cnquery/providers/panos"},"enabled":{"name":"enabled","type":"\u0004","is_mandatory":true,"title":"Whether HA is enabled","provider":"go.mondoo.com/cnquery/providers/panos"},"groupId":{"name":"groupId","type":"\u0005","is_mandatory":true,"title":"HA group ID shared by the two peers","provider":"go.mondoo.com/cnquery/providers/panos"},"ha2StateSyncEnabled":{"name":"ha2StateSyncEnabled","type":"\u0004","is_mandatory":true,"title":"Whether HA2 state synchronization is enabled","provider":"go.mondoo.com/cnquery/providers/panos"},"ha2StateSyncTransport":{"name":"ha2StateSyncTransport","type":"\u0007","is_mandatory":true,"title":"HA2 state sync transport","desc":"Transport used for session-state synchronization between peers. One of \"ethernet\" (direct link), \"ip\" (IP-routed), or \"udp\".","provider":"go.mondoo.com/cnquery/providers/panos"},"linkMonitorEnabled":{"name":"linkMonitorEnabled","type":"\u0004","is_mandatory":true,"title":"Whether link monitoring is enabled","provider":"go.mondoo.com/cnquery/providers/panos"},"linkMonitorFailureCondition":{"name":"linkMonitorFailureCondition","type":"\u0007","is_mandatory":true,"title":"Link monitor failure condition (any or all)","desc":"\"any\" fails over when any monitored link is down; \"all\" fails over only when every monitored link is down.","provider":"go.mondoo.com/cnquery/providers/panos"},"mode":{"name":"mode","type":"\u0007","is_mandatory":true,"title":"HA mode","desc":"One of \"active-passive\" or \"active-active\". Empty when HA is not configured.","provider":"go.mondoo.com/cnquery/providers/panos"},"monitorFailHoldDownTime":{"name":"monitorFailHoldDownTime","type":"\u0005","is_mandatory":true,"title":"Monitor-fail hold-down time in minutes for active-passive mode","provider":"go.mondoo.com/cnquery/providers/panos"},"passiveLinkState":{"name":"passiveLinkState","type":"\u0007","is_mandatory":true,"title":"Passive link state for active-passive mode","desc":"Behavior of the passive peer's data interfaces. One of \"auto\" (bring links up but not forwarding) or \"shutdown\" (keep links down until the peer becomes active). Applies only in active-passive mode.","provider":"go.mondoo.com/cnquery/providers/panos"},"peerHa1IpAddress":{"name":"peerHa1IpAddress","type":"\u0007","is_mandatory":true,"title":"Peer control-link (HA1) IP address","provider":"go.mondoo.com/cnquery/providers/panos"}},"title":"PAN-OS high availability configuration (firewall only)","desc":"High-availability pairing settings for the firewall: the HA mode, peer control-link (HA1) addresses, configuration and state (HA2) sync, the election settings that decide which peer is active, and link monitoring. When HA is not configured the resource is still returned with `enabled` false and empty settings, so audits can assert HA is or is not in use.","defaults":"enabled mode","provider":"go.mondoo.com/cnquery/providers/panos"},"panos.license":{"id":"panos.license","name":"panos.license","fields":{"authCode":{"name":"authCode","type":"\u0007","is_mandatory":true,"title":"Authorization code for the license","provider":"go.mondoo.com/cnquery/providers/panos"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Human-readable description of the license","provider":"go.mondoo.com/cnquery/providers/panos"},"expired":{"name":"expired","type":"\u0007","is_mandatory":true,"title":"Whether the license has expired (\"yes\" or \"no\")","provider":"go.mondoo.com/cnquery/providers/panos"},"expires":{"name":"expires","type":"\u0007","is_mandatory":true,"title":"Date the license expires","desc":"Device-formatted date string (for example \"August 31, 2025\"), or \"Never\" for perpetual licenses.","provider":"go.mondoo.com/cnquery/providers/panos"},"feature":{"name":"feature","type":"\u0007","is_mandatory":true,"title":"License feature name (e.g., \"Threat Prevention\", \"WildFire License\")","provider":"go.mondoo.com/cnquery/providers/panos"},"issued":{"name":"issued","type":"\u0007","is_mandatory":true,"title":"Date the license was issued (device-formatted string, may be empty)","provider":"go.mondoo.com/cnquery/providers/panos"},"serial":{"name":"serial","type":"\u0007","is_mandatory":true,"title":"Serial number associated with the license","provider":"go.mondoo.com/cnquery/providers/panos"}},"title":"PAN-OS license entry","desc":"A single activated subscription or capability on the device (for example Threat Prevention, WildFire, URL Filtering, GlobalProtect, or the base support license), with its issue and expiry dates and current expired flag. Filter by `feature` to check a specific subscription, or by `expired` to surface lapsed entitlements.","defaults":"feature expired expires","provider":"go.mondoo.com/cnquery/providers/panos"},"panos.nat":{"id":"panos.nat","fields":{"rule":{"name":"rule","type":"\u001bpanos.nat.rule","title":"PAN-OS NAT policy rule","desc":"A single rule in the NAT rulebase describing the source and destination address translation applied to matching traffic. The `satType` and `datType` fields distinguish the source and destination translation modes, while the `sat*` and `dat*` fields carry the translated addresses, ports, and interfaces. Order-sensitive like the security rulebase. Selected by `name`.","provider":"go.mondoo.com/cnquery/providers/panos","is_implicit_resource":true}},"is_extension":true},"panos.nat.rule":{"id":"panos.nat.rule","name":"panos.nat.rule","fields":{"datAddress":{"name":"datAddress","type":"\u0007","is_mandatory":true,"title":"Translated destination address; empty when no destination translation is configured","provider":"go.mondoo.com/cnquery/providers/panos"},"datPort":{"name":"datPort","type":"\u0005","is_mandatory":true,"title":"Translated destination port; 0 when the port is not translated","provider":"go.mondoo.com/cnquery/providers/panos"},"datType":{"name":"datType","type":"\u0007","is_mandatory":true,"title":"Destination address translation type","desc":"One of \"destination-translation\" (static one-to-one destination NAT), \"dynamic-destination-translation\" (dynamic destination NAT with a distribution method, PAN-OS 8.1+), or empty when no destination translation is configured.","provider":"go.mondoo.com/cnquery/providers/panos"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Rule description","provider":"go.mondoo.com/cnquery/providers/panos"},"destinationAddresses":{"name":"destinationAddresses","type":"\u0019\u0007","is_mandatory":true,"title":"Destination addresses the rule matches (\"any\" matches all)","provider":"go.mondoo.com/cnquery/providers/panos"},"destinationZone":{"name":"destinationZone","type":"\u0007","is_mandatory":true,"title":"Destination zone the rule matches","provider":"go.mondoo.com/cnquery/providers/panos"},"disabled":{"name":"disabled","type":"\u0004","is_mandatory":true,"title":"Whether the rule is disabled and skipped during matching","provider":"go.mondoo.com/cnquery/providers/panos"},"groupTag":{"name":"groupTag","type":"\u0007","is_mandatory":true,"title":"Group tag used to visually group rules in the rulebase (PAN-OS 9.0+)","provider":"go.mondoo.com/cnquery/providers/panos"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Rule name","provider":"go.mondoo.com/cnquery/providers/panos"},"satAddressType":{"name":"satAddressType","type":"\u0007","is_mandatory":true,"title":"Source translation address source when satType is dynamic: \"interface-address\" (use the egress interface IP) or","desc":"\"translated-address\" (use satTranslatedAddresses); \"none\" otherwise","provider":"go.mondoo.com/cnquery/providers/panos"},"satInterface":{"name":"satInterface","type":"\u0007","is_mandatory":true,"title":"Interface whose address is used for translation when satAddressType is \"interface-address\"","provider":"go.mondoo.com/cnquery/providers/panos"},"satIpAddress":{"name":"satIpAddress","type":"\u0007","is_mandatory":true,"title":"Specific IP on satInterface used for translation when the interface has multiple addresses","provider":"go.mondoo.com/cnquery/providers/panos"},"satStaticBiDirectional":{"name":"satStaticBiDirectional","type":"\u0004","is_mandatory":true,"title":"Whether \"static-ip\" source translation is bi-directional, auto-creating the reverse translation","provider":"go.mondoo.com/cnquery/providers/panos"},"satStaticTranslatedAddress":{"name":"satStaticTranslatedAddress","type":"\u0007","is_mandatory":true,"title":"Translated source address for \"static-ip\" source NAT","provider":"go.mondoo.com/cnquery/providers/panos"},"satTranslatedAddresses":{"name":"satTranslatedAddresses","type":"\u0019\u0007","is_mandatory":true,"title":"Translated source addresses used when satAddressType is \"translated-address\"","provider":"go.mondoo.com/cnquery/providers/panos"},"satType":{"name":"satType","type":"\u0007","is_mandatory":true,"title":"Source address translation type","desc":"One of \"dynamic-ip-and-port\" (PAT; many hosts share translated addresses with port overload), \"dynamic-ip\" (one-to-one dynamic IP, no port translation), \"static-ip\" (fixed one-to-one), or \"none\" (no source translation).","provider":"go.mondoo.com/cnquery/providers/panos"},"service":{"name":"service","type":"\u0007","is_mandatory":true,"title":"Service (port definition) the rule matches; \"any\" matches all ports","provider":"go.mondoo.com/cnquery/providers/panos"},"sourceAddresses":{"name":"sourceAddresses","type":"\u0019\u0007","is_mandatory":true,"title":"Source addresses the rule matches (\"any\" matches all)","provider":"go.mondoo.com/cnquery/providers/panos"},"sourceZones":{"name":"sourceZones","type":"\u0019\u0007","is_mandatory":true,"title":"Source zones the rule matches (\"any\" matches all zones)","provider":"go.mondoo.com/cnquery/providers/panos"},"tags":{"name":"tags","type":"\u0019\u0007","is_mandatory":true,"title":"Tags applied to this rule","provider":"go.mondoo.com/cnquery/providers/panos"},"toInterface":{"name":"toInterface","type":"\u0007","is_mandatory":true,"title":"Destination (egress) interface the rule matches; empty means any interface","provider":"go.mondoo.com/cnquery/providers/panos"},"type":{"name":"type","type":"\u0007","is_mandatory":true,"title":"NAT translation family: \"ipv4\" (standard IPv4 NAT), \"nat64\" (IPv6-to-IPv4), or \"nptv6\" (IPv6-to-IPv6 prefix translation)","provider":"go.mondoo.com/cnquery/providers/panos"},"uuid":{"name":"uuid","type":"\u0007","is_mandatory":true,"title":"Rule UUID, a stable identifier assigned by PAN-OS 9.0+; empty on older versions","provider":"go.mondoo.com/cnquery/providers/panos"}},"title":"PAN-OS NAT policy rule","desc":"A single rule in the NAT rulebase describing the source and destination address translation applied to matching traffic. The `satType` and `datType` fields distinguish the source and destination translation modes, while the `sat*` and `dat*` fields carry the translated addresses, ports, and interfaces. Order-sensitive like the security rulebase. Selected by `name`.","defaults":"name satType datType disabled","provider":"go.mondoo.com/cnquery/providers/panos"},"panos.network":{"id":"panos.network","fields":{"aggregateInterface":{"name":"aggregateInterface","type":"\u001bpanos.network.aggregateInterface","title":"PAN-OS aggregate interface","desc":"A link-aggregation bundle interface (for example ae1) that combines multiple physical ethernet interfaces via LACP for bandwidth and redundancy. Exposes the same configuration and runtime fields as an ethernet interface plus the LACP mode, rate, and negotiation settings. Runtime fields (status, macAddress, speed, duplex, zone, ipAddresses, ipv6Addresses) reflect live operational state. Selected by `name`.","provider":"go.mondoo.com/cnquery/providers/panos","is_implicit_resource":true},"bgp":{"name":"bgp","type":"\u001bpanos.network.bgp","title":"PAN-OS BGP configuration for a virtual router","desc":"The BGP routing configuration of a single virtual router: whether BGP is enabled, the router ID and local AS number, route-selection behavior (MED comparison, default local preference, default-route handling), route installation, graceful restart timers, and route-reflector and confederation settings. Reach it from a virtual router via its bgp field. Auditing BGP matters because a misconfigured or unauthenticated peering can leak or hijack routes; pair this with bgpPeerGroup and bgpPeer to confirm neighbors are authenticated and scoped as intended.","provider":"go.mondoo.com/cnquery/providers/panos","is_implicit_resource":true},"bgpPeer":{"name":"bgpPeer","type":"\u001bpanos.network.bgpPeer","title":"PAN-OS BGP peer","desc":"A single BGP neighbor within a peer group: its remote AS number, local and peer addresses, session timers, authentication profile, connection controls, and multiprotocol (MP-BGP) settings. The authProfile field reveals whether the TCP session is authenticated, which matters when auditing routing security: an empty authProfile means an unauthenticated peering. Selected by `name`, for example `panos.network.bgpPeerGroup.peers.where(authProfile == \"\")`.","provider":"go.mondoo.com/cnquery/providers/panos","is_implicit_resource":true},"bgpPeerGroup":{"name":"bgpPeerGroup","type":"\u001bpanos.network.bgpPeerGroup","title":"PAN-OS BGP peer group","desc":"A group of BGP peers on a virtual router that share type and next-hop policy. The type field distinguishes eBGP, iBGP, and their confederation variants, and the peers field lists the individual neighbors in the group. Selected by `name`. Use it to confirm peer groups apply the intended next-hop handling and to reach the neighbors beneath a group, for example `panos.network.virtualRouter.bgpPeerGroups.where(type == \"ebgp\")`.","provider":"go.mondoo.com/cnquery/providers/panos","is_implicit_resource":true},"dhcpInterface":{"name":"dhcpInterface","type":"\u001bpanos.network.dhcpInterface","title":"PAN-OS DHCP interface configuration","desc":"The DHCP relay configuration of a single interface, listing the IPv4 and IPv6 relay servers that DHCP requests received on the interface are forwarded to. Selected by `name` (for example \"ethernet1/1\"). Use it to verify DHCP requests are relayed only to sanctioned servers, for example `panos.network.dhcpInterfaces.where(relayIpv4Enabled)`.","provider":"go.mondoo.com/cnquery/providers/panos","is_implicit_resource":true},"ethernetInterface":{"name":"ethernetInterface","type":"\u001bpanos.network.ethernetInterface","title":"PAN-OS ethernet interface","desc":"A physical ethernet interface (for example ethernet1/1) with both its configured settings and its live operational state. Configuration covers the interface mode, static and DHCP addressing, MTU and TCP-MSS adjustment, management and NetFlow profiles, and LLDP/LACP options. Runtime fields (status, macAddress, speed, duplex, zone, ipAddresses, ipv6Addresses) come from the device's live interface state and reflect what the interface is actually doing now. Selected by `name`.","provider":"go.mondoo.com/cnquery/providers/panos","is_implicit_resource":true},"ikeGateway":{"name":"ikeGateway","type":"\u001bpanos.network.ikeGateway","title":"PAN-OS IKE gateway","desc":"An IKE (Internet Key Exchange) gateway defining how the firewall negotiates a security association with a VPN peer: the IKE version, peer addressing, authentication method (pre-shared key or certificate), local and peer identities, and the IKEv1/IKEv2 crypto profiles. Useful for auditing VPN authentication strength, for example finding gateways still using pre-shared keys or IKEv1. Selected by `name`.","provider":"go.mondoo.com/cnquery/providers/panos","is_implicit_resource":true},"ipsecTunnel":{"name":"ipsecTunnel","type":"\u001bpanos.network.ipsecTunnel","title":"PAN-OS IPsec tunnel","desc":"An IPsec tunnel binding a tunnel interface to an IKE gateway and IPsec crypto profile to carry site-to-site VPN traffic, with anti-replay and tunnel-monitoring settings. Selected by `name`.","provider":"go.mondoo.com/cnquery/providers/panos","is_implicit_resource":true},"loopbackInterface":{"name":"loopbackInterface","type":"\u001bpanos.network.loopbackInterface","title":"PAN-OS loopback interface","desc":"A logical loopback interface (for example loopback.1), often used as a stable service endpoint or router ID. Exposes its static addressing, management profile, MTU, and the live operational status, zone, and active addresses. Selected by `name`.","provider":"go.mondoo.com/cnquery/providers/panos","is_implicit_resource":true},"ospf":{"name":"ospf","type":"\u001bpanos.network.ospf","title":"PAN-OS OSPF configuration for a virtual router","desc":"The OSPFv2 routing configuration of a single virtual router: whether OSPF is enabled, the router ID, default-route handling, RFC 1583 compatibility, SPF and LSA timers, graceful-restart settings, and the global BFD profile. Reach it from a virtual router via its ospf field. Use it alongside ospfArea and ospfAreaInterface to confirm areas and adjacencies are authenticated and scoped as intended.","provider":"go.mondoo.com/cnquery/providers/panos","is_implicit_resource":true},"ospfArea":{"name":"ospfArea","type":"\u001bpanos.network.ospfArea","title":"PAN-OS OSPF area","desc":"A single OSPF area on a virtual router, identified by its area ID (for example \"0.0.0.0\" for the backbone). The type field governs how external routes and summaries are handled, and the interfaces and virtualLinks fields reach the member interfaces and any virtual links. Selected by `name`, for example `panos.network.virtualRouter.ospfAreas.where(type == \"nssa\")`.","provider":"go.mondoo.com/cnquery/providers/panos","is_implicit_resource":true},"ospfAreaInterface":{"name":"ospfAreaInterface","type":"\u001bpanos.network.ospfAreaInterface","title":"PAN-OS OSPF area interface","desc":"An interface participating in an OSPF area, with its OSPF timers, cost (metric), DR-election priority, link type, BFD profile, and authentication profile. The authProfile field reveals whether OSPF adjacencies on the interface are authenticated: an empty value means the adjacency is unauthenticated. Selected by `name`, for example `panos.network.ospfArea.interfaces.where(authProfile == \"\")`.","provider":"go.mondoo.com/cnquery/providers/panos","is_implicit_resource":true},"ospfAreaVirtualLink":{"name":"ospfAreaVirtualLink","type":"\u001bpanos.network.ospfAreaVirtualLink","title":"PAN-OS OSPF area virtual link","desc":"An OSPF virtual link that connects an area disconnected from the backbone to area 0 across a non-backbone transit area. Identified by the neighbor router ID and the transit area it traverses, and carrying the OSPF timers, BFD profile, and authentication profile for the link. Selected by `name`. The authProfile field reveals whether the virtual link is authenticated.","provider":"go.mondoo.com/cnquery/providers/panos","is_implicit_resource":true},"ospfExportRule":{"name":"ospfExportRule","type":"\u001bpanos.network.ospfExportRule","title":"PAN-OS OSPF export rule","desc":"A rule controlling how routes redistributed into OSPF are advertised as external routes: the external path type, the OSPF route tag, and the metric applied. Selected by `name`. Use it to confirm which redistributed routes leave the OSPF domain and with what external cost.","provider":"go.mondoo.com/cnquery/providers/panos","is_implicit_resource":true},"staticRoute":{"name":"staticRoute","type":"\u001bpanos.network.staticRoute","title":"PAN-OS IPv4 static route","desc":"A static IPv4 route on a virtual router, mapping a destination network to a next hop and egress interface. The next-hop type distinguishes a plain IP next hop from a blackhole (discard) or a handoff to another virtual router. Useful for reviewing default routes and blackhole entries.","provider":"go.mondoo.com/cnquery/providers/panos","is_implicit_resource":true},"tunnelInterface":{"name":"tunnelInterface","type":"\u001bpanos.network.tunnelInterface","title":"PAN-OS tunnel interface","desc":"A logical tunnel interface (for example tunnel.1) that serves as the termination point for IPsec and other tunnels. Exposes its addressing, management profile, MTU, and live operational status, zone, and active addresses. Selected by `name`.","provider":"go.mondoo.com/cnquery/providers/panos","is_implicit_resource":true},"virtualRouter":{"name":"virtualRouter","type":"\u001bpanos.network.virtualRouter","title":"PAN-OS virtual router","desc":"A layer-3 routing instance on the firewall. Holds its member interfaces, the administrative distances that rank each routing protocol, ECMP settings, and navigable sub-collections for static routes and dynamic routing (BGP and OSPF). Traverse from here to audit routing, for example `panos.virtualRouters { name staticRoutes { destination nextHop } }`. Selected by `name`.","provider":"go.mondoo.com/cnquery/providers/panos","is_implicit_resource":true},"vlanInterface":{"name":"vlanInterface","type":"\u001bpanos.network.vlanInterface","title":"PAN-OS VLAN interface","desc":"A logical VLAN interface (for example vlan.100) providing a layer-3 gateway for a VLAN. Exposes its static and DHCP addressing, management profile, MTU, and live operational status, zone, and active addresses. Selected by `name`.","provider":"go.mondoo.com/cnquery/providers/panos","is_implicit_resource":true},"zone":{"name":"zone","type":"\u001bpanos.network.zone","title":"PAN-OS network security zone","desc":"A security zone grouping one or more interfaces into a trust boundary that security, NAT, and decryption policy reference as source and destination. Exposes the member interfaces, the attached zone-protection profile, and whether User-ID, packet-buffer protection, and device identification are enabled. Useful for finding zones missing a protection profile, for example `panos.zones.where(zoneProfile == \"\")`. Selected by `name`.","provider":"go.mondoo.com/cnquery/providers/panos","is_implicit_resource":true}},"is_extension":true},"panos.network.aggregateInterface":{"id":"panos.network.aggregateInterface","name":"panos.network.aggregateInterface","fields":{"adjustTcpMss":{"name":"adjustTcpMss","type":"\u0004","is_mandatory":true,"title":"Whether to adjust TCP MSS","provider":"go.mondoo.com/cnquery/providers/panos"},"comment":{"name":"comment","type":"\u0007","is_mandatory":true,"title":"Comment/description configured for the interface","provider":"go.mondoo.com/cnquery/providers/panos"},"createDhcpDefaultRoute":{"name":"createDhcpDefaultRoute","type":"\u0004","is_mandatory":true,"title":"Whether to create a default route via DHCP","provider":"go.mondoo.com/cnquery/providers/panos"},"decryptForward":{"name":"decryptForward","type":"\u0004","is_mandatory":true,"title":"Decrypt forward","desc":"Whether the interface is enabled for decryption broker forwarding, passing decrypted sessions to a chain of security devices.","provider":"go.mondoo.com/cnquery/providers/panos"},"dhcpDefaultRouteMetric":{"name":"dhcpDefaultRouteMetric","type":"\u0005","is_mandatory":true,"title":"DHCP default route metric","provider":"go.mondoo.com/cnquery/providers/panos"},"dhcpSendHostnameEnable":{"name":"dhcpSendHostnameEnable","type":"\u0004","is_mandatory":true,"title":"DHCP hostname configuration enabled","provider":"go.mondoo.com/cnquery/providers/panos"},"dhcpSendHostnameValue":{"name":"dhcpSendHostnameValue","type":"\u0007","is_mandatory":true,"title":"DHCP hostname value","provider":"go.mondoo.com/cnquery/providers/panos"},"duplex":{"name":"duplex","type":"\u0007","is_mandatory":true,"title":"Actual operating duplex (runtime)","provider":"go.mondoo.com/cnquery/providers/panos"},"enableDhcp":{"name":"enableDhcp","type":"\u0004","is_mandatory":true,"title":"Whether DHCP is enabled","provider":"go.mondoo.com/cnquery/providers/panos"},"enableUntaggedSubinterface":{"name":"enableUntaggedSubinterface","type":"\u0004","is_mandatory":true,"title":"Enable untagged subinterface","provider":"go.mondoo.com/cnquery/providers/panos"},"ipAddresses":{"name":"ipAddresses","type":"\u0019\u000f","is_mandatory":true,"title":"Active IP addresses (runtime)","provider":"go.mondoo.com/cnquery/providers/panos"},"ipv4MssAdjust":{"name":"ipv4MssAdjust","type":"\u0005","is_mandatory":true,"title":"IPv4 MSS adjustment value in bytes","provider":"go.mondoo.com/cnquery/providers/panos"},"ipv6Addresses":{"name":"ipv6Addresses","type":"\u0019\u000f","is_mandatory":true,"title":"Active IPv6 addresses (runtime)","provider":"go.mondoo.com/cnquery/providers/panos"},"ipv6Enabled":{"name":"ipv6Enabled","type":"\u0004","is_mandatory":true,"title":"Whether IPv6 is enabled","provider":"go.mondoo.com/cnquery/providers/panos"},"ipv6InterfaceId":{"name":"ipv6InterfaceId","type":"\u0007","is_mandatory":true,"title":"IPv6 interface ID","provider":"go.mondoo.com/cnquery/providers/panos"},"ipv6MssAdjust":{"name":"ipv6MssAdjust","type":"\u0005","is_mandatory":true,"title":"IPv6 MSS adjustment value in bytes","provider":"go.mondoo.com/cnquery/providers/panos"},"lacpEnable":{"name":"lacpEnable","type":"\u0004","is_mandatory":true,"title":"LACP enabled","provider":"go.mondoo.com/cnquery/providers/panos"},"lacpHaPassivePreNegotiation":{"name":"lacpHaPassivePreNegotiation","type":"\u0004","is_mandatory":true,"title":"LACP HA passive pre-negotiation","provider":"go.mondoo.com/cnquery/providers/panos"},"lacpMode":{"name":"lacpMode","type":"\u0007","is_mandatory":true,"title":"LACP mode","desc":"One of \"active\" (actively initiate LACP negotiation) or \"passive\" (respond only to a peer's LACP packets).","provider":"go.mondoo.com/cnquery/providers/panos"},"lacpTransmissionRate":{"name":"lacpTransmissionRate","type":"\u0007","is_mandatory":true,"title":"LACP transmission rate","desc":"Rate at which LACP control packets are sent: \"fast\" (every second) or \"slow\" (every 30 seconds).","provider":"go.mondoo.com/cnquery/providers/panos"},"macAddress":{"name":"macAddress","type":"\u0007","is_mandatory":true,"title":"MAC address (runtime)","provider":"go.mondoo.com/cnquery/providers/panos"},"managementProfile":{"name":"managementProfile","type":"\u0007","is_mandatory":true,"title":"Management profile name","desc":"Name of the interface management profile controlling which management services (ping, HTTPS, SSH, SNMP) are permitted on the interface.","provider":"go.mondoo.com/cnquery/providers/panos"},"mode":{"name":"mode","type":"\u0007","is_mandatory":true,"title":"Interface mode","desc":"Deployment mode of the bundle. One of \"layer3\", \"layer2\", \"virtual-wire\", \"ha\", or \"decrypt-mirror\".","provider":"go.mondoo.com/cnquery/providers/panos"},"mtu":{"name":"mtu","type":"\u0005","is_mandatory":true,"title":"Maximum transmission unit in bytes","provider":"go.mondoo.com/cnquery/providers/panos"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Interface name (e.g., \"ae1\")","provider":"go.mondoo.com/cnquery/providers/panos"},"netflowProfile":{"name":"netflowProfile","type":"\u0007","is_mandatory":true,"title":"NetFlow profile name","provider":"go.mondoo.com/cnquery/providers/panos"},"speed":{"name":"speed","type":"\u0007","is_mandatory":true,"title":"Actual operating speed in Mbps (runtime)","provider":"go.mondoo.com/cnquery/providers/panos"},"staticIps":{"name":"staticIps","type":"\u0019\u000f","is_mandatory":true,"title":"Static IP addresses configured","provider":"go.mondoo.com/cnquery/providers/panos"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Operational status","desc":"Live link status of the bundle from the device: \"up\", \"down\", or \"unknown\" when operational data could not be read.","provider":"go.mondoo.com/cnquery/providers/panos"},"zone":{"name":"zone","type":"\u0007","is_mandatory":true,"title":"Security zone assignment (runtime)","provider":"go.mondoo.com/cnquery/providers/panos"}},"title":"PAN-OS aggregate interface","desc":"A link-aggregation bundle interface (for example ae1) that combines multiple physical ethernet interfaces via LACP for bandwidth and redundancy. Exposes the same configuration and runtime fields as an ethernet interface plus the LACP mode, rate, and negotiation settings. Runtime fields (status, macAddress, speed, duplex, zone, ipAddresses, ipv6Addresses) reflect live operational state. Selected by `name`.","defaults":"name mode status","provider":"go.mondoo.com/cnquery/providers/panos"},"panos.network.bgp":{"id":"panos.network.bgp","name":"panos.network.bgp","fields":{"aggregateMed":{"name":"aggregateMed","type":"\u0004","is_mandatory":true,"title":"Whether to aggregate the multi-exit discriminator (MED) across paths of an aggregate route","provider":"go.mondoo.com/cnquery/providers/panos"},"allowRedistributeDefaultRoute":{"name":"allowRedistributeDefaultRoute","type":"\u0004","is_mandatory":true,"title":"Whether the default route may be redistributed into BGP from other protocols","provider":"go.mondoo.com/cnquery/providers/panos"},"alwaysCompareMed":{"name":"alwaysCompareMed","type":"\u0004","is_mandatory":true,"title":"Whether to always compare the MED across routes from neighbors in different autonomous systems","provider":"go.mondoo.com/cnquery/providers/panos"},"asFormat":{"name":"asFormat","type":"\u0007","is_mandatory":true,"title":"AS number format","desc":"Format used to represent AS numbers, either \"2-byte\" or \"4-byte\".","provider":"go.mondoo.com/cnquery/providers/panos"},"asNumber":{"name":"asNumber","type":"\u0007","is_mandatory":true,"title":"Local autonomous system (AS) number of this router, as a string (supports 4-byte ASNs)","provider":"go.mondoo.com/cnquery/providers/panos"},"bfdProfile":{"name":"bfdProfile","type":"\u0007","is_mandatory":true,"title":"Global BFD profile for BGP","desc":"Name of the Bidirectional Forwarding Detection profile applied to all BGP sessions, or the literal \"None\" to disable BFD globally. Available in PAN-OS 7.1 and later.","provider":"go.mondoo.com/cnquery/providers/panos"},"confederationMemberAs":{"name":"confederationMemberAs","type":"\u0007","is_mandatory":true,"title":"Confederation member AS number","desc":"The AS number of the confederation sub-AS this router belongs to, used with the ebgp-confed and ibgp-confed peer group types. Empty when confederation is not configured.","provider":"go.mondoo.com/cnquery/providers/panos"},"defaultLocalPreference":{"name":"defaultLocalPreference","type":"\u0007","is_mandatory":true,"title":"Default local preference applied to routes, as a string (PAN-OS default is \"100\")","provider":"go.mondoo.com/cnquery/providers/panos"},"deterministicMedComparison":{"name":"deterministicMedComparison","type":"\u0004","is_mandatory":true,"title":"Whether to use deterministic MED comparison when selecting among routes from iBGP peers","provider":"go.mondoo.com/cnquery/providers/panos"},"ecmpMultiAs":{"name":"ecmpMultiAs","type":"\u0004","is_mandatory":true,"title":"Whether ECMP load balancing is allowed across routes learned from different autonomous systems (PAN-OS 7.0+)","provider":"go.mondoo.com/cnquery/providers/panos"},"enable":{"name":"enable","type":"\u0004","is_mandatory":true,"title":"Whether BGP is enabled on the virtual router","provider":"go.mondoo.com/cnquery/providers/panos"},"enableGracefulRestart":{"name":"enableGracefulRestart","type":"\u0004","is_mandatory":true,"title":"Whether BGP graceful restart is enabled, allowing forwarding to continue across a restart of the BGP control plane","provider":"go.mondoo.com/cnquery/providers/panos"},"enforceFirstAs":{"name":"enforceFirstAs","type":"\u0004","is_mandatory":true,"title":"Enforce first AS","desc":"Whether to reject inbound updates from an eBGP peer when the first AS in the AS_PATH does not match the peer's configured AS number, a protection against spoofed routing updates. Available in PAN-OS 8.0 and later.","provider":"go.mondoo.com/cnquery/providers/panos"},"installRoute":{"name":"installRoute","type":"\u0004","is_mandatory":true,"title":"Whether BGP routes are installed into the virtual router's forwarding table","provider":"go.mondoo.com/cnquery/providers/panos"},"localRestartTime":{"name":"localRestartTime","type":"\u0005","is_mandatory":true,"title":"Local restart time in seconds","desc":"How long this router advertises it will take to restart, sent to peers in the graceful-restart capability. PAN-OS default is 120 (range 1 to 3600).","provider":"go.mondoo.com/cnquery/providers/panos"},"maxPeerRestartTime":{"name":"maxPeerRestartTime","type":"\u0005","is_mandatory":true,"title":"Maximum peer restart time in seconds","desc":"Maximum restart time this router will accept from a peer's advertised restart time. PAN-OS default is 120 (range 1 to 3600).","provider":"go.mondoo.com/cnquery/providers/panos"},"reflectorClusterId":{"name":"reflectorClusterId","type":"\u0007","is_mandatory":true,"title":"Route-reflector cluster ID, as an IPv4-formatted string, set on route reflectors to prevent routing loops (empty when this router is not a reflector)","provider":"go.mondoo.com/cnquery/providers/panos"},"rejectDefaultRoute":{"name":"rejectDefaultRoute","type":"\u0004","is_mandatory":true,"title":"Whether to reject the default route (0.0.0.0/0) learned or redistributed into BGP","provider":"go.mondoo.com/cnquery/providers/panos"},"routerId":{"name":"routerId","type":"\u0007","is_mandatory":true,"title":"BGP router ID, the 32-bit identifier of this router (typically an IPv4 address such as \"10.0.0.1\")","provider":"go.mondoo.com/cnquery/providers/panos"},"staleRouteTime":{"name":"staleRouteTime","type":"\u0005","is_mandatory":true,"title":"Stale-route time in seconds","desc":"How long routes from a restarting peer are retained as stale before being removed. PAN-OS default is 120 (range 1 to 3600).","provider":"go.mondoo.com/cnquery/providers/panos"},"virtualRouter":{"name":"virtualRouter","type":"\u0007","is_mandatory":true,"title":"Name of the virtual router this BGP configuration belongs to","provider":"go.mondoo.com/cnquery/providers/panos"}},"title":"PAN-OS BGP configuration for a virtual router","desc":"The BGP routing configuration of a single virtual router: whether BGP is enabled, the router ID and local AS number, route-selection behavior (MED comparison, default local preference, default-route handling), route installation, graceful restart timers, and route-reflector and confederation settings. Reach it from a virtual router via its bgp field. Auditing BGP matters because a misconfigured or unauthenticated peering can leak or hijack routes; pair this with bgpPeerGroup and bgpPeer to confirm neighbors are authenticated and scoped as intended.","defaults":"enable routerId asNumber","provider":"go.mondoo.com/cnquery/providers/panos"},"panos.network.bgpPeer":{"id":"panos.network.bgpPeer","name":"panos.network.bgpPeer","fields":{"addressFamilyType":{"name":"addressFamilyType","type":"\u0007","is_mandatory":true,"title":"MP-BGP address family","desc":"Address family carried over the session when MP-BGP is enabled, either \"ipv4\" or \"ipv6\". Available in PAN-OS 8.0 and later.","provider":"go.mondoo.com/cnquery/providers/panos"},"allowIncomingConnections":{"name":"allowIncomingConnections","type":"\u0004","is_mandatory":true,"title":"Whether this router accepts inbound BGP connections from the peer","provider":"go.mondoo.com/cnquery/providers/panos"},"allowOutgoingConnections":{"name":"allowOutgoingConnections","type":"\u0004","is_mandatory":true,"title":"Whether this router initiates outbound BGP connections to the peer","provider":"go.mondoo.com/cnquery/providers/panos"},"authProfile":{"name":"authProfile","type":"\u0007","is_mandatory":true,"title":"Authentication profile","desc":"Name of the BGP authentication profile securing the session's TCP connection (MD5 or, on newer releases, TCP-AO). Empty means the peering is unauthenticated.","provider":"go.mondoo.com/cnquery/providers/panos"},"bfdProfile":{"name":"bfdProfile","type":"\u0007","is_mandatory":true,"title":"BFD profile for this peer","desc":"Name of the Bidirectional Forwarding Detection profile for the session, or \"Inherit-vr-global-setting\" to use the virtual router's global BGP BFD profile, or \"None\" to disable BFD on this peer. Available in PAN-OS 7.1 and later.","provider":"go.mondoo.com/cnquery/providers/panos"},"enable":{"name":"enable","type":"\u0004","is_mandatory":true,"title":"Whether the peer is enabled","provider":"go.mondoo.com/cnquery/providers/panos"},"enableMpBgp":{"name":"enableMpBgp","type":"\u0004","is_mandatory":true,"title":"Whether multiprotocol BGP (MP-BGP) is enabled for this peer (PAN-OS 8.0+)","provider":"go.mondoo.com/cnquery/providers/panos"},"enableSenderSideLoopDetection":{"name":"enableSenderSideLoopDetection","type":"\u0004","is_mandatory":true,"title":"Whether sender-side loop detection is enabled, checking the AS_PATH before advertising routes to the peer (PAN-OS 8.0+)","provider":"go.mondoo.com/cnquery/providers/panos"},"holdTime":{"name":"holdTime","type":"\u0005","is_mandatory":true,"title":"Hold time in seconds after which the peer is declared down if no keepalive or update is received (PAN-OS default is 90)","provider":"go.mondoo.com/cnquery/providers/panos"},"idleHoldTime":{"name":"idleHoldTime","type":"\u0005","is_mandatory":true,"title":"Idle hold time in seconds to wait before retrying a failed peering (PAN-OS default is 15)","provider":"go.mondoo.com/cnquery/providers/panos"},"incomingConnectionsRemotePort":{"name":"incomingConnectionsRemotePort","type":"\u0005","is_mandatory":true,"title":"Remote TCP port for accepted inbound connections (0 uses the default BGP port 179)","provider":"go.mondoo.com/cnquery/providers/panos"},"keepAliveInterval":{"name":"keepAliveInterval","type":"\u0005","is_mandatory":true,"title":"Keepalive interval in seconds (PAN-OS default is 30)","provider":"go.mondoo.com/cnquery/providers/panos"},"localAddressInterface":{"name":"localAddressInterface","type":"\u0007","is_mandatory":true,"title":"Name of the local interface used to source this BGP session (empty when an explicit local IP is used instead)","provider":"go.mondoo.com/cnquery/providers/panos"},"localAddressIp":{"name":"localAddressIp","type":"\u0007","is_mandatory":true,"title":"Local IP address used to source this BGP session","provider":"go.mondoo.com/cnquery/providers/panos"},"maxPrefixes":{"name":"maxPrefixes","type":"\u0007","is_mandatory":true,"title":"Maximum number of prefixes accepted from this peer","desc":"A numeric limit as a string, or the literal \"unlimited\" for no limit.","provider":"go.mondoo.com/cnquery/providers/panos"},"minRouteAdvertisementInterval":{"name":"minRouteAdvertisementInterval","type":"\u0005","is_mandatory":true,"title":"Minimum route advertisement interval in seconds between successive advertisements of the same route to the peer (PAN-OS 8.1+; default 30)","provider":"go.mondoo.com/cnquery/providers/panos"},"multiHop":{"name":"multiHop","type":"\u0005","is_mandatory":true,"title":"eBGP multihop TTL, the maximum number of hops allowed to the peer (0 disables multihop; used when the neighbor is not directly connected)","provider":"go.mondoo.com/cnquery/providers/panos"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Peer name","provider":"go.mondoo.com/cnquery/providers/panos"},"openDelayTime":{"name":"openDelayTime","type":"\u0005","is_mandatory":true,"title":"Open delay time in seconds, how long to wait before sending the first BGP OPEN message after the TCP session is established (PAN-OS default is 0)","provider":"go.mondoo.com/cnquery/providers/panos"},"outgoingConnectionsLocalPort":{"name":"outgoingConnectionsLocalPort","type":"\u0005","is_mandatory":true,"title":"Local TCP port for initiated outbound connections (0 uses an ephemeral or default port)","provider":"go.mondoo.com/cnquery/providers/panos"},"peerAddressIp":{"name":"peerAddressIp","type":"\u0007","is_mandatory":true,"title":"IP address of the remote BGP neighbor","provider":"go.mondoo.com/cnquery/providers/panos"},"peerAs":{"name":"peerAs","type":"\u0007","is_mandatory":true,"title":"Peer (remote) autonomous system number, as a string (supports 4-byte ASNs)","provider":"go.mondoo.com/cnquery/providers/panos"},"peerGroup":{"name":"peerGroup","type":"\u0007","is_mandatory":true,"title":"Name of the peer group this peer belongs to","provider":"go.mondoo.com/cnquery/providers/panos"},"peeringType":{"name":"peeringType","type":"\u0007","is_mandatory":true,"title":"Peering type","desc":"One of \"bilateral\" or \"unspecified\".","provider":"go.mondoo.com/cnquery/providers/panos"},"reflectorClient":{"name":"reflectorClient","type":"\u0007","is_mandatory":true,"title":"Route-reflector client role","desc":"The neighbor's role relative to a route reflector. One of \"non-client\" (a normal peer), \"client\" (a reflector client), or \"meshed-client\" (a client that is also part of a client mesh).","provider":"go.mondoo.com/cnquery/providers/panos"},"virtualRouter":{"name":"virtualRouter","type":"\u0007","is_mandatory":true,"title":"Name of the virtual router this peer belongs to","provider":"go.mondoo.com/cnquery/providers/panos"}},"init":{"args":[{"name":"name","type":"\u0007"}]},"title":"PAN-OS BGP peer","desc":"A single BGP neighbor within a peer group: its remote AS number, local and peer addresses, session timers, authentication profile, connection controls, and multiprotocol (MP-BGP) settings. The authProfile field reveals whether the TCP session is authenticated, which matters when auditing routing security: an empty authProfile means an unauthenticated peering. Selected by `name`, for example `panos.network.bgpPeerGroup.peers.where(authProfile == \"\")`.","defaults":"name peerAs peerAddressIp","provider":"go.mondoo.com/cnquery/providers/panos"},"panos.network.bgpPeerGroup":{"id":"panos.network.bgpPeerGroup","name":"panos.network.bgpPeerGroup","fields":{"aggregatedConfedAsPath":{"name":"aggregatedConfedAsPath","type":"\u0004","is_mandatory":true,"title":"Whether AS path aggregation is enabled for confederation peer groups","provider":"go.mondoo.com/cnquery/providers/panos"},"enable":{"name":"enable","type":"\u0004","is_mandatory":true,"title":"Whether the peer group is enabled","provider":"go.mondoo.com/cnquery/providers/panos"},"exportNextHop":{"name":"exportNextHop","type":"\u0007","is_mandatory":true,"title":"Export next-hop policy","desc":"How the next hop is set on routes advertised to peers in this group. One of \"original\" (keep the route's original next hop), \"use-self\" (set this router as the next hop), or \"resolve\" (valid only for eBGP export). Empty inherits the platform default.","provider":"go.mondoo.com/cnquery/providers/panos"},"importNextHop":{"name":"importNextHop","type":"\u0007","is_mandatory":true,"title":"Import next-hop policy","desc":"How the next hop is treated on routes received from peers in this group. One of \"original\" (keep the received next hop), \"use-self\", or \"use-peer\" (valid only for eBGP import). Empty inherits the platform default.","provider":"go.mondoo.com/cnquery/providers/panos"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Peer group name","provider":"go.mondoo.com/cnquery/providers/panos"},"peers":{"name":"peers","type":"\u0019\u001bpanos.network.bgpPeer","title":"Individual BGP neighbors in this peer group","provider":"go.mondoo.com/cnquery/providers/panos"},"removePrivateAs":{"name":"removePrivateAs","type":"\u0004","is_mandatory":true,"title":"Whether private AS numbers are removed from the AS_PATH of routes advertised to peers in this group","provider":"go.mondoo.com/cnquery/providers/panos"},"softResetWithStoredInfo":{"name":"softResetWithStoredInfo","type":"\u0004","is_mandatory":true,"title":"Whether inbound soft reset uses stored route information instead of requesting a full re-advertisement from the peer","provider":"go.mondoo.com/cnquery/providers/panos"},"type":{"name":"type","type":"\u0007","is_mandatory":true,"title":"Peer group type","desc":"One of \"ebgp\" (external BGP), \"ibgp\" (internal BGP), \"ebgp-confed\" (external confederation), or \"ibgp-confed\" (internal confederation).","provider":"go.mondoo.com/cnquery/providers/panos"},"virtualRouter":{"name":"virtualRouter","type":"\u0007","is_mandatory":true,"title":"Name of the virtual router this peer group belongs to","provider":"go.mondoo.com/cnquery/providers/panos"}},"init":{"args":[{"name":"name","type":"\u0007"}]},"title":"PAN-OS BGP peer group","desc":"A group of BGP peers on a virtual router that share type and next-hop policy. The type field distinguishes eBGP, iBGP, and their confederation variants, and the peers field lists the individual neighbors in the group. Selected by `name`. Use it to confirm peer groups apply the intended next-hop handling and to reach the neighbors beneath a group, for example `panos.network.virtualRouter.bgpPeerGroups.where(type == \"ebgp\")`.","defaults":"name type","provider":"go.mondoo.com/cnquery/providers/panos"},"panos.network.dhcpInterface":{"id":"panos.network.dhcpInterface","name":"panos.network.dhcpInterface","fields":{"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Interface name (e.g., \"ethernet1/1\")","provider":"go.mondoo.com/cnquery/providers/panos"},"relayIpv4Enabled":{"name":"relayIpv4Enabled","type":"\u0004","is_mandatory":true,"title":"Whether IPv4 DHCP relay is enabled on the interface","provider":"go.mondoo.com/cnquery/providers/panos"},"relayIpv4Servers":{"name":"relayIpv4Servers","type":"\u0019\u0007","is_mandatory":true,"title":"IPv4 addresses of the DHCP servers that requests received on this interface are relayed to","provider":"go.mondoo.com/cnquery/providers/panos"},"relayIpv6Enabled":{"name":"relayIpv6Enabled","type":"\u0004","is_mandatory":true,"title":"Whether IPv6 DHCP relay is enabled on the interface","provider":"go.mondoo.com/cnquery/providers/panos"},"relayIpv6Servers":{"name":"relayIpv6Servers","type":"\u0019\u0007","is_mandatory":true,"title":"IPv6 addresses of the DHCP servers that requests received on this interface are relayed to","provider":"go.mondoo.com/cnquery/providers/panos"}},"init":{"args":[{"name":"name","type":"\u0007"}]},"title":"PAN-OS DHCP interface configuration","desc":"The DHCP relay configuration of a single interface, listing the IPv4 and IPv6 relay servers that DHCP requests received on the interface are forwarded to. Selected by `name` (for example \"ethernet1/1\"). Use it to verify DHCP requests are relayed only to sanctioned servers, for example `panos.network.dhcpInterfaces.where(relayIpv4Enabled)`.","defaults":"name","provider":"go.mondoo.com/cnquery/providers/panos"},"panos.network.ethernetInterface":{"id":"panos.network.ethernetInterface","name":"panos.network.ethernetInterface","fields":{"adjustTcpMss":{"name":"adjustTcpMss","type":"\u0004","is_mandatory":true,"title":"Whether to adjust TCP MSS","provider":"go.mondoo.com/cnquery/providers/panos"},"aggregateGroup":{"name":"aggregateGroup","type":"\u0007","is_mandatory":true,"title":"Aggregate group membership (e.g., \"ae1\")","desc":"Name of the aggregate interface this ethernet port belongs to, when it is an LACP member. Empty when the interface is not part of a bundle.","provider":"go.mondoo.com/cnquery/providers/panos"},"comment":{"name":"comment","type":"\u0007","is_mandatory":true,"title":"Comment/description configured for the interface","provider":"go.mondoo.com/cnquery/providers/panos"},"createDhcpDefaultRoute":{"name":"createDhcpDefaultRoute","type":"\u0004","is_mandatory":true,"title":"Whether to create a default route via DHCP","provider":"go.mondoo.com/cnquery/providers/panos"},"decryptForward":{"name":"decryptForward","type":"\u0004","is_mandatory":true,"title":"Decrypt forward","desc":"Whether the interface is enabled for decryption broker forwarding, passing decrypted sessions to a chain of security devices.","provider":"go.mondoo.com/cnquery/providers/panos"},"dhcpDefaultRouteMetric":{"name":"dhcpDefaultRouteMetric","type":"\u0005","is_mandatory":true,"title":"DHCP default route metric","provider":"go.mondoo.com/cnquery/providers/panos"},"dhcpSendHostnameEnable":{"name":"dhcpSendHostnameEnable","type":"\u0004","is_mandatory":true,"title":"DHCP hostname configuration enabled","provider":"go.mondoo.com/cnquery/providers/panos"},"dhcpSendHostnameValue":{"name":"dhcpSendHostnameValue","type":"\u0007","is_mandatory":true,"title":"DHCP hostname value","provider":"go.mondoo.com/cnquery/providers/panos"},"duplex":{"name":"duplex","type":"\u0007","is_mandatory":true,"title":"Actual operating duplex (runtime)","provider":"go.mondoo.com/cnquery/providers/panos"},"enableDhcp":{"name":"enableDhcp","type":"\u0004","is_mandatory":true,"title":"Whether DHCP is enabled","provider":"go.mondoo.com/cnquery/providers/panos"},"enableUntaggedSubinterface":{"name":"enableUntaggedSubinterface","type":"\u0004","is_mandatory":true,"title":"Enable untagged subinterface","provider":"go.mondoo.com/cnquery/providers/panos"},"ipAddresses":{"name":"ipAddresses","type":"\u0019\u000f","is_mandatory":true,"title":"Active IP addresses (runtime)","provider":"go.mondoo.com/cnquery/providers/panos"},"ipv4MssAdjust":{"name":"ipv4MssAdjust","type":"\u0005","is_mandatory":true,"title":"IPv4 MSS adjustment value in bytes","provider":"go.mondoo.com/cnquery/providers/panos"},"ipv6Addresses":{"name":"ipv6Addresses","type":"\u0019\u000f","is_mandatory":true,"title":"Active IPv6 addresses (runtime)","provider":"go.mondoo.com/cnquery/providers/panos"},"ipv6Enabled":{"name":"ipv6Enabled","type":"\u0004","is_mandatory":true,"title":"Whether IPv6 is enabled","provider":"go.mondoo.com/cnquery/providers/panos"},"ipv6InterfaceId":{"name":"ipv6InterfaceId","type":"\u0007","is_mandatory":true,"title":"IPv6 interface ID","provider":"go.mondoo.com/cnquery/providers/panos"},"ipv6MssAdjust":{"name":"ipv6MssAdjust","type":"\u0005","is_mandatory":true,"title":"IPv6 MSS adjustment value in bytes","provider":"go.mondoo.com/cnquery/providers/panos"},"lacpHaPassivePreNegotiation":{"name":"lacpHaPassivePreNegotiation","type":"\u0004","is_mandatory":true,"title":"LACP HA passive pre-negotiation","provider":"go.mondoo.com/cnquery/providers/panos"},"lacpPortPriority":{"name":"lacpPortPriority","type":"\u0005","is_mandatory":true,"title":"LACP port priority","provider":"go.mondoo.com/cnquery/providers/panos"},"linkDuplex":{"name":"linkDuplex","type":"\u0007","is_mandatory":true,"title":"Configured link duplex mode (full, half, auto)","provider":"go.mondoo.com/cnquery/providers/panos"},"linkSpeed":{"name":"linkSpeed","type":"\u0007","is_mandatory":true,"title":"Configured link speed in Mbps (e.g., \"10\", \"100\", \"1000\", \"10000\", \"auto\")","provider":"go.mondoo.com/cnquery/providers/panos"},"linkState":{"name":"linkState","type":"\u0007","is_mandatory":true,"title":"Configured link state","desc":"Administratively configured link state: \"up\", \"down\", or \"auto\" (let the hardware negotiate). Distinct from the runtime status field.","provider":"go.mondoo.com/cnquery/providers/panos"},"lldpEnabled":{"name":"lldpEnabled","type":"\u0004","is_mandatory":true,"title":"Whether LLDP is enabled","provider":"go.mondoo.com/cnquery/providers/panos"},"lldpHaPassivePreNegotiation":{"name":"lldpHaPassivePreNegotiation","type":"\u0004","is_mandatory":true,"title":"LLDP HA passive pre-negotiation","provider":"go.mondoo.com/cnquery/providers/panos"},"lldpProfile":{"name":"lldpProfile","type":"\u0007","is_mandatory":true,"title":"LLDP profile name","provider":"go.mondoo.com/cnquery/providers/panos"},"macAddress":{"name":"macAddress","type":"\u0007","is_mandatory":true,"title":"MAC address (runtime)","provider":"go.mondoo.com/cnquery/providers/panos"},"managementProfile":{"name":"managementProfile","type":"\u0007","is_mandatory":true,"title":"Management profile name","desc":"Name of the interface management profile controlling which management services (ping, HTTPS, SSH, SNMP) are permitted on the interface.","provider":"go.mondoo.com/cnquery/providers/panos"},"mode":{"name":"mode","type":"\u0007","is_mandatory":true,"title":"Interface mode","desc":"Deployment mode of the interface. One of \"layer3\", \"layer2\", \"virtual-wire\", \"tap\", or \"decrypt-mirror\". Interfaces in \"ha\" or \"aggregate-group\" mode are not returned in this collection.","provider":"go.mondoo.com/cnquery/providers/panos"},"mtu":{"name":"mtu","type":"\u0005","is_mandatory":true,"title":"Maximum transmission unit in bytes","provider":"go.mondoo.com/cnquery/providers/panos"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Interface name (e.g., \"ethernet1/1\")","provider":"go.mondoo.com/cnquery/providers/panos"},"netflowProfile":{"name":"netflowProfile","type":"\u0007","is_mandatory":true,"title":"NetFlow profile name","provider":"go.mondoo.com/cnquery/providers/panos"},"rxPolicingRate":{"name":"rxPolicingRate","type":"\u0005","is_mandatory":true,"title":"RX policing rate in Mbps","provider":"go.mondoo.com/cnquery/providers/panos"},"speed":{"name":"speed","type":"\u0007","is_mandatory":true,"title":"Actual operating speed in Mbps (runtime)","provider":"go.mondoo.com/cnquery/providers/panos"},"staticIps":{"name":"staticIps","type":"\u0019\u000f","is_mandatory":true,"title":"Static IP addresses configured","provider":"go.mondoo.com/cnquery/providers/panos"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Operational status","desc":"Live physical link status from the device: \"up\", \"down\", or \"unknown\" when operational data could not be read.","provider":"go.mondoo.com/cnquery/providers/panos"},"txPolicingRate":{"name":"txPolicingRate","type":"\u0005","is_mandatory":true,"title":"TX policing rate in Mbps","provider":"go.mondoo.com/cnquery/providers/panos"},"zone":{"name":"zone","type":"\u0007","is_mandatory":true,"title":"Security zone assignment (runtime)","provider":"go.mondoo.com/cnquery/providers/panos"}},"title":"PAN-OS ethernet interface","desc":"A physical ethernet interface (for example ethernet1/1) with both its configured settings and its live operational state. Configuration covers the interface mode, static and DHCP addressing, MTU and TCP-MSS adjustment, management and NetFlow profiles, and LLDP/LACP options. Runtime fields (status, macAddress, speed, duplex, zone, ipAddresses, ipv6Addresses) come from the device's live interface state and reflect what the interface is actually doing now. Selected by `name`.","defaults":"name mode status linkState","provider":"go.mondoo.com/cnquery/providers/panos"},"panos.network.ikeGateway":{"id":"panos.network.ikeGateway","name":"panos.network.ikeGateway","fields":{"authType":{"name":"authType","type":"\u0007","is_mandatory":true,"title":"Peer authentication method: \"pre-shared-key\" or \"certificate\"","provider":"go.mondoo.com/cnquery/providers/panos"},"certProfile":{"name":"certProfile","type":"\u0007","is_mandatory":true,"title":"Certificate profile used to validate the peer certificate; empty for pre-shared-key gateways","provider":"go.mondoo.com/cnquery/providers/panos"},"deadPeerDetectionInterval":{"name":"deadPeerDetectionInterval","type":"\u0005","is_mandatory":true,"title":"IKEv1 dead-peer detection probe interval in seconds","provider":"go.mondoo.com/cnquery/providers/panos"},"deadPeerDetectionRetry":{"name":"deadPeerDetectionRetry","type":"\u0005","is_mandatory":true,"title":"IKEv1 dead-peer detection retry count before declaring the peer dead","provider":"go.mondoo.com/cnquery/providers/panos"},"disabled":{"name":"disabled","type":"\u0004","is_mandatory":true,"title":"Whether the gateway is disabled","provider":"go.mondoo.com/cnquery/providers/panos"},"enableDeadPeerDetection":{"name":"enableDeadPeerDetection","type":"\u0004","is_mandatory":true,"title":"Whether IKEv1 dead-peer detection is enabled","provider":"go.mondoo.com/cnquery/providers/panos"},"enableFragmentation":{"name":"enableFragmentation","type":"\u0004","is_mandatory":true,"title":"Whether IKE fragmentation is enabled to handle large IKE payloads across NAT devices","provider":"go.mondoo.com/cnquery/providers/panos"},"enableIpv6":{"name":"enableIpv6","type":"\u0004","is_mandatory":true,"title":"Whether the gateway uses IPv6 for the tunnel endpoints","provider":"go.mondoo.com/cnquery/providers/panos"},"enableLivenessCheck":{"name":"enableLivenessCheck","type":"\u0004","is_mandatory":true,"title":"Whether IKEv2 liveness check is enabled","provider":"go.mondoo.com/cnquery/providers/panos"},"enableNatTraversal":{"name":"enableNatTraversal","type":"\u0004","is_mandatory":true,"title":"Whether NAT-Traversal (UDP encapsulation of IKE/IPsec) is enabled","provider":"go.mondoo.com/cnquery/providers/panos"},"enablePassiveMode":{"name":"enablePassiveMode","type":"\u0004","is_mandatory":true,"title":"Whether the gateway operates in passive mode, responding to but never initiating IKE negotiation","provider":"go.mondoo.com/cnquery/providers/panos"},"ikev1CryptoProfile":{"name":"ikev1CryptoProfile","type":"\u0007","is_mandatory":true,"title":"IKEv1 crypto profile defining the phase-1 encryption, authentication, DH group, and lifetime","provider":"go.mondoo.com/cnquery/providers/panos"},"ikev1ExchangeMode":{"name":"ikev1ExchangeMode","type":"\u0007","is_mandatory":true,"title":"IKEv1 exchange mode: \"main\" (identity-protecting), \"aggressive\" (fewer messages, exposes identities), or \"auto\" (accept either)","provider":"go.mondoo.com/cnquery/providers/panos"},"ikev2CookieValidation":{"name":"ikev2CookieValidation","type":"\u0004","is_mandatory":true,"title":"Whether IKEv2 cookie validation (strict cookie exchange) is enforced against DoS attacks","provider":"go.mondoo.com/cnquery/providers/panos"},"ikev2CryptoProfile":{"name":"ikev2CryptoProfile","type":"\u0007","is_mandatory":true,"title":"IKEv2 crypto profile defining the phase-1 encryption, authentication, DH group, and lifetime","provider":"go.mondoo.com/cnquery/providers/panos"},"interface":{"name":"interface","type":"\u0007","is_mandatory":true,"title":"Local interface terminating the gateway","provider":"go.mondoo.com/cnquery/providers/panos"},"livenessCheckInterval":{"name":"livenessCheckInterval","type":"\u0005","is_mandatory":true,"title":"IKEv2 liveness check interval in seconds","provider":"go.mondoo.com/cnquery/providers/panos"},"localCert":{"name":"localCert","type":"\u0007","is_mandatory":true,"title":"Local certificate presented for certificate authentication; empty for pre-shared-key gateways","provider":"go.mondoo.com/cnquery/providers/panos"},"localIdType":{"name":"localIdType","type":"\u0007","is_mandatory":true,"title":"Local identity type presented to the peer","desc":"One of \"ipaddr\" (IP address), \"fqdn\" (fully qualified domain name), \"ufqdn\" (user FQDN / email address), \"keyid\" (arbitrary key ID), or \"dn\" (certificate distinguished name). Empty defaults to the local IP.","provider":"go.mondoo.com/cnquery/providers/panos"},"localIdValue":{"name":"localIdValue","type":"\u0007","is_mandatory":true,"title":"Local identity value, interpreted per localIdType","provider":"go.mondoo.com/cnquery/providers/panos"},"localIpAddressType":{"name":"localIpAddressType","type":"\u0007","is_mandatory":true,"title":"How the local address is specified: \"ip\" (a fixed address on the interface) or \"floating-ip\" (an HA floating IP)","provider":"go.mondoo.com/cnquery/providers/panos"},"localIpAddressValue":{"name":"localIpAddressValue","type":"\u0007","is_mandatory":true,"title":"Local IP address value, interpreted per localIpAddressType","provider":"go.mondoo.com/cnquery/providers/panos"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Gateway name","provider":"go.mondoo.com/cnquery/providers/panos"},"natTraversalKeepAlive":{"name":"natTraversalKeepAlive","type":"\u0005","is_mandatory":true,"title":"NAT-Traversal keep-alive interval in seconds","provider":"go.mondoo.com/cnquery/providers/panos"},"peerIdCheck":{"name":"peerIdCheck","type":"\u0007","is_mandatory":true,"title":"How the peer identity is validated against the certificate: \"exact\" (must match exactly) or \"wildcard\" (allows wildcard matching)","provider":"go.mondoo.com/cnquery/providers/panos"},"peerIdType":{"name":"peerIdType","type":"\u0007","is_mandatory":true,"title":"Expected peer identity type","desc":"One of \"ipaddr\", \"fqdn\", \"ufqdn\", \"keyid\", or \"dn\". Empty defaults to the peer IP.","provider":"go.mondoo.com/cnquery/providers/panos"},"peerIdValue":{"name":"peerIdValue","type":"\u0007","is_mandatory":true,"title":"Expected peer identity value, interpreted per peerIdType","provider":"go.mondoo.com/cnquery/providers/panos"},"peerIpType":{"name":"peerIpType","type":"\u0007","is_mandatory":true,"title":"How the peer address is specified","desc":"One of \"ip\" (static IP), \"dynamic\" (peer address is not fixed), or \"fqdn\" (peer resolved from a hostname).","provider":"go.mondoo.com/cnquery/providers/panos"},"peerIpValue":{"name":"peerIpValue","type":"\u0007","is_mandatory":true,"title":"Peer IP address or FQDN, interpreted per peerIpType; empty when peerIpType is \"dynamic\"","provider":"go.mondoo.com/cnquery/providers/panos"},"version":{"name":"version","type":"\u0007","is_mandatory":true,"title":"IKE protocol version","desc":"One of \"ikev1\" (IKEv1 only), \"ikev2\" (IKEv2 only), or \"ikev2-preferred\" (negotiate IKEv2, fall back to IKEv1).","provider":"go.mondoo.com/cnquery/providers/panos"}},"title":"PAN-OS IKE gateway","desc":"An IKE (Internet Key Exchange) gateway defining how the firewall negotiates a security association with a VPN peer: the IKE version, peer addressing, authentication method (pre-shared key or certificate), local and peer identities, and the IKEv1/IKEv2 crypto profiles. Useful for auditing VPN authentication strength, for example finding gateways still using pre-shared keys or IKEv1. Selected by `name`.","defaults":"name version peerIpValue","provider":"go.mondoo.com/cnquery/providers/panos"},"panos.network.ipsecTunnel":{"id":"panos.network.ipsecTunnel","name":"panos.network.ipsecTunnel","fields":{"akIkeGateway":{"name":"akIkeGateway","type":"\u0007","is_mandatory":true,"title":"IKE gateway used for key negotiation when type is \"auto-key\"; empty for other types","provider":"go.mondoo.com/cnquery/providers/panos"},"akIpsecCryptoProfile":{"name":"akIpsecCryptoProfile","type":"\u0007","is_mandatory":true,"title":"IPsec crypto profile (phase-2 ESP/AH, encryption, authentication, PFS group) used when type is \"auto-key\"","provider":"go.mondoo.com/cnquery/providers/panos"},"antiReplay":{"name":"antiReplay","type":"\u0004","is_mandatory":true,"title":"Whether anti-replay protection is enabled to reject replayed IPsec packets","provider":"go.mondoo.com/cnquery/providers/panos"},"copyFlowLabel":{"name":"copyFlowLabel","type":"\u0004","is_mandatory":true,"title":"Whether the inner packet's IPv6 flow label is copied to the outer tunnel header","provider":"go.mondoo.com/cnquery/providers/panos"},"copyTos":{"name":"copyTos","type":"\u0004","is_mandatory":true,"title":"Whether the inner packet's IPv4 TOS/DSCP byte is copied to the outer tunnel header","provider":"go.mondoo.com/cnquery/providers/panos"},"disabled":{"name":"disabled","type":"\u0004","is_mandatory":true,"title":"Whether the tunnel is disabled","provider":"go.mondoo.com/cnquery/providers/panos"},"enableIpv6":{"name":"enableIpv6","type":"\u0004","is_mandatory":true,"title":"Whether the tunnel carries IPv6 traffic","provider":"go.mondoo.com/cnquery/providers/panos"},"enableTunnelMonitor":{"name":"enableTunnelMonitor","type":"\u0004","is_mandatory":true,"title":"Whether tunnel monitoring probes the far end to track tunnel health","provider":"go.mondoo.com/cnquery/providers/panos"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Tunnel name","provider":"go.mondoo.com/cnquery/providers/panos"},"tunnelInterface":{"name":"tunnelInterface","type":"\u0007","is_mandatory":true,"title":"Tunnel interface (for example tunnel.1) the IPsec tunnel is bound to","provider":"go.mondoo.com/cnquery/providers/panos"},"tunnelMonitorDestinationIp":{"name":"tunnelMonitorDestinationIp","type":"\u0007","is_mandatory":true,"title":"Destination IP the tunnel monitor probes across the tunnel","provider":"go.mondoo.com/cnquery/providers/panos"},"tunnelMonitorProfile":{"name":"tunnelMonitorProfile","type":"\u0007","is_mandatory":true,"title":"Monitor profile defining the action (wait-recover or fail-over) taken when tunnel monitoring fails","provider":"go.mondoo.com/cnquery/providers/panos"},"tunnelMonitorSourceIp":{"name":"tunnelMonitorSourceIp","type":"\u0007","is_mandatory":true,"title":"Source IP used for tunnel monitor probes","provider":"go.mondoo.com/cnquery/providers/panos"},"type":{"name":"type","type":"\u0007","is_mandatory":true,"title":"Key-exchange type","desc":"One of \"auto-key\" (IKE-negotiated keys), \"manual-key\" (statically configured keys), or \"global-protect-satellite\" (GlobalProtect LSVPN satellite).","provider":"go.mondoo.com/cnquery/providers/panos"}},"title":"PAN-OS IPsec tunnel","desc":"An IPsec tunnel binding a tunnel interface to an IKE gateway and IPsec crypto profile to carry site-to-site VPN traffic, with anti-replay and tunnel-monitoring settings. Selected by `name`.","defaults":"name type akIkeGateway","provider":"go.mondoo.com/cnquery/providers/panos"},"panos.network.loopbackInterface":{"id":"panos.network.loopbackInterface","name":"panos.network.loopbackInterface","fields":{"adjustTcpMss":{"name":"adjustTcpMss","type":"\u0004","is_mandatory":true,"title":"Whether to adjust the TCP maximum segment size (MSS)","provider":"go.mondoo.com/cnquery/providers/panos"},"comment":{"name":"comment","type":"\u0007","is_mandatory":true,"title":"Comment/description configured for the interface","provider":"go.mondoo.com/cnquery/providers/panos"},"ipAddresses":{"name":"ipAddresses","type":"\u0019\u000f","is_mandatory":true,"title":"Active IP addresses currently bound to the interface","provider":"go.mondoo.com/cnquery/providers/panos"},"ipv4MssAdjust":{"name":"ipv4MssAdjust","type":"\u0005","is_mandatory":true,"title":"IPv4 MSS adjustment value in bytes","provider":"go.mondoo.com/cnquery/providers/panos"},"ipv6MssAdjust":{"name":"ipv6MssAdjust","type":"\u0005","is_mandatory":true,"title":"IPv6 MSS adjustment value in bytes","provider":"go.mondoo.com/cnquery/providers/panos"},"managementProfile":{"name":"managementProfile","type":"\u0007","is_mandatory":true,"title":"Management profile name controlling which management services are allowed","provider":"go.mondoo.com/cnquery/providers/panos"},"mtu":{"name":"mtu","type":"\u0005","is_mandatory":true,"title":"Maximum transmission unit in bytes","provider":"go.mondoo.com/cnquery/providers/panos"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Interface name (e.g., \"loopback.1\")","provider":"go.mondoo.com/cnquery/providers/panos"},"netflowProfile":{"name":"netflowProfile","type":"\u0007","is_mandatory":true,"title":"NetFlow profile name","provider":"go.mondoo.com/cnquery/providers/panos"},"staticIps":{"name":"staticIps","type":"\u0019\u000f","is_mandatory":true,"title":"Static IP addresses configured on the interface","provider":"go.mondoo.com/cnquery/providers/panos"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Operational status","desc":"Live interface status from the device: \"up\", \"down\", or \"unknown\" when operational data could not be read.","provider":"go.mondoo.com/cnquery/providers/panos"},"zone":{"name":"zone","type":"\u0007","is_mandatory":true,"title":"Security zone the interface is assigned to","provider":"go.mondoo.com/cnquery/providers/panos"}},"title":"PAN-OS loopback interface","desc":"A logical loopback interface (for example loopback.1), often used as a stable service endpoint or router ID. Exposes its static addressing, management profile, MTU, and the live operational status, zone, and active addresses. Selected by `name`.","defaults":"name status","provider":"go.mondoo.com/cnquery/providers/panos"},"panos.network.ospf":{"id":"panos.network.ospf","name":"panos.network.ospf","fields":{"allowRedistributeDefaultRoute":{"name":"allowRedistributeDefaultRoute","type":"\u0004","is_mandatory":true,"title":"Whether the default route may be redistributed into OSPF from other protocols","provider":"go.mondoo.com/cnquery/providers/panos"},"bfdProfile":{"name":"bfdProfile","type":"\u0007","is_mandatory":true,"title":"Global BFD profile for OSPF, the name of the Bidirectional Forwarding Detection profile, or \"None\" to disable BFD","provider":"go.mondoo.com/cnquery/providers/panos"},"enable":{"name":"enable","type":"\u0004","is_mandatory":true,"title":"Whether OSPF is enabled on the virtual router","provider":"go.mondoo.com/cnquery/providers/panos"},"enableGracefulRestart":{"name":"enableGracefulRestart","type":"\u0004","is_mandatory":true,"title":"Whether OSPF graceful restart is enabled, allowing forwarding to continue across a restart of the OSPF control plane","provider":"go.mondoo.com/cnquery/providers/panos"},"gracePeriod":{"name":"gracePeriod","type":"\u0005","is_mandatory":true,"title":"Grace period in seconds this router advertises to neighbors during a graceful restart (PAN-OS default is 120; range 5 to 1800)","provider":"go.mondoo.com/cnquery/providers/panos"},"helperEnable":{"name":"helperEnable","type":"\u0004","is_mandatory":true,"title":"Whether this router acts as a graceful-restart helper for restarting neighbors","provider":"go.mondoo.com/cnquery/providers/panos"},"lsaInterval":{"name":"lsaInterval","type":"\u0006","is_mandatory":true,"title":"LSA interval in seconds, the minimum time between successive originations of the same LSA (range 0 to 60)","provider":"go.mondoo.com/cnquery/providers/panos"},"maxNeighborRestartTime":{"name":"maxNeighborRestartTime","type":"\u0005","is_mandatory":true,"title":"Maximum neighbor restart time in seconds this router will accept from a restarting neighbor while acting as helper (PAN-OS default is 140","desc":"range 5 to 1800)","provider":"go.mondoo.com/cnquery/providers/panos"},"rejectDefaultRoute":{"name":"rejectDefaultRoute","type":"\u0004","is_mandatory":true,"title":"Whether to reject the default route (0.0.0.0/0) learned via OSPF","provider":"go.mondoo.com/cnquery/providers/panos"},"rfc1583":{"name":"rfc1583","type":"\u0004","is_mandatory":true,"title":"Whether RFC 1583 compatibility is enabled","desc":"controlling how the cost of summary and external routes is calculated (leave off unless interoperating with legacy RFC 1583 routers)","provider":"go.mondoo.com/cnquery/providers/panos"},"routerId":{"name":"routerId","type":"\u0007","is_mandatory":true,"title":"OSPF router ID, the 32-bit identifier of this router (typically an IPv4 address such as \"10.0.0.1\")","provider":"go.mondoo.com/cnquery/providers/panos"},"spfCalculationDelay":{"name":"spfCalculationDelay","type":"\u0006","is_mandatory":true,"title":"SPF calculation delay in seconds, the wait after a topology change before running the shortest-path-first calculation (range 0 to 60)","provider":"go.mondoo.com/cnquery/providers/panos"},"strictLsaChecking":{"name":"strictLsaChecking","type":"\u0004","is_mandatory":true,"title":"Whether strict LSA checking is enabled, causing the helper to exit graceful restart if a topology change occurs during a neighbor's restart","provider":"go.mondoo.com/cnquery/providers/panos"},"virtualRouter":{"name":"virtualRouter","type":"\u0007","is_mandatory":true,"title":"Name of the virtual router this OSPF configuration belongs to","provider":"go.mondoo.com/cnquery/providers/panos"}},"title":"PAN-OS OSPF configuration for a virtual router","desc":"The OSPFv2 routing configuration of a single virtual router: whether OSPF is enabled, the router ID, default-route handling, RFC 1583 compatibility, SPF and LSA timers, graceful-restart settings, and the global BFD profile. Reach it from a virtual router via its ospf field. Use it alongside ospfArea and ospfAreaInterface to confirm areas and adjacencies are authenticated and scoped as intended.","defaults":"enable routerId","provider":"go.mondoo.com/cnquery/providers/panos"},"panos.network.ospfArea":{"id":"panos.network.ospfArea","name":"panos.network.ospfArea","fields":{"acceptSummary":{"name":"acceptSummary","type":"\u0004","is_mandatory":true,"title":"Whether summary (inter-area) LSAs are accepted into the area (applies to stub and nssa areas)","provider":"go.mondoo.com/cnquery/providers/panos"},"advertiseMetric":{"name":"advertiseMetric","type":"\u0005","is_mandatory":true,"title":"Metric applied to the advertised default route (applies to stub and nssa areas)","provider":"go.mondoo.com/cnquery/providers/panos"},"advertiseType":{"name":"advertiseType","type":"\u0007","is_mandatory":true,"title":"NSSA default-route advertise type","desc":"External path type used when advertising the default route into an NSSA area, either \"ext-1\" (type-1, metric plus internal cost) or \"ext-2\" (type-2, external metric only). Applies to nssa areas.","provider":"go.mondoo.com/cnquery/providers/panos"},"defaultRouteAdvertise":{"name":"defaultRouteAdvertise","type":"\u0004","is_mandatory":true,"title":"Whether a default route is advertised into the area by the area border router (applies to stub and nssa areas)","provider":"go.mondoo.com/cnquery/providers/panos"},"interfaces":{"name":"interfaces","type":"\u0019\u001bpanos.network.ospfAreaInterface","title":"OSPF interfaces participating in this area","provider":"go.mondoo.com/cnquery/providers/panos"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Area identifier in dotted-decimal form (e.g., \"0.0.0.0\" for the backbone)","provider":"go.mondoo.com/cnquery/providers/panos"},"type":{"name":"type","type":"\u0007","is_mandatory":true,"title":"Area type","desc":"One of \"normal\" (a standard area that accepts all LSA types), \"stub\" (blocks external LSAs and uses a default route instead), or \"nssa\" (not-so-stubby area, which blocks external LSAs but allows limited external route import via type-7 LSAs).","provider":"go.mondoo.com/cnquery/providers/panos"},"virtualLinks":{"name":"virtualLinks","type":"\u0019\u001bpanos.network.ospfAreaVirtualLink","title":"Virtual links configured in this area","provider":"go.mondoo.com/cnquery/providers/panos"},"virtualRouter":{"name":"virtualRouter","type":"\u0007","is_mandatory":true,"title":"Name of the virtual router this area belongs to","provider":"go.mondoo.com/cnquery/providers/panos"}},"init":{"args":[{"name":"name","type":"\u0007"}]},"title":"PAN-OS OSPF area","desc":"A single OSPF area on a virtual router, identified by its area ID (for example \"0.0.0.0\" for the backbone). The type field governs how external routes and summaries are handled, and the interfaces and virtualLinks fields reach the member interfaces and any virtual links. Selected by `name`, for example `panos.network.virtualRouter.ospfAreas.where(type == \"nssa\")`.","defaults":"name type","provider":"go.mondoo.com/cnquery/providers/panos"},"panos.network.ospfAreaInterface":{"id":"panos.network.ospfAreaInterface","name":"panos.network.ospfAreaInterface","fields":{"area":{"name":"area","type":"\u0007","is_mandatory":true,"title":"Name of the OSPF area this interface belongs to","provider":"go.mondoo.com/cnquery/providers/panos"},"authProfile":{"name":"authProfile","type":"\u0007","is_mandatory":true,"title":"Authentication profile","desc":"Name of the OSPF authentication profile securing adjacencies on the interface (simple password or MD5). Empty means adjacencies are unauthenticated.","provider":"go.mondoo.com/cnquery/providers/panos"},"bfdProfile":{"name":"bfdProfile","type":"\u0007","is_mandatory":true,"title":"BFD profile for this interface, the name of the Bidirectional Forwarding Detection profile, or \"None\" to disable BFD","provider":"go.mondoo.com/cnquery/providers/panos"},"deadCounts":{"name":"deadCounts","type":"\u0005","is_mandatory":true,"title":"Dead counts, the number of missed hello intervals before a neighbor is declared down","desc":"dead interval equals deadCounts times helloInterval (PAN-OS default is 4)","provider":"go.mondoo.com/cnquery/providers/panos"},"enable":{"name":"enable","type":"\u0004","is_mandatory":true,"title":"Whether OSPF is enabled on this interface","provider":"go.mondoo.com/cnquery/providers/panos"},"graceRestartDelay":{"name":"graceRestartDelay","type":"\u0005","is_mandatory":true,"title":"Graceful-restart hello delay in seconds, how long grace LSAs are sent before restart (PAN-OS default is 10)","provider":"go.mondoo.com/cnquery/providers/panos"},"helloInterval":{"name":"helloInterval","type":"\u0005","is_mandatory":true,"title":"Hello interval in seconds between OSPF hello packets (PAN-OS default is 10)","provider":"go.mondoo.com/cnquery/providers/panos"},"linkType":{"name":"linkType","type":"\u0007","is_mandatory":true,"title":"Link type","desc":"One of \"broadcast\" (multi-access with DR/BDR election), \"p2p\" (point-to-point, no DR election), or \"p2mp\" (point-to-multipoint, which uses the neighbors field for statically configured neighbors).","provider":"go.mondoo.com/cnquery/providers/panos"},"metric":{"name":"metric","type":"\u0005","is_mandatory":true,"title":"Interface cost (metric) used in OSPF shortest-path calculations","provider":"go.mondoo.com/cnquery/providers/panos"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Interface name (e.g., \"ethernet1/1\")","provider":"go.mondoo.com/cnquery/providers/panos"},"neighbors":{"name":"neighbors","type":"\u0019\u0007","is_mandatory":true,"title":"Statically configured neighbor IP addresses (used only with the p2mp link type)","provider":"go.mondoo.com/cnquery/providers/panos"},"passive":{"name":"passive","type":"\u0004","is_mandatory":true,"title":"Whether this is a passive interface, meaning the subnet is advertised into OSPF but no adjacency is formed and no hellos are sent","provider":"go.mondoo.com/cnquery/providers/panos"},"priority":{"name":"priority","type":"\u0005","is_mandatory":true,"title":"Router priority for designated-router (DR) election on broadcast links","desc":"higher wins, and 0 makes the interface ineligible to be DR (PAN-OS default is 1)","provider":"go.mondoo.com/cnquery/providers/panos"},"retransmitInterval":{"name":"retransmitInterval","type":"\u0005","is_mandatory":true,"title":"Retransmit interval in seconds between retransmissions of unacknowledged LSAs (PAN-OS default is 5)","provider":"go.mondoo.com/cnquery/providers/panos"},"transitDelay":{"name":"transitDelay","type":"\u0005","is_mandatory":true,"title":"Transit delay in seconds, the estimated time to transmit an LSA on the interface (PAN-OS default is 1)","provider":"go.mondoo.com/cnquery/providers/panos"},"virtualRouter":{"name":"virtualRouter","type":"\u0007","is_mandatory":true,"title":"Name of the virtual router this interface belongs to","provider":"go.mondoo.com/cnquery/providers/panos"}},"init":{"args":[{"name":"name","type":"\u0007"}]},"title":"PAN-OS OSPF area interface","desc":"An interface participating in an OSPF area, with its OSPF timers, cost (metric), DR-election priority, link type, BFD profile, and authentication profile. The authProfile field reveals whether OSPF adjacencies on the interface are authenticated: an empty value means the adjacency is unauthenticated. Selected by `name`, for example `panos.network.ospfArea.interfaces.where(authProfile == \"\")`.","defaults":"name linkType","provider":"go.mondoo.com/cnquery/providers/panos"},"panos.network.ospfAreaVirtualLink":{"id":"panos.network.ospfAreaVirtualLink","name":"panos.network.ospfAreaVirtualLink","fields":{"area":{"name":"area","type":"\u0007","is_mandatory":true,"title":"Name of the OSPF area this virtual link belongs to","provider":"go.mondoo.com/cnquery/providers/panos"},"authProfile":{"name":"authProfile","type":"\u0007","is_mandatory":true,"title":"Authentication profile","desc":"Name of the OSPF authentication profile securing the virtual link. Empty means the link is unauthenticated.","provider":"go.mondoo.com/cnquery/providers/panos"},"bfdProfile":{"name":"bfdProfile","type":"\u0007","is_mandatory":true,"title":"BFD profile for this virtual link, the name of the Bidirectional Forwarding Detection profile, or \"None\" to disable BFD","provider":"go.mondoo.com/cnquery/providers/panos"},"deadCounts":{"name":"deadCounts","type":"\u0005","is_mandatory":true,"title":"Dead counts, the number of missed hello intervals before the neighbor is declared down (PAN-OS default is 4)","provider":"go.mondoo.com/cnquery/providers/panos"},"enable":{"name":"enable","type":"\u0004","is_mandatory":true,"title":"Whether this virtual link is enabled","provider":"go.mondoo.com/cnquery/providers/panos"},"helloInterval":{"name":"helloInterval","type":"\u0005","is_mandatory":true,"title":"Hello interval in seconds between OSPF hello packets on the link (PAN-OS default is 10)","provider":"go.mondoo.com/cnquery/providers/panos"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Virtual link name","provider":"go.mondoo.com/cnquery/providers/panos"},"neighborId":{"name":"neighborId","type":"\u0007","is_mandatory":true,"title":"Router ID of the virtual-link neighbor (the area border router at the far end of the link)","provider":"go.mondoo.com/cnquery/providers/panos"},"retransmitInterval":{"name":"retransmitInterval","type":"\u0005","is_mandatory":true,"title":"Retransmit interval in seconds between retransmissions of unacknowledged LSAs (PAN-OS default is 5)","provider":"go.mondoo.com/cnquery/providers/panos"},"transitAreaId":{"name":"transitAreaId","type":"\u0007","is_mandatory":true,"title":"Area ID of the non-backbone transit area the virtual link crosses (in dotted-decimal form)","provider":"go.mondoo.com/cnquery/providers/panos"},"transitDelay":{"name":"transitDelay","type":"\u0005","is_mandatory":true,"title":"Transit delay in seconds, the estimated time to transmit an LSA over the link (PAN-OS default is 1)","provider":"go.mondoo.com/cnquery/providers/panos"},"virtualRouter":{"name":"virtualRouter","type":"\u0007","is_mandatory":true,"title":"Name of the virtual router this virtual link belongs to","provider":"go.mondoo.com/cnquery/providers/panos"}},"init":{"args":[{"name":"name","type":"\u0007"}]},"title":"PAN-OS OSPF area virtual link","desc":"An OSPF virtual link that connects an area disconnected from the backbone to area 0 across a non-backbone transit area. Identified by the neighbor router ID and the transit area it traverses, and carrying the OSPF timers, BFD profile, and authentication profile for the link. Selected by `name`. The authProfile field reveals whether the virtual link is authenticated.","defaults":"name neighborId","provider":"go.mondoo.com/cnquery/providers/panos"},"panos.network.ospfExportRule":{"id":"panos.network.ospfExportRule","name":"panos.network.ospfExportRule","fields":{"metric":{"name":"metric","type":"\u0005","is_mandatory":true,"title":"Metric (cost) applied to advertised external routes","provider":"go.mondoo.com/cnquery/providers/panos"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Export rule name (matches the name of a redistribution profile)","provider":"go.mondoo.com/cnquery/providers/panos"},"pathType":{"name":"pathType","type":"\u0007","is_mandatory":true,"title":"External path type","desc":"Type of external route advertised into OSPF, either \"ext-1\" (type-1, external metric plus the internal cost to the ASBR) or \"ext-2\" (type-2, external metric only, ignoring internal cost).","provider":"go.mondoo.com/cnquery/providers/panos"},"tag":{"name":"tag","type":"\u0007","is_mandatory":true,"title":"OSPF route tag applied to advertised external routes, a 32-bit value used for route filtering and loop prevention (as a string)","provider":"go.mondoo.com/cnquery/providers/panos"},"virtualRouter":{"name":"virtualRouter","type":"\u0007","is_mandatory":true,"title":"Name of the virtual router this export rule belongs to","provider":"go.mondoo.com/cnquery/providers/panos"}},"init":{"args":[{"name":"name","type":"\u0007"}]},"title":"PAN-OS OSPF export rule","desc":"A rule controlling how routes redistributed into OSPF are advertised as external routes: the external path type, the OSPF route tag, and the metric applied. Selected by `name`. Use it to confirm which redistributed routes leave the OSPF domain and with what external cost.","defaults":"name pathType","provider":"go.mondoo.com/cnquery/providers/panos"},"panos.network.staticRoute":{"id":"panos.network.staticRoute","name":"panos.network.staticRoute","fields":{"adminDistance":{"name":"adminDistance","type":"\u0005","is_mandatory":true,"title":"Administrative distance ranking this route against routes to the same destination from other sources","provider":"go.mondoo.com/cnquery/providers/panos"},"bfdProfile":{"name":"bfdProfile","type":"\u0007","is_mandatory":true,"title":"BFD profile enabling bidirectional forwarding detection for fast failure detection on the route; empty when BFD is not configured","provider":"go.mondoo.com/cnquery/providers/panos"},"destination":{"name":"destination","type":"\u0007","is_mandatory":true,"title":"Destination network in CIDR notation (e.g., \"0.0.0.0/0\")","provider":"go.mondoo.com/cnquery/providers/panos"},"interface":{"name":"interface","type":"\u0007","is_mandatory":true,"title":"Egress interface for the route; empty when the route relies solely on the next-hop lookup","provider":"go.mondoo.com/cnquery/providers/panos"},"metric":{"name":"metric","type":"\u0005","is_mandatory":true,"title":"Route metric used to choose among routes of equal administrative distance (lower wins)","provider":"go.mondoo.com/cnquery/providers/panos"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Route name","provider":"go.mondoo.com/cnquery/providers/panos"},"nextHop":{"name":"nextHop","type":"\u0007","is_mandatory":true,"title":"Next-hop value interpreted per type: the IP address for \"ip-address\", or the virtual router name for \"next-vr\"","desc":"empty for \"discard\" and unconfigured routes","provider":"go.mondoo.com/cnquery/providers/panos"},"routeTable":{"name":"routeTable","type":"\u0007","is_mandatory":true,"title":"Route table the route is installed into","desc":"One of \"unicast\", \"multicast\", \"both\", or \"no install\" (configured but not placed in any forwarding table).","provider":"go.mondoo.com/cnquery/providers/panos"},"type":{"name":"type","type":"\u0007","is_mandatory":true,"title":"Next-hop type","desc":"One of \"ip-address\" (forward to the IP in nextHop), \"discard\" (blackhole and silently drop matching traffic), \"next-vr\" (hand off to the virtual router named in nextHop), or empty (no explicit next hop configured).","provider":"go.mondoo.com/cnquery/providers/panos"},"virtualRouter":{"name":"virtualRouter","type":"\u0007","is_mandatory":true,"title":"Virtual router this route belongs to","provider":"go.mondoo.com/cnquery/providers/panos"}},"title":"PAN-OS IPv4 static route","desc":"A static IPv4 route on a virtual router, mapping a destination network to a next hop and egress interface. The next-hop type distinguishes a plain IP next hop from a blackhole (discard) or a handoff to another virtual router. Useful for reviewing default routes and blackhole entries.","defaults":"name destination nextHop","provider":"go.mondoo.com/cnquery/providers/panos"},"panos.network.tunnelInterface":{"id":"panos.network.tunnelInterface","name":"panos.network.tunnelInterface","fields":{"comment":{"name":"comment","type":"\u0007","is_mandatory":true,"title":"Free-text description configured on the interface","provider":"go.mondoo.com/cnquery/providers/panos"},"ipAddresses":{"name":"ipAddresses","type":"\u0019\u000f","is_mandatory":true,"title":"Active IP addresses bound to the interface at runtime, from operational data","provider":"go.mondoo.com/cnquery/providers/panos"},"managementProfile":{"name":"managementProfile","type":"\u0007","is_mandatory":true,"title":"Interface management profile controlling which services (ping, SSH, HTTPS, SNMP) are permitted on the interface addresses","provider":"go.mondoo.com/cnquery/providers/panos"},"mtu":{"name":"mtu","type":"\u0005","is_mandatory":true,"title":"Maximum transmission unit in bytes","provider":"go.mondoo.com/cnquery/providers/panos"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Interface name (e.g., \"tunnel.1\")","provider":"go.mondoo.com/cnquery/providers/panos"},"netflowProfile":{"name":"netflowProfile","type":"\u0007","is_mandatory":true,"title":"NetFlow server profile the interface exports flow records to","provider":"go.mondoo.com/cnquery/providers/panos"},"staticIps":{"name":"staticIps","type":"\u0019\u000f","is_mandatory":true,"title":"Static IP addresses configured on the interface, in bare or CIDR notation","provider":"go.mondoo.com/cnquery/providers/panos"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Operational link status from \"show interface all\"","desc":"One of \"up\", \"down\", or \"unknown\". \"unknown\" is reported when no matching hardware entry is found in the operational data or when the operational query returned nothing.","provider":"go.mondoo.com/cnquery/providers/panos"},"zone":{"name":"zone","type":"\u0007","is_mandatory":true,"title":"Security zone the interface is assigned to, from operational data","provider":"go.mondoo.com/cnquery/providers/panos"}},"title":"PAN-OS tunnel interface","desc":"A logical tunnel interface (for example tunnel.1) that serves as the termination point for IPsec and other tunnels. Exposes its addressing, management profile, MTU, and live operational status, zone, and active addresses. Selected by `name`.","defaults":"name status","provider":"go.mondoo.com/cnquery/providers/panos"},"panos.network.virtualRouter":{"id":"panos.network.virtualRouter","name":"panos.network.virtualRouter","fields":{"bgp":{"name":"bgp","type":"\u001bpanos.network.bgp","title":"BGP configuration for this virtual router","provider":"go.mondoo.com/cnquery/providers/panos"},"bgpPeerGroups":{"name":"bgpPeerGroups","type":"\u0019\u001bpanos.network.bgpPeerGroup","title":"BGP peer groups configured on this virtual router","provider":"go.mondoo.com/cnquery/providers/panos"},"ebgpDist":{"name":"ebgpDist","type":"\u0005","is_mandatory":true,"title":"Administrative distance for external BGP routes (PAN-OS default 20)","provider":"go.mondoo.com/cnquery/providers/panos"},"ecmpLoadBalanceMethod":{"name":"ecmpLoadBalanceMethod","type":"\u0007","is_mandatory":true,"title":"ECMP load-balancing algorithm","desc":"One of \"ip-modulo\", \"ip-hash\", \"weighted-round-robin\", or \"balanced-round-robin\". Empty when ECMP is disabled.","provider":"go.mondoo.com/cnquery/providers/panos"},"ecmpMaxPath":{"name":"ecmpMaxPath","type":"\u0005","is_mandatory":true,"title":"Maximum number of equal-cost paths installed per destination (PAN-OS default 2, up to 4)","provider":"go.mondoo.com/cnquery/providers/panos"},"enableEcmp":{"name":"enableEcmp","type":"\u0004","is_mandatory":true,"title":"Whether equal-cost multipath (ECMP) routing is enabled","provider":"go.mondoo.com/cnquery/providers/panos"},"ibgpDist":{"name":"ibgpDist","type":"\u0005","is_mandatory":true,"title":"Administrative distance for internal BGP routes (PAN-OS default 200)","provider":"go.mondoo.com/cnquery/providers/panos"},"interfaces":{"name":"interfaces","type":"\u0019\u0007","is_mandatory":true,"title":"Interfaces assigned to this virtual router","provider":"go.mondoo.com/cnquery/providers/panos"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Virtual router name","provider":"go.mondoo.com/cnquery/providers/panos"},"ospf":{"name":"ospf","type":"\u001bpanos.network.ospf","title":"OSPF configuration for this virtual router","provider":"go.mondoo.com/cnquery/providers/panos"},"ospfAreas":{"name":"ospfAreas","type":"\u0019\u001bpanos.network.ospfArea","title":"OSPF areas configured on this virtual router","provider":"go.mondoo.com/cnquery/providers/panos"},"ospfExportRules":{"name":"ospfExportRules","type":"\u0019\u001bpanos.network.ospfExportRule","title":"OSPF export rules configured on this virtual router","provider":"go.mondoo.com/cnquery/providers/panos"},"ospfExtDist":{"name":"ospfExtDist","type":"\u0005","is_mandatory":true,"title":"Administrative distance for OSPF external routes (PAN-OS default 110)","provider":"go.mondoo.com/cnquery/providers/panos"},"ospfIntDist":{"name":"ospfIntDist","type":"\u0005","is_mandatory":true,"title":"Administrative distance for OSPF intra-area and inter-area routes (PAN-OS default 30)","provider":"go.mondoo.com/cnquery/providers/panos"},"ospfv3ExtDist":{"name":"ospfv3ExtDist","type":"\u0005","is_mandatory":true,"title":"Administrative distance for OSPFv3 external routes (PAN-OS default 110)","provider":"go.mondoo.com/cnquery/providers/panos"},"ospfv3IntDist":{"name":"ospfv3IntDist","type":"\u0005","is_mandatory":true,"title":"Administrative distance for OSPFv3 internal routes (PAN-OS default 30)","provider":"go.mondoo.com/cnquery/providers/panos"},"ripDist":{"name":"ripDist","type":"\u0005","is_mandatory":true,"title":"Administrative distance for RIP routes (PAN-OS default 120)","provider":"go.mondoo.com/cnquery/providers/panos"},"staticDist":{"name":"staticDist","type":"\u0005","is_mandatory":true,"title":"Administrative distance for static IPv4 routes (PAN-OS default 10)","provider":"go.mondoo.com/cnquery/providers/panos"},"staticIpv6Dist":{"name":"staticIpv6Dist","type":"\u0005","is_mandatory":true,"title":"Administrative distance for static IPv6 routes (PAN-OS default 10)","provider":"go.mondoo.com/cnquery/providers/panos"},"staticRoutes":{"name":"staticRoutes","type":"\u0019\u001bpanos.network.staticRoute","title":"Static routes configured on this virtual router","provider":"go.mondoo.com/cnquery/providers/panos"}},"title":"PAN-OS virtual router","desc":"A layer-3 routing instance on the firewall. Holds its member interfaces, the administrative distances that rank each routing protocol, ECMP settings, and navigable sub-collections for static routes and dynamic routing (BGP and OSPF). Traverse from here to audit routing, for example `panos.virtualRouters { name staticRoutes { destination nextHop } }`. Selected by `name`.","defaults":"name","provider":"go.mondoo.com/cnquery/providers/panos"},"panos.network.vlanInterface":{"id":"panos.network.vlanInterface","name":"panos.network.vlanInterface","fields":{"adjustTcpMss":{"name":"adjustTcpMss","type":"\u0004","is_mandatory":true,"title":"Whether TCP maximum segment size (MSS) clamping is applied to sessions on the interface","provider":"go.mondoo.com/cnquery/providers/panos"},"comment":{"name":"comment","type":"\u0007","is_mandatory":true,"title":"Free-text description configured on the interface","provider":"go.mondoo.com/cnquery/providers/panos"},"createDhcpDefaultRoute":{"name":"createDhcpDefaultRoute","type":"\u0004","is_mandatory":true,"title":"Whether a default route is installed from the DHCP-provided gateway","provider":"go.mondoo.com/cnquery/providers/panos"},"dhcpDefaultRouteMetric":{"name":"dhcpDefaultRouteMetric","type":"\u0005","is_mandatory":true,"title":"Administrative distance (metric) of the DHCP-installed default route","provider":"go.mondoo.com/cnquery/providers/panos"},"enableDhcp":{"name":"enableDhcp","type":"\u0004","is_mandatory":true,"title":"Whether the interface obtains its IPv4 address via DHCP client","provider":"go.mondoo.com/cnquery/providers/panos"},"ipAddresses":{"name":"ipAddresses","type":"\u0019\u000f","is_mandatory":true,"title":"Active IP addresses bound to the interface at runtime, from operational data","provider":"go.mondoo.com/cnquery/providers/panos"},"ipv4MssAdjust":{"name":"ipv4MssAdjust","type":"\u0005","is_mandatory":true,"title":"Bytes subtracted from the IPv4 MTU to compute the clamped TCP MSS","provider":"go.mondoo.com/cnquery/providers/panos"},"ipv6MssAdjust":{"name":"ipv6MssAdjust","type":"\u0005","is_mandatory":true,"title":"Bytes subtracted from the IPv6 MTU to compute the clamped TCP MSS","provider":"go.mondoo.com/cnquery/providers/panos"},"macAddress":{"name":"macAddress","type":"\u0007","is_mandatory":true,"title":"MAC address of the interface, from operational data","provider":"go.mondoo.com/cnquery/providers/panos"},"managementProfile":{"name":"managementProfile","type":"\u0007","is_mandatory":true,"title":"Interface management profile controlling which services (ping, SSH, HTTPS, SNMP) are permitted on the interface addresses","provider":"go.mondoo.com/cnquery/providers/panos"},"mtu":{"name":"mtu","type":"\u0005","is_mandatory":true,"title":"Maximum transmission unit in bytes","provider":"go.mondoo.com/cnquery/providers/panos"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Interface name (e.g., \"vlan.100\")","provider":"go.mondoo.com/cnquery/providers/panos"},"netflowProfile":{"name":"netflowProfile","type":"\u0007","is_mandatory":true,"title":"NetFlow server profile the interface exports flow records to","provider":"go.mondoo.com/cnquery/providers/panos"},"staticIps":{"name":"staticIps","type":"\u0019\u000f","is_mandatory":true,"title":"Static IP addresses configured on the interface, in bare or CIDR notation","provider":"go.mondoo.com/cnquery/providers/panos"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Operational link status from \"show interface all\"","desc":"One of \"up\", \"down\", or \"unknown\". \"unknown\" is reported when no matching hardware entry is found in the operational data.","provider":"go.mondoo.com/cnquery/providers/panos"},"subinterfaceIndex":{"name":"subinterfaceIndex","type":"\u0005","is_mandatory":true,"title":"Subinterface index parsed from the interface name (e.g., 100 from \"vlan.100\"); 0 when the name has no numeric suffix","provider":"go.mondoo.com/cnquery/providers/panos"},"zone":{"name":"zone","type":"\u0007","is_mandatory":true,"title":"Security zone the interface is assigned to, from operational data","provider":"go.mondoo.com/cnquery/providers/panos"}},"title":"PAN-OS VLAN interface","desc":"A logical VLAN interface (for example vlan.100) providing a layer-3 gateway for a VLAN. Exposes its static and DHCP addressing, management profile, MTU, and live operational status, zone, and active addresses. Selected by `name`.","defaults":"name subinterfaceIndex status","provider":"go.mondoo.com/cnquery/providers/panos"},"panos.network.zone":{"id":"panos.network.zone","name":"panos.network.zone","fields":{"deviceExcludeAcls":{"name":"deviceExcludeAcls","type":"\u0019\u0007","is_mandatory":true,"title":"Subnets excluded from device identification (PAN-OS 10.0+)","provider":"go.mondoo.com/cnquery/providers/panos"},"deviceIncludeAcls":{"name":"deviceIncludeAcls","type":"\u0019\u0007","is_mandatory":true,"title":"Subnets included in device identification (PAN-OS 10.0+)","provider":"go.mondoo.com/cnquery/providers/panos"},"enableDeviceIdentification":{"name":"enableDeviceIdentification","type":"\u0004","is_mandatory":true,"title":"Whether device identification is enabled for the zone (PAN-OS 10.0+)","provider":"go.mondoo.com/cnquery/providers/panos"},"enablePacketBufferProtection":{"name":"enablePacketBufferProtection","type":"\u0004","is_mandatory":true,"title":"Whether packet-buffer protection is enabled for the zone (PAN-OS 8.0+)","provider":"go.mondoo.com/cnquery/providers/panos"},"enableUserId":{"name":"enableUserId","type":"\u0004","is_mandatory":true,"title":"Whether User-ID IP-to-user mapping is enabled for the zone","provider":"go.mondoo.com/cnquery/providers/panos"},"excludeAcls":{"name":"excludeAcls","type":"\u0019\u0007","is_mandatory":true,"title":"Subnets excluded from User-ID mapping for the zone","provider":"go.mondoo.com/cnquery/providers/panos"},"includeAcls":{"name":"includeAcls","type":"\u0019\u0007","is_mandatory":true,"title":"Subnets included in User-ID mapping for the zone; empty means all subnets in the zone are included","provider":"go.mondoo.com/cnquery/providers/panos"},"interfaces":{"name":"interfaces","type":"\u0019\u0007","is_mandatory":true,"title":"Interfaces assigned to this zone","provider":"go.mondoo.com/cnquery/providers/panos"},"logSetting":{"name":"logSetting","type":"\u0007","is_mandatory":true,"title":"Log forwarding profile applied to zone-protection logs for the zone","provider":"go.mondoo.com/cnquery/providers/panos"},"mode":{"name":"mode","type":"\u0007","is_mandatory":true,"title":"Zone type determining how its interfaces process traffic","desc":"One of \"layer2\", \"layer3\", \"virtual-wire\", \"tap\", \"external\" (inter-vsys traffic, multi-vsys firewalls), or \"tunnel\" (PAN-OS 8.0+).","provider":"go.mondoo.com/cnquery/providers/panos"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Zone name","provider":"go.mondoo.com/cnquery/providers/panos"},"zoneProfile":{"name":"zoneProfile","type":"\u0007","is_mandatory":true,"title":"Zone-protection profile name; empty when none is attached, which leaves the zone without flood, reconnaissance, and packet-based-attack protection","provider":"go.mondoo.com/cnquery/providers/panos"}},"title":"PAN-OS network security zone","desc":"A security zone grouping one or more interfaces into a trust boundary that security, NAT, and decryption policy reference as source and destination. Exposes the member interfaces, the attached zone-protection profile, and whether User-ID, packet-buffer protection, and device identification are enabled. Useful for finding zones missing a protection profile, for example `panos.zones.where(zoneProfile == \"\")`. Selected by `name`.","defaults":"name mode","provider":"go.mondoo.com/cnquery/providers/panos"},"panos.pbf":{"id":"panos.pbf","fields":{"rule":{"name":"rule","type":"\u001bpanos.pbf.rule","title":"PAN-OS policy-based forwarding rule","desc":"A single rule in the policy-based-forwarding (PBF) rulebase that overrides the routing table for matching traffic, steering it to a specific virtual system, egress interface, or next hop. The `action` decides whether matching traffic is forwarded, sent to another virtual system, discarded, or exempted from PBF, and the `forward*` fields describe the forwarding target and its path monitoring. Rules are order-sensitive (first match wins). Select one directly by name, for example `panos.pbf.rule(\"vpn-steering\")`.","provider":"go.mondoo.com/cnquery/providers/panos","is_implicit_resource":true}},"is_extension":true},"panos.pbf.rule":{"id":"panos.pbf.rule","name":"panos.pbf.rule","fields":{"action":{"name":"action","type":"\u0007","is_mandatory":true,"title":"Forwarding action for matching traffic","desc":"One of forward (send out an egress interface or next hop), forward-to-vsys (hand off to another virtual system, named by forwardVsys), discard (drop the traffic), or no-pbf (exempt the traffic from PBF and use the normal routing table).","provider":"go.mondoo.com/cnquery/providers/panos"},"applications":{"name":"applications","type":"\u0019\u0007","is_mandatory":true,"title":"Applications the rule matches","provider":"go.mondoo.com/cnquery/providers/panos"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Description","provider":"go.mondoo.com/cnquery/providers/panos"},"destinationAddresses":{"name":"destinationAddresses","type":"\u0019\u0007","is_mandatory":true,"title":"Destination addresses the rule matches","desc":"Address objects, address groups, or literal IPs/subnets. Empty or \"any\" matches all destinations.","provider":"go.mondoo.com/cnquery/providers/panos"},"disabled":{"name":"disabled","type":"\u0004","is_mandatory":true,"title":"Whether the rule is disabled","provider":"go.mondoo.com/cnquery/providers/panos"},"enableEnforceSymmetricReturn":{"name":"enableEnforceSymmetricReturn","type":"\u0004","is_mandatory":true,"title":"Whether symmetric return is enforced for matching traffic","desc":"When true, return traffic is forced back through the same interface it arrived on, using symmetricReturnAddresses as next hops.","provider":"go.mondoo.com/cnquery/providers/panos"},"forwardEgressInterface":{"name":"forwardEgressInterface","type":"\u0007","is_mandatory":true,"title":"Egress interface when action is forward","provider":"go.mondoo.com/cnquery/providers/panos"},"forwardMonitorDisableIfUnreachable":{"name":"forwardMonitorDisableIfUnreachable","type":"\u0004","is_mandatory":true,"title":"Whether the rule is disabled when the monitored path is unreachable","desc":"When true and monitoring fails, PBF stops overriding routing for this rule so traffic falls back to the routing table.","provider":"go.mondoo.com/cnquery/providers/panos"},"forwardMonitorIpAddress":{"name":"forwardMonitorIpAddress","type":"\u0007","is_mandatory":true,"title":"IP address pinged to verify the forwarding path is reachable","provider":"go.mondoo.com/cnquery/providers/panos"},"forwardMonitorProfile":{"name":"forwardMonitorProfile","type":"\u0007","is_mandatory":true,"title":"Path-monitoring profile applied to the forwarding next hop","provider":"go.mondoo.com/cnquery/providers/panos"},"forwardNextHopType":{"name":"forwardNextHopType","type":"\u0007","is_mandatory":true,"title":"Next-hop type for the forwarding action","desc":"Either ip-address or fqdn (fqdn requires PAN-OS 9.0+). Empty when no next hop is set and traffic exits directly on forwardEgressInterface.","provider":"go.mondoo.com/cnquery/providers/panos"},"forwardNextHopValue":{"name":"forwardNextHopValue","type":"\u0007","is_mandatory":true,"title":"Next-hop value, interpreted per forwardNextHopType (an IP address or FQDN)","provider":"go.mondoo.com/cnquery/providers/panos"},"forwardVsys":{"name":"forwardVsys","type":"\u0007","is_mandatory":true,"title":"Target virtual system when action is forward-to-vsys","provider":"go.mondoo.com/cnquery/providers/panos"},"fromType":{"name":"fromType","type":"\u0007","is_mandatory":true,"title":"Source match type","desc":"Either zone (match by source security zone) or interface (match by ingress interface). fromValues is interpreted per this field.","provider":"go.mondoo.com/cnquery/providers/panos"},"fromValues":{"name":"fromValues","type":"\u0019\u0007","is_mandatory":true,"title":"Source zone or ingress interface names the rule matches, per fromType","provider":"go.mondoo.com/cnquery/providers/panos"},"groupTag":{"name":"groupTag","type":"\u0007","is_mandatory":true,"title":"Group tag used to visually group rules in the management UI","desc":"Available in PAN-OS 9.0+.","provider":"go.mondoo.com/cnquery/providers/panos"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Rule name","provider":"go.mondoo.com/cnquery/providers/panos"},"negateDestination":{"name":"negateDestination","type":"\u0004","is_mandatory":true,"title":"Whether the destination-address match is negated","provider":"go.mondoo.com/cnquery/providers/panos"},"negateSource":{"name":"negateSource","type":"\u0004","is_mandatory":true,"title":"Whether the source-address match is negated","provider":"go.mondoo.com/cnquery/providers/panos"},"schedule":{"name":"schedule","type":"\u0007","is_mandatory":true,"title":"Schedule constraining when the rule is active","desc":"Name of a schedule object, or empty when the rule is always active.","provider":"go.mondoo.com/cnquery/providers/panos"},"services":{"name":"services","type":"\u0019\u0007","is_mandatory":true,"title":"Services (ports) the rule matches","provider":"go.mondoo.com/cnquery/providers/panos"},"sourceAddresses":{"name":"sourceAddresses","type":"\u0019\u0007","is_mandatory":true,"title":"Source addresses the rule matches","desc":"Address objects, address groups, or literal IPs/subnets. Empty or \"any\" matches all sources.","provider":"go.mondoo.com/cnquery/providers/panos"},"sourceUsers":{"name":"sourceUsers","type":"\u0019\u0007","is_mandatory":true,"title":"Source users or user groups the rule matches","provider":"go.mondoo.com/cnquery/providers/panos"},"symmetricReturnAddresses":{"name":"symmetricReturnAddresses","type":"\u0019\u0007","is_mandatory":true,"title":"Next-hop addresses used to enforce symmetric return","provider":"go.mondoo.com/cnquery/providers/panos"},"tags":{"name":"tags","type":"\u0019\u0007","is_mandatory":true,"title":"Tags associated with this rule","provider":"go.mondoo.com/cnquery/providers/panos"},"uuid":{"name":"uuid","type":"\u0007","is_mandatory":true,"title":"Rule UUID","desc":"Stable identifier assigned by PAN-OS 9.0+. Empty on older versions.","provider":"go.mondoo.com/cnquery/providers/panos"}},"init":{"args":[{"name":"name","type":"\u0007"}]},"title":"PAN-OS policy-based forwarding rule","desc":"A single rule in the policy-based-forwarding (PBF) rulebase that overrides the routing table for matching traffic, steering it to a specific virtual system, egress interface, or next hop. The `action` decides whether matching traffic is forwarded, sent to another virtual system, discarded, or exempted from PBF, and the `forward*` fields describe the forwarding target and its path monitoring. Rules are order-sensitive (first match wins). Select one directly by name, for example `panos.pbf.rule(\"vpn-steering\")`.","defaults":"name action","provider":"go.mondoo.com/cnquery/providers/panos"},"panos.security":{"id":"panos.security","fields":{"rule":{"name":"rule","type":"\u001bpanos.security.rule","title":"PAN-OS security policy rule","desc":"A single rule in the security rulebase, matching traffic by zone, address, user, application, service, and URL category, then applying an action and a set of security profiles. The rulebase is order-sensitive (first match wins), so the collection preserves configured order. Central to firewall posture: audits look for overly permissive matches (any/any with allow), disabled logging, or allow rules with no threat-inspection profiles attached. Selected by `name`.","provider":"go.mondoo.com/cnquery/providers/panos","is_implicit_resource":true}},"is_extension":true},"panos.security.rule":{"id":"panos.security.rule","name":"panos.security.rule","fields":{"action":{"name":"action","type":"\u0007","is_mandatory":true,"title":"Action applied to matching traffic","desc":"One of \"allow\" (permit), \"deny\" (block using the application's default deny action), \"drop\" (silently discard with no notification), \"reset-client\" (send TCP RST or ICMP unreachable to the client), \"reset-server\" (send reset to the server), or \"reset-both\" (send reset to both ends).","provider":"go.mondoo.com/cnquery/providers/panos"},"applications":{"name":"applications","type":"\u0019\u0007","is_mandatory":true,"title":"Applications the rule matches (\"any\" matches all App-IDs)","provider":"go.mondoo.com/cnquery/providers/panos"},"categories":{"name":"categories","type":"\u0019\u0007","is_mandatory":true,"title":"URL categories the rule matches (\"any\" matches all categories)","provider":"go.mondoo.com/cnquery/providers/panos"},"dataFilteringProfile":{"name":"dataFilteringProfile","type":"\u0007","is_mandatory":true,"title":"Data filtering security profile applied to matching sessions for DLP-style content control","provider":"go.mondoo.com/cnquery/providers/panos"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Rule description","provider":"go.mondoo.com/cnquery/providers/panos"},"destinationAddresses":{"name":"destinationAddresses","type":"\u0019\u0007","is_mandatory":true,"title":"Destination addresses the rule matches (\"any\" matches all)","provider":"go.mondoo.com/cnquery/providers/panos"},"destinationZones":{"name":"destinationZones","type":"\u0019\u0007","is_mandatory":true,"title":"Destination zones the rule matches (\"any\" matches all zones)","provider":"go.mondoo.com/cnquery/providers/panos"},"disabled":{"name":"disabled","type":"\u0004","is_mandatory":true,"title":"Whether the rule is disabled and skipped during matching","provider":"go.mondoo.com/cnquery/providers/panos"},"fileBlockingProfile":{"name":"fileBlockingProfile","type":"\u0007","is_mandatory":true,"title":"File blocking security profile applied to matching sessions","provider":"go.mondoo.com/cnquery/providers/panos"},"groupTag":{"name":"groupTag","type":"\u0007","is_mandatory":true,"title":"Group tag used to visually group rules in the rulebase (PAN-OS 9.0+)","provider":"go.mondoo.com/cnquery/providers/panos"},"hipProfiles":{"name":"hipProfiles","type":"\u0019\u0007","is_mandatory":true,"title":"Host Information Profile (HIP) profiles the rule matches for GlobalProtect endpoint posture","provider":"go.mondoo.com/cnquery/providers/panos"},"logEnd":{"name":"logEnd","type":"\u0004","is_mandatory":true,"title":"Whether a traffic log is written at session end","provider":"go.mondoo.com/cnquery/providers/panos"},"logSetting":{"name":"logSetting","type":"\u0007","is_mandatory":true,"title":"Log forwarding profile applied to matching sessions; empty means matching traffic is not forwarded to external logging","provider":"go.mondoo.com/cnquery/providers/panos"},"logStart":{"name":"logStart","type":"\u0004","is_mandatory":true,"title":"Whether a traffic log is written at session start","provider":"go.mondoo.com/cnquery/providers/panos"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Rule name","provider":"go.mondoo.com/cnquery/providers/panos"},"negateDestination":{"name":"negateDestination","type":"\u0004","is_mandatory":true,"title":"Whether the destination address match is negated (matches everything except destinationAddresses)","provider":"go.mondoo.com/cnquery/providers/panos"},"negateSource":{"name":"negateSource","type":"\u0004","is_mandatory":true,"title":"Whether the source address match is negated (matches everything except sourceAddresses)","provider":"go.mondoo.com/cnquery/providers/panos"},"profileGroup":{"name":"profileGroup","type":"\u0007","is_mandatory":true,"title":"Security profile group name applied to matching sessions","desc":"When set, the group supplies the threat-inspection profiles; when empty, individual profile fields below are used instead.","provider":"go.mondoo.com/cnquery/providers/panos"},"schedule":{"name":"schedule","type":"\u0007","is_mandatory":true,"title":"Schedule object constraining the days and times the rule is active; empty means always active","provider":"go.mondoo.com/cnquery/providers/panos"},"services":{"name":"services","type":"\u0019\u0007","is_mandatory":true,"title":"Services the rule matches","desc":"Service objects, service groups, \"application-default\" (the standard ports for the matched App-IDs), or \"any\" (all ports).","provider":"go.mondoo.com/cnquery/providers/panos"},"sourceAddresses":{"name":"sourceAddresses","type":"\u0019\u0007","is_mandatory":true,"title":"Source addresses the rule matches (\"any\" matches all)","provider":"go.mondoo.com/cnquery/providers/panos"},"sourceUsers":{"name":"sourceUsers","type":"\u0019\u0007","is_mandatory":true,"title":"Source users or user groups the rule matches (\"any\" matches all, \"known-user\" any authenticated user, \"unknown\" unauthenticated)","provider":"go.mondoo.com/cnquery/providers/panos"},"sourceZones":{"name":"sourceZones","type":"\u0019\u0007","is_mandatory":true,"title":"Source zones the rule matches (\"any\" matches all zones)","provider":"go.mondoo.com/cnquery/providers/panos"},"spywareProfile":{"name":"spywareProfile","type":"\u0007","is_mandatory":true,"title":"Anti-spyware security profile applied to matching sessions; empty means no anti-spyware inspection unless profileGroup is set","provider":"go.mondoo.com/cnquery/providers/panos"},"tags":{"name":"tags","type":"\u0019\u0007","is_mandatory":true,"title":"Tags applied to this rule","provider":"go.mondoo.com/cnquery/providers/panos"},"type":{"name":"type","type":"\u0007","is_mandatory":true,"title":"Rule type controlling which zone combinations it matches","desc":"One of \"universal\" (default; matches both intrazone and interzone traffic), \"interzone\" (matches only traffic between different zones), or \"intrazone\" (matches only traffic within the same zone).","provider":"go.mondoo.com/cnquery/providers/panos"},"urlFilteringProfile":{"name":"urlFilteringProfile","type":"\u0007","is_mandatory":true,"title":"URL filtering security profile applied to matching sessions","provider":"go.mondoo.com/cnquery/providers/panos"},"uuid":{"name":"uuid","type":"\u0007","is_mandatory":true,"title":"Rule UUID, a stable identifier assigned by PAN-OS 9.0+; empty on older versions","provider":"go.mondoo.com/cnquery/providers/panos"},"virusProfile":{"name":"virusProfile","type":"\u0007","is_mandatory":true,"title":"Antivirus security profile applied to matching sessions; empty means no antivirus inspection unless profileGroup is set","provider":"go.mondoo.com/cnquery/providers/panos"},"vulnerabilityProfile":{"name":"vulnerabilityProfile","type":"\u0007","is_mandatory":true,"title":"Vulnerability protection security profile applied to matching sessions; empty means no vulnerability inspection unless profileGroup is set","provider":"go.mondoo.com/cnquery/providers/panos"},"wildFireAnalysisProfile":{"name":"wildFireAnalysisProfile","type":"\u0007","is_mandatory":true,"title":"WildFire analysis security profile controlling which files are submitted for cloud sandboxing","provider":"go.mondoo.com/cnquery/providers/panos"}},"title":"PAN-OS security policy rule","desc":"A single rule in the security rulebase, matching traffic by zone, address, user, application, service, and URL category, then applying an action and a set of security profiles. The rulebase is order-sensitive (first match wins), so the collection preserves configured order. Central to firewall posture: audits look for overly permissive matches (any/any with allow), disabled logging, or allow rules with no threat-inspection profiles attached. Selected by `name`.","defaults":"name action disabled","provider":"go.mondoo.com/cnquery/providers/panos"},"panos.service":{"id":"panos.service","name":"panos.service","fields":{"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Description","provider":"go.mondoo.com/cnquery/providers/panos"},"destinationPort":{"name":"destinationPort","type":"\u0007","is_mandatory":true,"title":"Destination port(s): single port, comma-separated list, or range","provider":"go.mondoo.com/cnquery/providers/panos"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Service name","provider":"go.mondoo.com/cnquery/providers/panos"},"overrideHalfClosedTimeout":{"name":"overrideHalfClosedTimeout","type":"\u0005","is_mandatory":true,"title":"Overridden half-closed TCP session timeout in seconds","desc":"Time a TCP session lingers after one FIN. TCP services only; applies when overrideSessionTimeout is true. PAN-OS 8.1+.","provider":"go.mondoo.com/cnquery/providers/panos"},"overrideSessionTimeout":{"name":"overrideSessionTimeout","type":"\u0004","is_mandatory":true,"title":"Whether this service overrides the protocol's default session timeouts","desc":"When false, the fields below are unused and the global timeouts apply. Available in PAN-OS 8.1+.","provider":"go.mondoo.com/cnquery/providers/panos"},"overrideTimeWaitTimeout":{"name":"overrideTimeWaitTimeout","type":"\u0005","is_mandatory":true,"title":"Overridden TIME-WAIT TCP session timeout in seconds","desc":"Time a TCP session lingers after both FINs. TCP services only; applies when overrideSessionTimeout is true. PAN-OS 8.1+.","provider":"go.mondoo.com/cnquery/providers/panos"},"overrideTimeout":{"name":"overrideTimeout","type":"\u0005","is_mandatory":true,"title":"Overridden session (idle) timeout in seconds","desc":"Applies only when overrideSessionTimeout is true. PAN-OS 8.1+.","provider":"go.mondoo.com/cnquery/providers/panos"},"protocol":{"name":"protocol","type":"\u0007","is_mandatory":true,"title":"Layer-4 protocol","desc":"One of tcp, udp, or sctp (SCTP requires PAN-OS 8.1+).","provider":"go.mondoo.com/cnquery/providers/panos"},"sourcePort":{"name":"sourcePort","type":"\u0007","is_mandatory":true,"title":"Source port(s): single port, comma-separated list, or range","desc":"Empty when the service matches any source port, which is the common case.","provider":"go.mondoo.com/cnquery/providers/panos"},"tags":{"name":"tags","type":"\u0019\u0007","is_mandatory":true,"title":"Tags associated with this service","provider":"go.mondoo.com/cnquery/providers/panos"}},"init":{"args":[{"name":"name","type":"\u0007"}]},"title":"PAN-OS service object","desc":"A named Layer-4 service (protocol plus source and destination port ranges) referenced by security, NAT, and policy-based-forwarding rules. May optionally override the protocol's default session timeouts. Select one directly by name, for example `panos.service(\"service-https\")`. The port fields are free-form strings holding a single port, a comma-separated list, or a range (e.g., \"443\", \"80,443\", \"1024-65535\").","defaults":"name protocol destinationPort","provider":"go.mondoo.com/cnquery/providers/panos"},"panos.serviceGroup":{"id":"panos.serviceGroup","name":"panos.serviceGroup","fields":{"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Group name","provider":"go.mondoo.com/cnquery/providers/panos"},"services":{"name":"services","type":"\u0019\u0007","is_mandatory":true,"title":"Member names: service objects or nested service groups","provider":"go.mondoo.com/cnquery/providers/panos"},"tags":{"name":"tags","type":"\u0019\u0007","is_mandatory":true,"title":"Tags associated with this group","provider":"go.mondoo.com/cnquery/providers/panos"}},"init":{"args":[{"name":"name","type":"\u0007"}]},"title":"PAN-OS service group","desc":"A named group of service objects referenced by policy as a single unit. Select one directly by name, for example `panos.serviceGroup(\"web-services\")`. The `services` field lists the member names, which may be service objects or other nested service groups.","defaults":"name","provider":"go.mondoo.com/cnquery/providers/panos"},"panos.system":{"id":"panos.system","name":"panos.system","fields":{"appVersion":{"name":"appVersion","type":"\u0007","is_mandatory":true,"title":"Application content (App-ID) version installed on the device","desc":"The App-ID content database version, for example \"8721-8125\". Combined with threat and antivirus versions this shows how current the device's dynamic content is.","provider":"go.mondoo.com/cnquery/providers/panos"},"avVersion":{"name":"avVersion","type":"\u0007","is_mandatory":true,"title":"Antivirus content version installed on the device","provider":"go.mondoo.com/cnquery/providers/panos"},"defaultGateway":{"name":"defaultGateway","type":"\u0007","is_mandatory":true,"title":"Default gateway of the management interface","provider":"go.mondoo.com/cnquery/providers/panos"},"family":{"name":"family","type":"\u0007","is_mandatory":true,"title":"Device family","desc":"Coarse device family string reported by PAN-OS, for example \"vm\", \"3000\", or \"5200\". Overlaps platformFamily on many platforms.","provider":"go.mondoo.com/cnquery/providers/panos"},"hostname":{"name":"hostname","type":"\u0007","is_mandatory":true,"title":"Device hostname","provider":"go.mondoo.com/cnquery/providers/panos"},"ipAddress":{"name":"ipAddress","type":"\u0007","is_mandatory":true,"title":"IP address of the management interface","provider":"go.mondoo.com/cnquery/providers/panos"},"isFipsMode":{"name":"isFipsMode","type":"\u0004","is_mandatory":true,"title":"Whether the device is running in FIPS-CC mode","desc":"True when FIPS-CC mode is enabled, the combined FIPS 140-2 and Common Criteria operating mode that enforces stricter cryptographic requirements and disables non-compliant algorithms. Often required by compliance baselines.","provider":"go.mondoo.com/cnquery/providers/panos"},"isVm":{"name":"isVm","type":"\u0004","is_mandatory":true,"title":"Whether the device is a virtual machine","desc":"True when the platform family is \"vm\" or \"pc\", or the model begins with \"PA-VM\", indicating a virtualized rather than hardware appliance.","provider":"go.mondoo.com/cnquery/providers/panos"},"logdbVersion":{"name":"logdbVersion","type":"\u0007","is_mandatory":true,"title":"Log database schema version","provider":"go.mondoo.com/cnquery/providers/panos"},"macAddress":{"name":"macAddress","type":"\u0007","is_mandatory":true,"title":"MAC address of the management interface","provider":"go.mondoo.com/cnquery/providers/panos"},"model":{"name":"model","type":"\u0007","is_mandatory":true,"title":"Device model (e.g., \"PA-VM\", \"PA-3220\")","provider":"go.mondoo.com/cnquery/providers/panos"},"multiVsys":{"name":"multiVsys","type":"\u0007","is_mandatory":true,"title":"Multi-virtual-system (multi-vsys) capability","desc":"Whether the device operates multiple virtual systems, reported as \"on\" or \"off\".","provider":"go.mondoo.com/cnquery/providers/panos"},"netmask":{"name":"netmask","type":"\u0007","is_mandatory":true,"title":"Netmask of the management interface","provider":"go.mondoo.com/cnquery/providers/panos"},"operationalMode":{"name":"operationalMode","type":"\u0007","is_mandatory":true,"title":"Operational mode","desc":"The device operating mode, for example \"normal\" or \"fips-cc\".","provider":"go.mondoo.com/cnquery/providers/panos"},"platformFamily":{"name":"platformFamily","type":"\u0007","is_mandatory":true,"title":"Platform family","desc":"Hardware or virtual platform family reported by the device, for example \"vm\" (VM-Series), \"pc\" (cloud/container), \"m\" (M-Series appliance), or a numeric hardware series such as \"3000\". Used to derive isVm.","provider":"go.mondoo.com/cnquery/providers/panos"},"serial":{"name":"serial","type":"\u0007","is_mandatory":true,"title":"Device serial number","provider":"go.mondoo.com/cnquery/providers/panos"},"threatVersion":{"name":"threatVersion","type":"\u0007","is_mandatory":true,"title":"Threat and vulnerability content version installed on the device","desc":"The Threat Prevention content database version (App-ID plus threat signatures), for example \"8721-8125\". Empty when no Threat Prevention content is installed.","provider":"go.mondoo.com/cnquery/providers/panos"},"time":{"name":"time","type":"\u0007","is_mandatory":true,"title":"Current device clock time","provider":"go.mondoo.com/cnquery/providers/panos"},"uptime":{"name":"uptime","type":"\u0007","is_mandatory":true,"title":"Device uptime as reported by the device (e.g., \"12 days, 3:14:07\")","provider":"go.mondoo.com/cnquery/providers/panos"},"version":{"name":"version","type":"\u0007","is_mandatory":true,"title":"PAN-OS software version","desc":"The running PAN-OS release, for example \"10.2.4\". Compare against known-fixed releases to find devices missing security patches.","provider":"go.mondoo.com/cnquery/providers/panos"},"wildfireVersion":{"name":"wildfireVersion","type":"\u0007","is_mandatory":true,"title":"WildFire content version installed on the device","provider":"go.mondoo.com/cnquery/providers/panos"}},"title":"PAN-OS system information","desc":"Identity, versioning, and management-plane state of the connected device, derived from the show-system-info operational command. Includes the software and content (application, antivirus, threat, WildFire) versions used to audit patch level, plus mode flags for virtual-machine and FIPS-CC operation. The parsed equivalent of the deprecated `systemInfo` map.","defaults":"hostname model version","provider":"go.mondoo.com/cnquery/providers/panos"}}}