> For the complete documentation index, see [llms.txt](https://nso-docs.cisco.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://nso-docs.cisco.com/neds/cisco-provided-neds/paloalto-panos_cli/readme-ned-settings.md).

# README-ned-settings

## NED settings details

***

This NED is equipped with a number of runtime configuration options "NED settings" allowing for customization by the end user. All options are configurable using the NSO API for NED settings. Most NED settings can be configured globally, per device profile or per device instance in the following locations:

global /ncs:devices/global-settings/ned-settings/paloalto-panos\_cli/ profile /ncs:devices/ncs:profiles/profile:/ned-settings/paloalto-panos\_cli/ device /ncs\:/device/devices/device:/ned-settings/paloalto-panos\_cli/

Profiles setting overrides global-settings and device settings override profile settings, hence the narrowest scope of the setting is used by the device.

If user changes a ned-setting, then user must reconnect to the device, i.e. disconnect and connect in order for the new setting to take effect.

From the NSO CLI the device instance NED settings for this NED are available under:

```
# config
# devices device dev-1 ned-settings paloalto-panos_cli

Press TAB to see all the NED settings.

```

## Table of contents

***

```
1. ned-settings paloalto-panos_cli
2. connection
3. proxy
4. logger
```

## 1. ned-settings paloalto-panos\_cli

***

Configure settings specific to the connection between NED and device.

```
- extended-parser <enum> (default auto)

  Make the NED enable extensions to ease the task of the NSO CLI command parser. A common
  problem with this parser is that it can easily get lost when trying to parse configuration not
  supported by the YANG model. In particular it is very sensitive for unsupported config that
  generates a mode switch.

  auto            - Uses turbo-mode when available, will use fastest availablemethod to load
                    data to NSO. If NSO doesn't support data-loading from CLI NED, robust-mode
                    is used.

  robust-mode     - The configuration dump is run through a pre-parser which is cleaning it from
                    all elements currently not supported in the YANG model (default).

  turbo-mode      - The NED executes the whole command parsing by itself, completely bypassing
                    the NSO CLI parser. The configuration dump is transferred to NSO using a
                    Maapi SetValues() call.

  turbo-xml-mode  - The NED executes the whole command parsing by itself, completely bypassing
                    the NSO CLI parser. The configuration dump is transferred to NSO in XML
                    format.


- commit-all-oper-command <string> (default )

  Commit command needed for having the changes pushed to firewall devices managed by Panorama.


- partial-sync <true|false> (default true)

  Enable/disable partial sync.


- commit-all-delay <NUM> (default 0)

  Delay in milliseconds before commit-all operation.
```

## 2. ned-settings paloalto-panos\_cli connection

***

Configure settings specific to the connection between NED and device.

```
- connection number-of-retries <uint8> (default 0)

  Configure max number of retries the NED will try to connect to the device before giving up.
  Default 0.


- connection time-between-retry <uint8> (default 1)

  Configure the time in seconds the NED will wait between each connect retry. Default 1s.


- connection connector <WORD>

  Change the default connector, e.g. 'ned-connector-default.json'.


- connection terminal width <uint32> (default 100000)


- connection terminal height <uint32> (default 24)


- connection ssh client <enum>

  Configure the SSH client to use. Relevant only when using the NED with NSO 5.6 or later.

  ganymed  - The legacy SSH client. Used on all older versions of NSO.

  sshj     - The new SSH client with support for the latest crypto features. This is the default
             when using the NED on NSO 5.6 or later.


- connection ssh host-key known-hosts-file <string>

  Path to openssh formatted 'known_hosts' file containing valid host keys.


- connection ssh host-key public-key-file <string>

  Path to openssh formatted public (.pub) host key file.


- connection ssh auth-key private-key-file <string>

  Path to openssh formatted private key file.


- connection ssh keep-alive-interval <seconds> (default 0)

  Configure SSH client keep alive interval in seconds, default 0 (i.e. no keep-alive). The
  keep-alive is implemented in the client by sending an ssh 'ignore' message on the given
  interval.
```

## 3. ned-settings paloalto-panos\_cli proxy

***

Configure NED to access device via a proxy.

```
- proxy remote-connection <enum>

  Connection type between proxy and device.

  ssh            - Start a new ssh client on proxy and connect to device (i.e. will launch
                   interactive shell on proxy).

  telnet         - Start a new telnet client on proxy and connect to device (i.e. will launch
                   interactive shell on proxy).

  serial         - Connect through a terminal server to device.

  ssh-direct     - Direct forward to device using ned local ssh client (i.e. without shell on
                   proxy).

  telnet-direct  - Direct forward to device using ned local telnet client (i.e. without shell on
                   proxy).


- proxy auth-key private-key-file <string>

  Path to openssh formatted private key file for doing public key auth to device behind proxy.


- proxy host-key-validation <true|false> (default false)

  Set this to true to force host-key validation of device behind proxy.


- proxy remote-address <union>

  Address of host behind the proxy.


- proxy remote-port <uint16>

  Port of host behind the proxy.


- proxy remote-name <string>

  User name on the device behind the proxy.


- proxy remote-password <string>

  Password on the device behind the proxy.


- proxy proxy-prompt <string>

  Prompt pattern on the proxy host.


- proxy remote-ssh-args <string>

  Additional arguments used to establish proxy connection.
```

## 4. ned-settings paloalto-panos\_cli logger

***

Settings for controlling logs generated.

```
- logger level <enum> (default info)

  Set level of logging.

  error    - error.

  info     - info.

  verbose  - verbose.

  debug    - debug.


- logger java <true|false> (default true)

  Toggle logs to be added to ncs-java-vm.log.
```


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://nso-docs.cisco.com/neds/cisco-provided-neds/paloalto-panos_cli/readme-ned-settings.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
