Palo Alto Networks · OpenAPI Overlay 1.0.0
API Evangelist conversational phrasing for Manage Cloud NGFW (V2) Manage NGFW V2 API
29 actions
29 updates
phrasing
extends
openapi/palo-alto-networks-managengfw-v2-api-openapi.yml
Generated by API Evangelist
Written by API Evangelist tooling for Palo Alto Networks's API. It is a proposal applied on top of the contract, not a document Palo Alto Networks publishes.
What the actions change
x-apievangelist-phrasing
Targets 29 · first 16 shown; the file carries all of them
$.info
$.paths['/v2/linkaccounts'].get
$.paths['/v2/linkaccounts'].post
$.paths['/v2/linkaccounts'].delete
$.paths['/v2/ngfirewalls'].get
$.paths['/v2/ngfirewalls'].post
$.paths['/v2/ngfirewalls/'].get
$.paths['/v2/ngfirewalls/'].post
$.paths['/v2/ngfirewalls/{firewall_id}'].get
$.paths['/v2/ngfirewalls/{firewall_id}'].delete
$.paths['/v2/ngfirewalls/{firewall_id}'].patch
$.paths['/v2/ngfirewalls/{firewall_id}/link'].post
$.paths['/v2/ngfirewalls/{firewall_id}/link'].delete
$.paths['/v2/ngfirewalls/{firewall_id}/logprofile'].get
$.paths['/v2/ngfirewalls/{firewall_id}/logprofile'].post
$.paths['/v2/ngfirewalls/{firewall_id}/rulestack'].post
OpenAPI Overlay
# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand.
overlay: 1.0.0
info:
title: API Evangelist conversational phrasing for Manage Cloud NGFW (V2) Manage NGFW V2 API
version: 1.0.0
extends: openapi/palo-alto-networks-managengfw-v2-api-openapi.yml
actions:
- target: $.info
update:
x-apievangelist-phrasing:
method: generated
generated: '2026-10-01'
generator: build-phrasing.py
label: Generated by API Evangelist
operations: 28
- target: $.paths['/v2/linkaccounts'].get
update:
x-apievangelist-phrasing:
intent: List linked AWS accounts for Cloud NGFW
effect: read
questions:
- Which AWS accounts are linked to my Cloud NGFW tenant?
- Can I page through linked accounts and get full descriptions of each one?
instructions:
- text: List every account linked to my Cloud NGFW tenant.
- text: Show up to {maxresults} linked accounts with full details.
slots:
maxresults: query.maxresults
method: generated
generated: '2026-09-26'
- target: $.paths['/v2/linkaccounts'].post
update:
x-apievangelist-phrasing:
intent: Link an AWS account to Cloud NGFW
effect: write
questions:
- How do I onboard a new AWS account into Cloud NGFW?
- Can I link an account using an AWS Marketplace token and pick its onboarding region?
instructions:
- text: Link AWS account {account} to Cloud NGFW.
slots:
account: requestBody.AccountId
- text: Onboard account {account} in {region} using marketplace token {token}.
slots:
account: requestBody.AccountId
region: requestBody.OnboardingRegion
token: requestBody.AWSMarketplaceToken
method: generated
generated: '2026-09-26'
- target: $.paths['/v2/linkaccounts'].delete
update:
x-apievangelist-phrasing:
intent: Unlink an AWS account from Cloud NGFW
effect: destructive
questions:
- Can I remove a linked AWS account from Cloud NGFW?
- What happens when I unlink an account that was onboarded for firewall management?
instructions:
- text: Unlink AWS account {account} from Cloud NGFW.
slots:
account: requestBody.AccountId
- text: Delete the link account entry for {account}.
slots:
account: requestBody.AccountId
method: generated
generated: '2026-09-26'
- target: $.paths['/v2/ngfirewalls'].get
update:
x-apievangelist-phrasing:
intent: List Cloud NGFW firewalls in a region
effect: read
questions:
- Which Cloud NGFW firewalls do I have running in a given AWS region?
- Can I filter my firewalls to those using a specific rulestack or global rulestack?
instructions:
- text: List all Cloud NGFW firewalls in {region}.
slots:
region: query.region
- text: Show firewalls in {region} that use rulestack {rulestack}.
slots:
region: query.region
rulestack: query.rulestackname
- text: Find firewalls in {region} attached to global rulestack {global_rulestack}.
slots:
region: query.region
global_rulestack: query.globalrulestackname
method: generated
generated: '2026-09-26'
- target: $.paths['/v2/ngfirewalls'].post
update:
x-apievangelist-phrasing:
intent: Create a Cloud NGFW firewall
effect: write
questions:
- How do I deploy a new Cloud NGFW firewall across availability zones?
- Can I turn on egress NAT and change protection when creating a firewall?
instructions:
- text: Create a Cloud NGFW firewall in {region} covering zones {zones}.
slots:
region: query.region
zones: requestBody.CustomerZoneIdList
- text: Create a firewall in {region} for zones {zones} using rulestack {rulestack}.
slots:
region: query.region
zones: requestBody.CustomerZoneIdList
rulestack: requestBody.RuleStackName
method: generated
generated: '2026-09-26'
- target: $.paths['/v2/ngfirewalls/'].get
update:
x-apievangelist-phrasing:
intent: List legacy V1 firewalls via the V2 endpoint
effect: read
questions:
- Can I still list my older V1-style firewalls through the V2 API?
- What does the v1 route flag do when listing legacy firewalls?
instructions:
- text: List my legacy V1 firewalls in {region} using the v1 route.
slots:
region: query.region
- text: Show V1 firewalls in {region} with v1route set to {v1route}.
slots:
region: query.region
v1route: query.v1route
method: generated
generated: '2026-09-26'
- target: $.paths['/v2/ngfirewalls/'].post
update:
x-apievangelist-phrasing:
intent: Create a legacy V1 firewall in a VPC
effect: write
questions:
- What does it take to create a V1-style firewall tied to a VPC and subnet mappings?
- Which fields are required to create a legacy V1 firewall through the V2 endpoint?
instructions:
- text: Create V1 firewall {name} in VPC {vpc} for account {account}.
slots:
name: requestBody.FirewallName
vpc: requestBody.VpcId
account: requestBody.AccountId
- text: Create legacy firewall {name} in {region} with subnet mappings {subnets} and endpoint mode {mode}.
slots:
name: requestBody.FirewallName
region: query.region
subnets: requestBody.SubnetMappings
mode: requestBody.EndpointMode
method: generated
generated: '2026-09-26'
- target: $.paths['/v2/ngfirewalls/{firewall_id}'].get
update:
x-apievangelist-phrasing:
intent: Get a firewall by its ID
effect: read
questions:
- Can I look up a single Cloud NGFW firewall by its firewall ID?
- What details come back for one firewall when I fetch it by ID?
instructions:
- text: Get firewall {firewall_id} in {region}.
slots:
firewall_id: path.firewall_id
region: query.region
- text: Show the configuration of firewall ID {firewall_id}.
slots:
firewall_id: path.firewall_id
method: generated
generated: '2026-09-26'
- target: $.paths['/v2/ngfirewalls/{firewall_id}'].delete
update:
x-apievangelist-phrasing:
intent: Delete a firewall by its ID
effect: destructive
questions:
- What is the call to tear down a Cloud NGFW firewall using its firewall ID?
- Is deleting a firewall by ID permanent?
instructions:
- text: Delete firewall {firewall_id} in {region}.
slots:
firewall_id: path.firewall_id
region: query.region
- text: Remove the Cloud NGFW firewall with ID {firewall_id}.
slots:
firewall_id: path.firewall_id
method: generated
generated: '2026-09-26'
- target: $.paths['/v2/ngfirewalls/{firewall_id}'].patch
update:
x-apievangelist-phrasing:
intent: Update a firewall's settings by ID
effect: write
questions:
- Can I change a firewall's allow-listed accounts, endpoints or egress NAT after it is created?
- Why does updating a firewall require an update token and deployment update token?
instructions:
- text: Update firewall {firewall_id} to use availability zones {zones}.
slots:
firewall_id: path.firewall_id
zones: requestBody.CustomerZoneIdList
- text: Set the GWLB TCP idle timeout on firewall {firewall_id} to {timeout} seconds.
slots:
firewall_id: path.firewall_id
timeout: requestBody.GwlbTcpIdleTimeout
- text: Allow accounts {accounts} on firewall {firewall_id} in {region}.
slots:
accounts: requestBody.AllowListAccounts
firewall_id: path.firewall_id
region: query.region
method: generated
generated: '2026-09-26'
- target: $.paths['/v2/ngfirewalls/{firewall_id}/link'].post
update:
x-apievangelist-phrasing:
intent: Associate a link with a firewall
effect: write
questions:
- Can I attach a link ID to an existing firewall?
- Can I associate a cross-account link with a firewall I already deployed?
instructions:
- text: Associate link {link} with firewall {firewall_id}.
slots:
link: requestBody.LinkId
firewall_id: path.firewall_id
- text: Attach link {link} to firewall {firewall_id} in {region}.
slots:
link: requestBody.LinkId
firewall_id: path.firewall_id
region: query.region
method: generated
generated: '2026-09-26'
- target: $.paths['/v2/ngfirewalls/{firewall_id}/link'].delete
update:
x-apievangelist-phrasing:
intent: Disassociate a link from a firewall
effect: destructive
questions:
- How do I detach a link from a firewall without deleting the firewall?
- What do I need to disassociate a link ID from a firewall?
instructions:
- text: Disassociate link {link} from firewall {firewall_id}.
slots:
link: requestBody.LinkId
firewall_id: path.firewall_id
- text: Detach link {link} from firewall {firewall_id} in {region}.
slots:
link: requestBody.LinkId
firewall_id: path.firewall_id
region: query.region
method: generated
generated: '2026-09-26'
- target: $.paths['/v2/ngfirewalls/{firewall_id}/logprofile'].get
update:
x-apievangelist-phrasing:
intent: Read a firewall's log profile by ID
effect: read
questions:
- Where is my firewall sending its logs, looked up by firewall ID?
- Can I see whether CloudWatch metrics and advanced threat logs are on for a firewall ID?
instructions:
- text: Show the log profile for firewall {firewall_id}.
slots:
firewall_id: path.firewall_id
- text: Read the logging configuration of firewall {firewall_id} in {region}.
slots:
firewall_id: path.firewall_id
region: query.region
method: generated
generated: '2026-09-26'
- target: $.paths['/v2/ngfirewalls/{firewall_id}/logprofile'].post
update:
x-apievangelist-phrasing:
intent: Update a firewall's log profile by ID
effect: write
questions:
- How do I change log destinations for a firewall I reference by ID?
- Can I enable advanced threat logging on a firewall by its ID?
instructions:
- text: Update the log config of firewall {firewall_id} to {log_config}.
slots:
firewall_id: path.firewall_id
log_config: requestBody.LogConfig
- text: Turn advanced threat logging {setting} on firewall ID {firewall_id}.
slots:
setting: requestBody.AdvancedThreatLog
firewall_id: path.firewall_id
method: generated
generated: '2026-09-26'
- target: $.paths['/v2/ngfirewalls/{firewall_id}/rulestack'].post
update:
x-apievangelist-phrasing:
intent: Attach a rulestack to a firewall by ID
effect: write
questions:
- How do I associate a rulestack with a firewall using the firewall ID?
- Can I attach a rulestack owned by another account to my firewall ID?
instructions:
- text: Associate rulestack {rulestack} with firewall {firewall_id}.
slots:
rulestack: requestBody.RuleStackName
firewall_id: path.firewall_id
- text: Attach rulestack {rulestack} from account {account} to firewall ID {firewall_id}.
slots:
rulestack: requestBody.RuleStackName
account: requestBody.AccountId
firewall_id: path.firewall_id
method: generated
generated: '2026-09-26'
- target: $.paths['/v2/ngfirewalls/{firewall_id}/rulestack'].delete
update:
x-apievangelist-phrasing:
intent: Detach a rulestack from a firewall by ID
effect: destructive
questions:
- Can I disassociate a rulestack from a firewall by firewall ID?
- What happens to a firewall's policy when I detach its rulestack?
instructions:
- text: Disassociate the rulestack from firewall {firewall_id}.
slots:
firewall_id: path.firewall_id
- text: Detach rulestack {rulestack} from firewall ID {firewall_id}.
slots:
rulestack: requestBody.RuleStackName
firewall_id: path.firewall_id
method: generated
generated: '2026-09-26'
- target: $.paths['/v2/ngfirewalls/{firewall_name}'].get
update:
x-apievangelist-phrasing:
intent: Get a firewall by its name
effect: read
questions:
- Can I look up a firewall by its name instead of its firewall ID?
- What does the firewall-by-name lookup return through the V1 route?
instructions:
- text: Get firewall {firewall_name} in {region} using the v1 route.
slots:
firewall_name: path.firewall_name
region: query.region
- text: Look up a named firewall in {region} with v1route {v1route}.
slots:
region: query.region
v1route: query.v1route
method: generated
generated: '2026-10-01'
- target: $.paths['/v2/ngfirewalls/{firewall_name}'].delete
update:
x-apievangelist-phrasing:
intent: Delete a firewall by its name
effect: destructive
questions:
- Is there a way to delete a legacy firewall using its name rather than its ID?
- Does the V1 route let me remove a firewall by name?
instructions:
- text: Delete firewall {firewall_name} in {region} via the v1 route.
slots:
firewall_name: path.firewall_name
region: query.region
- text: Remove a firewall by name in {region} with v1route {v1route}.
slots:
region: query.region
v1route: query.v1route
method: generated
generated: '2026-10-01'
- target: $.paths['/v2/ngfirewalls/{firewall_name}/contentversion'].put
update:
x-apievangelist-phrasing:
intent: Update a firewall's App-ID content version
effect: write
questions:
- How do I upgrade the App-ID content version on a firewall?
- Can I turn on automatic App-ID content upgrades for a firewall?
instructions:
- text: Set firewall {firewall_name} to App-ID version {version}.
slots:
firewall_name: path.firewall_name
version: requestBody.AppIdVersion
- text: 'Enable automatic App-ID upgrades on firewall {name}: {auto}.'
slots:
name: requestBody.FirewallName
auto: requestBody.AutomaticUpgradeAppIdVersion
method: generated
generated: '2026-10-01'
- target: $.paths['/v2/ngfirewalls/{firewall_name}/description'].put
update:
x-apievangelist-phrasing:
intent: Change a firewall's description
effect: write
questions:
- Where do I change the description text on a firewall?
- Can I update only a firewall's description without touching other settings?
instructions:
- text: Change the description of firewall {firewall_name} to {description}.
slots:
firewall_name: path.firewall_name
description: requestBody.Description
- text: Set firewall {name} description to {description} in {region}.
slots:
name: requestBody.FirewallName
description: requestBody.Description
region: query.region
method: generated
generated: '2026-10-01'
- target: $.paths['/v2/ngfirewalls/{firewall_name}/features'].put
update:
x-apievangelist-phrasing:
intent: Configure feature flags on a firewall
effect: write
questions:
- Which firewall features can I switch on or off by firewall name?
- How do I configure optional features on an existing firewall?
instructions:
- text: Configure features {features} on firewall {firewall_name}.
slots:
features: requestBody.Features
firewall_name: path.firewall_name
- text: Update the feature settings of firewall {name} in {region}.
slots:
name: requestBody.FirewallName
region: query.region
method: generated
generated: '2026-10-01'
- target: $.paths['/v2/ngfirewalls/{firewall_name}/logprofile'].get
update:
x-apievangelist-phrasing:
intent: Read a firewall's log profile by name
effect: read
questions:
- Where does a firewall I know by name send its logs?
- Can I read a legacy firewall's log profile using its account ID and name?
instructions:
- text: Show the log profile for firewall {firewall_name} in account {account}.
slots:
firewall_name: path.firewall_name
account: query.accountid
- text: Read logging settings of the firewall named {name} in {region}.
slots:
name: requestBody.FirewallName
region: query.region
method: generated
generated: '2026-10-01'
- target: $.paths['/v2/ngfirewalls/{firewall_name}/logprofile'].post
update:
x-apievangelist-phrasing:
intent: Update a firewall's log profile by name
effect: write
questions:
- Can I set log destinations for a firewall referenced by name?
- Can I choose a CloudWatch metric namespace for a legacy firewall's logs?
instructions:
- text: Send logs from firewall {firewall_name} to destinations {destinations}.
slots:
firewall_name: path.firewall_name
destinations: requestBody.LogDestinationConfigs
- text: Publish metrics for firewall {name} under CloudWatch namespace {namespace}.
slots:
name: requestBody.FirewallName
namespace: requestBody.CloudWatchMetricNamespace
method: generated
generated: '2026-10-01'
- target: $.paths['/v2/ngfirewalls/{firewall_name}/rulestack'].post
update:
x-apievangelist-phrasing:
intent: Attach a rulestack to a firewall by name
effect: write
questions:
- How do I associate a rulestack with a legacy firewall I know by name?
- Can the V1 route attach a rulestack to a named firewall?
instructions:
- text: Associate rulestack {rulestack} with the firewall named {firewall_name}.
slots:
rulestack: requestBody.RuleStackName
firewall_name: path.firewall_name
- text: Attach rulestack {rulestack} to firewall {name} in {region} via the v1 route.
slots:
rulestack: requestBody.RuleStackName
name: requestBody.FirewallName
region: query.region
method: generated
generated: '2026-10-01'
- target: $.paths['/v2/ngfirewalls/{firewall_name}/subnets'].post
update:
x-apievangelist-phrasing:
intent: Change a firewall's subnet mappings
effect: write
questions:
- Can I add or remove subnets on a legacy firewall?
- Can I enable multi-VPC on a firewall while updating its subnet mappings?
instructions:
- text: Associate subnets {subnets} with firewall {firewall_name}.
slots:
subnets: requestBody.AssociateSubnetMappings
firewall_name: path.firewall_name
- text: Disassociate subnets {subnets} from firewall {name}.
slots:
subnets: requestBody.DisassociateSubnetMappings
name: requestBody.FirewallName
method: generated
generated: '2026-10-01'
- target: $.paths['/v2/ngfirewalls/{firewall_name}/tags'].get
update:
x-apievangelist-phrasing:
intent: List tags on a firewall
effect: read
questions:
- What tags are applied to a given firewall?
- Can I see a named firewall's tags for a specific account?
instructions:
- text: List the tags on firewall {firewall_name}.
slots:
firewall_name: path.firewall_name
- text: Show tags for firewall {name} in account {account}.
slots:
name: requestBody.FirewallName
account: requestBody.AccountId
method: generated
generated: '2026-10-01'
- target: $.paths['/v2/ngfirewalls/{firewall_name}/tags'].post
update:
x-apievangelist-phrasing:
intent: Add tags to a firewall
effect: write
questions:
- What's the way to tag a firewall for cost tracking or ownership?
- Can I add several tags to a firewall in one call?
instructions:
- text: Add tags {tags} to firewall {firewall_name}.
slots:
tags: requestBody.Tags
firewall_name: path.firewall_name
- text: Tag firewall {name} in {region} with {tags}.
slots:
name: requestBody.FirewallName
region: query.region
tags: requestBody.Tags
method: generated
generated: '2026-10-01'
- target: $.paths['/v2/ngfirewalls/{firewall_name}/tags'].delete
update:
x-apievangelist-phrasing:
intent: Remove tags from a firewall
effect: destructive
questions:
- How do I strip specific tag keys off a firewall?
- Can I remove tags from a firewall without deleting the firewall itself?
instructions:
- text: Remove tag keys {keys} from firewall {firewall_name}.
slots:
keys: requestBody.TagKeys
firewall_name: path.firewall_name
- text: Untag firewall {name} in {region}, dropping keys {keys}.
slots:
name: requestBody.FirewallName
region: query.region
keys: requestBody.TagKeys
method: generated
generated: '2026-10-01'