# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand. overlay: 1.0.0 info: title: API Evangelist conversational phrasing for Network Services IPsec Tunnels API version: 1.0.0 extends: openapi/palo-alto-networks-ip-sec-tunnels-api-openapi.yml actions: - target: $.info update: x-apievangelist-phrasing: method: generated generated: '2026-10-01' generator: build-phrasing.py label: Generated by API Evangelist operations: 10 - target: $.paths['/ipsec-tunnels'].get update: x-apievangelist-phrasing: intent: List Prisma Access IPSec tunnels effect: read questions: - Which IPSec VPN tunnels connect my branches to Prisma Access? - Can I page through Prisma Access IPSec tunnel configurations by folder? instructions: - text: List Prisma Access IPSec tunnels. - text: Show Prisma Access IPSec tunnels in folder {folder}. slots: folder: query.folder method: generated generated: '2026-10-01' - target: $.paths['/ipsec-tunnels'].post update: x-apievangelist-phrasing: intent: Create a Prisma Access IPSec tunnel effect: write questions: - How do I add an IPSec tunnel to the Prisma Access candidate configuration? - What IKE gateway settings does a new Prisma Access tunnel need? instructions: - text: Create Prisma Access candidate IPSec tunnel {name} with auto key {auto_key}. slots: name: requestBody.name auto_key: requestBody.auto_key - text: Add candidate-config tunnel {name} with auto key {auto_key} and tunnel monitor {tunnel_monitor}. slots: name: requestBody.name auto_key: requestBody.auto_key tunnel_monitor: requestBody.tunnel_monitor method: generated generated: '2026-10-01' - target: $.paths['/ipsec-tunnels/{id}'].get update: x-apievangelist-phrasing: intent: Get a Prisma Access IPSec tunnel effect: read questions: - What is the configuration of one Prisma Access IPSec tunnel in the candidate config? - Can I check which IKE gateway a Prisma Access tunnel uses? instructions: - text: Show Prisma Access IPSec tunnel {id}. slots: id: path.id - text: Get the candidate configuration for Prisma Access tunnel {id}. slots: id: path.id method: generated generated: '2026-10-01' - target: $.paths['/ipsec-tunnels/{id}'].put update: x-apievangelist-phrasing: intent: Update a Prisma Access IPSec tunnel effect: write questions: - How do I change a Prisma Access IPSec tunnel in the candidate configuration? - Can I adjust tunnel monitoring on a Prisma Access tunnel? instructions: - text: Update Prisma Access candidate tunnel {id} named {name} with auto key {auto_key}. slots: id: path.id name: requestBody.name auto_key: requestBody.auto_key - text: Change tunnel monitoring on Prisma Access tunnel {id} to {tunnel_monitor}. slots: id: path.id tunnel_monitor: requestBody.tunnel_monitor method: generated generated: '2026-10-01' - target: $.paths['/ipsec-tunnels/{id}'].delete update: x-apievangelist-phrasing: intent: Delete a Prisma Access IPSec tunnel effect: destructive questions: - How do I remove an IPSec tunnel from the Prisma Access candidate configuration? - Does deleting a Prisma Access tunnel cut the branch off before a push? instructions: - text: Delete Prisma Access IPSec tunnel {id} from the candidate config. slots: id: path.id - text: Remove candidate-config tunnel {id} from Prisma Access. slots: id: path.id method: generated generated: '2026-10-01' - target: $.paths['/sse/config/v1/ipsec-tunnels'].get update: x-apievangelist-phrasing: intent: List IPSec tunnels via the SSE config API effect: read questions: - Which IPSec tunnels exist in a folder through the SSE config v1 endpoint? - Can I find an SSE config IPSec tunnel by name? instructions: - text: List SSE config IPSec tunnels in folder {folder}. slots: folder: query.folder - text: Find the SSE IPSec tunnel named {name} in folder {folder}. slots: name: query.name folder: query.folder method: generated generated: '2026-10-01' - target: $.paths['/sse/config/v1/ipsec-tunnels'].post update: x-apievangelist-phrasing: intent: Create an IPSec tunnel via the SSE config API effect: write questions: - How do I create an IPSec tunnel through the SSE config v1 API? - Can I turn on GRE encapsulation when creating an SSE IPSec tunnel? instructions: - text: Create SSE config IPSec tunnel {name} in folder {folder} with auto key {auto_key}. slots: name: requestBody.name folder: query.folder auto_key: requestBody.auto_key - text: Add SSE IPSec tunnel {name} in folder {folder} using auto key {auto_key} and GRE encapsulation {enable_gre_encapsulation}. slots: name: requestBody.name folder: query.folder auto_key: requestBody.auto_key enable_gre_encapsulation: requestBody.enable_gre_encapsulation method: generated generated: '2026-10-01' - target: $.paths['/sse/config/v1/ipsec-tunnels/{id}'].get update: x-apievangelist-phrasing: intent: Get an IPSec tunnel via the SSE config API effect: read questions: - What is configured on a specific SSE config IPSec tunnel? - Can I read one SSE IPSec tunnel's IKE settings by ID and folder? instructions: - text: Show SSE config IPSec tunnel {id} in folder {folder}. slots: id: path.id folder: query.folder - text: Fetch SSE IPSec tunnel {id} from folder {folder} and show its tunnel monitor. slots: id: path.id folder: query.folder method: generated generated: '2026-10-01' - target: $.paths['/sse/config/v1/ipsec-tunnels/{id}'].put update: x-apievangelist-phrasing: intent: Edit an IPSec tunnel via the SSE config API effect: write questions: - How do I change the auto key settings on an SSE config IPSec tunnel? - Can I enable anti-replay on an existing SSE IPSec tunnel? instructions: - text: Update SSE config IPSec tunnel {id} named {name} with auto key {auto_key}. slots: id: path.id name: requestBody.name auto_key: requestBody.auto_key - text: Set anti-replay to {anti_replay} on SSE IPSec tunnel {id}. slots: id: path.id anti_replay: requestBody.anti_replay method: generated generated: '2026-10-01' - target: $.paths['/sse/config/v1/ipsec-tunnels/{id}'].delete update: x-apievangelist-phrasing: intent: Delete an IPSec tunnel via the SSE config API effect: destructive questions: - How do I delete an IPSec tunnel with the SSE config v1 endpoint? - What breaks if I remove an SSE config IPSec tunnel? instructions: - text: Delete SSE config IPSec tunnel {id}. slots: id: path.id - text: Remove SSE IPSec tunnel {id}. slots: id: path.id method: generated generated: '2026-10-01'