# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand. overlay: 1.0.0 info: title: API Evangelist conversational phrasing for Palo Alto Networks IPSec Crypto Profiles API version: 1.0.0 extends: openapi/palo-alto-networks-ipsec-crypto-profiles-api-openapi.yml actions: - target: $.info update: x-apievangelist-phrasing: method: generated generated: '2026-10-01' generator: build-phrasing.py label: Generated by API Evangelist operations: 16 - target: $.paths['/v1/ipsec-crypto-profiles'].get update: x-apievangelist-phrasing: intent: Check status of an IPSec crypto profile job effect: read questions: - Did my IPSec crypto profile create or delete request succeed? - Can I check the result of an IPSec profile change using its request UUID? instructions: - text: Check the status of IPSec crypto profile request {id}. slots: id: query.id - text: Verify whether profile change job {id} finished. slots: id: query.id method: generated generated: '2026-09-26' - target: $.paths['/v1/ipsec-crypto-profiles'].put update: x-apievangelist-phrasing: intent: Modify an IPSec crypto profile (v1 async) effect: write questions: - How do I change the lifetime on an IPSec crypto profile in a multi-tenant Panorama setup? - Can I edit a v1 IPSec crypto profile for a specific sub-tenant? instructions: - text: Modify v1 IPSec crypto profile {name} to lifetime {lifetime}. slots: name: requestBody.name lifetime: requestBody.lifetime - text: Edit IPSec profile {name} for sub-tenant {SubTenantName} with DH group {dh_group} and lifetime {lifetime}. slots: name: requestBody.name SubTenantName: query.SubTenantName dh_group: requestBody.dh_group lifetime: requestBody.lifetime method: generated generated: '2026-09-26' - target: $.paths['/v1/ipsec-crypto-profiles'].post update: x-apievangelist-phrasing: intent: Create an IPSec crypto profile (v1 async) effect: write questions: - Can I create an IPSec crypto profile for a Panorama sub-tenant? - What do I need to submit a new v1 IPSec crypto profile with an ESP setting? instructions: - text: Submit a new v1 IPSec crypto profile {name} with lifetime {lifetime}. slots: name: requestBody.name lifetime: requestBody.lifetime - text: Create v1 profile {name} for sub-tenant {SubTenantName} using ESP {esp}, lifetime {lifetime}. slots: name: requestBody.name SubTenantName: query.SubTenantName esp: requestBody.esp lifetime: requestBody.lifetime method: generated generated: '2026-09-26' - target: $.paths['/v1/ipsec-crypto-profiles'].delete update: x-apievangelist-phrasing: intent: Delete an IPSec crypto profile by name (v1) effect: destructive questions: - Can I delete a v1 IPSec crypto profile just by name? - How is an IPSec profile removed for one Panorama sub-tenant? instructions: - text: Delete v1 IPSec crypto profile {name}. slots: name: query.name - text: Remove IPSec profile {name} from sub-tenant {SubTenantName}. slots: name: query.name SubTenantName: query.SubTenantName method: generated generated: '2026-09-26' - target: $.paths['/v1/ipsec-crypto-profiles-read'].get update: x-apievangelist-phrasing: intent: Fetch results of an IPSec profile read job effect: read questions: - Where do I pick up the IPSec profile configurations after submitting a read request? - Can I read back the created IPSec crypto profile configs by request UUID? instructions: - text: Get the IPSec crypto profile configurations for read request {id}. slots: id: query.id - text: Fetch read job {id} results for IPSec profiles. slots: id: query.id method: generated generated: '2026-09-26' - target: $.paths['/v1/ipsec-crypto-profiles-read'].post update: x-apievangelist-phrasing: intent: Request a read of IPSec crypto profiles effect: read questions: - How do I start an async read of specific IPSec crypto profiles? - Can I ask for only certain IPSec profiles by name to be read back? instructions: - text: Start a read request for IPSec profiles {ipsec_crypto_profiles_names}. slots: ipsec_crypto_profiles_names: requestBody.ipsec_crypto_profiles_names - text: Queue a read of IPSec crypto profiles for sub-tenant {SubTenantName}. slots: SubTenantName: query.SubTenantName method: generated generated: '2026-09-26' - target: $.paths['/ipsec-crypto-profiles'].get update: x-apievangelist-phrasing: intent: List IPsec crypto profiles in a folder effect: read questions: - Which IPsec crypto profiles are defined in a given folder or snippet? - Can I page through IPsec crypto profiles in Strata Cloud Manager config? instructions: - text: List IPsec crypto profiles in folder {folder}. slots: folder: query.folder - text: Find IPsec crypto profiles named {name} on device {device}. slots: name: query.name device: query.device method: generated generated: '2026-09-26' - target: $.paths['/ipsec-crypto-profiles'].post update: x-apievangelist-phrasing: intent: Create an IPsec crypto profile effect: write questions: - How do I add an IPsec crypto profile with additional key exchange for post-quantum tunnels? - What fields does a new IPsec crypto profile need in the config API? instructions: - text: Create IPsec crypto profile {name} with lifetime {lifetime}. slots: name: requestBody.name lifetime: requestBody.lifetime - text: Add IPsec profile {name}, DH group {dh_group}, lifetime {lifetime} and AKE {ake}. slots: name: requestBody.name dh_group: requestBody.dh_group lifetime: requestBody.lifetime ake: requestBody.ake method: generated generated: '2026-09-26' - target: $.paths['/ipsec-crypto-profiles/{id}'].get update: x-apievangelist-phrasing: intent: Get an IPsec crypto profile by ID effect: read questions: - What encryption settings does one IPsec crypto profile use? - Can I look up an IPsec crypto profile by its UUID? instructions: - text: Get IPsec crypto profile {id}. slots: id: path.id - text: Show the settings of IPsec profile {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/ipsec-crypto-profiles/{id}'].put update: x-apievangelist-phrasing: intent: Update an IPsec crypto profile by ID effect: write questions: - Can I change the DH group on an IPsec crypto profile by UUID? - How would I shorten the lifetime of an existing IPsec profile? instructions: - text: Update IPsec crypto profile {id} to lifetime {lifetime}, name {name}. slots: id: path.id lifetime: requestBody.lifetime name: requestBody.name - text: Set DH group {dh_group} on IPsec profile {id}. slots: dh_group: requestBody.dh_group id: path.id method: generated generated: '2026-09-26' - target: $.paths['/ipsec-crypto-profiles/{id}'].delete update: x-apievangelist-phrasing: intent: Delete an IPsec crypto profile by ID effect: destructive questions: - Can I remove an IPsec crypto profile using its UUID? - What's the way to delete an unused IPsec profile from config? instructions: - text: Delete IPsec crypto profile {id}. slots: id: path.id - text: Remove IPsec profile with UUID {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/sse/config/v1/ipsec-crypto-profiles'].get update: x-apievangelist-phrasing: intent: List IPSec crypto profiles effect: read questions: - Which IPSec crypto profiles exist in a Prisma Access folder? - Can I find an IPSec crypto profile by name? instructions: - text: List IPSec crypto profiles in folder {folder} through the SSE config v1 path. slots: folder: query.folder - text: Find IPSec crypto profile {name} in folder {folder}. slots: name: query.name folder: query.folder method: generated generated: '2026-10-01' - target: $.paths['/sse/config/v1/ipsec-crypto-profiles'].post update: x-apievangelist-phrasing: intent: Create an IPSec crypto profile effect: write questions: - How do I create an IPSec crypto profile for a VPN tunnel? - Can I choose the Diffie-Hellman group for a new IPSec crypto profile? instructions: - text: Create IPSec crypto profile {name} with lifetime {lifetime} in folder {folder}. slots: name: requestBody.name lifetime: requestBody.lifetime folder: query.folder - text: Create IPSec profile {name} in {folder} using DH group {dh_group} and lifetime {lifetime}. slots: name: requestBody.name folder: query.folder dh_group: requestBody.dh_group lifetime: requestBody.lifetime method: generated generated: '2026-10-01' - target: $.paths['/sse/config/v1/ipsec-crypto-profiles/{id}'].get update: x-apievangelist-phrasing: intent: Get an IPSec crypto profile effect: read questions: - What lifetime and DH group does a particular IPSec crypto profile use? - Can I fetch one IPSec crypto profile by id? instructions: - text: Show IPSec crypto profile {id} in folder {folder}. slots: id: path.id folder: query.folder - text: Get the settings of IPSec crypto profile {id} from folder {folder}. slots: id: path.id folder: query.folder method: generated generated: '2026-10-01' - target: $.paths['/sse/config/v1/ipsec-crypto-profiles/{id}'].put update: x-apievangelist-phrasing: intent: Edit an IPSec crypto profile effect: write questions: - How do I change the key lifetime on an existing IPSec crypto profile? - Can I update the lifesize of an IPSec profile already in use? instructions: - text: Edit IPSec crypto profile {id} named {name} to lifetime {lifetime}. slots: id: path.id name: requestBody.name lifetime: requestBody.lifetime - text: Change existing IPSec profile {id} ({name}) to lifesize {lifesize} and lifetime {lifetime}. slots: id: path.id name: requestBody.name lifesize: requestBody.lifesize lifetime: requestBody.lifetime method: generated generated: '2026-10-01' - target: $.paths['/sse/config/v1/ipsec-crypto-profiles/{id}'].delete update: x-apievangelist-phrasing: intent: Delete an IPSec crypto profile effect: destructive questions: - How do I delete an IPSec crypto profile? - Can I remove an IPSec crypto profile no tunnel uses anymore? instructions: - text: Delete IPSec crypto profile {id} using the SSE config v1 endpoint. slots: id: path.id - text: Remove the unused IPSec crypto profile {id}. slots: id: path.id method: generated generated: '2026-10-01'