# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand. overlay: 1.0.0 info: title: API Evangelist conversational phrasing for Manage Cloud NGFW (V2) Manage NGFW V2 API version: 1.0.0 extends: openapi/palo-alto-networks-managengfw-v2-api-openapi.yml actions: - target: $.info update: x-apievangelist-phrasing: method: generated generated: '2026-10-01' generator: build-phrasing.py label: Generated by API Evangelist operations: 28 - target: $.paths['/v2/linkaccounts'].get update: x-apievangelist-phrasing: intent: List linked AWS accounts for Cloud NGFW effect: read questions: - Which AWS accounts are linked to my Cloud NGFW tenant? - Can I page through linked accounts and get full descriptions of each one? instructions: - text: List every account linked to my Cloud NGFW tenant. - text: Show up to {maxresults} linked accounts with full details. slots: maxresults: query.maxresults method: generated generated: '2026-09-26' - target: $.paths['/v2/linkaccounts'].post update: x-apievangelist-phrasing: intent: Link an AWS account to Cloud NGFW effect: write questions: - How do I onboard a new AWS account into Cloud NGFW? - Can I link an account using an AWS Marketplace token and pick its onboarding region? instructions: - text: Link AWS account {account} to Cloud NGFW. slots: account: requestBody.AccountId - text: Onboard account {account} in {region} using marketplace token {token}. slots: account: requestBody.AccountId region: requestBody.OnboardingRegion token: requestBody.AWSMarketplaceToken method: generated generated: '2026-09-26' - target: $.paths['/v2/linkaccounts'].delete update: x-apievangelist-phrasing: intent: Unlink an AWS account from Cloud NGFW effect: destructive questions: - Can I remove a linked AWS account from Cloud NGFW? - What happens when I unlink an account that was onboarded for firewall management? instructions: - text: Unlink AWS account {account} from Cloud NGFW. slots: account: requestBody.AccountId - text: Delete the link account entry for {account}. slots: account: requestBody.AccountId method: generated generated: '2026-09-26' - target: $.paths['/v2/ngfirewalls'].get update: x-apievangelist-phrasing: intent: List Cloud NGFW firewalls in a region effect: read questions: - Which Cloud NGFW firewalls do I have running in a given AWS region? - Can I filter my firewalls to those using a specific rulestack or global rulestack? instructions: - text: List all Cloud NGFW firewalls in {region}. slots: region: query.region - text: Show firewalls in {region} that use rulestack {rulestack}. slots: region: query.region rulestack: query.rulestackname - text: Find firewalls in {region} attached to global rulestack {global_rulestack}. slots: region: query.region global_rulestack: query.globalrulestackname method: generated generated: '2026-09-26' - target: $.paths['/v2/ngfirewalls'].post update: x-apievangelist-phrasing: intent: Create a Cloud NGFW firewall effect: write questions: - How do I deploy a new Cloud NGFW firewall across availability zones? - Can I turn on egress NAT and change protection when creating a firewall? instructions: - text: Create a Cloud NGFW firewall in {region} covering zones {zones}. slots: region: query.region zones: requestBody.CustomerZoneIdList - text: Create a firewall in {region} for zones {zones} using rulestack {rulestack}. slots: region: query.region zones: requestBody.CustomerZoneIdList rulestack: requestBody.RuleStackName method: generated generated: '2026-09-26' - target: $.paths['/v2/ngfirewalls/'].get update: x-apievangelist-phrasing: intent: List legacy V1 firewalls via the V2 endpoint effect: read questions: - Can I still list my older V1-style firewalls through the V2 API? - What does the v1 route flag do when listing legacy firewalls? instructions: - text: List my legacy V1 firewalls in {region} using the v1 route. slots: region: query.region - text: Show V1 firewalls in {region} with v1route set to {v1route}. slots: region: query.region v1route: query.v1route method: generated generated: '2026-09-26' - target: $.paths['/v2/ngfirewalls/'].post update: x-apievangelist-phrasing: intent: Create a legacy V1 firewall in a VPC effect: write questions: - What does it take to create a V1-style firewall tied to a VPC and subnet mappings? - Which fields are required to create a legacy V1 firewall through the V2 endpoint? instructions: - text: Create V1 firewall {name} in VPC {vpc} for account {account}. slots: name: requestBody.FirewallName vpc: requestBody.VpcId account: requestBody.AccountId - text: Create legacy firewall {name} in {region} with subnet mappings {subnets} and endpoint mode {mode}. slots: name: requestBody.FirewallName region: query.region subnets: requestBody.SubnetMappings mode: requestBody.EndpointMode method: generated generated: '2026-09-26' - target: $.paths['/v2/ngfirewalls/{firewall_id}'].get update: x-apievangelist-phrasing: intent: Get a firewall by its ID effect: read questions: - Can I look up a single Cloud NGFW firewall by its firewall ID? - What details come back for one firewall when I fetch it by ID? instructions: - text: Get firewall {firewall_id} in {region}. slots: firewall_id: path.firewall_id region: query.region - text: Show the configuration of firewall ID {firewall_id}. slots: firewall_id: path.firewall_id method: generated generated: '2026-09-26' - target: $.paths['/v2/ngfirewalls/{firewall_id}'].delete update: x-apievangelist-phrasing: intent: Delete a firewall by its ID effect: destructive questions: - What is the call to tear down a Cloud NGFW firewall using its firewall ID? - Is deleting a firewall by ID permanent? instructions: - text: Delete firewall {firewall_id} in {region}. slots: firewall_id: path.firewall_id region: query.region - text: Remove the Cloud NGFW firewall with ID {firewall_id}. slots: firewall_id: path.firewall_id method: generated generated: '2026-09-26' - target: $.paths['/v2/ngfirewalls/{firewall_id}'].patch update: x-apievangelist-phrasing: intent: Update a firewall's settings by ID effect: write questions: - Can I change a firewall's allow-listed accounts, endpoints or egress NAT after it is created? - Why does updating a firewall require an update token and deployment update token? instructions: - text: Update firewall {firewall_id} to use availability zones {zones}. slots: firewall_id: path.firewall_id zones: requestBody.CustomerZoneIdList - text: Set the GWLB TCP idle timeout on firewall {firewall_id} to {timeout} seconds. slots: firewall_id: path.firewall_id timeout: requestBody.GwlbTcpIdleTimeout - text: Allow accounts {accounts} on firewall {firewall_id} in {region}. slots: accounts: requestBody.AllowListAccounts firewall_id: path.firewall_id region: query.region method: generated generated: '2026-09-26' - target: $.paths['/v2/ngfirewalls/{firewall_id}/link'].post update: x-apievangelist-phrasing: intent: Associate a link with a firewall effect: write questions: - Can I attach a link ID to an existing firewall? - Can I associate a cross-account link with a firewall I already deployed? instructions: - text: Associate link {link} with firewall {firewall_id}. slots: link: requestBody.LinkId firewall_id: path.firewall_id - text: Attach link {link} to firewall {firewall_id} in {region}. slots: link: requestBody.LinkId firewall_id: path.firewall_id region: query.region method: generated generated: '2026-09-26' - target: $.paths['/v2/ngfirewalls/{firewall_id}/link'].delete update: x-apievangelist-phrasing: intent: Disassociate a link from a firewall effect: destructive questions: - How do I detach a link from a firewall without deleting the firewall? - What do I need to disassociate a link ID from a firewall? instructions: - text: Disassociate link {link} from firewall {firewall_id}. slots: link: requestBody.LinkId firewall_id: path.firewall_id - text: Detach link {link} from firewall {firewall_id} in {region}. slots: link: requestBody.LinkId firewall_id: path.firewall_id region: query.region method: generated generated: '2026-09-26' - target: $.paths['/v2/ngfirewalls/{firewall_id}/logprofile'].get update: x-apievangelist-phrasing: intent: Read a firewall's log profile by ID effect: read questions: - Where is my firewall sending its logs, looked up by firewall ID? - Can I see whether CloudWatch metrics and advanced threat logs are on for a firewall ID? instructions: - text: Show the log profile for firewall {firewall_id}. slots: firewall_id: path.firewall_id - text: Read the logging configuration of firewall {firewall_id} in {region}. slots: firewall_id: path.firewall_id region: query.region method: generated generated: '2026-09-26' - target: $.paths['/v2/ngfirewalls/{firewall_id}/logprofile'].post update: x-apievangelist-phrasing: intent: Update a firewall's log profile by ID effect: write questions: - How do I change log destinations for a firewall I reference by ID? - Can I enable advanced threat logging on a firewall by its ID? instructions: - text: Update the log config of firewall {firewall_id} to {log_config}. slots: firewall_id: path.firewall_id log_config: requestBody.LogConfig - text: Turn advanced threat logging {setting} on firewall ID {firewall_id}. slots: setting: requestBody.AdvancedThreatLog firewall_id: path.firewall_id method: generated generated: '2026-09-26' - target: $.paths['/v2/ngfirewalls/{firewall_id}/rulestack'].post update: x-apievangelist-phrasing: intent: Attach a rulestack to a firewall by ID effect: write questions: - How do I associate a rulestack with a firewall using the firewall ID? - Can I attach a rulestack owned by another account to my firewall ID? instructions: - text: Associate rulestack {rulestack} with firewall {firewall_id}. slots: rulestack: requestBody.RuleStackName firewall_id: path.firewall_id - text: Attach rulestack {rulestack} from account {account} to firewall ID {firewall_id}. slots: rulestack: requestBody.RuleStackName account: requestBody.AccountId firewall_id: path.firewall_id method: generated generated: '2026-09-26' - target: $.paths['/v2/ngfirewalls/{firewall_id}/rulestack'].delete update: x-apievangelist-phrasing: intent: Detach a rulestack from a firewall by ID effect: destructive questions: - Can I disassociate a rulestack from a firewall by firewall ID? - What happens to a firewall's policy when I detach its rulestack? instructions: - text: Disassociate the rulestack from firewall {firewall_id}. slots: firewall_id: path.firewall_id - text: Detach rulestack {rulestack} from firewall ID {firewall_id}. slots: rulestack: requestBody.RuleStackName firewall_id: path.firewall_id method: generated generated: '2026-09-26' - target: $.paths['/v2/ngfirewalls/{firewall_name}'].get update: x-apievangelist-phrasing: intent: Get a firewall by its name effect: read questions: - Can I look up a firewall by its name instead of its firewall ID? - What does the firewall-by-name lookup return through the V1 route? instructions: - text: Get firewall {firewall_name} in {region} using the v1 route. slots: firewall_name: path.firewall_name region: query.region - text: Look up a named firewall in {region} with v1route {v1route}. slots: region: query.region v1route: query.v1route method: generated generated: '2026-10-01' - target: $.paths['/v2/ngfirewalls/{firewall_name}'].delete update: x-apievangelist-phrasing: intent: Delete a firewall by its name effect: destructive questions: - Is there a way to delete a legacy firewall using its name rather than its ID? - Does the V1 route let me remove a firewall by name? instructions: - text: Delete firewall {firewall_name} in {region} via the v1 route. slots: firewall_name: path.firewall_name region: query.region - text: Remove a firewall by name in {region} with v1route {v1route}. slots: region: query.region v1route: query.v1route method: generated generated: '2026-10-01' - target: $.paths['/v2/ngfirewalls/{firewall_name}/contentversion'].put update: x-apievangelist-phrasing: intent: Update a firewall's App-ID content version effect: write questions: - How do I upgrade the App-ID content version on a firewall? - Can I turn on automatic App-ID content upgrades for a firewall? instructions: - text: Set firewall {firewall_name} to App-ID version {version}. slots: firewall_name: path.firewall_name version: requestBody.AppIdVersion - text: 'Enable automatic App-ID upgrades on firewall {name}: {auto}.' slots: name: requestBody.FirewallName auto: requestBody.AutomaticUpgradeAppIdVersion method: generated generated: '2026-10-01' - target: $.paths['/v2/ngfirewalls/{firewall_name}/description'].put update: x-apievangelist-phrasing: intent: Change a firewall's description effect: write questions: - Where do I change the description text on a firewall? - Can I update only a firewall's description without touching other settings? instructions: - text: Change the description of firewall {firewall_name} to {description}. slots: firewall_name: path.firewall_name description: requestBody.Description - text: Set firewall {name} description to {description} in {region}. slots: name: requestBody.FirewallName description: requestBody.Description region: query.region method: generated generated: '2026-10-01' - target: $.paths['/v2/ngfirewalls/{firewall_name}/features'].put update: x-apievangelist-phrasing: intent: Configure feature flags on a firewall effect: write questions: - Which firewall features can I switch on or off by firewall name? - How do I configure optional features on an existing firewall? instructions: - text: Configure features {features} on firewall {firewall_name}. slots: features: requestBody.Features firewall_name: path.firewall_name - text: Update the feature settings of firewall {name} in {region}. slots: name: requestBody.FirewallName region: query.region method: generated generated: '2026-10-01' - target: $.paths['/v2/ngfirewalls/{firewall_name}/logprofile'].get update: x-apievangelist-phrasing: intent: Read a firewall's log profile by name effect: read questions: - Where does a firewall I know by name send its logs? - Can I read a legacy firewall's log profile using its account ID and name? instructions: - text: Show the log profile for firewall {firewall_name} in account {account}. slots: firewall_name: path.firewall_name account: query.accountid - text: Read logging settings of the firewall named {name} in {region}. slots: name: requestBody.FirewallName region: query.region method: generated generated: '2026-10-01' - target: $.paths['/v2/ngfirewalls/{firewall_name}/logprofile'].post update: x-apievangelist-phrasing: intent: Update a firewall's log profile by name effect: write questions: - Can I set log destinations for a firewall referenced by name? - Can I choose a CloudWatch metric namespace for a legacy firewall's logs? instructions: - text: Send logs from firewall {firewall_name} to destinations {destinations}. slots: firewall_name: path.firewall_name destinations: requestBody.LogDestinationConfigs - text: Publish metrics for firewall {name} under CloudWatch namespace {namespace}. slots: name: requestBody.FirewallName namespace: requestBody.CloudWatchMetricNamespace method: generated generated: '2026-10-01' - target: $.paths['/v2/ngfirewalls/{firewall_name}/rulestack'].post update: x-apievangelist-phrasing: intent: Attach a rulestack to a firewall by name effect: write questions: - How do I associate a rulestack with a legacy firewall I know by name? - Can the V1 route attach a rulestack to a named firewall? instructions: - text: Associate rulestack {rulestack} with the firewall named {firewall_name}. slots: rulestack: requestBody.RuleStackName firewall_name: path.firewall_name - text: Attach rulestack {rulestack} to firewall {name} in {region} via the v1 route. slots: rulestack: requestBody.RuleStackName name: requestBody.FirewallName region: query.region method: generated generated: '2026-10-01' - target: $.paths['/v2/ngfirewalls/{firewall_name}/subnets'].post update: x-apievangelist-phrasing: intent: Change a firewall's subnet mappings effect: write questions: - Can I add or remove subnets on a legacy firewall? - Can I enable multi-VPC on a firewall while updating its subnet mappings? instructions: - text: Associate subnets {subnets} with firewall {firewall_name}. slots: subnets: requestBody.AssociateSubnetMappings firewall_name: path.firewall_name - text: Disassociate subnets {subnets} from firewall {name}. slots: subnets: requestBody.DisassociateSubnetMappings name: requestBody.FirewallName method: generated generated: '2026-10-01' - target: $.paths['/v2/ngfirewalls/{firewall_name}/tags'].get update: x-apievangelist-phrasing: intent: List tags on a firewall effect: read questions: - What tags are applied to a given firewall? - Can I see a named firewall's tags for a specific account? instructions: - text: List the tags on firewall {firewall_name}. slots: firewall_name: path.firewall_name - text: Show tags for firewall {name} in account {account}. slots: name: requestBody.FirewallName account: requestBody.AccountId method: generated generated: '2026-10-01' - target: $.paths['/v2/ngfirewalls/{firewall_name}/tags'].post update: x-apievangelist-phrasing: intent: Add tags to a firewall effect: write questions: - What's the way to tag a firewall for cost tracking or ownership? - Can I add several tags to a firewall in one call? instructions: - text: Add tags {tags} to firewall {firewall_name}. slots: tags: requestBody.Tags firewall_name: path.firewall_name - text: Tag firewall {name} in {region} with {tags}. slots: name: requestBody.FirewallName region: query.region tags: requestBody.Tags method: generated generated: '2026-10-01' - target: $.paths['/v2/ngfirewalls/{firewall_name}/tags'].delete update: x-apievangelist-phrasing: intent: Remove tags from a firewall effect: destructive questions: - How do I strip specific tag keys off a firewall? - Can I remove tags from a firewall without deleting the firewall itself? instructions: - text: Remove tag keys {keys} from firewall {firewall_name}. slots: keys: requestBody.TagKeys firewall_name: path.firewall_name - text: Untag firewall {name} in {region}, dropping keys {keys}. slots: name: requestBody.FirewallName region: query.region keys: requestBody.TagKeys method: generated generated: '2026-10-01'