Agent skill

Pyats Asa Firewall

by automateyournetwork in automateyournetwork/netclaw

Cisco ASA firewall operations via pyATS — VPN sessions, failover state, interfaces, routing, service policies, resource usage, AnyConnect monitoring.

Apache-2.0Auto-check passedDevOps & Cloud

Install Pyats Asa Firewall

skills CLI
$ npx skills add automateyournetwork/netclaw --skill pyats-asa-firewall -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install automateyournetwork/netclaw pyats-asa-firewall --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/automateyournetwork/netclaw.git skills-src && mkdir -p .claude/skills && cp -r skills-src/workspace/skills/pyats-asa-firewall .claude/skills/pyats-asa-firewall && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
pyats-asa-firewall
GitHub stars
676
Token cost
~2.8k tokens
SKILL.md length
694 words
Files
1
Skills in repo
120
Repo updated
First seen
Licence
Apache-2.0

At a glance

Cisco ASA firewall operations via pyATS — VPN sessions, failover state, interfaces, routing, service policies, resource usage, AnyConnect monitoring.

  • Works in 5 steps: ASA Health Check → VPN Monitoring Dashboard → ASA Failover Verification → …
  • Checking ASA failover status
  • SKILL.md covers Testbed Requirements, How to Call, Commands and Workflows, plus 4 more sections
  • Calls python3; needs NETCLAW_PASSWORD

What it does

Pyats Asa Firewall is an agent skill from automateyournetwork/netclaw. Cisco ASA firewall operations via pyATS — VPN sessions, failover state, interfaces, routing, service policies, resource usage, AnyConnect monitoring. Use when checking ASA failover status, monitoring VPN sessions, auditing ASA security, or troubleshooting AnyConnect connectivity.

Its SKILL.md is about 2.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Backup and disaster recovery. The repository describes itself as: An AI agent that claws through your network. The licence is Apache-2.0.

When your agent uses it

  • Checking ASA failover status
  • Monitoring VPN sessions
  • Auditing ASA security
  • Troubleshooting AnyConnect connectivity

Example prompts

  • “/pyats-asa-firewall”

Requirements

  • Python 3

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. ASA Health Check
  2. VPN Monitoring Dashboard
  3. ASA Failover Verification
  4. ASA Security Audit
  5. VPN Troubleshooting

What it can do on your machine

Read from SKILL.md and the folder at commit aa90e7d. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • NETCLAW_PASSWORD

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Pyats Asa Firewall loads about 2.8k tokens when it runs. Until then it costs about 75 tokens; SKILL.md has 694 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~75
When it runs · the whole SKILL.md, loaded when a task matches
~2.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from automateyournetwork/netclaw at commit aa90e7d, republished under its Apache-2.0 licence (© automateyournetwork). 694 words, ~2,825 tokens.

Download SKILL.mdSave it as .claude/skills/pyats-asa-firewall/SKILL.md (or your agent's skills folder).
name
pyats-asa-firewall
description
Cisco ASA firewall operations via pyATS — VPN sessions, failover state, interfaces, routing, service policies, resource usage, AnyConnect monitoring. Use when checking ASA failover status, monitoring VPN sessions, auditing ASA security, or troubleshooting AnyConnect connectivity.
license
Apache-2.0
user-invocable
true

Cisco ASA Firewall Operations via pyATS

Testbed Requirements

ASA devices in the pyATS testbed with os: asa:

yaml
devices:
  asa-fw-01:
    os: asa
    type: firewall
    connections:
      cli:
        protocol: ssh
        ip: 10.0.0.10
        port: 22
    credentials:
      default:
        username: "%ENV{NETCLAW_USERNAME}"
        password: "%ENV{NETCLAW_PASSWORD}"
      enable:
        password: "%ENV{NETCLAW_ENABLE}"

How to Call

bash
PYATS_TESTBED_PATH=$PYATS_TESTBED_PATH python3 $MCP_CALL "${PYATS_PYTHON:-python3} -u $PYATS_MCP_SCRIPT" pyats_run_show_command '{"device_name":"asa-fw-01","command":"<command>"}'

Commands

System & Inventory
Version
bash
pyats_run_show_command '{"device_name":"asa-fw-01","command":"show version"}'

ASA software version, hardware model, serial number, RAM, flash, license, uptime, last reload reason.

Hardware Inventory
bash
pyats_run_show_command '{"device_name":"asa-fw-01","command":"show inventory"}'

Hardware inventory: chassis, modules, SFPs with serial numbers and PIDs.

Resource Usage
bash
pyats_run_show_command '{"device_name":"asa-fw-01","command":"show resource usage"}'

Per-context resource utilization: connections, xlates, hosts, NAT, routes, ACL elements. Critical for multi-context ASA — identifies contexts approaching resource limits.

Failover & High Availability
Failover Status
bash
pyats_run_show_command '{"device_name":"asa-fw-01","command":"show failover"}'

Failover state (Active/Standby), peer state, last failover time, failover reason, stateful failover stats. Check this first on any HA pair.

Failover Interfaces
bash
pyats_run_show_command '{"device_name":"asa-fw-01","command":"show failover interface"}'

Failover and stateful failover link status, IP addresses, hello interval, peer monitoring.

Interfaces
Interface Summary
bash
pyats_run_show_command '{"device_name":"asa-fw-01","command":"show interface ip brief"}'

Compact interface table: interface name, IP address, status (up/down), method.

Interface Detail
bash
pyats_run_show_command '{"device_name":"asa-fw-01","command":"show interface detail"}'

Full interface details: speed, duplex, MAC, input/output packets/bytes/errors, collision counts, CRC errors.

Interface Summary (Traffic)
bash
pyats_run_show_command '{"device_name":"asa-fw-01","command":"show interface summary"}'

Summary traffic stats per interface.

Interface Name Mapping
bash
pyats_run_show_command '{"device_name":"asa-fw-01","command":"show nameif"}'

Maps physical interface names to security zone names (e.g., GigabitEthernet0/0 → outside, GigabitEthernet0/1 → inside). Shows security level per interface.

Routing
Routing Table
bash
pyats_run_show_command '{"device_name":"asa-fw-01","command":"show route"}'

Full routing table: connected, static, OSPF, EIGRP, BGP routes with next-hop, interface, metric, age.

ARP Table
bash
pyats_run_show_command '{"device_name":"asa-fw-01","command":"show arp"}'

ARP cache: interface, IP address, MAC address, age. Cross-reference with NetBox for MAC verification.

ASP (Accelerated Security Path) Drops
bash
pyats_run_show_command '{"device_name":"asa-fw-01","command":"show asp drop"}'

Packets dropped by the ASP — categorized by reason: flow-drop, acl-drop, inspect-drop, rpf-violated, no-route, etc. Critical for troubleshooting — reveals why traffic is being blocked.

Security Contexts
bash
pyats_run_show_command '{"device_name":"asa-fw-01","command":"show context"}'
pyats_run_show_command '{"device_name":"asa-fw-01","command":"show context detail"}'

Multi-context ASA: list all security contexts, allocated interfaces, resource class, admin state. detail shows interface allocation and URL mappings.

Traffic & Service Policies
Traffic Statistics
bash
pyats_run_show_command '{"device_name":"asa-fw-01","command":"show traffic"}'

Per-interface traffic rates: input/output packets/sec and bytes/sec.

Service Policy (MPF)
bash
pyats_run_show_command '{"device_name":"asa-fw-01","command":"show service-policy"}'

Modular Policy Framework hit counts: class-maps, inspect actions, policing, shaping, QoS. Shows connection counts per policy.

VPN Sessions
VPN Session Summary
bash
pyats_run_show_command '{"device_name":"asa-fw-01","command":"show vpn-sessiondb summary"}'

Summary of all active VPN sessions by type: AnyConnect, L2L, WebVPN, clientless, total sessions, peak concurrent.

All VPN Sessions
bash
pyats_run_show_command '{"device_name":"asa-fw-01","command":"show vpn-sessiondb"}'

Full VPN session database — all types, user, duration, bytes, encryption.

AnyConnect Sessions
bash
pyats_run_show_command '{"device_name":"asa-fw-01","command":"show vpn-sessiondb anyconnect"}'

AnyConnect SSL VPN sessions: username, duration, bytes tx/rx, IP assignment, tunnel group, encryption, NAC result.

AnyConnect Inactive Sessions
bash
pyats_run_show_command '{"device_name":"asa-fw-01","command":"show vpn-sessiondb anyconnect sort inactivity"}'

AnyConnect sessions sorted by inactivity time — useful for identifying idle sessions consuming licenses.

WebVPN Sessions
bash
pyats_run_show_command '{"device_name":"asa-fw-01","command":"show vpn-sessiondb webvpn"}'

Clientless WebVPN sessions: user, duration, bytes, inactivity.

VPN Load Balancing
bash
pyats_run_show_command '{"device_name":"asa-fw-01","command":"show vpn load-balancing"}'

VPN cluster load distribution across ASA peers — sessions per member, load percentage.

IPSec / IKEv2
bash
pyats_run_show_command '{"device_name":"asa-fw-01","command":"show crypto ikev2 sa"}'

IKEv2 Security Associations: peer, state (READY), local/remote IDs, encryption, PRF, DH group, lifetime.

IP Pool
bash
pyats_run_show_command '{"device_name":"asa-fw-01","command":"show ip local pool vpn-pool"}'

VPN IP address pool usage: available, in use, range. Monitor for pool exhaustion — running out of addresses blocks new VPN connections.


Workflows

1. ASA Health Check
show version → ASA version, model, uptime, last reload
→ show failover → HA state (Active/Standby), peer health
→ show interface ip brief → interface up/down state
→ show resource usage → context resource utilization
→ show asp drop → dropped packet analysis
→ Severity-sort → GAIT
2. VPN Monitoring Dashboard
show vpn-sessiondb summary → total sessions by type, peak concurrent
→ show vpn-sessiondb anyconnect → active AnyConnect users
→ show vpn-sessiondb anyconnect sort inactivity → idle sessions
→ show ip local pool vpn-pool → address pool utilization
→ show vpn load-balancing → cluster distribution
→ show crypto ikev2 sa → IKEv2 tunnel state
→ Flag: pool > 80% used, sessions near license limit, idle > 8h
→ GAIT
Show full SKILL.md (277 more words)Show less
3. ASA Failover Verification
show failover → verify Active/Standby state
→ show failover interface → failover link health
→ show interface ip brief → all interfaces match expected state
→ show route → routing table consistent with active role
→ show vpn-sessiondb summary → VPN sessions present on active unit
→ GAIT
4. ASA Security Audit
show version → verify supported ASA version (cross-reference NVD CVE)
→ show asp drop → analyze drop reasons for anomalies
→ show service-policy → policy hit counts, inspect actions
→ show context detail → verify context isolation (multi-context)
→ show traffic → per-interface throughput baseline
→ GAIT
5. VPN Troubleshooting
show vpn-sessiondb anyconnect → verify user session exists
→ show crypto ikev2 sa → IKEv2 tunnel established?
→ show interface ip brief → outside interface up?
→ show route → default route present?
→ show ip local pool vpn-pool → addresses available?
→ show asp drop → packets being dropped for this flow?
→ show service-policy → inspect policies blocking traffic?
→ GAIT

Parallel Operations

Run ASA health checks across multiple firewalls concurrently:

bash
# ASA Pair - Primary
PYATS_TESTBED_PATH=$PYATS_TESTBED_PATH python3 $MCP_CALL "${PYATS_PYTHON:-python3} -u $PYATS_MCP_SCRIPT" pyats_run_show_command '{"device_name":"asa-fw-01","command":"show failover"}'

# ASA Pair - Secondary
PYATS_TESTBED_PATH=$PYATS_TESTBED_PATH python3 $MCP_CALL "${PYATS_PYTHON:-python3} -u $PYATS_MCP_SCRIPT" pyats_run_show_command '{"device_name":"asa-fw-02","command":"show failover"}'

# Remote Site ASA
PYATS_TESTBED_PATH=$PYATS_TESTBED_PATH python3 $MCP_CALL "${PYATS_PYTHON:-python3} -u $PYATS_MCP_SCRIPT" pyats_run_show_command '{"device_name":"asa-remote-01","command":"show failover"}'

Integration with Other Skills

SkillIntegration
pyats-networkCore pyATS commands for IOS-XE/NX-OS devices alongside ASA firewalls
pyats-securityCIS benchmark-style audits complement ASA-specific security checks
pyats-parallel-opspCall pattern for fleet-wide ASA health checks
fmc-firewall-opsFMC manages FTD; ASA is managed directly — different platforms, similar mission
ise-posture-auditISE NAC results correlate with ASA VPN session NAC status
netbox-reconcileCross-reference ASA interfaces, IP assignments with NetBox
nvd-cveScan ASA version against NVD vulnerability database
servicenow-change-workflowGate ASA config changes behind ServiceNow CRs
gait-session-trackingEvery ASA command logged in GAIT

Guardrails

  • All commands are read-only — show commands only
  • No config changes — never use configure terminal or write memory via this skill
  • Monitor VPN pool usage — alert when pool utilization exceeds 80%
  • Check failover before maintenance — always verify HA state before any maintenance window
  • Cross-reference with SoT — compare interface IPs and routes with NetBox
  • Record in GAIT — every command execution must be logged

Failure Behavior

  • If a tool call fails with an authentication or connection error, check that PYATS_MCP_SCRIPT, PYATS_TESTBED_PATH are set and valid before assuming a data or device problem.
  • On a tool error (timeout, unreachable host, malformed response), report the failure and its error message directly to the user rather than fabricating or guessing at results.
  • For a confirmed read-only call, check connectivity and retry once if appropriate. For any call that changes state or sends a message, a timeout does not prove the action failed: inspect current state or delivery status before retrying, preserve the required approval/change gates, and do not repeat an action whose outcome is unknown.

© automateyournetwork, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in workspace/skills/pyats-asa-firewall of automateyournetwork/netclaw.

Open the folder on GitHubat commit aa90e7d

Compare with similar skills

Pyats Asa Firewall next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Pyats Asa Firewall compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Pyats Asa Firewall this skillautomateyournetwork/netclaw676—~2.8kAutomated safety check: PassApache-2.0
Storage S3 Resiliency Expertiseaws/tools-for-devops-agent103—~2.8kAutomated safety check: PassApache-2.0
Frontmcp Production Readinessagentfront/frontmcp146—~6.5kAutomated safety check: PassApache-2.0
Implementing Immutable Backup With Resticmukul975/Anthropic-Cybersecurity-Skills34k—~1kAutomated safety check: PassApache-2.0
Recovering From Ransomware Attackmukul975/Anthropic-Cybersecurity-Skills34k—~3.2kAutomated safety check: PassApache-2.0
Testing Ransomware Recovery Proceduresmukul975/Anthropic-Cybersecurity-Skills34k—~1.9kAutomated safety check: PassApache-2.0

Similar skills

  • Storage S3 Resiliency Expertise

    aws/tools-for-devops-agent

    Official

    S3 resiliency, security, and data protection review. An agent skill from aws/tools-for-devops-agent.

    103 GitHub stars~2.8k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Pre-production audit, hardening, and go-live checklists for FrontMCP servers.

    146 GitHub stars~6.5k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Implementing Immutable Backup With Restic

    mukul975/Anthropic-Cybersecurity-Skills

    Implements ransomware-resistant backups using restic with S3-compatible Object Lock (AWS S3, MinIO, Backblaze B2), automating backup creation, integrity checks via restic check --read-data…

    34k GitHub stars~1k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Recovering From Ransomware Attack

    mukul975/Anthropic-Cybersecurity-Skills

    Executes structured ransomware incident recovery following NIST/CISA frameworks: environment isolation, forensic evidence preservation, clean infrastructure rebuild, prioritized restoration from…

    34k GitHub stars~3.2k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Testing Ransomware Recovery Procedures

    mukul975/Anthropic-Cybersecurity-Skills

    Tests and validates ransomware recovery procedures - backup restore operations (e.g.

    34k GitHub stars~1.9k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Source Leak Hunt

    uphiago/recon-skills

    Mass scan for exposed env files, backups, and git configs. An agent skill from uphiago/recon-skills.

    1.3k GitHub stars~2.2k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check: notes

More from automateyournetwork/netclaw

All 120 skills in this repo
  • EVE-NG Lab Topology Design

    automateyournetwork/netclaw

    Entry point for designing EVE-NG network labs: classifies the request, gathers missing requirements, proposes options and validates the resulting topology.

    677 GitHub stars~612 tokensUpdated today
    Auto-check passed
  • ACI Policy Change Deployment

    automateyournetwork/netclaw

    Deploys Cisco ACI policy changes only behind an approved ServiceNow Change Request, capturing pre and post-change fault baselines and rolling back automatically on a fault delta.

    677 GitHub stars~4.2k tokensUpdated today
    Auto-check passed
  • Cisco ACI Fabric Health Audit

    automateyournetwork/netclaw

    Runs a phased health audit of a Cisco ACI fabric through MCP tools: node status, links, tenant and policy review, faults and endpoint learning.

    677 GitHub stars~2.9k tokensUpdated today
    Auto-check passed
  • Anta Validation

    automateyournetwork/netclaw

    Validate Arista EOS network state against ANTA's pre-built 208-test catalogue, with structured pass/fail verdicts.

    677 GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Arista Cvp

    automateyournetwork/netclaw

    Arista CloudVision Portal (CVP) automation via REST API — device inventory, events, connectivity monitoring, tag management (4 tools).

    677 GitHub stars~2.2k tokensUpdated today
    Auto-check: notes
  • AWS Cloud Monitoring

    automateyournetwork/netclaw

    AWS CloudWatch monitoring — metrics, alarms, log queries, VPC flow log analysis, network performance.

    677 GitHub stars~1k tokensUpdated today
    Auto-check passed

Questions about Pyats Asa Firewall

What does Pyats Asa Firewall do?

Cisco ASA firewall operations via pyATS — VPN sessions, failover state, interfaces, routing, service policies, resource usage, AnyConnect monitoring. Pyats Asa Firewall is an agent skill from automateyournetwork/netclaw. Cisco ASA firewall operations via pyATS — VPN sessions, failover state, interfaces, routing, service policies, resource usage, AnyConnect monitoring.

When should I use Pyats Asa Firewall?

Pyats Asa Firewall fits situations like: checking ASA failover status; monitoring VPN sessions; auditing ASA security; troubleshooting AnyConnect connectivity.

How do I install Pyats Asa Firewall in Claude Code?

Run `npx skills add automateyournetwork/netclaw --skill pyats-asa-firewall -a claude-code`. Or copy the skill folder (workspace/skills/pyats-asa-firewall in automateyournetwork/netclaw) into .claude/skills/pyats-asa-firewall in your project. Claude Code loads it when a task matches its description.

How do I install Pyats Asa Firewall in Codex?

Run `npx skills add automateyournetwork/netclaw --skill pyats-asa-firewall -a codex`. Or copy the skill folder (workspace/skills/pyats-asa-firewall in automateyournetwork/netclaw) into .agents/skills/pyats-asa-firewall in your project. Codex loads it when a task matches its description.

Can I use Pyats Asa Firewall in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add automateyournetwork/netclaw --skill pyats-asa-firewall -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/pyats-asa-firewall, .gemini/skills/pyats-asa-firewall, .github/skills/pyats-asa-firewall and .opencode/skills/pyats-asa-firewall in your project.

What does Pyats Asa Firewall need to run?

Going by SKILL.md and its folder, Pyats Asa Firewall needs the command-line tools its instructions call (python3) and credentials named NETCLAW_PASSWORD. Our summary lists: Python 3.

Does Pyats Asa Firewall access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Pyats Asa Firewall safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Pyats Asa Firewall use?

Pyats Asa Firewall is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Pyats Asa Firewall use?

About 2.8k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Pyats Asa Firewall?

Skills that share tags, products or a category with Pyats Asa Firewall: Storage S3 Resiliency Expertise (aws/tools-for-devops-agent, 103 stars), Frontmcp Production Readiness (agentfront/frontmcp, 146 stars), Implementing Immutable Backup With Restic (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Recovering From Ransomware Attack (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Pyats Asa Firewall?

automateyournetwork (a GitHub user) maintains it in automateyournetwork/netclaw, which has 676 GitHub stars. The repository holds 120 skills in this directory. The repository was last updated on October 9, 2026.

Source: automateyournetwork/netclaw on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.