set cli config-output-format set
bring rules in as disabled
set device-group PALO-5420 pre-rulebase security rule acl1 disabled yes
show device-group
show device-group dg1 address <- get addresses
show device-group dg1 address-group <- get address-groups
show shared profile-group