Setting a Service Route for Services to Use a Dataplane Interface from the Web UI and CLI

Setting a Service Route for Services to Use a Dataplane Interface from the Web UI and CLI

Created On 09/25/18 17:30 PM - Last Modified 04/20/20 23:38 PM

  • PAN-OS
  • Service route

By default, the firewall uses management interface to communicate to various servers including DNS, Email, Palo Alto Updates, User-ID agent, Syslog, Panorama  etc. The article explains how to configure service route to use non management dataplane port to reach these services.



Use Device > Setup > Services > Service Route Configuration > Customize and configure the appropriate service routes.

service route configuration.png


To configure service routes for non-predefined services, the destination addresses can be manually entered in the Destination section:

destination service route.png

In the example above, the service routes for and are configured to source from on a dataplane interface and the management interface, respectively.


On the CLI

Run the command set deviceconfig system route service to show the options for the command.

> configure
# set deviceconfig system route service
  autofocus                    AutoFocus Cloud
  crl-status                   CRL servers
  deployments                  Panorama pushed updates
  dns                          DNS server(s)
  edl-updates                  External Dynamic List update server
  email                        SMTP gateway(s)
  hsm                          Hardware Security Module server(s)
  http                         HTTP Forwarding server(s)
  kerberos                     Kerberos server
  ldap                         LDAP server
  mdm                          MDM servers
  mfa                          Multi-Factor Authentication
  netflow                      Netflow server(s)
  ntp                          NTP server(s)
  paloalto-networks-services   Palo Alto Networks Services
  panorama                     Panorama server
  proxy                        Proxy server
  radius                       RADIUS server
  scep                         SCEP
  snmp                         SNMP server(s)
  syslog                       Syslog server(s)
  tacplus                      TACACS+ server
  uid-agent                    UID agent(s)
  url-updates                  URL update server
  vmmonitor                    VM monitor
  wildfire-private             WildFire Appliance
  <value>                      Service name


 Select the service and source address. Example given below. The source address listed is the address configured on the dataplane interfaces.


# set deviceconfig system route service paloalto-networks-services source address         ip       ip    ip   ip        mgmt     ip
  <value>             Source IP address to use to reach destination

Example command to set a service route for receiving Palo Alto Networks updates using one of the available dataplane interfaces:

# set deviceconfig system route service paloalto-networks-services source address

Non-predefined service routes can also be configured through CLI. For example:

# set deviceconfig system route destination source address

Note: Explicit policies are required in the security rules to log and allow traffic.


Additional Information
Depending on the code version on Firewall, the output of command set deviceconfig system route service may list different services.

  • Print
  • Copy Link

Choose Language