Routing entry "0.0.0.0/0" is displayed when checking Routing information of Service Connections/Remote Networks in Prisma Access
828
Created On 01/23/24 01:51 AM - Last Modified 05/30/25 02:50 AM
Symptom
- The routing entries on Prisma Access SC CAN and RN SPN can be accessed via GUI: Panorama > Cloud Services > Configuration > Service Setup > Service Operations > Troubleshooting Commands > Routing Information.
- Here one may see routing entries for Destination:0.0.0.0/0, Nexthop:0.0.0.0/0, and Flags:
Environment
- Panorama Managed Prisma Access
- Cloud Managed Prisma Access
- SC CAN (Service connection, also known as a Corporate Access Node)
- RN SPN (Remote Network Security Processing Node)
Cause
- This entry is be displayed when "Advertise Default Route" for BGP has been enabled in the peer site settings configured on the CAN/SPN.
- Panorama > Cloud Services > Configuration > Service Setup > Service Operations > Onboarding
Resolution
- This behavior is expected when "Advertise Default Route" has been enabled.
- With this setting Prisma Access Firewalls create a Redistribution Rule of 0.0.0.0/0 internally.
- Therefore, the corresponding routing entry will be displayed for the internal use.
- It is not possible to hide this routing entry when "Advertise Default Route" is enabled.
Additional Information
This behavior is consistent with the On-Prem FW described under Understanding routing flag.