Enhanced Security Measures in Place:   To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.

Service route in panorama.

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Service route in panorama.

L4 Transporter

Dear Team,

 

I have two interfaces configured in my panorama:

1-management interface

2 -ethernet1/1.

 

for software and dynamic updates by default, my traffic is going via management interface. I want to change the service route through ethernet1/1 but I am not able to see any option to change the service route. below is the snapshot.

Jafar_Hussain_0-1593346305511.png

 

can anyone help with this where I can find this option?

 

 

12 REPLIES 12

Cyber Elite
Cyber Elite

You are in the right track.

You should see 

Screen Shot 2020-06-28 at 9.23.31 AM.png

Pa has role based access control.

so you need to have rights to see all the info on gui

Can you log into this PA with admin username and then try?

 

 

MP

Help the community: Like helpful comments and mark solutions.

@MP18Yes, i have the super admin rights.

 

Is there any way to change the service route through the CLI.

 

Yes you can change it via cli.

Please use below command from config mode

 

# set deviceconfig system route service ??

 

example

set deviceconfig system route service paloalto-networks-services source address   10.0.10.1/24

 

 

where source address can be of data plane interface

 

MP

Help the community: Like helpful comments and mark solutions.

@MP18Thank you for your reply,

 

I have checked this command is only working in Palo alto. when I check the same command in panorama it is not working.

 

My bad.

Need morning coffee.

 

As Panorama is only for management and no data traffic goes via Panorama so that's the reason there is no service route config there

So this is by design you do not see service route config in GUI.

MP

Help the community: Like helpful comments and mark solutions.

@MP18 

Thanks for the reply, it means we can not change the default behavior of the panorama to update the software or dynamic updates through the data plane interface(ethernet 1/1) interface.

Yes we can not change the default behavior.

MP

Help the community: Like helpful comments and mark solutions.

@MP18thanks for the reply.

@MP18 

Hello , one last question have any documents for this, because i have searched everywhere but couldn't find anything.

@Jafar_Hussain 

 

I found below document that shows Panorama port usage

 

https://docs.paloaltonetworks.com/panorama/9-1/panorama-admin/troubleshooting/troubleshoot-log-stora...

 

This should clear the doubts.

 

Regard

MP

Help the community: Like helpful comments and mark solutions.

@MP18 

thanks, appreciate your help.

L0 Member

To change the service of the panorama deployment, push content and firmware and log collection its at Interfaces tab.

https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-web-interface-help/panorama-web-interface/panora...

  • 8599 Views
  • 12 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!