I have configured trust and untrust zone with respect to their interface.
I create policy of any any...my firewall internet only work when i configure service route and destination as outgoing interface,if i set it as default and select use management for all interface...my firewall lose its internet connectivity for upgrading OS,URL updates.
My DNS is 220.127.116.11 and update is updates.paloaltonetworks.com
I'm assuming that you don't actually have your MGMT interface plugged into anything (or what it is plugged into isn't allowed internet access), and in that case you would require a service route to facilitate that communication. So what your describing would appear to be expected behavior unless you actually do have your MGMT interface plugged in and it should have internet access.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!