I temporary change the service route config to "Use Management Interface for all". But still cannot ping outside. The Management interface set as below: IP Address: 192.168.123.123 Netmask: 255.255.255.0 Default Gateway: 192.168.123.254 Speed: auto-negotiate MTU: 1500 Network Connectivity Services: HTTPS, Ping, SSH Services set as below: Primary DNS Server: 8.8.8.8 Secondary DNS Server: 8.8.4.4 Update Server: updates.paloaltonetworks.com Security Policy set allow the source zone of management interface to destination zone internet facing interface Monitor Traffic show source 192.168.123.123 to destination 8.8.8.8, application ping and dns are allow. Use the correct rule too.
... View more