to enable firewalls to
connect to the internet.
By default, matched traffic is sent to Enterprise DLP through the
management interface. Configuring a service route allows you to dedicate a
specific Ethernet interface from which to send matched traffic to Enterprise DLP and for Enterprise DLP to return a verdict.
Palo Alto Networkss recommends configuring a service route to ensure a high
level of performance for enforcement points forwarding traffic to Enterprise DLP. While recommended, Enterprise DLP doesn't require
a service route for traffic forwarding.
For a multi-vsys firewall, the service route is a global configuration and is
applied to all vsys of a multi-vsys firewall regardless of which vsys the
service route belongs to.
Create a service route for all supported
firewall models running PAN-OS
10.1 or a later release.