On a firewall where multiple virtual systems are enabled, select
Services
to display the
Global
and
Virtual Systems
tabs where you set services that the firewall or its virtual systems, respectively, use to operate efficiently. (If the firewall is a single virtual system or if multiple virtual systems are disabled, there are not two tabs, but just a
Services
menu.)
The
Destination
tab is another Global service route feature that you can customize. This tab appears in the Service Route Configuration window and is described in
Destination Service Route .
Use the
Virtual Systems
tab to specify service routes for a single virtual system. Select a Location (virtual system) and click
Service Route Configuration . Select
Inherit Global Service Route Configuration
or
Customize
service routes for a virtual system
. If you choose to customize settings, select
IPv4
or
IPv6 . Select the one or more services you want to customize to have the same settings and click
Set Selected Service Routes . See Table 13 for services that can be customized.

To control and redirect DNS queries between shared and specific virtual systems, you can use a
DNS proxy
and a
DNS Server profile
.


When customizing a
Global
service route, on either the
IPv4
or
IPv6
tab, select from the list of available services, click
Set Selected Service Routes , and select the
Source Interface
and
Source Address
from the drop-down. A Source Interface that is set to
Any
allows you to select a Source Address from any of the interfaces available. The Source Address displays the IPv4 or IPv6 address assigned to the selected interface; the selected IP address will be the source for the service traffic. You do not have to define a destination address because the destination is configured when configuring each service. For example, when you define your DNS servers (
Device > Setup > Services ), that will set the destination for DNS queries.
When configuring service routes for a
Virtual System , the
Inherit Global Service Route Configuration
option means that all services for the virtual system will inherit the global service route settings. Or you can choose
Customize , select IPv4 or IPv6, select a service, and click
Set Selected Service Routes . The
Source Interface
has the following three choices:
Returning to the
Global
tab, when you click on
Service Route Configuration
and then
Customize , the
Destination
tab appears. Destination service routes are available under the
Global
tab only (not the
Virtual Systems
tab), so that the service route for an individual virtual system cannot override route table entries that are not associated with that virtual system.
A destination service route can be used to add a customized redirection of a service that is not supported on the
Customize
list of services (Table 13). A destination service route is a way to set up routing to override the forwarding information base (FIB) route table. Any settings in the Destination service routes override the route table entries. They could be related or unrelated to any service.