Verify the Tunnel Adapter Routing Priority Configuration
Focus
Focus
Prisma Agent

Verify the Tunnel Adapter Routing Priority Configuration

Table of Contents

Verify the Tunnel Adapter Routing Priority Configuration

Run pacli traffic show on an endpoint to confirm that the Third Party Co-Existence option is active after you push the forwarding profile configuration.
Where Can I Use This?What Do I Need?
  • Prisma Access (Managed by Strata Cloud Manager)
  • Check the prerequisites for your deployment
  • Prisma Agent 26.3 or later
  • macOS or Windows endpoints
After you push the forwarding profile configuration, verify on an endpoint that Prisma Agent has applied the Third Party Co-Existence option. The pacli traffic show command displays the active traffic enforcement state, including whether the Third Party Co-Existence option is on or off.
  1. On the endpoint, open a command prompt or terminal with administrator privileges.
  2. Run the following command:
    pacli traffic show
  3. In the command output, confirm that Adjust Default Route shows ON:
    ON - Adjust Default Route
    If the output shows OFF or the line is absent, the Third Party Co-Existence option has not been pushed to the endpoint yet. Push the configuration again and allow time for the agent to receive and apply the update, then re-run the command.
  4. (Optional) Ping a remote host to confirm that ICMP traffic exits via the physical interface rather than the Prisma Agent tunnel:
    Because non-TCP/non-UDP traffic is not enforced by forwarding profile rules when Third Party Co-Existence is enabled, ICMP traffic should use the physical interface. If the ping resolves via the expected physical interface, the routing configuration is correct.