panredirect configure
Focus
Focus
Prisma AIRS

panredirect configure

Table of Contents

panredirect configure

Write the global redirection parameters to the configuration blob. Must be run before enable or start.

Syntax

panredirect.exe configure --fwip <IP> [--fwsubnet <CIDR>] [--hc on|off] [--hc_interval <sec>] [--hc_fail_count <N>] [--hc_pkt <spec>]

Options

OptionRequiredDefaultDescription
--fwip IPYes—IPv4 address of the firewall appliance that receives redirected traffic.
--fwsubnet CIDRNo—IPv4 CIDR of the firewall subnet. Required only when firewall instances sit behind a load balancer operating in Direct Server Return (DSR) mode.
--hc on|offNoonEnable or disable the kernel health-check worker. When off, no probe packets are sent and health_check_state stays 0.
--hc_interval SECONDSNo1Probe interval in seconds (range: 1–86400). The worker sends one probe per interval, or skips it if live firewall traffic was seen within that window.
--hc_fail_count COUNTNo3Number of consecutive missed intervals before health_check_state drops to 0 (range: 1–255). The firewall is considered stale after hc_interval × hc_fail_count seconds with no reply.
--hc_pkt 5-TUPLENoudp:169.254.1.1:45000:169.254.1.2:45000Probe 5-tuple in proto:src_ip:src_port:dst_ip:dst_port format. proto must be tcp or udp.

Examples

# Minimal — single firewall instance, default health-check settings panredirect.exe configure --fwip 10.0.0.1 # Load-balanced firewall pool with DSR panredirect.exe configure --fwip 10.0.0.1 --fwsubnet 10.0.0.0/24 # Aggressive health-check: probe every 500 ms, declare stale after 2 misses panredirect.exe configure --fwip 10.0.0.1 --hc_interval 1 --hc_fail_count 2 # Custom probe 5-tuple using TCP panredirect.exe configure --fwip 10.0.0.1 --hc_pkt tcp:169.254.1.1:45000:169.254.1.2:45000 # Disable health checks entirely panredirect.exe configure --fwip 10.0.0.1 --hc off