panredirect rule
Focus
Focus
Prisma AIRS

panredirect rule

Table of Contents

panredirect rule

Manage the selective steering rule list for a redirected interface. Rules are evaluated in order; the first match wins. If no rule matches, the default action is to redirect the packet to the firewall.

Syntax

panredirect.exe rule SUBCOMMAND

Sub-subcommands

Sub-subcommandDescription
rule listPrint all rules across all interfaces.
rule appendAdd a new rule at the end of an interface's rule list.
rule insertInsert a new rule at a specific index.
rule deleteDelete a rule by index.

Rule Fields

Every rule matches on a combination of the following fields. Omitting a field (or passing any) makes it a wildcard that matches all values.
FieldCLI OptionAccepted Values
Protocol--protoany, tcp, udp, icmp, or a decimal/hex protocol number (0–255).
Remote IP--remoteipany or an IPv4 CIDR (for example, 192.168.1.0/24).
Remote port--remoteportany or a decimal port number (1–65535); meaningful only for TCP/UDP.
Local IP--localipany or an IPv4 CIDR.
Local port--localportany or a decimal port number (1–65535); meaningful only for TCP/UDP.
Action--actionpass — let the packet through without redirection; redirect — send to the firewall.
"Remote" refers to the far-end address/port of the connection as seen by the host (source for inbound, destination for outbound). "Local" refers to the host-side address/port.

rule list

Print all steering rules across every configured interface.
panredirect.exe rule list
No additional options.
Example output:
PS C:\> panredirect.exe rule list ifname rule# proto remoteip rport localip lport action ---------------------------------------- ----- ----- ---------------- ----- ---------------- ----- -------- Ethernet1 0 any 192.168.142.10 any any any redirect

rule append

Append a new rule to the end of the rule list for the specified interface. Equivalent to rule insert with the highest possible index.
panredirect.exe rule append --iface <name> --action <pass|redirect> [--proto <proto>] [--remoteip <CIDR>] [--remoteport <port>] [--localip <CIDR>] [--localport <port>] [--commit]
OptionRequiredDefaultDescription
--iface TEXTYes—NIC friendly name. The interface must already be enabled.
--action TEXTYes—pass or redirect.
--proto TEXTNoanyProtocol filter.
--remoteip TEXTNoanyRemote IPv4 CIDR filter.
--remoteport TEXTNoanyRemote port filter (TCP/UDP only).
--localip TEXTNoanyLocal IPv4 CIDR filter.
--localport TEXTNoanyLocal port filter (TCP/UDP only).
--commitNo—Restart the service after appending the rule.
Examples:
# Pass all DNS traffic without redirecting it panredirect.exe rule append --iface Ethernet --proto udp --remoteport 53 --action pass # Redirect all TCP traffic to 10.1.0.0/16 panredirect.exe rule append --iface Ethernet --proto tcp --remoteip 10.1.0.0/16 --action redirect --commit

rule insert

Insert a new rule at a specific 0-based index in the rule list for the specified interface. Existing rules at that index and beyond are shifted down by one.
panredirect.exe rule insert --index <N> --iface <name> --action <pass|redirect> [--proto <proto>] [--remoteip <CIDR>] [--remoteport <port>] [--localip <CIDR>] [--localport <port>] [--commit]
OptionRequiredDefaultDescription
--index INTYes—0-based position at which to insert the rule.
--iface TEXTYes—NIC friendly name. The interface must already be enabled.
--action TEXTYes—pass or redirect.
--proto TEXTNoanyProtocol filter.
--remoteip TEXTNoanyRemote IPv4 CIDR filter.
--remoteport TEXTNoanyRemote port filter (TCP/UDP only).
--localip TEXTNoanyLocal IPv4 CIDR filter.
--localport TEXTNoanyLocal port filter (TCP/UDP only).
--commitNo—Restart the service after inserting the rule.
Example:
# Insert a "pass ICMP" rule at position 0 (highest priority) panredirect.exe rule insert --index 0 --iface Ethernet --proto icmp --action pass

rule delete

Delete the rule at a specific 0-based index from the rule list for the specified interface. Rules after the deleted entry are shifted up by one.
panredirect.exe rule delete --index <N> --iface <name> [--commit]
OptionRequiredDescription
--index INTYes0-based index of the rule to delete. Use rule list to find the index.
--iface TEXTYesNIC friendly name.
--commitNoRestart the service after deleting the rule.
Example:
# Delete rule 0 on Ethernet and apply immediately panredirect.exe rule delete --index 0 --iface Ethernet --commit