<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: management interface &amp;amp; service route configuration in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/management-interface-amp-service-route-configuration/m-p/462008#M102217</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/192693"&gt;@PavelK&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your answer&lt;/P&gt;&lt;P&gt;What I understood is that the control plane and the data plane are "physically" separated, and there is no direct communication between the management interface and the WAN output interface (for example).&lt;BR /&gt;If I connect my management interface directly to my pc, I will encounter problems connecting to the internet for external services, so this case to be eliminated since you completely isolate the management plane from any network! and this is what you have confirmed.&lt;BR /&gt;but if we connect the mgt interface to a switch port, there we can declare the data port of the firewall corresponding to the switch port, in route service configuration and this port becomes the source for external services.&lt;BR /&gt;but if we assume that a vlan is dedicated and that the dns server is in another vlan, do we have to set a policy rule to pass the inter-vlan flow (so inter-zone)?&lt;BR /&gt;actually the route service configuration is not only used for external services, but also for internal services like dns?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Kind Regards&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Toufik&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 30 Jan 2022 10:31:32 GMT</pubDate>
    <dc:creator>Toufik</dc:creator>
    <dc:date>2022-01-30T10:31:32Z</dc:date>
    <item>
      <title>management interface &amp; service route configuration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/management-interface-amp-service-route-configuration/m-p/461982#M102213</link>
      <description>&lt;P&gt;Hello&lt;BR /&gt;I am new in palo alto, I did a self-training&lt;BR /&gt;I would like to have more details about the relation between the management interface and the service route configuration&lt;BR /&gt;I have a little bit stuck on when to use the route configuration service&lt;BR /&gt;I think there are some webgui ways to manage the AP:&lt;BR /&gt;-directly connect a pc to Mgmt interface&lt;BR /&gt;-connect mgmt interface to switch with dedicated vlan&lt;BR /&gt;- connect mgmt interface to switch in the same vlan as the data interfaces&lt;BR /&gt;how to enter the concept of service route configuration in the above cases.&lt;BR /&gt;I know that the management interface is used by the FW PA to go on the internet and retrieve updates,...etc, but sometimes there is a need to use the service route configuration to point into the service in the LAN data&lt;BR /&gt;I have some ambiguities to master this concept and the why and how of the thing.&lt;BR /&gt;thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 29 Jan 2022 23:23:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/management-interface-amp-service-route-configuration/m-p/461982#M102213</guid>
      <dc:creator>Toufik</dc:creator>
      <dc:date>2022-01-29T23:23:30Z</dc:date>
    </item>
    <item>
      <title>Re: management interface &amp; service route configuration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/management-interface-amp-service-route-configuration/m-p/461992#M102214</link>
      <description>&lt;P&gt;Thank you for the post&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/207857"&gt;@Toufik&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Basically by default all communication that Firewall will initiate will be over management interface. In the case you for what ever reason can't use management interface, you can change all services to communicate via data plane interface instead of management interface. You can also do it selectively based on service you want to communicate over data plane interface. Here is KB:&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClGJCA0" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClGJCA0&lt;/A&gt;&lt;/P&gt;&lt;P&gt;In the case of Active/Standby HA you will come across an issue when standby Firewall will not be able to use data plane interfaces (Depending on HA configuration interfaces are either shut or suspended), so service route configuration will not work unless Firewall assumes active role or you change it back to use management interface.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Connecting management port to switch with dedicated Vlan is the most optimal way. Having management interface on the same subnet as data plane interface is possible and it will work, however I would avoid this security reasons. The first option you mentioned is of course possible to connect management interface directly to your PC, but outside of the lab environment, this is not scalable option. If you need to change management interface IP address from CLI to range for management Vlan, you can do it from CLI:&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClN7CAK" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClN7CAK&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind Regards&lt;/P&gt;&lt;P&gt;Pavel&lt;/P&gt;</description>
      <pubDate>Sun, 30 Jan 2022 01:06:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/management-interface-amp-service-route-configuration/m-p/461992#M102214</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2022-01-30T01:06:16Z</dc:date>
    </item>
    <item>
      <title>Re: management interface &amp; service route configuration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/management-interface-amp-service-route-configuration/m-p/462008#M102217</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/192693"&gt;@PavelK&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your answer&lt;/P&gt;&lt;P&gt;What I understood is that the control plane and the data plane are "physically" separated, and there is no direct communication between the management interface and the WAN output interface (for example).&lt;BR /&gt;If I connect my management interface directly to my pc, I will encounter problems connecting to the internet for external services, so this case to be eliminated since you completely isolate the management plane from any network! and this is what you have confirmed.&lt;BR /&gt;but if we connect the mgt interface to a switch port, there we can declare the data port of the firewall corresponding to the switch port, in route service configuration and this port becomes the source for external services.&lt;BR /&gt;but if we assume that a vlan is dedicated and that the dns server is in another vlan, do we have to set a policy rule to pass the inter-vlan flow (so inter-zone)?&lt;BR /&gt;actually the route service configuration is not only used for external services, but also for internal services like dns?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Kind Regards&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Toufik&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 30 Jan 2022 10:31:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/management-interface-amp-service-route-configuration/m-p/462008#M102217</guid>
      <dc:creator>Toufik</dc:creator>
      <dc:date>2022-01-30T10:31:32Z</dc:date>
    </item>
  </channel>
</rss>

