<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Management IP in Active/passive setup in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/management-ip-in-active-passive-setup/m-p/486648#M104625</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am quite new to Palo Alto firewalls, but have worked with different vendors before.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When running a HA in Active/passive a central VIP for mgmt is usually setup, so you dont connect to the passive FW.&lt;/P&gt;&lt;P&gt;From what i see there is no VIP for mgmt in the HA setup i am working on here. Is that something that is setup wrong or ?&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;We have a dns name internally that points to one of the firewalls, but in case of failover this might end up being the passive node.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;hope someone can enlighten me.&lt;/P&gt;</description>
    <pubDate>Thu, 12 May 2022 08:15:49 GMT</pubDate>
    <dc:creator>hh_cloudio</dc:creator>
    <dc:date>2022-05-12T08:15:49Z</dc:date>
    <item>
      <title>Management IP in Active/passive setup</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/management-ip-in-active-passive-setup/m-p/486648#M104625</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am quite new to Palo Alto firewalls, but have worked with different vendors before.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When running a HA in Active/passive a central VIP for mgmt is usually setup, so you dont connect to the passive FW.&lt;/P&gt;&lt;P&gt;From what i see there is no VIP for mgmt in the HA setup i am working on here. Is that something that is setup wrong or ?&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;We have a dns name internally that points to one of the firewalls, but in case of failover this might end up being the passive node.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;hope someone can enlighten me.&lt;/P&gt;</description>
      <pubDate>Thu, 12 May 2022 08:15:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/management-ip-in-active-passive-setup/m-p/486648#M104625</guid>
      <dc:creator>hh_cloudio</dc:creator>
      <dc:date>2022-05-12T08:15:49Z</dc:date>
    </item>
    <item>
      <title>Re: Management IP in Active/passive setup</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/management-ip-in-active-passive-setup/m-p/486672#M104626</link>
      <description>&lt;P&gt;You are correct.&lt;BR /&gt;Palo Alto firewalls in HA need their own separate management IPs.&lt;/P&gt;&lt;P&gt;Kiki&lt;/P&gt;</description>
      <pubDate>Thu, 12 May 2022 08:29:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/management-ip-in-active-passive-setup/m-p/486672#M104626</guid>
      <dc:creator>KieraMitchell</dc:creator>
      <dc:date>2022-05-12T08:29:22Z</dc:date>
    </item>
    <item>
      <title>Re: Management IP in Active/passive setup</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/management-ip-in-active-passive-setup/m-p/486675#M104627</link>
      <description>&lt;P&gt;So that how are people handling the management in a failover case ? just change the DNS entry or this there something easier ?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 12 May 2022 08:31:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/management-ip-in-active-passive-setup/m-p/486675#M104627</guid>
      <dc:creator>hh_cloudio</dc:creator>
      <dc:date>2022-05-12T08:31:38Z</dc:date>
    </item>
    <item>
      <title>Re: Management IP in Active/passive setup</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/management-ip-in-active-passive-setup/m-p/486683#M104628</link>
      <description>&lt;P&gt;In most cases, each node has its own DNS name. In my lab, for example, I have&lt;/P&gt;&lt;P&gt;&lt;A href="https://palo-pri.kiki.lab" target="_blank"&gt;https://palo-pri.kiki.lab&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://palo-sec.kiki.lab" target="_blank"&gt;https://palo-sec.kiki.lab&lt;/A&gt;&lt;/P&gt;&lt;P&gt;It's designed this way for a number of reasons, including so that each node can have its HA status controlled, reach out the internet for updates, telemetry forwarding, forward Syslog to external servers, etc.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 12 May 2022 08:34:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/management-ip-in-active-passive-setup/m-p/486683#M104628</guid>
      <dc:creator>KieraMitchell</dc:creator>
      <dc:date>2022-05-12T08:34:12Z</dc:date>
    </item>
    <item>
      <title>Re: Management IP in Active/passive setup</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/management-ip-in-active-passive-setup/m-p/486848#M104661</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/219478"&gt;@hh_cloudio&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;What is the use case you are attempting to resolve? Just connecting or something else, more curious than anything?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Thu, 12 May 2022 17:07:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/management-ip-in-active-passive-setup/m-p/486848#M104661</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2022-05-12T17:07:50Z</dc:date>
    </item>
    <item>
      <title>Re: Management IP in Active/passive setup</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/management-ip-in-active-passive-setup/m-p/487337#M104703</link>
      <description>&lt;P&gt;Just so in case of a failover that you allways connect to the active firewall. Its not a issue, i am just used to management via. a VIP so you allways connect to the active firewall.&lt;/P&gt;</description>
      <pubDate>Mon, 16 May 2022 07:27:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/management-ip-in-active-passive-setup/m-p/487337#M104703</guid>
      <dc:creator>hh_cloudio</dc:creator>
      <dc:date>2022-05-16T07:27:56Z</dc:date>
    </item>
    <item>
      <title>Re: Management IP in Active/passive setup</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/management-ip-in-active-passive-setup/m-p/487376#M104706</link>
      <description>&lt;P&gt;Would you means you want to access current active firewall in same IP independent of which take a active?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can set a loopback interface and set it &lt;SPAN&gt;permits for management traffic&lt;/SPAN&gt;&lt;SPAN&gt;. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Since the passive firewall data-port will not turn on, you will always access to the current active firewall through that loopback interface IP.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;You may refer below link&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-admin/networking/configure-interfaces/use-interface-management-profiles-to-restrict-access" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-admin/networking/configure-interfaces/use-interface-management-profiles-to-restrict-access&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 16 May 2022 09:56:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/management-ip-in-active-passive-setup/m-p/487376#M104706</guid>
      <dc:creator>JoeKwok</dc:creator>
      <dc:date>2022-05-16T09:56:51Z</dc:date>
    </item>
    <item>
      <title>Re: Management IP in Active/passive setup</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/management-ip-in-active-passive-setup/m-p/488568#M104832</link>
      <description>&lt;P&gt;That was just what i was looking for. Thanks!&lt;/P&gt;</description>
      <pubDate>Thu, 19 May 2022 12:50:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/management-ip-in-active-passive-setup/m-p/488568#M104832</guid>
      <dc:creator>hh_cloudio</dc:creator>
      <dc:date>2022-05-19T12:50:24Z</dc:date>
    </item>
    <item>
      <title>Re: Management IP in Active/passive setup</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/management-ip-in-active-passive-setup/m-p/1248265#M126001</link>
      <description>&lt;P&gt;I just stumbled over this. I struggle to understand how this can work. If we configure a loopback interface with an IP address on the passive firewall, how can the traffic via the active firewall reach the loopback? It has to arrive on the passive firewall on a physical port, which all are on Discard.&lt;BR /&gt;We're currently thinking about how to provide emergency management access on both firewalls independently, without unplugging the management port.&lt;/P&gt;</description>
      <pubDate>Mon, 16 Feb 2026 12:27:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/management-ip-in-active-passive-setup/m-p/1248265#M126001</guid>
      <dc:creator>J.Dhling</dc:creator>
      <dc:date>2026-02-16T12:27:43Z</dc:date>
    </item>
  </channel>
</rss>

