<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Switch port configuration for management interface on HA pair in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/switch-port-configuration-for-management-interface-on-ha-pair/m-p/488369#M104808</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/29232"&gt;@SilvioReis&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;The management interface should be an access port, the interface itself doesn't support tagging. Your current design would work perfectly fine, the management IP can be on the same interface as the trust zone without any issues.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 18 May 2022 21:14:49 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2022-05-18T21:14:49Z</dc:date>
    <item>
      <title>Switch port configuration for management interface on HA pair</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/switch-port-configuration-for-management-interface-on-ha-pair/m-p/488301#M104802</link>
      <description>&lt;P&gt;Are there any recomendations or requirements to configure a switch port for management interface for a PA firewall?&lt;/P&gt;&lt;P&gt;Should it be an access port or could it be a 802.1q port (trunk mode)?&lt;/P&gt;&lt;P&gt;Are there any recomendations to enable/disable/specify lldp/cdp/vtp/igmp/spf on switch port for management interface?&lt;/P&gt;&lt;P&gt;If the management interface will be used for backup of HA1 interface/traffic is there any addicional recomendations?&lt;/P&gt;&lt;P&gt;Any problems if ip address of management interface resides on the same subnet of inside/trusted zone/interface on the same firewall/ha pair and default gateway of management interface point to the ip address of inside interface?&lt;/P&gt;&lt;P&gt;I know that it could be an access port or directly connected to a management pc using a regular cat5e/cat6 patchcord.&lt;/P&gt;&lt;P&gt;Thanks,&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PA_mgmt_interface.jpg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/41037i7DDF1AC0F8156EAE/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="PA_mgmt_interface.jpg" alt="PA_mgmt_interface.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 18 May 2022 18:33:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/switch-port-configuration-for-management-interface-on-ha-pair/m-p/488301#M104802</guid>
      <dc:creator>SilvioReis</dc:creator>
      <dc:date>2022-05-18T18:33:38Z</dc:date>
    </item>
    <item>
      <title>Re: Switch port configuration for management interface on HA pair</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/switch-port-configuration-for-management-interface-on-ha-pair/m-p/488366#M104807</link>
      <description>&lt;P&gt;I am not sure about later PaloAlto models, but on mine at least, the dedicated management interface does not support VLAN tagging. You must connect it to an access switch port. Generally, you want the management interface on a separate subnet, accessible only from specific devices. Though I don't believe it will cause any specific errors if it is on the same subnet as the internal Trust zone.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;One thing to make sure of though, is that the HA data and management ports are on a completely separate network, that there are no explicit routes to over the data or management interfaces to the same IP ranges.&lt;/P&gt;</description>
      <pubDate>Wed, 18 May 2022 21:14:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/switch-port-configuration-for-management-interface-on-ha-pair/m-p/488366#M104807</guid>
      <dc:creator>Adrian_Jensen</dc:creator>
      <dc:date>2022-05-18T21:14:06Z</dc:date>
    </item>
    <item>
      <title>Re: Switch port configuration for management interface on HA pair</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/switch-port-configuration-for-management-interface-on-ha-pair/m-p/488369#M104808</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/29232"&gt;@SilvioReis&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;The management interface should be an access port, the interface itself doesn't support tagging. Your current design would work perfectly fine, the management IP can be on the same interface as the trust zone without any issues.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 18 May 2022 21:14:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/switch-port-configuration-for-management-interface-on-ha-pair/m-p/488369#M104808</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2022-05-18T21:14:49Z</dc:date>
    </item>
    <item>
      <title>Re: Switch port configuration for management interface on HA pair</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/switch-port-configuration-for-management-interface-on-ha-pair/m-p/488381#M104813</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I protect my management interface with the Palo Alto in a 'management network'. I create a vlan , lets call it mgmt, and anchor it on the Palo Alto, meaning the vlan IP is on the Palo Alto so i can create security policies to protect it as to who can connect in the first place, .e.g AD group fw_admins are the only ones that can even get into the vlan.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Wed, 18 May 2022 21:58:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/switch-port-configuration-for-management-interface-on-ha-pair/m-p/488381#M104813</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2022-05-18T21:58:17Z</dc:date>
    </item>
  </channel>
</rss>

