<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Question about Management Interface in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/question-about-management-interface/m-p/528219#M109076</link>
    <description>&lt;P&gt;There is no internal passthrough.&lt;/P&gt;
&lt;P&gt;Either connect cable to mgmt port (preferred option) or configure some (preferably internal) dataplane interface with interface management profile (&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-networking-admin/configure-interfaces/use-interface-management-profiles-to-restrict-access" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-networking-admin/configure-interfaces/use-interface-management-profiles-to-restrict-access&lt;/A&gt;).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Management interface cable is preferred because Palo separates dataplane and management plane.&lt;/P&gt;
&lt;P&gt;You can access Palo through physical mgmt port even if firewall dataplane is overloaded.&lt;/P&gt;</description>
    <pubDate>Mon, 23 Jan 2023 20:17:05 GMT</pubDate>
    <dc:creator>Raido_Rattameister</dc:creator>
    <dc:date>2023-01-23T20:17:05Z</dc:date>
    <item>
      <title>Question about Management Interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/question-about-management-interface/m-p/528212#M109073</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My current management IP is set to a private IP and is up and pingable from the PALO ALTO command line. How ever I cannot log onto the management IP via WEB GUI...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Does the management interface correlate to the physical management port on the palo or is there someway to connect to the management IP from a different network? Or can you connect to a passive palo from the web interface somehow? I am trying to upgrade an HA pair with no downtime but I am not finding a way to connect to the PASSIVE unit via the web....&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jan 2023 19:28:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/question-about-management-interface/m-p/528212#M109073</guid>
      <dc:creator>james_savage</dc:creator>
      <dc:date>2023-01-23T19:28:30Z</dc:date>
    </item>
    <item>
      <title>Re: Question about Management Interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/question-about-management-interface/m-p/528215#M109074</link>
      <description>&lt;P&gt;Management interface correlates to physical port on Palo.&lt;/P&gt;
&lt;P&gt;What do you see in traffic log when you try to access management IP?&lt;/P&gt;
&lt;P&gt;Is this traffic permitted in security policy?&lt;/P&gt;
&lt;P&gt;Does management interface have default gateway configured?&lt;/P&gt;
&lt;P&gt;Do you have "permitted IP addresses" configured on management interface?&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jan 2023 19:53:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/question-about-management-interface/m-p/528215#M109074</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2023-01-23T19:53:52Z</dc:date>
    </item>
    <item>
      <title>Re: Question about Management Interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/question-about-management-interface/m-p/528218#M109075</link>
      <description>&lt;P&gt;There is no cable plugged into these ports yet the prior sysadmin has the management interfaced staticly addressed and the address is pingable only by the Palo itself.... is this setup pointless and I need to set up traditional cabled out of band management? Or is there some internal passthrough on the management IP?&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jan 2023 20:11:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/question-about-management-interface/m-p/528218#M109075</guid>
      <dc:creator>james_savage</dc:creator>
      <dc:date>2023-01-23T20:11:35Z</dc:date>
    </item>
    <item>
      <title>Re: Question about Management Interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/question-about-management-interface/m-p/528219#M109076</link>
      <description>&lt;P&gt;There is no internal passthrough.&lt;/P&gt;
&lt;P&gt;Either connect cable to mgmt port (preferred option) or configure some (preferably internal) dataplane interface with interface management profile (&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-networking-admin/configure-interfaces/use-interface-management-profiles-to-restrict-access" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-networking-admin/configure-interfaces/use-interface-management-profiles-to-restrict-access&lt;/A&gt;).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Management interface cable is preferred because Palo separates dataplane and management plane.&lt;/P&gt;
&lt;P&gt;You can access Palo through physical mgmt port even if firewall dataplane is overloaded.&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jan 2023 20:17:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/question-about-management-interface/m-p/528219#M109076</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2023-01-23T20:17:05Z</dc:date>
    </item>
    <item>
      <title>Re: Question about Management Interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/question-about-management-interface/m-p/528220#M109077</link>
      <description>&lt;P&gt;Is this the only way to connect to a passive UNIT in a HA pair? Is via the management interface?&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jan 2023 20:18:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/question-about-management-interface/m-p/528220#M109077</guid>
      <dc:creator>james_savage</dc:creator>
      <dc:date>2023-01-23T20:18:23Z</dc:date>
    </item>
    <item>
      <title>Re: Question about Management Interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/question-about-management-interface/m-p/528243#M109082</link>
      <description>&lt;P&gt;Yes only way to access passive is through mgmt.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jan 2023 00:02:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/question-about-management-interface/m-p/528243#M109082</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2023-01-24T00:02:38Z</dc:date>
    </item>
  </channel>
</rss>

