<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: DNS server can't access to management interface in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/dns-server-can-t-access-to-management-interface/m-p/570270#M114924</link>
    <description>&lt;P&gt;The OP and you have not provided a lot of debugging information, so its a bit difficult to guess, but there are a couple important caveats to check for:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;STRIKE&gt;The management interface IP should never exist on the same subnet as a regular interface on the PA.&lt;/STRIKE&gt;&amp;nbsp;Edit: Actually.. I think I was thinking about the HA interface IP here... management IP might be OK, would have to re-read documentation.&lt;/LI&gt;
&lt;LI&gt;If you have previous made service route configuration changes, look to see if a management destination route has been added (Setup-&amp;gt;Services-&amp;gt;Service Route Configuration-&amp;gt;Destination), you may be forcing traffic to certain destination out other interfaces.&lt;/LI&gt;
&lt;LI&gt;If a separate device is to contact the management interface, verify that the source is allowed as a permitted address if an ACL has been added (Setup-&amp;gt;Interfaces-&amp;gt;Management).&lt;/LI&gt;
&lt;/OL&gt;</description>
    <pubDate>Mon, 18 Dec 2023 19:43:03 GMT</pubDate>
    <dc:creator>Adrian_Jensen</dc:creator>
    <dc:date>2023-12-18T19:43:03Z</dc:date>
    <item>
      <title>DNS server can't access to management interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-server-can-t-access-to-management-interface/m-p/484783#M104453</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't know if this is a normal behavior or not. We have 3 DNS servers.&amp;nbsp;&lt;BR /&gt;DNS_A&lt;BR /&gt;DNS_B&lt;BR /&gt;DNS_C&lt;/P&gt;&lt;P&gt;We are not able to ping or ssh/http to the management interface from the DNS server, if this DNS server is configured as DNS server in the firewall.&lt;/P&gt;&lt;P&gt;When we configure DNS_A and DNS_B as a primary and secondary DNS servers in the firewall, we are not able to ping or access from those DNS servers to the mgmt interface. But DNS_C is able to ping with no problems.&lt;/P&gt;&lt;P&gt;When we configure DNS_A and DNS_C, they are not able to ping, but DNS_B can do it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Why is it? I did a tcpdump and see that all pings arrived to the firewall but there are only replies from fw to the server that is not configured as DNS.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 04 May 2022 11:44:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-server-can-t-access-to-management-interface/m-p/484783#M104453</guid>
      <dc:creator>IsaacCasal</dc:creator>
      <dc:date>2022-05-04T11:44:26Z</dc:date>
    </item>
    <item>
      <title>Re: DNS server can't access to management interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-server-can-t-access-to-management-interface/m-p/484859#M104460</link>
      <description>&lt;P&gt;Hey &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/141917"&gt;@IsaacCasal&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;Are you using default service route for DNS traffic through the management interface, or you are using different service route - either for dns service, or specific destination?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 04 May 2022 13:24:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-server-can-t-access-to-management-interface/m-p/484859#M104460</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2022-05-04T13:24:53Z</dc:date>
    </item>
    <item>
      <title>Re: DNS server can't access to management interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-server-can-t-access-to-management-interface/m-p/484875#M104465</link>
      <description>&lt;P&gt;Hi! Thanks for the reply. The DNS traffic has a custom configuration in service routing, for a specific interface, not the default (management). But if I am not wrong, this is referred to a specific port, in this case service: "dns", so it has to be not only for layer 3 routing, but also port 53 traffic. So it will not affect the ping or ssh, and so on. Am I wrong?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 04 May 2022 13:52:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-server-can-t-access-to-management-interface/m-p/484875#M104465</guid>
      <dc:creator>IsaacCasal</dc:creator>
      <dc:date>2022-05-04T13:52:04Z</dc:date>
    </item>
    <item>
      <title>Re: DNS server can't access to management interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-server-can-t-access-to-management-interface/m-p/569797#M114880</link>
      <description>&lt;P&gt;Was this ever resolved? I am facing the same issue after changing where the GW resided on a switch, but now the GW is on the PA itself and can ping everything except for one of the configured DNS servers&lt;/P&gt;</description>
      <pubDate>Thu, 14 Dec 2023 00:14:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-server-can-t-access-to-management-interface/m-p/569797#M114880</guid>
      <dc:creator>Stephen_Muma</dc:creator>
      <dc:date>2023-12-14T00:14:52Z</dc:date>
    </item>
    <item>
      <title>Re: DNS server can't access to management interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-server-can-t-access-to-management-interface/m-p/570270#M114924</link>
      <description>&lt;P&gt;The OP and you have not provided a lot of debugging information, so its a bit difficult to guess, but there are a couple important caveats to check for:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;STRIKE&gt;The management interface IP should never exist on the same subnet as a regular interface on the PA.&lt;/STRIKE&gt;&amp;nbsp;Edit: Actually.. I think I was thinking about the HA interface IP here... management IP might be OK, would have to re-read documentation.&lt;/LI&gt;
&lt;LI&gt;If you have previous made service route configuration changes, look to see if a management destination route has been added (Setup-&amp;gt;Services-&amp;gt;Service Route Configuration-&amp;gt;Destination), you may be forcing traffic to certain destination out other interfaces.&lt;/LI&gt;
&lt;LI&gt;If a separate device is to contact the management interface, verify that the source is allowed as a permitted address if an ACL has been added (Setup-&amp;gt;Interfaces-&amp;gt;Management).&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Mon, 18 Dec 2023 19:43:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-server-can-t-access-to-management-interface/m-p/570270#M114924</guid>
      <dc:creator>Adrian_Jensen</dc:creator>
      <dc:date>2023-12-18T19:43:03Z</dc:date>
    </item>
  </channel>
</rss>

