<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Panorama to VM Firewall in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-to-vm-firewall/m-p/571828#M115105</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/77347"&gt;@TomYoung&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;to be honest I never tried this without management profile being attached to an interface, however I think you are right. If Firewall is completely managed by Panorama it should work without it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Pavel&lt;/P&gt;</description>
    <pubDate>Thu, 04 Jan 2024 21:14:42 GMT</pubDate>
    <dc:creator>PavelK</dc:creator>
    <dc:date>2024-01-04T21:14:42Z</dc:date>
    <item>
      <title>Panorama to VM Firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-to-vm-firewall/m-p/571744#M115095</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;
&lt;P&gt;Is it mandatory to configure the Management Interface on firewall if we plan to manage the firewalls via Panorama?&lt;/P&gt;
&lt;P&gt;I am trying to setup connection from the firewall to manage it over the Panorama but unable to get the connection.&lt;/P&gt;
&lt;P&gt;Even TAC was saying it is necessary to have Mgmt interface if we manage it over Panorama. But in Service Policy i can see an option for Panorama to change the interface other than default. So it should work is what i think. Please suggest.&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Sanjay S&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jan 2024 10:15:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panorama-to-vm-firewall/m-p/571744#M115095</guid>
      <dc:creator>Sanjay_Ramaiah</dc:creator>
      <dc:date>2024-01-04T10:15:19Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama to VM Firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-to-vm-firewall/m-p/571760#M115098</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/249853"&gt;@Sanjay_Ramaiah&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I had a few Firewalls where circumstances forced me to use data plane interface instead of management interface to register Firewall to Panorama, so I can confirm from my own experience that it is possible. I do not recall memory to do anything special than making a change in service route to use data plane interface. Can you see any clue any traffic logs?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Pavel&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jan 2024 12:43:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panorama-to-vm-firewall/m-p/571760#M115098</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2024-01-04T12:43:14Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama to VM Firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-to-vm-firewall/m-p/571777#M115101</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/192693"&gt;@PavelK&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;That's good to know.&amp;nbsp; Thank you!&amp;nbsp; Since the management traffic is always initiated by the NGFW, do we even need an Interface Management Profile?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks again,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jan 2024 14:29:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panorama-to-vm-firewall/m-p/571777#M115101</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2024-01-04T14:29:00Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama to VM Firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-to-vm-firewall/m-p/571828#M115105</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/77347"&gt;@TomYoung&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;to be honest I never tried this without management profile being attached to an interface, however I think you are right. If Firewall is completely managed by Panorama it should work without it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Pavel&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jan 2024 21:14:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panorama-to-vm-firewall/m-p/571828#M115105</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2024-01-04T21:14:42Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama to VM Firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-to-vm-firewall/m-p/572502#M115199</link>
      <description>&lt;P&gt;Thanks All, I am still working on this.&lt;/P&gt;
&lt;P&gt;Issue still not resolved but TAC says that it is must to have Mgmt interface configured. But i dont find any document says that it is must to configure the Mgmt interface. Will keep this chain updated.&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Sanjay S&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jan 2024 08:02:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panorama-to-vm-firewall/m-p/572502#M115199</guid>
      <dc:creator>Sanjay_Ramaiah</dc:creator>
      <dc:date>2024-01-10T08:02:25Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama to VM Firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-to-vm-firewall/m-p/572535#M115207</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/249853"&gt;@Sanjay_Ramaiah&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Did you change ALL the service routes to the data plane interface?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jan 2024 12:37:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panorama-to-vm-firewall/m-p/572535#M115207</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2024-01-10T12:37:35Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama to VM Firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-to-vm-firewall/m-p/573452#M115308</link>
      <description>&lt;P&gt;Hi Tom,&lt;/P&gt;
&lt;P&gt;No, not all the service routes but only the DNS, Radius and now Panorama. Whichever is required only those i changed.&lt;/P&gt;
&lt;P&gt;Will that cause an issue at all?&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Sanjay S&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jan 2024 10:48:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panorama-to-vm-firewall/m-p/573452#M115308</guid>
      <dc:creator>Sanjay_Ramaiah</dc:creator>
      <dc:date>2024-01-18T10:48:29Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama to VM Firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-to-vm-firewall/m-p/573463#M115311</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/249853"&gt;@Sanjay_Ramaiah&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Since you do not plan to use the management interface, I will configure all the service routes the same.&amp;nbsp; The service routes you listed should be all you need, but it is not working.&amp;nbsp; Let's see if this makes a difference.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jan 2024 13:43:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panorama-to-vm-firewall/m-p/573463#M115311</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2024-01-18T13:43:02Z</dc:date>
    </item>
  </channel>
</rss>

