<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Is there any way to apply multiple interface management profiles in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/is-there-any-way-to-apply-multiple-interface-management-profiles/m-p/591834#M117842</link>
    <description>&lt;P&gt;Don't do https or ssh on an untrust interface! it's too easy to spoof IPs&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Set a public management profile with only ping enabled&lt;/P&gt;
&lt;P&gt;Then create globalprotect portal+gateway to give your staff secure access to your device and have them connect to the management interface, or possibly even a secured loopback interface with management profile&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;and to answer your question: you can only set one mgmt profile per interface&lt;/P&gt;</description>
    <pubDate>Fri, 12 Jul 2024 10:00:38 GMT</pubDate>
    <dc:creator>reaper</dc:creator>
    <dc:date>2024-07-12T10:00:38Z</dc:date>
    <item>
      <title>Is there any way to apply multiple interface management profiles</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-there-any-way-to-apply-multiple-interface-management-profiles/m-p/591789#M117838</link>
      <description>&lt;DIV id="activity_a0d0ae4a97d3ce54598bfba90353afc0" class="sn-card-component sn-card-component_summary sn-card-component_summary_spacing"&gt;
&lt;DIV class="sn-widget sn-widget-textblock state-expanded"&gt;&lt;SPAN class="sn-widget-textblock-body sn-widget-textblock-body_formatted"&gt;I have an interface management profile that allow HTTPS, SSH and PING on an untrust interface for specific IP addresses.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;My ISP cannot monitor this interface because their monitoring IP addresses are not in the list of permitted IP address. I don't want to add their IP addresses because I do not want these IP addresses to have SSH or HTTPS access to this interface. Is there any way to add an addtional interface management profile to that same interface? If not, is there any other way to only allow the IPS pin access to the interface while still allowing my management team to have SSH and HTTPS access?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;What component is affected?&lt;BR /&gt;PA460&lt;BR /&gt;&lt;BR /&gt;What version of firmware are you running on your device?&lt;BR /&gt;10.2.8&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Fri, 12 Jul 2024 05:04:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-there-any-way-to-apply-multiple-interface-management-profiles/m-p/591789#M117838</guid>
      <dc:creator>A.Rith</dc:creator>
      <dc:date>2024-07-12T05:04:28Z</dc:date>
    </item>
    <item>
      <title>Re: Is there any way to apply multiple interface management profiles</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-there-any-way-to-apply-multiple-interface-management-profiles/m-p/591834#M117842</link>
      <description>&lt;P&gt;Don't do https or ssh on an untrust interface! it's too easy to spoof IPs&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Set a public management profile with only ping enabled&lt;/P&gt;
&lt;P&gt;Then create globalprotect portal+gateway to give your staff secure access to your device and have them connect to the management interface, or possibly even a secured loopback interface with management profile&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;and to answer your question: you can only set one mgmt profile per interface&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jul 2024 10:00:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-there-any-way-to-apply-multiple-interface-management-profiles/m-p/591834#M117842</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2024-07-12T10:00:38Z</dc:date>
    </item>
  </channel>
</rss>

