<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Routing to/from the Management Interface in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/routing-to-from-the-management-interface/m-p/1204757#M122967</link>
    <description>&lt;P&gt;I have two new PA-455-5G firewalls running 11.2.3. These have 8 ethernet interfaces, two management ports, and two console ports. I have configured the management ports as 10.0.0.1 &amp;amp; .2 respectively on FW1&amp;amp; 2. These will be in A/P HA, so I want to be able to manage the firewalls individually via these management ports. I do NOT want to use one of the 8 ethernet ports.&lt;/P&gt;
&lt;P&gt;I have finished the initial config, and it looks like this:&lt;/P&gt;
&lt;P&gt;Ethernet1/1 Primary internet&lt;/P&gt;
&lt;P&gt;Ethernet1/2 Secondary internet&lt;/P&gt;
&lt;P&gt;Ethernet1/3 (and sub-interfaces) LAN/VLANs&lt;/P&gt;
&lt;P&gt;Ethernet 1/7 HA2&lt;/P&gt;
&lt;P&gt;Ethernet 1/8 HA1 backup&lt;/P&gt;
&lt;P&gt;Management Ports (a.k.a MPs) HA1 (10.0.0.1/29 primary and 10.0.0.2/29 secondary)&lt;/P&gt;
&lt;P&gt;I have a single default router configured, and this FW pair is the primary router for the LAN. I have security policies in place that allow certain VLANs to communicate with the management ports and that rule is being hit as expected when trying to access or ping the MPs, but I cannot get to them at all from the LAN, nor can they get out to the internet (so I can use them as the primary service route.).&lt;/P&gt;
&lt;P&gt;I have tried adding them to the default router, but there does not seem to be a way to do that. I also tried adding a new VLAN for them, but there is also no way to assign the MPs to a VLAN.&lt;/P&gt;
&lt;P&gt;So - How the heck do you get these ports to be accessible from the LAN and allow them to get out to the internet? I cannot find anything in the admin guide that shows this.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 21 Jan 2025 20:30:19 GMT</pubDate>
    <dc:creator>R.Rehart</dc:creator>
    <dc:date>2025-01-21T20:30:19Z</dc:date>
    <item>
      <title>Routing to/from the Management Interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/routing-to-from-the-management-interface/m-p/1204757#M122967</link>
      <description>&lt;P&gt;I have two new PA-455-5G firewalls running 11.2.3. These have 8 ethernet interfaces, two management ports, and two console ports. I have configured the management ports as 10.0.0.1 &amp;amp; .2 respectively on FW1&amp;amp; 2. These will be in A/P HA, so I want to be able to manage the firewalls individually via these management ports. I do NOT want to use one of the 8 ethernet ports.&lt;/P&gt;
&lt;P&gt;I have finished the initial config, and it looks like this:&lt;/P&gt;
&lt;P&gt;Ethernet1/1 Primary internet&lt;/P&gt;
&lt;P&gt;Ethernet1/2 Secondary internet&lt;/P&gt;
&lt;P&gt;Ethernet1/3 (and sub-interfaces) LAN/VLANs&lt;/P&gt;
&lt;P&gt;Ethernet 1/7 HA2&lt;/P&gt;
&lt;P&gt;Ethernet 1/8 HA1 backup&lt;/P&gt;
&lt;P&gt;Management Ports (a.k.a MPs) HA1 (10.0.0.1/29 primary and 10.0.0.2/29 secondary)&lt;/P&gt;
&lt;P&gt;I have a single default router configured, and this FW pair is the primary router for the LAN. I have security policies in place that allow certain VLANs to communicate with the management ports and that rule is being hit as expected when trying to access or ping the MPs, but I cannot get to them at all from the LAN, nor can they get out to the internet (so I can use them as the primary service route.).&lt;/P&gt;
&lt;P&gt;I have tried adding them to the default router, but there does not seem to be a way to do that. I also tried adding a new VLAN for them, but there is also no way to assign the MPs to a VLAN.&lt;/P&gt;
&lt;P&gt;So - How the heck do you get these ports to be accessible from the LAN and allow them to get out to the internet? I cannot find anything in the admin guide that shows this.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jan 2025 20:30:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/routing-to-from-the-management-interface/m-p/1204757#M122967</guid>
      <dc:creator>R.Rehart</dc:creator>
      <dc:date>2025-01-21T20:30:19Z</dc:date>
    </item>
    <item>
      <title>Re: Routing to/from the Management Interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/routing-to-from-the-management-interface/m-p/1205025#M122978</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/714836709"&gt;@R.Rehart&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The mgmt ports are entirely out-of-bound and cannot be added to the VR.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;By using the MGT port, you separate the management functions of the firewall from the data processing functions, safeguarding access to the firewall and enhancing performance:&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Source:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-admin/getting-started/integrate-the-firewall-into-your-management-network" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-admin/getting-started/integrate-the-firewall-into-your-management-network&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Consider the management interface as a standalone host on your network. It connects via a cable from the management port to an access port on the switch, within the management VLAN designated for your network. Like any other network you can route it to a FW-dataport interface to go through the FW and to the internet for which it requires an allow policy and NAT configuration.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps,&lt;/P&gt;
&lt;P&gt;-Kim.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jan 2025 10:56:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/routing-to-from-the-management-interface/m-p/1205025#M122978</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2025-01-22T10:56:27Z</dc:date>
    </item>
    <item>
      <title>Re: Routing to/from the Management Interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/routing-to-from-the-management-interface/m-p/1205352#M123025</link>
      <description>&lt;P&gt;Thanks, Kiwi, but that isn't what I was looking for. I solved the problem by adding a gateway address in the same subnet as the management ports to the default VR and changing their gateway to point there. Now, I can route between the LAN and the management ports without issue.&lt;/P&gt;</description>
      <pubDate>Fri, 24 Jan 2025 15:20:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/routing-to-from-the-management-interface/m-p/1205352#M123025</guid>
      <dc:creator>R.Rehart</dc:creator>
      <dc:date>2025-01-24T15:20:46Z</dc:date>
    </item>
  </channel>
</rss>

