<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Mgmt Traffic through VPN Tunnel in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/mgmt-traffic-through-vpn-tunnel/m-p/20673#M15099</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have a fairly straightforward network topology for a firewall at a remote datacenter with one little catch. The PAN's revenue interfaces are an Internet interface, an internal interface, a DMZ interface, and a device management network. The catch is the PAN's MGMT interface lies on the device mangement network for which it is also the default router. For example, it's ethernet1/4 is 10.254.10.1/25 and it's MGMT interface is 10.254.10.4/25.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Oh, and another little catch, this being a remote datacenter, we talk to that device mangement network over a VPN that terminates on the PAN itslef.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So the problem is that I cannot reach the PAN on its MGMT interface or have it talk to our Panorama server over the VPN.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would prefer to still use the MGMT interface for system management. I would expect there may be others in the same or similar situations. How do you manage and use Panorama with your PAN over a VPN that terminates on the PAN itself? Pointers to vendor docs or your own experiences would be appreciated. Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 14 Jul 2011 20:40:14 GMT</pubDate>
    <dc:creator>cosx</dc:creator>
    <dc:date>2011-07-14T20:40:14Z</dc:date>
    <item>
      <title>Mgmt Traffic through VPN Tunnel</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/mgmt-traffic-through-vpn-tunnel/m-p/20673#M15099</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have a fairly straightforward network topology for a firewall at a remote datacenter with one little catch. The PAN's revenue interfaces are an Internet interface, an internal interface, a DMZ interface, and a device management network. The catch is the PAN's MGMT interface lies on the device mangement network for which it is also the default router. For example, it's ethernet1/4 is 10.254.10.1/25 and it's MGMT interface is 10.254.10.4/25.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Oh, and another little catch, this being a remote datacenter, we talk to that device mangement network over a VPN that terminates on the PAN itslef.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So the problem is that I cannot reach the PAN on its MGMT interface or have it talk to our Panorama server over the VPN.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would prefer to still use the MGMT interface for system management. I would expect there may be others in the same or similar situations. How do you manage and use Panorama with your PAN over a VPN that terminates on the PAN itself? Pointers to vendor docs or your own experiences would be appreciated. Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Jul 2011 20:40:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/mgmt-traffic-through-vpn-tunnel/m-p/20673#M15099</guid>
      <dc:creator>cosx</dc:creator>
      <dc:date>2011-07-14T20:40:14Z</dc:date>
    </item>
    <item>
      <title>Re: Mgmt Traffic through VPN Tunnel</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/mgmt-traffic-through-vpn-tunnel/m-p/20674#M15100</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It should work, can you check the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) If any of the security policy is not blocking the connection between the Internal zone and the VPN zone &lt;/P&gt;&lt;P&gt;2) If you are not able check it through the Monitor logs, please add a deny rule at the end and check if any logs generated&lt;/P&gt;&lt;P&gt;3) See if you can add the Mac address of the management interface statically to the internal interface &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Khubaib &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Jul 2011 23:29:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/mgmt-traffic-through-vpn-tunnel/m-p/20674#M15100</guid>
      <dc:creator>kalavi</dc:creator>
      <dc:date>2011-07-14T23:29:05Z</dc:date>
    </item>
  </channel>
</rss>

