<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Set Up Data Port for external services in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/set-up-data-port-for-external-services/m-p/20721#M15137</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Guys,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i think you have not understood my question.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I understand that i can set up a dataport to get the updates. However the admin guide suggests that I should configure 2 dataports. So the admin guide basically says:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. Configure one data port, for example, e1, and give it a static IP address, put it in a inside zone for example lets say L3-trust and attach a management profile allowing ping.&lt;/P&gt;&lt;P&gt;2. Configure another data port, for example, e2, which is facing internet. Give it an IP and put it in an external zone lets say L3-Untrust.&lt;/P&gt;&lt;P&gt;3. Confgure a security policy allowing traffic between L3-Trust and L3-Untrust zones.&lt;/P&gt;&lt;P&gt;4. In Service Route Configuration, select the interface e1 for the required services.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now my question is:&lt;/P&gt;&lt;P&gt;Instead of setting up 2 data ports and then allowing traffic between them, can I directly select the external facing port, that is port e2 in above example, and then in the Service Route Configuration, select e2 for the required services, so that I get the updates?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 22 Oct 2014 09:09:53 GMT</pubDate>
    <dc:creator>Neo.The.One</dc:creator>
    <dc:date>2014-10-22T09:09:53Z</dc:date>
    <item>
      <title>Set Up Data Port for external services</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/set-up-data-port-for-external-services/m-p/20717#M15133</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hallo all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am following the document PAN OS 6.0 Admin Guide. Since my management port does not have internet access, I have to setup a data port for external access and updates. So the mentioned document, in the section called "Set Up Network Access for External Services", it is suggested that I should configure 2 ports, one on internal zone say (l3-trust) and one external facing port (in the zone lets say l3-untrust) Then create a security policy to allow traffic between these 2 zones and if needed create a NAT policy. &lt;/P&gt;&lt;P&gt;However, I have only one port on FW available and I have&amp;nbsp; public IP for that. So can I just configure that port into an external facing zone and change the "Service Route Configuration" in the FW to get updates via this configured data port? Will this work?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks a lot!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 Oct 2014 08:12:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/set-up-data-port-for-external-services/m-p/20717#M15133</guid>
      <dc:creator>Neo.The.One</dc:creator>
      <dc:date>2014-10-22T08:12:32Z</dc:date>
    </item>
    <item>
      <title>Re: Set Up Data Port for external services</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/set-up-data-port-for-external-services/m-p/20718#M15134</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Amit,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You have to select a physical port &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;( &lt;/SPAN&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;dataplane&lt;/SPAN&gt; &lt;/SPAN&gt;interface) in order to get &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;management access&lt;/SPAN&gt;&lt;/SPAN&gt; through a data-plane interface. Belo mentioned documents will help you for the same.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-6167"&gt;Setting a Service Route for Services to Use a Dataplane Interface from the Web UI and CLI&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-7650"&gt;How To Verify If Service Routes Are Correctly Installed in Management Plane&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 Oct 2014 08:34:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/set-up-data-port-for-external-services/m-p/20718#M15134</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-10-22T08:34:01Z</dc:date>
    </item>
    <item>
      <title>Re: Set Up Data Port for external services</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/set-up-data-port-for-external-services/m-p/20719#M15135</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Amit,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes you can use the dataplane port to use it for updates. All you have to do is to setup service routes for whatever updates you need, to use that dataplane interface. Please ensure the following:&lt;/P&gt;&lt;P&gt;-your DNS can resolve to updates.paloaltonetworks.com, &lt;/P&gt;&lt;P&gt;-There is no deny all rule which can block this traffic&lt;/P&gt;&lt;P&gt;-Any upstream device via that interface must allow access on port 443.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please refer to the above document referred by Hulk for assistance with service route.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Dileep&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 Oct 2014 08:59:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/set-up-data-port-for-external-services/m-p/20719#M15135</guid>
      <dc:creator>dreputi</dc:creator>
      <dc:date>2014-10-22T08:59:56Z</dc:date>
    </item>
    <item>
      <title>Re: Set Up Data Port for external services</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/set-up-data-port-for-external-services/m-p/20720#M15136</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Amit,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please make sure you have configured DNS with the service route through the data-plane interface. Because the URL &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;( &lt;/SPAN&gt;updates.paloaltonetworks.com) will first resolve to an IP address from the DNS then it will try to reach the Palo Alto Update server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 Oct 2014 09:00:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/set-up-data-port-for-external-services/m-p/20720#M15136</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-10-22T09:00:20Z</dc:date>
    </item>
    <item>
      <title>Re: Set Up Data Port for external services</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/set-up-data-port-for-external-services/m-p/20721#M15137</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Guys,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i think you have not understood my question.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I understand that i can set up a dataport to get the updates. However the admin guide suggests that I should configure 2 dataports. So the admin guide basically says:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. Configure one data port, for example, e1, and give it a static IP address, put it in a inside zone for example lets say L3-trust and attach a management profile allowing ping.&lt;/P&gt;&lt;P&gt;2. Configure another data port, for example, e2, which is facing internet. Give it an IP and put it in an external zone lets say L3-Untrust.&lt;/P&gt;&lt;P&gt;3. Confgure a security policy allowing traffic between L3-Trust and L3-Untrust zones.&lt;/P&gt;&lt;P&gt;4. In Service Route Configuration, select the interface e1 for the required services.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now my question is:&lt;/P&gt;&lt;P&gt;Instead of setting up 2 data ports and then allowing traffic between them, can I directly select the external facing port, that is port e2 in above example, and then in the Service Route Configuration, select e2 for the required services, so that I get the updates?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 Oct 2014 09:09:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/set-up-data-port-for-external-services/m-p/20721#M15137</guid>
      <dc:creator>Neo.The.One</dc:creator>
      <dc:date>2014-10-22T09:09:53Z</dc:date>
    </item>
    <item>
      <title>Re: Set Up Data Port for external services</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/set-up-data-port-for-external-services/m-p/20722#M15138</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, you can do it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 Oct 2014 09:13:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/set-up-data-port-for-external-services/m-p/20722#M15138</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-10-22T09:13:59Z</dc:date>
    </item>
    <item>
      <title>Re: Set Up Data Port for external services</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/set-up-data-port-for-external-services/m-p/20723#M15139</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Amit,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As per the Admin-guide, it is suggested to configure an internal interface &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;( &lt;/SPAN&gt;trust-L3) with &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;an&lt;/SPAN&gt; management profile for below mentioned reasons.&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&amp;gt; More visibility on traffic, passing through the firewall. You need to configure a security policy from Trust-L3 to Untrust-L3 &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;( &lt;/SPAN&gt;if you select Untrust L3, no security policy require in this case. Since intra zone traffic will be allowed by default, until you have a DENY_ALL rule at the bottom)&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&amp;gt; Not to configure a management profile on the public facing interface, which potentially cause a DOS attack on your firewall. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&amp;gt; Specific NAT rule "from zone TRUST-L3 to Untrust L3", instead of "ANY to Untrust L-3"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;Hope this helps.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;Thanks&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 Oct 2014 09:21:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/set-up-data-port-for-external-services/m-p/20723#M15139</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-10-22T09:21:00Z</dc:date>
    </item>
    <item>
      <title>Re: Set Up Data Port for external services</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/set-up-data-port-for-external-services/m-p/20724#M15140</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If there are any issues while using management interface then you can always look at the logs under&lt;/P&gt;&lt;P&gt;&amp;gt; tail follow yes mp-log ms.log&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 Oct 2014 17:55:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/set-up-data-port-for-external-services/m-p/20724#M15140</guid>
      <dc:creator>Mystique</dc:creator>
      <dc:date>2014-10-27T17:55:51Z</dc:date>
    </item>
  </channel>
</rss>

