<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: management GUI issue in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/management-gui-issue/m-p/35458#M26037</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;when using any any deny you should be careful not to disconnect any intra traffic so you should add intrazone allow rules.&lt;/P&gt;&lt;P&gt;trust trust allow&lt;/P&gt;&lt;P&gt;dmz dmz allow&lt;/P&gt;&lt;P&gt;any any deny&lt;/P&gt;&lt;P&gt;also you should check what you need to open for untrust to untrust and allow that also(tcp 443 , udp 500 etc..)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 11 Jul 2013 13:10:07 GMT</pubDate>
    <dc:creator>Retired Member</dc:creator>
    <dc:date>2013-07-11T13:10:07Z</dc:date>
    <item>
      <title>management GUI issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/management-gui-issue/m-p/35448#M26027</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I have a PA-200 with PANOS 4.1.13.&lt;/P&gt;&lt;P&gt;After some changes in configuration and after a commit, I lost connection to the management interface and now it is impossible to connect by web GUI.&lt;/P&gt;&lt;P&gt;Only SSH CLI&amp;nbsp; is running. How can I check by CLI what happened ? The system services SSH, HTTPS and PING are enabled and all IP are permitted to connect to management interface. The system process mgmtsrvr is running and the group mgmt_service is running.&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;/TD&gt;&lt;TD&gt;_&lt;/TD&gt;&lt;TD&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Jul 2013 10:05:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/management-gui-issue/m-p/35448#M26027</guid>
      <dc:creator>lauro7</dc:creator>
      <dc:date>2013-07-11T10:05:32Z</dc:date>
    </item>
    <item>
      <title>Re: management GUI issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/management-gui-issue/m-p/35449#M26028</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;try that&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;debug software restart web-server&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Jul 2013 10:12:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/management-gui-issue/m-p/35449#M26028</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-07-11T10:12:49Z</dc:date>
    </item>
    <item>
      <title>Re: management GUI issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/management-gui-issue/m-p/35450#M26029</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have tried, but Web GUI is still not running.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Jul 2013 10:23:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/management-gui-issue/m-p/35450#M26029</guid>
      <dc:creator>lauro7</dc:creator>
      <dc:date>2013-07-11T10:23:50Z</dc:date>
    </item>
    <item>
      <title>Re: management GUI issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/management-gui-issue/m-p/35451#M26030</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;did you try restarting management also ?&lt;/P&gt;&lt;P&gt; debug software restart management-server&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Jul 2013 10:27:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/management-gui-issue/m-p/35451#M26030</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-07-11T10:27:40Z</dc:date>
    </item>
    <item>
      <title>Re: management GUI issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/management-gui-issue/m-p/35452#M26031</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, I tried, but this is the output. I think it is for the cli connection lost.&lt;/P&gt;&lt;P&gt;But GUI is still not running.&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;____________________________________________________&lt;/P&gt;&lt;P&gt;Process 'mgmtsrvr' executing RESTART&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jul 11 12:30:26 Error: pan_read_full(comm_utils.c:97): srvr: fatal recv error. sock=3 err=Connection reset by peer (131)&lt;/P&gt;&lt;P&gt;admin@FW12003&amp;gt;&lt;/P&gt;&lt;P&gt;_____________________________________________________________________________&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Jul 2013 10:35:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/management-gui-issue/m-p/35452#M26031</guid>
      <dc:creator>lauro7</dc:creator>
      <dc:date>2013-07-11T10:35:58Z</dc:date>
    </item>
    <item>
      <title>Re: management GUI issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/management-gui-issue/m-p/35453#M26032</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Two options:&lt;/P&gt;&lt;P&gt;1&amp;gt;You can reload the config version&amp;nbsp; that allowed&amp;nbsp; https&lt;/P&gt;&lt;P&gt;# load config version &amp;lt;version&amp;gt;&lt;/P&gt;&lt;P&gt;#commit&lt;/P&gt;&lt;P&gt;OR&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;2&amp;gt;Try enabling http &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;# set deviceconfig system service disable-http no&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;#commit&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Jul 2013 11:25:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/management-gui-issue/m-p/35453#M26032</guid>
      <dc:creator>UhMayYeah</dc:creator>
      <dc:date>2013-07-11T11:25:33Z</dc:date>
    </item>
    <item>
      <title>Re: management GUI issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/management-gui-issue/m-p/35454#M26033</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;yes that will resolve I missed "After some change" &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Jul 2013 11:27:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/management-gui-issue/m-p/35454#M26033</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-07-11T11:27:30Z</dc:date>
    </item>
    <item>
      <title>Re: management GUI issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/management-gui-issue/m-p/35455#M26034</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I tried http, but the output was this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;H1 style="font-size: 20px; font-weight: bold; color: #196390; font-family: Tahoma, Helvetica, Arial, sans-serif; font-style: normal; text-align: start; text-indent: 0px;"&gt;Web Page Blocked&lt;/H1&gt;&lt;P style="color: #000000; font-family: Tahoma,Helvetica,Arial,sans-serif; font-size: 12px; font-style: normal; font-weight: normal; text-align: start; text-indent: 0px;"&gt;Access to the web page you were trying to visit has been blocked in accordance with company policy. Please contact your system administrator if you believe this is in error.&lt;/P&gt;&lt;P style="color: #000000; font-family: Tahoma,Helvetica,Arial,sans-serif; font-size: 12px; font-style: normal; font-weight: normal; text-align: start; text-indent: 0px;"&gt;&lt;STRONG style="color: #196390;"&gt;User:&lt;/STRONG&gt;&lt;SPAN class="Apple-converted-space"&gt; &lt;/SPAN&gt;192.168.86.167&lt;/P&gt;&lt;P style="color: #000000; font-family: Tahoma,Helvetica,Arial,sans-serif; font-size: 12px; font-style: normal; font-weight: normal; text-align: start; text-indent: 0px;"&gt;&lt;STRONG style="color: #196390;"&gt;URL:&lt;/STRONG&gt;&lt;SPAN class="Apple-converted-space"&gt; &lt;/SPAN&gt;192.168.2.2/&lt;/P&gt;&lt;P style="color: #000000; font-family: Tahoma,Helvetica,Arial,sans-serif; font-size: 12px; font-style: normal; font-weight: normal; text-align: start; text-indent: 0px;"&gt;&lt;STRONG style="color: #196390;"&gt;Category:&lt;/STRONG&gt;&lt;SPAN class="Apple-converted-space"&gt; &lt;/SPAN&gt;private-ip-addresses&lt;/P&gt;&lt;P style="color: #000000; font-family: Tahoma,Helvetica,Arial,sans-serif; font-size: 12px; font-style: normal; font-weight: normal; text-align: start; text-indent: 0px;"&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: Tahoma,Helvetica,Arial,sans-serif; font-size: 12px; font-style: normal; font-weight: normal; text-align: start; text-indent: 0px;"&gt;and that is strange....192.168.2.2 is the management IP address...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Jul 2013 11:40:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/management-gui-issue/m-p/35455#M26034</guid>
      <dc:creator>lauro7</dc:creator>
      <dc:date>2013-07-11T11:40:43Z</dc:date>
    </item>
    <item>
      <title>Re: management GUI issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/management-gui-issue/m-p/35456#M26035</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;goto configure mode&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;set rulebase security rules new from any to any destination 192.168.2.2 action allow&lt;/P&gt;&lt;P&gt;move rulebase security rules new top&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;commit&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Jul 2013 11:47:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/management-gui-issue/m-p/35456#M26035</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-07-11T11:47:04Z</dc:date>
    </item>
    <item>
      <title>Re: management GUI issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/management-gui-issue/m-p/35457#M26036</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Panos,&lt;/P&gt;&lt;P&gt;I have solved with the rule "new" that you suggested. With this rule at top I am able to connect by HTTP and HTTPS.&lt;/P&gt;&lt;P&gt;The problem was that my customer, by himself, introduced a rule at&amp;nbsp; bottom like "deny any any any any...." &lt;/P&gt;&lt;P&gt;after the normal rules to log all traffic denied ("after some changes he said me"&amp;nbsp; &lt;img id="smileywink" class="emoticon emoticon-smileywink" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-wink.png" alt="Smiley Wink" title="Smiley Wink" /&gt;&amp;nbsp; ). He said that in previous PANOS releases ( e.g. 4.1.8) this "deny all rule" worked fine....I don't know...but I suggest him to specify in the deny rule at least one source zone and not any.. any. What is your opinion ?&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Lauro&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Jul 2013 13:03:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/management-gui-issue/m-p/35457#M26036</guid>
      <dc:creator>lauro7</dc:creator>
      <dc:date>2013-07-11T13:03:04Z</dc:date>
    </item>
    <item>
      <title>Re: management GUI issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/management-gui-issue/m-p/35458#M26037</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;when using any any deny you should be careful not to disconnect any intra traffic so you should add intrazone allow rules.&lt;/P&gt;&lt;P&gt;trust trust allow&lt;/P&gt;&lt;P&gt;dmz dmz allow&lt;/P&gt;&lt;P&gt;any any deny&lt;/P&gt;&lt;P&gt;also you should check what you need to open for untrust to untrust and allow that also(tcp 443 , udp 500 etc..)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Jul 2013 13:10:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/management-gui-issue/m-p/35458#M26037</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-07-11T13:10:07Z</dc:date>
    </item>
  </channel>
</rss>

