<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How can I only allow specific source address to insert XML-API request in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-only-allow-specific-source-address-to-insert-xml-api/m-p/37204#M27294</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The interface that you are using to log in to the API browser or to put in the API request, you set up an interface management profile on that interface and&amp;nbsp; specify permitted Ip addresses on it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That should help you achieve what you are trying to achieve.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 09 Aug 2013 06:22:51 GMT</pubDate>
    <dc:creator>Chatri</dc:creator>
    <dc:date>2013-08-09T06:22:51Z</dc:date>
    <item>
      <title>How can I only allow specific source address to insert XML-API request</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-only-allow-specific-source-address-to-insert-xml-api/m-p/37202#M27292</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As title, everybody can ask PA and insert the URI to do what they want PA to do if people have the plaintext key and correct URI request.&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;I want to limit the request to only permitted source address, but I cannot find any app-id about it, how can I do?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Sample Wu&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 09 Aug 2013 02:37:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-only-allow-specific-source-address-to-insert-xml-api/m-p/37202#M27292</guid>
      <dc:creator>SampleWu</dc:creator>
      <dc:date>2013-08-09T02:37:44Z</dc:date>
    </item>
    <item>
      <title>Re: How can I only allow specific source address to insert XML-API request</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-only-allow-specific-source-address-to-insert-xml-api/m-p/37203#M27293</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;XML API request on PA interface would be treated as general admin web access ,identified as web-browsing.&lt;/P&gt;&lt;P&gt;If there is a particular data plane interface that is used for XML-API requests ,you could configure Permitted IP through Interface-Management Profile or create an intra-zone rule allowing only a single address for Web-browsing .&lt;/P&gt;&lt;P&gt;Other option would be to create&amp;nbsp; a Custom- HTTP based app for XML api.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 09 Aug 2013 06:22:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-only-allow-specific-source-address-to-insert-xml-api/m-p/37203#M27293</guid>
      <dc:creator>UhMayYeah</dc:creator>
      <dc:date>2013-08-09T06:22:08Z</dc:date>
    </item>
    <item>
      <title>Re: How can I only allow specific source address to insert XML-API request</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-only-allow-specific-source-address-to-insert-xml-api/m-p/37204#M27294</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The interface that you are using to log in to the API browser or to put in the API request, you set up an interface management profile on that interface and&amp;nbsp; specify permitted Ip addresses on it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That should help you achieve what you are trying to achieve.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 09 Aug 2013 06:22:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-only-allow-specific-source-address-to-insert-xml-api/m-p/37204#M27294</guid>
      <dc:creator>Chatri</dc:creator>
      <dc:date>2013-08-09T06:22:51Z</dc:date>
    </item>
    <item>
      <title>Re: How can I only allow specific source address to insert XML-API request</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-only-allow-specific-source-address-to-insert-xml-api/m-p/37205#M27295</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;For dataplane ports create a management profile by going to Network ----&amp;gt;interface management---&amp;gt;&lt;/P&gt;&lt;P&gt;select the services you want and allow permitted ip addresses.&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Capture.JPG" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/7602_Capture.JPG" width="450" /&gt;&lt;/P&gt;&lt;P&gt;Now apply to the interface you are interested on by going to network ----&amp;gt;interfaces&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Capture.JPG" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/7603_Capture.JPG" width="450" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To permit certain ip address on management interface you can go to Device--&amp;gt; setup -&amp;gt; management-&amp;gt;management interface settings.&lt;/P&gt;&lt;P&gt;select the services you want and allow permitted ip addresses.&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Capture.JPG" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/7628_Capture.JPG" width="450" /&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 10 Aug 2013 23:36:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-only-allow-specific-source-address-to-insert-xml-api/m-p/37205#M27295</guid>
      <dc:creator>mbutt</dc:creator>
      <dc:date>2013-08-10T23:36:43Z</dc:date>
    </item>
    <item>
      <title>Re: How can I only allow specific source address to insert XML-API request</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-only-allow-specific-source-address-to-insert-xml-api/m-p/37206#M27296</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, Nadir, Chatri, and mbutt,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm appreciated about your replies, it's helpful.&lt;/P&gt;&lt;P&gt;Besides this way, do we have another way to control who can use the XML-API request ? just like an app-id ?&lt;/P&gt;&lt;P&gt;I want to control it by service port number, but it cannot be.&lt;/P&gt;&lt;P&gt;Because the service port number are tcp/80, tcp/443, or tcp/4443, so that I cannot limit it and seprate the Admin's management and XML-API request.&lt;/P&gt;&lt;P&gt;Is it possible to create an app-id is about XML-API request ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Sample Wu&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 11 Aug 2013 00:49:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-only-allow-specific-source-address-to-insert-xml-api/m-p/37206#M27296</guid>
      <dc:creator>SampleWu</dc:creator>
      <dc:date>2013-08-11T00:49:27Z</dc:date>
    </item>
  </channel>
</rss>

