<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Restricted access to API? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/restricted-access-to-api/m-p/69758#M40377</link>
    <description>&lt;P&gt;Hi Xavier&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;in the Management Interface Settings you can control which IP addresses or subnets are permitted to connect to the firewall interface.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/1729iF4CCF4C2E160B2A8/image-size/original?v=mpbl-1&amp;amp;px=-1" border="0" alt="2015-12-22_15-30-49.png" title="2015-12-22_15-30-49.png" /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;you can then prevent individual administrator accounts from accessing the API by creating an admin role&lt;/P&gt;
&lt;P&gt;(so the best practice here is to not share &lt;EM&gt;your&lt;/EM&gt; API key, as this is linked to your account and grants access to the API)&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/1730iC88353D8E2052309/image-size/original?v=mpbl-1&amp;amp;px=-1" border="0" alt="2015-12-22_15-36-32.png" title="2015-12-22_15-36-32.png" /&gt;&lt;/P&gt;
&lt;P&gt;and then create new admins with that role&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/1731i17A5EDB4823CD6C6/image-size/original?v=mpbl-1&amp;amp;px=-1" border="0" alt="2015-12-22_15-42-04.png" title="2015-12-22_15-42-04.png" /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;any interface that has management features enabled (mgmt interface or dataplane interface with management profile) will also respond to API if the IP is permitted to connect to any management feature&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;hope this helps&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
    <pubDate>Tue, 22 Dec 2015 14:43:28 GMT</pubDate>
    <dc:creator>reaper</dc:creator>
    <dc:date>2015-12-22T14:43:28Z</dc:date>
    <item>
      <title>Restricted access to API?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/restricted-access-to-api/m-p/69755#M40376</link>
      <description>&lt;P&gt;Hi *,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'd like to know if it's possible to restrict access to the API? (ex: to some IP addresses).&lt;/P&gt;
&lt;P&gt;Example: if remote management is allowed from 192.168.0.0/24, is it possible to restrict the API usage to 192.168.0.1 by example?&lt;/P&gt;
&lt;P&gt;Is it an option to dedicate a specific IP address to the answer to API requests?&lt;/P&gt;
&lt;P&gt;What are the best practices to prevent an API key to be used by another host to access the firewall?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;KR,&lt;/P&gt;
&lt;P&gt;/x&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Dec 2015 14:21:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/restricted-access-to-api/m-p/69755#M40376</guid>
      <dc:creator>XavierMe</dc:creator>
      <dc:date>2015-12-22T14:21:53Z</dc:date>
    </item>
    <item>
      <title>Re: Restricted access to API?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/restricted-access-to-api/m-p/69758#M40377</link>
      <description>&lt;P&gt;Hi Xavier&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;in the Management Interface Settings you can control which IP addresses or subnets are permitted to connect to the firewall interface.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/1729iF4CCF4C2E160B2A8/image-size/original?v=mpbl-1&amp;amp;px=-1" border="0" alt="2015-12-22_15-30-49.png" title="2015-12-22_15-30-49.png" /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;you can then prevent individual administrator accounts from accessing the API by creating an admin role&lt;/P&gt;
&lt;P&gt;(so the best practice here is to not share &lt;EM&gt;your&lt;/EM&gt; API key, as this is linked to your account and grants access to the API)&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/1730iC88353D8E2052309/image-size/original?v=mpbl-1&amp;amp;px=-1" border="0" alt="2015-12-22_15-36-32.png" title="2015-12-22_15-36-32.png" /&gt;&lt;/P&gt;
&lt;P&gt;and then create new admins with that role&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/1731i17A5EDB4823CD6C6/image-size/original?v=mpbl-1&amp;amp;px=-1" border="0" alt="2015-12-22_15-42-04.png" title="2015-12-22_15-42-04.png" /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;any interface that has management features enabled (mgmt interface or dataplane interface with management profile) will also respond to API if the IP is permitted to connect to any management feature&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;hope this helps&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Tue, 22 Dec 2015 14:43:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/restricted-access-to-api/m-p/69758#M40377</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2015-12-22T14:43:28Z</dc:date>
    </item>
    <item>
      <title>Re: Restricted access to API?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/restricted-access-to-api/m-p/151750#M50229</link>
      <description>&lt;P&gt;Has the thought been made to allow admins to restrict an API account to certain commands? For example API accounts built for dynamic address groups but you don't want them to be able to run any other commands..?&lt;/P&gt;</description>
      <pubDate>Fri, 07 Apr 2017 16:49:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/restricted-access-to-api/m-p/151750#M50229</guid>
      <dc:creator>Gun-Slinger</dc:creator>
      <dc:date>2017-04-07T16:49:14Z</dc:date>
    </item>
    <item>
      <title>Re: Restricted access to API?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/restricted-access-to-api/m-p/151782#M50237</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/5588"&gt;@Gun-Slinger&lt;/a&gt;&amp;nbsp;I would put in a future request for it and see if it maybe already has a request in place for it. Currently you only have the ability to lock down the api so that they have the right to perform different types of request.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Apr 2017 18:52:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/restricted-access-to-api/m-p/151782#M50237</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-04-07T18:52:50Z</dc:date>
    </item>
    <item>
      <title>Re: Restricted access to API?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/restricted-access-to-api/m-p/151810#M50249</link>
      <description>&lt;P&gt;Feature Request Submitted. If anyone else is looking for this feature please have your SE vote for the following:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;FR ID:&lt;/STRONG&gt; 7154&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 08 Apr 2017 14:51:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/restricted-access-to-api/m-p/151810#M50249</guid>
      <dc:creator>Gun-Slinger</dc:creator>
      <dc:date>2017-04-08T14:51:39Z</dc:date>
    </item>
  </channel>
</rss>

