<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Port 4443 in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/port-4443/m-p/86055#M43401</link>
    <description>&lt;P&gt;Hihi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Actually your WEB GUI &amp;nbsp;PA server switched to the port 4443 when you have GP enabled. GP running on the port 443.&lt;/P&gt;</description>
    <pubDate>Tue, 14 Jun 2016 15:54:16 GMT</pubDate>
    <dc:creator>Transporter</dc:creator>
    <dc:date>2016-06-14T15:54:16Z</dc:date>
    <item>
      <title>Port 4443</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/port-4443/m-p/86018#M43400</link>
      <description>&lt;P&gt;It has been&amp;nbsp;noted that our global protect portal is reachable from the internet using port 4443 and is presenting a self signed cert which is seen as a security vulnerability. Can you let me know if port 4443 is necessary in terms of GlobalProtect connectivity?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The below comes to mind, but does anyone have any suggestions?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Management-Articles/How-to-Access-the-WebGUI-when-GlobalProtect-Is-Enabled/ta-p/62399" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Management-Articles/How-to-Access-the-WebGUI-when-GlobalProtect-Is-Enabled/ta-p/62399&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers&lt;/P&gt;
&lt;P&gt;Jack&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jun 2016 15:29:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/port-4443/m-p/86018#M43400</guid>
      <dc:creator>Jack_Howells</dc:creator>
      <dc:date>2016-06-14T15:29:43Z</dc:date>
    </item>
    <item>
      <title>Re: Port 4443</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/port-4443/m-p/86055#M43401</link>
      <description>&lt;P&gt;Hihi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Actually your WEB GUI &amp;nbsp;PA server switched to the port 4443 when you have GP enabled. GP running on the port 443.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jun 2016 15:54:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/port-4443/m-p/86055#M43401</guid>
      <dc:creator>Transporter</dc:creator>
      <dc:date>2016-06-14T15:54:16Z</dc:date>
    </item>
    <item>
      <title>Re: Port 4443</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/port-4443/m-p/86056#M43402</link>
      <description>&lt;P&gt;Okay, thanks for the confirmation.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Port 4443 will be needed then, but is there anything else we could do?&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jun 2016 15:56:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/port-4443/m-p/86056#M43402</guid>
      <dc:creator>Jack_Howells</dc:creator>
      <dc:date>2016-06-14T15:56:21Z</dc:date>
    </item>
    <item>
      <title>Re: Port 4443</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/port-4443/m-p/86057#M43403</link>
      <description>&lt;P&gt;Hi Jack,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;can you please clarify what exactly do you want to achieve?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank,&lt;/P&gt;
&lt;P&gt;Mykhaylo&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jun 2016 15:59:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/port-4443/m-p/86057#M43403</guid>
      <dc:creator>Transporter</dc:creator>
      <dc:date>2016-06-14T15:59:50Z</dc:date>
    </item>
    <item>
      <title>Re: Port 4443</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/port-4443/m-p/86778#M43418</link>
      <description>&lt;P&gt;Hi Mykhaylo,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Basically, I would like to know if port 4443 is needed. I don't think it is, unless you have set the GP portal to be on the management interface, which isn't the case. If it was, I would need 4443 because that is how you get to the management instead of the portal, on the same interface/IP.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers&lt;/P&gt;
&lt;P&gt;Jack&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jun 2016 10:43:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/port-4443/m-p/86778#M43418</guid>
      <dc:creator>Jack_Howells</dc:creator>
      <dc:date>2016-06-15T10:43:18Z</dc:date>
    </item>
    <item>
      <title>Re: Port 4443</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/port-4443/m-p/86786#M43420</link>
      <description>&lt;P&gt;I would definitely not allow firewall management from external interface.&lt;/P&gt;
&lt;P&gt;You can check what management profile is attached to untrust interface if you go to&lt;/P&gt;
&lt;P&gt;Network &amp;gt; Interfaces and check "Management profile" column.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Then go to&lt;/P&gt;
&lt;P&gt;Network &amp;gt; Network Profiles &amp;gt; Interface Mgmt&lt;/P&gt;
&lt;P&gt;And create new profile for wan side or change current one.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you need mgmt access from wan then at least limit it down with security policy to whitelisted IPs.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jun 2016 10:49:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/port-4443/m-p/86786#M43420</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2016-06-15T10:49:19Z</dc:date>
    </item>
    <item>
      <title>Re: Port 4443</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/port-4443/m-p/86793#M43421</link>
      <description>&lt;P&gt;Hi Raido,&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Thanks for your response,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;However, as said above I'm not using management on an external interface.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Cheers&lt;/P&gt;
&lt;P&gt;Jack&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jun 2016 10:53:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/port-4443/m-p/86793#M43421</guid>
      <dc:creator>Jack_Howells</dc:creator>
      <dc:date>2016-06-15T10:53:09Z</dc:date>
    </item>
    <item>
      <title>Re: Port 4443</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/port-4443/m-p/86796#M43423</link>
      <description>&lt;P&gt;If you use globalprotect and have enabled management on same interface then management port jumps from 443 to 4443.&lt;/P&gt;
&lt;P&gt;Are you sure you have not attached interface management profile to untrust interface that permits management through this untrust interface?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jun 2016 10:58:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/port-4443/m-p/86796#M43423</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2016-06-15T10:58:07Z</dc:date>
    </item>
  </channel>
</rss>

