<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Default Management Ports in PAN OS 7.1 in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/default-management-ports-in-pan-os-7-1/m-p/106692#M44830</link>
    <description>&lt;P&gt;Thanks for your response&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Possibly I am doing something wrong then - I configured everything as per the article, except for using 192.168.2.1 as the loopback IP address, and was unable to gain management access via the alternative&amp;nbsp;port.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The WAN address was&amp;nbsp;configured with a /30 (i.e. 1.2.3.4/30).&amp;nbsp;I tested via&amp;nbsp;a laptop connected to the Ethernet Inteferace in the Untrusted zone, configured with an interface address of&amp;nbsp;1.2.3.5/30. When I attempted to access 1.2.3.4:8443,&amp;nbsp;there was no response.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I had a PAT rule in place with&amp;nbsp;using a&amp;nbsp;custom Service object of 8443, and the PAT rule translated the destination to 192.168.2.1:443. There was a Security policy allowing access from the&amp;nbsp;Untrusted to Trusted zones, as per the instructions, and the loopback interface was configured with a Management profile allowing access via HTTPS.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I configured the Etehrnet Interface in the Untrusted zone with the same Management Profiles, I was able to access &lt;A href="https://1.2.3.4:443" target="_blank"&gt;https://1.2.3.4:443&lt;/A&gt;. But I was still&amp;nbsp;unable to access &lt;A href="https://1.2.3.4:8443" target="_blank"&gt;https://1.2.3.4:8443&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there anything obvious I may have overlooked?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sam&lt;/P&gt;</description>
    <pubDate>Wed, 24 Aug 2016 13:36:11 GMT</pubDate>
    <dc:creator>Retired Member</dc:creator>
    <dc:date>2016-08-24T13:36:11Z</dc:date>
    <item>
      <title>Default Management Ports in PAN OS 7.1</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/default-management-ports-in-pan-os-7-1/m-p/106621#M44825</link>
      <description>&lt;P&gt;Hi all&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The standard&amp;nbsp;guide for configuring&amp;nbsp;a PANW Firewall to allow access to HTTPS/SSH etc from the outside has been this link:&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Change-the-Default-Management-Port/ta-p/62333" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Change-the-Default-Management-Port/ta-p/62333&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But with the release of PAN OS 7, the provided instructions no longer work. A loopback interface&amp;nbsp;cannot share an IP address with the management interface.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Given this, what would be the appropriate way to configure Security &amp;amp; NAT policies to allow access to HTTPS&amp;nbsp;management on a non-standard port from an&amp;nbsp;Untrusted interface?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I tried setting the loopback to 192.168.1.2 and 192.168.2.1 (and updating the appropriate Policies of course), but had no luck. Does anyone have&amp;nbsp;any insight to share?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;(FYI: obviously I'm aware of the security implications in allowing access to management via HTTPS over the WAN,&amp;nbsp;this is a temporary requirement to pre-stage devices, send them to site, and&amp;nbsp;configure them remotely once they arrive. When the configuration has been completed,&amp;nbsp;management via the WAN will be disabled)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sam&lt;/P&gt;</description>
      <pubDate>Wed, 24 Aug 2016 11:48:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/default-management-ports-in-pan-os-7-1/m-p/106621#M44825</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2016-08-24T11:48:15Z</dc:date>
    </item>
    <item>
      <title>Re: Default Management Ports in PAN OS 7.1</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/default-management-ports-in-pan-os-7-1/m-p/106645#M44826</link>
      <description>&lt;P&gt;Hi Sam&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This article does not stipulate the IP on the loopback should be the management interface, but I see in the comments this appears to be misleading, I will add a note in the article (the connection is made to the management profile active on the interface on the dataplane rather than a redirect to the physical management interface)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;litteraly any ip on the loopback will do the trick, as long as it is not already assigned to the dataplane or management interfaces and preferably one that is not routed anywhere else in the organization to prevent conflicts&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Aug 2016 12:19:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/default-management-ports-in-pan-os-7-1/m-p/106645#M44826</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2016-08-24T12:19:42Z</dc:date>
    </item>
    <item>
      <title>Re: Default Management Ports in PAN OS 7.1</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/default-management-ports-in-pan-os-7-1/m-p/106646#M44827</link>
      <description>&lt;P&gt;I don't know the answer to your question.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But if you have static IP where you are and on the device you are deploying;&amp;nbsp;just leave MGMT access on 443 and limit it to just your public IP address?&lt;/P&gt;</description>
      <pubDate>Wed, 24 Aug 2016 12:22:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/default-management-ports-in-pan-os-7-1/m-p/106646#M44827</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2016-08-24T12:22:15Z</dc:date>
    </item>
    <item>
      <title>Re: Default Management Ports in PAN OS 7.1</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/default-management-ports-in-pan-os-7-1/m-p/106692#M44830</link>
      <description>&lt;P&gt;Thanks for your response&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Possibly I am doing something wrong then - I configured everything as per the article, except for using 192.168.2.1 as the loopback IP address, and was unable to gain management access via the alternative&amp;nbsp;port.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The WAN address was&amp;nbsp;configured with a /30 (i.e. 1.2.3.4/30).&amp;nbsp;I tested via&amp;nbsp;a laptop connected to the Ethernet Inteferace in the Untrusted zone, configured with an interface address of&amp;nbsp;1.2.3.5/30. When I attempted to access 1.2.3.4:8443,&amp;nbsp;there was no response.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I had a PAT rule in place with&amp;nbsp;using a&amp;nbsp;custom Service object of 8443, and the PAT rule translated the destination to 192.168.2.1:443. There was a Security policy allowing access from the&amp;nbsp;Untrusted to Trusted zones, as per the instructions, and the loopback interface was configured with a Management profile allowing access via HTTPS.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I configured the Etehrnet Interface in the Untrusted zone with the same Management Profiles, I was able to access &lt;A href="https://1.2.3.4:443" target="_blank"&gt;https://1.2.3.4:443&lt;/A&gt;. But I was still&amp;nbsp;unable to access &lt;A href="https://1.2.3.4:8443" target="_blank"&gt;https://1.2.3.4:8443&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there anything obvious I may have overlooked?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sam&lt;/P&gt;</description>
      <pubDate>Wed, 24 Aug 2016 13:36:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/default-management-ports-in-pan-os-7-1/m-p/106692#M44830</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2016-08-24T13:36:11Z</dc:date>
    </item>
    <item>
      <title>Re: Default Management Ports in PAN OS 7.1</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/default-management-ports-in-pan-os-7-1/m-p/106740#M44838</link>
      <description>&lt;P&gt;ok so to make sure i wasn't completely sending you into the woods or anything i did a quick replication, and it works, lemme add some screenshots:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="the external IP of my lab firewall"&gt;&lt;img src="https://live.paloaltonetworks.com/skins/images/2F2A72B3BE70ACC5EBC3E1D7685F5297/responsive_peak/images/image_not_found.png" alt="the external IP of my lab firewall" /&gt;&lt;/span&gt;﻿&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="the loopback interface with a wildly random IP, management profile 'all' and inside the trust zone"&gt;&lt;img src="https://live.paloaltonetworks.com/skins/images/2F2A72B3BE70ACC5EBC3E1D7685F5297/responsive_peak/images/image_not_found.png" alt="the loopback interface with a wildly random IP, management profile 'all' and inside the trust zone" /&gt;&lt;/span&gt;﻿&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="the mgmt profile allowing me http, https ans ssh"&gt;&lt;img src="https://live.paloaltonetworks.com/skins/images/2F2A72B3BE70ACC5EBC3E1D7685F5297/responsive_peak/images/image_not_found.png" alt="the mgmt profile allowing me http, https ans ssh" /&gt;&lt;/span&gt;﻿&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;the NAT rule points at the IP assigned to my external interface on port 7777 and translates to the loopback IP on port 443 (second one for sanity check)&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2 nat rules, the top one to redirect 7777 to ssl, the bottom one as a sanity check to see if normal nat also worked, they both do"&gt;&lt;img src="https://live.paloaltonetworks.com/skins/images/2F2A72B3BE70ACC5EBC3E1D7685F5297/responsive_peak/images/image_not_found.png" alt="2 nat rules, the top one to redirect 7777 to ssl, the bottom one as a sanity check to see if normal nat also worked, they both do" /&gt;&lt;/span&gt;﻿&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="security policy"&gt;&lt;img src="https://live.paloaltonetworks.com/skins/images/2F2A72B3BE70ACC5EBC3E1D7685F5297/responsive_peak/images/image_not_found.png" alt="security policy" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="the interface on 7777"&gt;&lt;img src="https://live.paloaltonetworks.com/skins/images/2F2A72B3BE70ACC5EBC3E1D7685F5297/responsive_peak/images/image_not_found.png" alt="the interface on 7777" /&gt;&lt;/span&gt;﻿&lt;/P&gt;</description>
      <pubDate>Wed, 24 Aug 2016 15:03:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/default-management-ports-in-pan-os-7-1/m-p/106740#M44838</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2016-08-24T15:03:58Z</dc:date>
    </item>
    <item>
      <title>Re: Default Management Ports in PAN OS 7.1</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/default-management-ports-in-pan-os-7-1/m-p/106747#M44840</link>
      <description>&lt;P&gt;Hi Reaper&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the detailed response, I appreciate the assistance&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That looks&amp;nbsp;pretty much like how I set it up, but I'll double-check when I'm back at the office tomorrow and let you know&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hopefully I missed something simple&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks again!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sam&lt;/P&gt;</description>
      <pubDate>Wed, 24 Aug 2016 15:21:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/default-management-ports-in-pan-os-7-1/m-p/106747#M44840</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2016-08-24T15:21:23Z</dc:date>
    </item>
  </channel>
</rss>

