<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: What services are used by the Management port? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/what-services-are-used-by-the-management-port/m-p/161664#M52578</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16319"&gt;@kjsocher&lt;/a&gt;&lt;/P&gt;&lt;P&gt;The management port supports the following services by default: HTTP, HTTP OCSP, HTTPS, Telnet, SSH, Ping, SNMP, User-ID, User-ID Syslog Listener SSL, and User-ID Syslog Listener-UDP.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Management-Interface.PNG" style="width: 354px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/9760iF8999D55268F1F88/image-dimensions/354x286/is-moderation-mode/true?v=v2" width="354" height="286" role="button" title="Management-Interface.PNG" alt="Management-Interface.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Additional services using the management port by default can be checked by going to: Setup --&amp;gt; Services --&amp;gt; Service Route Configuration&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Service-Route.PNG" style="width: 500px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/9761i5BAC24B5EA50C6FA/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Service-Route.PNG" alt="Service-Route.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Note that if you have services that you do not want to go through the management port, you can always change it and set it to go through one of your data ports; however, bear in mind that by doing so, that traffic is now going through the data plane instead of the management plane; hence, if that service is critical for your environment and there is a unilateral failure of the data plane that service will no longer be available. Finally, if you decide to put that traffic over the data plane, now you will have to enforce it via specific security rules.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;More details can be found at:&amp;nbsp;&lt;A href="https://www.paloaltonetworks.com/documentation/60/pan-os/pan-os/getting-started/set-up-management-access-to-the-firewall&amp;nbsp;" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/60/pan-os/pan-os/getting-started/set-up-management-access-to-the-firewall&amp;nbsp;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope this helps.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 16 Jun 2017 19:32:55 GMT</pubDate>
    <dc:creator>acc6d0b3610eec313831f7900fdbd235</dc:creator>
    <dc:date>2017-06-16T19:32:55Z</dc:date>
    <item>
      <title>What services are used by the Management port?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-services-are-used-by-the-management-port/m-p/161589#M52563</link>
      <description>&lt;P&gt;We have been tasked to follow the CIS benchmark for our Palo Alto firewalls. One item is to limit access to specific IP addresses for the Management port. That is easy enough if the only thing using the management port was users connecting to manage the firewall itself. My question is what other services use the management port (Panorama, User-ID agents on other servers, HA configurations, external monitoring systems, automation)?&lt;/P&gt;</description>
      <pubDate>Fri, 16 Jun 2017 15:03:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-services-are-used-by-the-management-port/m-p/161589#M52563</guid>
      <dc:creator>kjsocher</dc:creator>
      <dc:date>2017-06-16T15:03:00Z</dc:date>
    </item>
    <item>
      <title>Re: What services are used by the Management port?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-services-are-used-by-the-management-port/m-p/161659#M52576</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Of the list you proved, they all use the management port, HA to a lesser extent on the larger models. May be this will help[ answer your questions?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Panorama, User-ID agents on other servers, HA configurations, external monitoring systems, automation&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Jun 2017 19:11:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-services-are-used-by-the-management-port/m-p/161659#M52576</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2017-06-16T19:11:56Z</dc:date>
    </item>
    <item>
      <title>Re: What services are used by the Management port?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-services-are-used-by-the-management-port/m-p/161664#M52578</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16319"&gt;@kjsocher&lt;/a&gt;&lt;/P&gt;&lt;P&gt;The management port supports the following services by default: HTTP, HTTP OCSP, HTTPS, Telnet, SSH, Ping, SNMP, User-ID, User-ID Syslog Listener SSL, and User-ID Syslog Listener-UDP.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Management-Interface.PNG" style="width: 354px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/9760iF8999D55268F1F88/image-dimensions/354x286/is-moderation-mode/true?v=v2" width="354" height="286" role="button" title="Management-Interface.PNG" alt="Management-Interface.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Additional services using the management port by default can be checked by going to: Setup --&amp;gt; Services --&amp;gt; Service Route Configuration&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Service-Route.PNG" style="width: 500px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/9761i5BAC24B5EA50C6FA/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Service-Route.PNG" alt="Service-Route.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Note that if you have services that you do not want to go through the management port, you can always change it and set it to go through one of your data ports; however, bear in mind that by doing so, that traffic is now going through the data plane instead of the management plane; hence, if that service is critical for your environment and there is a unilateral failure of the data plane that service will no longer be available. Finally, if you decide to put that traffic over the data plane, now you will have to enforce it via specific security rules.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;More details can be found at:&amp;nbsp;&lt;A href="https://www.paloaltonetworks.com/documentation/60/pan-os/pan-os/getting-started/set-up-management-access-to-the-firewall&amp;nbsp;" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/60/pan-os/pan-os/getting-started/set-up-management-access-to-the-firewall&amp;nbsp;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope this helps.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Jun 2017 19:32:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-services-are-used-by-the-management-port/m-p/161664#M52578</guid>
      <dc:creator>acc6d0b3610eec313831f7900fdbd235</dc:creator>
      <dc:date>2017-06-16T19:32:55Z</dc:date>
    </item>
    <item>
      <title>Re: What services are used by the Management port?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-services-are-used-by-the-management-port/m-p/161674#M52580</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16319"&gt;@kjsocher&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When you limit the access on the managemdnt port to specific ip addresses, it really depends on what services you have activated (ssh, https, snmp, ...). But for tje ip addresses you have to configure you only need to specify rhe ones which connect TO the mgmt ip address --&amp;gt; the access list only applies to incoming traffic. Outgoing traffic will still be allowed to dst's which you do not specify. (Panorama connection is also outgoing)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Remo&lt;/P&gt;</description>
      <pubDate>Fri, 16 Jun 2017 19:46:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-services-are-used-by-the-management-port/m-p/161674#M52580</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2017-06-16T19:46:41Z</dc:date>
    </item>
  </channel>
</rss>

