<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Is it possible to enable DHCP-Server on Management Interface? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-enable-dhcp-server-on-management-interface/m-p/7894#M5829</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have been pondering on this question since you wrote it. Why do you need DHCP on the management interface.&amp;nbsp; What is wrong with a crossover cable with a static IP on the laptop, if you need to talk to the mgmt interface. As the other person commented, DHCP services are limited to the dataplane ports, not the mgmt plane, so you cannot set one up.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 29 Mar 2013 19:34:53 GMT</pubDate>
    <dc:creator>scantwell</dc:creator>
    <dc:date>2013-03-29T19:34:53Z</dc:date>
    <item>
      <title>Is it possible to enable DHCP-Server on Management Interface?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-enable-dhcp-server-on-management-interface/m-p/7891#M5826</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, I would like to know, if there is a way to enable DHCP-Server on management interface? We are using another interface for management so we could enable DHCP-Server on the dedicated management interface. In case of need we can establish a physical connection between the management interface and a laptop.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Mar 2013 10:24:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-enable-dhcp-server-on-management-interface/m-p/7891#M5826</guid>
      <dc:creator>KaiGrunewald</dc:creator>
      <dc:date>2013-03-18T10:24:03Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to enable DHCP-Server on Management Interface?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-enable-dhcp-server-on-management-interface/m-p/7892#M5827</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A DHCP server, and other services, can only be enabled on the dataplane interfaces so the dedicated mgmt port cannot be used to run services.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;Tom&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Mar 2013 11:05:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-enable-dhcp-server-on-management-interface/m-p/7892#M5827</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2013-03-18T11:05:40Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to enable DHCP-Server on Management Interface?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-enable-dhcp-server-on-management-interface/m-p/7893#M5828</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Wouldnt this be a valid workaround (sort of)?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) Create a management profile and attach this to a dataplane interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) Create a dhcp server configuration and attach this to the same dataplane interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3) Connect client to this specific dataplane interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Of course you will lose the gui in case dataplane malfunctions but you can still use the dedicated mgmt interface if this occurs (that is connect two interfaces to your mgmt-vlan).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Mar 2013 17:36:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-enable-dhcp-server-on-management-interface/m-p/7893#M5828</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2013-03-18T17:36:46Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to enable DHCP-Server on Management Interface?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-enable-dhcp-server-on-management-interface/m-p/7894#M5829</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have been pondering on this question since you wrote it. Why do you need DHCP on the management interface.&amp;nbsp; What is wrong with a crossover cable with a static IP on the laptop, if you need to talk to the mgmt interface. As the other person commented, DHCP services are limited to the dataplane ports, not the mgmt plane, so you cannot set one up.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 29 Mar 2013 19:34:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-enable-dhcp-server-on-management-interface/m-p/7894#M5829</guid>
      <dc:creator>scantwell</dc:creator>
      <dc:date>2013-03-29T19:34:53Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to enable DHCP-Server on Management Interface?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-enable-dhcp-server-on-management-interface/m-p/7895#M5830</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I guess DHCP is handy if you have more than one admin client, on the other hand using fixed ip's makes it slightly harder for an attacker (with dhcp you can just plugin any device, with fixed ip you need to know which network is being used).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 29 Mar 2013 21:39:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-enable-dhcp-server-on-management-interface/m-p/7895#M5830</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2013-03-29T21:39:33Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to enable DHCP-Server on Management Interface?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-enable-dhcp-server-on-management-interface/m-p/7896#M5831</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, of course there are many ways and workarounds to handle this. The reason for my question is to make it easier for our admins to connect to the device in case of loosing any other connection. (I haven't tried so far, but I think it is possible to deny the access through policy rules??) So, if I could use DHCP on management interface I could easily plug in my notebook and get a new connection without rembering IP-settings on this interface. It is more or less playing around, we will use it without DHCP on management interface. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Apr 2013 13:51:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-enable-dhcp-server-on-management-interface/m-p/7896#M5831</guid>
      <dc:creator>KaiGrunewald</dc:creator>
      <dc:date>2013-04-02T13:51:49Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to enable DHCP-Server on Management Interface?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-enable-dhcp-server-on-management-interface/m-p/7897#M5832</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In that case I would setup static ip on the mgmt interface and connect that to your mgmt network and at the same time create a management profile which only allows ssh/https/ping and connect that to a dedicated dataplane interface (like the last one or so) along with setup a dhcp server profile which you attach to the same dedicated dataplane interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dont forget to put this in its own VSYS if possible (along with its own VROUTER).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This way your technician(s) can use either the dedicated mgmt-network OR connect directly to the PA device on the last dataplane interface (or which one you choose) by DHCP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Another method is to simply use static ip on the mgmt dataplane interface (along with VSYS and VROUTER) - this way your technician(s) knows that last interface always uses 10.0.0.1/24 (or whatever) and is for mgmt being directly attached when you have physical access to the box.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The point of VSYS/VROUTER is to isolate it as much as possible from the other dataplane interfaces.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Apr 2013 14:50:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-enable-dhcp-server-on-management-interface/m-p/7897#M5832</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2013-04-02T14:50:29Z</dc:date>
    </item>
  </channel>
</rss>

