<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Traffic going through Management port in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/traffic-going-through-management-port/m-p/228609#M65708</link>
    <description>&lt;P&gt;Hello Otaka,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is a sample of our configuration&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Network-&amp;gt;VirtualRouter1-&amp;gt;Interface ethernet1/1(interface layer3)-&amp;gt;outside (zone to internet)-&amp;gt; ip address: public ip&lt;/P&gt;&lt;P&gt;Network-&amp;gt;VirtualRouter1-&amp;gt;Interface ethernet1/2(interface layer3)-&amp;gt;inside(zone to lan)-&amp;gt;ip address: private ip 192.168.0.x/24&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For Management purposes we have&lt;/P&gt;&lt;P&gt;Device-&amp;gt; Interfaces -&amp;gt; Management-&amp;gt;Ip add 192.168.14.x/24 with a default gateway 192.168.14.1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For some reason, even the traffic that has a default route 0.0.0.0/0 ethernet 1/1 to public ip is being routed to 192.168.14.1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the fast answer.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
    <pubDate>Tue, 28 Aug 2018 17:53:55 GMT</pubDate>
    <dc:creator>the_jonathan</dc:creator>
    <dc:date>2018-08-28T17:53:55Z</dc:date>
    <item>
      <title>Traffic going through Management port</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/traffic-going-through-management-port/m-p/228568#M65695</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We were setting up a PaloAlto Firewall and made all the basic configuration to make a test on the production environment, however when connecting to the production environment, we could see that all the traffic from the PaloAlto firewall was going through the management port and we have already defined the routes with the interface and next hop ip address.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For example if we want to reach the public IP from the provider that is directly connected, the traffic goes to the management port, then traffic goes inside the LAN and it gets stuck there forever.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are only working with static routes and we haven't specifically detailed a route for the management port, the only place where we configured this is in the device-&amp;gt;configuration-&amp;gt;management-&amp;gt;default gateway, but for some reason al the traffic is going over this interface?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Could somebody give some insight?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Tue, 28 Aug 2018 14:48:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/traffic-going-through-management-port/m-p/228568#M65695</guid>
      <dc:creator>the_jonathan</dc:creator>
      <dc:date>2018-08-28T14:48:53Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic going through Management port</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/traffic-going-through-management-port/m-p/228595#M65700</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;From the sounds of it the static routes are pointing at the management port ip address or port. The management port is used just for management, that is why it has its own config under the setup tab.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would start by checking your routes on your other devices and then on the PAN virtual router.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Aug 2018 16:43:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/traffic-going-through-management-port/m-p/228595#M65700</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-08-28T16:43:12Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic going through Management port</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/traffic-going-through-management-port/m-p/228606#M65706</link>
      <description>&lt;P&gt;I assume you mean management traffic - device updates, licensing, etc. and not user traffic.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;By default all management traffic exits via the management interface.&amp;nbsp; If you want it to exit another route, this can be configured via Service Route Configuration (Device -&amp;gt; Setup -&amp;gt; Services)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If it is what you are intending to do, I recommend against having this traffic exit directy to an untrusted network. &amp;nbsp;Instead, have it exit to an internal network, then traverse back through the firewall to be scanned, just in case something nefarious is going on.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Aug 2018 17:31:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/traffic-going-through-management-port/m-p/228606#M65706</guid>
      <dc:creator>JoeAndreini</dc:creator>
      <dc:date>2018-08-28T17:31:50Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic going through Management port</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/traffic-going-through-management-port/m-p/228609#M65708</link>
      <description>&lt;P&gt;Hello Otaka,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is a sample of our configuration&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Network-&amp;gt;VirtualRouter1-&amp;gt;Interface ethernet1/1(interface layer3)-&amp;gt;outside (zone to internet)-&amp;gt; ip address: public ip&lt;/P&gt;&lt;P&gt;Network-&amp;gt;VirtualRouter1-&amp;gt;Interface ethernet1/2(interface layer3)-&amp;gt;inside(zone to lan)-&amp;gt;ip address: private ip 192.168.0.x/24&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For Management purposes we have&lt;/P&gt;&lt;P&gt;Device-&amp;gt; Interfaces -&amp;gt; Management-&amp;gt;Ip add 192.168.14.x/24 with a default gateway 192.168.14.1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For some reason, even the traffic that has a default route 0.0.0.0/0 ethernet 1/1 to public ip is being routed to 192.168.14.1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the fast answer.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Tue, 28 Aug 2018 17:53:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/traffic-going-through-management-port/m-p/228609#M65708</guid>
      <dc:creator>the_jonathan</dc:creator>
      <dc:date>2018-08-28T17:53:55Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic going through Management port</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/traffic-going-through-management-port/m-p/228613#M65712</link>
      <description>&lt;P&gt;Hello Joe,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Im afraid even user traffic is going through management, we are unable to send any type of traffic through the other interfaces.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Tue, 28 Aug 2018 18:21:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/traffic-going-through-management-port/m-p/228613#M65712</guid>
      <dc:creator>the_jonathan</dc:creator>
      <dc:date>2018-08-28T18:21:58Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic going through Management port</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/traffic-going-through-management-port/m-p/228614#M65713</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/96288"&gt;@the_jonathan&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is how to firewall is designed. The management traffic from the firewall by default does not use the routes configured in the virtual router. The virtual router and the management port are kind of comoletely separate routing instances. This makes it possible that traffic from the management port can be routed through your network and then also through your paloalto firewall to apply security profiles and other protections (even though this would be also possible with service routes).&lt;/P&gt;&lt;P&gt;If you want to have the traffic to be sent directly to the internet then you could configure service routes (what I wouldn't recommend). This way the firewall connects for updates, or whatever you configure, directly to that interface that you specify.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Aug 2018 18:23:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/traffic-going-through-management-port/m-p/228614#M65713</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-08-28T18:23:18Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic going through Management port</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/traffic-going-through-management-port/m-p/228616#M65715</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/96288"&gt;@the_jonathan&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;Hello Joe,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Im afraid even user traffic is going through management, we are unable to send any type of traffic through the other interfaces.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Where do you see that usertraffic is routed through the management port?&lt;/P&gt;</description>
      <pubDate>Tue, 28 Aug 2018 18:25:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/traffic-going-through-management-port/m-p/228616#M65715</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-08-28T18:25:00Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic going through Management port</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/traffic-going-through-management-port/m-p/228617#M65716</link>
      <description>&lt;P&gt;Hello Joe,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As an example, when we do a traceroute from the firewall to the google dns 8.8.8.8 (when the firewall was directly connected to ISP), the traceroute showed us that the packet was sent to the gateway of the Management interface and stayed inside of our LAn until the TTL went to 0, because our LAN sent it back to the firewall and so on.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have read the manuals and tried configuring this very basic simple point to point (firewall to isp) connection and still all the traffic is going through management port.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Aug 2018 18:30:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/traffic-going-through-management-port/m-p/228617#M65716</guid>
      <dc:creator>the_jonathan</dc:creator>
      <dc:date>2018-08-28T18:30:17Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic going through Management port</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/traffic-going-through-management-port/m-p/228618#M65717</link>
      <description>&lt;P&gt;Hello &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592"&gt;@Remo&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes, indeed we have seen that management interface is completely on a different "section" of the firewall and we have configured according to the manuals.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am afraid we do not want to send traffic directly to the internet for the services of paloalto, we want it to "go" into our LAN through the management port as it is configured and then pass again through the firewall as standard traffic from the LAN.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Tue, 28 Aug 2018 18:34:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/traffic-going-through-management-port/m-p/228618#M65717</guid>
      <dc:creator>the_jonathan</dc:creator>
      <dc:date>2018-08-28T18:34:20Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic going through Management port</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/traffic-going-through-management-port/m-p/228619#M65718</link>
      <description>&lt;P&gt;unless you traceroute or ping with the source argument, it is management traffic and will go out the management interface.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;traceroute source &amp;lt;source IP address&amp;gt; host 8.8.8.8&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I describe user traffic, I mean traffic from one zone (trusted likely) to another (untrusted likely)&lt;/P&gt;</description>
      <pubDate>Tue, 28 Aug 2018 18:35:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/traffic-going-through-management-port/m-p/228619#M65718</guid>
      <dc:creator>JoeAndreini</dc:creator>
      <dc:date>2018-08-28T18:35:57Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic going through Management port</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/traffic-going-through-management-port/m-p/228642#M65729</link>
      <description>&lt;P&gt;Hello &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/83021"&gt;@JoeAndreini&lt;/a&gt; &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592"&gt;@Remo&lt;/a&gt; and &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you very much for all your support, FYI our issue was pretty stupid, but we saw that the interface had no management profile assigned, therefore no traffic was allowed from any zone to inside the firewall.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Once we assigned a management profile to the interface (with ping enabled) we were able to succesfuly connect ISP provider to PaloAlto Firewall.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks a lot for your support.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Tue, 28 Aug 2018 21:06:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/traffic-going-through-management-port/m-p/228642#M65729</guid>
      <dc:creator>the_jonathan</dc:creator>
      <dc:date>2018-08-28T21:06:25Z</dc:date>
    </item>
  </channel>
</rss>

