<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Able to ping management interface but cannot get GUI (over secure IPsec connection) in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/able-to-ping-management-interface-but-cannot-get-gui-over-secure/m-p/248584#M70703</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;, thanks for the reply! Turned out it was a policy in Policies &amp;gt; Security, which we called "Access from Remote" (which isn't actually remote, but a remote computer on the same LAN we wanted access from). Under Application it had "Ping" which I changed to "Any". Now I am able to ping AND access the web GUI (I assume SSH will work now as well).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Question - how much of a security hole is this? What else should I do to secure it even more? I understand having the Mgmt port completely closed off will do the trick - but its a remote office so need to be able to run configurations (and we are not using Panorama)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Many thanks&lt;/P&gt;&lt;P&gt;Kay&lt;/P&gt;</description>
    <pubDate>Sat, 02 Feb 2019 12:05:45 GMT</pubDate>
    <dc:creator>kay.sammer</dc:creator>
    <dc:date>2019-02-02T12:05:45Z</dc:date>
    <item>
      <title>Able to ping management interface but cannot get GUI (over secure IPsec connection)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/able-to-ping-management-interface-but-cannot-get-gui-over-secure/m-p/248513#M70672</link>
      <description>&lt;P&gt;Have a PA820 connected to a remote machine via IPsec tunnel - Management port has been opened up to access over LAN (works) - and can ping the Management IP over the tunnel - but am not able to connect to the web GUI. Any pointers?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Many thanks in advance!&lt;/P&gt;</description>
      <pubDate>Fri, 01 Feb 2019 17:59:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/able-to-ping-management-interface-but-cannot-get-gui-over-secure/m-p/248513#M70672</guid>
      <dc:creator>kay.sammer</dc:creator>
      <dc:date>2019-02-01T17:59:19Z</dc:date>
    </item>
    <item>
      <title>Re: Able to ping management interface but cannot get GUI (over secure IPsec connection)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/able-to-ping-management-interface-but-cannot-get-gui-over-secure/m-p/248532#M70680</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Check the logs to see why/if traffic is getting blocked.&amp;nbsp;Did you set restrictions of&amp;nbsp;'Permitted IP Addresses' can connect to the Mgmt interface?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just a few thoughts.&lt;/P&gt;</description>
      <pubDate>Fri, 01 Feb 2019 21:31:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/able-to-ping-management-interface-but-cannot-get-gui-over-secure/m-p/248532#M70680</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2019-02-01T21:31:03Z</dc:date>
    </item>
    <item>
      <title>Re: Able to ping management interface but cannot get GUI (over secure IPsec connection)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/able-to-ping-management-interface-but-cannot-get-gui-over-secure/m-p/248584#M70703</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;, thanks for the reply! Turned out it was a policy in Policies &amp;gt; Security, which we called "Access from Remote" (which isn't actually remote, but a remote computer on the same LAN we wanted access from). Under Application it had "Ping" which I changed to "Any". Now I am able to ping AND access the web GUI (I assume SSH will work now as well).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Question - how much of a security hole is this? What else should I do to secure it even more? I understand having the Mgmt port completely closed off will do the trick - but its a remote office so need to be able to run configurations (and we are not using Panorama)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Many thanks&lt;/P&gt;&lt;P&gt;Kay&lt;/P&gt;</description>
      <pubDate>Sat, 02 Feb 2019 12:05:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/able-to-ping-management-interface-but-cannot-get-gui-over-secure/m-p/248584#M70703</guid>
      <dc:creator>kay.sammer</dc:creator>
      <dc:date>2019-02-02T12:05:45Z</dc:date>
    </item>
    <item>
      <title>Re: Able to ping management interface but cannot get GUI (over secure IPsec connection)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/able-to-ping-management-interface-but-cannot-get-gui-over-secure/m-p/248589#M70708</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/106177"&gt;@kay.sammer&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Well your effectively authorizing that one device to do whatever it wants to the management port of your firewall, which wouldn't be exactly something I would call best practice.&lt;/P&gt;&lt;P&gt;I would modify this security policy so the application is [ ping ssh ssl panos-web-interface ], and then I would only the necissary IPs that need to access this device under Permitted IPs so that no other device can contact the management interface.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 02 Feb 2019 15:12:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/able-to-ping-management-interface-but-cannot-get-gui-over-secure/m-p/248589#M70708</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2019-02-02T15:12:49Z</dc:date>
    </item>
    <item>
      <title>Re: Able to ping management interface but cannot get GUI (over secure IPsec connection)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/able-to-ping-management-interface-but-cannot-get-gui-over-secure/m-p/248615#M70721</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I agree with&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;on locking it down.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers!&lt;/P&gt;</description>
      <pubDate>Sun, 03 Feb 2019 00:50:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/able-to-ping-management-interface-but-cannot-get-gui-over-secure/m-p/248615#M70721</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2019-02-03T00:50:38Z</dc:date>
    </item>
    <item>
      <title>Re: Able to ping management interface but cannot get GUI (over secure IPsec connection)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/able-to-ping-management-interface-but-cannot-get-gui-over-secure/m-p/384394#M90036</link>
      <description>&lt;P&gt;I have 2 3260 Palo Alto firewalls in 2 data centers. I configured GRE tunnels between 2 Arista Switches and they are in front of Firewalls. I configured OSPF routing protocol. All prefixes are learned by OSPF. Both Firewalls can ping each other of management interfaces. GUI and SSH are not working remotely. I researched but not able to find the right solution. Please reply if you have any solution for this issue.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Feb 2021 02:46:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/able-to-ping-management-interface-but-cannot-get-gui-over-secure/m-p/384394#M90036</guid>
      <dc:creator>Mrahman1</dc:creator>
      <dc:date>2021-02-08T02:46:48Z</dc:date>
    </item>
  </channel>
</rss>

