<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Natting Palo Alto's Management Address? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/natting-palo-alto-s-management-address/m-p/251930#M71632</link>
    <description>&lt;P&gt;but do you not already have outgoing (trust to untrust) NAT in place for your outgoing traffic.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;if so then i would have assumed that your local routing would have pushed&amp;nbsp; outgoing traffic from management interface via this route.&lt;/P&gt;</description>
    <pubDate>Fri, 01 Mar 2019 15:58:23 GMT</pubDate>
    <dc:creator>Mick_Ball</dc:creator>
    <dc:date>2019-03-01T15:58:23Z</dc:date>
    <item>
      <title>Natting Palo Alto's Management Address?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/natting-palo-alto-s-management-address/m-p/251916#M71628</link>
      <description>&lt;P&gt;Hello.&amp;nbsp; I currently have the management interface on my PA configured with a IP address on my outside/untrusted network.&amp;nbsp; I would like to change the management address to an IP on one of my inside/trusted networks.&amp;nbsp; When I change my management address, how do I&amp;nbsp;configure NAT for this new management address to allow access to outside for Panorama, Palo Alto Network Services, etc. ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Fri, 01 Mar 2019 14:22:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/natting-palo-alto-s-management-address/m-p/251916#M71628</guid>
      <dc:creator>JoelGuy</dc:creator>
      <dc:date>2019-03-01T14:22:25Z</dc:date>
    </item>
    <item>
      <title>Re: Natting Palo Alto's Management Address?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/natting-palo-alto-s-management-address/m-p/251927#M71629</link>
      <description>&lt;P&gt;I'm not sure if i understood your question fully but why dont you just go into device\services\service route config and change your external services to your external interface, i assume they already work on that interface....&lt;/P&gt;</description>
      <pubDate>Fri, 01 Mar 2019 15:45:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/natting-palo-alto-s-management-address/m-p/251927#M71629</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2019-03-01T15:45:06Z</dc:date>
    </item>
    <item>
      <title>Re: Natting Palo Alto's Management Address?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/natting-palo-alto-s-management-address/m-p/251929#M71631</link>
      <description>&lt;P&gt;Thanks for the response.&amp;nbsp; Using Service Route was my first thoughts, but I had read somewhere that it was not best practice.&amp;nbsp; I don't recall&amp;nbsp;thier reasoning, I'll have to find&amp;nbsp;it again.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 01 Mar 2019 15:54:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/natting-palo-alto-s-management-address/m-p/251929#M71631</guid>
      <dc:creator>JoelGuy</dc:creator>
      <dc:date>2019-03-01T15:54:37Z</dc:date>
    </item>
    <item>
      <title>Re: Natting Palo Alto's Management Address?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/natting-palo-alto-s-management-address/m-p/251930#M71632</link>
      <description>&lt;P&gt;but do you not already have outgoing (trust to untrust) NAT in place for your outgoing traffic.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;if so then i would have assumed that your local routing would have pushed&amp;nbsp; outgoing traffic from management interface via this route.&lt;/P&gt;</description>
      <pubDate>Fri, 01 Mar 2019 15:58:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/natting-palo-alto-s-management-address/m-p/251930#M71632</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2019-03-01T15:58:23Z</dc:date>
    </item>
    <item>
      <title>Re: Natting Palo Alto's Management Address?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/natting-palo-alto-s-management-address/m-p/251944#M71636</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Also make sure you have a policy that allows the traffic, dont inspect it and also dont decrypt it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Fri, 01 Mar 2019 18:31:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/natting-palo-alto-s-management-address/m-p/251944#M71636</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2019-03-01T18:31:16Z</dc:date>
    </item>
    <item>
      <title>Re: Natting Palo Alto's Management Address?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/natting-palo-alto-s-management-address/m-p/252163#M71691</link>
      <description>&lt;P&gt;I agree with MickBall.&amp;nbsp; Either edit your service route config and use an internet routable address to pull from PAN or set your mgmt interface on a subnet with a gateway that routes to the PAN for NAT.&amp;nbsp; Having your mgmt interface on an internet routable address is a really BAD idea.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Mar 2019 15:26:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/natting-palo-alto-s-management-address/m-p/252163#M71691</guid>
      <dc:creator>jeremy.larsen</dc:creator>
      <dc:date>2019-03-04T15:26:35Z</dc:date>
    </item>
    <item>
      <title>Re: Natting Palo Alto's Management Address?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/natting-palo-alto-s-management-address/m-p/252183#M71698</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;If you are using a legit certificate for your management interface and are using policies to allow access from only certain IP's (others you own), I dont see why allowing access should be an issue?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just my thoughts.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Mar 2019 17:21:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/natting-palo-alto-s-management-address/m-p/252183#M71698</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2019-03-04T17:21:17Z</dc:date>
    </item>
  </channel>
</rss>

