<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Remote Access on passive node of firewall ha cluster in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/remote-access-on-passive-node-of-firewall-ha-cluster/m-p/278028#M75544</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;am I missing something or the Panorama is not valid option here?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Even it is cluster setup (with config synchronization) Panorama needs to have access to both members.&lt;/P&gt;&lt;P&gt;Dedicated Mgmt interface is not reachable so the Panorama cannot use that&lt;/P&gt;&lt;P&gt;It is active-passive cluster so you cannot use service route through one of the dataplane interfaces.&lt;/P&gt;</description>
    <pubDate>Mon, 22 Jul 2019 07:58:54 GMT</pubDate>
    <dc:creator>aleksandar.astardzhiev</dc:creator>
    <dc:date>2019-07-22T07:58:54Z</dc:date>
    <item>
      <title>Remote Access on passive node of firewall ha cluster</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/remote-access-on-passive-node-of-firewall-ha-cluster/m-p/277704#M75485</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am currently configuring an HA cluster (active / passive) with the following configuration:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Primary (active) box: PA-820&lt;BR /&gt;ethernet1 / 1: 1.1.1.1/29 (external interface)&lt;BR /&gt;ethernet1 / 2: 192.168.0.1/24 (internal interface)&lt;BR /&gt;MGMT: 192.168.50.251/25 (Management interface)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Secondary (passive) box: PA-820&lt;BR /&gt;ethernet1 / 1: No IP address, as this is the secondary (passive) box.&lt;BR /&gt;ethernet1 / 2: No IP address, as this is the secondary (passive) box.&lt;BR /&gt;MGMT: 192.168.50.252/25 (Management interface)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The two firewall systems are located at the customer, so I have no physical access to the MGMT interface. Nevertheless, I would like to be able to administrate both (!!!) firewall systems remotely. Previous attempts to access the management port (MGMT) via a NAT or similar have failed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What works is access to the primary system via VPN. The internal interface (ethernet1 / 2) is in the list of protected networks and the interface itself has been assigned the management role&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What options do I have left?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;An active / active HA configuration is eliminated because DHCP is needed on the firewall.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your help!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Guido&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jul 2019 10:55:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/remote-access-on-passive-node-of-firewall-ha-cluster/m-p/277704#M75485</guid>
      <dc:creator>GuidoKramer</dc:creator>
      <dc:date>2019-07-19T10:55:52Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access on passive node of firewall ha cluster</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/remote-access-on-passive-node-of-firewall-ha-cluster/m-p/277727#M75490</link>
      <description>&lt;P&gt;You can set up Panorama to manage multiple systems from a single entity, all managed systems connect into Panorama, so no need for access to the network at all&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;An alternative 'industry best practice' method would be to set up a bastion host that is dual homed so you can VPN into the network and hop onto that station to perform admin on both firewalls&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jul 2019 12:05:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/remote-access-on-passive-node-of-firewall-ha-cluster/m-p/277727#M75490</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2019-07-19T12:05:37Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access on passive node of firewall ha cluster</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/remote-access-on-passive-node-of-firewall-ha-cluster/m-p/278028#M75544</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;am I missing something or the Panorama is not valid option here?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Even it is cluster setup (with config synchronization) Panorama needs to have access to both members.&lt;/P&gt;&lt;P&gt;Dedicated Mgmt interface is not reachable so the Panorama cannot use that&lt;/P&gt;&lt;P&gt;It is active-passive cluster so you cannot use service route through one of the dataplane interfaces.&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jul 2019 07:58:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/remote-access-on-passive-node-of-firewall-ha-cluster/m-p/278028#M75544</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2019-07-22T07:58:54Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access on passive node of firewall ha cluster</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/remote-access-on-passive-node-of-firewall-ha-cluster/m-p/278048#M75547</link>
      <description>Ideally you'd set the panorama up so it has an "in" to the oob network
Either set it up locally, via a bastion proxy or via a segmented dataplane interface (via the active member)</description>
      <pubDate>Mon, 22 Jul 2019 10:31:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/remote-access-on-passive-node-of-firewall-ha-cluster/m-p/278048#M75547</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2019-07-22T10:31:03Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access on passive node of firewall ha cluster</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/remote-access-on-passive-node-of-firewall-ha-cluster/m-p/278222#M75575</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;What about a VPN Tunnel to the HA pair or use Global Protect to connect?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jul 2019 21:45:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/remote-access-on-passive-node-of-firewall-ha-cluster/m-p/278222#M75575</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2019-07-22T21:45:47Z</dc:date>
    </item>
  </channel>
</rss>

