<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Management Interface Permitted IP Addresses &amp;amp; other devices in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/management-interface-permitted-ip-addresses-amp-other-devices/m-p/323524#M82655</link>
    <description>&lt;P&gt;Thanks,&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;.&amp;nbsp; From the configuration I've done since I got your response, I haven't had any problems if I omit the firewalls from the access lists.&amp;nbsp; I'm using the XML files to configure them, which is certainly easier!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 17 Apr 2020 21:17:53 GMT</pubDate>
    <dc:creator>stevenkadish</dc:creator>
    <dc:date>2020-04-17T21:17:53Z</dc:date>
    <item>
      <title>Management Interface Permitted IP Addresses &amp; other devices</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/management-interface-permitted-ip-addresses-amp-other-devices/m-p/323489#M82646</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Our PAN-OS Management Interface Permitted IP Addresses (on both Panorama and firewalls, version 8.14) contain IPs for the firewalls and both members of the Panorama cluster.&amp;nbsp; These weren't set up by me and I'm wondering if that's necessary.&amp;nbsp; I have read an article that said that that device configs, log retrieval, etc. are managed over that interface.&amp;nbsp; So, does every Panorama and firewall have to have every other Panorama and firewall in its access list?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also, is there a trick anyone knows of to make it easy to copy those access lists from device to device?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any help is appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance,&lt;/P&gt;&lt;P&gt;- Steve&lt;/P&gt;</description>
      <pubDate>Fri, 17 Apr 2020 19:25:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/management-interface-permitted-ip-addresses-amp-other-devices/m-p/323489#M82646</guid>
      <dc:creator>stevenkadish</dc:creator>
      <dc:date>2020-04-17T19:25:08Z</dc:date>
    </item>
    <item>
      <title>Re: Management Interface Permitted IP Addresses &amp; other devices</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/management-interface-permitted-ip-addresses-amp-other-devices/m-p/323502#M82647</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/73625"&gt;@stevenkadish&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;This depends on how you actually have things configured; a lot of the time you wouldn't need to add all of the other firewalls into the permitted-ip list on the other firewalls. That being said, they could be using user-id redistribution or using it as a backup management access solution or something like that.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The easiest answer really is that managing this through the API or the XML is going to be the easiest solution I've found for managing this. It's easy enough to do in the API for each firewall, or if you're working in the XML configuration file already it's extremely easy.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Apr 2020 19:38:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/management-interface-permitted-ip-addresses-amp-other-devices/m-p/323502#M82647</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2020-04-17T19:38:43Z</dc:date>
    </item>
    <item>
      <title>Re: Management Interface Permitted IP Addresses &amp; other devices</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/management-interface-permitted-ip-addresses-amp-other-devices/m-p/323524#M82655</link>
      <description>&lt;P&gt;Thanks,&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;.&amp;nbsp; From the configuration I've done since I got your response, I haven't had any problems if I omit the firewalls from the access lists.&amp;nbsp; I'm using the XML files to configure them, which is certainly easier!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Apr 2020 21:17:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/management-interface-permitted-ip-addresses-amp-other-devices/m-p/323524#M82655</guid>
      <dc:creator>stevenkadish</dc:creator>
      <dc:date>2020-04-17T21:17:53Z</dc:date>
    </item>
  </channel>
</rss>

