<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Management profile issue in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/management-profile-issue/m-p/12723#M9336</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Satish,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you have a "default deny" policy on this firewall, it may block interface management traffic &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;( &lt;/SPAN&gt;intra zone traffic). &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;For an example:&lt;/STRONG&gt; If you have enabled &lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-size: 13.3333339691162px;"&gt;management profile (ping&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;,&lt;/SPAN&gt;ssh&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;,&lt;/SPAN&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;https&lt;/SPAN&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt; )&lt;/SPAN&gt; on ethernet-1/1 interface &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;( &lt;/SPAN&gt;Trust zone) and you are trying to access the firewall from your Trust network, then you have to configure a "Trust to Trust" security policy on this firewall &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;( &lt;/SPAN&gt;if you have a any-any-deny rule at the bottom). &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 19 Nov 2014 08:00:05 GMT</pubDate>
    <dc:creator>HULK</dc:creator>
    <dc:date>2014-11-19T08:00:05Z</dc:date>
    <item>
      <title>Management profile issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/management-profile-issue/m-p/12722#M9335</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Friends,&lt;/P&gt;&lt;P&gt;please suggest, i have create a management profile (ping,ssh,https ) and apply e1/1 (static ip) but i am not able to ping and web access.&lt;/P&gt;&lt;P&gt;Regards Satish&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Nov 2014 07:44:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/management-profile-issue/m-p/12722#M9335</guid>
      <dc:creator>Satish</dc:creator>
      <dc:date>2014-11-19T07:44:06Z</dc:date>
    </item>
    <item>
      <title>Re: Management profile issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/management-profile-issue/m-p/12723#M9336</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Satish,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you have a "default deny" policy on this firewall, it may block interface management traffic &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;( &lt;/SPAN&gt;intra zone traffic). &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;For an example:&lt;/STRONG&gt; If you have enabled &lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-size: 13.3333339691162px;"&gt;management profile (ping&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;,&lt;/SPAN&gt;ssh&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;,&lt;/SPAN&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;https&lt;/SPAN&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt; )&lt;/SPAN&gt; on ethernet-1/1 interface &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;( &lt;/SPAN&gt;Trust zone) and you are trying to access the firewall from your Trust network, then you have to configure a "Trust to Trust" security policy on this firewall &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;( &lt;/SPAN&gt;if you have a any-any-deny rule at the bottom). &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Nov 2014 08:00:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/management-profile-issue/m-p/12723#M9336</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-11-19T08:00:05Z</dc:date>
    </item>
    <item>
      <title>Re: Management profile issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/management-profile-issue/m-p/12724#M9337</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Hulk,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;I have already&amp;nbsp; create a policy for the same like (trust to trust and wan to wan ) but facing same issue and also i am not getting any logs. please suggest.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;Regards&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;Satish&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Nov 2014 08:06:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/management-profile-issue/m-p/12724#M9337</guid>
      <dc:creator>Satish</dc:creator>
      <dc:date>2014-11-19T08:06:40Z</dc:date>
    </item>
    <item>
      <title>Re: Management profile issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/management-profile-issue/m-p/12725#M9338</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Satish,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you have multiple VR or VSYS on your setup...?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Nov 2014 08:18:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/management-profile-issue/m-p/12725#M9338</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-11-19T08:18:21Z</dc:date>
    </item>
    <item>
      <title>Re: Management profile issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/management-profile-issue/m-p/12726#M9339</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi,&lt;/P&gt;&lt;P&gt;best way look if paloalto drops that or not (ping with -t and start doing)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;go to cli&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;debug dataplane packet-diag set filter match source SOURCEIP destination INTERFACEIP&lt;/P&gt;&lt;P&gt;debug dataplane packet-diag set filter match source INTERFACEIP destination SOURCEIP&lt;/P&gt;&lt;P&gt;debug dataplane packet-diag set filter on&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;show counter global filter packet-filter yes delta yes severity drop&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;output will show information&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Nov 2014 08:21:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/management-profile-issue/m-p/12726#M9339</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2014-11-19T08:21:32Z</dc:date>
    </item>
    <item>
      <title>Re: Management profile issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/management-profile-issue/m-p/12727#M9340</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Satish,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you have any NAT policy configured for the same interface IP address..?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Nov 2014 08:22:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/management-profile-issue/m-p/12727#M9340</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-11-19T08:22:24Z</dc:date>
    </item>
    <item>
      <title>Re: Management profile issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/management-profile-issue/m-p/12728#M9341</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-3367"&gt;Unable to Connect to or Ping a Firewall Interface&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/message/16155"&gt;mgmt&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Nov 2014 08:23:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/management-profile-issue/m-p/12728#M9341</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-11-19T08:23:33Z</dc:date>
    </item>
    <item>
      <title>Re: Management profile issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/management-profile-issue/m-p/12729#M9342</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Hulk, No, i dont have multiple VR. Regards Satish&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Nov 2014 09:12:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/management-profile-issue/m-p/12729#M9342</guid>
      <dc:creator>Satish</dc:creator>
      <dc:date>2014-11-19T09:12:04Z</dc:date>
    </item>
    <item>
      <title>Re: Management profile issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/management-profile-issue/m-p/12730#M9343</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Hulk,&lt;/P&gt;&lt;P&gt;yes i have NET policy for the same interface.&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Satish&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Nov 2014 09:18:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/management-profile-issue/m-p/12730#M9343</guid>
      <dc:creator>Satish</dc:creator>
      <dc:date>2014-11-19T09:18:13Z</dc:date>
    </item>
    <item>
      <title>Re: Management profile issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/management-profile-issue/m-p/12731#M9344</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;if you have a NAT rule with source zone any this can be the issue&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Nov 2014 09:19:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/management-profile-issue/m-p/12731#M9344</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2014-11-19T09:19:28Z</dc:date>
    </item>
    <item>
      <title>Re: Management profile issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/management-profile-issue/m-p/12732#M9345</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi PANOS,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You are right after disable NAT rule. i am able to ping and SSH, HTTPS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Satish&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Nov 2014 09:44:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/management-profile-issue/m-p/12732#M9345</guid>
      <dc:creator>Satish</dc:creator>
      <dc:date>2014-11-19T09:44:44Z</dc:date>
    </item>
    <item>
      <title>Re: Management profile issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/management-profile-issue/m-p/12733#M9346</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;please suggest to me best practice for the same.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Nov 2014 09:45:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/management-profile-issue/m-p/12733#M9346</guid>
      <dc:creator>Satish</dc:creator>
      <dc:date>2014-11-19T09:45:35Z</dc:date>
    </item>
    <item>
      <title>Re: Management profile issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/management-profile-issue/m-p/12734#M9347</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;When using NAT rules do not use any,&lt;/P&gt;&lt;P&gt;instead use the real zone names related.&lt;/P&gt;&lt;P&gt;What is the rule disabled ? can you share &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Nov 2014 09:56:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/management-profile-issue/m-p/12734#M9347</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2014-11-19T09:56:56Z</dc:date>
    </item>
  </channel>
</rss>

