<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: MGMT interface routing questions in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/mgmt-interface-routing-questions/m-p/426202#M94457</link>
    <description>&lt;P&gt;In addition to what &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/160615"&gt;@LAYER_8&lt;/a&gt;&amp;nbsp;already wrote. From a dataplane interface you cannot connect to the management interface. Dataplane and management plane have separated routing tables. You can access the cli/webui over a dataplane interface by configuring an interface management profile. But in an active/standby pair this way you will be able to access only the active firewall.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The service routes are used if you want to send some management traffic out of another interface than the management interface (for example that the firewall connect to the update servers directly from the internet facing interface).&lt;/P&gt;&lt;P&gt;In an active/standby high availability pair not everything is synced. All the configurations that are not synced you can find here:&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/high-availability/reference-ha-synchronization/what-settings-dont-sync-in-activepassive-ha.html" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/high-availability/reference-ha-synchronization/what-settings-dont-sync-in-activepassive-ha.html&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 11 Aug 2021 19:06:59 GMT</pubDate>
    <dc:creator>Remo</dc:creator>
    <dc:date>2021-08-11T19:06:59Z</dc:date>
    <item>
      <title>MGMT interface routing questions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/mgmt-interface-routing-questions/m-p/426184#M94455</link>
      <description>&lt;P&gt;When I configure the mgmt interface on its own network and I use the PA for routing, do I need to setup a static route to access the HTTP interface from a different network? Or d&lt;SPAN&gt;oes a service route take care of this automatically?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I have an HA active/standby pair, do service routes need to be configured on each device?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Aug 2021 18:17:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/mgmt-interface-routing-questions/m-p/426184#M94455</guid>
      <dc:creator>MikeSangray2019</dc:creator>
      <dc:date>2021-08-11T18:17:50Z</dc:date>
    </item>
    <item>
      <title>Re: MGMT interface routing questions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/mgmt-interface-routing-questions/m-p/426189#M94456</link>
      <description>&lt;P&gt;If the MGT interface is plugged into a downstream switch that acts as a terminus for your LAN/IAPs, then you can access the MGT portal. If you have your MGT interface isolated on a VLAN, yet still want to access it from the users interface, you would create an &lt;A href="https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-admin/networking/configure-interfaces/use-interface-management-profiles-to-restrict-access" target="_self"&gt;interface management profile&lt;/A&gt;.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Whatever changes you make to one device, these populate over to the other in an HA pair configuration.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Aug 2021 18:24:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/mgmt-interface-routing-questions/m-p/426189#M94456</guid>
      <dc:creator>LAYER_8</dc:creator>
      <dc:date>2021-08-11T18:24:51Z</dc:date>
    </item>
    <item>
      <title>Re: MGMT interface routing questions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/mgmt-interface-routing-questions/m-p/426202#M94457</link>
      <description>&lt;P&gt;In addition to what &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/160615"&gt;@LAYER_8&lt;/a&gt;&amp;nbsp;already wrote. From a dataplane interface you cannot connect to the management interface. Dataplane and management plane have separated routing tables. You can access the cli/webui over a dataplane interface by configuring an interface management profile. But in an active/standby pair this way you will be able to access only the active firewall.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The service routes are used if you want to send some management traffic out of another interface than the management interface (for example that the firewall connect to the update servers directly from the internet facing interface).&lt;/P&gt;&lt;P&gt;In an active/standby high availability pair not everything is synced. All the configurations that are not synced you can find here:&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/high-availability/reference-ha-synchronization/what-settings-dont-sync-in-activepassive-ha.html" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/high-availability/reference-ha-synchronization/what-settings-dont-sync-in-activepassive-ha.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Aug 2021 19:06:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/mgmt-interface-routing-questions/m-p/426202#M94457</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2021-08-11T19:06:59Z</dc:date>
    </item>
  </channel>
</rss>

