<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Can't access management console in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/can-t-access-management-console/m-p/433957#M95930</link>
    <description>&lt;P&gt;Do you have physical access to the firewall? You should still be able to console in.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I believe this article is referencing your issue.&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClLqCAK" target="_blank" rel="noopener"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClLqCAK&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In regards to whitelisting for PCI scans, you may be wanting to look at an exclusion for the zone protection profile.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="bafergel_0-1631652609287.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/36395iFD63B317D9BDB804/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="bafergel_0-1631652609287.png" alt="bafergel_0-1631652609287.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 14 Sep 2021 20:50:17 GMT</pubDate>
    <dc:creator>bafergel</dc:creator>
    <dc:date>2021-09-14T20:50:17Z</dc:date>
    <item>
      <title>Can't access management console</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-t-access-management-console/m-p/433917#M95926</link>
      <description>&lt;P&gt;&lt;SPAN&gt;I made a big mistake and not sure how to correct it. &amp;nbsp;We have a Palo Alto Firewall. &amp;nbsp;I wanted to white list an IP address so my PCI Scans would not fail. &amp;nbsp;I found an article but it seems it lead me a totally different direction. &amp;nbsp;It had me put the IP in the Trusted IP list on the Management Interface Policy. &amp;nbsp;Now I can't login or even ping the PA management IP. &amp;nbsp;Is there way I can redeem myself and get the IP out of the Trusted IP list. &amp;nbsp;Would I have to be at the physical device and via the console port?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Sep 2021 17:27:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-t-access-management-console/m-p/433917#M95926</guid>
      <dc:creator>bobvaal</dc:creator>
      <dc:date>2021-09-14T17:27:18Z</dc:date>
    </item>
    <item>
      <title>Re: Can't access management console</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-t-access-management-console/m-p/433957#M95930</link>
      <description>&lt;P&gt;Do you have physical access to the firewall? You should still be able to console in.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I believe this article is referencing your issue.&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClLqCAK" target="_blank" rel="noopener"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClLqCAK&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In regards to whitelisting for PCI scans, you may be wanting to look at an exclusion for the zone protection profile.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="bafergel_0-1631652609287.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/36395iFD63B317D9BDB804/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="bafergel_0-1631652609287.png" alt="bafergel_0-1631652609287.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Sep 2021 20:50:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-t-access-management-console/m-p/433957#M95930</guid>
      <dc:creator>bafergel</dc:creator>
      <dc:date>2021-09-14T20:50:17Z</dc:date>
    </item>
    <item>
      <title>Re: Can't access management console</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-t-access-management-console/m-p/433993#M95933</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/193663"&gt;@bobvaal&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you RDP to the IP address that you put in the Permitted IP Addresses and then HTTPS to the firewall from it?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Tue, 14 Sep 2021 22:58:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-t-access-management-console/m-p/433993#M95933</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2021-09-14T22:58:43Z</dc:date>
    </item>
    <item>
      <title>Re: Can't access management console</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-t-access-management-console/m-p/434031#M95937</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/193663"&gt;@bobvaal&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Assuming that you don't otherwise have an interface management profile configured to allow management access of any kind through a data plane interface, the only way to access this unit is now from the IP address that you put into the permitted-ip list or through the console cable.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The one thing that you potentially can do depending on the site is simply give yourself the IP address that you've permitted access. This can generally be accomplished through a NAT setup on a L3 capable switch or router that may exist on the site. Depending on the equipment you have available at the site outside of the firewall, it's a possibility for most enterprise environments.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Sep 2021 03:14:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-t-access-management-console/m-p/434031#M95937</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2021-09-15T03:14:41Z</dc:date>
    </item>
  </channel>
</rss>

