- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
10-18-2021 02:09 AM
I can't connect via SSH HTTP or HTTPS to my PA-500 firewall .
I can ping it from my network and that's all .
Also , the strange thing it is that from panorama the device is reachable
I have checked the traffic -> is allow
I have checked management interface -> is allowing my IP addresses + HTTPS SSH and HTTP are ticked .
What else could be the issue ?
10-18-2021 09:59 AM
Are you using Management Interface of PA to ssh it?
Is your IP address from which you are trying to ping is in allowed list?
Regards
10-18-2021 08:20 PM
In addition to what @MP18 already mentioned, I would look and see if you don't have a service route configured to allow Panorama traffic and if that's actually using your management interface or not.
Enabling access to the management interface is straightforward and should be working with what you have described if you have committed the configuration and are attempting to connect to the proper IP address.
10-18-2021 11:43 PM
Are you using Management Interface of PA to ssh it? -> Yes
Is your IP address from which you are trying to ping is in allowed list? -> Yes , it is
10-19-2021 05:02 AM
Please do PCAP on the MGMT interface while you test the ssh to PA
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CleECAS
This will show you if traffic is hitting the PA or not?
Regards
10-21-2021 03:33 AM
I have removed all of the allowed IP from mgmt interface , and then it works .
Practically i dont have an explanation because my IP address was there .
Case is solved , maybe if you can help me with an explanation , why it works after
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!