Enhanced Security Measures in Place:   To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.

control plane vs management plane

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Palo Alto Networks Approved
Palo Alto Networks Approved
Community Expert Verified
Community Expert Verified

control plane vs management plane

L4 Transporter

What is the difference between the control plane and management plane? Or are the the same thing?

1 accepted solution

Accepted Solutions

they're different chipsets responsible for different things

management plane is purely magement things (run the web interface, do the lookups, get the updates, ...)

dataplane is the thing that controls how bits are received, inspected and forwarded

control plane is only used in the larger platforms, it helps the dataplane with more menial tasks so it can focus even more on raw processing, with things like routing

 

you can see what processes are running on each plane by checking the logs:

admin@PA-5220> less cp-log 
bcm.log                        brdagent.log                   brdagent.log.old               cp-monitor.log                 cp-monitor.log.1               
cp-monitor.log.2               cp-monitor.log.3               cp-monitor.log.4               cp-telemetry.log               dataplane0-console-output.log  
ehmon.log                      ehmon.log.old                  fpp_1.log                      fpp_2.log                      fpp_3.log                      
fpp_4.log                      fpp_5.log                      fpp_7.log                      fpp_cp.log                     masterd.log                    
masterd_apps.log               masterd_detail.log             mprelay.log                    pan_comm_0.log                 supervisor.log                 
sysdagent.log                  fpp_6.log                      

admin@PA-5220> less dp0-log 
bfd.log             brdagent.log        dp-monitor.log      dp-monitor.log.1    dp-monitor.log.2    dp-monitor.log.3    dp-monitor.log.4    dp-telemetry.log    
masterd.log         masterd_apps.log    mprelay.log         pan_comm_0.log      pan_comm_0.log.old  pan_dha.log         pan_task_1.log      panio.log           
panio.log.old       pdtrc.log           supervisor.log      sysdagent.log       tund.log            masterd_detail.log  

admin@PA-5220> less mp-log 
agent                            appweb3-panmodule.log            appweb3-sslvpn.log               appweb3-websrvr.log              authd.log                        
botnet.log                       chasd.log                        content_telemetry.log            controlplane-console-output.log  cord.log                         
cryptod.log                      curlog_out_content               dagger.log                       default-dpipkt.log               devsrv.log                       
devsrv.log.old                   dnsproxyd.log                    dsms-certificates.log            ehmon.log                        fips.log                         
fix_rpm_db.log                   get_content_issue_msg.log        ha_agent.log                     ikemgr.log                       indexgen.log                     
indexgen.log.1                   indexgen.log.2                   keymgr.log                       l2ctrld.log                      l3svc_ngx_error.log              
lcaas_agent.log                  logdb_dirs_gen.log               logpurger.log                    logpurger.log.old                logrcvr.log                      
logrcvr.log.old                  masterd.log                      masterd_apps.log                 masterd_detail.log               mgmt_fb.log                      
mgmt_ngx_error.log               mp-monitor.log                   mp-monitor.log.1                 mp-monitor.log.2                 mp-monitor.log.3                 
mp-monitor.log.4                 mp-telemetry.log                 ms.log                           ms.log.old                       nf_conntrack.log                 
opcmdhistory.log                 pan_dhcpd.log                    pan_mgmt_firstboot.log           paninstaller_content.log         panlogs-partition.log            
parrot.log                       pdtrc.log                        php.debug.log                    php.janitor.log                  pppoed.log                       
raid.log                         rasmgr.log                       report_gen.log                   satd.log                         snmpd.log                        
sslmgr.log                       sslvpn_ngx_error.log             stats_service.log                sysd.log                         sysdagent.log                    
syslog-ng.log                    useridd.log                      varrcvr.log                      vif.log                          wf_ramdisk.log                   
wildfire-upload.log              routed.log                       
Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

View solution in original post

5 REPLIES 5

L4 Transporter

@reaper @BPry Just looking for someone to confirm

they're different chipsets responsible for different things

management plane is purely magement things (run the web interface, do the lookups, get the updates, ...)

dataplane is the thing that controls how bits are received, inspected and forwarded

control plane is only used in the larger platforms, it helps the dataplane with more menial tasks so it can focus even more on raw processing, with things like routing

 

you can see what processes are running on each plane by checking the logs:

admin@PA-5220> less cp-log 
bcm.log                        brdagent.log                   brdagent.log.old               cp-monitor.log                 cp-monitor.log.1               
cp-monitor.log.2               cp-monitor.log.3               cp-monitor.log.4               cp-telemetry.log               dataplane0-console-output.log  
ehmon.log                      ehmon.log.old                  fpp_1.log                      fpp_2.log                      fpp_3.log                      
fpp_4.log                      fpp_5.log                      fpp_7.log                      fpp_cp.log                     masterd.log                    
masterd_apps.log               masterd_detail.log             mprelay.log                    pan_comm_0.log                 supervisor.log                 
sysdagent.log                  fpp_6.log                      

admin@PA-5220> less dp0-log 
bfd.log             brdagent.log        dp-monitor.log      dp-monitor.log.1    dp-monitor.log.2    dp-monitor.log.3    dp-monitor.log.4    dp-telemetry.log    
masterd.log         masterd_apps.log    mprelay.log         pan_comm_0.log      pan_comm_0.log.old  pan_dha.log         pan_task_1.log      panio.log           
panio.log.old       pdtrc.log           supervisor.log      sysdagent.log       tund.log            masterd_detail.log  

admin@PA-5220> less mp-log 
agent                            appweb3-panmodule.log            appweb3-sslvpn.log               appweb3-websrvr.log              authd.log                        
botnet.log                       chasd.log                        content_telemetry.log            controlplane-console-output.log  cord.log                         
cryptod.log                      curlog_out_content               dagger.log                       default-dpipkt.log               devsrv.log                       
devsrv.log.old                   dnsproxyd.log                    dsms-certificates.log            ehmon.log                        fips.log                         
fix_rpm_db.log                   get_content_issue_msg.log        ha_agent.log                     ikemgr.log                       indexgen.log                     
indexgen.log.1                   indexgen.log.2                   keymgr.log                       l2ctrld.log                      l3svc_ngx_error.log              
lcaas_agent.log                  logdb_dirs_gen.log               logpurger.log                    logpurger.log.old                logrcvr.log                      
logrcvr.log.old                  masterd.log                      masterd_apps.log                 masterd_detail.log               mgmt_fb.log                      
mgmt_ngx_error.log               mp-monitor.log                   mp-monitor.log.1                 mp-monitor.log.2                 mp-monitor.log.3                 
mp-monitor.log.4                 mp-telemetry.log                 ms.log                           ms.log.old                       nf_conntrack.log                 
opcmdhistory.log                 pan_dhcpd.log                    pan_mgmt_firstboot.log           paninstaller_content.log         panlogs-partition.log            
parrot.log                       pdtrc.log                        php.debug.log                    php.janitor.log                  pppoed.log                       
raid.log                         rasmgr.log                       report_gen.log                   satd.log                         snmpd.log                        
sslmgr.log                       sslvpn_ngx_error.log             stats_service.log                sysd.log                         sysdagent.log                    
syslog-ng.log                    useridd.log                      varrcvr.log                      vif.log                          wf_ramdisk.log                   
wildfire-upload.log              routed.log                       
Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

@reaper

 

cp-log refers to the control plane?

yes ma'am

 

only available on the platforms that have one (most don't)

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

@reaper very good explanation.!

MP

Help the community: Like helpful comments and mark solutions.
  • 1 accepted solution
  • 18936 Views
  • 5 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!