- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
10-04-2026 04:40 PM
Does the firewall need to have Panorama IPs in its permitted IP list for MGMT interface?
I tested and it seems I only need Panorama to allow FW IP. But from the article below for MGMT interface profile it mentions adding Panorama IP is required.
https://live.paloaltonetworks.com/t5/general-articles/why-it-s-essential-to-secure-your-management-i...
10-04-2026 11:52 PM
Hello @nahiar
I do not believe it is required. Firewall initiates connection to Panorama. Not other way around, therefore Panorama's IP address does not have to be on the management interface permitted list. The link you shared seems to be cut off. Could you please share the complete link?
Thank you and Regards
Pavel
10-05-2026 12:11 AM
10-05-2026 07:56 AM
@nahiar as far as I know Panorama needs firewall IP in the MGMT Interface allowed list.
Firewall MGMT Interface does not need Panorama IP in the allowed list.
Regards
10-05-2026 03:06 PM
Hello @nahiar
thank you for reply.
From my point of view the statement in that article is misleading. I will ask internally whether this post can be reviewed and corrected.
All the communication is initiated by Firewall, therefore it is not necessary to include Panorama IP address in the management profile. There might have been exception in PAN-OS 7.1 and earlier where deployment updates were initiated by Panorama: Ports Used for Panorama, however in current PAN-OS releases it is no longer case.
If Panorama has Permitted IP address list configured of course Firewalls' IP addresses have to be included: Managed Devices Unable to Establish Connections to Panorama after Configuring Permitted IP Addresse....
Kind Regards
Pavel
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!

