Enhanced Security Measures in Place:   To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.

Having issue with management profile to be applied to Outside (public) interface.

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Having issue with management profile to be applied to Outside (public) interface.

L1 Bithead

We have /24 public ip allocated to the main office. So we have pretty wide range of pubic addresses to use while testing configuration.

I have been configuring Palo Alto firewall for new migration project. 

Currently managing Palo Alto through dedicated management port. 

I have setup management profile to allow: HTTPS, SSH, PING only.

Want to access management interface remotely while I'm not at the office. I have assigned one of available public ip address to interface assigned to external zone.

And here is weird issue occurring  unless if I'm not missing fundamental settings on Palo Alto.

So when I access management interface from our public IP address range no issues and these 3 ports (mentioned above) are accessible. However when I try to access outside of our public IP address range it is not accessible for example from my home.

I have not setup any management access restrictions on profile.

I'm stumbled at this point and need help if anybody has better experience.

 

Thank you very much.

2 REPLIES 2

Cyber Elite
Cyber Elite

There's a couple of things that might be the problem, but let's address a more important thing first:

Do not set a management profile on an external interface 😉

 

It's better to take a little bit of time to set up GlobalProtect for example, and set up a secured connection to your firewall to manage it. This is much more secure than having your management exposed for people to try and break into

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

L0 Member

Do you have a security policy allowing access from your home internet to the publicly reachable IP on the firewall? outside zone to outside zone in this case?

  • 621 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!