- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
Enhanced Security Measures in Place: To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.
07-26-2024 10:40 AM
We have /24 public ip allocated to the main office. So we have pretty wide range of pubic addresses to use while testing configuration.
I have been configuring Palo Alto firewall for new migration project.
Currently managing Palo Alto through dedicated management port.
I have setup management profile to allow: HTTPS, SSH, PING only.
Want to access management interface remotely while I'm not at the office. I have assigned one of available public ip address to interface assigned to external zone.
And here is weird issue occurring unless if I'm not missing fundamental settings on Palo Alto.
So when I access management interface from our public IP address range no issues and these 3 ports (mentioned above) are accessible. However when I try to access outside of our public IP address range it is not accessible for example from my home.
I have not setup any management access restrictions on profile.
I'm stumbled at this point and need help if anybody has better experience.
Thank you very much.
07-30-2024 02:16 AM
There's a couple of things that might be the problem, but let's address a more important thing first:
Do not set a management profile on an external interface 😉
It's better to take a little bit of time to set up GlobalProtect for example, and set up a secured connection to your firewall to manage it. This is much more secure than having your management exposed for people to try and break into
07-30-2024 12:57 PM
Do you have a security policy allowing access from your home internet to the publicly reachable IP on the firewall? outside zone to outside zone in this case?
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!