- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
04-17-2020 12:25 PM
Hello all,
Our PAN-OS Management Interface Permitted IP Addresses (on both Panorama and firewalls, version 8.14) contain IPs for the firewalls and both members of the Panorama cluster. These weren't set up by me and I'm wondering if that's necessary. I have read an article that said that that device configs, log retrieval, etc. are managed over that interface. So, does every Panorama and firewall have to have every other Panorama and firewall in its access list?
Also, is there a trick anyone knows of to make it easy to copy those access lists from device to device?
Any help is appreciated.
Thanks in advance,
- Steve
04-17-2020 12:38 PM
This depends on how you actually have things configured; a lot of the time you wouldn't need to add all of the other firewalls into the permitted-ip list on the other firewalls. That being said, they could be using user-id redistribution or using it as a backup management access solution or something like that.
The easiest answer really is that managing this through the API or the XML is going to be the easiest solution I've found for managing this. It's easy enough to do in the API for each firewall, or if you're working in the XML configuration file already it's extremely easy.
04-17-2020 12:38 PM
This depends on how you actually have things configured; a lot of the time you wouldn't need to add all of the other firewalls into the permitted-ip list on the other firewalls. That being said, they could be using user-id redistribution or using it as a backup management access solution or something like that.
The easiest answer really is that managing this through the API or the XML is going to be the easiest solution I've found for managing this. It's easy enough to do in the API for each firewall, or if you're working in the XML configuration file already it's extremely easy.
04-17-2020 02:17 PM
Thanks, @BPry . From the configuration I've done since I got your response, I haven't had any problems if I omit the firewalls from the access lists. I'm using the XML files to configure them, which is certainly easier!
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!