- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
05-05-2019 02:14 AM
this is my first time deploying palo alto , is it important to have the managment port connected? does it play important role in the device function or is it just solely for managment?
like can i manage the device from the inside interface only?
05-05-2019 05:07 AM - edited 05-05-2019 05:10 AM
You can manage the device from any interface, the management port is there if you need it for out of band management, it is seperate from all your other interfaces. If you dont use OOB management then you dont have to configure it but please note that all your service routes, ldap, updates, dns etc are by default going to use this interface, so if you dont use it then modify your service routes via another interface.
05-05-2019 05:07 AM - edited 05-05-2019 05:10 AM
You can manage the device from any interface, the management port is there if you need it for out of band management, it is seperate from all your other interfaces. If you dont use OOB management then you dont have to configure it but please note that all your service routes, ldap, updates, dns etc are by default going to use this interface, so if you dont use it then modify your service routes via another interface.
05-05-2019 10:29 AM
Hi @chuckles
As mentionned by @Mick_Ball, yes you can manage the device without the mgmt port. But in addition to the described things in case of problems on the dataplane you will no longer be able to manage the firewall (except if you are able to connect remotely to the console port).
In addition to that I would also recommend to use the management port because of security reasons, as you could logically place the managementnport behind another dedicated management firewall for example.
05-05-2019 11:44 AM
what do you mean by service routes?
05-05-2019 12:03 PM
@chuckles wrote:what do you mean by service routes?
--> https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/networking/service-routes
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!