Palo Alto Mgmt Port Issue

Reply
Highlighted
L2 Linker

Palo Alto Mgmt Port Issue

Dear Friends,

 

We are facing a issue that currently we are unable to console to firewall device. But traffic is passing through active firewall. Status is HA1 backup= Down

 

Please advice 

 

Thanks,

Lakshitha

Highlighted
Cyber Elite

@Lakshitha,

You'll have to provide a bit more info then that. Is the management interface your HA1 backup interface? Have you tried directly connecting to the Mgmt interface and verifying that the interface itself functions as it should? 

Highlighted
L2 Linker

Hi,

 

Yes you r correct. Tried but mgmt interface not loading even Console port also not connecting. If we reboot it it may works. But I need to know exact resion. Please advice

 

Thanks

Lakshitha

Highlighted
Cyber Elite

@Lakshitha,

At that point you really need to reload the box and see if you gain any sort of output from the firewall again. You can't troubleshoot this if you don't have any way to actually look at the box. 

Highlighted
L7 Applicator

@Lakshitha if neither console or mgmt interface works then check if you have configured interface management profile to any of network interfaces to allow fw management.

If yes then during offhours send active firewall to reboot and log into problematic firewall through dataplane interface.

If not then reboot problematic firewall and see if connectivity restores.

Enterprise Architect @ Cloud Carib www.cloudcarib.com
ACE, PCNSE, PCNSI
Highlighted
L2 Linker

Dear Friends,

 

Thnaks everyone. It was sort out. Problem was an ip address on Mgmt allowed ip list. I deleted it using 

 

Configure

delete deviceconfig system permitted-ip <subnet to be removed>

 

But my question is Why Console port also does not work ?

 

Thanks,

Lakshitha.

Highlighted
Cyber Elite

@Lakshitha,

You can actually turn off the MGMT port if you've enabled FIPS mode or CCEAL4. That's the only time I would expect the console port to be non-functional short of a malfunction of the port itself. 

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!