- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
01-23-2023 11:28 AM
Hello All,
My current management IP is set to a private IP and is up and pingable from the PALO ALTO command line. How ever I cannot log onto the management IP via WEB GUI...
Does the management interface correlate to the physical management port on the palo or is there someway to connect to the management IP from a different network? Or can you connect to a passive palo from the web interface somehow? I am trying to upgrade an HA pair with no downtime but I am not finding a way to connect to the PASSIVE unit via the web....
01-23-2023 11:53 AM
Management interface correlates to physical port on Palo.
What do you see in traffic log when you try to access management IP?
Is this traffic permitted in security policy?
Does management interface have default gateway configured?
Do you have "permitted IP addresses" configured on management interface?
01-23-2023 12:11 PM
There is no cable plugged into these ports yet the prior sysadmin has the management interfaced staticly addressed and the address is pingable only by the Palo itself.... is this setup pointless and I need to set up traditional cabled out of band management? Or is there some internal passthrough on the management IP?
01-23-2023 12:16 PM - edited 01-23-2023 12:17 PM
There is no internal passthrough.
Either connect cable to mgmt port (preferred option) or configure some (preferably internal) dataplane interface with interface management profile (https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-networking-admin/configure-interfaces/use-inter...).
Management interface cable is preferred because Palo separates dataplane and management plane.
You can access Palo through physical mgmt port even if firewall dataplane is overloaded.
01-23-2023 12:18 PM
Is this the only way to connect to a passive UNIT in a HA pair? Is via the management interface?
01-23-2023 04:02 PM
Yes only way to access passive is through mgmt.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!