Question about Management Interface

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Question about Management Interface

L1 Bithead

Hello All,

 

My current management IP is set to a private IP and is up and pingable from the PALO ALTO command line. How ever I cannot log onto the management IP via WEB GUI...

 

 

Does the management interface correlate to the physical management port on the palo or is there someway to connect to the management IP from a different network? Or can you connect to a passive palo from the web interface somehow? I am trying to upgrade an HA pair with no downtime but I am not finding a way to connect to the PASSIVE unit via the web.... 

5 REPLIES 5

Cyber Elite
Cyber Elite

Management interface correlates to physical port on Palo.

What do you see in traffic log when you try to access management IP?

Is this traffic permitted in security policy?

Does management interface have default gateway configured?

Do you have "permitted IP addresses" configured on management interface?

Enterprise Architect, Security @ Cloud Carib Ltd
Palo Alto Networks certified from 2011

There is no cable plugged into these ports yet the prior sysadmin has the management interfaced staticly addressed and the address is pingable only by the Palo itself.... is this setup pointless and I need to set up traditional cabled out of band management? Or is there some internal passthrough on the management IP?

Cyber Elite
Cyber Elite

There is no internal passthrough.

Either connect cable to mgmt port (preferred option) or configure some (preferably internal) dataplane interface with interface management profile (https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-networking-admin/configure-interfaces/use-inter...).

 

Management interface cable is preferred because Palo separates dataplane and management plane.

You can access Palo through physical mgmt port even if firewall dataplane is overloaded.

Enterprise Architect, Security @ Cloud Carib Ltd
Palo Alto Networks certified from 2011

Is this the only way to connect to a passive UNIT in a HA pair? Is via the management interface?

Yes only way to access passive is through mgmt.

Enterprise Architect, Security @ Cloud Carib Ltd
Palo Alto Networks certified from 2011
  • 1583 Views
  • 5 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!