cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Who rated this post

L7 Applicator

First, I have to mention that it is probably a bad idea to put firewall management on a public interface. I highly recommend against doing that.

 

If you must, please restrict it to the IPs you're using and ideally lock it down to multi-factor auth.

edit: Here's the official best practices for management of the devices:

https://www.paloaltonetworks.com/documentation/80/pan-os/pan-os/getting-started/best-practices-for-s...

 

That said, if you do want to put GlobalProtect (GP) as the same interface as a dataplane port for which you have enabled management, the firewall will automatically shift the management listener to port 4443 while keeping GP on 443. It's not something that can be customized so you'll need to make do with those ports, but will allow you to access the management service and still provide GP functionality.

Who rated this post