<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Firewalls - Management in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/firewalls-management/m-p/2237589#M346856</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jouni,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Thanks for your reply. Iam just looking for the standard practices while connecting and managing Firewalls in general (be it Palo Alto or Cisco ASA), and in my case how best to assign management IPs to FWs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you could point me to the Cisco documentation on Firewall design, that would be helpful too.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Mikey&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 08 Jul 2013 15:20:45 GMT</pubDate>
    <dc:creator>Mikey John</dc:creator>
    <dc:date>2013-07-08T15:20:45Z</dc:date>
    <item>
      <title>Firewalls - Management</title>
      <link>https://community.cisco.com/t5/network-security/firewalls-management/m-p/2237586#M346846</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have two Palo Alto firewalls connected to 2 x 4900M switches. I have assigned a /29 subnet (Vlan 100) for FW handoff and assigned IPs from this range to these devices.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I need to connect the management ports of the FWs too onto the switches. &lt;SPAN style="font-size: 10pt;"&gt;Can I connect the Mngmt port of the firewall and assign IP from the same /29 subnet? Or else it should be from a different subnet? &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can anyone please point me to a simple design which talks about IP assignments and port connections for Firewalls? And maybe some link which talks about design aspects involving firewalls?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Iam sorry if I have reached the wrong forum, but would appreciate your help in pointing me to the right direction.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Mikey&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 02:08:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewalls-management/m-p/2237586#M346846</guid>
      <dc:creator>Mikey John</dc:creator>
      <dc:date>2019-03-12T02:08:45Z</dc:date>
    </item>
    <item>
      <title>Firewalls - Management</title>
      <link>https://community.cisco.com/t5/network-security/firewalls-management/m-p/2237587#M346850</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Appreciate if someone replies to this post.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Mikey&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Jul 2013 15:07:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewalls-management/m-p/2237587#M346850</guid>
      <dc:creator>Mikey John</dc:creator>
      <dc:date>2013-07-08T15:07:02Z</dc:date>
    </item>
    <item>
      <title>Firewalls - Management</title>
      <link>https://community.cisco.com/t5/network-security/firewalls-management/m-p/2237588#M346853</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Well this is mainly a Cisco forum so there isnt really any information here regarding Palo Alto firewalls unless someone happens to have used them or is still using them. And to be honest there is very little discussion here about other vendor products in general from what I have seen.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have personally never used the firewalls in question so I cant really help you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would imagine that the Palo alto has some manuals/document that would provide information about setting them up in different scenarios? I can't really say as I have never dealt with Palo Alto products.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Jul 2013 15:17:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewalls-management/m-p/2237588#M346853</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-07-08T15:17:12Z</dc:date>
    </item>
    <item>
      <title>Firewalls - Management</title>
      <link>https://community.cisco.com/t5/network-security/firewalls-management/m-p/2237589#M346856</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jouni,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Thanks for your reply. Iam just looking for the standard practices while connecting and managing Firewalls in general (be it Palo Alto or Cisco ASA), and in my case how best to assign management IPs to FWs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you could point me to the Cisco documentation on Firewall design, that would be helpful too.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Mikey&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Jul 2013 15:20:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewalls-management/m-p/2237589#M346856</guid>
      <dc:creator>Mikey John</dc:creator>
      <dc:date>2013-07-08T15:20:45Z</dc:date>
    </item>
    <item>
      <title>Firewalls - Management</title>
      <link>https://community.cisco.com/t5/network-security/firewalls-management/m-p/2237590#M346858</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Well when talking about Cisco ASAs I guess the main management setups would be to&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Use existing Data interfaces for management. This is a pretty common setup with regards to the situations I see here on the forums.&lt;/LI&gt;&lt;LI&gt;Use the separate Management interface solely for managing the firewall and connect this interface to its own Vlan/VRF on the core network.&lt;/LI&gt;&lt;LI&gt;Use a management network separate from the actual data network and connect this network either to the Management interface or have a separate device to provide Console access to the firewall directly. This would be especially good in certain troubleshooting situations.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Majority of the firewalls I manage are part of a separate management network isolated from all other networks. We have a predefined address space used for all those management purposes and reserve small subnets whenever a new device is connected to the network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With regards to the documents its hard to say. I have never really used any. I have mainly dicussed the options regarding our network with my more expirienced co-workers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Looking around quickly with Google will probably provide the same results as I got&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For example:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/solutions/SBA/August2012/Cisco_SBA_BN_FirewallAndIPSDeploymentGuide-Aug2012.pdf"&gt;http://www.cisco.com/en/US/docs/solutions/SBA/August2012/Cisco_SBA_BN_FirewallAndIPSDeploymentGuide-Aug2012.pdf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/solutions/Enterprise/Security/IE_DG.html#wp42252"&gt;http://www.cisco.com/en/US/docs/solutions/Enterprise/Security/IE_DG.html#wp42252&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Jul 2013 15:51:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewalls-management/m-p/2237590#M346858</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-07-08T15:51:31Z</dc:date>
    </item>
  </channel>
</rss>

