When Firewall's service route is configured with ethernet interface for Panorama, why is Panorama displaying connected to firewall's management interface?

When Firewall's service route is configured with ethernet interface for Panorama, why is Panorama displaying connected to firewall's management interface?

9039
Created On 08/30/20 21:28 PM - Last Modified 05/20/25 02:25 AM


Question


When Firewall's service route is configured with ethernet interface for Panorama, why is Panorama displaying connected to firewall's management interface?
 

Example:

  • Topology
User-added image
  • Firewall's Service Route
User-added image
  • Panorama:
panorma> show devices connected | match <firewall's serial-number>

<firewall's serial-number>             <firewall's hostname>        <firewall's management-interface-ip>  unknown                                yes
  Certificate subject Name: <firewall's serial-number>

panorama> show netstat numeric yes | match 3978
tcp6 0 0 <panorama's ip-address>:3978 <firewall's ethernet-ip-address>:52570 ESTABLISHED
  • Firewall:
Firewall> show system info
hostname: Firewall
ip-address: <mgmt ip>
public-ip-address: unknown
serial: <serial-number>

Firewall> show netstat numeric yes | match 3978
tcp 0 0 <firewall's ethernet-ip-address>:39938 <panorama's ip-address>:3978 ESTABLISHED


Environment


  • Palo Alto Firewalls and Panorama
  • PANOS versions: 8.1.x, 9.0.x, 9.1.x, 10.0.x


Answer


  1. The IP address of the firewall on Panorama is fetched from the show system info command of the firewall
  2. For the non ZTP firewall, Panorama will display the IP address of the firewall mgmt interface


Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000HAZ2CAO&lang=en_US&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language