<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Sub Interfaces or VLAN interfaces supported on VM-300 in AWS? in VM-Series in the Public Cloud</title>
    <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/sub-interfaces-or-vlan-interfaces-supported-on-vm-300-in-aws/m-p/350338#M997</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/93962"&gt;@pmchenry&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes,&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp; is correct we don't support sub-interfaces in Public Cloud for now. There is no workaround for this.&amp;nbsp;&lt;/P&gt;&lt;P&gt;As already mentioned you should plan your design and to avoid this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Torsten&lt;/P&gt;</description>
    <pubDate>Fri, 18 Sep 2020 07:32:50 GMT</pubDate>
    <dc:creator>tostern</dc:creator>
    <dc:date>2020-09-18T07:32:50Z</dc:date>
    <item>
      <title>Sub Interfaces or VLAN interfaces supported on VM-300 in AWS?</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/sub-interfaces-or-vlan-interfaces-supported-on-vm-300-in-aws/m-p/350200#M994</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We were wondering if sub-interfaces or VLAN interfaces are supported on the VM seriies in AWS.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We would like to separate customer traffic using these VLANs/ sub-interfaces as we do in our own DC, but it doesn't seem possible in AWS on the VM-300 as there are no options when I highlight the individual interface.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If sub-interfaces and VLANs are not supported, are there any work-arounds?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you, Pat&lt;/P&gt;</description>
      <pubDate>Thu, 17 Sep 2020 18:24:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/sub-interfaces-or-vlan-interfaces-supported-on-vm-300-in-aws/m-p/350200#M994</guid>
      <dc:creator>pmchenry</dc:creator>
      <dc:date>2020-09-17T18:24:53Z</dc:date>
    </item>
    <item>
      <title>Re: Sub Interfaces or VLAN interfaces supported on VM-300 in AWS?</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/sub-interfaces-or-vlan-interfaces-supported-on-vm-300-in-aws/m-p/350291#M996</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/93962"&gt;@pmchenry&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;You are correct, this is a known limitation within AWS. The only interface type that you are allowed is layer3, and VLAN and subinterface isn't supported at all. There's really no way to workaround that issue that I'm aware of, at that point you would be having more of a design discussion about how the environment is being built out and isolated.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Sep 2020 04:41:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/sub-interfaces-or-vlan-interfaces-supported-on-vm-300-in-aws/m-p/350291#M996</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2020-09-18T04:41:08Z</dc:date>
    </item>
    <item>
      <title>Re: Sub Interfaces or VLAN interfaces supported on VM-300 in AWS?</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/sub-interfaces-or-vlan-interfaces-supported-on-vm-300-in-aws/m-p/350338#M997</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/93962"&gt;@pmchenry&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes,&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp; is correct we don't support sub-interfaces in Public Cloud for now. There is no workaround for this.&amp;nbsp;&lt;/P&gt;&lt;P&gt;As already mentioned you should plan your design and to avoid this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Torsten&lt;/P&gt;</description>
      <pubDate>Fri, 18 Sep 2020 07:32:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/sub-interfaces-or-vlan-interfaces-supported-on-vm-300-in-aws/m-p/350338#M997</guid>
      <dc:creator>tostern</dc:creator>
      <dc:date>2020-09-18T07:32:50Z</dc:date>
    </item>
    <item>
      <title>Re: Sub Interfaces or VLAN interfaces supported on VM-300 in AWS?</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/sub-interfaces-or-vlan-interfaces-supported-on-vm-300-in-aws/m-p/352706#M1014</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/157312"&gt;@Welborn&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i dont' understand the question. could you please explain what are you trying to do?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Torsten&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 10:39:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/sub-interfaces-or-vlan-interfaces-supported-on-vm-300-in-aws/m-p/352706#M1014</guid>
      <dc:creator>tostern</dc:creator>
      <dc:date>2020-09-29T10:39:51Z</dc:date>
    </item>
    <item>
      <title>Re: Sub Interfaces or VLAN interfaces supported on VM-300 in AWS?</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/sub-interfaces-or-vlan-interfaces-supported-on-vm-300-in-aws/m-p/574033#M2084</link>
      <description>&lt;P&gt;I am confused on the idea that Sub-Interfaces are not supported, I am following the Palo Alto AWS Design and Deployment documentation and very specifically they call for a Sub-Interface, here is the link for the Palo Alto published document and jump to page 79 section 3.8 titled "Add Private Sub-Interface".&amp;nbsp; This blows my mind!&lt;BR /&gt;LINK:&amp;nbsp;&amp;nbsp;&lt;A href="https://www.paloaltonetworks.com/apps/pan/public/downloadResource?pagePath=/content/pan/en_US/resources/guides/aws-transit-gateway-deployment-guide" target="_blank"&gt;*Securing Application in AWS - Centralized Model Deployment Guide (paloaltonetworks.com)&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jan 2024 05:48:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/sub-interfaces-or-vlan-interfaces-supported-on-vm-300-in-aws/m-p/574033#M2084</guid>
      <dc:creator>RDarcy</dc:creator>
      <dc:date>2024-01-23T05:48:51Z</dc:date>
    </item>
    <item>
      <title>Re: Sub Interfaces or VLAN interfaces supported on VM-300 in AWS?</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/sub-interfaces-or-vlan-interfaces-supported-on-vm-300-in-aws/m-p/574395#M2088</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/126115"&gt;@RDarcy&lt;/a&gt;&amp;nbsp;you're replying to an old post when sub-interfaces were not supported. The design you're referring to leverages&lt;FONT face="inherit"&gt;&amp;nbsp;GWLB endpoint mapping, which allows you to associate traffic received by a GWLBe with a sub-interface and therefore security zone, however in the Central Design Model you can only separate Outbound from East/West as the chosen GWLBe is determined by the destination IP in the TGW &lt;/FONT&gt;attachment&lt;FONT face="inherit"&gt;&amp;nbsp;subnet's route table (good explanation at &lt;A href="https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/gwlb-sub-interface/m-p/504218/highlight/true#M1592" target="_blank"&gt;LIVEcommunity - Re: GWLB Sub-Interface - LIVEcommunity - 502945 (paloaltonetworks.com)&lt;/A&gt;)&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Note the sub-interfaces have no relation to VLANs, just the GWLB endpoint ID in the GENEVE header supplied by the GWLB to the firewall.&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jan 2024 06:41:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/sub-interfaces-or-vlan-interfaces-supported-on-vm-300-in-aws/m-p/574395#M2088</guid>
      <dc:creator>mb_equate</dc:creator>
      <dc:date>2024-01-25T06:41:46Z</dc:date>
    </item>
    <item>
      <title>Re: Sub Interfaces or VLAN interfaces supported on VM-300 in AWS?</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/sub-interfaces-or-vlan-interfaces-supported-on-vm-300-in-aws/m-p/574434#M2089</link>
      <description>&lt;P&gt;I would also recommend reading the relevant Design Guide (&lt;A href="https://www.paloaltonetworks.com/resources/guides/intelligent-architectures-aws-reference-architecture" target="_blank"&gt;Securing Applications in AWS - Design Guide - Palo Alto Networks&lt;/A&gt;) as it explains the use of subinterfaces with AWS GWLB.&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jan 2024 08:49:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/sub-interfaces-or-vlan-interfaces-supported-on-vm-300-in-aws/m-p/574434#M2089</guid>
      <dc:creator>mb_equate</dc:creator>
      <dc:date>2024-01-25T08:49:29Z</dc:date>
    </item>
  </channel>
</rss>

