<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Firewall subinterface in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/firewall-subinterface/m-p/581359#M2866</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1278486673"&gt;@pyrainath&lt;/a&gt;, I would like to highlight two important considerations regarding this scenario:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;To create a subinterface, it is necessary to establish a VLAN in the configuration.&lt;/LI&gt;
&lt;LI&gt;Having two IPs from the same subnet on different interfaces or subinterfaces is not permissible.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
    <pubDate>Fri, 22 Mar 2024 15:22:08 GMT</pubDate>
    <dc:creator>jpomachagua</dc:creator>
    <dc:date>2024-03-22T15:22:08Z</dc:date>
    <item>
      <title>Firewall subinterface</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/firewall-subinterface/m-p/581174#M2860</link>
      <description>&lt;P&gt;Greetings,&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp;i have some doubts in configuring sub interface. i have eth1/1 (physical interface)ip-10.0.2.1 now for some testing i want to configure a sub interface for eth1/1 with same subnet like 10.0.2.2 and without vlan tag.&lt;/P&gt;
&lt;P&gt;will this work ???&amp;nbsp;&lt;/P&gt;
&lt;P&gt;can i have same network on both physical and sub interfaces ??&lt;/P&gt;
&lt;P&gt;what should i be aware of????&lt;/P&gt;</description>
      <pubDate>Thu, 21 Mar 2024 10:26:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/firewall-subinterface/m-p/581174#M2860</guid>
      <dc:creator>pyrainath</dc:creator>
      <dc:date>2024-03-21T10:26:31Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall subinterface</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/firewall-subinterface/m-p/581359#M2866</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1278486673"&gt;@pyrainath&lt;/a&gt;, I would like to highlight two important considerations regarding this scenario:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;To create a subinterface, it is necessary to establish a VLAN in the configuration.&lt;/LI&gt;
&lt;LI&gt;Having two IPs from the same subnet on different interfaces or subinterfaces is not permissible.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Fri, 22 Mar 2024 15:22:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/firewall-subinterface/m-p/581359#M2866</guid>
      <dc:creator>jpomachagua</dc:creator>
      <dc:date>2024-03-22T15:22:08Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall subinterface</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/firewall-subinterface/m-p/581447#M2872</link>
      <description>&lt;P&gt;greetings,&lt;/P&gt;
&lt;P&gt;Thank you so much for the information.....&lt;/P&gt;</description>
      <pubDate>Sat, 23 Mar 2024 05:33:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/firewall-subinterface/m-p/581447#M2872</guid>
      <dc:creator>pyrainath</dc:creator>
      <dc:date>2024-03-23T05:33:48Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall subinterface</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/firewall-subinterface/m-p/581448#M2873</link>
      <description>&lt;P&gt;hello &lt;SPAN class="UserName lia-user-name lia-user-rank-L2-Linker"&gt;&lt;SPAN class="lia-link-navigation lia-page-link lia-link-disabled lia-user-name-link" aria-disabled="true"&gt;&lt;SPAN class=""&gt;Jpomachagua,&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-L2-Linker"&gt;&lt;SPAN class="lia-link-navigation lia-page-link lia-link-disabled lia-user-name-link" aria-disabled="true"&gt;&lt;SPAN class=""&gt;The thing is we are borrowing bandwidth from another dept in my company .so they have a firewall. they give us some private ips and we configured that ip on one interface for example 10.x.x.1/29 and they map this ip with a public ip for our vpn connection. they have already mapped another public ip with 10.x.x.2/28 and this private ip is not yet configured on our firewall. now we have a requirement to host a webserver so we were hopping that we could dnat through 10.x.x.2/28. in order to do that we need to configure that ip on our firewall thats why we hope sub interface will do that job.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-L2-Linker"&gt;&lt;SPAN class="lia-link-navigation lia-page-link lia-link-disabled lia-user-name-link" aria-disabled="true"&gt;&lt;SPAN class=""&gt;1.can you give any other suggestion to make this work. ?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-L2-Linker"&gt;&lt;SPAN class="lia-link-navigation lia-page-link lia-link-disabled lia-user-name-link" aria-disabled="true"&gt;&lt;SPAN class=""&gt;2.what will actually happen if we configure&amp;nbsp;&lt;SPAN&gt;two IPs from the same subnet on different interfaces or sub interfaces?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-L2-Linker"&gt;&lt;SPAN class="lia-link-navigation lia-page-link lia-link-disabled lia-user-name-link" aria-disabled="true"&gt;&lt;SPAN class=""&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV id="messageEditor_614c89b74bd644_0" class="MessageEditor"&gt;&lt;A id="previewButton_614c89b74bd644_8cf4" class="lia-link-navigation lia-message-editor-preview-button" href="https://live.paloaltonetworks.com/t5/next-generation-firewall/firewall-subinterface/m-p/581359#" target="_blank"&gt;PREVIEW&lt;/A&gt;
&lt;DIV class="lia-js-block-events"&gt;
&lt;DIV class="lia-form-row lia-form-body-entry"&gt;
&lt;DIV class="lia-quilt-row lia-quilt-row-standard"&gt;
&lt;DIV class="lia-quilt-column lia-quilt-column-24 lia-quilt-column-single"&gt;
&lt;DIV class="lia-quilt-column-alley lia-quilt-column-alley-single"&gt;
&lt;DIV class="lia-form-input-wrapper"&gt;
&lt;DIV id="rich_614c89b74bd644_8cf4" class="message-body-editor lia-inline-message-body-editor"&gt;
&lt;DIV class="lia-inline-ajax-feedback"&gt;
&lt;DIV id="ajaxFeedback_614c89b74bd644_0_8cf4" class="AjaxFeedback"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV id="mceu_195" class="mce-tinymce mce-container mce-panel lia-editor-gte-2" tabindex="-1" role="application"&gt;
&lt;DIV id="mceu_195-body" class="mce-container-body mce-stack-layout"&gt;
&lt;DIV id="mceu_196" class="mce-top-part mce-container mce-stack-layout-item mce-first"&gt;
&lt;DIV id="mceu_196-body" class="mce-container-body"&gt;
&lt;DIV id="mceu_197" class="mce-toolbar-grp mce-container mce-panel mce-first mce-last" tabindex="-1" role="group"&gt;
&lt;DIV id="mceu_197-body" class="mce-container-body mce-stack-layout"&gt;
&lt;DIV id="mceu_198" class="mce-container mce-toolbar mce-stack-layout-item mce-first" role="toolbar"&gt;
&lt;DIV id="mceu_198-body" class="mce-container-body mce-flow-layout"&gt;
&lt;DIV id="mceu_199" class="mce-container mce-flow-layout-item mce-first mce-last mce-btn-group" role="group"&gt;
&lt;DIV id="mceu_199-body"&gt;
&lt;DIV id="mceu_156" class="mce-widget mce-btn mce-btn-small mce-first" tabindex="-1" role="button" aria-label="Undo" aria-disabled="false"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV id="mceu_157" class="mce-widget mce-btn mce-btn-small lia-mce-toolbar-bold" tabindex="-1" role="button" aria-pressed="false" aria-label="Bold"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Sat, 23 Mar 2024 07:40:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/firewall-subinterface/m-p/581448#M2873</guid>
      <dc:creator>pyrainath</dc:creator>
      <dc:date>2024-03-23T07:40:51Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall subinterface</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/firewall-subinterface/m-p/581771#M2893</link>
      <description>&lt;P&gt;Hello Pyrainath&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;An option is to set up two IPs on the same interface. The first IP, for instance, could be 10.10.10.1/29, and the second IP could be 10.10.10.2/32. This approach allows you to manage two IPs without the need to create a subinterface.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Tue, 26 Mar 2024 21:33:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/firewall-subinterface/m-p/581771#M2893</guid>
      <dc:creator>jpomachagua</dc:creator>
      <dc:date>2024-03-26T21:33:30Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall subinterface</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/firewall-subinterface/m-p/581805#M2895</link>
      <description>&lt;P&gt;Thanks again&amp;nbsp;&lt;SPAN&gt;Jpomachagua,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;so i have already configured the ip 10.10.10.1/29 on the physical interface eth1/1. so like u said i hope to configure the ip 10.10.10.2/32 on a loopback interface, will this work in my situation?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Mar 2024 06:55:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/firewall-subinterface/m-p/581805#M2895</guid>
      <dc:creator>pyrainath</dc:creator>
      <dc:date>2024-03-27T06:55:41Z</dc:date>
    </item>
  </channel>
</rss>

