<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PA firewall conencting to the CISCO router in VRF lite in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/pa-firewall-conencting-to-the-cisco-router-in-vrf-lite/m-p/525905#M729</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/265475"&gt;@Tech_pp&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Could you verify the license on the C9300 as requested before?&amp;nbsp; That's the only thing I can think of right now.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So you are placing the IP addresses on the interfaces and not using VLANs?&amp;nbsp; Then what I said earlier still applies to the physical interfaces and not the VLAN interfaces.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You are correct in that no configuration is required on the NGFW for the VRF.&amp;nbsp; The VRF is local to the C9300.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
    <pubDate>Wed, 04 Jan 2023 14:36:32 GMT</pubDate>
    <dc:creator>TomYoung</dc:creator>
    <dc:date>2023-01-04T14:36:32Z</dc:date>
    <item>
      <title>PA firewall conencting to the CISCO router in VRF lite</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/pa-firewall-conencting-to-the-cisco-router-in-vrf-lite/m-p/525863#M725</link>
      <description>&lt;P&gt;Trying to connect a cisco 9300 device with 2 VRF's accross the PA firewall. the PA firewall can not ping the attached 9300 interface in a VRF. IF the interface is taken out of the VRF the connectivity works.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Dose any one know whats causing this&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jan 2023 09:58:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/pa-firewall-conencting-to-the-cisco-router-in-vrf-lite/m-p/525863#M725</guid>
      <dc:creator>Tech_pp</dc:creator>
      <dc:date>2023-01-04T09:58:08Z</dc:date>
    </item>
    <item>
      <title>Re: PA firewall conencting to the CISCO router in VRF lite</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/pa-firewall-conencting-to-the-cisco-router-in-vrf-lite/m-p/525900#M727</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/265475"&gt;@Tech_pp&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Given the small amount of information, I have to make certain assumptions.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you can ping outside the VRF...&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;the interface and VLAN configurations are probably correct, and&lt;/LI&gt;
&lt;LI&gt;L2 connectivity is good, and&lt;/LI&gt;
&lt;LI&gt;the Management Profile (if pinging the NGFW) is probably correct.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;It sounds like an issue with the C9300.&amp;nbsp; No changes are made on the NGFW between working and not.&amp;nbsp; You may need to go to the Cisco forum.&amp;nbsp; However, I will add a couple thoughts.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Placing a VLAN interface inside a VRF is only one command, "ip vrf forwarding VRF_NAME", and it would fail if the VRF were not created.&amp;nbsp; You should get a warning the IP address has been removed and needs to be re-added.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Network Advantage is required for VRFs on the C9300.&amp;nbsp; What does "show license summary" show on your C9300?&amp;nbsp; I don't know if you would get an error if you tried to create a VRF without the proper license.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jan 2023 14:01:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/pa-firewall-conencting-to-the-cisco-router-in-vrf-lite/m-p/525900#M727</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2023-01-04T14:01:46Z</dc:date>
    </item>
    <item>
      <title>Re: PA firewall conencting to the CISCO router in VRF lite</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/pa-firewall-conencting-to-the-cisco-router-in-vrf-lite/m-p/525903#M728</link>
      <description>Hi Tom,&lt;BR /&gt;&lt;BR /&gt;The setup Is as below&lt;BR /&gt;&lt;BR /&gt;PA firewall is connected with point to point physical connections to a 9300&lt;BR /&gt;1 connection (Inside) is in 1 VRF and the other (Outside) in the other VRF (Default)&lt;BR /&gt;&lt;BR /&gt;I cant ping from the other end of the link from the firewall when the interface on the 9300 is in a VRF, if I move it out of the ver and place it in the default the IP reachability is established.&lt;BR /&gt;&lt;BR /&gt;Is there a specific config I am missing or required on the PA for connecting into a VRF?  I did not think so since VRF is a local concept. (The PA are in active/active setup). I can't get this connectivity for Primary as well as secondary)&lt;BR /&gt;&lt;BR /&gt;The config on the 9300 is good in my opinion&lt;BR /&gt;      Interface is allocated to a VRF and given an IP address (/30)&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Thanks &amp;amp; best regards&lt;BR /&gt;Prasanna Patki&lt;BR /&gt;#CCIE (RS, Sec, DC)</description>
      <pubDate>Wed, 04 Jan 2023 14:24:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/pa-firewall-conencting-to-the-cisco-router-in-vrf-lite/m-p/525903#M728</guid>
      <dc:creator>Tech_pp</dc:creator>
      <dc:date>2023-01-04T14:24:52Z</dc:date>
    </item>
    <item>
      <title>Re: PA firewall conencting to the CISCO router in VRF lite</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/pa-firewall-conencting-to-the-cisco-router-in-vrf-lite/m-p/525905#M729</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/265475"&gt;@Tech_pp&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Could you verify the license on the C9300 as requested before?&amp;nbsp; That's the only thing I can think of right now.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So you are placing the IP addresses on the interfaces and not using VLANs?&amp;nbsp; Then what I said earlier still applies to the physical interfaces and not the VLAN interfaces.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You are correct in that no configuration is required on the NGFW for the VRF.&amp;nbsp; The VRF is local to the C9300.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jan 2023 14:36:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/pa-firewall-conencting-to-the-cisco-router-in-vrf-lite/m-p/525905#M729</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2023-01-04T14:36:32Z</dc:date>
    </item>
    <item>
      <title>Re: PA firewall conencting to the CISCO router in VRF lite</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/pa-firewall-conencting-to-the-cisco-router-in-vrf-lite/m-p/525906#M730</link>
      <description>&lt;P&gt;The cat is having an advantage License.&lt;/P&gt;
&lt;P&gt;The ip is on a l3 point to point no svi's&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My thoughts as well. it is in my lab so will go through it again to see what the issue is. May be some thing to do with clustering Active/Active&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Will keep yo uposted here&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Prasanna&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jan 2023 14:41:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/pa-firewall-conencting-to-the-cisco-router-in-vrf-lite/m-p/525906#M730</guid>
      <dc:creator>Tech_pp</dc:creator>
      <dc:date>2023-01-04T14:41:24Z</dc:date>
    </item>
  </channel>
</rss>

