<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Help With Configure PA-220 in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/help-with-configure-pa-220/m-p/472043#M103174</link>
    <description>&lt;P&gt;A switch would be L2, not L3. You can connect the servers directly to the PA-220, but you will need to decide if each port will be its own network (L3 routing thru the PaloAlto between servers), or if you will try to bridge all 3 server ports together into a single L2 network. See this for bridging L2 ports:&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClRqCAK" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClRqCAK&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 10 Mar 2022 16:17:11 GMT</pubDate>
    <dc:creator>Adrian_Jensen</dc:creator>
    <dc:date>2022-03-10T16:17:11Z</dc:date>
    <item>
      <title>Help With Configure PA-220</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/help-with-configure-pa-220/m-p/471748#M103135</link>
      <description>&lt;P&gt;I am trying to build firewall from scratch. Our use case is to secure 3 servers with separate DSP connected to PA-220. We do not have any managed switch or router between ISP to firewall. It is direct from modem to firewall.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can anyone help with this? Palo Alto's documentation isnt helpful as I am not network guru.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Mar 2022 20:59:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/help-with-configure-pa-220/m-p/471748#M103135</guid>
      <dc:creator>PranamShah</dc:creator>
      <dc:date>2022-03-09T20:59:27Z</dc:date>
    </item>
    <item>
      <title>Re: Help With Configure PA-220</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/help-with-configure-pa-220/m-p/471858#M103140</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/212204"&gt;@PranamShah&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;That a broad request.&amp;nbsp; I'd recommend checking out some of the getting started guides.&amp;nbsp; You'll find plenty of those on our &lt;A href="https://www.youtube.com/channel/UCPRouchFt58TZnjoI65aelA" target="_blank" rel="noopener"&gt;LIVEcommunity YouTube channel&lt;/A&gt; over a variety of different topics.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There's also the &lt;A href="https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/getting-started.html" target="_blank" rel="noopener"&gt;getting started documentation DOC&lt;/A&gt; which provides detailed steps to help you deploy a new Palo Alto Networks next-generation firewall.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;These should definitely help to get you started.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;-Kiwi.&lt;/P&gt;
&lt;DIV id="ConnectiveDocSignExtentionInstalled" data-extension-version="1.0.4"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Thu, 10 Mar 2022 09:12:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/help-with-configure-pa-220/m-p/471858#M103140</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2022-03-10T09:12:33Z</dc:date>
    </item>
    <item>
      <title>Re: Help With Configure PA-220</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/help-with-configure-pa-220/m-p/471988#M103165</link>
      <description>&lt;P&gt;Thanks Kiwi.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do you know if my use case as below is Valid?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;3 servers&lt;/LI&gt;&lt;LI&gt;ISP (Modem) to PA-220 directly&lt;/LI&gt;&lt;LI&gt;No router or switch&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do I need to have Switch (L3) / Router (L3) between my servers and PA-220 or can I directly plug in Servers to PA-220?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Mar 2022 14:19:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/help-with-configure-pa-220/m-p/471988#M103165</guid>
      <dc:creator>PranamShah</dc:creator>
      <dc:date>2022-03-10T14:19:21Z</dc:date>
    </item>
    <item>
      <title>Re: Help With Configure PA-220</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/help-with-configure-pa-220/m-p/472043#M103174</link>
      <description>&lt;P&gt;A switch would be L2, not L3. You can connect the servers directly to the PA-220, but you will need to decide if each port will be its own network (L3 routing thru the PaloAlto between servers), or if you will try to bridge all 3 server ports together into a single L2 network. See this for bridging L2 ports:&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClRqCAK" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClRqCAK&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Mar 2022 16:17:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/help-with-configure-pa-220/m-p/472043#M103174</guid>
      <dc:creator>Adrian_Jensen</dc:creator>
      <dc:date>2022-03-10T16:17:11Z</dc:date>
    </item>
    <item>
      <title>Re: Help With Configure PA-220</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/help-with-configure-pa-220/m-p/472198#M103182</link>
      <description>&lt;P&gt;Thanks Adrian.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;L2 switch is an unmanaged switch isn't it? Managed switch would be L3?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So basically I can not connect Server/VM Hosts directly to one one of 8 available interfaces on PA-220? Do I have to have a switch? And if yes, will unmanaged switch work or do I have to buy a managed switch?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also for the internet to PA-220, can I connect ISP Modem directly to PA-220 and configure public IP on either management port or one of the interfaces?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Something like below is what I want to achieve. Is it viable?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="palo-alto-flow.png" style="width: 349px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/39587i6461DCD16791E6A2/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="palo-alto-flow.png" alt="palo-alto-flow.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Sorry to ask some basics but I am a bit new to this.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Mar 2022 00:48:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/help-with-configure-pa-220/m-p/472198#M103182</guid>
      <dc:creator>PranamShah</dc:creator>
      <dc:date>2022-03-11T00:48:57Z</dc:date>
    </item>
    <item>
      <title>Re: Help With Configure PA-220</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/help-with-configure-pa-220/m-p/472199#M103183</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/212204"&gt;@PranamShah&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes, it is viable.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;You can connect the ISP directly to the PA-220.&lt;/LI&gt;&lt;LI&gt;You can connect your servers directly to the PA-220.&lt;/LI&gt;&lt;LI&gt;Set the ISP interface to L3 in a L3 untrust zone with the public IP.&lt;/LI&gt;&lt;LI&gt;Set your server interfaces to L2 in a L2 zone.&amp;nbsp; Put them in the same VLAN.&lt;/LI&gt;&lt;LI&gt;Create a L3 VLAN interface tied to the L2 VLAN in a L3 trust zone.&lt;/LI&gt;&lt;LI&gt;Create default route to ISP.&lt;/LI&gt;&lt;LI&gt;Create DIPP NAT rule to outside interface IP from trust zone to untrust zone.&lt;/LI&gt;&lt;LI&gt;Create security policy rule to allow traffic from trust zone to untrust zone.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Fri, 11 Mar 2022 01:11:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/help-with-configure-pa-220/m-p/472199#M103183</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2022-03-11T01:11:36Z</dc:date>
    </item>
    <item>
      <title>Re: Help With Configure PA-220</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/help-with-configure-pa-220/m-p/472407#M103207</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/212204"&gt;@PranamShah&lt;/a&gt;&amp;nbsp;wrote:&lt;P&gt;L2 switch is an unmanaged switch isn't it? Managed switch would be L3&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&amp;nbsp;No... A switch is always an L2 device, a device that receives packets in one port and sends packets out to other ports based on destination MAC address. It works on layer 2, the packet MAC hardware destination address. (OK... this gets a bit complicated as there are L2/L3+ switches, but for the definition of "switch", it is always a layer 2 device). An unmanaged switch is just that, a collection of ports that just pass packets based on MAC destination. A managed switch allows you to segment the switch into different layer 2 domains (VLANs), acting as multiple switches in one. (ports 1-4 are one VLAN, ports 5-6 are a different VLAN, etc., packets from 1-4 don't pass to ports 5-6).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;A L3 device works on layer 3 - the IP address. It receives packets on one port (this is typically the gateway IP of the network) and routes them to other ports/networks based on the destination IP address. Hence an L3 device is a router.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The PaloAlto ports can be configured as L3 router ports (the default) or as L2 switch ports (done by creating a VLAN to route L3 on and assigning it to multiple ports).&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="network.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/39597i16AC1AF080800FAB/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="network.png" alt="network.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Mar 2022 17:17:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/help-with-configure-pa-220/m-p/472407#M103207</guid>
      <dc:creator>Adrian_Jensen</dc:creator>
      <dc:date>2022-03-11T17:17:53Z</dc:date>
    </item>
  </channel>
</rss>

