<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Palo FW setup site to site in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/palo-fw-setup-site-to-site/m-p/479559#M103908</link>
    <description>&lt;P&gt;You can control the access in your end Firewall&amp;nbsp;&lt;SPAN&gt;3220.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Your partner network have dedicated fiber line till your network right. Then just create a VLAN in PA3220 assign it to security zone for ACL rule creation and extend it to your partner network switch.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 11 Apr 2022 02:54:29 GMT</pubDate>
    <dc:creator>JANARTHANAN1392</dc:creator>
    <dc:date>2022-04-11T02:54:29Z</dc:date>
    <item>
      <title>Palo FW setup site to site</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-fw-setup-site-to-site/m-p/477771#M103703</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;We have a HA fw 3220 in our environment and our partner want to access some of our resources. They propose a PA-440 fw +&amp;nbsp; small 12-port-Cisco 3560 in between the two sites by dark fiber.&lt;/P&gt;&lt;P&gt;Just wonder if you can setup FWs back to back instead of having a switch in between ie a extra point of failure?&lt;/P&gt;&lt;P&gt;is the Gateway going to be the switch or the FW440 behind it?&lt;/P&gt;&lt;P&gt;Any suggestion are much appreciated.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;QL&lt;/P&gt;</description>
      <pubDate>Mon, 04 Apr 2022 00:57:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-fw-setup-site-to-site/m-p/477771#M103703</guid>
      <dc:creator>Qui</dc:creator>
      <dc:date>2022-04-04T00:57:38Z</dc:date>
    </item>
    <item>
      <title>Re: Palo FW setup site to site</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-fw-setup-site-to-site/m-p/478470#M103765</link>
      <description>&lt;P&gt;I do not believe any of the PA4xx series including SFP ports, to connect up to fiber.&amp;nbsp; A media converter would work in lieu of a switch, but it is still a Single Point of Failure....&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Why not configure the FW to setup a site to site VPN to more securely connect.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Why not configure Global Protect and control where the users are allowed to client vpn into?&lt;/P&gt;&lt;P&gt;Why not configure clientless VPN and let the outside team use the FW to proxy internally inside of your network.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Lots o' questions.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Apr 2022 20:08:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-fw-setup-site-to-site/m-p/478470#M103765</guid>
      <dc:creator>S.Cantwell</dc:creator>
      <dc:date>2022-04-05T20:08:33Z</dc:date>
    </item>
    <item>
      <title>Re: Palo FW setup site to site</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-fw-setup-site-to-site/m-p/478794#M103807</link>
      <description>Hi Steve,&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Thank you for your advice.&lt;BR /&gt;&lt;BR /&gt;We have already dark-fiber in place and I think it would be more secure/faster than other VPN option.&lt;BR /&gt;&lt;BR /&gt;Thanks again.&lt;BR /&gt;&lt;BR /&gt;Qui&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Thu, 07 Apr 2022 00:30:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-fw-setup-site-to-site/m-p/478794#M103807</guid>
      <dc:creator>Qui</dc:creator>
      <dc:date>2022-04-07T00:30:02Z</dc:date>
    </item>
    <item>
      <title>Re: Palo FW setup site to site</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-fw-setup-site-to-site/m-p/479041#M103842</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I prefer to put the layer 3 VLAN interface as a VLAN interface on the PAN. This way you have more granular control of the traffic using security policies and have the traffic inspected.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Thu, 07 Apr 2022 16:59:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-fw-setup-site-to-site/m-p/479041#M103842</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2022-04-07T16:59:05Z</dc:date>
    </item>
    <item>
      <title>Re: Palo FW setup site to site</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-fw-setup-site-to-site/m-p/479450#M103894</link>
      <description>&lt;P&gt;This is a simple and doesn't required to add PA 440+ Just 12port switch is enough.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 09 Apr 2022 06:18:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-fw-setup-site-to-site/m-p/479450#M103894</guid>
      <dc:creator>JANARTHANAN1392</dc:creator>
      <dc:date>2022-04-09T06:18:15Z</dc:date>
    </item>
    <item>
      <title>Re: Palo FW setup site to site</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-fw-setup-site-to-site/m-p/479537#M103903</link>
      <description>HI JANARTHANAN,&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Does it mean we need to have ACL on the 12 port switch ?&lt;BR /&gt;&lt;BR /&gt;Because we only want them to access certain resources.&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;BR /&gt;&lt;BR /&gt;Q&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Mon, 11 Apr 2022 00:06:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-fw-setup-site-to-site/m-p/479537#M103903</guid>
      <dc:creator>Qui</dc:creator>
      <dc:date>2022-04-11T00:06:02Z</dc:date>
    </item>
    <item>
      <title>Re: Palo FW setup site to site</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-fw-setup-site-to-site/m-p/479559#M103908</link>
      <description>&lt;P&gt;You can control the access in your end Firewall&amp;nbsp;&lt;SPAN&gt;3220.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Your partner network have dedicated fiber line till your network right. Then just create a VLAN in PA3220 assign it to security zone for ACL rule creation and extend it to your partner network switch.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Apr 2022 02:54:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-fw-setup-site-to-site/m-p/479559#M103908</guid>
      <dc:creator>JANARTHANAN1392</dc:creator>
      <dc:date>2022-04-11T02:54:29Z</dc:date>
    </item>
  </channel>
</rss>

