<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Passing  a Circuit Prefix Through Palo Firewall in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/passing-a-circuit-prefix-through-palo-firewall/m-p/486418#M104605</link>
    <description>&lt;P&gt;I'll do my best to put this question into words.&lt;BR /&gt;&lt;BR /&gt;My company owns a /24 Public IP range. I have an engineering department that needs a /29 IP space off of that block for their &lt;STRONG&gt;Lab Environment&lt;/STRONG&gt;.&amp;nbsp;&lt;BR /&gt;I have a Juniper MX104 Router and a Palo 5220 Firewall.&lt;BR /&gt;&lt;BR /&gt;I'm not sure what my best steps are to get this circuit passed&amp;nbsp;&lt;STRONG&gt;through&lt;/STRONG&gt; the Firewall straight to the Lab environment (and Palo support is extremely slow at the moment).&lt;BR /&gt;&lt;BR /&gt;1. On the Juniper Router I have a Logical Interface created&amp;nbsp;&lt;STRONG&gt;irb.312&lt;/STRONG&gt; which is using the &lt;EM&gt;first available&lt;/EM&gt; IP in the /29 range.&lt;BR /&gt;2. On the Juniper Router I have a Physical interface created to be a&amp;nbsp;&lt;STRONG&gt;bridge&amp;nbsp;&lt;/STRONG&gt;interface using vlan-id 312&lt;BR /&gt;3. The&amp;nbsp;&lt;STRONG&gt;Lab&lt;/STRONG&gt; has an SRX that is setup to use the&amp;nbsp;&lt;EM&gt;second available&amp;nbsp;&lt;/EM&gt;IP in the /29 range.&lt;BR /&gt;&lt;BR /&gt;What are my best steps on the Palo? I was hoping a&amp;nbsp;&lt;STRONG&gt;Virtual Wire&lt;/STRONG&gt; would work, but the interface goes straight to&amp;nbsp;&lt;STRONG&gt;down&lt;/STRONG&gt; when I configure it as a Virtual Wire interface. I am hoping I don't need to create a Layer 3 interface on the Palo as I don't want to use anymore of the IPs available in the /29 (since the Edge Router and the Lab SRX are both using an IP in that /29 range already).&lt;BR /&gt;&lt;BR /&gt;In terms of "topology", we do want the traffic to pass through our Palo since that is what our Network Team manages. The Lab Firewall is not managed by us, so we don't want to bypass our own Firewall. If that makes sense?&lt;BR /&gt;&lt;BR /&gt;Any input would be appreciated!&lt;BR /&gt;Thank you.&lt;/P&gt;</description>
    <pubDate>Wed, 11 May 2022 17:39:52 GMT</pubDate>
    <dc:creator>TroyAbbott</dc:creator>
    <dc:date>2022-05-11T17:39:52Z</dc:date>
    <item>
      <title>Passing  a Circuit Prefix Through Palo Firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/passing-a-circuit-prefix-through-palo-firewall/m-p/486418#M104605</link>
      <description>&lt;P&gt;I'll do my best to put this question into words.&lt;BR /&gt;&lt;BR /&gt;My company owns a /24 Public IP range. I have an engineering department that needs a /29 IP space off of that block for their &lt;STRONG&gt;Lab Environment&lt;/STRONG&gt;.&amp;nbsp;&lt;BR /&gt;I have a Juniper MX104 Router and a Palo 5220 Firewall.&lt;BR /&gt;&lt;BR /&gt;I'm not sure what my best steps are to get this circuit passed&amp;nbsp;&lt;STRONG&gt;through&lt;/STRONG&gt; the Firewall straight to the Lab environment (and Palo support is extremely slow at the moment).&lt;BR /&gt;&lt;BR /&gt;1. On the Juniper Router I have a Logical Interface created&amp;nbsp;&lt;STRONG&gt;irb.312&lt;/STRONG&gt; which is using the &lt;EM&gt;first available&lt;/EM&gt; IP in the /29 range.&lt;BR /&gt;2. On the Juniper Router I have a Physical interface created to be a&amp;nbsp;&lt;STRONG&gt;bridge&amp;nbsp;&lt;/STRONG&gt;interface using vlan-id 312&lt;BR /&gt;3. The&amp;nbsp;&lt;STRONG&gt;Lab&lt;/STRONG&gt; has an SRX that is setup to use the&amp;nbsp;&lt;EM&gt;second available&amp;nbsp;&lt;/EM&gt;IP in the /29 range.&lt;BR /&gt;&lt;BR /&gt;What are my best steps on the Palo? I was hoping a&amp;nbsp;&lt;STRONG&gt;Virtual Wire&lt;/STRONG&gt; would work, but the interface goes straight to&amp;nbsp;&lt;STRONG&gt;down&lt;/STRONG&gt; when I configure it as a Virtual Wire interface. I am hoping I don't need to create a Layer 3 interface on the Palo as I don't want to use anymore of the IPs available in the /29 (since the Edge Router and the Lab SRX are both using an IP in that /29 range already).&lt;BR /&gt;&lt;BR /&gt;In terms of "topology", we do want the traffic to pass through our Palo since that is what our Network Team manages. The Lab Firewall is not managed by us, so we don't want to bypass our own Firewall. If that makes sense?&lt;BR /&gt;&lt;BR /&gt;Any input would be appreciated!&lt;BR /&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Wed, 11 May 2022 17:39:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/passing-a-circuit-prefix-through-palo-firewall/m-p/486418#M104605</guid>
      <dc:creator>TroyAbbott</dc:creator>
      <dc:date>2022-05-11T17:39:52Z</dc:date>
    </item>
    <item>
      <title>Re: Passing  a Circuit Prefix Through Palo Firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/passing-a-circuit-prefix-through-palo-firewall/m-p/486463#M104608</link>
      <description>&lt;P&gt;Hi Troy,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How about if rather than configuring the /29 on the router int, what if you route the /29 toward the Palo and the configure /29 one int on PA and one SRX?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Router &amp;lt;&amp;gt; route n.n.n.n/29 &amp;gt; PA &amp;lt;int&amp;gt;/29&amp;nbsp; &amp;nbsp;&amp;lt;int&amp;gt;/29SRx&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 11 May 2022 21:02:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/passing-a-circuit-prefix-through-palo-firewall/m-p/486463#M104608</guid>
      <dc:creator>Y-alwaysMe</dc:creator>
      <dc:date>2022-05-11T21:02:18Z</dc:date>
    </item>
    <item>
      <title>Re: Passing  a Circuit Prefix Through Palo Firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/passing-a-circuit-prefix-through-palo-firewall/m-p/486539#M104610</link>
      <description>&lt;P&gt;Instead of assigning IPs on the MX and PA within the /29 block that you want to use behind the firewall, could you just route the entire /24 to the PA, and then route the /29 to the SRX? From your description I am assuming you are BGP announcing the /24 from the MX104?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Setup a private inter-network range between the MX104 and the PA (say, 198.18.x.x/30) and route the /24 to the PA. On the PA assign the public IPs you want to use locally to a loopback interface as /32s. Then use another 198.18.x.x/30 to route the /29 to the LAB SRX behind the PA. Advantages: you don't have use the publics for routing, can put a suballocation for third party devices on a DMZ interface, can send suballocations to different routers behind the PA, and can pick off individual IPs to use on the PA. Disadvantages: if your DMZ is already using IPs scattered across a fixed /24 subnet, subdividing gets messy.&lt;/P&gt;</description>
      <pubDate>Wed, 11 May 2022 22:49:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/passing-a-circuit-prefix-through-palo-firewall/m-p/486539#M104610</guid>
      <dc:creator>Adrian_Jensen</dc:creator>
      <dc:date>2022-05-11T22:49:01Z</dc:date>
    </item>
    <item>
      <title>Re: Passing  a Circuit Prefix Through Palo Firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/passing-a-circuit-prefix-through-palo-firewall/m-p/487479#M104719</link>
      <description>&lt;P&gt;Thank you very much for the quick response to this. It provided extremely helpful steps in my troubleshooting process!&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;I ended up getting the Palo Alto Virtual Wire to work out in this scenario so I didn't have to set up too many routes.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But again, thank you!&lt;/P&gt;</description>
      <pubDate>Mon, 16 May 2022 15:10:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/passing-a-circuit-prefix-through-palo-firewall/m-p/487479#M104719</guid>
      <dc:creator>TroyAbbott</dc:creator>
      <dc:date>2022-05-16T15:10:45Z</dc:date>
    </item>
  </channel>
</rss>

