<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Are Virtual Routers required? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/are-virtual-routers-required/m-p/512751#M106535</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/231978"&gt;@Nhussain&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;by default a Firewall is using management interface for this communication: Panorama and NTP/License Check&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you want to change that behavior, you can configure it by using service route. Here is corresponding KB:&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClGJCA0" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClGJCA0&lt;/A&gt;&amp;nbsp;From service route setting you can separate Panorama/Panorama Log Forwarding to use one dedicated data plane interface and for NTP and Palo Alto Networks Services (I think this one is used for license check)&amp;nbsp;to use different dedicated data plane interface. Any other data plane interface will be used for&amp;nbsp;&lt;SPAN&gt;East/West/North/South traffic depending on your configuration.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If you want to further separate data plane interfaces, you can create 2 Virtual Routes. One where you assign interfaces for&amp;nbsp;East/West/North/South traffic and another one for management where you assign interface for traffic from Firewall itself for Panorama, NTP/License Check communication.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Kind Regards&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Pavel&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 23 Aug 2022 21:46:57 GMT</pubDate>
    <dc:creator>PavelK</dc:creator>
    <dc:date>2022-08-23T21:46:57Z</dc:date>
    <item>
      <title>Are Virtual Routers required?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/are-virtual-routers-required/m-p/512735#M106531</link>
      <description>&lt;DIV class=""&gt;I am working with a customer whereby the requirements are to split different traffic by different interfaces. Its an internal firewall and will not route internet traffic
&lt;DIV class=""&gt;&amp;nbsp;
&lt;DIV class=""&gt;1x Interface for East/West/North/South traffic
&lt;DIV class=""&gt;1x Interface for communications to Panorama
&lt;DIV class=""&gt;1x Interface for any communication to internet targets the firewall needs(NTP/License Check)
&lt;DIV class=""&gt;&amp;nbsp;
&lt;DIV class=""&gt;If we want to achieve this flow would we have to use Virtual Routers for the&amp;nbsp;East/West/North/South. Are there any good articles for Multi-Interface setup of Palo alto? I know that is is against best practice however this is the requirements the customer has.&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Tue, 23 Aug 2022 19:33:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/are-virtual-routers-required/m-p/512735#M106531</guid>
      <dc:creator>Nhussain</dc:creator>
      <dc:date>2022-08-23T19:33:41Z</dc:date>
    </item>
    <item>
      <title>Re: Are Virtual Routers required?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/are-virtual-routers-required/m-p/512751#M106535</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/231978"&gt;@Nhussain&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;by default a Firewall is using management interface for this communication: Panorama and NTP/License Check&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you want to change that behavior, you can configure it by using service route. Here is corresponding KB:&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClGJCA0" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClGJCA0&lt;/A&gt;&amp;nbsp;From service route setting you can separate Panorama/Panorama Log Forwarding to use one dedicated data plane interface and for NTP and Palo Alto Networks Services (I think this one is used for license check)&amp;nbsp;to use different dedicated data plane interface. Any other data plane interface will be used for&amp;nbsp;&lt;SPAN&gt;East/West/North/South traffic depending on your configuration.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If you want to further separate data plane interfaces, you can create 2 Virtual Routes. One where you assign interfaces for&amp;nbsp;East/West/North/South traffic and another one for management where you assign interface for traffic from Firewall itself for Panorama, NTP/License Check communication.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Kind Regards&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Pavel&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Aug 2022 21:46:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/are-virtual-routers-required/m-p/512751#M106535</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2022-08-23T21:46:57Z</dc:date>
    </item>
    <item>
      <title>Re: Are Virtual Routers required?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/are-virtual-routers-required/m-p/512788#M106539</link>
      <description>&lt;P&gt;Thank you for your response.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So this article suggests it is possible&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClGJCA0" target="_blank" rel="nofollow noopener noreferrer"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClGJCA0&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;however once you implement virtual routers this no longer is possible. That is correct?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;"another one for management where you assign interface for traffic from Firewall itself for Panorama, NTP/License Check communication."&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;In this setup we move from using 2x interfaces to one interface for management? Is it not possible when using virtual routers to route the internet traffic(NTP) to a different interface and Panorama traffic to a different interface?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Aug 2022 07:32:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/are-virtual-routers-required/m-p/512788#M106539</guid>
      <dc:creator>Nhussain</dc:creator>
      <dc:date>2022-08-24T07:32:42Z</dc:date>
    </item>
    <item>
      <title>Re: Are Virtual Routers required?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/are-virtual-routers-required/m-p/512933#M106554</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/231978"&gt;@Nhussain&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thank you for reply.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I did basic verification in Lab Firewall and the answer is yes to both. It is possible to assign different interfaces to different VRs and still use them as a service routes:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PavelK_0-1661402060452.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/43372iF7AF27220708DFBC/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="PavelK_0-1661402060452.png" alt="PavelK_0-1661402060452.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PavelK_1-1661402151158.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/43373i5445C91533EA0BC7/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="PavelK_1-1661402151158.png" alt="PavelK_1-1661402151158.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Pavel&lt;/P&gt;</description>
      <pubDate>Thu, 25 Aug 2022 04:36:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/are-virtual-routers-required/m-p/512933#M106554</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2022-08-25T04:36:45Z</dc:date>
    </item>
  </channel>
</rss>

