<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Subinterfaces with same VLAN tag in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/subinterfaces-with-same-vlan-tag/m-p/518076#M107480</link>
    <description>&lt;P&gt;Same VLAN cannot exist in multiple subinterface under 1 physical interface. Same subinterface under 1 physical interface cannot assign to multiple vsys(es). Therefore, the only workaround is to create the same VLAN ID under multiple physical interfaces in order to assign to multiple vsys(es) to the same VLAN. To save the 10G interface capacity, you might wanna trunk that interface.&lt;/P&gt;</description>
    <pubDate>Mon, 17 Oct 2022 06:45:26 GMT</pubDate>
    <dc:creator>KengSeng</dc:creator>
    <dc:date>2022-10-17T06:45:26Z</dc:date>
    <item>
      <title>Subinterfaces with same VLAN tag</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/subinterfaces-with-same-vlan-tag/m-p/194570#M58197</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;We are designing a setup with PA 3060. On that we plan to have 2 vsys, lets call them V1 and V2.&lt;/P&gt;&lt;P&gt;I have an aggregated interface, lets call it ae22.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I want to create 2 subinterfaces:&lt;/P&gt;&lt;P&gt;ae22.1 ----- will be assigned to V1&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;ae22.2 ----- will be assigned to V2&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Question: Can ae22.1 and ae22.2 have the same vlan number lets say vlan 100 ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks and Regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;R&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jan 2018 12:17:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/subinterfaces-with-same-vlan-tag/m-p/194570#M58197</guid>
      <dc:creator>rjdahav163</dc:creator>
      <dc:date>2018-01-10T12:17:01Z</dc:date>
    </item>
    <item>
      <title>Re: Subinterfaces with same VLAN tag</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/subinterfaces-with-same-vlan-tag/m-p/194593#M58203</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/44973"&gt;@rjdahav163&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Since they will be assinged to a different vsys this shouldn't pose any issues at all.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jan 2018 13:58:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/subinterfaces-with-same-vlan-tag/m-p/194593#M58203</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-01-10T13:58:22Z</dc:date>
    </item>
    <item>
      <title>Re: Subinterfaces with same VLAN tag</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/subinterfaces-with-same-vlan-tag/m-p/231454#M66448</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is not possible, you can not use the same vlan tag on the same aggregated interface for layer3 sub-interfaces. I also tried using a L2 aggregated interface with 2 vlan interfaces but no success &amp;gt;&amp;gt; "&amp;nbsp;No two logical aggregate interfaces can have same tag value."&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I guess you already figured this out the hard way.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So as far as I know now it is not possible to have 2 or more vsys to have a IP in the same network/vlan when this is going via one and the same aggregated interface.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;kr,&lt;/P&gt;&lt;P&gt;Tommy&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Sep 2018 11:16:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/subinterfaces-with-same-vlan-tag/m-p/231454#M66448</guid>
      <dc:creator>tommyschoemans</dc:creator>
      <dc:date>2018-09-19T11:16:12Z</dc:date>
    </item>
    <item>
      <title>Re: Subinterfaces with same VLAN tag</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/subinterfaces-with-same-vlan-tag/m-p/438801#M99467</link>
      <description>&lt;P&gt;hello, have you figured a way to handle your design requirement? I am facing similar problem to have multiple interfaces with same dot1q tag between vSYS.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Oct 2021 12:27:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/subinterfaces-with-same-vlan-tag/m-p/438801#M99467</guid>
      <dc:creator>psycoma1984</dc:creator>
      <dc:date>2021-10-05T12:27:20Z</dc:date>
    </item>
    <item>
      <title>Re: Subinterfaces with same VLAN tag</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/subinterfaces-with-same-vlan-tag/m-p/438814#M99469</link>
      <description>&lt;P&gt;HI&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/44973"&gt;@rjdahav163&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can I ask why you need the same vlan tag to span the Vsys ? under any condition I would think this would be strange configuration but I have seen stranger requirements, As far as I am aware the configuration as you want it will not work as the firewall will need to use the tag to direct the traffic at the right VSYS.&lt;/P&gt;&lt;P&gt;If we had a better understanding of what you need to achieve it may be easier to assist with a solution.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Oct 2021 13:26:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/subinterfaces-with-same-vlan-tag/m-p/438814#M99469</guid>
      <dc:creator>laurence64</dc:creator>
      <dc:date>2021-10-05T13:26:09Z</dc:date>
    </item>
    <item>
      <title>Re: Subinterfaces with same VLAN tag</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/subinterfaces-with-same-vlan-tag/m-p/438819#M99470</link>
      <description>&lt;P&gt;Hello Laurence,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In my case it is just a simple migration of 3 Cisco ASA virtual contexts to Palo Alto in 1:1 fashion. Since Cisco ASA has no problem with having subinterfaces with same dot1q tag on different contexts it was supposed we proceed with a migration in similar fashion to Palo Alto vSys. Right now it looks like it has such kind of limitation though, which is not a problem on Cisco.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please see attached picture of our current design. We want to have only single port-channel between PA box and switches. All logical subinterfaces should be hanging off of it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="shared_int.PNG" style="width: 719px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/36827iC90CC60884413979/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="shared_int.PNG" alt="shared_int.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;So the question is - how can we work around this problem and if adding another physical interface for each context is the only solution?&lt;/P&gt;</description>
      <pubDate>Tue, 05 Oct 2021 13:35:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/subinterfaces-with-same-vlan-tag/m-p/438819#M99470</guid>
      <dc:creator>psycoma1984</dc:creator>
      <dc:date>2021-10-05T13:35:23Z</dc:date>
    </item>
    <item>
      <title>Re: Subinterfaces with same VLAN tag</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/subinterfaces-with-same-vlan-tag/m-p/438828#M99472</link>
      <description>&lt;P&gt;So, let me see if I understand this, you have the three contexts at the bottom of the diagram and you are wanting to share the gateway that is on vlan 99 across the three VSYS ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If this is the case then I would look at the shared gateway implementation as this would fit your use case perfectly&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-admin/virtual-systems/shared-gateway.html" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-admin/virtual-systems/shared-gateway.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this helps, if not let me know if I can be of anymore assistance.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Oct 2021 14:00:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/subinterfaces-with-same-vlan-tag/m-p/438828#M99472</guid>
      <dc:creator>laurence64</dc:creator>
      <dc:date>2021-10-05T14:00:36Z</dc:date>
    </item>
    <item>
      <title>Re: Subinterfaces with same VLAN tag</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/subinterfaces-with-same-vlan-tag/m-p/438832#M99473</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;AFAIK it won't fit my requirements.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We need to have L3 interface on each of 3 new vSYS on PA box, which is sharing same IP subnet and (ideally) VLAN ID. This is required as we have multiple networks routed through each firewall context and those L3 interfaces are acting like next-hop-address.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So in my picture above 10.10.10.254 is the common gateway for all 3 contexts, but it is not located on FW, it is just a router which has interface within same VLAN/Subnet.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Oct 2021 14:21:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/subinterfaces-with-same-vlan-tag/m-p/438832#M99473</guid>
      <dc:creator>psycoma1984</dc:creator>
      <dc:date>2021-10-05T14:21:35Z</dc:date>
    </item>
    <item>
      <title>Re: Subinterfaces with same VLAN tag</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/subinterfaces-with-same-vlan-tag/m-p/438836#M99474</link>
      <description>&lt;P&gt;I see, I would like to go away and Lab this up, I am sure there will be a way to make this an easy migration, just for confirmation sake the Vlan that needs to shared across the VSYS in this example is 99 yes ? and then the three contexts are the nexthop gateway for your subnets ?&lt;/P&gt;</description>
      <pubDate>Tue, 05 Oct 2021 14:22:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/subinterfaces-with-same-vlan-tag/m-p/438836#M99474</guid>
      <dc:creator>laurence64</dc:creator>
      <dc:date>2021-10-05T14:22:27Z</dc:date>
    </item>
    <item>
      <title>Re: Subinterfaces with same VLAN tag</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/subinterfaces-with-same-vlan-tag/m-p/438845#M99476</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That's exactly correct. So in our design simplified from a router point of view on top of the pic we have for example:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. Network A, next-hop is 10.10.10.1/24;&lt;/P&gt;&lt;P&gt;2. Network B, next-hop is 10.10.10.2/24;&lt;/P&gt;&lt;P&gt;3. Network C, next-hop is 10.10.10.3/24&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So in fact 10.10.10.0/24 is a transit network between router and firewall contexts.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I see so following workaround: perform migration Cisco--&amp;gt;PA as they currently are, but add PHYSICAL interface to each of vSYS and tag it to VLAN99 from switch side (assuming it will be configured L3 untagged on FW side) or have a subinterface off from it. This way I would be able to overcome a restriction PA has - 'to not have subinterface with the same dot1q VLAN tag on same physical interface'.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Would be grateful if you can share other option which does not require to occupy physical interface for subinterface workload just because it is not allowed by PA.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 05 Oct 2021 14:30:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/subinterfaces-with-same-vlan-tag/m-p/438845#M99476</guid>
      <dc:creator>psycoma1984</dc:creator>
      <dc:date>2021-10-05T14:30:47Z</dc:date>
    </item>
    <item>
      <title>Re: Subinterfaces with same VLAN tag</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/subinterfaces-with-same-vlan-tag/m-p/439771#M99838</link>
      <description>&lt;P&gt;Hello Laurence,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Few other questions if I may:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have 3 additional questions I want to ask you:&lt;/P&gt;&lt;P&gt;1. Is it the same with a port-channels (aggregated interfaces)? Can we create subinterfaces from aeX interface with the same VLAN tag?&lt;BR /&gt;2. Will it work if we create subinterfaces from physical interface or aggregate interface with same VLAN tag, but move each in separate vSYS?&lt;BR /&gt;3. In 'shared gateway' scenario, do we need to use PHYSICAL INTERFACE as a 'external interface' on shared gateway or can it be subinterface or port-channel as well?&lt;/P&gt;&lt;P&gt;Thanks and appreciate if you can answer those!&lt;/P&gt;</description>
      <pubDate>Fri, 08 Oct 2021 20:12:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/subinterfaces-with-same-vlan-tag/m-p/439771#M99838</guid>
      <dc:creator>psycoma1984</dc:creator>
      <dc:date>2021-10-08T20:12:44Z</dc:date>
    </item>
    <item>
      <title>Re: Subinterfaces with same VLAN tag</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/subinterfaces-with-same-vlan-tag/m-p/518076#M107480</link>
      <description>&lt;P&gt;Same VLAN cannot exist in multiple subinterface under 1 physical interface. Same subinterface under 1 physical interface cannot assign to multiple vsys(es). Therefore, the only workaround is to create the same VLAN ID under multiple physical interfaces in order to assign to multiple vsys(es) to the same VLAN. To save the 10G interface capacity, you might wanna trunk that interface.&lt;/P&gt;</description>
      <pubDate>Mon, 17 Oct 2022 06:45:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/subinterfaces-with-same-vlan-tag/m-p/518076#M107480</guid>
      <dc:creator>KengSeng</dc:creator>
      <dc:date>2022-10-17T06:45:26Z</dc:date>
    </item>
  </channel>
</rss>

