<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PA-VM on ESXi - L2 Topology Design Questions in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/pa-vm-on-esxi-l2-topology-design-questions/m-p/15551#M11396</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="font-size: 13px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-size: 10pt; font-family: inherit;"&gt;- Does the protected port group on the vSphere DSwitch have to be VLAN ID 8 as well, or can I just leave it as VLAN type "None"?&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 13px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-size: 10pt; font-family: inherit;"&gt;Both sides will be none in your case.&amp;nbsp; You only need to set tags if you have a Q tag port.&amp;nbsp; In your design these are access ports so none is all you need to do.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 13px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-size: 10pt; font-family: inherit;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 13px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;- Is there anything extra I need to do to ensure that the HA pair will never accidentally create a loop between the two segments of the same network?&lt;/P&gt;&lt;P style="font-size: 13px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;No, the passive device keeps the traffic interfaces up but never passing traffic.&amp;nbsp; The PA will not participate in STP at all so all you need to do is make sure the switching system never puts the active device into a blocking port.&lt;/P&gt;&lt;P style="font-size: 13px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;/P&gt;&lt;P style="font-size: 13px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;- Are there any other considerations I need to know about in a deployment like this?&lt;/P&gt;&lt;P style="font-size: 13px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;I have not used the VMs for HA but I assume you still need the HA ports connected to communicate state tables and the like.&amp;nbsp; I don't see that in your setup here.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;your may find the example for layer 2 HA in the Design guide helpful starting on page 80&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-2561"&gt;Designing Networks with Palo Alto Networks Firewalls&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 14 Jul 2015 12:10:57 GMT</pubDate>
    <dc:creator>pulukas</dc:creator>
    <dc:date>2015-07-14T12:10:57Z</dc:date>
    <item>
      <title>PA-VM on ESXi - L2 Topology Design Questions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-vm-on-esxi-l2-topology-design-questions/m-p/15550#M11395</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm looking to deploy a pair of PA-VM 200s running 7.x on a vSphere 5.5 cluster and would like a sanity check on the design.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My client's network currently has one large VLAN that houses most of their servers.&amp;nbsp; For the sake of this example, we'll say it's VLAN 8.&amp;nbsp; There are servers on this network with varying degrees of importance, but among them are things like domain controllers and file servers.&amp;nbsp; To increase security, we're looking to deploy an active/passive HA pair of PA-VM 200s running 7.x (for the real HA capabilities) in L2 mode so that we can move some of the more important VMs behind them and not have to renumber.&amp;nbsp; &lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;I'm assuming that the ethernet1/2 interfaces will also need to be assigned to VLAN 8 on the PA-VMs so that it knows to bridge the traffic.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;- Does the protected port group on the vSphere DSwitch have to be VLAN ID 8 as well, or can I just leave it as VLAN type "None"?&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;- Is there anything extra I need to do to ensure that the HA pair will never accidentally create a loop between the two segments of the same network?&lt;/P&gt;&lt;P&gt;- Are there any other considerations I need to know about in a deployment like this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="20329" alt="PA-VM Topology.png" class="image-1 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/20329_PA-VM Topology.png" style="height: 545px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Jul 2015 19:04:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-vm-on-esxi-l2-topology-design-questions/m-p/15550#M11395</guid>
      <dc:creator>bkeifer</dc:creator>
      <dc:date>2015-07-13T19:04:12Z</dc:date>
    </item>
    <item>
      <title>Re: PA-VM on ESXi - L2 Topology Design Questions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-vm-on-esxi-l2-topology-design-questions/m-p/15551#M11396</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="font-size: 13px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-size: 10pt; font-family: inherit;"&gt;- Does the protected port group on the vSphere DSwitch have to be VLAN ID 8 as well, or can I just leave it as VLAN type "None"?&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 13px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-size: 10pt; font-family: inherit;"&gt;Both sides will be none in your case.&amp;nbsp; You only need to set tags if you have a Q tag port.&amp;nbsp; In your design these are access ports so none is all you need to do.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 13px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-size: 10pt; font-family: inherit;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 13px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;- Is there anything extra I need to do to ensure that the HA pair will never accidentally create a loop between the two segments of the same network?&lt;/P&gt;&lt;P style="font-size: 13px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;No, the passive device keeps the traffic interfaces up but never passing traffic.&amp;nbsp; The PA will not participate in STP at all so all you need to do is make sure the switching system never puts the active device into a blocking port.&lt;/P&gt;&lt;P style="font-size: 13px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;/P&gt;&lt;P style="font-size: 13px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;- Are there any other considerations I need to know about in a deployment like this?&lt;/P&gt;&lt;P style="font-size: 13px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;I have not used the VMs for HA but I assume you still need the HA ports connected to communicate state tables and the like.&amp;nbsp; I don't see that in your setup here.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;your may find the example for layer 2 HA in the Design guide helpful starting on page 80&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-2561"&gt;Designing Networks with Palo Alto Networks Firewalls&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Jul 2015 12:10:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-vm-on-esxi-l2-topology-design-questions/m-p/15551#M11396</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2015-07-14T12:10:57Z</dc:date>
    </item>
  </channel>
</rss>

