<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Internet and internal network sepration via virtual router in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/internet-and-internal-network-sepration-via-virtual-router/m-p/564704#M114253</link>
    <description>&lt;P&gt;Thank you for the reply. I will put my recommendation to not separate them based on every one's reply. If not then I have solution now. I will find a lab online to do some labs.. do you know what is the best way to lab it.. either azure/aws/gcp with PAYG setup or EVN-NG lab .. need to find out the way to get the PA VM and licences for lab purpose.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 08 Nov 2023 02:14:31 GMT</pubDate>
    <dc:creator>gondolf</dc:creator>
    <dc:date>2023-11-08T02:14:31Z</dc:date>
    <item>
      <title>Internet and internal network sepration via virtual router</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/internet-and-internal-network-sepration-via-virtual-router/m-p/562850#M114010</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am new to Palo Alto. I have basic question.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Traditional setup I worked on my last project was as below,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;VRF on cisco router for&amp;nbsp;&lt;/P&gt;
&lt;P&gt;- Internet -0 bgp&lt;/P&gt;
&lt;P&gt;- Production - bgp&lt;/P&gt;
&lt;P&gt;- DMZ&amp;nbsp; - bgp&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;FW connects to all 3 VRF. Route between VRF is via FW.&amp;nbsp; FW harden the access.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;New project with PA and L2 switch for the same setup.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My idea is&amp;nbsp;&lt;/P&gt;
&lt;P&gt;create 3 x Virtual routers on FW ( Internet, Prod, DMZ)&lt;/P&gt;
&lt;P&gt;and one policy for all of it.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;However, what is the best way to route the traffic between VR with all the policy applied?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Oct 2023 06:52:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/internet-and-internal-network-sepration-via-virtual-router/m-p/562850#M114010</guid>
      <dc:creator>gondolf</dc:creator>
      <dc:date>2023-10-24T06:52:29Z</dc:date>
    </item>
    <item>
      <title>Re: Internet and internal network sepration via virtual router</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/internet-and-internal-network-sepration-via-virtual-router/m-p/562991#M114032</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Is there a reason you want to use 3 virtual routers? Its the security policies that determine what traffic can go where. The Virtual router is just that, routing. I'm a fan on keeping it simple and having 3 can get complicated, etc.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Oct 2023 20:20:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/internet-and-internal-network-sepration-via-virtual-router/m-p/562991#M114032</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2023-10-24T20:20:11Z</dc:date>
    </item>
    <item>
      <title>Re: Internet and internal network sepration via virtual router</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/internet-and-internal-network-sepration-via-virtual-router/m-p/563024#M114043</link>
      <description>&lt;P&gt;It is the cyber policy so I don't have much say in that one.&amp;nbsp; &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Oct 2023 22:41:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/internet-and-internal-network-sepration-via-virtual-router/m-p/563024#M114043</guid>
      <dc:creator>gondolf</dc:creator>
      <dc:date>2023-10-24T22:41:24Z</dc:date>
    </item>
    <item>
      <title>Re: Internet and internal network sepration via virtual router</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/internet-and-internal-network-sepration-via-virtual-router/m-p/563030#M114045</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/322754"&gt;@gondolf&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The cyber policy requires 3 VRs on the NGFW or just the router?&amp;nbsp; They are fine on the router.&amp;nbsp; They are generally not needed on the NGFW.&amp;nbsp; Some cyber security analysts think that separate routing tables provide an extra layer of security.&amp;nbsp; The problem is that in order for it to work you have to &lt;EM&gt;route&lt;/EM&gt; between the VRs, thus breaking the isolation.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Your router is different where an external device routes between VRFs.&amp;nbsp; The NGFW does not require VRs to do so, only 3 separate zones and interfaces.&amp;nbsp; VRs on the NGFW only increases the complexity without increasing the security.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt; is correct.&amp;nbsp; KISS is not only a good design principle, but an architectural guideline for the Internet.&amp;nbsp; &lt;A href="https://datatracker.ietf.org/doc/html/rfc3439" target="_blank" rel="noopener"&gt;https://datatracker.ietf.org/doc/html/rfc3439&lt;/A&gt;&amp;nbsp; There is a link in there that says 80% of outages are caused by people or process errors.&amp;nbsp; Complex designs increase those opportunities.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you HAVE to do it on the NGFW:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Create 3 different VRs.&lt;/LI&gt;
&lt;LI&gt;Route between them with the next hop pointing to the VR and not an IP or interface.&lt;/LI&gt;
&lt;LI&gt;The zones and security policy will remain the same whether you have VRs or not.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Wed, 25 Oct 2023 01:10:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/internet-and-internal-network-sepration-via-virtual-router/m-p/563030#M114045</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2023-10-25T01:10:12Z</dc:date>
    </item>
    <item>
      <title>Re: Internet and internal network sepration via virtual router</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/internet-and-internal-network-sepration-via-virtual-router/m-p/564704#M114253</link>
      <description>&lt;P&gt;Thank you for the reply. I will put my recommendation to not separate them based on every one's reply. If not then I have solution now. I will find a lab online to do some labs.. do you know what is the best way to lab it.. either azure/aws/gcp with PAYG setup or EVN-NG lab .. need to find out the way to get the PA VM and licences for lab purpose.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Nov 2023 02:14:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/internet-and-internal-network-sepration-via-virtual-router/m-p/564704#M114253</guid>
      <dc:creator>gondolf</dc:creator>
      <dc:date>2023-11-08T02:14:31Z</dc:date>
    </item>
  </channel>
</rss>

