<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Using Virtual-Wire to isolate and allow/deny traffic to a couple hosts on existing subnet. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/using-virtual-wire-to-isolate-and-allow-deny-traffic-to-a-couple/m-p/15701#M11487</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We have a situation as a result of going through a PCI audit. We have a single subnet which contains a handful of servers that need to be isolated and traffic restricted. Originally we were going to move these few servers to a new switch VLAN changing the IP scheme and use the PA to permit/allow traffic between that new vlan and the existing subnet and internet. Now it looks like it is going to be pain since there are a lot of changes that will need to be done to these few servers to change the IP. Worse yet is that the vendor is on a service blackout as a result of being purchased by Oracle. So there is no time before our deadline to get assistance from them before we will be fined for not being in compliance. &lt;/P&gt;&lt;P&gt;My thought was to create a virtual wire where traffic would ingress to the PA from the existing LAN-VLAN (Client-SIde) and egress on the interface of the virtual wire (Server Side) so I can apply rules to all traffic bound to/from those servers. Seems like it should work in my mind, but wondering if I'm on the right track or is there is a better way to isolate these few hosts to lock them down. &lt;/P&gt;&lt;P&gt;Hopefully this makes sense. I can do a visual if needed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 16 Apr 2015 22:42:28 GMT</pubDate>
    <dc:creator>Retired Member</dc:creator>
    <dc:date>2015-04-16T22:42:28Z</dc:date>
    <item>
      <title>Using Virtual-Wire to isolate and allow/deny traffic to a couple hosts on existing subnet.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/using-virtual-wire-to-isolate-and-allow-deny-traffic-to-a-couple/m-p/15701#M11487</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We have a situation as a result of going through a PCI audit. We have a single subnet which contains a handful of servers that need to be isolated and traffic restricted. Originally we were going to move these few servers to a new switch VLAN changing the IP scheme and use the PA to permit/allow traffic between that new vlan and the existing subnet and internet. Now it looks like it is going to be pain since there are a lot of changes that will need to be done to these few servers to change the IP. Worse yet is that the vendor is on a service blackout as a result of being purchased by Oracle. So there is no time before our deadline to get assistance from them before we will be fined for not being in compliance. &lt;/P&gt;&lt;P&gt;My thought was to create a virtual wire where traffic would ingress to the PA from the existing LAN-VLAN (Client-SIde) and egress on the interface of the virtual wire (Server Side) so I can apply rules to all traffic bound to/from those servers. Seems like it should work in my mind, but wondering if I'm on the right track or is there is a better way to isolate these few hosts to lock them down. &lt;/P&gt;&lt;P&gt;Hopefully this makes sense. I can do a visual if needed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Apr 2015 22:42:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/using-virtual-wire-to-isolate-and-allow-deny-traffic-to-a-couple/m-p/15701#M11487</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2015-04-16T22:42:28Z</dc:date>
    </item>
    <item>
      <title>Re: Using Virtual-Wire to isolate and allow/deny traffic to a couple hosts on existing subnet.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/using-virtual-wire-to-isolate-and-allow-deny-traffic-to-a-couple/m-p/15702#M11488</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You're on the right track - and this would work as described.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The other way to accomplish this would be using L2 mode with vlan-tag re-write.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Either method would allow you to keep the same IP scheme, yet isolate one group of hosts from another.&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Apr 2015 22:57:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/using-virtual-wire-to-isolate-and-allow-deny-traffic-to-a-couple/m-p/15702#M11488</guid>
      <dc:creator>jvalentine</dc:creator>
      <dc:date>2015-04-16T22:57:31Z</dc:date>
    </item>
    <item>
      <title>Re: Using Virtual-Wire to isolate and allow/deny traffic to a couple hosts on existing subnet.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/using-virtual-wire-to-isolate-and-allow-deny-traffic-to-a-couple/m-p/15703#M11489</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you! That is what I needed to know. I went with the L2 mode with VLAN re-write. Works just as expected.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Josh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Apr 2015 22:54:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/using-virtual-wire-to-isolate-and-allow-deny-traffic-to-a-couple/m-p/15703#M11489</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2015-04-30T22:54:33Z</dc:date>
    </item>
  </channel>
</rss>

