<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Public Web Server, Secondary IP Address, and Loopback Interface in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/public-web-server-secondary-ip-address-and-loopback-interface/m-p/572639#M115218</link>
    <description>&lt;P&gt;so, are you saying the solution is to:&lt;/P&gt;
&lt;P&gt;1. configure a Pub. &amp;lt;-&amp;gt; Private IP mapping in AWS on its External interface.&lt;/P&gt;
&lt;P&gt;2. on PA VM configure Lo. in same zone as where the Ext. interface (or Outside in terms of FW) is defined&lt;/P&gt;
&lt;P&gt;3. Create a Sec. policy for access to this Lo. as per requirement.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;is this the solution then?&lt;/P&gt;</description>
    <pubDate>Thu, 11 Jan 2024 01:19:22 GMT</pubDate>
    <dc:creator>NahushRajgor</dc:creator>
    <dc:date>2024-01-11T01:19:22Z</dc:date>
    <item>
      <title>Public Web Server, Secondary IP Address, and Loopback Interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/public-web-server-secondary-ip-address-and-loopback-interface/m-p/305425#M79365</link>
      <description>&lt;DIV&gt;&lt;DIV class=""&gt;&lt;DIV class="public-DraftStyleDefault-block public-DraftStyleDefault-ltr"&gt;&lt;SPAN&gt;We have a VM-100 running 9.0.3.xfr to do some testing.&amp;nbsp; This is currently setup on AWS, and we are trying to support traffic for multiple public web server's being sent through the firewall.&amp;nbsp; There are the three standard zones and network interfaces (Untrusted, Trusted, and Management).&amp;nbsp; The Untrusted has a public IP (Elastic IP) and internal subnet IP (AWS does the NAT for this).&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="public-DraftStyleDefault-block public-DraftStyleDefault-ltr"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class="public-DraftStyleDefault-block public-DraftStyleDefault-ltr"&gt;&lt;SPAN&gt;A secondary IP address was created (different public IP NAT'd by AWS to different internal subnet IP) for the first public web server, and attached to the same network interface as the Untrusted.&amp;nbsp; Additionally, this secondary IP address has to be NAT'd using the firewall's NAT Policy to direct it to the internal web server IP.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="public-DraftStyleDefault-block public-DraftStyleDefault-ltr"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class="public-DraftStyleDefault-block public-DraftStyleDefault-ltr"&gt;&lt;SPAN&gt;This knowledgebase article (&lt;/SPAN&gt;&lt;SPAN&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClSDCA0" target="_blank" rel="noopener"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClSDCA0&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN&gt;) suggested the preferred way was to setup the secondary IP as a loopback, apply a different security zone, and then security policies could be written using this additional security zone assigned via the loopback interface.&amp;nbsp; This was done with an additional security zone called Public Web.&amp;nbsp;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class="public-DraftStyleDefault-block public-DraftStyleDefault-ltr"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="public-DraftStyleDefault-block public-DraftStyleDefault-ltr"&gt;&lt;SPAN&gt;The only way I can get it to work is with a NAT policy configured in a way that changes the security zone from Public Web to Untrusted (which happens first).&amp;nbsp; Then all of the Security Policy rules cannot use the Public Web security zone, and can only use the Untrusted zone.&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class="public-DraftStyleDefault-block public-DraftStyleDefault-ltr"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="public-DraftStyleDefault-block public-DraftStyleDefault-ltr"&gt;&lt;SPAN&gt;Is there a way to do what is described in the article?&amp;nbsp; Am I missing something from the article?&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Thu, 02 Jan 2020 15:55:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/public-web-server-secondary-ip-address-and-loopback-interface/m-p/305425#M79365</guid>
      <dc:creator>cdpeek</dc:creator>
      <dc:date>2020-01-02T15:55:42Z</dc:date>
    </item>
    <item>
      <title>Re: Public Web Server, Secondary IP Address, and Loopback Interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/public-web-server-secondary-ip-address-and-loopback-interface/m-p/305577#M79411</link>
      <description>&lt;P&gt;So I spoke with support, and received further information.&amp;nbsp; The general summation is that the loopback interfaces work differently on the VM series (virtual firewalls) as compared to hardware firewalls.&amp;nbsp; The article was written for a hardware firewall.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Support explained that the loopback interface on the VM series in a cloud environment does not handle packets in the same way.&amp;nbsp; The cloud provider infrastructure knows nothing of the loopback interface nor it's routing.&amp;nbsp; Using a loopback interface in the VM series does not allow you to change the security zone as described in the article.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Support Summary:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;This is specifically written for a hardware firewall which can perform an internal route lookup to find which interface an IP range is attached to, and leverage proxy arp to respond to ARP requests for IP addresses configured in NAT on the interface. This technique makes the configured IP address available to outside hosts trying to reach it while not being physically configured on the interface.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;VM has two part of the interface/zone configuration, one on Firewall itself and corresponding interface association in AWS side. If you just configure a loopback, AWS does not know about this interface, hence the route lookup may fail.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Jan 2020 17:44:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/public-web-server-secondary-ip-address-and-loopback-interface/m-p/305577#M79411</guid>
      <dc:creator>cdpeek</dc:creator>
      <dc:date>2020-01-03T17:44:22Z</dc:date>
    </item>
    <item>
      <title>Re: Public Web Server, Secondary IP Address, and Loopback Interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/public-web-server-secondary-ip-address-and-loopback-interface/m-p/572639#M115218</link>
      <description>&lt;P&gt;so, are you saying the solution is to:&lt;/P&gt;
&lt;P&gt;1. configure a Pub. &amp;lt;-&amp;gt; Private IP mapping in AWS on its External interface.&lt;/P&gt;
&lt;P&gt;2. on PA VM configure Lo. in same zone as where the Ext. interface (or Outside in terms of FW) is defined&lt;/P&gt;
&lt;P&gt;3. Create a Sec. policy for access to this Lo. as per requirement.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;is this the solution then?&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jan 2024 01:19:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/public-web-server-secondary-ip-address-and-loopback-interface/m-p/572639#M115218</guid>
      <dc:creator>NahushRajgor</dc:creator>
      <dc:date>2024-01-11T01:19:22Z</dc:date>
    </item>
  </channel>
</rss>

