<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Layer 3 Sub-Interface Question in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/layer-3-sub-interface-question/m-p/1205092#M122989</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Check the unified logs to see if/where the traffic is getting blocked. Since you have the different IP's in different zones, you'll need security policies. I prefer to make my physical interfaces layer 2 and have a layer 3 vlan. This can be tricky for external interfaces however.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
    <pubDate>Wed, 22 Jan 2025 21:52:56 GMT</pubDate>
    <dc:creator>OtakarKlier</dc:creator>
    <dc:date>2025-01-22T21:52:56Z</dc:date>
    <item>
      <title>Layer 3 Sub-Interface Question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/layer-3-sub-interface-question/m-p/1201815#M122955</link>
      <description>&lt;P&gt;All,&lt;/P&gt;
&lt;P&gt;&amp;nbsp; I have recently set up a test lab with a PA440. In the lab I have created a WAN and LAN zone from two different physical interfaces.&lt;/P&gt;
&lt;P&gt;&amp;nbsp; In addition, I have created a sub-Interface from the physical ethernet port 1/3. This is what the ethernet port 1/3 looks like:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; Ethernet 1/3 (Physical Port)&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; - Sub-Interface Eth1/3.25 ~ L3 (IP = &lt;STRONG&gt;10.10.25.1/24&lt;/STRONG&gt;)&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; - Sub-Interface Eth1/3.35 ~ L3 (IP = 10.10.35.1/24)&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; - Sub-Interface Eth1/3.55 ~ L3 (IP = 10.10.55.1/24)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Each Sub_interface has its own zone and mgmt profile with the service to ping. Each interface has a tag of its interface number.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have taken a laptop and assigned it to Ip address: {&lt;STRONG&gt;10.10.25.55/24&lt;/STRONG&gt; with gateway &lt;STRONG&gt;10.10.25.1} and connected directly to Port1/3.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;I have another latop on another port that does not have an sub-interface, just the physcial (Eth1/6) port with IP = 12.12.12.124.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My issue is that I can ping my gateway (12.12.12.1) on my laptop (12.12.12.12) from a Physcial interface (Eth1/6). From the same laptop I can ping all the IP's gateways from each sub-interface {10.10.25.1, 10.10.35.1, 10.10.55.1} but I cannot reach any device behind those IP's. I have no switch, just testing connection from one laptop to another each, directly connected to its ports. The l&lt;U&gt;aptop that is connected to the eth1/3&lt;/U&gt; port cannot ping any none of its own sub-Interface IP's nor the eth1/6 IP address.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;Not sure what I am missing?&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jan 2025 22:25:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/layer-3-sub-interface-question/m-p/1201815#M122955</guid>
      <dc:creator>D.Callahan</dc:creator>
      <dc:date>2025-01-20T22:25:04Z</dc:date>
    </item>
    <item>
      <title>Re: Layer 3 Sub-Interface Question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/layer-3-sub-interface-question/m-p/1205092#M122989</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Check the unified logs to see if/where the traffic is getting blocked. Since you have the different IP's in different zones, you'll need security policies. I prefer to make my physical interfaces layer 2 and have a layer 3 vlan. This can be tricky for external interfaces however.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jan 2025 21:52:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/layer-3-sub-interface-question/m-p/1205092#M122989</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2025-01-22T21:52:56Z</dc:date>
    </item>
  </channel>
</rss>

