<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Shutting down/disabling subinterfaces in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/shutting-down-disabling-subinterfaces/m-p/1231212#M124504</link>
    <description>&lt;P&gt;Good luck.&amp;nbsp; I'm moving from Fortinet to Palo Alto (by someone else's direction) and the UI is like taking a 15 year step backward.&amp;nbsp; I'm amazed at how many little things I've gotten used to in Fortinet that don't exist in Palo.&amp;nbsp; I go off and search to see if I'm missing something and, like this thread, I find an ancient thread indicating that Palo just 'doesn't do that'.&amp;nbsp; And there's always the 'submit a request' line, as if that gets anywhere.&amp;nbsp; It's as if Palo's interface was designed by someone who has never managed a firewall before and architectural decisions were designed by someone who's never managed a network before.&amp;nbsp; Beyond frustrating.....&lt;/P&gt;</description>
    <pubDate>Fri, 06 Jun 2025 13:42:31 GMT</pubDate>
    <dc:creator>K.Saucier</dc:creator>
    <dc:date>2025-06-06T13:42:31Z</dc:date>
    <item>
      <title>Shutting down/disabling subinterfaces</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/shutting-down-disabling-subinterfaces/m-p/12104#M8875</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am very new to the PANOS world so I will apologize in advance if this is obvious, however my search of documentation and knowledebase did not yield anything. I have been looking for a way to administratively shut down sub interfaces. Is this possible? While it's easy enough to shutdown a physical interface by assigning it's link-state we're not seeing a way to do the same for an individual sub-interface.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 Jul 2013 15:02:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/shutting-down-disabling-subinterfaces/m-p/12104#M8875</guid>
      <dc:creator>scourge</dc:creator>
      <dc:date>2013-07-26T15:02:28Z</dc:date>
    </item>
    <item>
      <title>Re: Shutting down/disabling subinterfaces</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/shutting-down-disabling-subinterfaces/m-p/12105#M8876</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Scourge,&lt;/P&gt;&lt;P&gt;We do not have an option of shutting down a sub interface as its logical in nature. We could however, select "none" zone for the sub-interface or "none" virtual router or both, if you do not want traffic to ingress/egress via this sub interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;BR,&lt;/P&gt;&lt;P&gt;Karthik &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 Jul 2013 15:15:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/shutting-down-disabling-subinterfaces/m-p/12105#M8876</guid>
      <dc:creator>kprakash</dc:creator>
      <dc:date>2013-07-26T15:15:06Z</dc:date>
    </item>
    <item>
      <title>Re: Shutting down/disabling subinterfaces</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/shutting-down-disabling-subinterfaces/m-p/12106#M8877</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Subinterfaces are logical interfaces and they do not have link state as I&amp;nbsp; know.&lt;/P&gt;&lt;P&gt;Why do you need that option ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 Jul 2013 15:18:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/shutting-down-disabling-subinterfaces/m-p/12106#M8877</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-07-26T15:18:41Z</dc:date>
    </item>
    <item>
      <title>Re: Shutting down/disabling subinterfaces</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/shutting-down-disabling-subinterfaces/m-p/12107#M8878</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It's a very useful feature when you are replacing existing equipment for example. The ability to disable a subinteterface would allow you to assign and commit an ip address that would potentially conflict with an existing piece of equipment. When you're ready to cut over you can just disable the interfaces on the old equipment and enable them on the PA firewall. This is why there's a concept of administrative shutdown in the cisco world for example. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 Jul 2013 15:29:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/shutting-down-disabling-subinterfaces/m-p/12107#M8878</guid>
      <dc:creator>scourge</dc:creator>
      <dc:date>2013-07-26T15:29:01Z</dc:date>
    </item>
    <item>
      <title>Re: Shutting down/disabling subinterfaces</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/shutting-down-disabling-subinterfaces/m-p/12108#M8879</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You have a valid point, but we do not have that feature as of today on the box. You can contact your Sales Engineer for this enhancement request and he can apply one for you on your behalf. Till then you have to work around it with the steps that I mentioned before.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;BR,&lt;/P&gt;&lt;P&gt;Karthik &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 Jul 2013 16:22:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/shutting-down-disabling-subinterfaces/m-p/12108#M8879</guid>
      <dc:creator>kprakash</dc:creator>
      <dc:date>2013-07-26T16:22:14Z</dc:date>
    </item>
    <item>
      <title>Re: Shutting down/disabling subinterfaces</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/shutting-down-disabling-subinterfaces/m-p/12109#M8880</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks. I appreciate your feedback!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 Jul 2013 18:39:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/shutting-down-disabling-subinterfaces/m-p/12109#M8880</guid>
      <dc:creator>scourge</dc:creator>
      <dc:date>2013-07-26T18:39:22Z</dc:date>
    </item>
    <item>
      <title>Re: Shutting down/disabling subinterfaces</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/shutting-down-disabling-subinterfaces/m-p/391921#M90814</link>
      <description>&lt;P&gt;Has there been any advance on this?&lt;/P&gt;&lt;P&gt;Last message was 2013.&lt;/P&gt;&lt;P&gt;Moreover if I use the work around and set my subinterface into Zone = None, change the VR:&lt;/P&gt;&lt;P&gt;Will the interface still respond to packets?&lt;/P&gt;&lt;P&gt;E.g. ARP, ping etc?&lt;/P&gt;&lt;P&gt;I am replacing old FW with new Palo and I need to be sure even with above measures taken that there will be no effect of duplicating the existing live interface&lt;/P&gt;&lt;P&gt;Thanks for any reply&lt;/P&gt;</description>
      <pubDate>Thu, 18 Mar 2021 06:55:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/shutting-down-disabling-subinterfaces/m-p/391921#M90814</guid>
      <dc:creator>Shaun_Louw</dc:creator>
      <dc:date>2021-03-18T06:55:32Z</dc:date>
    </item>
    <item>
      <title>Re: Shutting down/disabling subinterfaces</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/shutting-down-disabling-subinterfaces/m-p/445453#M100470</link>
      <description>&lt;P&gt;I'm facing the same situation right now. I want to&amp;nbsp;&lt;SPAN&gt;replace the old FWs with the new Palo Alto FWs. So, I need to disable an exiting sub-interface on the old FWs and enable it on the new FWs. Select "none" for the sub-interface zone or "none" for the virtual router, or both it will take time for me. So, s&lt;/SPAN&gt;&lt;SPAN&gt;hutdown sub interfaces would make it easy.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Nov 2021 11:07:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/shutting-down-disabling-subinterfaces/m-p/445453#M100470</guid>
      <dc:creator>majidx94</dc:creator>
      <dc:date>2021-11-04T11:07:49Z</dc:date>
    </item>
    <item>
      <title>Re: Shutting down/disabling subinterfaces</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/shutting-down-disabling-subinterfaces/m-p/445515#M100479</link>
      <description>&lt;P&gt;Same here - I was going to hot-cut a 3-tier infrastructure into one cluster but I just got told yesterday I need to do it one tier at a time.&amp;nbsp; I guess the zone workaround is about the same amount of but I don't feel comfortable with the zone option.&amp;nbsp; I guess I'm old school, lol.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Edit: What about duplicate IP addresses?&amp;nbsp; Does the zone workaround completely take it out of routing &amp;amp; ARP'ing?&amp;nbsp; Since I'm moving multiple VLANs' gateways from one firewall to another there's the potential for IP address conflicts.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Nov 2021 17:15:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/shutting-down-disabling-subinterfaces/m-p/445515#M100479</guid>
      <dc:creator>justamoment</dc:creator>
      <dc:date>2021-11-04T17:15:47Z</dc:date>
    </item>
    <item>
      <title>Re: Shutting down/disabling subinterfaces</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/shutting-down-disabling-subinterfaces/m-p/449765#M100972</link>
      <description>&lt;P&gt;FYI, I mentioned this to a support engineer and he said just remove the IP address and leave the zone &amp;amp; VR alone.&lt;/P&gt;</description>
      <pubDate>Sun, 28 Nov 2021 02:21:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/shutting-down-disabling-subinterfaces/m-p/449765#M100972</guid>
      <dc:creator>justamoment</dc:creator>
      <dc:date>2021-11-28T02:21:32Z</dc:date>
    </item>
    <item>
      <title>Re: Shutting down/disabling subinterfaces</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/shutting-down-disabling-subinterfaces/m-p/509785#M106117</link>
      <description>&lt;P&gt;I have found the only simple option to remove the VLAN assignment from the trunk on the switch side.&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jul 2022 12:03:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/shutting-down-disabling-subinterfaces/m-p/509785#M106117</guid>
      <dc:creator>andrasim</dc:creator>
      <dc:date>2022-07-25T12:03:59Z</dc:date>
    </item>
    <item>
      <title>Re: Shutting down/disabling subinterfaces</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/shutting-down-disabling-subinterfaces/m-p/557026#M113049</link>
      <description>&lt;P&gt;Neither solutions work for me on Panorama 10.2.4-h4 &amp;amp; PA-460 with Pan-OS 10.2.3 -0 the FW doesn't accept the sub0interface without IP, VR or Zone...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;we told the customer to&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/26536"&gt;@kprakash&lt;/a&gt;&amp;nbsp;'s idea - waiting on results&lt;/P&gt;</description>
      <pubDate>Thu, 07 Sep 2023 16:25:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/shutting-down-disabling-subinterfaces/m-p/557026#M113049</guid>
      <dc:creator>Kobiher</dc:creator>
      <dc:date>2023-09-07T16:25:09Z</dc:date>
    </item>
    <item>
      <title>Re: Shutting down/disabling subinterfaces</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/shutting-down-disabling-subinterfaces/m-p/1204798#M122972</link>
      <description>&lt;P&gt;Other vendors like Cisco has. Moreover, rename the zone to none will lead to validation errors if there are policies referring to that zone where you want to shut down the sub-interface&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jan 2025 03:20:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/shutting-down-disabling-subinterfaces/m-p/1204798#M122972</guid>
      <dc:creator>N.Gurjar</dc:creator>
      <dc:date>2025-01-22T03:20:27Z</dc:date>
    </item>
    <item>
      <title>Re: Shutting down/disabling subinterfaces</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/shutting-down-disabling-subinterfaces/m-p/1205020#M122977</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1400169621"&gt;@N.Gurjar&lt;/a&gt;&amp;nbsp;Please see my reply above.&amp;nbsp; It's what I ended up doing and it worked just fine.&amp;nbsp; With that said, I 100% agree that there should just be a "shutdown" command like Cisco.&amp;nbsp; However, at least one person reported that it didn't work.&amp;nbsp; When I did it,I want to say I was either on 8.1 or 9.1.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jan 2025 09:45:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/shutting-down-disabling-subinterfaces/m-p/1205020#M122977</guid>
      <dc:creator>justamoment</dc:creator>
      <dc:date>2025-01-22T09:45:37Z</dc:date>
    </item>
    <item>
      <title>Re: Shutting down/disabling subinterfaces</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/shutting-down-disabling-subinterfaces/m-p/1205053#M122983</link>
      <description>&lt;P&gt;I have always wanted this feature.&amp;nbsp; If everyone on this thread contacts their PANW SE and requests this feature, then we should get a feature request ID created.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jan 2025 16:44:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/shutting-down-disabling-subinterfaces/m-p/1205053#M122983</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2025-01-22T16:44:54Z</dc:date>
    </item>
    <item>
      <title>Re: Shutting down/disabling subinterfaces</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/shutting-down-disabling-subinterfaces/m-p/1231212#M124504</link>
      <description>&lt;P&gt;Good luck.&amp;nbsp; I'm moving from Fortinet to Palo Alto (by someone else's direction) and the UI is like taking a 15 year step backward.&amp;nbsp; I'm amazed at how many little things I've gotten used to in Fortinet that don't exist in Palo.&amp;nbsp; I go off and search to see if I'm missing something and, like this thread, I find an ancient thread indicating that Palo just 'doesn't do that'.&amp;nbsp; And there's always the 'submit a request' line, as if that gets anywhere.&amp;nbsp; It's as if Palo's interface was designed by someone who has never managed a firewall before and architectural decisions were designed by someone who's never managed a network before.&amp;nbsp; Beyond frustrating.....&lt;/P&gt;</description>
      <pubDate>Fri, 06 Jun 2025 13:42:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/shutting-down-disabling-subinterfaces/m-p/1231212#M124504</guid>
      <dc:creator>K.Saucier</dc:creator>
      <dc:date>2025-06-06T13:42:31Z</dc:date>
    </item>
  </channel>
</rss>

