<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: TAP interface questions in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/tap-interface-questions/m-p/1245317#M125808</link>
    <description>&lt;P&gt;On the Cisco device, two interfaces (Ethernet 1 and Ethernet 2) are configured as part of the same aggregated link (Port-Channel 1).&lt;BR /&gt;SPAN is configured with the source VLANs 1–100 and the destination interface Port-Channel 1, as shown below:&lt;/P&gt;
&lt;P&gt;monitor session 1 source vlan 1-100&lt;BR /&gt;monitor session 1 destination interface port-channel 1&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;On the Palo Alto device, the corresponding two interfaces (port 1 and port 2) are configured in TAP mode to receive the mirrored traffic from the Cisco device.&lt;/P&gt;
&lt;P&gt;The question is: when SPAN traffic is sent out via a Port-Channel, can the Palo Alto device correctly receive and process the TAP traffic across these two interfaces?&lt;/P&gt;</description>
    <pubDate>Sun, 11 Jan 2026 03:59:27 GMT</pubDate>
    <dc:creator>T.XuanDung</dc:creator>
    <dc:date>2026-01-11T03:59:27Z</dc:date>
    <item>
      <title>TAP interface questions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/tap-interface-questions/m-p/75727#M42064</link>
      <description>&lt;P&gt;I'd like to monitor a portion of my network on my failover PA in TAP mode.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Will this affect my HA pair at all?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is it possible to set up an aggregate TAP of 2 ports?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks in advance...&lt;/P&gt;</description>
      <pubDate>Mon, 04 Apr 2016 14:51:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/tap-interface-questions/m-p/75727#M42064</guid>
      <dc:creator>VSU_ITSEC</dc:creator>
      <dc:date>2016-04-04T14:51:14Z</dc:date>
    </item>
    <item>
      <title>Re: TAP interface questions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/tap-interface-questions/m-p/75736#M42066</link>
      <description>&lt;P&gt;Do you mean that passive firewall in active/passive cluster would perform monitoring (have TAP port listening)?&lt;/P&gt;
&lt;P&gt;You can't do that because as name says - it is passive. Network ports are turned off on that fw.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Apr 2016 18:06:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/tap-interface-questions/m-p/75736#M42066</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2016-04-04T18:06:11Z</dc:date>
    </item>
    <item>
      <title>Re: TAP interface questions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/tap-interface-questions/m-p/75745#M42069</link>
      <description>&lt;P&gt;Also, yes you can place 2 tap ports across 2 aggregated links. &amp;nbsp;Just make sure to put both tap ports on the same security zone.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Apr 2016 21:42:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/tap-interface-questions/m-p/75745#M42069</guid>
      <dc:creator>rmonvon</dc:creator>
      <dc:date>2016-04-04T21:42:55Z</dc:date>
    </item>
    <item>
      <title>Re: TAP interface questions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/tap-interface-questions/m-p/1245317#M125808</link>
      <description>&lt;P&gt;On the Cisco device, two interfaces (Ethernet 1 and Ethernet 2) are configured as part of the same aggregated link (Port-Channel 1).&lt;BR /&gt;SPAN is configured with the source VLANs 1–100 and the destination interface Port-Channel 1, as shown below:&lt;/P&gt;
&lt;P&gt;monitor session 1 source vlan 1-100&lt;BR /&gt;monitor session 1 destination interface port-channel 1&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;On the Palo Alto device, the corresponding two interfaces (port 1 and port 2) are configured in TAP mode to receive the mirrored traffic from the Cisco device.&lt;/P&gt;
&lt;P&gt;The question is: when SPAN traffic is sent out via a Port-Channel, can the Palo Alto device correctly receive and process the TAP traffic across these two interfaces?&lt;/P&gt;</description>
      <pubDate>Sun, 11 Jan 2026 03:59:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/tap-interface-questions/m-p/1245317#M125808</guid>
      <dc:creator>T.XuanDung</dc:creator>
      <dc:date>2026-01-11T03:59:27Z</dc:date>
    </item>
  </channel>
</rss>

