<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Layer 3 switch behind Layer 3 PA-3020 interface in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/layer-3-switch-behind-layer-3-pa-3020-interface/m-p/17279#M12614</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The subinterfaces on the PA will be 802.1Q tagged vlans to your switch.&amp;nbsp; So you need to create the matching vlan tag on that trunk port for your Cisco and assign this same tag to your access port vlan on the switch.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have a look at Case 1 on page 3 and following in this document.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-1618"&gt;Securing Inter VLAN Traffic&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 06 Jun 2015 13:03:37 GMT</pubDate>
    <dc:creator>pulukas</dc:creator>
    <dc:date>2015-06-06T13:03:37Z</dc:date>
    <item>
      <title>Layer 3 switch behind Layer 3 PA-3020 interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/layer-3-switch-behind-layer-3-pa-3020-interface/m-p/17277#M12612</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So I'm new to my PA-3020 and trying to get beyond my basic config has introduced a new problem for me.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a Layer 3 Cisco connected to my PA eth 1/2 via a routed interface on the switch.&amp;nbsp; My traffic is all working fine now, but I want to make some changes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;All my vlans have IP addresses on my switch, and they route via the switch routing table to the LAN or on the PA.&amp;nbsp; I want to have some of those vlans isolated from the LAN, so they can't route via the switch.&amp;nbsp; I think I need to set up subinterfaces on my PA, but it has not been working.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I created a test vlan on my switch (100).&amp;nbsp; No ip address, so it does not have a route in the switch.&amp;nbsp; I set the vlan ip helper-address as the IP of the PA subinterface, so it should forward DHCP requests on that vlan to the subinterface IP on the PA.&amp;nbsp; I created eth1/2.100 on my PA, gave it a dhcp relay for my dhcp servers on the LAN, made sure there is a route from the PA to the servers vlan on the LAN, created a Test Zone and Security Policy to allow DHCP between Test and Trust zones.&amp;nbsp; I can ping through these zones and networks, but my DHCP requests are not making it out of my switch to the PA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How should I accomplish what I want to do?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Steve&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Jun 2015 16:58:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/layer-3-switch-behind-layer-3-pa-3020-interface/m-p/17277#M12612</guid>
      <dc:creator>GCA</dc:creator>
      <dc:date>2015-06-03T16:58:15Z</dc:date>
    </item>
    <item>
      <title>Re: Layer 3 switch behind Layer 3 PA-3020 interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/layer-3-switch-behind-layer-3-pa-3020-interface/m-p/17278#M12613</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I would start with Monitor &amp;gt; Packet Capture to see if PA receives those DHCP requests from switch and offers from server.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Jun 2015 09:22:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/layer-3-switch-behind-layer-3-pa-3020-interface/m-p/17278#M12613</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2015-06-04T09:22:05Z</dc:date>
    </item>
    <item>
      <title>Re: Layer 3 switch behind Layer 3 PA-3020 interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/layer-3-switch-behind-layer-3-pa-3020-interface/m-p/17279#M12614</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The subinterfaces on the PA will be 802.1Q tagged vlans to your switch.&amp;nbsp; So you need to create the matching vlan tag on that trunk port for your Cisco and assign this same tag to your access port vlan on the switch.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have a look at Case 1 on page 3 and following in this document.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-1618"&gt;Securing Inter VLAN Traffic&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 06 Jun 2015 13:03:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/layer-3-switch-behind-layer-3-pa-3020-interface/m-p/17279#M12614</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2015-06-06T13:03:37Z</dc:date>
    </item>
    <item>
      <title>Re: Layer 3 switch behind Layer 3 PA-3020 interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/layer-3-switch-behind-layer-3-pa-3020-interface/m-p/17280#M12615</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The problem was that my Cisco port was routed, not a switch trunk port.&amp;nbsp; All vlan tags were being dropped in the routing.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Jun 2015 14:26:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/layer-3-switch-behind-layer-3-pa-3020-interface/m-p/17280#M12615</guid>
      <dc:creator>GCA</dc:creator>
      <dc:date>2015-06-08T14:26:49Z</dc:date>
    </item>
    <item>
      <title>Re: Layer 3 switch behind Layer 3 PA-3020 interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/layer-3-switch-behind-layer-3-pa-3020-interface/m-p/17281#M12616</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In order to use the sub interfaces you will need to configure the attached Cisco port into trunk mode.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Jun 2015 22:39:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/layer-3-switch-behind-layer-3-pa-3020-interface/m-p/17281#M12616</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2015-06-08T22:39:14Z</dc:date>
    </item>
  </channel>
</rss>

