<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Is it possible to use public IPs on the same subnet on different interfaces? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-use-public-ips-on-the-same-subnet-on-different/m-p/21062#M15370</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;We want to use inbound NAT in different VSYS on a PAN 4020 device. The question is, is it possible to use adresses(mip equivalent on netscreen devices) from the same subnet on different phisycal interfaces in different vsys? On netscreen devices we must split adresses in different subnets and make routing on network routers behind the firewall, is the same condition present on Palo Alto devices or we can make it work without this kind of segmentation.&lt;/P&gt;&lt;P&gt;Thank you for your answers.&lt;/P&gt;&lt;P&gt;Regrd's.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 16 Feb 2011 17:54:42 GMT</pubDate>
    <dc:creator>asia</dc:creator>
    <dc:date>2011-02-16T17:54:42Z</dc:date>
    <item>
      <title>Is it possible to use public IPs on the same subnet on different interfaces?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-use-public-ips-on-the-same-subnet-on-different/m-p/21062#M15370</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;We want to use inbound NAT in different VSYS on a PAN 4020 device. The question is, is it possible to use adresses(mip equivalent on netscreen devices) from the same subnet on different phisycal interfaces in different vsys? On netscreen devices we must split adresses in different subnets and make routing on network routers behind the firewall, is the same condition present on Palo Alto devices or we can make it work without this kind of segmentation.&lt;/P&gt;&lt;P&gt;Thank you for your answers.&lt;/P&gt;&lt;P&gt;Regrd's.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Feb 2011 17:54:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-use-public-ips-on-the-same-subnet-on-different/m-p/21062#M15370</guid>
      <dc:creator>asia</dc:creator>
      <dc:date>2011-02-16T17:54:42Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to use public IPs on the same subnet on different interfaces?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-use-public-ips-on-the-same-subnet-on-different/m-p/21063#M15371</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;yes this is possible, but it requires a separate virtual router per physical interface in&amp;nbsp; the same subnet.&lt;/P&gt;&lt;P&gt;Since you are working with multiple vsys you will already have a separate VR from the one that holds the original IP subnet, so you can create an interface in the same subnet as the first VR&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;Tom&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Feb 2011 12:42:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-use-public-ips-on-the-same-subnet-on-different/m-p/21063#M15371</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2011-02-17T12:42:06Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to use public IPs on the same subnet on different interfaces?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-use-public-ips-on-the-same-subnet-on-different/m-p/21064#M15372</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Along the same lines as this is it ok to have 2 seperate vrouters (same vsys), each with an interface attached to the same subnet and with the interfaces assigned the same zone?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Jul 2011 20:31:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-use-public-ips-on-the-same-subnet-on-different/m-p/21064#M15372</guid>
      <dc:creator>brownn</dc:creator>
      <dc:date>2011-07-04T20:31:30Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to use public IPs on the same subnet on different interfaces?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-use-public-ips-on-the-same-subnet-on-different/m-p/21065#M15373</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;As far as whether or not this is possible, yes. You can create (2) unique VR's within the same vsys (assigning each physical L3 interface to their designated VR's), assign IP's to each of the L3 interfaces on the same subnet, with both interfaces (seperate VR's) assigned to the same zone. (as long as the IP's do not conflict as the PAN will not allow you to commit).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As far as functionality/expected behavior, I'd suggest implementing/experimenting with this configuration in a test environment.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Bryan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Jul 2011 04:25:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-use-public-ips-on-the-same-subnet-on-different/m-p/21065#M15373</guid>
      <dc:creator>bryan</dc:creator>
      <dc:date>2011-07-06T04:25:19Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to use public IPs on the same subnet on different interfaces?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-use-public-ips-on-the-same-subnet-on-different/m-p/21066#M15374</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks bryan,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I assumed it was possible as well but when I tried it an incoming service that was dst NAT'd broke and I have yet to figure out why. There was a gap in the log traffic until I had removed the changes so basically the Palo was not seeing the incoming traffic from the Internet for this particular service. The only thing I could think of was that maybe the Palo started to proxy-arp out of the new interface hence pulling traffic into the wrong vrouter. It was just a theory and not one I can prove without breaking the environment again at the moment! I need to schedule an out-of-hours change to try again.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Jul 2011 15:29:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-use-public-ips-on-the-same-subnet-on-different/m-p/21066#M15374</guid>
      <dc:creator>brownn</dc:creator>
      <dc:date>2011-07-06T15:29:43Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to use public IPs on the same subnet on different interfaces?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-use-public-ips-on-the-same-subnet-on-different/m-p/21067#M15375</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have built a similar config, but on 1 vsys with 4 ip adresses in one subnet on the public interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;At first we were only able to configure this using the primary IP with a /29 subnet and the other 3 IP adresses with a /32 subnetmask.&lt;/P&gt;&lt;P&gt;Not the cleanest configuration of course. Eventually we found out that it is possible to configure just one IP address with /29 and just configure the other adresses using the NAT configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This seems to work perfectly fine.&amp;nbsp; Probably not a direct answer, but it might push others in the right direction.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Bas Sanders&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Oct 2011 20:50:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-use-public-ips-on-the-same-subnet-on-different/m-p/21067#M15375</guid>
      <dc:creator>bsanders</dc:creator>
      <dc:date>2011-10-24T20:50:48Z</dc:date>
    </item>
  </channel>
</rss>

