<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: vLAN clarification &amp; help in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/vlan-clarification-help/m-p/21089#M15393</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;For terminating multiple VLANs on the &lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt; same physical interface, multiple tagged sub-interfaces should be created &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;refer :&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" class="active_link" href="https://live.paloaltonetworks.com/docs/DOC-1805"&gt;https://live.paloaltonetworks.com/docs/DOC-1805&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Ameya&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 25 Sep 2012 03:06:49 GMT</pubDate>
    <dc:creator>UhMayYeah</dc:creator>
    <dc:date>2012-09-25T03:06:49Z</dc:date>
    <item>
      <title>vLAN clarification &amp; help</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vlan-clarification-help/m-p/21088#M15392</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;At my place of employment we've implemented a couple PAN-2020s in HA and have defined about 6 to 8 networks 1 attached to 1 physical port in a L3 configuration. We have cables running to a switch that each are untagged with different vLAN ID's (LAN = Default_VLAN, DMZ = DMZ_VLAN, etc). The vLAN'ing is done on the switch (HP ProCurve 2810-48G) and other ports are tagged and represented to VMware hosts. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PAN --&amp;gt; HP 2810-48G ==&amp;lt; VMware HOSTs&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a few open ports, but am needing to create about 3 more networks to use and have quickly run out of physical ports. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For those of you who have done this, or any PAN techs helping out here, what is the best practice for implementing vLANS in this type of environment.&amp;nbsp; I've seen some example of L2 configurations as well as L3 and I am a bit confused on what is best.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What is the best way to make a handful of physical ports aggregate&amp;nbsp; on the firewall to present those vLANs to the switches, and then to the VMware hosts without doing that over just one cable? Do I need to configure the vLANs on the switch as well and tag those ports?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I realize these are a lot of questions - unfortunately the project was escalated a few months ago and I did not get sufficient time to design this out, so it's made it hard to design well, and I have some opportunity to implement changes before this environment goes 100% into production. So I don't have quite the liberty to test this out. &lt;img id="smileysad" class="emoticon emoticon-smileysad" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-sad.png" alt="Smiley Sad" title="Smiley Sad" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Am I on the right track with this document? &lt;A __default_attr="3756" __jive_macro_name="document" class="jive_macro jive_macro_document" href="https://live.paloaltonetworks.com/"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for all your help!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Sep 2012 01:23:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vlan-clarification-help/m-p/21088#M15392</guid>
      <dc:creator>cmateam</dc:creator>
      <dc:date>2012-09-25T01:23:24Z</dc:date>
    </item>
    <item>
      <title>Re: vLAN clarification &amp; help</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vlan-clarification-help/m-p/21089#M15393</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;For terminating multiple VLANs on the &lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt; same physical interface, multiple tagged sub-interfaces should be created &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;refer :&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" class="active_link" href="https://live.paloaltonetworks.com/docs/DOC-1805"&gt;https://live.paloaltonetworks.com/docs/DOC-1805&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Ameya&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Sep 2012 03:06:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vlan-clarification-help/m-p/21089#M15393</guid>
      <dc:creator>UhMayYeah</dc:creator>
      <dc:date>2012-09-25T03:06:49Z</dc:date>
    </item>
    <item>
      <title>Re: vLAN clarification &amp; help</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vlan-clarification-help/m-p/21090#M15394</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you aggregate these across interfaces?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Sep 2012 23:08:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vlan-clarification-help/m-p/21090#M15394</guid>
      <dc:creator>cmateam</dc:creator>
      <dc:date>2012-09-25T23:08:50Z</dc:date>
    </item>
    <item>
      <title>Re: vLAN clarification &amp; help</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vlan-clarification-help/m-p/21091#M15395</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Per this discussion: &lt;A __default_attr="3461" __jive_macro_name="message" class="jive_macro jive_macro_message" href="https://live.paloaltonetworks.com/"&gt;&lt;/A&gt; can you set one of the sub interfaces to have the route while all the others are just tagged?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For example:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;eth1/8.8 10.55.1.1/24&lt;/P&gt;&lt;P&gt;eth1/9.8 - blank -?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Sep 2012 23:12:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vlan-clarification-help/m-p/21091#M15395</guid>
      <dc:creator>cmateam</dc:creator>
      <dc:date>2012-09-25T23:12:15Z</dc:date>
    </item>
    <item>
      <title>Re: vLAN clarification &amp; help</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vlan-clarification-help/m-p/21092#M15396</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yeah,this configuration was accepted by the firewall.&lt;/P&gt;&lt;P&gt;PFA&lt;/P&gt;&lt;P&gt;&lt;IMG alt="VLaN-tag.GIF" class="jiveImage" src="https://live.paloaltonetworks.com/legacyfs/online/4189_VLaN-tag.GIF" style="width: 450px; height: 46px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Ameya&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Sep 2012 23:46:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vlan-clarification-help/m-p/21092#M15396</guid>
      <dc:creator>UhMayYeah</dc:creator>
      <dc:date>2012-09-25T23:46:45Z</dc:date>
    </item>
    <item>
      <title>Re: vLAN clarification &amp; help</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vlan-clarification-help/m-p/21093#M15397</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I had one additional question pertaining to this initial question.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So within my network, I have setup all the VLANs on L3 interfaces, with no networks defined (untagged) - everything works great.&amp;nbsp; However, when I define a network on another L3 interface, without any VLANing all my networking goes crazy. The reason I am needing to do this is because some devices that have management interfaces (like our SAN, PAN FWs, and KVM) does not support vlan tagging on their interfaces.&amp;nbsp; But since I can't specify a network on the default vlan L3 interface, I am now unable to manage these devices (without buying another switch. So my question was, can I create another virtual router and setup a L3 interface with the untagged vlan and network (a management network of sorts) present that to the default vlan on my switch, to manage such devices and then just route traffic between the to VRs? Does that make sense.&amp;nbsp; Anyone else run into this before?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 Oct 2012 20:46:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vlan-clarification-help/m-p/21093#M15397</guid>
      <dc:creator>cmateam</dc:creator>
      <dc:date>2012-10-10T20:46:49Z</dc:date>
    </item>
  </channel>
</rss>

