<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Convert from vwire to layer 3 for globalprotect. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/convert-from-vwire-to-layer-3-for-globalprotect/m-p/24354#M17753</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you very much. It is a great relief to not have to re-write the policies. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;About the virtual router. I'm not trying to disrupt existing routes, but an only trying to make globalprotect portal and gateway work. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 10 Feb 2014 18:23:03 GMT</pubDate>
    <dc:creator>Netwerx</dc:creator>
    <dc:date>2014-02-10T18:23:03Z</dc:date>
    <item>
      <title>Convert from vwire to layer 3 for globalprotect.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/convert-from-vwire-to-layer-3-for-globalprotect/m-p/24352#M17751</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm trying to put together a plan of action to get globalprotect to work for us. I have a work ticket open with PA. Our PA firewall is currently deployed in a VWire setup, on the lan side of our router. Here are my big questions for getting this accomplished. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) If I switch the vwire to layer 3 can I migrate the security profile name so I don't have to re-write every security policy? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) Can the establishment of a virtual router on the layer 3 interface disrupt existing routes established by our physical router? This may be a silly question here. I'm just wondering if establishing a virtual router behind our physical one would disrupt or block any existing traffic routes, or if it would only momentarily establish new routes with RIP or the like. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 09 Feb 2014 20:50:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/convert-from-vwire-to-layer-3-for-globalprotect/m-p/24352#M17751</guid>
      <dc:creator>Netwerx</dc:creator>
      <dc:date>2014-02-09T20:50:08Z</dc:date>
    </item>
    <item>
      <title>Re: Convert from vwire to layer 3 for globalprotect.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/convert-from-vwire-to-layer-3-for-globalprotect/m-p/24353#M17752</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Sir,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(A) If you are planning to change the config from Virtual-wire to Layer-3,&amp;nbsp; you need not to re-write all security policies again. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. You have to change the interface type, from &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;vwire&lt;/SPAN&gt; to Layer-3.&lt;/P&gt;&lt;P&gt;2. Change the Zone type from &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;vwire&lt;/SPAN&gt; to Layer-3&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Example:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Zone.JPG.jpg" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/11499_Zone.JPG.jpg" style="width: 620px; height: 449px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(B)&amp;nbsp; If &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;i&lt;/SPAN&gt; understand your query correctly&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;,&lt;/SPAN&gt;you can create a new virtual router for a Layer-3 interface and It would not impact on your &lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;existing routes established by your physical router. Until and unless you are not pointing any route to that/from Virtual router. Virtual router is a logical separation of routing table inside the same physical device.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let us know if you need further information on this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 09 Feb 2014 23:14:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/convert-from-vwire-to-layer-3-for-globalprotect/m-p/24353#M17752</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-02-09T23:14:36Z</dc:date>
    </item>
    <item>
      <title>Re: Convert from vwire to layer 3 for globalprotect.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/convert-from-vwire-to-layer-3-for-globalprotect/m-p/24354#M17753</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you very much. It is a great relief to not have to re-write the policies. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;About the virtual router. I'm not trying to disrupt existing routes, but an only trying to make globalprotect portal and gateway work. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Feb 2014 18:23:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/convert-from-vwire-to-layer-3-for-globalprotect/m-p/24354#M17753</guid>
      <dc:creator>Netwerx</dc:creator>
      <dc:date>2014-02-10T18:23:03Z</dc:date>
    </item>
    <item>
      <title>Re: Convert from vwire to layer 3 for globalprotect.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/convert-from-vwire-to-layer-3-for-globalprotect/m-p/24355#M17754</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For your question 'A' Instead of re-writing security policies I'd recommend to change source and destination zones to any and then change zones from v-wire to L-3 and then refer the new zones in your security policies.&lt;/P&gt;&lt;P&gt;Hope it helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hari&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Feb 2014 18:33:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/convert-from-vwire-to-layer-3-for-globalprotect/m-p/24355#M17754</guid>
      <dc:creator>hyadavalli</dc:creator>
      <dc:date>2014-02-10T18:33:20Z</dc:date>
    </item>
  </channel>
</rss>

