<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Routing Issues with Layer 3 Deployment in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/routing-issues-with-layer-3-deployment/m-p/24382#M17775</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The Palo Alto is connection on port 36 on the Layer 3 Switch, that port is on the VLAN 100.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Basically all the users have their gateway to the Layer 3 switch. The Layer 3 switch then forward all requests to 192.168.200.254 which is the interface of the Palo Alto.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Only users on the VLAN100 are managing to access the internet which is on the same subnet of the PA&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I used to manage on my old firewall through some rules (these were done by some company).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope I made myself clear. Cheers&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 11 Mar 2011 11:03:38 GMT</pubDate>
    <dc:creator>devere</dc:creator>
    <dc:date>2011-03-11T11:03:38Z</dc:date>
    <item>
      <title>Routing Issues with Layer 3 Deployment</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/routing-issues-with-layer-3-deployment/m-p/24380#M17773</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm having issues with internet access on different subnets. I have attached a diagram on my network. The Server VLAN has Internet access but the rest somehow are not managing, I'm seeing the traffic in the logs but nothing seems to be working.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have tried various settings but somehow I'm missing it. Does anyone have any thoughts?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Mar 2011 21:36:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/routing-issues-with-layer-3-deployment/m-p/24380#M17773</guid>
      <dc:creator>devere</dc:creator>
      <dc:date>2011-03-10T21:36:47Z</dc:date>
    </item>
    <item>
      <title>Re: Routing Issues with Layer 3 Deployment</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/routing-issues-with-layer-3-deployment/m-p/24381#M17774</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Are you terminating each VLAN on the Palo Alto box (having the gw address on the Palo) or do you have a link-network between the Palo "internal" interface and the switch.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Mar 2011 10:55:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/routing-issues-with-layer-3-deployment/m-p/24381#M17774</guid>
      <dc:creator>rapoint_person</dc:creator>
      <dc:date>2011-03-11T10:55:17Z</dc:date>
    </item>
    <item>
      <title>Re: Routing Issues with Layer 3 Deployment</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/routing-issues-with-layer-3-deployment/m-p/24382#M17775</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The Palo Alto is connection on port 36 on the Layer 3 Switch, that port is on the VLAN 100.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Basically all the users have their gateway to the Layer 3 switch. The Layer 3 switch then forward all requests to 192.168.200.254 which is the interface of the Palo Alto.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Only users on the VLAN100 are managing to access the internet which is on the same subnet of the PA&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I used to manage on my old firewall through some rules (these were done by some company).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope I made myself clear. Cheers&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Mar 2011 11:03:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/routing-issues-with-layer-3-deployment/m-p/24382#M17775</guid>
      <dc:creator>devere</dc:creator>
      <dc:date>2011-03-11T11:03:38Z</dc:date>
    </item>
    <item>
      <title>Re: Routing Issues with Layer 3 Deployment</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/routing-issues-with-layer-3-deployment/m-p/24383#M17776</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;OK, great. So what do you see in the log-files from the networks that doesn't work? Possible to post an output from the log?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I take it you have checked your routing and it's correct?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A Palo route Example:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Route_internal 192.168.203.0/24 gateway 192.168.200.1 (.1 beeing the Switch)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Mar 2011 12:03:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/routing-issues-with-layer-3-deployment/m-p/24383#M17776</guid>
      <dc:creator>rapoint_person</dc:creator>
      <dc:date>2011-03-11T12:03:37Z</dc:date>
    </item>
    <item>
      <title>Re: Routing Issues with Layer 3 Deployment</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/routing-issues-with-layer-3-deployment/m-p/24384#M17777</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There could be a couple reasons for this, depending on how your PAN is setup.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(these are not necessarily in any order)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) Do you have the appropriate user subnets listed in the correct security zones?&lt;/P&gt;&lt;P&gt;2) Are the correct security zones applied to the correct interfaces?&lt;/P&gt;&lt;P&gt;3) Do you have multiple virtual routers or just one?&lt;/P&gt;&lt;P&gt;4) If only one virtual router, you should have the static routes defining each of the user vlans AND have the gateway of those networks point to the L3 switch.&lt;/P&gt;&lt;P&gt;5) NAT rules?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The way I built our PAN config is similiar to our checkpoint configs. We start out with creating network objects of all the networks that we support. Then create logical groups with those networks. Then apply the groups to the right security zones. Use the logical groups for NAT rules as well.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Mar 2011 17:44:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/routing-issues-with-layer-3-deployment/m-p/24384#M17777</guid>
      <dc:creator>camkim_MDEA</dc:creator>
      <dc:date>2011-03-11T17:44:10Z</dc:date>
    </item>
    <item>
      <title>Re: Routing Issues with Layer 3 Deployment</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/routing-issues-with-layer-3-deployment/m-p/24385#M17778</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;devere wrote:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The Palo Alto is connection on port 36 on the Layer 3 Switch, that port is on the VLAN 100.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Basically all the users have their gateway to the Layer 3 switch. The Layer 3 switch then forward all requests to 192.168.200.254 which is the interface of the Palo Alto.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Only users on the VLAN100 are managing to access the internet which is on the same subnet of the PA&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I used to manage on my old firewall through some rules (these were done by some company).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope I made myself clear. Cheers&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you actually have a route in the Palo Alto to get point traffic back into the network via VLAN100?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The PA won't need a route to VLAN100 - because it's a directly connected network, the PA will just "know' how to get to devices in this network. However, if you don;t have a VR setup on the PAN telling it how to get traffic back tot he other VLAN's - for example, route 192.168.201.0/24 via 192.168.200.1.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The configuration should look something like this&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;virtual-router {&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; router-1 {&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; interface [ ethernet1/1 ethernet1/2];&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; routing-table {&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ip {&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; static-route {&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; servers {&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; destination 192.168.200.0/24;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; interface ethernet1/1;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; nexthop {&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ip-address 192.168.200.1;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; }&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; }&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; level1 {&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; destination 192.168.201.0/24;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; interface ethernet1/1;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; nexthop {&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ip-address 192.168.200.1;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; }&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; }&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From the GUI, you should have something similar to the graphic attached - a route in the PA sending everything for the other subnets tot he "router" (layer 3) IP address for VLAN 100.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Mar 2011 22:46:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/routing-issues-with-layer-3-deployment/m-p/24385#M17778</guid>
      <dc:creator>dagibbs</dc:creator>
      <dc:date>2011-03-15T22:46:11Z</dc:date>
    </item>
    <item>
      <title>Re: Routing Issues with Layer 3 Deployment</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/routing-issues-with-layer-3-deployment/m-p/24386#M17779</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;after much aggrevation the problem was the layer 3 switch. it developed some fault where it couldn't correctly route to the PA on different VLANS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On a side note would it be ideal/practical to use the PA as my layer 3 device also?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Mar 2011 08:12:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/routing-issues-with-layer-3-deployment/m-p/24386#M17779</guid>
      <dc:creator>devere</dc:creator>
      <dc:date>2011-03-25T08:12:39Z</dc:date>
    </item>
    <item>
      <title>Re: Routing Issues with Layer 3 Deployment</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/routing-issues-with-layer-3-deployment/m-p/24387#M17780</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;devere wrote:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;after much aggrevation the problem was the layer 3 switch. it developed some fault where it couldn't correctly route to the PA on different VLANS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On a side note would it be ideal/practical to use the PA as my layer 3 device also?&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I wouldn't call it either - the PA is already doing a lot of work - firewall, web filter, virus checking, threat detection and filtering - adding layer 3 for your entire network, while possible, would not be the greatest idea.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Having said that, you *could* do it - I just don't know if it'd be the smartest idea, not knowing which model PA you have.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 27 Mar 2011 22:03:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/routing-issues-with-layer-3-deployment/m-p/24387#M17780</guid>
      <dc:creator>dagibbs</dc:creator>
      <dc:date>2011-03-27T22:03:30Z</dc:date>
    </item>
  </channel>
</rss>

