<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Multiple DMZ setup question in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/multiple-dmz-setup-question/m-p/2955#M2195</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I'm looking to create 2 dmz's on the PAN as separate networks.&amp;nbsp; This is how I have it envisioned and would appreciate any feedback.&lt;/P&gt;&lt;P&gt;1. configure two layer 3 interafaces with GW IP assigned&lt;BR /&gt;2. assign security zone to each interface&lt;BR /&gt;3. attach each interface to existing VR&lt;BR /&gt;4. route internal dmz address networks to each interface in VR&lt;BR /&gt;5. set security and nat policies as appropriate&lt;/P&gt;&lt;P&gt;I know I could configure the interfaces as layer 2 as spelled out in the L2 networking pdf, but I'm unable to do that in this situation.&amp;nbsp; Are there any considerations I should be aware of?&amp;nbsp; My existing VR is used for VPN tunnels only.&amp;nbsp; Should I consider a separate VR?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;BR /&gt;Ian&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 05 Oct 2012 16:57:33 GMT</pubDate>
    <dc:creator>iguarino</dc:creator>
    <dc:date>2012-10-05T16:57:33Z</dc:date>
    <item>
      <title>Multiple DMZ setup question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/multiple-dmz-setup-question/m-p/2955#M2195</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I'm looking to create 2 dmz's on the PAN as separate networks.&amp;nbsp; This is how I have it envisioned and would appreciate any feedback.&lt;/P&gt;&lt;P&gt;1. configure two layer 3 interafaces with GW IP assigned&lt;BR /&gt;2. assign security zone to each interface&lt;BR /&gt;3. attach each interface to existing VR&lt;BR /&gt;4. route internal dmz address networks to each interface in VR&lt;BR /&gt;5. set security and nat policies as appropriate&lt;/P&gt;&lt;P&gt;I know I could configure the interfaces as layer 2 as spelled out in the L2 networking pdf, but I'm unable to do that in this situation.&amp;nbsp; Are there any considerations I should be aware of?&amp;nbsp; My existing VR is used for VPN tunnels only.&amp;nbsp; Should I consider a separate VR?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;BR /&gt;Ian&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Oct 2012 16:57:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/multiple-dmz-setup-question/m-p/2955#M2195</guid>
      <dc:creator>iguarino</dc:creator>
      <dc:date>2012-10-05T16:57:33Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple DMZ setup question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/multiple-dmz-setup-question/m-p/2956#M2196</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You are in the right path, can you please brief the problem you are facing with the config ?. Are u not able to configure L3 interfaces or what is the problem that you are facing?&amp;nbsp; You do not need two VR's for this. One virtual router should be fine.&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Sandeep T&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Oct 2012 20:31:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/multiple-dmz-setup-question/m-p/2956#M2196</guid>
      <dc:creator>sdurga</dc:creator>
      <dc:date>2012-10-05T20:31:50Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple DMZ setup question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/multiple-dmz-setup-question/m-p/2957#M2197</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Ian,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As per the description, I am assuming you might be doing the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) Tying to add L3 interface and L2 in the same DMZ zone: It might not be possible because the Zones are defined based on Zone type, they should be either layer 3 or layer 2 or vwire or tap, we can not create a combination out of it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) If the above assumption is wrong, the next thing I can assume is that you are trying to configure two DMZ zone with same name but one for layer 3 and another for layer 2, that would also not be possible because by design we can not have two zone with same name even though they are of different type.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let us know if you are trying something else, we would try our best to respond you back as soon as possible.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Khubaib Alavi&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Oct 2012 23:22:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/multiple-dmz-setup-question/m-p/2957#M2197</guid>
      <dc:creator>kalavi</dc:creator>
      <dc:date>2012-10-05T23:22:45Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple DMZ setup question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/multiple-dmz-setup-question/m-p/2958#M2198</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks guys.&amp;nbsp; The issue was a bad configuration on the vmhost side.&amp;nbsp; I just wanted to get a sanity check on my side of the config.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Oct 2012 12:58:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/multiple-dmz-setup-question/m-p/2958#M2198</guid>
      <dc:creator>iguarino</dc:creator>
      <dc:date>2012-10-11T12:58:41Z</dc:date>
    </item>
  </channel>
</rss>

