<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: configuration help-vwire subinterfaces with different policies per vlans in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/configuration-help-vwire-subinterfaces-with-different-policies/m-p/3108#M2323</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;great - it worked &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;P&gt;after modifications&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="ScreenShot011.bmp" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/6299_ScreenShot011.bmp" width="450" /&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="ScreenShot012.bmp" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/6300_ScreenShot012.bmp" width="450" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;so this is not true what the book says&amp;nbsp; &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote" modifiedtitle="true"&gt;
&lt;P&gt;Note that you do not specify the virtual wire object during the creation of the subinteface. Since the subinterface is built on an existing virtual wire interface, the virtual wire object is inherited from parent interface. However, the subinterface and parent interface can be configured on different zones&lt;/P&gt;
&lt;P&gt;...&lt;/P&gt;
&lt;P&gt;The subinterfaces allow you to separate and classify traffic into different zones by either VLAN tags or VLAN tags in conjunction with IP classifiers (address, range, or subnet.)&lt;/P&gt;
&lt;P&gt;...&lt;/P&gt;
&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;the main interface must be on separate vwire object and each one of the subinterfaces as well.&lt;/LI&gt;&lt;LI&gt;No vlan tagging on Vwire !!! only on subinterfaces&lt;/LI&gt;&lt;LI&gt;only then subinterfaces are seen as being on separeted zones&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="ScreenShot013.bmp" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/6301_ScreenShot013.bmp" width="450" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thx Seweryn&lt;/P&gt;&lt;P&gt;hope to be in touch&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;Przemek&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 17 Apr 2013 09:19:09 GMT</pubDate>
    <dc:creator>pkonitz</dc:creator>
    <dc:date>2013-04-17T09:19:09Z</dc:date>
    <item>
      <title>configuration help-vwire subinterfaces with different policies per vlans</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/configuration-help-vwire-subinterfaces-with-different-policies/m-p/3104#M2319</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Hi all,&lt;/P&gt;&lt;P&gt;Its my first post here so I hope someone can answer my question regarding vwire subinterfaces.&lt;/P&gt;&lt;P&gt;As I was looking through the older topics the thing I want to achieve is similar to this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" class="active_link" href="https://live.paloaltonetworks.com/message/9679#9679" title="https://live.paloaltonetworks.com/message/9679#9679"&gt;https://live.paloaltonetworks.com/message/9679#9679&lt;/A&gt;&lt;/P&gt;&lt;P&gt;however I want to use vwire subinterfaces instead of L2.&lt;/P&gt;&lt;P&gt;According to course material it can be done.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Basicly I want to create differnet policies between different zones with vwire subinterface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;switch (trunk - allowed vlans 123,812) -------------- PAN (vwire LAN) ------------- (trunk) cisco ASA&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have 4 zones&lt;/P&gt;&lt;P&gt;Trust-LAN&lt;/P&gt;&lt;P&gt;Trust-NAVIS&lt;/P&gt;&lt;P&gt;Untrust-LAN&lt;/P&gt;&lt;P&gt;Untrust-NAVIS&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="6258" alt="ScreenShot001.bmp" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/6258_ScreenShot001.bmp" width="450" /&gt;&lt;/P&gt;&lt;P&gt;with this configuration traffic can't pass the PAN (with "none" set as security zone on physical interface)&lt;/P&gt;&lt;P&gt;traffic flows only if the main interfaces has a security zone assigned to it, but then all traffic is considered to be from this zone.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="6259" alt="ScreenShot002.bmp" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/6259_ScreenShot002.bmp" width="450" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can I differentiate vwire subinterfaces or not ( I mean zones on subinterfaces)?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thx for help&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 15 Apr 2013 12:28:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/configuration-help-vwire-subinterfaces-with-different-policies/m-p/3104#M2319</guid>
      <dc:creator>pkonitz</dc:creator>
      <dc:date>2013-04-15T12:28:45Z</dc:date>
    </item>
    <item>
      <title>Re: configuration help-vwire subinterfaces with different policies per vlans</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/configuration-help-vwire-subinterfaces-with-different-policies/m-p/3105#M2320</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Not sure (have not tested yet) but it looks like you did not do a VLAN/vwire config for your subinterfaces?&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Seweryn&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Apr 2013 07:55:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/configuration-help-vwire-subinterfaces-with-different-policies/m-p/3105#M2320</guid>
      <dc:creator>sjodlowski</dc:creator>
      <dc:date>2013-04-17T07:55:09Z</dc:date>
    </item>
    <item>
      <title>Re: configuration help-vwire subinterfaces with different policies per vlans</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/configuration-help-vwire-subinterfaces-with-different-policies/m-p/3106#M2321</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Seweryn,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What do u mean by not configuring a Vlan/vwire on subinterfaces?&lt;/P&gt;&lt;P&gt;As it is written in coursebook subinterfaces inherits vlan/vwire config from main interface. I can set it on the main interface but after that there is no choice for subinterface to have the same vwire assigment (casue this vwire was already used)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;from the book:&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;
&lt;P&gt;Note that you do not specify the virtual wire object during the creation of the subinteface. Since the subinterface is built on an existing virtual wire interface, the virtual wire object is inherited from parent interface. However, the subinterface and parent interface can be configured on different zones&lt;/P&gt;
&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have vwire crated (its called LAN)&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="6288" alt="ScreenShot008.bmp" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/6288_ScreenShot008.bmp" width="450" /&gt;&lt;/P&gt;&lt;P&gt;have ethernet 1/1 assigned to LAN.&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="6289" alt="ScreenShot010.bmp" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/6289_ScreenShot010.bmp" width="450" /&gt;&lt;/P&gt;&lt;P&gt;then have no option for subinterface.&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="6290" alt="ScreenShot009.bmp" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/6290_ScreenShot009.bmp" width="450" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But i think this in not the problem. The main issue is that even though I've got different security zones assigned to subinterfaces the traffic flows only when main interfaces is assigned to it as well. As a consequence subinterfaces inherits it from main interface (the proof is in logs) so I cant diferentiate traffic based on ZONES.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Message was edited by: Przemyslaw Konitz&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Apr 2013 08:12:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/configuration-help-vwire-subinterfaces-with-different-policies/m-p/3106#M2321</guid>
      <dc:creator>pkonitz</dc:creator>
      <dc:date>2013-04-17T08:12:23Z</dc:date>
    </item>
    <item>
      <title>Re: configuration help-vwire subinterfaces with different policies per vlans</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/configuration-help-vwire-subinterfaces-with-different-policies/m-p/3107#M2322</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Przemek,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please click on New Virtual Wire and create one for this subinterface. I did it for my PA-200 but can't test if it works as expected.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Seweryn&lt;/P&gt;&lt;P&gt;&lt;IMG alt="2013-04-17 10.23.40 am.png" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/6297_2013-04-17 10.23.40 am.png" width="450" /&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="2013-04-17 10.23.17 am.png" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/6298_2013-04-17 10.23.17 am.png" width="450" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Apr 2013 08:30:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/configuration-help-vwire-subinterfaces-with-different-policies/m-p/3107#M2322</guid>
      <dc:creator>sjodlowski</dc:creator>
      <dc:date>2013-04-17T08:30:09Z</dc:date>
    </item>
    <item>
      <title>Re: configuration help-vwire subinterfaces with different policies per vlans</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/configuration-help-vwire-subinterfaces-with-different-policies/m-p/3108#M2323</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;great - it worked &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;P&gt;after modifications&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="ScreenShot011.bmp" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/6299_ScreenShot011.bmp" width="450" /&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="ScreenShot012.bmp" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/6300_ScreenShot012.bmp" width="450" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;so this is not true what the book says&amp;nbsp; &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote" modifiedtitle="true"&gt;
&lt;P&gt;Note that you do not specify the virtual wire object during the creation of the subinteface. Since the subinterface is built on an existing virtual wire interface, the virtual wire object is inherited from parent interface. However, the subinterface and parent interface can be configured on different zones&lt;/P&gt;
&lt;P&gt;...&lt;/P&gt;
&lt;P&gt;The subinterfaces allow you to separate and classify traffic into different zones by either VLAN tags or VLAN tags in conjunction with IP classifiers (address, range, or subnet.)&lt;/P&gt;
&lt;P&gt;...&lt;/P&gt;
&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;the main interface must be on separate vwire object and each one of the subinterfaces as well.&lt;/LI&gt;&lt;LI&gt;No vlan tagging on Vwire !!! only on subinterfaces&lt;/LI&gt;&lt;LI&gt;only then subinterfaces are seen as being on separeted zones&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="ScreenShot013.bmp" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/6301_ScreenShot013.bmp" width="450" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thx Seweryn&lt;/P&gt;&lt;P&gt;hope to be in touch&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;Przemek&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Apr 2013 09:19:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/configuration-help-vwire-subinterfaces-with-different-policies/m-p/3108#M2323</guid>
      <dc:creator>pkonitz</dc:creator>
      <dc:date>2013-04-17T09:19:09Z</dc:date>
    </item>
  </channel>
</rss>

