<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: one leg setup clarification .. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/one-leg-setup-clarification/m-p/33972#M24911</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;if we can do in vwire it would be great , but can you explain more please..&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 13 Jun 2012 11:13:32 GMT</pubDate>
    <dc:creator>LCMember4717</dc:creator>
    <dc:date>2012-06-13T11:13:32Z</dc:date>
    <item>
      <title>one leg setup clarification ..</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/one-leg-setup-clarification/m-p/33970#M24909</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i need to setup two PA-2050 ( HA mode ) but am not sure about the design were i need some help her, the customer network is devided into vlans and they all communicato to each other through the corre switch ( cisco 6500) and if they require internet access the core switch will route them to a firewall ( firewall module in the core sw ) , now obviously i cant setup the appliances in vwire mode since there are no physical cables ( all virtual links and vlan ) so i was thinking to make a defult route on the customer switch to redirect internet traffic to the PA device then it routes back to the core sw , not wccp as i know they call this one leg setup am just wondering if it can achieved by the PA appliance .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;am attaching a diagram of what am looking for .&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Dasman_setup.jpg" class="jive-image-thumbnail jive-image" onclick="" src="https://live.paloaltonetworks.com/legacyfs/online/3065_Dasman_setup.jpg" width="450" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Jun 2012 15:23:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/one-leg-setup-clarification/m-p/33970#M24909</guid>
      <dc:creator>LCMember4717</dc:creator>
      <dc:date>2012-06-12T15:23:23Z</dc:date>
    </item>
    <item>
      <title>Re: one leg setup clarification ..</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/one-leg-setup-clarification/m-p/33971#M24910</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi...To do the one arm routing, we would have to redirect traffic from the VLANs to the PA device before it reaches the fw module.&amp;nbsp; We then have to NAT at the PA device to ensure the return packets come back to the PA device, or redirect the inbound traffic at the sw as well.&amp;nbsp; Otherwise the fw module would forward the replies to the users and bypass the PA device.&amp;nbsp; We need to maintain session state on the PA device.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Another option is to do L2 bridging and configure the PA device in vwire mode.&amp;nbsp; Put the fw module on a standalone vlan and aggregate the user vlans onto a 2nd standalone vlan.&amp;nbsp; Use the vwire to bridge the two standalone vlans.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Jun 2012 16:48:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/one-leg-setup-clarification/m-p/33971#M24910</guid>
      <dc:creator>rmonvon</dc:creator>
      <dc:date>2012-06-12T16:48:17Z</dc:date>
    </item>
    <item>
      <title>Re: one leg setup clarification ..</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/one-leg-setup-clarification/m-p/33972#M24911</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;if we can do in vwire it would be great , but can you explain more please..&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Jun 2012 11:13:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/one-leg-setup-clarification/m-p/33972#M24911</guid>
      <dc:creator>LCMember4717</dc:creator>
      <dc:date>2012-06-13T11:13:32Z</dc:date>
    </item>
    <item>
      <title>Re: one leg setup clarification ..</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/one-leg-setup-clarification/m-p/33973#M24912</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;For the vwire option, we would need to use a vlan bridge as shown in the attached diagram.&amp;nbsp; We need to create 2 isolated vlans and they are depicted as untrust and trust vlans.The vwire would act as a bridge and traffic would flow through the PAN device.&amp;nbsp; Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Jun 2012 13:27:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/one-leg-setup-clarification/m-p/33973#M24912</guid>
      <dc:creator>rmonvon</dc:creator>
      <dc:date>2012-06-13T13:27:40Z</dc:date>
    </item>
    <item>
      <title>Re: one leg setup clarification ..</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/one-leg-setup-clarification/m-p/33974#M24913</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;AM testing the one arm routing do I need to have PBF to instruct the traffic to leave from the same interface again because it's reaching the PA but it drops then .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 17 Jun 2012 21:22:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/one-leg-setup-clarification/m-p/33974#M24913</guid>
      <dc:creator>LCMember4717</dc:creator>
      <dc:date>2012-06-17T21:22:36Z</dc:date>
    </item>
  </channel>
</rss>

