<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Layer 2 vs. Layer 3 Deployment in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/layer-2-vs-layer-3-deployment/m-p/38452#M28175</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Steven!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for your answer. Of course, vwire does support Q-tags, but I think, is does only support trunks. In my environment, VLAN A is "Layer 2 outside" and VLAN B is "Layer 2 inside". So my Layer 2 deployment does link two different VLANs of my switches.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It seems to me, Layer 2 deployments with PA are not very popular.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phil&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 07 Jul 2014 11:58:43 GMT</pubDate>
    <dc:creator>PStricker</dc:creator>
    <dc:date>2014-07-07T11:58:43Z</dc:date>
    <item>
      <title>Layer 2 vs. Layer 3 Deployment</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/layer-2-vs-layer-3-deployment/m-p/38450#M28173</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;At the moment, I hover between a Layer 2 and Layer 3 Deployment of my PA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My setup is:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |&amp;nbsp;&amp;nbsp;&amp;nbsp; | &lt;/P&gt;&lt;P&gt;Internet &amp;lt;-&amp;gt; IPSEC-router &amp;lt;-&amp;gt; DMZ &amp;lt;-&amp;gt; internal firewall&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |&amp;nbsp;&amp;nbsp;&amp;nbsp; | &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My IPSec-router-cluster and the internal firewall need to persist. The internal firewall does route and filter between 23 VLANs/networks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the first step, I took my PA-3020 cluster as Layer2-Firwall behind the IPSec-router (Layer 2 instead of VirtualWire to be able to use a Vlan-Trunk), but I do sometimes see high latency and I do not really know why.&lt;/P&gt;&lt;P&gt;Do you think this is a good idea, or should I add a transfer network segment and user Layer 3?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My thoughts:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Layer 2:&lt;/P&gt;&lt;P&gt;pro&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; easy deployment&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; no change to any device&lt;/P&gt;&lt;P&gt;cons&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; sometimes slow and no idea, why&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; switches see one mac on two VLANs&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Layer 3:&lt;/P&gt;&lt;P&gt;pro:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; easy debugging&lt;/P&gt;&lt;P&gt;cons:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; need to add transfer network&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; change of configuration for DMZ-network&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; need to maintain routing-table of one additional device&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Of course, If I need "Layer 3 features", I can assign another interface of the PA as Layer 3, but is this a good idea, or would a "clean" "just Layer3-setup" be more "future-proof"?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for your hints&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Phil&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Jul 2014 11:27:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/layer-2-vs-layer-3-deployment/m-p/38450#M28173</guid>
      <dc:creator>PStricker</dc:creator>
      <dc:date>2014-07-07T11:27:33Z</dc:date>
    </item>
    <item>
      <title>Re: Layer 2 vs. Layer 3 Deployment</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/layer-2-vs-layer-3-deployment/m-p/38451#M28174</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote" modifiedtitle="true"&gt;
&lt;P&gt;PStricker wrote:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;(Layer 2 instead of VirtualWire to be able to use a Vlan-Trunk),&lt;/P&gt;
&lt;/PRE&gt;&lt;P&gt;You can do Q tags on V-wire in PanOS 5 (think it was introduced in 5.0.4)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think you have the lay of the land for the differences.&amp;nbsp; I'll just add another option to complicate things for you.&amp;nbsp; You could deploy using vsys and have some layer three segments and treat others are v-wire and layer 2.&amp;nbsp;&amp;nbsp; This could potentially give you the best of both worlds.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't see any performance impact on the v-wire deploys we manage.&amp;nbsp; But I'm not running layer 2 in production to compare.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Jul 2014 11:37:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/layer-2-vs-layer-3-deployment/m-p/38451#M28174</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2014-07-07T11:37:18Z</dc:date>
    </item>
    <item>
      <title>Re: Layer 2 vs. Layer 3 Deployment</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/layer-2-vs-layer-3-deployment/m-p/38452#M28175</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Steven!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for your answer. Of course, vwire does support Q-tags, but I think, is does only support trunks. In my environment, VLAN A is "Layer 2 outside" and VLAN B is "Layer 2 inside". So my Layer 2 deployment does link two different VLANs of my switches.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It seems to me, Layer 2 deployments with PA are not very popular.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phil&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Jul 2014 11:58:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/layer-2-vs-layer-3-deployment/m-p/38452#M28175</guid>
      <dc:creator>PStricker</dc:creator>
      <dc:date>2014-07-07T11:58:43Z</dc:date>
    </item>
    <item>
      <title>Re: Layer 2 vs. Layer 3 Deployment</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/layer-2-vs-layer-3-deployment/m-p/38453#M28176</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In your situation I would use a layer 3 deploy. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I also have not seen any pure layer 2 deploys.&amp;nbsp; It seems that v-wire is the way to go with a true layer 2 insertion.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Jul 2014 21:57:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/layer-2-vs-layer-3-deployment/m-p/38453#M28176</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2014-07-07T21:57:13Z</dc:date>
    </item>
  </channel>
</rss>

