<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: L3 vlans and devices/systems that don't support vlanning issue. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/l3-vlans-and-devices-systems-that-don-t-support-vlanning-issue/m-p/39300#M28834</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If the switch interface supports both tagged and untagged on the same interface you should be able to have both tagged and untagged traffic on the PA connected to this interface if I fully understand your question &lt;span class="lia-unicode-emoji" title=":grinning_face_with_big_eyes:"&gt;😃&lt;/span&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 16 Oct 2012 03:18:36 GMT</pubDate>
    <dc:creator>mikand</dc:creator>
    <dc:date>2012-10-16T03:18:36Z</dc:date>
    <item>
      <title>L3 vlans and devices/systems that don't support vlanning issue.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/l3-vlans-and-devices-systems-that-don-t-support-vlanning-issue/m-p/39299#M28833</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello all,&lt;/P&gt;&lt;P&gt;I've recently setup our PAN-2020's with L3 sub-interfaces presenting VLANS to our core switches (per this discussion: &lt;A __default_attr="5866" __jive_macro_name="thread" class="jive_macro jive_macro_thread" href="https://live.paloaltonetworks.com/"&gt;&lt;/A&gt; ). However, I've run into a problem that I can't manage or connect to devices, like our SAN, KVM, and even the PAN Firewall (management port) because they are on the same switch and use the default vlan of the switch. If I define an available L3 port as a management network, and leave it untagged, it creates headaches and breaks the L3 vlanning.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My question is, can I create a L3 interface with a network and untagged, attach it to another VR and route management traffic to that VR, and then present that interface to the switch with the untagged network.&amp;nbsp; I don't think that should cause any issues, but wondered if anyone's had experience with this, or ran into similar issues? I've also found this discussion, but they've not complete given me any insight into if this is possible or not:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A __default_attr="2781" __jive_macro_name="document" class="jive_macro jive_macro_document" href="https://live.paloaltonetworks.com/"&gt;&lt;/A&gt; - can I define an untagged L3 sub-interface on top of the main untagged interface with a network without causing issues?&amp;nbsp; This would be a lot better of a solution then having to setup another VR. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for any help you can give. &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Oct 2012 19:58:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/l3-vlans-and-devices-systems-that-don-t-support-vlanning-issue/m-p/39299#M28833</guid>
      <dc:creator>cmateam</dc:creator>
      <dc:date>2012-10-11T19:58:49Z</dc:date>
    </item>
    <item>
      <title>Re: L3 vlans and devices/systems that don't support vlanning issue.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/l3-vlans-and-devices-systems-that-don-t-support-vlanning-issue/m-p/39300#M28834</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If the switch interface supports both tagged and untagged on the same interface you should be able to have both tagged and untagged traffic on the PA connected to this interface if I fully understand your question &lt;span class="lia-unicode-emoji" title=":grinning_face_with_big_eyes:"&gt;😃&lt;/span&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Oct 2012 03:18:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/l3-vlans-and-devices-systems-that-don-t-support-vlanning-issue/m-p/39300#M28834</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-10-16T03:18:36Z</dc:date>
    </item>
    <item>
      <title>Re: L3 vlans and devices/systems that don't support vlanning issue.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/l3-vlans-and-devices-systems-that-don-t-support-vlanning-issue/m-p/39301#M28835</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I guess my question is... in L3 vlanning, since the physical port is untagged with no defined network, and L3 sub interfaces are added with defined networks, can I define a subinterface untagged with a network without any problems?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 19 Oct 2012 19:48:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/l3-vlans-and-devices-systems-that-don-t-support-vlanning-issue/m-p/39301#M28835</guid>
      <dc:creator>cmateam</dc:creator>
      <dc:date>2012-10-19T19:48:15Z</dc:date>
    </item>
  </channel>
</rss>

