<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic DMZ network configuration in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/dmz-network-configuration/m-p/40400#M29656</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We have installed PAN-2050 in my customer site.&lt;/P&gt;&lt;P&gt;It has been deployed with two L2 interface as vmwire.&lt;/P&gt;&lt;P&gt;And we made one L3 vlan interface for secondary IP.&lt;/P&gt;&lt;P&gt;There are 2 IP subnets. (192.168.10.0/24, 192.168.1.0/24)&lt;/P&gt;&lt;P&gt;One(192.168.10.0/24) is for user.&lt;/P&gt;&lt;P&gt;The other(192.168.1.0/24) is for DMZ server.&lt;/P&gt;&lt;P&gt;Both IP subnet set gateway as PAN L3 vlan interface.&lt;/P&gt;&lt;P&gt;And one VR is in PAN-2050 for its gateway.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;User subnet which uses NAT policy can use internet and intranet service as well.&lt;/P&gt;&lt;P&gt;Problem is DMZ server couldn't use their service.&lt;/P&gt;&lt;P&gt;There are no security policy.&lt;/P&gt;&lt;P&gt;Maybe my configuration is wrong.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please let me know what should I add any other configuration.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 16 Apr 2012 05:59:36 GMT</pubDate>
    <dc:creator>sjlee</dc:creator>
    <dc:date>2012-04-16T05:59:36Z</dc:date>
    <item>
      <title>DMZ network configuration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dmz-network-configuration/m-p/40400#M29656</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We have installed PAN-2050 in my customer site.&lt;/P&gt;&lt;P&gt;It has been deployed with two L2 interface as vmwire.&lt;/P&gt;&lt;P&gt;And we made one L3 vlan interface for secondary IP.&lt;/P&gt;&lt;P&gt;There are 2 IP subnets. (192.168.10.0/24, 192.168.1.0/24)&lt;/P&gt;&lt;P&gt;One(192.168.10.0/24) is for user.&lt;/P&gt;&lt;P&gt;The other(192.168.1.0/24) is for DMZ server.&lt;/P&gt;&lt;P&gt;Both IP subnet set gateway as PAN L3 vlan interface.&lt;/P&gt;&lt;P&gt;And one VR is in PAN-2050 for its gateway.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;User subnet which uses NAT policy can use internet and intranet service as well.&lt;/P&gt;&lt;P&gt;Problem is DMZ server couldn't use their service.&lt;/P&gt;&lt;P&gt;There are no security policy.&lt;/P&gt;&lt;P&gt;Maybe my configuration is wrong.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please let me know what should I add any other configuration.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Apr 2012 05:59:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dmz-network-configuration/m-p/40400#M29656</guid>
      <dc:creator>sjlee</dc:creator>
      <dc:date>2012-04-16T05:59:36Z</dc:date>
    </item>
    <item>
      <title>Re: DMZ network configuration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dmz-network-configuration/m-p/40401#M29657</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can the servers reach the users? or is the problem just the servers not getting access to the Internet?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Apr 2012 18:48:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dmz-network-configuration/m-p/40401#M29657</guid>
      <dc:creator>rmonvon</dc:creator>
      <dc:date>2012-04-16T18:48:27Z</dc:date>
    </item>
    <item>
      <title>Re: DMZ network configuration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dmz-network-configuration/m-p/40402#M29658</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;yes, server and users can communicat each other. &lt;/P&gt;&lt;P&gt;Server has a problem to access to internet. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Apr 2012 00:22:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dmz-network-configuration/m-p/40402#M29658</guid>
      <dc:creator>sjlee</dc:creator>
      <dc:date>2012-04-17T00:22:13Z</dc:date>
    </item>
    <item>
      <title>Re: DMZ network configuration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dmz-network-configuration/m-p/40403#M29659</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You should check your NAT rule to ensure the DMZ zone/address is included. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, you mentioned there is no security policy.&amp;nbsp; The implicit deny all rule will block all traffic that does not match a security rule.&amp;nbsp; You should have a security rule to allow traffic from DMZ to Internet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Apr 2012 04:23:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dmz-network-configuration/m-p/40403#M29659</guid>
      <dc:creator>rmonvon</dc:creator>
      <dc:date>2012-04-17T04:23:04Z</dc:date>
    </item>
    <item>
      <title>Re: DMZ network configuration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dmz-network-configuration/m-p/40404#M29660</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The issue has been solved with no tcp-reject-non-syn option.&lt;/P&gt;&lt;P&gt;PA looked it as asymetric routing because syn is L3 flow and syn/ack is L2 flow.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Apr 2012 04:50:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dmz-network-configuration/m-p/40404#M29660</guid>
      <dc:creator>sjlee</dc:creator>
      <dc:date>2012-04-17T04:50:35Z</dc:date>
    </item>
    <item>
      <title>Re: DMZ network configuration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dmz-network-configuration/m-p/40405#M29661</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;glad to hear it. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If this PA device is the only firewall in used, I recommend that you re-enable the 'tcp-reject-non-syn' as soon as possible and not leave it off for long.&amp;nbsp; You should re-design the network to separate the user and DMZ zones into its own L3 zone, and remove the L2.&amp;nbsp; This will permit you to enforce 'tcp-reject-non-syn' for security reason.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Apr 2012 14:06:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dmz-network-configuration/m-p/40405#M29661</guid>
      <dc:creator>rmonvon</dc:creator>
      <dc:date>2012-04-17T14:06:37Z</dc:date>
    </item>
  </channel>
</rss>

