<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic VWire configuration testing in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/vwire-configuration-testing/m-p/41542#M30542</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;At a recent PA training, the instructor mentioned a testing method for testing the configuration of VWire objects and the traffic flow, as configured in your Security Policy.&amp;nbsp; The goal of this method is the ability to do testing in a lab environment vs. testing your traffic flow after you've put the device into production.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With your device in a lab environment and the VWire objects and interfaces configured, you connect ethernet to two ports you're testing.&amp;nbsp; To that you connect two switches and one laptop to either swtich (two laptops total).&amp;nbsp; You then set each laptop's gateway to the other laptop and see if you can connect.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;By reaching the laptop over the other port, you're able to determine that your security policy between those two zones is configured as needed.&amp;nbsp; And you repeat this for your other ports/zones to test inter-zone traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is anyone able to confirm this method or offer a suggestion on testing VWires object / zone / Security Policy configurations prior to deploying the PA into production?&amp;nbsp; Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 02 Aug 2013 16:39:04 GMT</pubDate>
    <dc:creator>Mic</dc:creator>
    <dc:date>2013-08-02T16:39:04Z</dc:date>
    <item>
      <title>VWire configuration testing</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vwire-configuration-testing/m-p/41542#M30542</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;At a recent PA training, the instructor mentioned a testing method for testing the configuration of VWire objects and the traffic flow, as configured in your Security Policy.&amp;nbsp; The goal of this method is the ability to do testing in a lab environment vs. testing your traffic flow after you've put the device into production.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With your device in a lab environment and the VWire objects and interfaces configured, you connect ethernet to two ports you're testing.&amp;nbsp; To that you connect two switches and one laptop to either swtich (two laptops total).&amp;nbsp; You then set each laptop's gateway to the other laptop and see if you can connect.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;By reaching the laptop over the other port, you're able to determine that your security policy between those two zones is configured as needed.&amp;nbsp; And you repeat this for your other ports/zones to test inter-zone traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is anyone able to confirm this method or offer a suggestion on testing VWires object / zone / Security Policy configurations prior to deploying the PA into production?&amp;nbsp; Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Aug 2013 16:39:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vwire-configuration-testing/m-p/41542#M30542</guid>
      <dc:creator>Mic</dc:creator>
      <dc:date>2013-08-02T16:39:04Z</dc:date>
    </item>
    <item>
      <title>Re: VWire configuration testing</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vwire-configuration-testing/m-p/41543#M30543</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thats an easy test to begin with. But you will only be able to test minimal traffic between the 2 laptops. The real load test would be when you pass pre-production traffic, with the PANFW, inline with the netwok ( before you replace your existing firewall with the PANFW ), without disturbing your existing layer 3 setup.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;------------ internal networl---------- inside vwire inter-------------PANW----------outside vwire interface -------------router/firewall---------internet cloud&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The PANFW will act as an IPS, process the traffic, matching for the applications and looking for threats.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;BR,&lt;/P&gt;&lt;P&gt;karthik &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Aug 2013 17:25:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vwire-configuration-testing/m-p/41543#M30543</guid>
      <dc:creator>kprakash</dc:creator>
      <dc:date>2013-08-02T17:25:47Z</dc:date>
    </item>
    <item>
      <title>Re: VWire configuration testing</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vwire-configuration-testing/m-p/41544#M30544</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Right, it's a very basic initial test with the goal being sure that your Security Policy allows all your inter-zone traffic.&amp;nbsp; I'm hoping to get details from others that have tested VWire configurations in a lab environment, without having to generate traffic from different networks to test the Source&amp;lt;-&amp;gt;Destination allows in the Security Policy.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Aug 2013 17:32:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vwire-configuration-testing/m-p/41544#M30544</guid>
      <dc:creator>Mic</dc:creator>
      <dc:date>2013-08-02T17:32:42Z</dc:date>
    </item>
  </channel>
</rss>

