<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Multiple Virtual Routers sharing the same INSIDE zone? Possible? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/multiple-virtual-routers-sharing-the-same-inside-zone-possible/m-p/4425#M3281</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;jsherlow wrote:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hi There,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is possible:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;An interface cannot be in two virtual routers - however, you can have sub-interfaces in different virtual routers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So you can put a physical/logical interface from the new virtual router into the LAN and have routes to that IP for the new DMZ.&amp;nbsp; This interface would be on the same subnet, but different IP, to the other interface already in this LAN.&lt;/P&gt;&lt;P&gt;Alternatively, you can move to PAN-OS 4.0.x and make use of one of two features:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;virtual router to virtual router routing&lt;/LI&gt;&lt;LI&gt;PBF to virtual system and have the "New Network" in a new virtual system.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;James&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;James.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for that - I can manage to put another IP on the "inside" interface without too much hassle - since I don't think I'm quite ready to upgrade to PanOS 4 yet, I'll most likely run with that.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 28 Feb 2011 21:04:17 GMT</pubDate>
    <dc:creator>dagibbs</dc:creator>
    <dc:date>2011-02-28T21:04:17Z</dc:date>
    <item>
      <title>Multiple Virtual Routers sharing the same INSIDE zone? Possible?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/multiple-virtual-routers-sharing-the-same-inside-zone-possible/m-p/4423#M3279</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have my PA's running fine and dandy with my normal internet link(s) and DMZ farmed out to my edge routers without issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now I have coming a requirement for a dedicated, seperate Internet link and DMZ for a special purpose with the traffic being completely isolated from my "main' links.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I want to assign two new interfaces - one for the extra DMZ required, and one for the additional Internet link - and use a different VR to link these two interfaces, with the default route for this pair or ports point to the 'new" internet link rather than my normal "default" route - however, I also want machines from my normal "inside" interface to be able to access devices in this DMZ.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can I put the "normal" inside interface into the new VR and allow communciation between the inside and the new DMZ/Link without affecting the standard default route out my 'main" links?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Configuration something like this&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;VR Name : Router 1&lt;/P&gt;&lt;P&gt;Interfaces : Ethernet1/1 (inside)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Ethernet1/2 (outside - default route)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Ethernet1/3 (Main DMZ)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;VR Name : Router-2&lt;/P&gt;&lt;P&gt;Interfaces : Ethernet1/1 (inside)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Ethernet1/4 (New-Internet, special-purpose route)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Ethernet1/5 (Special DMZ)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't want traffic from E1/2 mixing with E1/4 9I.E. all "Internet" bound traffic from E1/1 and E1/3 should default out this route), but I do to be able to get to nodes in both both E1/3 &amp;amp; E1/5 from the inside (E1/1) inetrface, and I want ALL internet traffic froM E1/5 to go out E1/4 instead of E1/2.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this is clear enough explaination - I think I just confused myself!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Feb 2011 04:09:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/multiple-virtual-routers-sharing-the-same-inside-zone-possible/m-p/4423#M3279</guid>
      <dc:creator>dagibbs</dc:creator>
      <dc:date>2011-02-28T04:09:56Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Virtual Routers sharing the same INSIDE zone? Possible?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/multiple-virtual-routers-sharing-the-same-inside-zone-possible/m-p/4424#M3280</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi There,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is possible:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;An interface cannot be in two virtual routers - however, you can have sub-interfaces in different virtual routers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So you can put a physical/logical interface from the new virtual router into the LAN and have routes to that IP for the new DMZ.&amp;nbsp; This interface would be on the same subnet, but different IP, to the other interface already in this LAN.&lt;/P&gt;&lt;P&gt;Alternatively, you can move to PAN-OS 4.0.x and make use of one of two features:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;virtual router to virtual router routing&lt;/LI&gt;&lt;LI&gt;PBF to virtual system and have the "New Network" in a new virtual system.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;James&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Feb 2011 17:11:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/multiple-virtual-routers-sharing-the-same-inside-zone-possible/m-p/4424#M3280</guid>
      <dc:creator>James</dc:creator>
      <dc:date>2011-02-28T17:11:02Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Virtual Routers sharing the same INSIDE zone? Possible?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/multiple-virtual-routers-sharing-the-same-inside-zone-possible/m-p/4425#M3281</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;jsherlow wrote:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hi There,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is possible:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;An interface cannot be in two virtual routers - however, you can have sub-interfaces in different virtual routers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So you can put a physical/logical interface from the new virtual router into the LAN and have routes to that IP for the new DMZ.&amp;nbsp; This interface would be on the same subnet, but different IP, to the other interface already in this LAN.&lt;/P&gt;&lt;P&gt;Alternatively, you can move to PAN-OS 4.0.x and make use of one of two features:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;virtual router to virtual router routing&lt;/LI&gt;&lt;LI&gt;PBF to virtual system and have the "New Network" in a new virtual system.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;James&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;James.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for that - I can manage to put another IP on the "inside" interface without too much hassle - since I don't think I'm quite ready to upgrade to PanOS 4 yet, I'll most likely run with that.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Feb 2011 21:04:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/multiple-virtual-routers-sharing-the-same-inside-zone-possible/m-p/4425#M3281</guid>
      <dc:creator>dagibbs</dc:creator>
      <dc:date>2011-02-28T21:04:17Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Virtual Routers sharing the same INSIDE zone? Possible?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/multiple-virtual-routers-sharing-the-same-inside-zone-possible/m-p/4426#M3282</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Good Luck &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Feb 2011 22:57:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/multiple-virtual-routers-sharing-the-same-inside-zone-possible/m-p/4426#M3282</guid>
      <dc:creator>James</dc:creator>
      <dc:date>2011-02-28T22:57:33Z</dc:date>
    </item>
  </channel>
</rss>

