<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Creating Zones (Sub-Zones) on PA-500 in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/creating-zones-sub-zones-on-pa-500/m-p/47104#M34628</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You will need a 2.5: Connect zone to (physical or logical) interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And personally I would apply a protection profile even for the wireless users &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 09 Feb 2012 08:29:30 GMT</pubDate>
    <dc:creator>mikand</dc:creator>
    <dc:date>2012-02-09T08:29:30Z</dc:date>
    <item>
      <title>Creating Zones (Sub-Zones) on PA-500</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/creating-zones-sub-zones-on-pa-500/m-p/47098#M34622</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This question might sound very stupid, but never mind:&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a PA-500 configured which does a specific job which does layer 3 and that requires creating a lot of zones in-order to differentiate the traffic ( as per my understanding, zones are defined for differentiating between traffic.&amp;nbsp; If my thinking is wrong, please correct me).&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Since the PA-500 can only have 20 zones and I already have 18 zones configured ( i would need more than this over the year), I was just wondering if there was any way in increasing this number by creating sub-zones (like creating sub-interfaces).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Or any sorts of work around....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 Feb 2012 16:31:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/creating-zones-sub-zones-on-pa-500/m-p/47098#M34622</guid>
      <dc:creator>kalyanram.piratla</dc:creator>
      <dc:date>2012-02-06T16:31:59Z</dc:date>
    </item>
    <item>
      <title>Re: Creating Zones (Sub-Zones) on PA-500</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/creating-zones-sub-zones-on-pa-500/m-p/47099#M34623</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi...Zones are used to define your network boundary and not necessary to differentiate traffic.&amp;nbsp; For example, separating users from server farm, inside vs outside vs dmz.&amp;nbsp; For multiple vlans where each vlan is an IP subnet for users, you can put all vlans on the same zone because they all are users.&amp;nbsp; Same goes for servers.&amp;nbsp;&amp;nbsp; You may have some smtp servers, dns servers, &amp;amp; file servers and you can group them together under 1 zone.&amp;nbsp; Then you define security policies to control traffic between your users and your servers.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 Feb 2012 17:14:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/creating-zones-sub-zones-on-pa-500/m-p/47099#M34623</guid>
      <dc:creator>rmonvon</dc:creator>
      <dc:date>2012-02-06T17:14:42Z</dc:date>
    </item>
    <item>
      <title>Re: Creating Zones (Sub-Zones) on PA-500</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/creating-zones-sub-zones-on-pa-500/m-p/47100#M34624</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the reply.&amp;nbsp; It was useful, but the only problem I would face is, the zones for me define a customer's boundary or network.&amp;nbsp; It does not necessarily mean different VLANs for me as they are completely different networks and are external. It looks like:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Client -&amp;gt; A&lt;/P&gt;&lt;P&gt;Interface -&amp;gt; ethernet 1/6.1001&lt;/P&gt;&lt;P&gt;Source Zone -&amp;gt; Internal&lt;/P&gt;&lt;P&gt;Destination Zone -&amp;gt; A zone&lt;/P&gt;&lt;P&gt;IP Address -&amp;gt; 2.0.0.1/27&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Client -&amp;gt; B&lt;/P&gt;&lt;P&gt;Interface -&amp;gt; ethernet 1/6.1002&lt;/P&gt;&lt;P&gt;Source zone -&amp;gt; Internal&lt;/P&gt;&lt;P&gt;Destination Zone -&amp;gt; B Zone&lt;/P&gt;&lt;P&gt;IP Address -&amp;gt; 128.x.x.x/24&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Based on this, I will be creating zones for all the clients I register which would run in quite a few numbers.&amp;nbsp; I can only see replacing the PA with a router or a layer 3 switch do pass the traffic onto their networks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any Thoughts..??&lt;/P&gt;&lt;P&gt;Thanks..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Feb 2012 16:04:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/creating-zones-sub-zones-on-pa-500/m-p/47100#M34624</guid>
      <dc:creator>kalyanram.piratla</dc:creator>
      <dc:date>2012-02-07T16:04:05Z</dc:date>
    </item>
    <item>
      <title>Re: Creating Zones (Sub-Zones) on PA-500</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/creating-zones-sub-zones-on-pa-500/m-p/47101#M34625</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Why not create zone for 'clients', or more broadly lump them into 'untrust' depending on which network interface the clients are behind.&amp;nbsp; If the clients are all external off the internet then go with 'untrust'.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then create address book definitions per client in the appropriate zone (ex. 'clients' or 'untrust'):&lt;/P&gt;&lt;P&gt;client-a-net = 2.0.0.0/27&lt;/P&gt;&lt;P&gt;client-b-net = 128.x.x.x/24&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then in your security policy permit the desired traffic to the zone and destination as appropriate.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Seems like it would work.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Feb 2012 23:33:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/creating-zones-sub-zones-on-pa-500/m-p/47101#M34625</guid>
      <dc:creator>mtetzlaff</dc:creator>
      <dc:date>2012-02-07T23:33:48Z</dc:date>
    </item>
    <item>
      <title>Re: Creating Zones (Sub-Zones) on PA-500</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/creating-zones-sub-zones-on-pa-500/m-p/47102#M34626</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think thats the more common way of using zones.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The zone is just the description of the "interface" (no matter if the interface is physical such as EthernetX/Y or logical such as VLAN123). So instead of using "ethernet1.6/200" or "vlan123" you bring this interface a useful name such as "Internet".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Which gives that your security rules looks like&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;src zone: Internet&lt;/P&gt;&lt;P&gt;dst zone: DMZ-DNS&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;instead of&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;src interface: Ethernet1.6/200&lt;/P&gt;&lt;P&gt;dst interface: Ethernet1.3/104&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And then use address objects and address groups to further make your security rules easier to interpret when you are staring at them.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Like (already mentioned):&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;client-a-net = 2.0.0.0/27&lt;/P&gt;&lt;P&gt;client-b-net = 128.x.x.x/24&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;with group:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;client-internet = client-a-net, client-b-net&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And your security rule becomes:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;srczone: Internet&lt;/P&gt;&lt;P&gt;src ip: client-internet&lt;/P&gt;&lt;P&gt;src port: &amp;gt;1023&lt;/P&gt;&lt;P&gt;dstzone: DMZ-DNS&lt;/P&gt;&lt;P&gt;dst ip: dns-servers&lt;/P&gt;&lt;P&gt;dst port: specific (TCP53, UDP53)&lt;/P&gt;&lt;P&gt;appid: dns&lt;/P&gt;&lt;P&gt;profile: PROFILEGROUP_BLOCK&lt;/P&gt;&lt;P&gt;action: allow&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Feb 2012 23:55:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/creating-zones-sub-zones-on-pa-500/m-p/47102#M34626</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-02-07T23:55:33Z</dc:date>
    </item>
    <item>
      <title>Re: Creating Zones (Sub-Zones) on PA-500</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/creating-zones-sub-zones-on-pa-500/m-p/47103#M34627</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Many thanks for your thoughts Guys.&amp;nbsp; I will trying doing this in a couple of days time to add in a new customer.&amp;nbsp; Will get back to you guys on this..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So, this is how I would go around configuring it (EXAMPLE):&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1.&amp;nbsp; Source Zone:&amp;nbsp; Internal&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2.&amp;nbsp; Destination Zone:&amp;nbsp; External&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3.&amp;nbsp; Create Layer 3 Sub-Interface:&amp;nbsp; ethernet 1/6.1010 with an ip address 1.1.1.1&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;4.&amp;nbsp; Add an Address object:&amp;nbsp; 1.1.1.1 -&amp;gt; Client A&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;5.&amp;nbsp; Create a Security rule:&amp;nbsp; From Internal zone (Any source address) -&amp;gt; to External Zone with Destination Address of Client A (pulled from&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; address object) -&amp;gt; any application, any service, no profiles ( as it is basically allowing routing traffic from our Wireless Controller)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Feb 2012 10:13:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/creating-zones-sub-zones-on-pa-500/m-p/47103#M34627</guid>
      <dc:creator>kalyanram.piratla</dc:creator>
      <dc:date>2012-02-08T10:13:41Z</dc:date>
    </item>
    <item>
      <title>Re: Creating Zones (Sub-Zones) on PA-500</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/creating-zones-sub-zones-on-pa-500/m-p/47104#M34628</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You will need a 2.5: Connect zone to (physical or logical) interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And personally I would apply a protection profile even for the wireless users &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Feb 2012 08:29:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/creating-zones-sub-zones-on-pa-500/m-p/47104#M34628</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-02-09T08:29:30Z</dc:date>
    </item>
    <item>
      <title>Re: Creating Zones (Sub-Zones) on PA-500</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/creating-zones-sub-zones-on-pa-500/m-p/47105#M34629</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Oh yes, connecting the zone to physical or logical interface.&amp;nbsp; With respect to security profiles, we have another firewall doing filtering as this Palo Alto in question is doing content filtering on virtual wire mode for internal users and L3 routing.&amp;nbsp; &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Feb 2012 09:26:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/creating-zones-sub-zones-on-pa-500/m-p/47105#M34629</guid>
      <dc:creator>kalyanram.piratla</dc:creator>
      <dc:date>2012-02-09T09:26:34Z</dc:date>
    </item>
  </channel>
</rss>

