<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Intial Setup Help in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/intial-setup-help/m-p/48038#M35321</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It is confusing, because you could use untagged subinterfaces to achieve the same thing. So there's more than one way to do it, which presents confusion &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 19 Aug 2014 13:19:58 GMT</pubDate>
    <dc:creator>ericgearhart</dc:creator>
    <dc:date>2014-08-19T13:19:58Z</dc:date>
    <item>
      <title>Intial Setup Help</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/intial-setup-help/m-p/48023#M35306</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi everyone ... just bought a PA-200, and this is my first experience with this sort of device.&amp;nbsp; A little bit of a learning curve!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am moving from a Barracuda Link Balancer.&amp;nbsp; This is my setup.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have 5 public IP addresses, let's say for simplicity sake 173.61.106.10-14.&amp;nbsp; ISP gateway is 173.61.106.1.&amp;nbsp; We have FIOS and all 5 IPs come through 1 cable.&amp;nbsp; The cable goes into a switch.&amp;nbsp; One cable from the switch goes to the Barracuda.&amp;nbsp; The Barracuda manages IPs .10 .11 .12 on it's WAN port.&amp;nbsp; .13 goes to a Wifi device and .14 goes to our VOIP system.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We currently have traffic hitting all 3 public IPs on the Barracuda and being forwarded to our internal LAN.&amp;nbsp; I'd like to keep this as-is.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Couple of questions, because I've gotten conflicting info from the support people I have talked to thus far.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1.&amp;nbsp; Can you have multiple IP addresses on one interface, as I do above with the Barracuda?&amp;nbsp; If so, could I get some basic advise on how to set that up?&amp;nbsp; I've seen "use /32" and "use subinterface" and "you can't do that" on this discussion forum.&amp;nbsp; I'm hoping to get the final answer!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think if I get the basics of how that would work, that will get me to my next questions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 16 Aug 2014 04:04:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/intial-setup-help/m-p/48023#M35306</guid>
      <dc:creator>BRRABill</dc:creator>
      <dc:date>2014-08-16T04:04:03Z</dc:date>
    </item>
    <item>
      <title>Re: Intial Setup Help</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/intial-setup-help/m-p/48024#M35307</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The conflicting answers are because of the nuances of the possible situations.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can put multiple ip addresses on an interface but they cannot be in the same subnet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In your situation it just appears that the Barracuda works differently than the Palo Alto.&amp;nbsp; Instead of putting multiple same subnet ip addresses on an interface the Palo Alto and most other firewalls only put one.&amp;nbsp; You then use nat and proxy arp to forward those addresses down to the ultimate server destinations.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can start with this document to determine what type of nat is best for your scenario.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-1517"&gt;Understanding PAN-OS NAT&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 16 Aug 2014 12:06:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/intial-setup-help/m-p/48024#M35307</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2014-08-16T12:06:36Z</dc:date>
    </item>
    <item>
      <title>Re: Intial Setup Help</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/intial-setup-help/m-p/48025#M35308</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What I have done several times is put a single public ip on the physical interface, then I create a loopback interface which has all of the other /32 addresses. Then create your NAT policies. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You may be able to skip the loopback portion but I have better luck with doing it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 16 Aug 2014 13:14:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/intial-setup-help/m-p/48025#M35308</guid>
      <dc:creator>SDorsey</dc:creator>
      <dc:date>2014-08-16T13:14:14Z</dc:date>
    </item>
    <item>
      <title>Re: Intial Setup Help</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/intial-setup-help/m-p/48026#M35309</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Steve,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can have multiple IPs on an interface in the same subnet - but you don't seem to be able to do it from the GUI.&amp;nbsp; (At least in 5.x - I've not tried in 6.x)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the CLI; you can specify an additional IP (in the same subnet) on an interface as long as you do not specify any subnet mask.... (The GUI's validity checks ensures the slash of the subnet mask is specified - hence why you can't do this through the GUI.).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here's an example from a live box,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;set network interface ethernet ethernet1/1 layer3 units ethernet1/1.2 tag 2&lt;/P&gt;&lt;P&gt;set network interface ethernet ethernet1/1 layer3 units ethernet1/1.2 ip 10.20.1.254/18&lt;/P&gt;&lt;P&gt;set network interface ethernet ethernet1/1 layer3 units ethernet1/1.2 ip 10.20.1.1&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;set network interface ethernet ethernet1/1 layer3 units ethernet1/1.2 interface-management-profile PingAccess&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It took a bit of frantic searching to get this working once; when I moved a LAN to a PA to find half the hosts on the LAN were using .254 for their gateway and the other half using .1!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aid&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 16 Aug 2014 18:30:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/intial-setup-help/m-p/48026#M35309</guid>
      <dc:creator>ajbool</dc:creator>
      <dc:date>2014-08-16T18:30:30Z</dc:date>
    </item>
    <item>
      <title>Re: Intial Setup Help</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/intial-setup-help/m-p/48027#M35310</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yeah, you can skip the loopbacks as if an IP address is specified in a NAT rule that is in the same subnet as one of the interfaces of the firewall; the firewall will automatically "proxy arp" for this IP address on that LAN.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 16 Aug 2014 18:33:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/intial-setup-help/m-p/48027#M35310</guid>
      <dc:creator>ajbool</dc:creator>
      <dc:date>2014-08-16T18:33:06Z</dc:date>
    </item>
    <item>
      <title>Re: Intial Setup Help</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/intial-setup-help/m-p/48028#M35311</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can I use subinterfaces?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried reaching out to support, and he had me make a "blank" interface ethernet 1/1 and then a subinterface 1.1 1.2 and 1.3&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm also having an issue where I cannot get traffic back through my FIOS router because of an ARP issue.&amp;nbsp; I think I have that one figured out, though.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 16 Aug 2014 20:34:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/intial-setup-help/m-p/48028#M35311</guid>
      <dc:creator>BRRABill</dc:creator>
      <dc:date>2014-08-16T20:34:18Z</dc:date>
    </item>
    <item>
      <title>Re: Intial Setup Help</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/intial-setup-help/m-p/48029#M35312</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Another question ... can I accomplish this with NAT?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The .10 is going to my desktops, and the .12 is going to a mail server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My concern is down thee road when I need two things on port 80 (or whatever) that I cannot move.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 16 Aug 2014 20:35:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/intial-setup-help/m-p/48029#M35312</guid>
      <dc:creator>BRRABill</dc:creator>
      <dc:date>2014-08-16T20:35:31Z</dc:date>
    </item>
    <item>
      <title>Re: Intial Setup Help</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/intial-setup-help/m-p/48030#M35313</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sub-interfaces are what you use to connect the firewall to a switch trunk port with multiple vlans.&amp;nbsp; This is the PA support for 802.1Q standard trunking.&amp;nbsp; This would not be appropriate for your situation where all these address really are coming in from a single vlan on an untagged port.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Nat is the standard solution to the scenario you have where you want to take your carrier public addresses and forward either the entire address or selective ports to an internal address on your network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One advantage of this method is that it is easy to change that server address down the road and the outside world never notices.&amp;nbsp; they are still sending the same DNS entry and public address but the firewall simply changes the nat rule to hit a new server.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 16 Aug 2014 21:55:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/intial-setup-help/m-p/48030#M35313</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2014-08-16T21:55:49Z</dc:date>
    </item>
    <item>
      <title>Re: Intial Setup Help</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/intial-setup-help/m-p/48031#M35314</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So with NAT policies on the PA-200 I can plug my FIOS cable into one of the ports and "listen" for all 5 public IPs on that cable?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 17 Aug 2014 02:07:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/intial-setup-help/m-p/48031#M35314</guid>
      <dc:creator>BRRABill</dc:creator>
      <dc:date>2014-08-17T02:07:17Z</dc:date>
    </item>
    <item>
      <title>Re: Intial Setup Help</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/intial-setup-help/m-p/48032#M35315</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes. And not just with the PAN200, that is how you would typically configure any perimeter firewall.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 17 Aug 2014 03:32:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/intial-setup-help/m-p/48032#M35315</guid>
      <dc:creator>SDorsey</dc:creator>
      <dc:date>2014-08-17T03:32:25Z</dc:date>
    </item>
    <item>
      <title>Re: Intial Setup Help</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/intial-setup-help/m-p/48033#M35316</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;
&lt;P&gt;BRRABill wrote:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;So with NAT policies on the PA-200 I can plug my FIOS cable into one of the ports and "listen" for all 5 public IPs on that cable?&lt;/P&gt;
&lt;/PRE&gt;&lt;P&gt;As mackwage says, nat is the standard procedure for this operation on any firewall.&amp;nbsp; The process works via proxy-arp from the interface facing your carrier.&amp;nbsp; When an interface has the address configured it will automatically respond to requests from the FIOS for that address.&amp;nbsp; Proxy-arp is when an address is used by nat the interface configured with a different address responses for that address.&amp;nbsp; So there is no need for that address to be configured on the interface facing your FIOS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the PA when you configure this type of nat rule in the same subnet as the FIOS interface the firewall will automatically take care of the proxy-arp.&amp;nbsp; On other firewalls you may have to specify the interface and ip address you want a proxy-arp to occur.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 17 Aug 2014 11:07:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/intial-setup-help/m-p/48033#M35316</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2014-08-17T11:07:53Z</dc:date>
    </item>
    <item>
      <title>Re: Intial Setup Help</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/intial-setup-help/m-p/48034#M35317</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can put mulitple /32s on an interface. Make the first IP you add have the correct subnet mask, and have all additional IPs have a /32. We do this today, right now, in production on our PAs.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Aug 2014 13:50:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/intial-setup-help/m-p/48034#M35317</guid>
      <dc:creator>ericgearhart</dc:creator>
      <dc:date>2014-08-18T13:50:12Z</dc:date>
    </item>
    <item>
      <title>Re: Intial Setup Help</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/intial-setup-help/m-p/48035#M35318</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Steven - you have to add IPs to the interface in question, otherwise the interface itself won't ARP out for inbound traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can put mulitple /32s on an interface. Make the first IP you add have the correct subnet mask, and have all additional IPs have a /32. We do this today, right now, in production on our PAs.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Aug 2014 13:50:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/intial-setup-help/m-p/48035#M35318</guid>
      <dc:creator>ericgearhart</dc:creator>
      <dc:date>2014-08-18T13:50:54Z</dc:date>
    </item>
    <item>
      <title>Re: Intial Setup Help</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/intial-setup-help/m-p/48036#M35319</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You just had to go and disagree. Now I have to set it up in my lab and test for myself. Lol :smileylaugh:&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Aug 2014 13:53:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/intial-setup-help/m-p/48036#M35319</guid>
      <dc:creator>SDorsey</dc:creator>
      <dc:date>2014-08-18T13:53:54Z</dc:date>
    </item>
    <item>
      <title>Re: Intial Setup Help</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/intial-setup-help/m-p/48037#M35320</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Well, what did you find out?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you see why I am having issues getting this configured?&amp;nbsp; LOL.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Aug 2014 02:03:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/intial-setup-help/m-p/48037#M35320</guid>
      <dc:creator>BRRABill</dc:creator>
      <dc:date>2014-08-19T02:03:24Z</dc:date>
    </item>
    <item>
      <title>Re: Intial Setup Help</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/intial-setup-help/m-p/48038#M35321</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It is confusing, because you could use untagged subinterfaces to achieve the same thing. So there's more than one way to do it, which presents confusion &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Aug 2014 13:19:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/intial-setup-help/m-p/48038#M35321</guid>
      <dc:creator>ericgearhart</dc:creator>
      <dc:date>2014-08-19T13:19:58Z</dc:date>
    </item>
  </channel>
</rss>

