<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: L3 install issue - two internet lines of L3 mode installation on same networks in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/l3-install-issue-two-internet-lines-of-l3-mode-installation-on/m-p/49370#M36372</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Kelly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks for your great advice but, i've been failed with your recommand way.&lt;/P&gt;&lt;P&gt;I will try to discuss to change network configuration with prospective customer.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks again.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Eugene.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 07 Apr 2011 04:37:21 GMT</pubDate>
    <dc:creator>willstech</dc:creator>
    <dc:date>2011-04-07T04:37:21Z</dc:date>
    <item>
      <title>L3 install issue - two internet lines of L3 mode installation on same networks</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/l3-install-issue-two-internet-lines-of-l3-mode-installation-on/m-p/49367#M36369</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi all.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt;One of demo customer has two internet lines from same ISP and same network. &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt;PA appliance runs on V-wire mode behind L3 office router at now.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt;But, customer wants to change network like attached file therefore, PA should be changed from Vwire to L3 router mode.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt;(Refer to attached network diagram.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt; &lt;/SPAN&gt;&lt;SPAN lang="EN-US"&gt;Ultimately, Router will be changed to PA appliance, if the deal will get win.)&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt;The important problem of new diagram is same networks of two internet lines.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt;i tried to install like below, but failed.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt;1.&lt;/SPAN&gt;&lt;SPAN lang="EN-US"&gt; i tried to deploy L3 for each external line, but failed due to same network. &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt;2. &lt;/SPAN&gt;&lt;SPAN lang="EN-US"&gt;I tried to deploy L2 for each external line and, i was tie to VLAN for both of L2 interface. &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt;VLAN interface has a role of L3 for external connection at this configuration. But it also failed due to network looping. &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt;3. &lt;/SPAN&gt;&lt;SPAN lang="EN-US"&gt;I tried to deploy aggregate for each external line, but failed due to aggregate link was not up. &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt;it should be considered that NAT requirement for L3 deployment.&lt;/SPAN&gt;&lt;SPAN lang="EN-US"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-US" style="FONT-SIZE: 10pt; FONT-FAMILY: '맑은 고딕'; mso-bidi-font-size: 11.0pt; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: 'Times New Roman'; mso-bidi-theme-font: minor-bidi; mso-ansi-language: EN-US; mso-fareast-language: KO; mso-bidi-language: AR-SA"&gt;Eugene&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 31 Mar 2011 08:09:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/l3-install-issue-two-internet-lines-of-l3-mode-installation-on/m-p/49367#M36369</guid>
      <dc:creator>willstech</dc:creator>
      <dc:date>2011-03-31T08:09:28Z</dc:date>
    </item>
    <item>
      <title>Re: L3 install issue - two internet lines of L3 mode installation on same networks</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/l3-install-issue-two-internet-lines-of-l3-mode-installation-on/m-p/49368#M36370</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Eugene -&lt;/P&gt;&lt;P&gt;Have you configured the outside addresses for your nat tables yet? &lt;/P&gt;&lt;P&gt;I think you also might have the subnetting or the addresses wrong.&amp;nbsp; For L3 connections with a /32 this is used for Point-to-point links, if you were to have a single link from the ISP.&amp;nbsp; If this setup is currently working double check your subnets used. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;/32 indicates PA-2020 (100.100.100.197/32) --&amp;gt; ISP (100.100.100.198/32)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We'll work on getting basic connectivity now:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;GOTO:&amp;nbsp; Objects tab and make sure you have the proper outside address in the ADDRESS menu.&amp;nbsp; Make sure you are using the IP Netmask configuration with just a single IP address per config.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Policies &amp;gt; NAT -- make sure you have a rule saying trust to untrust you are doing source address translation.&amp;nbsp; You will be doing Port and IP address translation and using the OUTSIDE address you just configured.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Under the Network tab &amp;gt; Interfaces do you have zones set, virtual router (internal and external interfaces need to be on the same router).&amp;nbsp; Both untagged and both have a L3 interface type.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Under Network &amp;gt; Virtual Routers -- check your vitual router has a default route to the outside world. &lt;/P&gt;&lt;P&gt;Destination 0.0.0.0/0&lt;/P&gt;&lt;P&gt;Net hop type: IP&lt;/P&gt;&lt;P&gt;Next hop value: GATEWAY-PROVIDED BY YOUR ISP (100.100.100.100)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;FOR doing the NAT to your web server at 10.1.1.2/32 you will do the following:&lt;/P&gt;&lt;P&gt;Object &amp;gt; ADDRESS - add your external address used for your server (100.100.100.197?)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Policies &amp;gt; NAT -- make a new rule. &lt;/P&gt;&lt;P&gt;Source zone: untrust&lt;/P&gt;&lt;P&gt;Destination zone: trust&lt;/P&gt;&lt;P&gt;Destination Address: choose the new 100.100.100.197? address you just created&lt;/P&gt;&lt;P&gt;service: http/https/whatever service you are using.&lt;/P&gt;&lt;P&gt;destination translation: translation address 10.1.1.2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; translated port - can leave blank or use 80/443 if you want.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;commit and be awesome.&lt;/P&gt;&lt;P&gt;let us know if any of this was helpful.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 31 Mar 2011 11:43:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/l3-install-issue-two-internet-lines-of-l3-mode-installation-on/m-p/49368#M36370</guid>
      <dc:creator>cityofkingsland</dc:creator>
      <dc:date>2011-03-31T11:43:30Z</dc:date>
    </item>
    <item>
      <title>Re: L3 install issue - two internet lines of L3 mode installation on same networks</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/l3-install-issue-two-internet-lines-of-l3-mode-installation-on/m-p/49369#M36371</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is certainly an interesting design! &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt; I don't see two physical interfaces with IPs in the same subnet very often.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the ISP cannot change your external addressing or you cannot use just a single outside interface, then you might try the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Create two Virtual Routers (You can have overlapping subnets using multiple Virtual Routers) and put each external interface into its own.&amp;nbsp; Call them Default and Server.&amp;nbsp; Both have a 0.0.0.0/0 route next hop of 100.100.100.100.&lt;/LI&gt;&lt;LI&gt;Create three L3 interfaces:&lt;UL&gt;&lt;LI&gt;Inside interface goes into Default Virtual Router, Inside zone&lt;/LI&gt;&lt;LI&gt;.198 goes into Default Virtual Router, Public zone&lt;/LI&gt;&lt;LI&gt;.197 goes into Server Virtual Router, Public zone&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;Create your NAT rules as you have defined in the diagram&lt;UL&gt;&lt;LI&gt;Make the Server rule static, Bidirectional&lt;/LI&gt;&lt;LI&gt;Make the Client PC rule dynamic-ip-and-port&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;Create two PBF rules:&lt;UL&gt;&lt;LI&gt;Inbound PBF rule for the Server:&amp;nbsp; from .197 interface, then send to Internal interface&lt;/LI&gt;&lt;LI&gt;Outbound PBF rule for the Server: from 10.1.1.2/32 address, then send to .197 interface&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;Create an any any allow Security rule to test&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Seems like this should work in theory. You are basically using normal routing for the bulk of the traffic and PBF to force the Server traffic over the other link.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kelly&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 31 Mar 2011 16:46:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/l3-install-issue-two-internet-lines-of-l3-mode-installation-on/m-p/49369#M36371</guid>
      <dc:creator>kbrazil</dc:creator>
      <dc:date>2011-03-31T16:46:43Z</dc:date>
    </item>
    <item>
      <title>Re: L3 install issue - two internet lines of L3 mode installation on same networks</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/l3-install-issue-two-internet-lines-of-l3-mode-installation-on/m-p/49370#M36372</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Kelly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks for your great advice but, i've been failed with your recommand way.&lt;/P&gt;&lt;P&gt;I will try to discuss to change network configuration with prospective customer.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks again.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Eugene.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Apr 2011 04:37:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/l3-install-issue-two-internet-lines-of-l3-mode-installation-on/m-p/49370#M36372</guid>
      <dc:creator>willstech</dc:creator>
      <dc:date>2011-04-07T04:37:21Z</dc:date>
    </item>
  </channel>
</rss>

