<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Tagged subinterfaces configuration on L3 mode in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/tagged-subinterfaces-configuration-on-l3-mode/m-p/63724#M38293</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I ahve done this and it works really well for me. Not saying its the only way of doing it but for my proposes it works.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Make the interfaces and subinterfaces layer2&lt;/P&gt;&lt;P&gt;Create layer 3 vlans for the ones that are trunked&lt;/P&gt;&lt;P&gt;Create a zone for each vlan (make sure to add all the rules and nats that you need)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I use it because it allwos me to control traffic between the vlans, kind of like a collapsed DMZ.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also if you have a DENY ALL rule at the bottom, it will not allow intrazone traffice so you would need a rule to allow it, i.e. trust&amp;lt;-&amp;gt;trust allow.&lt;/P&gt;&lt;P&gt;Hope this helps!&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/111iC250D4FCE7172C2F/image-size/original?v=mpbl-1&amp;amp;px=-1" alt="collapsedDMZ.JPG" title="collapsedDMZ.JPG" border="0" /&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 27 Aug 2015 16:04:29 GMT</pubDate>
    <dc:creator>OtakarKlier</dc:creator>
    <dc:date>2015-08-27T16:04:29Z</dc:date>
    <item>
      <title>Tagged subinterfaces configuration on L3 mode</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/tagged-subinterfaces-configuration-on-l3-mode/m-p/63581#M38237</link>
      <description>&lt;P&gt;hello;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;we work on our organisation to do the migration of the configuration from another firewall to the palo lato networks PA-500 . With the recent architecture the segmentation of the networks is in the switch . But now , we like to do this segmentation in the PA-500 by creation of subinterfaces . we like to do like show the screenshot : a router of trafic from inside to outside that a second router from vlan 10 to inside than another router from vlan 20 to inside . The interface eth1/2 is related with a truk port configured on the switch with tagged vlan 10 and vlan 20.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The problem that the traffic not passe to the subinterfaces! Please correct me if there is any mistake that i make it in my configuration.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you!&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/70iF4F58F2245A0892F/image-size/original?v=mpbl-1&amp;amp;px=-1" border="0" alt="subinterfaces-config.JPG" title="subinterfaces-config.JPG" /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Aug 2015 08:32:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/tagged-subinterfaces-configuration-on-l3-mode/m-p/63581#M38237</guid>
      <dc:creator>RCHAIBI</dc:creator>
      <dc:date>2015-08-25T08:32:26Z</dc:date>
    </item>
    <item>
      <title>Re: Tagged subinterfaces configuration on L3 mode</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/tagged-subinterfaces-configuration-on-l3-mode/m-p/63582#M38238</link>
      <description>&lt;P&gt;You're proably missing VLAN 1 on trunk between switch and PA.&lt;/P&gt;&lt;P&gt;Besides you're speaking of different (virtual) routers and you have only 1 for all interfaces (vr_vsys1). But that shouldn't be a problem, in fact that should make your life easier.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hard to tell much more without seeing all configuration and rules.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Aug 2015 09:16:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/tagged-subinterfaces-configuration-on-l3-mode/m-p/63582#M38238</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2015-08-25T09:16:40Z</dc:date>
    </item>
    <item>
      <title>Re: Tagged subinterfaces configuration on L3 mode</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/tagged-subinterfaces-configuration-on-l3-mode/m-p/63587#M38241</link>
      <description>&lt;P&gt;Do you also have the security policies setup betwee zones vlan10 to inside; vlan20 to inside; and inside to outside.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You will also need a NAT policy for inside to outside.&lt;/P&gt;</description>
      <pubDate>Tue, 25 Aug 2015 10:41:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/tagged-subinterfaces-configuration-on-l3-mode/m-p/63587#M38241</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2015-08-25T10:41:04Z</dc:date>
    </item>
    <item>
      <title>Re: Tagged subinterfaces configuration on L3 mode</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/tagged-subinterfaces-configuration-on-l3-mode/m-p/63700#M38286</link>
      <description>&lt;P&gt;What kind of switch do you use?&lt;/P&gt;&lt;P&gt;Is L2 connection brought up?&lt;/P&gt;&lt;P&gt;I notice you are using default management profile on all interfaces. Normaly I would use profile that allows ping only on such interfaces.&lt;/P&gt;&lt;P&gt;Can you ping PA interfaces from switch or laptop connected to one of the switch ports?&lt;/P&gt;&lt;P&gt;If answer is positive to all this, then you will need to have permissive security policy that allows traffic to flow between the zones.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Aug 2015 11:25:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/tagged-subinterfaces-configuration-on-l3-mode/m-p/63700#M38286</guid>
      <dc:creator>katavag</dc:creator>
      <dc:date>2015-08-27T11:25:15Z</dc:date>
    </item>
    <item>
      <title>Re: Tagged subinterfaces configuration on L3 mode</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/tagged-subinterfaces-configuration-on-l3-mode/m-p/63724#M38293</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I ahve done this and it works really well for me. Not saying its the only way of doing it but for my proposes it works.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Make the interfaces and subinterfaces layer2&lt;/P&gt;&lt;P&gt;Create layer 3 vlans for the ones that are trunked&lt;/P&gt;&lt;P&gt;Create a zone for each vlan (make sure to add all the rules and nats that you need)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I use it because it allwos me to control traffic between the vlans, kind of like a collapsed DMZ.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also if you have a DENY ALL rule at the bottom, it will not allow intrazone traffice so you would need a rule to allow it, i.e. trust&amp;lt;-&amp;gt;trust allow.&lt;/P&gt;&lt;P&gt;Hope this helps!&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/111iC250D4FCE7172C2F/image-size/original?v=mpbl-1&amp;amp;px=-1" alt="collapsedDMZ.JPG" title="collapsedDMZ.JPG" border="0" /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Aug 2015 16:04:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/tagged-subinterfaces-configuration-on-l3-mode/m-p/63724#M38293</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2015-08-27T16:04:29Z</dc:date>
    </item>
    <item>
      <title>Re: Tagged subinterfaces configuration on L3 mode</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/tagged-subinterfaces-configuration-on-l3-mode/m-p/64015#M38447</link>
      <description>&lt;P&gt;Hello;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you very much for all the respenses. It's ok , the configuration now work in Layer 3 by adding a Nat rules in the Palo Alto Networks from a vlan to outside.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I really appreciate all your helps&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Wed, 02 Sep 2015 15:38:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/tagged-subinterfaces-configuration-on-l3-mode/m-p/64015#M38447</guid>
      <dc:creator>RCHAIBI</dc:creator>
      <dc:date>2015-09-02T15:38:31Z</dc:date>
    </item>
  </channel>
</rss>

