<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Deny the access to the servers in LAN zone in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/deny-the-access-to-the-servers-in-lan-zone/m-p/66856#M39350</link>
    <description>&lt;P&gt;Usually it is done like this:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Documentation-Articles/Securing-Inter-VLAN-Traffic/ta-p/54749" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Documentation-Articles/Securing-Inter-VLAN-Traffic/ta-p/54749&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But if you can't change IP's then do it with Layer 2 setup:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Documentation-Articles/Layer-2-Networking/ta-p/57040" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Documentation-Articles/Layer-2-Networking/ta-p/57040&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Screenshots are taken from older version but you should get the point.&lt;/P&gt;</description>
    <pubDate>Mon, 19 Oct 2015 21:06:01 GMT</pubDate>
    <dc:creator>Raido_Rattameister</dc:creator>
    <dc:date>2015-10-19T21:06:01Z</dc:date>
    <item>
      <title>Deny the access to the servers in LAN zone</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/deny-the-access-to-the-servers-in-lan-zone/m-p/66846#M39343</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I need to restrict the access to a critical server in our company i the LAN zone . I add a security rule that restrict for exemple the address 192.18.1.25 to access to database server tht has the address 192.168.1.20 . I add a security rule from LAN to LAN with this address but the rstrection do't work!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;How can i do this restriction ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I will be appreciated for all helps &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Oct 2015 19:08:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/deny-the-access-to-the-servers-in-lan-zone/m-p/66846#M39343</guid>
      <dc:creator>RCHAIBI</dc:creator>
      <dc:date>2015-10-19T19:08:26Z</dc:date>
    </item>
    <item>
      <title>Re: Deny the access to the servers in LAN zone</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/deny-the-access-to-the-servers-in-lan-zone/m-p/66847#M39344</link>
      <description>&lt;P&gt;Are those servers directly connected to Palo Alto firewall ports or there is switch between those servers and Palo?&lt;/P&gt;
&lt;P&gt;If there is cable from Palo to switch and then cables from switch to both servers then servers talk directly through switch.&lt;/P&gt;
&lt;P&gt;If those servers connect to diferent firewall ports then it is possible to get this setup working.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Oct 2015 19:14:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/deny-the-access-to-the-servers-in-lan-zone/m-p/66847#M39344</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2015-10-19T19:14:45Z</dc:date>
    </item>
    <item>
      <title>Re: Deny the access to the servers in LAN zone</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/deny-the-access-to-the-servers-in-lan-zone/m-p/66848#M39345</link>
      <description>&lt;P&gt;Did you mean that your client is 192.1&lt;STRONG&gt;6&lt;/STRONG&gt;8.1.25? If so, then the client wouldn't even be passing through the firewall most likely. If your client and server are in the same subnet, such as 192.168.1.0/24, the client will ARP directly for the server. If both the server and the client are connected to the same switch (or can access each other via L2 only), there will be no routing.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Generally you would set up your clients and servers in different zones and on different subnets, so that you can control the traffic as it routes through the firewall.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Oct 2015 19:13:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/deny-the-access-to-the-servers-in-lan-zone/m-p/66848#M39345</guid>
      <dc:creator>gwesson</dc:creator>
      <dc:date>2015-10-19T19:13:24Z</dc:date>
    </item>
    <item>
      <title>Re: Deny the access to the servers in LAN zone</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/deny-the-access-to-the-servers-in-lan-zone/m-p/66849#M39346</link>
      <description>&lt;P&gt;The eth 1/2 of PAN is configuredwith LAN zone and this interface is connected to the switch . Yes the servers and the clients&amp;nbsp;PC are connected to the same swith . I need torestrict the access to of the uses to a servers that's located in the same subnet 192.168.1.0/24.&lt;/P&gt;
&lt;P&gt;It's posibleto do this?&lt;/P&gt;</description>
      <pubDate>Mon, 19 Oct 2015 19:24:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/deny-the-access-to-the-servers-in-lan-zone/m-p/66849#M39346</guid>
      <dc:creator>RCHAIBI</dc:creator>
      <dc:date>2015-10-19T19:24:44Z</dc:date>
    </item>
    <item>
      <title>Re: Deny the access to the servers in LAN zone</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/deny-the-access-to-the-servers-in-lan-zone/m-p/66850#M39347</link>
      <description>&lt;P&gt;It is possible but as mentioned before - in your case devices talk directly through the switch.&lt;/P&gt;
&lt;P&gt;You have to configure it so that traffic passes firewall.&lt;/P&gt;
&lt;P&gt;Either with diferent vlans (does your switch support them?) or with connecting diferent devices to diferent fw ports.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Oct 2015 19:30:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/deny-the-access-to-the-servers-in-lan-zone/m-p/66850#M39347</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2015-10-19T19:30:28Z</dc:date>
    </item>
    <item>
      <title>Re: Deny the access to the servers in LAN zone</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/deny-the-access-to-the-servers-in-lan-zone/m-p/66851#M39348</link>
      <description>&lt;P&gt;So this case is only possible with te configuration of VLANS in PAN or in the switch ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I found this article talk about the configuration of VLANs interfce in PAN :&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/Configuration-Articles/Setting-Up-the-PA-200-for-Home-and-Small-Office/tac-p/61841/highlight/true" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Configuration-Articles/Setting-Up-the-PA-200-for-Home-and-Small-Office/tac-p/61841/highlight/true&lt;/A&gt; &amp;nbsp; &amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So if I like to confgure a VLANs in PAN ,I should do as mentioned n the article : config from L3 to L2 &amp;nbsp;&lt;/P&gt;
&lt;P&gt;interface 1/1: WAN : L3&lt;/P&gt;
&lt;P&gt;interface 1/2: LAN (interface VLAN 192 with &amp;nbsp;address 192.168.1.0/24)&lt;/P&gt;
&lt;P&gt;interface 1/3: Server zone with address &amp;nbsp;(interfac VLAN 10 : 10.200.1.0/24)&lt;/P&gt;
&lt;P&gt;Then I will relate the inter1/2 and iner1/3 to a separate switch . I will add then a access and Vroute in PAN that's te solution??&lt;/P&gt;</description>
      <pubDate>Mon, 19 Oct 2015 19:45:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/deny-the-access-to-the-servers-in-lan-zone/m-p/66851#M39348</guid>
      <dc:creator>RCHAIBI</dc:creator>
      <dc:date>2015-10-19T19:45:51Z</dc:date>
    </item>
    <item>
      <title>Re: Deny the access to the servers in LAN zone</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/deny-the-access-to-the-servers-in-lan-zone/m-p/66856#M39350</link>
      <description>&lt;P&gt;Usually it is done like this:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Documentation-Articles/Securing-Inter-VLAN-Traffic/ta-p/54749" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Documentation-Articles/Securing-Inter-VLAN-Traffic/ta-p/54749&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But if you can't change IP's then do it with Layer 2 setup:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Documentation-Articles/Layer-2-Networking/ta-p/57040" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Documentation-Articles/Layer-2-Networking/ta-p/57040&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Screenshots are taken from older version but you should get the point.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Oct 2015 21:06:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/deny-the-access-to-the-servers-in-lan-zone/m-p/66856#M39350</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2015-10-19T21:06:01Z</dc:date>
    </item>
  </channel>
</rss>

