<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: vwire using a single physical interface possible? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/vwire-using-a-single-physical-interface-possible/m-p/100960#M44340</link>
    <description>&lt;P&gt;You can't use a "virtual-wire" in this scenario, as a v-wire requires exactly 2 interfaces... no more, no less. &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can use an "L2" interface to perform what you're requesting. &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;They're two different interface modes with different capabilities and limitations. &amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sat, 30 Jul 2016 20:43:47 GMT</pubDate>
    <dc:creator>jvalentine</dc:creator>
    <dc:date>2016-07-30T20:43:47Z</dc:date>
    <item>
      <title>vwire using a single physical interface possible?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vwire-using-a-single-physical-interface-possible/m-p/100952#M44335</link>
      <description>&lt;P&gt;Right now we use a standard vwire with 2 physical interfaces.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We're about to make some hardware changes that means that the vwire input and output will be from/to the same physical switch.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I &lt;EM&gt;&lt;STRONG&gt;have&lt;/STRONG&gt; &lt;/EM&gt;to use 2 interfaces then on that switch I'll just be using two untagged ports from/to the appropriate VLANs on the switch.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But do I have to use 2 &lt;STRONG&gt;physical&lt;/STRONG&gt; interfaces? &amp;nbsp;Is it possible to use a single physical interface with subinterfaces (I think that's the magic word?) so the input and output are simply tagged across the one physical link?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Apologies if my terminology is way off here, but hopefully I've explained it well enough, if any clarification is needed please just ask &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 30 Jul 2016 14:23:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vwire-using-a-single-physical-interface-possible/m-p/100952#M44335</guid>
      <dc:creator>networkadmin</dc:creator>
      <dc:date>2016-07-30T14:23:07Z</dc:date>
    </item>
    <item>
      <title>Re: vwire using a single physical interface possible?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vwire-using-a-single-physical-interface-possible/m-p/100955#M44336</link>
      <description>A v-wire requires exactly two physical interfaces.&lt;BR /&gt;&lt;BR /&gt;What you're asking for can be accomplished using a single L2 interface on the firewall and enabling vlan tag rewrite. In essence you are bridging two vlans together.</description>
      <pubDate>Sat, 30 Jul 2016 15:39:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vwire-using-a-single-physical-interface-possible/m-p/100955#M44336</guid>
      <dc:creator>jvalentine</dc:creator>
      <dc:date>2016-07-30T15:39:33Z</dc:date>
    </item>
    <item>
      <title>Re: vwire using a single physical interface possible?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vwire-using-a-single-physical-interface-possible/m-p/100957#M44338</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/22017"&gt;@jvalentine&lt;/a&gt; wrote:&lt;BR /&gt;A v-wire requires exactly two physical interfaces.&lt;BR /&gt;&lt;BR /&gt;What you're asking for can be accomplished using a single L2 interface on the firewall and enabling vlan tag rewrite. In essence you are bridging two vlans together.&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Thanks, bit confused now as you said it requires two physical interfaces then suggested it can be done with one? &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If it needs 2 in order to be supported so be it, just frustrating when it's using NICs and all going into the same switch...&lt;/P&gt;</description>
      <pubDate>Sat, 30 Jul 2016 19:22:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vwire-using-a-single-physical-interface-possible/m-p/100957#M44338</guid>
      <dc:creator>networkadmin</dc:creator>
      <dc:date>2016-07-30T19:22:58Z</dc:date>
    </item>
    <item>
      <title>Re: vwire using a single physical interface possible?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vwire-using-a-single-physical-interface-possible/m-p/100960#M44340</link>
      <description>&lt;P&gt;You can't use a "virtual-wire" in this scenario, as a v-wire requires exactly 2 interfaces... no more, no less. &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can use an "L2" interface to perform what you're requesting. &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;They're two different interface modes with different capabilities and limitations. &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 30 Jul 2016 20:43:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vwire-using-a-single-physical-interface-possible/m-p/100960#M44340</guid>
      <dc:creator>jvalentine</dc:creator>
      <dc:date>2016-07-30T20:43:47Z</dc:date>
    </item>
    <item>
      <title>Re: vwire using a single physical interface possible?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vwire-using-a-single-physical-interface-possible/m-p/100963#M44342</link>
      <description>&lt;P&gt;OK thanks, is there any easy and supported way to combine everything across a single physical link between the switch and the PAN?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Essentially I would have:&lt;/P&gt;&lt;P&gt;L3 interface/subinterface between PAN and switch&lt;/P&gt;&lt;P&gt;L2 interface to inspect&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm guessing L2 and L3 cannot be mixed on the same physical interfacel which makes sense and hopefully the topology will be changing fairly soon to accomodate this so we don't need to be doing it at all.&lt;/P&gt;</description>
      <pubDate>Sun, 31 Jul 2016 08:04:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vwire-using-a-single-physical-interface-possible/m-p/100963#M44342</guid>
      <dc:creator>networkadmin</dc:creator>
      <dc:date>2016-07-31T08:04:46Z</dc:date>
    </item>
    <item>
      <title>Re: vwire using a single physical interface possible?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vwire-using-a-single-physical-interface-possible/m-p/100981#M44350</link>
      <description>&lt;P&gt;VirtualWire is L1 and always requires pair of ports.&lt;/P&gt;&lt;P&gt;Correct, you can't mix L2 and L3 on same interface.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And yes, you can make L2 subinterfaces and assign to different VLANs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm not sure I understant correctly your scenario tho. If you already have L3 (trunk) interface to PA why don't you just move those 2 networks&amp;nbsp;you wish to inspect and secure to PA instead of them being on&amp;nbsp;L3 switch?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Aug 2016 09:31:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vwire-using-a-single-physical-interface-possible/m-p/100981#M44350</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2016-08-01T09:31:51Z</dc:date>
    </item>
    <item>
      <title>Re: vwire using a single physical interface possible?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vwire-using-a-single-physical-interface-possible/m-p/100989#M44355</link>
      <description>&lt;P&gt;Document for PAN-OS 4.0 but it should still work:&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Documentation-Articles/Securing-Inter-VLAN-Traffic/ta-p/54749" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Documentation-Articles/Securing-Inter-VLAN-Traffic/ta-p/54749&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/twzvq79624/attachments/twzvq79624/documentation_tkb/188/1/Layer2_Networking-PAN-OS-revB.pdf" target="_blank"&gt;https://live.paloaltonetworks.com/twzvq79624/attachments/twzvq79624/documentation_tkb/188/1/Layer2_Networking-PAN-OS-revB.pdf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Aug 2016 10:59:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vwire-using-a-single-physical-interface-possible/m-p/100989#M44355</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2016-08-01T10:59:31Z</dc:date>
    </item>
  </channel>
</rss>

