<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: intra-interface (packets enter and exit same interface) ? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/intra-interface-packets-enter-and-exit-same-interface/m-p/136478#M47647</link>
    <description>&lt;P&gt;In other vendors.&amp;nbsp; ZONE and INTERFACE are two disinct things.&lt;/P&gt;&lt;P&gt;The INTRA-zone is not an issue, but INTRA-interface tends to be an issue and the capability to forward traffic (such that it INGRESSES and EGRESSES out the same interface) must be something explicitly enabled.&amp;nbsp; but INTRA-zone tends to just work.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So.. is this 2 x distinct different things in PANOS also like other vendors.. or is ZONE and INTERFACE almagamated into the same thing in their OS architecture based on your reply ?&lt;/P&gt;</description>
    <pubDate>Mon, 09 Jan 2017 13:07:52 GMT</pubDate>
    <dc:creator>mpgioia</dc:creator>
    <dc:date>2017-01-09T13:07:52Z</dc:date>
    <item>
      <title>intra-interface (packets enter and exit same interface) ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/intra-interface-packets-enter-and-exit-same-interface/m-p/136470#M47645</link>
      <description>&lt;P&gt;This is a problem for other vendors (and something must be enabled/configured to allow this to occur).&lt;/P&gt;&lt;P&gt;Have not tried this in PANOS, but wondering if this just works or is it a similar scenario where you must enable something in PANOS ?&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.networkstraining.com/permitting-traffic-to-enter-and-exit-the-same-interface-same-security-traffic-permit/" target="_blank"&gt;http://www.networkstraining.com/permitting-traffic-to-enter-and-exit-the-same-interface-same-security-traffic-permit/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Jan 2017 12:57:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/intra-interface-packets-enter-and-exit-same-interface/m-p/136470#M47645</guid>
      <dc:creator>mpgioia</dc:creator>
      <dc:date>2017-01-09T12:57:40Z</dc:date>
    </item>
    <item>
      <title>Re: intra-interface (packets enter and exit same interface) ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/intra-interface-packets-enter-and-exit-same-interface/m-p/136477#M47646</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you are running PAN-OS 6.1 or above intrazone traffic permitted by default with intrazone-defult policy.&lt;/P&gt;&lt;P&gt;If you are running lower then 6.1 PAN-OS you ahve to create a policy to allow same zone traffic:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Management-Articles/What-are-Universal-Intrazone-and-Interzone-Rules/ta-p/57491" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Management-Articles/What-are-Universal-Intrazone-and-Interzone-Rules/ta-p/57491&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thx,&lt;/P&gt;&lt;P&gt;Myky&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Jan 2017 13:02:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/intra-interface-packets-enter-and-exit-same-interface/m-p/136477#M47646</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-01-09T13:02:17Z</dc:date>
    </item>
    <item>
      <title>Re: intra-interface (packets enter and exit same interface) ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/intra-interface-packets-enter-and-exit-same-interface/m-p/136478#M47647</link>
      <description>&lt;P&gt;In other vendors.&amp;nbsp; ZONE and INTERFACE are two disinct things.&lt;/P&gt;&lt;P&gt;The INTRA-zone is not an issue, but INTRA-interface tends to be an issue and the capability to forward traffic (such that it INGRESSES and EGRESSES out the same interface) must be something explicitly enabled.&amp;nbsp; but INTRA-zone tends to just work.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So.. is this 2 x distinct different things in PANOS also like other vendors.. or is ZONE and INTERFACE almagamated into the same thing in their OS architecture based on your reply ?&lt;/P&gt;</description>
      <pubDate>Mon, 09 Jan 2017 13:07:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/intra-interface-packets-enter-and-exit-same-interface/m-p/136478#M47647</guid>
      <dc:creator>mpgioia</dc:creator>
      <dc:date>2017-01-09T13:07:52Z</dc:date>
    </item>
    <item>
      <title>Re: intra-interface (packets enter and exit same interface) ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/intra-interface-packets-enter-and-exit-same-interface/m-p/136479#M47648</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cisco ASA is interface based firewall and work a bit in different way then zone based firewall (PA, Juniper SRX ect).&lt;/P&gt;&lt;P&gt;If we are talking about PA, every interface beloning to the zone (only one zone). So if you want to permit same zone trafic (lets say one inreface configured in the zone OUTSIDE) you have to have a policy in place&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Jan 2017 13:14:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/intra-interface-packets-enter-and-exit-same-interface/m-p/136479#M47648</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-01-09T13:14:31Z</dc:date>
    </item>
    <item>
      <title>Re: intra-interface (packets enter and exit same interface) ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/intra-interface-packets-enter-and-exit-same-interface/m-p/136481#M47649</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/14607"&gt;@mpgioia&lt;/a&gt;&amp;nbsp;The Palo Alto looks strictly at zones and not interfaces when it comes to security profiles. Same interface traffic is looked at the same as intrazone traffic. The only thing that you really have to do is to verify that your static routes and security policies are setup in a way that this actually functions. &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Jan 2017 13:53:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/intra-interface-packets-enter-and-exit-same-interface/m-p/136481#M47649</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-01-09T13:53:06Z</dc:date>
    </item>
    <item>
      <title>Re: intra-interface (packets enter and exit same interface) ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/intra-interface-packets-enter-and-exit-same-interface/m-p/136487#M47653</link>
      <description>&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt; , &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/37163"&gt;@TranceforLife&lt;/a&gt;. Music to my ears. Thankyou.&lt;BR /&gt;</description>
      <pubDate>Mon, 09 Jan 2017 14:09:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/intra-interface-packets-enter-and-exit-same-interface/m-p/136487#M47653</guid>
      <dc:creator>mpgioia</dc:creator>
      <dc:date>2017-01-09T14:09:52Z</dc:date>
    </item>
    <item>
      <title>Re: intra-interface (packets enter and exit same interface) ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/intra-interface-packets-enter-and-exit-same-interface/m-p/136515#M47660</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;TranceforLife wrote:&lt;/FONT&gt;&lt;BR /&gt;
&lt;P&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;Hi,&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;If you are running PAN-OS 6.1 or above intrazone traffic permitted by default with intrazone-defult policy.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;If you are running lower then 6.1 PAN-OS you ahve to create a policy to allow same zone traffic:&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Management-Articles/What-are-Universal-Intrazone-and-Interzone-Rules/ta-p/57491" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Management-Articles/What-are-Universal-Intrazone-and-Interzone-Rules/ta-p/57491&lt;/A&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;Thx,&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;Myky&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;that's incorrect, intrazone traffic has always been allowed. PAN-OS 6.1 just made the policies visible &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Depending on what you're trying to accomplish, you may need U-turn NAT to force returning packets back to the firewall interface so sessions process both directions of the flow:&amp;nbsp;&lt;A title="How to Configure U-Turn NAT" href="https://live.paloaltonetworks.com/t5/Learning-Articles/How-to-Configure-U-Turn-NAT/ta-p/65081" target="_blank"&gt;How to Configure U-Turn NAT&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;other than that there's no restrictions in bouncing traffic back out of the same interface&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Jan 2017 15:59:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/intra-interface-packets-enter-and-exit-same-interface/m-p/136515#M47660</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2017-01-09T15:59:47Z</dc:date>
    </item>
    <item>
      <title>Re: intra-interface (packets enter and exit same interface) ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/intra-interface-packets-enter-and-exit-same-interface/m-p/136617#M47668</link>
      <description>&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt; yes absolutely. Sorry my bad</description>
      <pubDate>Mon, 09 Jan 2017 23:34:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/intra-interface-packets-enter-and-exit-same-interface/m-p/136617#M47668</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-01-09T23:34:41Z</dc:date>
    </item>
  </channel>
</rss>

