<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Two L3 interfaces on One Zone in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/two-l3-interfaces-on-one-zone/m-p/140416#M48270</link>
    <description>&lt;P&gt;Yes, you can have both&amp;nbsp;interfaces in the same security zone.&lt;/P&gt;&lt;P&gt;And then make rules based on security zones.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;((but you can't have same interface in multiple security zones))&lt;/P&gt;</description>
    <pubDate>Wed, 01 Feb 2017 08:12:44 GMT</pubDate>
    <dc:creator>santonic</dc:creator>
    <dc:date>2017-02-01T08:12:44Z</dc:date>
    <item>
      <title>Two L3 interfaces on One Zone</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/two-l3-interfaces-on-one-zone/m-p/140303#M48257</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Question.jpg" style="width: 300px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/7544i550AE8BB1BF8006F/image-size/small/is-moderation-mode/true?v=v2&amp;amp;px=200" role="button" title="Question.jpg" alt="Question.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;in the setup of the above diagram , I need to run OSPF on Paloalto between two Core-SWs, so I have to create two L3 interfaces &amp;nbsp;Point to Point with the two SWs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the two core-SW is considered as inside for me , so from the prespective of routing it is okay.&lt;/P&gt;&lt;P&gt;but the issue on the polices, I have to create the polices duoble between two inside zones to outside.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;my question : &amp;nbsp;is it possible to combine the two interfaces on one zone to use it on one policy ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I know that my question seems to be unusal but I need your suggestions on this setup ??&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 31 Jan 2017 18:48:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/two-l3-interfaces-on-one-zone/m-p/140303#M48257</guid>
      <dc:creator>Mohamed_Mabrouk</dc:creator>
      <dc:date>2017-01-31T18:48:16Z</dc:date>
    </item>
    <item>
      <title>Re: Two L3 interfaces on One Zone</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/two-l3-interfaces-on-one-zone/m-p/140416#M48270</link>
      <description>&lt;P&gt;Yes, you can have both&amp;nbsp;interfaces in the same security zone.&lt;/P&gt;&lt;P&gt;And then make rules based on security zones.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;((but you can't have same interface in multiple security zones))&lt;/P&gt;</description>
      <pubDate>Wed, 01 Feb 2017 08:12:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/two-l3-interfaces-on-one-zone/m-p/140416#M48270</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2017-02-01T08:12:44Z</dc:date>
    </item>
    <item>
      <title>Re: Two L3 interfaces on One Zone</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/two-l3-interfaces-on-one-zone/m-p/140479#M48279</link>
      <description>&lt;P&gt;When you create an interface under the 'config' tab you have to assign the interface a virtual router and a security zone. You would simply put the security zone into the same zone as the other interface and then build the rules out with the security zone that includes both interfaces.&amp;nbsp;&lt;/P&gt;&lt;P&gt;As santonic mentioned what you&amp;nbsp;&lt;STRONG&gt;can't&lt;/STRONG&gt; do is include one interface in multiple security zones. So the same interface can't be assigned to both a 'trust' and a 'dmz' zone at the same time.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Feb 2017 14:32:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/two-l3-interfaces-on-one-zone/m-p/140479#M48279</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-02-01T14:32:31Z</dc:date>
    </item>
  </channel>
</rss>

