<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Inter Vsys Routing in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/inter-vsys-routing/m-p/147229#M49348</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; I have to configure Inter vsys Routing where the traffic has to leave the firewall fromone vsys and enter into another Vsys. I am not able to find any documention on this scenario. I have already configured and tested the communication between vsys that will not leave the firewall but stuck on where traffic should leave the firewall.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I have a Internet Vsys and a Datacenter Vsys I will take a cable from Inet Vsys interface and connect to DC Vsys interface for physicall connectivity now the question is about routing do I need to configure static routing on both the vsys and I believe it wont be towards the VR's of each other then how the routes would be configured towards the physical interfaces ? and both the VR's will see all the routes of each other ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Sat, 11 Mar 2017 19:36:06 GMT</pubDate>
    <dc:creator>Kashif.Kamal</dc:creator>
    <dc:date>2017-03-11T19:36:06Z</dc:date>
    <item>
      <title>Inter Vsys Routing</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/inter-vsys-routing/m-p/147229#M49348</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; I have to configure Inter vsys Routing where the traffic has to leave the firewall fromone vsys and enter into another Vsys. I am not able to find any documention on this scenario. I have already configured and tested the communication between vsys that will not leave the firewall but stuck on where traffic should leave the firewall.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I have a Internet Vsys and a Datacenter Vsys I will take a cable from Inet Vsys interface and connect to DC Vsys interface for physicall connectivity now the question is about routing do I need to configure static routing on both the vsys and I believe it wont be towards the VR's of each other then how the routes would be configured towards the physical interfaces ? and both the VR's will see all the routes of each other ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Sat, 11 Mar 2017 19:36:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/inter-vsys-routing/m-p/147229#M49348</guid>
      <dc:creator>Kashif.Kamal</dc:creator>
      <dc:date>2017-03-11T19:36:06Z</dc:date>
    </item>
    <item>
      <title>Re: Inter Vsys Routing</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/inter-vsys-routing/m-p/147230#M49349</link>
      <description>&lt;P&gt;A very good article:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Featured-Articles/Tips-amp-Tricks-Inter-VSYS-routing/ta-p/69699" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Featured-Articles/Tips-amp-Tricks-Inter-VSYS-routing/ta-p/69699&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 11 Mar 2017 19:46:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/inter-vsys-routing/m-p/147230#M49349</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-03-11T19:46:04Z</dc:date>
    </item>
    <item>
      <title>Re: Inter Vsys Routing</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/inter-vsys-routing/m-p/147254#M49352</link>
      <description>&lt;P&gt;Hi, &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; Thanks for the informative link. My question is what is the benefit we get by&amp;nbsp;&lt;SPAN&gt;Inter-VSYS Traffic That Must Leave the Firewall over&amp;nbsp;Inter-VSYS Traffic That Remains Within the Firewall as far as I understood we will not have External zones between Vsys if we send the traffic out of firewall. Is there any other benefit to send the traffic out and back again&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 12 Mar 2017 07:50:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/inter-vsys-routing/m-p/147254#M49352</guid>
      <dc:creator>Kashif.Kamal</dc:creator>
      <dc:date>2017-03-12T07:50:06Z</dc:date>
    </item>
    <item>
      <title>Re: Inter Vsys Routing</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/inter-vsys-routing/m-p/147277#M49355</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can use a shared gateway as the shared interface as shared_untrust and created external zone as untrust zone for each vsys and make sure the visability use configured between the shared gateway and all the vsys.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The interesting part will be traffic from vsys1 to vsys2 you will see two sessions&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;session 1: trust-vsys1 to untrust (vsys1)&lt;/P&gt;&lt;P&gt;session 2: untrust (vsys2) to trust vsys2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If the traffic desintation is not vsys1 or vsys2. &amp;nbsp;the session will trust-vsys1 to shared_untrust.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The down side of doing it this way is any intervsys traffic will handle ONLY by the data plane processors. &amp;nbsp;The intervsys traffic will not be able to offload by the offloader. &amp;nbsp; The data plane processors have very limited throughtput. &amp;nbsp;(Depend on your appliance). &amp;nbsp; &amp;nbsp;That can cause the DP CPU to go to 100% and stay as long as the intervsys sessions are alive.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Check this link out, &amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/Learning-Articles/Differences-between-packets-in-slow-path-fast-path-and-offloaded/ta-p/58845" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Learning-Articles/Differences-between-packets-in-slow-path-fast-path-and-offloaded/ta-p/58845&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You may want to have a deep dive with your SEs/Reseller too..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 12 Mar 2017 10:58:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/inter-vsys-routing/m-p/147277#M49355</guid>
      <dc:creator>nextgenhappines</dc:creator>
      <dc:date>2017-03-12T10:58:39Z</dc:date>
    </item>
  </channel>
</rss>

