<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: vwire policies in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/vwire-policies/m-p/6751#M4949</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thnak's for your help &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 19 Feb 2013 08:33:29 GMT</pubDate>
    <dc:creator>atelcom</dc:creator>
    <dc:date>2013-02-19T08:33:29Z</dc:date>
    <item>
      <title>vwire policies</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vwire-policies/m-p/6747#M4945</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;HI all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;when we deploy the paloalto firewall in vwire mode and we have multiple zones (system zone, application zone, bdd zone), can we create rules to permit traffic between these zones through pan firewall ??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thank's in advance&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 17 Feb 2013 10:54:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vwire-policies/m-p/6747#M4945</guid>
      <dc:creator>atelcom</dc:creator>
      <dc:date>2013-02-17T10:54:26Z</dc:date>
    </item>
    <item>
      <title>Re: vwire policies</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vwire-policies/m-p/6748#M4946</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can configure rules to allow/deny traffic between V-wire zones. You can also make use of other features like anti-virus filtering, url filtering, NAT and almost every other feature done by regular L3-traffic. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here are some documents that can help you with Vwire config.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-1165"&gt;How to Configure Virtual Wire (VWire)&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/videos/1005"&gt; Video Link : 1005&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A __default_attr="2729" __jive_macro_name="document" class="jive_macro jive_macro_document" href="https://live.paloaltonetworks.com/"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Sandeep T&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 17 Feb 2013 16:47:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vwire-policies/m-p/6748#M4946</guid>
      <dc:creator>sdurga</dc:creator>
      <dc:date>2013-02-17T16:47:57Z</dc:date>
    </item>
    <item>
      <title>Re: vwire policies</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vwire-policies/m-p/6749#M4947</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;To further add to Sandeep's answer. If you are only using vwire you will only control access between the zones defined in the vwire interfaces that are part of the same vwire object. &lt;/P&gt;&lt;P&gt;So if you had ethernet1/1 and ethernet1/8 in a pair, which are defined as Trust and Untrust respectively, then you could create a security policy to control traffic from Trust to Untrust or from Untrust to Trust. A security policy from Trust to DMZ would never be hit as it's not possible for the PAN to forward the traffic to the DMZ zone.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If however you are using V5.0 you can implement vwire sub-interfaces which allows you to put a VLAN into a vwire sub-interface and thus put it into it's own zone which means you then have to create a policy to allow the traffic.&lt;/P&gt;&lt;P&gt;So if we created a vwire sub-interface on ethernet1/8 which had the zone of DMZ, then we could configure a policy to control traffic from Trust to Untrust and another from Trust to DMZ.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that makes things a bit clearer.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Feb 2013 08:51:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vwire-policies/m-p/6749#M4947</guid>
      <dc:creator>SCoupland</dc:creator>
      <dc:date>2013-02-18T08:51:14Z</dc:date>
    </item>
    <item>
      <title>Re: vwire policies</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vwire-policies/m-p/6750#M4948</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thank's for your reply &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Feb 2013 08:33:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vwire-policies/m-p/6750#M4948</guid>
      <dc:creator>atelcom</dc:creator>
      <dc:date>2013-02-19T08:33:06Z</dc:date>
    </item>
    <item>
      <title>Re: vwire policies</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vwire-policies/m-p/6751#M4949</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thnak's for your help &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Feb 2013 08:33:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vwire-policies/m-p/6751#M4949</guid>
      <dc:creator>atelcom</dc:creator>
      <dc:date>2013-02-19T08:33:29Z</dc:date>
    </item>
  </channel>
</rss>

