<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Tagged subinterface in different zone than parent not working in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/tagged-subinterface-in-different-zone-than-parent-not-working/m-p/182872#M56275</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/4441"&gt;@razor192&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Your text and screen shot Zones do not match up. If you haveyour source zone set as&amp;nbsp;&lt;SPAN&gt;UnSecuteWiFi-66, you should be ableto create policies around that.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Hope that helps.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 19 Oct 2017 21:24:45 GMT</pubDate>
    <dc:creator>OtakarKlier</dc:creator>
    <dc:date>2017-10-19T21:24:45Z</dc:date>
    <item>
      <title>Tagged subinterface in different zone than parent not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/tagged-subinterface-in-different-zone-than-parent-not-working/m-p/181392#M56038</link>
      <description>&lt;P&gt;So up to this point I'd only been using tagged sub interfaces for capacity\housekeeping\etc,&amp;nbsp; so they were all in the same security zone.&amp;nbsp; Now I have a case where I'd like to be able to add some rules to where traffic from this new VLAN can go..&amp;nbsp;&lt;/P&gt;&lt;P&gt;I put the new sub interface in a new zone,&amp;nbsp; add the new zone to the general internet access rules and outbound NAT rule..&amp;nbsp; no love..&amp;nbsp; So I look in at the traffic monitor, I see the traffic but it has a source zone of the parent interface, not the zone it is configured with..&amp;nbsp; &amp;nbsp; am I missing somthing obvious here?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PA sub interfaces.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/11893iC9D0780E97BFFCE0/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="PA sub interfaces.PNG" alt="PA sub interfaces.PNG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PA monitor log.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/11894iF7F4066E07278038/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="PA monitor log.PNG" alt="PA monitor log.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Oct 2017 19:59:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/tagged-subinterface-in-different-zone-than-parent-not-working/m-p/181392#M56038</guid>
      <dc:creator>razor192</dc:creator>
      <dc:date>2017-10-11T19:59:24Z</dc:date>
    </item>
    <item>
      <title>Re: Tagged subinterface in different zone than parent not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/tagged-subinterface-in-different-zone-than-parent-not-working/m-p/181406#M56040</link>
      <description>&lt;P&gt;Monitor &amp;gt; Traffic&lt;/P&gt;&lt;P&gt;Add Ingress I/F column. Are those packets coming in from ethernet1/2.66 interface?&lt;/P&gt;</description>
      <pubDate>Wed, 11 Oct 2017 20:16:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/tagged-subinterface-in-different-zone-than-parent-not-working/m-p/181406#M56040</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2017-10-11T20:16:30Z</dc:date>
    </item>
    <item>
      <title>Re: Tagged subinterface in different zone than parent not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/tagged-subinterface-in-different-zone-than-parent-not-working/m-p/181426#M56041</link>
      <description>&lt;P&gt;Hmmm.. No it says the are coming from the parent interface&amp;nbsp;&lt;SPAN&gt;ethernet1/2.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Oct 2017 21:22:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/tagged-subinterface-in-different-zone-than-parent-not-working/m-p/181426#M56041</guid>
      <dc:creator>razor192</dc:creator>
      <dc:date>2017-10-11T21:22:46Z</dc:date>
    </item>
    <item>
      <title>Re: Tagged subinterface in different zone than parent not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/tagged-subinterface-in-different-zone-than-parent-not-working/m-p/181429#M56043</link>
      <description>&lt;P&gt;In this case your vlans are messed up. Maybe wifi access point is in incorrect vlan.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Oct 2017 22:09:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/tagged-subinterface-in-different-zone-than-parent-not-working/m-p/181429#M56043</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2017-10-11T22:09:32Z</dc:date>
    </item>
    <item>
      <title>Re: Tagged subinterface in different zone than parent not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/tagged-subinterface-in-different-zone-than-parent-not-working/m-p/181495#M56052</link>
      <description>&lt;P&gt;if your traffic log is showing the sessions in the wrong zone you're probably receiving them untagged. your original source may be connected to an untagged switch port or your trunk/switch doesn;t support/isnt configured for the vlan tag you configured on the subinterface&lt;/P&gt;</description>
      <pubDate>Thu, 12 Oct 2017 12:25:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/tagged-subinterface-in-different-zone-than-parent-not-working/m-p/181495#M56052</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2017-10-12T12:25:41Z</dc:date>
    </item>
    <item>
      <title>Re: Tagged subinterface in different zone than parent not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/tagged-subinterface-in-different-zone-than-parent-not-working/m-p/181497#M56053</link>
      <description>&lt;P&gt;I agree with reaper. the tell-tale signs are there to support that particular view ...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you share the switch/router port/interface config here with us ...&lt;/P&gt;&lt;P&gt;And also can I please ask you to confirm that you have set 'Tag' on the Palo side?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ajaz Nawaz | Network &amp;amp; Security Consultant&lt;/P&gt;&lt;P&gt;JNCIE-SEC #254&amp;nbsp; |&amp;nbsp; CCIE-RS #15721&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Oct 2017 14:09:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/tagged-subinterface-in-different-zone-than-parent-not-working/m-p/181497#M56053</guid>
      <dc:creator>nawaza</dc:creator>
      <dc:date>2017-10-12T14:09:45Z</dc:date>
    </item>
    <item>
      <title>Re: Tagged subinterface in different zone than parent not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/tagged-subinterface-in-different-zone-than-parent-not-working/m-p/182830#M56272</link>
      <description>&lt;P&gt;I think I figgured out why this is happeing..&amp;nbsp; I have a Layer 3 core switch that sits in front of the PA and does inter VLAN routing.&amp;nbsp; The only route it has to the interwebs is it's default gateway which is the 192.168.10.2&amp;nbsp; address of the parent interface on the PA.&amp;nbsp; &amp;nbsp;This setup works and VLAN traffic makes it's way to the interwebs.&amp;nbsp; If I remove the Tagged subinterface for a VALN from the config,&amp;nbsp; traffic for that VALN stops at the 192.168.10.2 interface.&amp;nbsp; &amp;nbsp;To be 100% honest I'm not clear on WHY this actually works, tagged VLAN traffic is being forwarded to an untagged interface, perhaps it has to be with the way PA is doing the subinterface?&amp;nbsp; &amp;nbsp;Anyhow,&amp;nbsp; I think for this to work the way I want it to, traffic from each VLAN needs to be forwarded to the subinterface.&amp;nbsp; The only way I can come up with to do this, and leave the core layer 3 switch doing inter VLAN routing, is to move to Policy Based Routing.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Oct 2017 19:47:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/tagged-subinterface-in-different-zone-than-parent-not-working/m-p/182830#M56272</guid>
      <dc:creator>razor192</dc:creator>
      <dc:date>2017-10-19T19:47:14Z</dc:date>
    </item>
    <item>
      <title>Re: Tagged subinterface in different zone than parent not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/tagged-subinterface-in-different-zone-than-parent-not-working/m-p/182835#M56273</link>
      <description>&lt;P&gt;this is the pertanant config from the core switch.&amp;nbsp; &amp;nbsp;and the sub interface on the PA&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ip route 0.0.0.0 0.0.0.0 192.168.10.2&lt;BR /&gt;ip routing&lt;BR /&gt;interface 1&lt;BR /&gt;name "To PA Eth 2"&lt;BR /&gt;exit&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;vlan 66&lt;BR /&gt;name "UnSecuteWiFi-66"&lt;BR /&gt;tagged 1,A1&lt;BR /&gt;ip address 10.10.66.1 255.255.255.0&lt;BR /&gt;ip helper-address 192.168.10.216&lt;BR /&gt;exit&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="sub interface config.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/12021i730ACCF2EC136F02/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="sub interface config.PNG" alt="sub interface config.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Oct 2017 20:15:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/tagged-subinterface-in-different-zone-than-parent-not-working/m-p/182835#M56273</guid>
      <dc:creator>razor192</dc:creator>
      <dc:date>2017-10-19T20:15:14Z</dc:date>
    </item>
    <item>
      <title>Re: Tagged subinterface in different zone than parent not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/tagged-subinterface-in-different-zone-than-parent-not-working/m-p/182872#M56275</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/4441"&gt;@razor192&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Your text and screen shot Zones do not match up. If you haveyour source zone set as&amp;nbsp;&lt;SPAN&gt;UnSecuteWiFi-66, you should be ableto create policies around that.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Hope that helps.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Oct 2017 21:24:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/tagged-subinterface-in-different-zone-than-parent-not-working/m-p/182872#M56275</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2017-10-19T21:24:45Z</dc:date>
    </item>
    <item>
      <title>Re: Tagged subinterface in different zone than parent not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/tagged-subinterface-in-different-zone-than-parent-not-working/m-p/182874#M56277</link>
      <description>&lt;P&gt;the 1st screen cap is a nonworking config..&amp;nbsp; &amp;nbsp;the second screen cap is a working config&lt;/P&gt;</description>
      <pubDate>Thu, 19 Oct 2017 21:37:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/tagged-subinterface-in-different-zone-than-parent-not-working/m-p/182874#M56277</guid>
      <dc:creator>razor192</dc:creator>
      <dc:date>2017-10-19T21:37:23Z</dc:date>
    </item>
    <item>
      <title>Re: Tagged subinterface in different zone than parent not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/tagged-subinterface-in-different-zone-than-parent-not-working/m-p/182876#M56279</link>
      <description>&lt;P&gt;One other thing we do to cut down on the nmber of Zones, is to use Zones and Source IP's. That way you can write a rule with source zone and ip range.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just another thought.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Oct 2017 21:39:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/tagged-subinterface-in-different-zone-than-parent-not-working/m-p/182876#M56279</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2017-10-19T21:39:17Z</dc:date>
    </item>
  </channel>
</rss>

