<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Apply policy security on vlan in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/apply-policy-security-on-vlan/m-p/185919#M56814</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/73785"&gt;@hamza_ineos&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Personally, I don't think it's a matter of which is best practice ...&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Both are valid ways to configure.&amp;nbsp; You'll just need to decide on a design that best fits your network and configure the firewall/switch accordingly.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers !&lt;/P&gt;
&lt;P&gt;-Kiwi.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 08 Nov 2017 08:40:15 GMT</pubDate>
    <dc:creator>kiwi</dc:creator>
    <dc:date>2017-11-08T08:40:15Z</dc:date>
    <item>
      <title>Apply policy security on vlan</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/apply-policy-security-on-vlan/m-p/185727#M56787</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;Plz i need ansewr as soon as possible, can i apply the security policy rule on vlans ? for exepmle let vlan 10 connect to facebook, but bloc facebook for vlan20 ??&lt;/P&gt;</description>
      <pubDate>Tue, 07 Nov 2017 12:13:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/apply-policy-security-on-vlan/m-p/185727#M56787</guid>
      <dc:creator>hamza_ineos</dc:creator>
      <dc:date>2017-11-07T12:13:31Z</dc:date>
    </item>
    <item>
      <title>Re: Apply policy security on vlan</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/apply-policy-security-on-vlan/m-p/185750#M56791</link>
      <description>&lt;P&gt;Hi Hamza,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Short answer is yes you can. Does the different vlans have different zones ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;If they do just apply the src zone as required in your rules.&amp;nbsp;&lt;/P&gt;&lt;P&gt;If they don't can seperate it using an address object range if the vlans have different subnets.&amp;nbsp;&lt;/P&gt;&lt;P&gt;ref :&amp;nbsp;&lt;/P&gt;&lt;P&gt;here's a link of a guy setting up a pa-200, using vlans and rules for the vlan&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Configuration-Articles/Setting-Up-the-PA-200-for-Home-and-Small-Office/ta-p/61838" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Configuration-Articles/Setting-Up-the-PA-200-for-Home-and-Small-Office/ta-p/61838&lt;/A&gt;&lt;/P&gt;&lt;P&gt;here's a link for creating address range if no seperate zones for the vlans&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/71/pan-os/web-interface-help/objects/objects-addresses" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/71/pan-os/web-interface-help/objects/objects-addresses&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;cheers&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rob&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Nov 2017 13:10:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/apply-policy-security-on-vlan/m-p/185750#M56791</guid>
      <dc:creator>DonohoeRobert</dc:creator>
      <dc:date>2017-11-07T13:10:50Z</dc:date>
    </item>
    <item>
      <title>Re: Apply policy security on vlan</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/apply-policy-security-on-vlan/m-p/185751#M56792</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/73785"&gt;@hamza_ineos&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yes you can.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Just use different zones per vlan and you can control your policies based on those zones.&lt;/P&gt;
&lt;P&gt;The following getting started guides should be very helpful for you :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Featured-Articles/Getting-Started-Layer-2-Interfaces/ta-p/68229" target="_blank"&gt;Getting-Started-Layer-2-Interfaces&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Featured-Articles/Getting-Started-Layer-3-Subinterfaces/ta-p/67395" target="_blank"&gt;Getting-Started-Layer-3-Subinterfaces&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers !&lt;/P&gt;
&lt;P&gt;-Kiwi.&lt;/P&gt;</description>
      <pubDate>Tue, 07 Nov 2017 13:11:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/apply-policy-security-on-vlan/m-p/185751#M56792</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2017-11-07T13:11:28Z</dc:date>
    </item>
    <item>
      <title>Re: Apply policy security on vlan</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/apply-policy-security-on-vlan/m-p/185829#M56806</link>
      <description>&lt;P&gt;thank you very much brothers&lt;/P&gt;&lt;P&gt;i still have some questions plz,&amp;nbsp;we have 2 scénarios in our deployment:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1-creating the vlan in PaloAlto firwall, and then manage it from the firewall.&lt;/P&gt;&lt;P&gt;2-or create the vlans on the cisco switch, in this case can the firwall apply the security rule on the vlans created in cisco switch ? (Important question).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;witch of the this 2 sénarios is the best practice ??&amp;nbsp;&lt;/P&gt;&lt;P&gt;plz if it's possible give me what the&amp;nbsp;advantage/disadvantage of creating vlan on paloalto and not on cisco switch !!&lt;/P&gt;&lt;P&gt;and what&amp;nbsp;&lt;SPAN&gt;the&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;advantage/&lt;/SPAN&gt;&lt;SPAN&gt;disadvantage of creating vlan on&amp;nbsp;cisco switch and not on&amp;nbsp;paloalto&amp;nbsp;!!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Nov 2017 22:12:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/apply-policy-security-on-vlan/m-p/185829#M56806</guid>
      <dc:creator>hamza_ineos</dc:creator>
      <dc:date>2017-11-07T22:12:40Z</dc:date>
    </item>
    <item>
      <title>Re: Apply policy security on vlan</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/apply-policy-security-on-vlan/m-p/185919#M56814</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/73785"&gt;@hamza_ineos&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Personally, I don't think it's a matter of which is best practice ...&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Both are valid ways to configure.&amp;nbsp; You'll just need to decide on a design that best fits your network and configure the firewall/switch accordingly.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers !&lt;/P&gt;
&lt;P&gt;-Kiwi.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Nov 2017 08:40:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/apply-policy-security-on-vlan/m-p/185919#M56814</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2017-11-08T08:40:15Z</dc:date>
    </item>
    <item>
      <title>Re: Apply policy security on vlan</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/apply-policy-security-on-vlan/m-p/185932#M56818</link>
      <description>&lt;P&gt;thnk for you ansewr bro &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Then if i&amp;nbsp;&lt;SPAN&gt;create the vlans on the cisco switch, in this case can the firwall apply the security rule on the vlans created in cisco switch ?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Nov 2017 09:09:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/apply-policy-security-on-vlan/m-p/185932#M56818</guid>
      <dc:creator>hamza_ineos</dc:creator>
      <dc:date>2017-11-08T09:09:12Z</dc:date>
    </item>
    <item>
      <title>Re: Apply policy security on vlan</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/apply-policy-security-on-vlan/m-p/185933#M56819</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/73785"&gt;@hamza_ineos&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yes, you can use tags and zones for this.&lt;/P&gt;
&lt;P&gt;It's explained in the 2nd link I posted earlier :&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/Featured-Articles/Getting-Started-Layer-3-Subinterfaces/ta-p/67395" target="_self"&gt;Getting-Started-Layer-3-Subinterfaces&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers !&lt;/P&gt;
&lt;P&gt;-Kiwi.&lt;/P&gt;</description>
      <pubDate>Wed, 08 Nov 2017 09:17:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/apply-policy-security-on-vlan/m-p/185933#M56819</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2017-11-08T09:17:43Z</dc:date>
    </item>
    <item>
      <title>Re: Apply policy security on vlan</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/apply-policy-security-on-vlan/m-p/185957#M56822</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11943"&gt;@kiwi&lt;/a&gt;&lt;/P&gt;&lt;P&gt;Thank very much for help!&lt;/P&gt;&lt;P&gt;this tutorial is very nice, but i have a question, i see in the toturial that we must give an ip adresse for the vlan(in paloalto), this adresse ip is the same that i gave it to this vlan when i created in cisco switch ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ex: i create a vlan10 on cisco switch with ip adresse: 10.1.1.1/24, then i must create a subinterface in palo alto with the tag 10, and the adresse ip :&amp;nbsp;&lt;SPAN&gt;10.1.1.1/24 ??&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;thanks a lot&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Nov 2017 10:49:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/apply-policy-security-on-vlan/m-p/185957#M56822</guid>
      <dc:creator>hamza_ineos</dc:creator>
      <dc:date>2017-11-08T10:49:48Z</dc:date>
    </item>
    <item>
      <title>Re: Apply policy security on vlan</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/apply-policy-security-on-vlan/m-p/185996#M56828</link>
      <description>&lt;P&gt;where are you brother&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11943"&gt;@kiwi&lt;/a&gt;&amp;nbsp;, plz i need answer for my previous question&lt;/P&gt;</description>
      <pubDate>Wed, 08 Nov 2017 15:17:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/apply-policy-security-on-vlan/m-p/185996#M56828</guid>
      <dc:creator>hamza_ineos</dc:creator>
      <dc:date>2017-11-08T15:17:23Z</dc:date>
    </item>
    <item>
      <title>Re: Apply policy security on vlan</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/apply-policy-security-on-vlan/m-p/186049#M56839</link>
      <description>&lt;P&gt;Hi Mate,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;someone asked a similiar question below here; [check out the comments at the bottom]&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Featured-Articles/Getting-Started-Layer-3-Subinterfaces/ta-p/67395" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Featured-Articles/Getting-Started-Layer-3-Subinterfaces/ta-p/67395&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;generally can always test it one way or the other if not sure. best way to learn aswell.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;cheers&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;rob&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Nov 2017 21:48:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/apply-policy-security-on-vlan/m-p/186049#M56839</guid>
      <dc:creator>DonohoeRobert</dc:creator>
      <dc:date>2017-11-08T21:48:32Z</dc:date>
    </item>
    <item>
      <title>Re: Apply policy security on vlan</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/apply-policy-security-on-vlan/m-p/186171#M56856</link>
      <description>&lt;P&gt;thank you very much bro &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Nov 2017 10:11:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/apply-policy-security-on-vlan/m-p/186171#M56856</guid>
      <dc:creator>hamza_ineos</dc:creator>
      <dc:date>2017-11-09T10:11:28Z</dc:date>
    </item>
  </channel>
</rss>

