<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Configuration of PA's - Internet Circuits in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/configuration-of-pa-s-internet-circuits/m-p/190962#M57599</link>
    <description>I really appreciate your answer.&lt;BR /&gt;&lt;BR /&gt;See that’s the thing, I can’t assign the sub interface the IP address on each individual Palo. So I went onto the panorama and assigned it to the device template and pushed it. However when I log into each PA, I still don’t see the IP address assigned. I thought this was part of where my problem was. Do I have to do anything special in panorama so it pushes the IPs to each device sub interface ? Thanks again</description>
    <pubDate>Sun, 10 Dec 2017 23:01:09 GMT</pubDate>
    <dc:creator>szannikos</dc:creator>
    <dc:date>2017-12-10T23:01:09Z</dc:date>
    <item>
      <title>Configuration of PA's - Internet Circuits</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/configuration-of-pa-s-internet-circuits/m-p/190939#M57597</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2017-12-09_19-34-15.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/12920iCCC569F454762314/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="2017-12-09_19-34-15.png" alt="2017-12-09_19-34-15.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Folks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm new to the PA's, so I wanted to present this question for you.&amp;nbsp; I have two PA 5020's, in Active/Passive configuration shown above.&amp;nbsp; On each PA, eth1/4 and eth1/5 is in an aggregate group.&amp;nbsp; I have two Nexus 9504's as our core switches.&amp;nbsp; I two layer 2 VLAN's created.&amp;nbsp; One for each of our internet circuits.&amp;nbsp; I've created vPC for each of the interfaces for the port channels.&amp;nbsp; On the PA's, I've IP'd each aggregate sub-interface with the respective IP for each of the internet circuits.&amp;nbsp; Let's say that I have subinterface 299 and 300.&amp;nbsp; Sub-interface 299 is 1.1.1.2/30, and Sub-interface 300 is 2.2.2.2/30.&amp;nbsp; When I add a default 0 route, on the Nexus core swithces, that points to the public address of VLAN 299, the route doesn't add to the route table.&amp;nbsp; I'm assuming this is because the ARP table doesn't contain the public IP of the internet circuits.&amp;nbsp; Was wondering if anyone had any luck with this type of configuration, and if there was any insight you could give for this type of setup.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Dec 2017 00:44:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/configuration-of-pa-s-internet-circuits/m-p/190939#M57597</guid>
      <dc:creator>szannikos</dc:creator>
      <dc:date>2017-12-10T00:44:14Z</dc:date>
    </item>
    <item>
      <title>Re: Configuration of PA's - Internet Circuits</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/configuration-of-pa-s-internet-circuits/m-p/190960#M57598</link>
      <description>&lt;P&gt;In order for routes to be active the next hop has to be reachable.&amp;nbsp; So if you want to use vlan 299 and your default route the next hop in your example would be&amp;nbsp;&lt;SPAN&gt;1.1.1.2 on the PA interface.&amp;nbsp; This will be reachable on the Nexus and the route will be active.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Dec 2017 22:21:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/configuration-of-pa-s-internet-circuits/m-p/190960#M57598</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2017-12-10T22:21:03Z</dc:date>
    </item>
    <item>
      <title>Re: Configuration of PA's - Internet Circuits</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/configuration-of-pa-s-internet-circuits/m-p/190962#M57599</link>
      <description>I really appreciate your answer.&lt;BR /&gt;&lt;BR /&gt;See that’s the thing, I can’t assign the sub interface the IP address on each individual Palo. So I went onto the panorama and assigned it to the device template and pushed it. However when I log into each PA, I still don’t see the IP address assigned. I thought this was part of where my problem was. Do I have to do anything special in panorama so it pushes the IPs to each device sub interface ? Thanks again</description>
      <pubDate>Sun, 10 Dec 2017 23:01:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/configuration-of-pa-s-internet-circuits/m-p/190962#M57599</guid>
      <dc:creator>szannikos</dc:creator>
      <dc:date>2017-12-10T23:01:09Z</dc:date>
    </item>
    <item>
      <title>Re: Configuration of PA's - Internet Circuits</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/configuration-of-pa-s-internet-circuits/m-p/191324#M57645</link>
      <description>&lt;P&gt;I haven't used Panorama in a while, so I'm not sure about the current interface.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Templates and groups are where you put settings that will be on multiple devices.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For settings like this that are specific to the individual device you change context to the specific PA in Panorama and then configure the setting there.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Dec 2017 13:47:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/configuration-of-pa-s-internet-circuits/m-p/191324#M57645</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2017-12-12T13:47:16Z</dc:date>
    </item>
  </channel>
</rss>

