<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Apply Policies to a subnet in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/apply-policies-to-a-subnet/m-p/191553#M57681</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/22936"&gt;@msgroup&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;If done properly there isn't any reason why you wouldn't be able to setup the DHCP to hand out the available public IPs, and then setup a couple layer2 interfaces on the PA to actually gain all of the functionality of the firewall. NAT would really be the best solution however, and if you setup a NAT policy properly I've never really had an issue with IPSec tunnels.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 13 Dec 2017 15:46:55 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2017-12-13T15:46:55Z</dc:date>
    <item>
      <title>Apply Policies to a subnet</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/apply-policies-to-a-subnet/m-p/191437#M57661</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;New here so I hope this is right spot for this question.&lt;/P&gt;&lt;P&gt;I have a router from an ISP that is giving a public /28 subnet out its lan port. (Nat off)&lt;/P&gt;&lt;P&gt;I can't easily replace the device for a couple of reasons.&lt;/P&gt;&lt;P&gt;I wish to run the traffic from this through my PA so I can apply policies to the other devices I will place on this subnet.&lt;/P&gt;&lt;P&gt;A Virtual Wire would work but wouldn't give me any layer 3 control - as I understand it.&lt;/P&gt;&lt;P&gt;I tried a ingress and egress interface in a test virtual router but this can't work because the subnets overlap.&lt;/P&gt;&lt;P&gt;Any ideas?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Peter&lt;/P&gt;</description>
      <pubDate>Wed, 13 Dec 2017 00:01:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/apply-policies-to-a-subnet/m-p/191437#M57661</guid>
      <dc:creator>msgroup</dc:creator>
      <dc:date>2017-12-13T00:01:13Z</dc:date>
    </item>
    <item>
      <title>Re: Apply Policies to a subnet</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/apply-policies-to-a-subnet/m-p/191444#M57662</link>
      <description>&lt;P&gt;You could put all the devices behind the PAN and NAT them through it.&amp;nbsp; Put all the public IPs on the firewall and use rules for incoming traffic.&lt;/P&gt;&lt;P&gt;Definately not the only option but it would be a good way of controlling all the traffic.&amp;nbsp; This would require:&lt;/P&gt;&lt;P&gt;* Security Policies&lt;/P&gt;&lt;P&gt;* NAT Policies&lt;/P&gt;&lt;P&gt;* Internal &amp;amp; External Zones&lt;/P&gt;&lt;P&gt;* Private IP subnet (DHCP or no)&lt;/P&gt;&lt;P&gt;Internet &amp;lt;--&amp;gt; Vendor Router &amp;lt;--&amp;gt; PAN &amp;lt;--&amp;gt; Servers/hardware&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Brian&lt;/P&gt;</description>
      <pubDate>Wed, 13 Dec 2017 00:24:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/apply-policies-to-a-subnet/m-p/191444#M57662</guid>
      <dc:creator>BrianRa</dc:creator>
      <dc:date>2017-12-13T00:24:43Z</dc:date>
    </item>
    <item>
      <title>Re: Apply Policies to a subnet</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/apply-policies-to-a-subnet/m-p/191445#M57663</link>
      <description>&lt;P&gt;HI thanks for the reply.&lt;/P&gt;&lt;P&gt;Didn't really want to go down the NAT path as some of the devices will use IPSEC.&lt;/P&gt;&lt;P&gt;Some don't of course and those are the ones you really need to monitor.&lt;/P&gt;&lt;P&gt;Agreed though NAT would make the job simple.&lt;/P&gt;&lt;P&gt;Peter&lt;/P&gt;</description>
      <pubDate>Wed, 13 Dec 2017 00:35:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/apply-policies-to-a-subnet/m-p/191445#M57663</guid>
      <dc:creator>msgroup</dc:creator>
      <dc:date>2017-12-13T00:35:34Z</dc:date>
    </item>
    <item>
      <title>Re: Apply Policies to a subnet</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/apply-policies-to-a-subnet/m-p/191553#M57681</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/22936"&gt;@msgroup&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;If done properly there isn't any reason why you wouldn't be able to setup the DHCP to hand out the available public IPs, and then setup a couple layer2 interfaces on the PA to actually gain all of the functionality of the firewall. NAT would really be the best solution however, and if you setup a NAT policy properly I've never really had an issue with IPSec tunnels.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Dec 2017 15:46:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/apply-policies-to-a-subnet/m-p/191553#M57681</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-12-13T15:46:55Z</dc:date>
    </item>
    <item>
      <title>Re: Apply Policies to a subnet</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/apply-policies-to-a-subnet/m-p/191567#M57685</link>
      <description>&lt;P&gt;I believe when using NAT and IPSEC Tunnels we needed to do PBFs (Policy Based Forward).&amp;nbsp; That may have been our environment as not everything was in the Virtual Routers default routes (you could probably put everything there?).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It is probably possible to use the firewall as the gateway for the rest of the public IPs (creating rules that way) and just hand them out but I think the return route will be a problem as the ISP gateway is in the same subnet and will want to send return traffic directly to the devices. &lt;STRONG&gt;BPry&lt;/STRONG&gt; is probably right about using firewall interfaces (or a switch off of one of the interfaces) and passing the traffic through the firewall and setting up Security Policies based on the IPs.&amp;nbsp; I have not played with this however.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Brian&lt;/P&gt;</description>
      <pubDate>Wed, 13 Dec 2017 16:57:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/apply-policies-to-a-subnet/m-p/191567#M57685</guid>
      <dc:creator>BrianRa</dc:creator>
      <dc:date>2017-12-13T16:57:01Z</dc:date>
    </item>
    <item>
      <title>Re: Apply Policies to a subnet</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/apply-policies-to-a-subnet/m-p/191623#M57690</link>
      <description>&lt;P&gt;Thanks for the replies.&lt;/P&gt;&lt;P&gt;Looks like Nat. Policy Forwarding Rules are probaby a good idea anyway. It least it not production yet so I can play.&lt;/P&gt;&lt;P&gt;I don't anticipate any real issue just though there may have been a simple more elegant solution I hadn't seen.&lt;/P&gt;&lt;P&gt;Peter&lt;/P&gt;</description>
      <pubDate>Wed, 13 Dec 2017 21:33:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/apply-policies-to-a-subnet/m-p/191623#M57690</guid>
      <dc:creator>msgroup</dc:creator>
      <dc:date>2017-12-13T21:33:56Z</dc:date>
    </item>
    <item>
      <title>Re: Apply Policies to a subnet</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/apply-policies-to-a-subnet/m-p/191646#M57696</link>
      <description>&lt;P&gt;NAT has worked well for us.&amp;nbsp; You may not need to use PBFs if you put everything in the VS default routes.&amp;nbsp; Its the Security Policies and the NAT Policies that will be required.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Good luck with the project.&lt;/P&gt;&lt;P&gt;Brian&lt;/P&gt;</description>
      <pubDate>Thu, 14 Dec 2017 00:52:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/apply-policies-to-a-subnet/m-p/191646#M57696</guid>
      <dc:creator>BrianRa</dc:creator>
      <dc:date>2017-12-14T00:52:54Z</dc:date>
    </item>
  </channel>
</rss>

