<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to configure the firewall so that all traffic goes in and out through it? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-configure-the-firewall-so-that-all-traffic-goes-in-and/m-p/196374#M58494</link>
    <description>&lt;P&gt;If all your internal servers will get a private IP on their physical interface and have the firewall perform NAT, then your layer3 design will work perfectly&lt;/P&gt;
&lt;P&gt;If it is your intention to assign each host a public IP on it's interface, then you may need to consider a vwire or layer2 design&lt;/P&gt;</description>
    <pubDate>Tue, 23 Jan 2018 10:47:49 GMT</pubDate>
    <dc:creator>reaper</dc:creator>
    <dc:date>2018-01-23T10:47:49Z</dc:date>
    <item>
      <title>How to configure the firewall so that all traffic goes in and out through it?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-configure-the-firewall-so-that-all-traffic-goes-in-and/m-p/196349#M58490</link>
      <description>&lt;P&gt;Hello, everybody.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am configuring a VM-300 Virtual Firewall on a KVM installed in CentOS.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The dedicated server where the virtual firewall is installed has two network cards.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;One of which connects to the Internet and the other with which it connects to a switch to which other servers are connected.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My intention is for all incoming and outgoing traffic to pass through the firewall.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="DRAW.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/13362i273F64AA63B56DCE/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="DRAW.png" alt="DRAW.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Certainly all servers, have their own public ip, and their future virtualized systems in them will also have their public ips.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can someone please tell me what kind of configuration would be appropriate for this scenario?&lt;/P&gt;&lt;P&gt;For the moment, without being very sure I have thought that I should follow a Layer3 configuration, and I am doing steps as they are referred to in this guide.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A title="Getting-Started-Layer-3-NAT-and-DHCP" href="https://live.paloaltonetworks.com/t5/Featured-Articles/Getting-Started-Layer-3-NAT-and-DHCP/ta-p/66999" target="_blank"&gt;Getting-Started-Layer-3-NAT-and-DHCP&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Am I on the right track or will this guide not apply to my scenario?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Greetings and thanks&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jan 2018 08:23:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-configure-the-firewall-so-that-all-traffic-goes-in-and/m-p/196349#M58490</guid>
      <dc:creator>javihere</dc:creator>
      <dc:date>2018-01-23T08:23:08Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure the firewall so that all traffic goes in and out through it?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-configure-the-firewall-so-that-all-traffic-goes-in-and/m-p/196374#M58494</link>
      <description>&lt;P&gt;If all your internal servers will get a private IP on their physical interface and have the firewall perform NAT, then your layer3 design will work perfectly&lt;/P&gt;
&lt;P&gt;If it is your intention to assign each host a public IP on it's interface, then you may need to consider a vwire or layer2 design&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jan 2018 10:47:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-configure-the-firewall-so-that-all-traffic-goes-in-and/m-p/196374#M58494</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2018-01-23T10:47:49Z</dc:date>
    </item>
  </channel>
</rss>

