<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Native VLAN configuration in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/native-vlan-configuration/m-p/754#M592</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would expect things to stop working after the native vlan command had been issued as from then on, traffic would be tagged from PA&amp;gt;Cisco and untagged from Cisco&amp;gt;PA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have you tried configuring your PA with a L2 port untagged assigned to VLAN 888?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Dave &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 27 Jul 2011 09:28:43 GMT</pubDate>
    <dc:creator>DavePalo</dc:creator>
    <dc:date>2011-07-27T09:28:43Z</dc:date>
    <item>
      <title>Native VLAN configuration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/native-vlan-configuration/m-p/749#M587</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have configured a&amp;nbsp; couple of layer-3 subinterfaces on a aggregate, they are tagged as VLAN 700 and VLAN 800, in my cisco switch I have configured a trunk port that permits VLAN 700 and VLAN 800 to pass traffic across it. When plugged in, everything comes up just fine and I'm able to ping both interfaces etc etc.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As soon as I add a&amp;nbsp; native vlan to the trunk port the switch shuts it's interfaces down and stops passing traffic (due to a native vlan mismatch obviously) how do I configure a native vlan other than vlan 1 on a layer-3 interface on the palo alto.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Using VLAN 1 is NOT an option.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Jul 2011 22:48:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/native-vlan-configuration/m-p/749#M587</guid>
      <dc:creator>bjaming</dc:creator>
      <dc:date>2011-07-18T22:48:00Z</dc:date>
    </item>
    <item>
      <title>Re: Native VLAN configuration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/native-vlan-configuration/m-p/750#M588</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Bjaming,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you add a native vlan other then VLAN1 on the switch, then you might want to configure the same vlan tag&amp;nbsp; as configured on the trunk port on the switch on the ae interface on the PA firewall as well to see if that keeps the interface on the switch side up.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do please let us know if this works for you. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Jul 2011 14:37:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/native-vlan-configuration/m-p/750#M588</guid>
      <dc:creator>mrajdev</dc:creator>
      <dc:date>2011-07-19T14:37:39Z</dc:date>
    </item>
    <item>
      <title>Re: Native VLAN configuration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/native-vlan-configuration/m-p/751#M589</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In the example above I mentioned VLAN 800 and 700, on the firewall I configured 2 layer-3 tagged sub-interfaces, one was tagged .800 the other was tagged .700&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the switch when I set the native VLAN as 700 (for example) traffic was no longer forwarded from the switch because the firewall, even though it was tagging traffic for VLAN 700 and 800 did not have the correct native VLAN configured on it's interfaces.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In effect I already tried that, and even though there was a sub-interface configured with the correct VLAN tag the switch still shut down the interfaces.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for the suggestion.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Jul 2011 15:59:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/native-vlan-configuration/m-p/751#M589</guid>
      <dc:creator>bjaming</dc:creator>
      <dc:date>2011-07-19T15:59:17Z</dc:date>
    </item>
    <item>
      <title>Re: Native VLAN configuration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/native-vlan-configuration/m-p/752#M590</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Okay just to simplify things,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've removed the second vlan&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have created a VLAN named 888 with an ip on the switch side of 10.8.8.2/24&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the interface configs are as follows&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;int g1/1/1&lt;/P&gt;&lt;P&gt;switchport trunk encapsulation dot1q&lt;/P&gt;&lt;P&gt;switchport mode trunk&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;int vlan 888&lt;/P&gt;&lt;P&gt;ip address 10.8.8.2 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;on the firewall&lt;/P&gt;&lt;P&gt;ethernet 1/3&lt;/P&gt;&lt;P&gt;link-speed auto;&lt;/P&gt;&lt;P&gt;link-duplex auto;&lt;/P&gt;&lt;P&gt;link-state auto;&lt;/P&gt;&lt;P&gt;layer3 {&lt;/P&gt;&lt;P&gt;&amp;nbsp; mtu1500;&lt;/P&gt;&lt;P&gt;&amp;nbsp; interface-management-profile ping-allowed;&lt;/P&gt;&lt;P&gt;ipv6 {&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; enabled no;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; }&lt;/P&gt;&lt;P&gt;}&lt;/P&gt;&lt;P&gt;units {&lt;/P&gt;&lt;P&gt;ethernet 1/3.888 {&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; mtu 1500;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; interface-management-profile ping-allowed;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; tag 888;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; ip {&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.8.8.1/24 { }&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; }&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; ipv6 {&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; enabled no;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; }&lt;/P&gt;&lt;P&gt;}&lt;/P&gt;&lt;P&gt;}&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Configured like that I am able to ping, no problems&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I apply&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;switchport trunk native vlan 888&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;to interface g1/1/1 I am no longer able to ping.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How do I configure native VLAN tagging on a 4020?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do I need to open a support ticket in order to get a resolution?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Jul 2011 16:36:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/native-vlan-configuration/m-p/752#M590</guid>
      <dc:creator>bjaming</dc:creator>
      <dc:date>2011-07-21T16:36:58Z</dc:date>
    </item>
    <item>
      <title>Re: Native VLAN configuration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/native-vlan-configuration/m-p/753#M591</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;To get a better understanding of how you are trying to deploy this please open a case. the native vlan should be untag and should not have any problems. we may want to see what errors are generated on the palo alto interface.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 23 Jul 2011 00:23:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/native-vlan-configuration/m-p/753#M591</guid>
      <dc:creator>jnguyen</dc:creator>
      <dc:date>2011-07-23T00:23:28Z</dc:date>
    </item>
    <item>
      <title>Re: Native VLAN configuration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/native-vlan-configuration/m-p/754#M592</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would expect things to stop working after the native vlan command had been issued as from then on, traffic would be tagged from PA&amp;gt;Cisco and untagged from Cisco&amp;gt;PA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have you tried configuring your PA with a L2 port untagged assigned to VLAN 888?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Dave &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Jul 2011 09:28:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/native-vlan-configuration/m-p/754#M592</guid>
      <dc:creator>DavePalo</dc:creator>
      <dc:date>2011-07-27T09:28:43Z</dc:date>
    </item>
    <item>
      <title>Re: Native VLAN configuration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/native-vlan-configuration/m-p/755#M593</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry I've been on vacation (blackhat/defcon) I'll try an untagged l2 interface and get back to you guys, thanks for the help! &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Aug 2011 16:46:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/native-vlan-configuration/m-p/755#M593</guid>
      <dc:creator>bjaming</dc:creator>
      <dc:date>2011-08-09T16:46:32Z</dc:date>
    </item>
    <item>
      <title>Re: Native VLAN configuration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/native-vlan-configuration/m-p/756#M594</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Did that work in the end?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Dave &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Oct 2011 08:31:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/native-vlan-configuration/m-p/756#M594</guid>
      <dc:creator>DavePalo</dc:creator>
      <dc:date>2011-10-20T08:31:36Z</dc:date>
    </item>
  </channel>
</rss>

