<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PaloAlto WAN Interface segmentation in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/paloalto-wan-interface-segmentation/m-p/200014#M59202</link>
    <description>&lt;P&gt;Thank you very much brother, it was very helpful&lt;/P&gt;</description>
    <pubDate>Mon, 12 Feb 2018 10:43:37 GMT</pubDate>
    <dc:creator>hamza-zidane</dc:creator>
    <dc:date>2018-02-12T10:43:37Z</dc:date>
    <item>
      <title>PaloAlto WAN Interface segmentation</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/paloalto-wan-interface-segmentation/m-p/199941#M59187</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please help me in this scenario&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There is the big "Company Site" and the other branches point to this Site, there is an MPLS connection between the branches.&lt;/P&gt;&lt;P&gt;Our need is, the PaloAlto supports segmentation on the WAN part ? can we create a sub-interfaces in the connected interface (MPLS) at the big headquarters, and each sub-interface communicates with a VRF separately.&lt;/P&gt;&lt;P&gt;(NB: Our Client has in WAN side 3 VRF )&lt;BR /&gt;Ex:&lt;BR /&gt;GAB traffic is coming out of the WAN sub-interface by VRF GAB ...&lt;BR /&gt;Traffic production sub-interface WAN by VRF production ...&lt;/P&gt;&lt;P&gt;What I need just a confirmation that on the port Wan PaloAlto supports the segmentation? because in the LAN port I already create sub-interfaces and each sub-interface communicate with his VRF but that on the LAN port, I 'm not sure if the case for the WAN port.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="VRF WAN.jpg" style="width: 829px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/13773i0A86A4362165E0D4/image-dimensions/829x345/is-moderation-mode/true?v=v2" width="829" height="345" role="button" title="VRF WAN.jpg" alt="VRF WAN.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 11 Feb 2018 15:04:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/paloalto-wan-interface-segmentation/m-p/199941#M59187</guid>
      <dc:creator>hamza-zidane</dc:creator>
      <dc:date>2018-02-11T15:04:23Z</dc:date>
    </item>
    <item>
      <title>Re: PaloAlto WAN Interface segmentation</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/paloalto-wan-interface-segmentation/m-p/199991#M59195</link>
      <description>&lt;P&gt;The Palo Alto Networks firewall does not diufferentiate between lan or wan interfaces, only the technology 'mode' it is set to, so it supports layer2, layer3 or vwire (and some others but let's just stick to these)&lt;/P&gt;
&lt;P&gt;So your MPLS provider will need to transform the traffic to match one of these technologies (we can't terminate mpls on the firewall)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;All of these interface types are capable of supporting tagged sub interfaces where you segregate all connected networks using vlan tags&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;so if your WAN provider supports separating each VRF with a unique VLAN tag, you can perfectly create tagged subinterfaces on your 'wan' layer3 interface and even provide each VRF with it's own zone (if so desired) to provide ganular security zones per remote network&lt;/P&gt;</description>
      <pubDate>Mon, 12 Feb 2018 07:34:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/paloalto-wan-interface-segmentation/m-p/199991#M59195</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2018-02-12T07:34:22Z</dc:date>
    </item>
    <item>
      <title>Re: PaloAlto WAN Interface segmentation</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/paloalto-wan-interface-segmentation/m-p/200014#M59202</link>
      <description>&lt;P&gt;Thank you very much brother, it was very helpful&lt;/P&gt;</description>
      <pubDate>Mon, 12 Feb 2018 10:43:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/paloalto-wan-interface-segmentation/m-p/200014#M59202</guid>
      <dc:creator>hamza-zidane</dc:creator>
      <dc:date>2018-02-12T10:43:37Z</dc:date>
    </item>
  </channel>
</rss>

