<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Creating a duplicate network? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/creating-a-duplicate-network/m-p/206472#M60588</link>
    <description>&lt;P&gt;This may be possible by creating multiple VSYS and then a transit zone, but I would be really careful&amp;nbsp;with having the same IP subnets on the same firewall in the same VSYS.&amp;nbsp; We ran into an issue where we had the same public facing network on outside multiple interfaces and ran into an issue where bi-directional NAT feature did not work as it would randomly chose to start advertising the MAC address on an interface that did not have rules for that particular NATed IP.&amp;nbsp; We had to then create both inbound and outbound&amp;nbsp;NAT rules.&amp;nbsp; Not even sure how this would look or what potential issues you could run into.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In our case we have a separate&amp;nbsp;firewall for sandbox&amp;nbsp;testing.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- Matt&lt;/P&gt;</description>
    <pubDate>Mon, 19 Mar 2018 20:54:50 GMT</pubDate>
    <dc:creator>mlinsemier</dc:creator>
    <dc:date>2018-03-19T20:54:50Z</dc:date>
    <item>
      <title>Creating a duplicate network?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/creating-a-duplicate-network/m-p/206457#M60585</link>
      <description>&lt;P&gt;Hi folks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am being asked to create a duplicate network that will service VM clones of production VMs for testing and development purposes (without changing their IP or anything else).&amp;nbsp; We have something similar at a different site using "transit" zones and individual NAT rules (that I did not configure), but this task is a bit different from that.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I need a L3 interface to represent this duplicate network, to eventually communicate to the internet.&lt;/P&gt;&lt;P&gt;I am trying this small test first.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there a way to NAT the IP of devices (and maybe gateway IP) to communicate to a unique L3 interface on the firewall?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I assume separate zones and virtual routers will keep the traffic separate, looking for suggestions for the NAT rules to accomplish.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="replica_diagram.jpg" style="width: 379px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/14327iB3CA6F3414AD01BF/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="replica_diagram.jpg" alt="replica_diagram.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Mar 2018 20:17:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/creating-a-duplicate-network/m-p/206457#M60585</guid>
      <dc:creator>OMatlock</dc:creator>
      <dc:date>2018-03-19T20:17:28Z</dc:date>
    </item>
    <item>
      <title>Re: Creating a duplicate network?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/creating-a-duplicate-network/m-p/206472#M60588</link>
      <description>&lt;P&gt;This may be possible by creating multiple VSYS and then a transit zone, but I would be really careful&amp;nbsp;with having the same IP subnets on the same firewall in the same VSYS.&amp;nbsp; We ran into an issue where we had the same public facing network on outside multiple interfaces and ran into an issue where bi-directional NAT feature did not work as it would randomly chose to start advertising the MAC address on an interface that did not have rules for that particular NATed IP.&amp;nbsp; We had to then create both inbound and outbound&amp;nbsp;NAT rules.&amp;nbsp; Not even sure how this would look or what potential issues you could run into.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In our case we have a separate&amp;nbsp;firewall for sandbox&amp;nbsp;testing.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- Matt&lt;/P&gt;</description>
      <pubDate>Mon, 19 Mar 2018 20:54:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/creating-a-duplicate-network/m-p/206472#M60588</guid>
      <dc:creator>mlinsemier</dc:creator>
      <dc:date>2018-03-19T20:54:50Z</dc:date>
    </item>
    <item>
      <title>Re: Creating a duplicate network?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/creating-a-duplicate-network/m-p/206551#M60606</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/56398"&gt;@OMatlock&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I would say that the only way to properly do this is by having multiple VSYS as already mentioned by&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7143"&gt;@mlinsemier&lt;/a&gt;. That would allow you to keep the traffic fully seperated and only allow inter-VSYS communications exactly where needed. This also ensures that you can build out security policies for your test/dev enviroment that will&amp;nbsp;&lt;EM&gt;never&lt;/EM&gt; apply to your production traffic until you actually role out to production.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 20 Mar 2018 13:09:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/creating-a-duplicate-network/m-p/206551#M60606</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-03-20T13:09:29Z</dc:date>
    </item>
    <item>
      <title>Re: Creating a duplicate network?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/creating-a-duplicate-network/m-p/206601#M60621</link>
      <description>&lt;P&gt;Thank you guys for the feedback.&amp;nbsp; I just created my first transit network (without a new vsys).&lt;/P&gt;&lt;P&gt;But still need to configure it in a more specific way.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am in process of that and researching creating a new vsys.&amp;nbsp; Will report back, update, and close this week.&lt;/P&gt;</description>
      <pubDate>Tue, 20 Mar 2018 19:46:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/creating-a-duplicate-network/m-p/206601#M60621</guid>
      <dc:creator>OMatlock</dc:creator>
      <dc:date>2018-03-20T19:46:27Z</dc:date>
    </item>
  </channel>
</rss>

