<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Plz urgent help in Bridge+Tap mode in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/plz-urgent-help-in-bridge-tap-mode/m-p/206621#M60627</link>
    <description>&lt;P&gt;When you configure the TAP port, you must assign that port into a "Zone".&amp;nbsp; When you create this zone, you must define it as a Zone to be used for TAP interfaces.&amp;nbsp; (Call it anything you like, I typically use tapzone).&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When you use v-wire or L2 bridging, you will create a pair of zones (trust &amp;amp; untrust, inside &amp;amp; outside, etc.) that will also need to be defined as "v-wire" or "L2"-specific zones.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In your security policy, you would then use 2 different rules:&lt;/P&gt;&lt;P&gt;1.) permit from tapzone to tapzone all apps, all ports, all content features, logging enabled&lt;/P&gt;&lt;P&gt;2.) permit from trust to untrust, specific app, application-default port, content features enabled, logging enabled, etc.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does that answer the question?&lt;/P&gt;</description>
    <pubDate>Tue, 20 Mar 2018 23:20:42 GMT</pubDate>
    <dc:creator>jvalentine</dc:creator>
    <dc:date>2018-03-20T23:20:42Z</dc:date>
    <item>
      <title>Plz urgent help in Bridge+Tap mode</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/plz-urgent-help-in-bridge-tap-mode/m-p/206616#M60625</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;I just need a confirmation if i can configure a TAP interface + 2 bridges interfaces, and make 2 policy rules, one for TAP and the second for the bridge, in order to generate logs for TAP and bridge traffic at once, that is possible?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 20 Mar 2018 22:38:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/plz-urgent-help-in-bridge-tap-mode/m-p/206616#M60625</guid>
      <dc:creator>hamza-zidane</dc:creator>
      <dc:date>2018-03-20T22:38:00Z</dc:date>
    </item>
    <item>
      <title>Re: Plz urgent help in Bridge+Tap mode</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/plz-urgent-help-in-bridge-tap-mode/m-p/206621#M60627</link>
      <description>&lt;P&gt;When you configure the TAP port, you must assign that port into a "Zone".&amp;nbsp; When you create this zone, you must define it as a Zone to be used for TAP interfaces.&amp;nbsp; (Call it anything you like, I typically use tapzone).&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When you use v-wire or L2 bridging, you will create a pair of zones (trust &amp;amp; untrust, inside &amp;amp; outside, etc.) that will also need to be defined as "v-wire" or "L2"-specific zones.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In your security policy, you would then use 2 different rules:&lt;/P&gt;&lt;P&gt;1.) permit from tapzone to tapzone all apps, all ports, all content features, logging enabled&lt;/P&gt;&lt;P&gt;2.) permit from trust to untrust, specific app, application-default port, content features enabled, logging enabled, etc.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does that answer the question?&lt;/P&gt;</description>
      <pubDate>Tue, 20 Mar 2018 23:20:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/plz-urgent-help-in-bridge-tap-mode/m-p/206621#M60627</guid>
      <dc:creator>jvalentine</dc:creator>
      <dc:date>2018-03-20T23:20:42Z</dc:date>
    </item>
    <item>
      <title>Re: Plz urgent help in Bridge+Tap mode</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/plz-urgent-help-in-bridge-tap-mode/m-p/206628#M60628</link>
      <description>&lt;P&gt;ok that mean i can configure the PA for TAP and bridge mode at once, ok that was very helpful i thank you very very much.&lt;/P&gt;&lt;P&gt;NB:(for bridge mode i think also i can use one ZONE layer2 for exmple)&lt;/P&gt;</description>
      <pubDate>Tue, 20 Mar 2018 23:31:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/plz-urgent-help-in-bridge-tap-mode/m-p/206628#M60628</guid>
      <dc:creator>hamza-zidane</dc:creator>
      <dc:date>2018-03-20T23:31:03Z</dc:date>
    </item>
    <item>
      <title>Re: Plz urgent help in Bridge+Tap mode</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/plz-urgent-help-in-bridge-tap-mode/m-p/206630#M60629</link>
      <description>&lt;P&gt;Each interface can be configured to support a specific mode.&amp;nbsp; You may select one mode per interface (and sometimes, per sub-interface).&amp;nbsp; For your configuration, you would need 1 port for TAP mode, and then use other ports for other modes (such as L2, L3, v-wire, HA, etc.)&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="interfacemode.png" style="width: 500px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/14353i69E54FBA01B3DD53/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="interfacemode.png" alt="interfacemode.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 20 Mar 2018 23:38:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/plz-urgent-help-in-bridge-tap-mode/m-p/206630#M60629</guid>
      <dc:creator>jvalentine</dc:creator>
      <dc:date>2018-03-20T23:38:40Z</dc:date>
    </item>
    <item>
      <title>Re: Plz urgent help in Bridge+Tap mode</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/plz-urgent-help-in-bridge-tap-mode/m-p/206652#M60634</link>
      <description>&lt;P&gt;thank you very much brother&lt;/P&gt;</description>
      <pubDate>Wed, 21 Mar 2018 08:42:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/plz-urgent-help-in-bridge-tap-mode/m-p/206652#M60634</guid>
      <dc:creator>hamza-zidane</dc:creator>
      <dc:date>2018-03-21T08:42:26Z</dc:date>
    </item>
  </channel>
</rss>

