<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Untagged L3 sub interfaces won't process traffic in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/untagged-l3-sub-interfaces-won-t-process-traffic/m-p/208868#M61102</link>
    <description>&lt;P&gt;Thanks for your answer.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From our production network (e.g. 10.0.0.0/24) we'd like to connect to different DMZs which are protected by different vsys.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Example:&lt;/P&gt;&lt;P&gt;vsys 1 - internal IP in production network: 10.0.0.10/24&lt;/P&gt;&lt;P&gt;vsys&amp;nbsp;2 - internal IP in production network: 10.0.0.11/24&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We'd like to trunk those two connections via one cable from the production network to the Palo device. If we would use a seperate VLAN for both vsys in between the production network and the Palo device it would require a major reconfiguration of our network infrastructure.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Denis&lt;/P&gt;</description>
    <pubDate>Thu, 05 Apr 2018 13:40:34 GMT</pubDate>
    <dc:creator>DenisHierholzer</dc:creator>
    <dc:date>2018-04-05T13:40:34Z</dc:date>
    <item>
      <title>Untagged L3 sub interfaces won't process traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/untagged-l3-sub-interfaces-won-t-process-traffic/m-p/208833#M61093</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As described in following links we've configured multiple untagged sub interfaces all assigned to different vsys (different virtual routers and different zones) but with different IPs from the same network and the same VLAN:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Configure-L3-Untagged-Subinterfaces-to-Communicate-within/ta-p/55830" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Configure-L3-Untagged-Subinterfaces-to-Communicate-within/ta-p/55830&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Learning-Articles/Untagged-Subinterfaces-L3/ta-p/55942" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Learning-Articles/Untagged-Subinterfaces-L3/ta-p/55942&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Example:&lt;BR /&gt;eth1, IP: none, tag: none, vsys: 1, zone: none, virtual router: none&lt;BR /&gt;--- eth1.1, IP: 192.168.0.10/24, tag: none, vsys: 2, zone: Zone-2, virtual router: VR-2&lt;BR /&gt;--- eth1.2, IP: 192.168.0.11/24, tag: none, vsys: 3, zone: Zone-3, virtual router: VR-3&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The interface IPs 192.168.0.10 and 192.168.0.11 are pingable but traffic through the firewall won't be processed.&lt;BR /&gt;&amp;nbsp;&lt;BR /&gt;The same problem was described in following thread:&lt;BR /&gt;&lt;A href="https://live.paloaltonetworks.com/t5/General-Topics/Multiple-Zones-with-one-VLAN/m-p/100851#M44302" target="_blank"&gt;https://live.paloaltonetworks.com/t5/General-Topics/Multiple-Zones-with-one-VLAN/m-p/100851#M44302&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Unfortunately I don't understand why this does not work. Would somebody please explain this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;BR /&gt;Denis&lt;/P&gt;</description>
      <pubDate>Thu, 05 Apr 2018 05:39:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/untagged-l3-sub-interfaces-won-t-process-traffic/m-p/208833#M61093</guid>
      <dc:creator>DenisHierholzer</dc:creator>
      <dc:date>2018-04-05T05:39:46Z</dc:date>
    </item>
    <item>
      <title>Re: Untagged L3 sub interfaces won't process traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/untagged-l3-sub-interfaces-won-t-process-traffic/m-p/208866#M61100</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/59908"&gt;@DenisHierholzer&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;This really isn't how this is supposed to function and you cannot use untagged frames for all the sub-interfaces.&amp;nbsp;Subinterfaces really are meant to connect multiple VLANs onto a single physical port, similar to how you would setup a single trunk port but use it to pass multiple VLANs. The biggest issue that you have here is that if you have everything untagged the switch and the firewall doesn't really understand what it's supposed to do with the traffic.&lt;/P&gt;&lt;P&gt;Can you say what you're actually attempting to accomplish with your setup? There may be a better solution that we can recommend to get things working correctly.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Apr 2018 13:32:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/untagged-l3-sub-interfaces-won-t-process-traffic/m-p/208866#M61100</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-04-05T13:32:44Z</dc:date>
    </item>
    <item>
      <title>Re: Untagged L3 sub interfaces won't process traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/untagged-l3-sub-interfaces-won-t-process-traffic/m-p/208868#M61102</link>
      <description>&lt;P&gt;Thanks for your answer.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From our production network (e.g. 10.0.0.0/24) we'd like to connect to different DMZs which are protected by different vsys.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Example:&lt;/P&gt;&lt;P&gt;vsys 1 - internal IP in production network: 10.0.0.10/24&lt;/P&gt;&lt;P&gt;vsys&amp;nbsp;2 - internal IP in production network: 10.0.0.11/24&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We'd like to trunk those two connections via one cable from the production network to the Palo device. If we would use a seperate VLAN for both vsys in between the production network and the Palo device it would require a major reconfiguration of our network infrastructure.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Denis&lt;/P&gt;</description>
      <pubDate>Thu, 05 Apr 2018 13:40:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/untagged-l3-sub-interfaces-won-t-process-traffic/m-p/208868#M61102</guid>
      <dc:creator>DenisHierholzer</dc:creator>
      <dc:date>2018-04-05T13:40:34Z</dc:date>
    </item>
    <item>
      <title>Re: Untagged L3 sub interfaces won't process traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/untagged-l3-sub-interfaces-won-t-process-traffic/m-p/209019#M61130</link>
      <description>&lt;P&gt;VLAN tag is what detemines which packet goes to which logical interface on same physical interface. Without it FW can't know which packet to put where.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Apr 2018 11:32:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/untagged-l3-sub-interfaces-won-t-process-traffic/m-p/209019#M61130</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2018-04-06T11:32:59Z</dc:date>
    </item>
    <item>
      <title>Re: Untagged L3 sub interfaces won't process traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/untagged-l3-sub-interfaces-won-t-process-traffic/m-p/209175#M61164</link>
      <description>&lt;P&gt;But the logical interfaces are also identified by a unique IP address. I don't understand why this is not enough to assign traffic to a specific logical interface.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Apr 2018 06:17:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/untagged-l3-sub-interfaces-won-t-process-traffic/m-p/209175#M61164</guid>
      <dc:creator>DenisHierholzer</dc:creator>
      <dc:date>2018-04-09T06:17:42Z</dc:date>
    </item>
    <item>
      <title>Re: Untagged L3 sub interfaces won't process traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/untagged-l3-sub-interfaces-won-t-process-traffic/m-p/209187#M61169</link>
      <description>&lt;P&gt;The packet doesn't even get picked by routing process (virtual router) as PA can't even assign which vsys will handle it.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What are you trying to achieve? Why exactly do you need different vsys for those DMZs? And if you already need different vsys why are you using same network for both? Accessing both DMZs in your current configuration will not be an easy task, you will need host routes on clients.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Apr 2018 06:54:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/untagged-l3-sub-interfaces-won-t-process-traffic/m-p/209187#M61169</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2018-04-09T06:54:34Z</dc:date>
    </item>
    <item>
      <title>Re: Untagged L3 sub interfaces won't process traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/untagged-l3-sub-interfaces-won-t-process-traffic/m-p/209233#M61187</link>
      <description>&lt;P&gt;Ok - I've realized that I cannot use untagged sub interfaces in my specific scenario.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Untagged sub interfaces are only for a specific scenario described in the links in my original post - beside this specific scenario untagged sub interfaces won't work. I will use tagged sub interfaces and different VLANs to communicate with the different vsys.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your help.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Apr 2018 12:20:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/untagged-l3-sub-interfaces-won-t-process-traffic/m-p/209233#M61187</guid>
      <dc:creator>DenisHierholzer</dc:creator>
      <dc:date>2018-04-09T12:20:31Z</dc:date>
    </item>
  </channel>
</rss>

