<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Controling East-West traffic without NSX in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/controling-east-west-traffic-without-nsx/m-p/214451#M62322</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;One other thing you could try, could be a lot of work if you have a lot of servers, is to put them all in their own vlan. That way you cna use the PAN to control east-west traffic.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have one zone setup, call it DMZ, and a bunch of /29 subnets. Since we dont allow inter-zone traffic, we have to have policies to allow traffic to flow between server subnets.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope that makes sense.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
    <pubDate>Wed, 16 May 2018 14:04:42 GMT</pubDate>
    <dc:creator>OtakarKlier</dc:creator>
    <dc:date>2018-05-16T14:04:42Z</dc:date>
    <item>
      <title>Controling East-West traffic without NSX</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/controling-east-west-traffic-without-nsx/m-p/214376#M62303</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;In a "Supported Deployments on VMware vSphere Hypervisor (ESXi)" section of the documentation (&lt;A href="https://www.paloaltonetworks.com/documentation/71/virtualization/virtualization/set-up-a-vm-series-firewall-on-an-esxi-server/supported-deployments-on-vmware-vsphere-hypervisor-esxi#_92501" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/71/virtualization/virtualization/set-up-a-vm-series-firewall-on-an-esxi-server/supported-deployments-on-vmware-vsphere-hypervisor-esxi#_92501&lt;/A&gt;) for VM series it is mentioned that VM Firewall can be deployed to control East-West traffic of VMs within the same ESXi host - "&lt;SPAN&gt;One variation of this use case is to also require all traffic to flow through the firewall, including server to server (east-west traffic) on the same ESXi host.&lt;/SPAN&gt;". It is also mentioned that this is "&lt;SPAN&gt;(for environments that are not using VMware NSX)".&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Can anybody, please, describe more detailed technically how to setup this? Thank you!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Hand&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 16 May 2018 06:04:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/controling-east-west-traffic-without-nsx/m-p/214376#M62303</guid>
      <dc:creator>handshake</dc:creator>
      <dc:date>2018-05-16T06:04:24Z</dc:date>
    </item>
    <item>
      <title>Re: Controling East-West traffic without NSX</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/controling-east-west-traffic-without-nsx/m-p/214443#M62316</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/89614"&gt;@handshake&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;You would have to route all of the traffic from your VMs through the vm-firewall to get this to function properly. This deployment makes heavy use of virtual standard switches to get everything to route properly. I would recommend engaging your SE so that they can look at your existing enviroment and develop a deployment method that will work for you.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 16 May 2018 13:50:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/controling-east-west-traffic-without-nsx/m-p/214443#M62316</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-05-16T13:50:33Z</dc:date>
    </item>
    <item>
      <title>Re: Controling East-West traffic without NSX</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/controling-east-west-traffic-without-nsx/m-p/214451#M62322</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;One other thing you could try, could be a lot of work if you have a lot of servers, is to put them all in their own vlan. That way you cna use the PAN to control east-west traffic.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have one zone setup, call it DMZ, and a bunch of /29 subnets. Since we dont allow inter-zone traffic, we have to have policies to allow traffic to flow between server subnets.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope that makes sense.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Wed, 16 May 2018 14:04:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/controling-east-west-traffic-without-nsx/m-p/214451#M62322</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-05-16T14:04:42Z</dc:date>
    </item>
    <item>
      <title>Re: Controling East-West traffic without NSX</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/controling-east-west-traffic-without-nsx/m-p/215841#M62556</link>
      <description>&lt;P&gt;Thank you, BPry!&lt;/P&gt;&lt;P&gt;If I understand correctly I have to connect each VM to separate virtual switch, right?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 30 May 2018 07:01:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/controling-east-west-traffic-without-nsx/m-p/215841#M62556</guid>
      <dc:creator>handshake</dc:creator>
      <dc:date>2018-05-30T07:01:58Z</dc:date>
    </item>
    <item>
      <title>Re: Controling East-West traffic without NSX</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/controling-east-west-traffic-without-nsx/m-p/215842#M62557</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;&lt;/P&gt;&lt;P&gt;Yes, thanks! But this scenario is possible to implement with any firewall of any type. I thought there is a special case of being able to implement east-west control in a flexible way without using NSX.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 30 May 2018 07:06:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/controling-east-west-traffic-without-nsx/m-p/215842#M62557</guid>
      <dc:creator>handshake</dc:creator>
      <dc:date>2018-05-30T07:06:37Z</dc:date>
    </item>
    <item>
      <title>Re: Controling East-West traffic without NSX</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/controling-east-west-traffic-without-nsx/m-p/215917#M62576</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;So NSX is just Software Defined Networking and is not required to have traffic flow through a firewall as you have mentioned. All of this is possible without the use of NSX as NSX is just an overlay to make it easier for an admin. As ou mentioned you can have a vswitch for each VM or subnet and have that traffic terminate on a firewall.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/71/virtualization/virtualization/set-up-a-vm-series-nsx-edition-firewall/how-do-the-components-in-the-nsx-edition-solution-work-together" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/71/virtualization/virtualization/set-up-a-vm-series-nsx-edition-firewall/how-do-the-components-in-the-nsx-edition-solution-work-together&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope this helps and doesnt confuse, as I might has misread your initial question.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Wed, 30 May 2018 13:59:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/controling-east-west-traffic-without-nsx/m-p/215917#M62576</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-05-30T13:59:29Z</dc:date>
    </item>
  </channel>
</rss>

