<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Palo Alto Layer2 mode and brdige vlan in different subnets in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-layer2-mode-and-brdige-vlan-in-different-subnets/m-p/223187#M64155</link>
    <description>&lt;P&gt;To have the inspection at layer 2 with the gateway on the core switch you need to find a layer 2 path where you can insert the PAN in the link using v-wire would probably be simplest.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you core device is a pure core with nothing but other switches attached this should be possible.&amp;nbsp; Intercept the links from the core switch to the aggregation switch and insert the layer 2 PAN in these lines.&amp;nbsp; Assuming you have enough ports for all the links.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On the PAN side then you need to create all the vlans that exist on that line and setup the rules for inspection then for traffic that crosses the PAN v-wire for each vlan.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 22 Jul 2018 17:30:28 GMT</pubDate>
    <dc:creator>pulukas</dc:creator>
    <dc:date>2018-07-22T17:30:28Z</dc:date>
    <item>
      <title>Palo Alto Layer2 mode and brdige vlan in different subnets</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-layer2-mode-and-brdige-vlan-in-different-subnets/m-p/223179#M64153</link>
      <description>&lt;P&gt;Hi All&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can Palo Alto bridge two VLAN like VLAN 10 and VLAN 30 that have different subnets? or both VLAN should have same subnet?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Basically what I want, I have VLAN 10 having subnet 10.10.10.0/24 and VLAN 30 having subnet 192.168.1.0/24. Both VLAN have gateway on core switch. How can I use Palo Alto firewall in layer 2 mode to do the firewalling between two VLAN&lt;/P&gt;</description>
      <pubDate>Sun, 22 Jul 2018 16:44:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-layer2-mode-and-brdige-vlan-in-different-subnets/m-p/223179#M64153</guid>
      <dc:creator>faizankhurshid</dc:creator>
      <dc:date>2018-07-22T16:44:52Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Layer2 mode and brdige vlan in different subnets</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-layer2-mode-and-brdige-vlan-in-different-subnets/m-p/223187#M64155</link>
      <description>&lt;P&gt;To have the inspection at layer 2 with the gateway on the core switch you need to find a layer 2 path where you can insert the PAN in the link using v-wire would probably be simplest.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you core device is a pure core with nothing but other switches attached this should be possible.&amp;nbsp; Intercept the links from the core switch to the aggregation switch and insert the layer 2 PAN in these lines.&amp;nbsp; Assuming you have enough ports for all the links.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On the PAN side then you need to create all the vlans that exist on that line and setup the rules for inspection then for traffic that crosses the PAN v-wire for each vlan.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 22 Jul 2018 17:30:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-layer2-mode-and-brdige-vlan-in-different-subnets/m-p/223187#M64155</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2018-07-22T17:30:28Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Layer2 mode and brdige vlan in different subnets</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-layer2-mode-and-brdige-vlan-in-different-subnets/m-p/223189#M64157</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9524"&gt;@pulukas&lt;/a&gt;&amp;nbsp;thank you. I got your point. But then I have to make two security rules right? one for vwire-10 (going to gateway of vlan10) and other policy is for vwire-20 (coming from gateway of vlan 20 to server?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also, if firewall is off path to core firewall, then I have to host vlan gateway also on L2 firewall for inter-vlan firewalling?&lt;/P&gt;</description>
      <pubDate>Sun, 22 Jul 2018 19:18:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-layer2-mode-and-brdige-vlan-in-different-subnets/m-p/223189#M64157</guid>
      <dc:creator>faizankhurshid</dc:creator>
      <dc:date>2018-07-22T19:18:35Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Layer2 mode and brdige vlan in different subnets</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-layer2-mode-and-brdige-vlan-in-different-subnets/m-p/223464#M64242</link>
      <description>&lt;P&gt;I have not done this but I think you won't need two rules if you place everything in the same zone.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The rules will be intrazone traffic.&lt;/P&gt;&lt;P&gt;They are written in the direction that traffic is initiated.&lt;/P&gt;&lt;P&gt;As the traffic comes through it should still match the existing sessions even though it goes through the PAN twice in each direction.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jul 2018 22:37:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-layer2-mode-and-brdige-vlan-in-different-subnets/m-p/223464#M64242</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2018-07-24T22:37:49Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Layer2 mode and brdige vlan in different subnets</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-layer2-mode-and-brdige-vlan-in-different-subnets/m-p/223523#M64252</link>
      <description>&lt;P&gt;you can also create a Layer2 interface with 2 subinterfaces, then create a policy to allow traffic from one's zone to the others and back (interzone&amp;nbsp;will do this if you only want to create a single policy)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;the only thing you'll need to take care of yourself, is how the different broadcast domains are going to communicate to one another without a routing device in between&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jul 2018 11:02:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-layer2-mode-and-brdige-vlan-in-different-subnets/m-p/223523#M64252</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2018-07-25T11:02:38Z</dc:date>
    </item>
  </channel>
</rss>

