<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic DMZ with multiple VLANs, multiple Zones? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/dmz-with-multiple-vlans-multiple-zones/m-p/227505#M65464</link>
    <description>If you have a DMZ behind the Palo and it contains multiple VLANs or sub-interfaces, would you create multiple Zones(one for each VLAN)? Or create a single "DMZ" zone and apply that to all of the VLANs?</description>
    <pubDate>Fri, 17 Aug 2018 23:34:38 GMT</pubDate>
    <dc:creator>jambulo</dc:creator>
    <dc:date>2018-08-17T23:34:38Z</dc:date>
    <item>
      <title>DMZ with multiple VLANs, multiple Zones?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dmz-with-multiple-vlans-multiple-zones/m-p/227505#M65464</link>
      <description>If you have a DMZ behind the Palo and it contains multiple VLANs or sub-interfaces, would you create multiple Zones(one for each VLAN)? Or create a single "DMZ" zone and apply that to all of the VLANs?</description>
      <pubDate>Fri, 17 Aug 2018 23:34:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dmz-with-multiple-vlans-multiple-zones/m-p/227505#M65464</guid>
      <dc:creator>jambulo</dc:creator>
      <dc:date>2018-08-17T23:34:38Z</dc:date>
    </item>
    <item>
      <title>Re: DMZ with multiple VLANs, multiple Zones?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dmz-with-multiple-vlans-multiple-zones/m-p/227515#M65465</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7542"&gt;@jambulo&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There is no simple answer for your question. It depends ...&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Are the subnets equal to each other?&lt;/LI&gt;&lt;LI&gt;Will you generally allow traffic between the subnets?&lt;/LI&gt;&lt;LI&gt;Are the subnets contain different group of servers? (One subnet for linux and one for windows for example)&lt;/LI&gt;&lt;LI&gt;Do you plan to configure generic zone firewallrules or do you configure specific rules for each server?&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Sat, 18 Aug 2018 10:37:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dmz-with-multiple-vlans-multiple-zones/m-p/227515#M65465</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-08-18T10:37:32Z</dc:date>
    </item>
    <item>
      <title>Re: DMZ with multiple VLANs, multiple Zones?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dmz-with-multiple-vlans-multiple-zones/m-p/227764#M65514</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I agree with&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592"&gt;@Remo&lt;/a&gt;. The way I do it is use one zone and then create policies around the vlan subnets. This way I dont run out of zones and can keep the traffic highly segregated. This is also because I have an implicite DENY ALL at the end of my rules so the built in intra-zone traffic rules doesnt apply and traffic is denied by policy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope that makes sense.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Aug 2018 17:40:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dmz-with-multiple-vlans-multiple-zones/m-p/227764#M65514</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-08-21T17:40:05Z</dc:date>
    </item>
    <item>
      <title>Re: DMZ with multiple VLANs, multiple Zones?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dmz-with-multiple-vlans-multiple-zones/m-p/227766#M65515</link>
      <description>&lt;UL&gt;&lt;LI&gt;Are the subnets equal to each other?&lt;UL&gt;&lt;LI&gt;Not sure what you mean.&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;Will you generally allow traffic between the subnets?&lt;UL&gt;&lt;LI&gt;Generally will not allow traffic between subnets.&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;Are the subnets contain different group of servers? (One subnet for linux and one for windows for example)&lt;UL&gt;&lt;LI&gt;Subnets can contain different types of servers, but mainly are separated by the functions that the servers provide.&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;Do you plan to configure generic zone firewallrules or do you configure specific rules for each server?&lt;UL&gt;&lt;LI&gt;Specific rules for each server.&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Tue, 21 Aug 2018 17:52:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dmz-with-multiple-vlans-multiple-zones/m-p/227766#M65515</guid>
      <dc:creator>jambulo</dc:creator>
      <dc:date>2018-08-21T17:52:49Z</dc:date>
    </item>
    <item>
      <title>Re: DMZ with multiple VLANs, multiple Zones?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dmz-with-multiple-vlans-multiple-zones/m-p/227795#M65520</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7542"&gt;@jambulo&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;UL&gt;&lt;LI&gt;Are the subnets equal to each other?&lt;UL&gt;&lt;LI&gt;Not sure what you mean.&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;I meant if these subnets are all the same and the only reason you have more than one is mabe because one /24 isn't big enough, so you created a second. But as you wrote you want to group the servers based on their functions.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Depending on the number of subnets and the hardware you are using, I would create one zone per vlan/subnet. As you group the servers by their functions this would fit perfectly into the zonenames so you have a better overview in the ruleset.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you have more than 40 subnets and you are using a PA-3020, then you have to go the way with one zone where you drop intrazone traffic, but in case you have a PA-5220 or even bigger then the number of zones will probably not be a limit in any way.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Aug 2018 23:26:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dmz-with-multiple-vlans-multiple-zones/m-p/227795#M65520</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-08-21T23:26:08Z</dc:date>
    </item>
  </channel>
</rss>

