<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: One Internet line Multiple intefaces in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/one-internet-line-multiple-intefaces/m-p/229335#M65926</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&amp;nbsp;for the answer&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I have one PA device for this&amp;nbsp;example this work ....&lt;/P&gt;</description>
    <pubDate>Tue, 04 Sep 2018 05:23:15 GMT</pubDate>
    <dc:creator>MFayez</dc:creator>
    <dc:date>2018-09-04T05:23:15Z</dc:date>
    <item>
      <title>One Internet line Multiple intefaces</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/one-internet-line-multiple-intefaces/m-p/229297#M65917</link>
      <description>&lt;P&gt;Hi Everyone&lt;BR /&gt;In my sinaro i have one internet line 10 MB and i have 5 zones configured in PA my question . and each zone for different purpose for example (IP SEC - Intenet -Email)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;1-&amp;nbsp; how i can provide the internet to multiple zones with a multiple services&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;2- How many Public ip address reqiued for this &lt;SPAN&gt;sinaro&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Sep 2018 21:40:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/one-internet-line-multiple-intefaces/m-p/229297#M65917</guid>
      <dc:creator>MFayez</dc:creator>
      <dc:date>2018-09-03T21:40:10Z</dc:date>
    </item>
    <item>
      <title>Re: One Internet line Multiple intefaces</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/one-internet-line-multiple-intefaces/m-p/229308#M65922</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/69689"&gt;@MFayez&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;STRONG&gt;1-&amp;nbsp; how i can provide the internet to multiple zones with a multiple services&lt;/STRONG&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;With a NAT rule where you configure your internet facing interface as translated source address&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/69689"&gt;@MFayez&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;&lt;STRONG&gt;2- How many Public ip address reqiued for this &lt;SPAN&gt;sinaro&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;It depends how many servers you need to make available and even more important what services do the offer. For example if you have the PA as VPN gateway, one emailserver and one webserver then you only need one public IP. In case you have multiple webservers and all expose their websites on port 80 and 443, then you either need one address for each of them or you place a reverse proxy in front of them and then you still only need one IP as the reverse proxy forwards the requests to the apropriate server based on the URL.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Sep 2018 01:03:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/one-internet-line-multiple-intefaces/m-p/229308#M65922</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-09-04T01:03:19Z</dc:date>
    </item>
    <item>
      <title>Re: One Internet line Multiple intefaces</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/one-internet-line-multiple-intefaces/m-p/229335#M65926</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&amp;nbsp;for the answer&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I have one PA device for this&amp;nbsp;example this work ....&lt;/P&gt;</description>
      <pubDate>Tue, 04 Sep 2018 05:23:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/one-internet-line-multiple-intefaces/m-p/229335#M65926</guid>
      <dc:creator>MFayez</dc:creator>
      <dc:date>2018-09-04T05:23:15Z</dc:date>
    </item>
    <item>
      <title>Re: One Internet line Multiple intefaces</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/one-internet-line-multiple-intefaces/m-p/229354#M65929</link>
      <description>&lt;P&gt;Why do you need a zone for each service?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rob&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Sep 2018 08:04:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/one-internet-line-multiple-intefaces/m-p/229354#M65929</guid>
      <dc:creator>RobinClayton</dc:creator>
      <dc:date>2018-09-04T08:04:27Z</dc:date>
    </item>
    <item>
      <title>Re: One Internet line Multiple intefaces</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/one-internet-line-multiple-intefaces/m-p/229357#M65930</link>
      <description>&lt;P&gt;I think you have the wrong idea of zones.&amp;nbsp; Zones are collection of interfaces/subnets that we write policies against.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the policy we specify the specific services and ports not in the zones.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Sep 2018 09:39:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/one-internet-line-multiple-intefaces/m-p/229357#M65930</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2018-09-04T09:39:59Z</dc:date>
    </item>
    <item>
      <title>Re: One Internet line Multiple intefaces</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/one-internet-line-multiple-intefaces/m-p/229360#M65931</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9524"&gt;@pulukas&lt;/a&gt;&lt;/P&gt;&lt;P&gt;What is wrong when &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/69689"&gt;@MFayez&lt;/a&gt;&amp;nbsp;wants to separate the servers from each other with zones? Doed not necessary mean that he understood something wrong with the concept if zones. (Specially if you may be don't have a lot of servers but a firewall with enough capacity of zones)&lt;/P&gt;</description>
      <pubDate>Tue, 04 Sep 2018 10:07:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/one-internet-line-multiple-intefaces/m-p/229360#M65931</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-09-04T10:07:48Z</dc:date>
    </item>
    <item>
      <title>Re: One Internet line Multiple intefaces</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/one-internet-line-multiple-intefaces/m-p/229373#M65934</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Current Setup" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/16417i12D471324EC8FFDE/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Current setup - Copy.png" alt="Current Setup" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Current Setup&lt;/span&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="New Setup" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/16418iDD1962730B756C07/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="New - Copy.png" alt="New Setup" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;New Setup&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Sep 2018 10:27:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/one-internet-line-multiple-intefaces/m-p/229373#M65934</guid>
      <dc:creator>MFayez</dc:creator>
      <dc:date>2018-09-04T10:27:28Z</dc:date>
    </item>
    <item>
      <title>Re: One Internet line Multiple intefaces</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/one-internet-line-multiple-intefaces/m-p/229375#M65935</link>
      <description>&lt;P&gt;For the new setup&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;how many public IP's do we need?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;how will natting work for the interfaces?&lt;/P&gt;</description>
      <pubDate>Tue, 04 Sep 2018 10:32:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/one-internet-line-multiple-intefaces/m-p/229375#M65935</guid>
      <dc:creator>MFayez</dc:creator>
      <dc:date>2018-09-04T10:32:39Z</dc:date>
    </item>
    <item>
      <title>Re: One Internet line Multiple intefaces</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/one-internet-line-multiple-intefaces/m-p/229378#M65936</link>
      <description>&lt;P&gt;What "IP" service ports are being connected to by each application? if none of them overlap then 1 public IP will do.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You also don't need to use 4 physical connections to the router&amp;nbsp; ( you could tag&amp;nbsp;VLANS into one&amp;nbsp;single port )&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rob&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Sep 2018 11:29:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/one-internet-line-multiple-intefaces/m-p/229378#M65936</guid>
      <dc:creator>RobinClayton</dc:creator>
      <dc:date>2018-09-04T11:29:01Z</dc:date>
    </item>
    <item>
      <title>Re: One Internet line Multiple intefaces</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/one-internet-line-multiple-intefaces/m-p/229476#M65974</link>
      <description>&lt;P&gt;Typically this is how you would be looking at your public facing services.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How many different public ip addresses do you need and for what services then add one for the PAN.&amp;nbsp; You request then from your ISP the appropriate subnet sized for that need, in your case looks like you will need either a /29 or /28.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This gets delivered on the ISP device facing your PAN.&amp;nbsp; You use one of these addresses on the PAN.&lt;/P&gt;&lt;P&gt;This is now your untrust zone.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You now organize your publicly facing resources into risk groups and create the muliple zones and private networks to support them or if the risk is similar they can all go into one DMZ zone.&amp;nbsp; These are the inside interface(s) of your PAN with zone assignments.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now you create your nat rules pointing each ip address from the ISP scope at the matching internal address of the server providing the public service.&amp;nbsp; And write the security policies needed for the inbound and outbound communications for each server.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Sep 2018 22:15:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/one-internet-line-multiple-intefaces/m-p/229476#M65974</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2018-09-04T22:15:10Z</dc:date>
    </item>
    <item>
      <title>Re: One Internet line Multiple intefaces</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/one-internet-line-multiple-intefaces/m-p/270798#M74755</link>
      <description>&lt;P&gt;this case still is not clear for me i will explain current setup&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1- 4 router is connected phiscaly to PA and each router provide defrent services (Email , Internet , VPN)&lt;/P&gt;&lt;P&gt;2- PBF are configer for pass the traffice and NAT&lt;/P&gt;&lt;P&gt;3-One defult routur are configer for untrust zone for all services&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Our reqiuerment :&lt;/P&gt;&lt;P&gt;1- Shift to 4 router to 1 Fiber line&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9524"&gt;@pulukas&lt;/a&gt;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/71756"&gt;@RobinClayton&lt;/a&gt;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592"&gt;@Remo&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jun 2019 08:07:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/one-internet-line-multiple-intefaces/m-p/270798#M74755</guid>
      <dc:creator>MFayez</dc:creator>
      <dc:date>2019-06-18T08:07:40Z</dc:date>
    </item>
    <item>
      <title>Re: One Internet line Multiple intefaces</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/one-internet-line-multiple-intefaces/m-p/270801#M74758</link>
      <description>&lt;P&gt;So -One router.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You no longer need PBF as you only have one route out.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You have 2x incomming SMTP so you need an IP for each on service port [25 &amp;amp; 587]&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Everything else does not overlap in terms of service port so can use either of the IP's.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jun 2019 08:21:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/one-internet-line-multiple-intefaces/m-p/270801#M74758</guid>
      <dc:creator>RobinClayton</dc:creator>
      <dc:date>2019-06-18T08:21:35Z</dc:date>
    </item>
    <item>
      <title>Re: One Internet line Multiple intefaces</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/one-internet-line-multiple-intefaces/m-p/270810#M74760</link>
      <description>&lt;P&gt;Okay ...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What about interface is required to create subinterface because i will user on physical line&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jun 2019 08:32:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/one-internet-line-multiple-intefaces/m-p/270810#M74760</guid>
      <dc:creator>MFayez</dc:creator>
      <dc:date>2019-06-18T08:32:41Z</dc:date>
    </item>
    <item>
      <title>Re: One Internet line Multiple intefaces</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/one-internet-line-multiple-intefaces/m-p/270817#M74761</link>
      <description>&lt;P&gt;No sub interface is necessary.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Have one interface external with the IP you want to be the primary and nat rules..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Then just have an inbound NAT for the second IP. (Untrust-&amp;gt;Untrust)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rob&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jun 2019 08:44:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/one-internet-line-multiple-intefaces/m-p/270817#M74761</guid>
      <dc:creator>RobinClayton</dc:creator>
      <dc:date>2019-06-18T08:44:41Z</dc:date>
    </item>
    <item>
      <title>Re: One Internet line Multiple intefaces</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/one-internet-line-multiple-intefaces/m-p/271190#M74801</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/71756"&gt;@RobinClayton&lt;/a&gt;&amp;nbsp; for your &lt;SPAN&gt;advise&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I will got from ISP 6 public ip address&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Should added the IP to interface !!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and it can be assigned to Zones&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Jun 2019 05:59:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/one-internet-line-multiple-intefaces/m-p/271190#M74801</guid>
      <dc:creator>MFayez</dc:creator>
      <dc:date>2019-06-19T05:59:01Z</dc:date>
    </item>
  </channel>
</rss>

