<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: recommendation when putting the Palo Alto in a vwire mode. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/recommendation-when-putting-the-palo-alto-in-a-vwire-mode/m-p/237338#M67995</link>
    <description>&lt;P&gt;When you create Aggregate Ethernet Interface in Palo you leave LACP disabled so switches are not aware that this traffic is merged in firewall.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How should firewall otherwise merge packets passing over different interfaces together into same session?&lt;/P&gt;</description>
    <pubDate>Fri, 26 Oct 2018 18:34:09 GMT</pubDate>
    <dc:creator>Raido_Rattameister</dc:creator>
    <dc:date>2018-10-26T18:34:09Z</dc:date>
    <item>
      <title>recommendation when putting the Palo Alto in a vwire mode.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/recommendation-when-putting-the-palo-alto-in-a-vwire-mode/m-p/237059#M67927</link>
      <description>&lt;P&gt;Folks,&lt;/P&gt;&lt;P&gt;we have a switch to switch routing protocol running and the requirement is to put a palo alto in a vwire mode on such an environent. Please see the file attached with tis post.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now, the catch to this is the "switch-out" forms neighbours with "switch-01" and "switch-02" and packets going inside one link could come out of the other. I just wanted to ensure that this will not cause any packets drops as long as the zones are correctly configured.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;also, from a very high level what configuration would be needed? Convert each interface to a vwire? add the zones? add the policies? anything else?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!!!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PA Live Community.jpg" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/17296i9D44D4FC12027977/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="PA Live Community.jpg" alt="PA Live Community.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Oct 2018 13:55:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/recommendation-when-putting-the-palo-alto-in-a-vwire-mode/m-p/237059#M67927</guid>
      <dc:creator>nson2139</dc:creator>
      <dc:date>2018-10-25T13:55:28Z</dc:date>
    </item>
    <item>
      <title>Re: recommendation when putting the Palo Alto in a vwire mode.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/recommendation-when-putting-the-palo-alto-in-a-vwire-mode/m-p/237106#M67940</link>
      <description>&lt;P&gt;Does it have to be virtual wire?&lt;/P&gt;&lt;P&gt;What if you configure those 4 Palo interfaces in Layer 2 mode.&lt;/P&gt;&lt;P&gt;Set Ethernet 1 and 3 into one Aggregate Group.&lt;/P&gt;&lt;P&gt;Set Ethernet 4 and 6 into second Aggregate Group.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In this case all packets from same communication are correctly matched into correct session in Palo.&lt;/P&gt;</description>
      <pubDate>Thu, 25 Oct 2018 16:07:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/recommendation-when-putting-the-palo-alto-in-a-vwire-mode/m-p/237106#M67940</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2018-10-25T16:07:06Z</dc:date>
    </item>
    <item>
      <title>Re: recommendation when putting the Palo Alto in a vwire mode.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/recommendation-when-putting-the-palo-alto-in-a-vwire-mode/m-p/237108#M67942</link>
      <description>&lt;P&gt;thanks for the comments mate!!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes, it has to be virtual wire becuase we do not want to disturb anything in the existing setup. There is already routing protocols running between the switches and we want to retain that.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The firewall should maintain the state table from one zone to the other, right?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;if yes, this should work without any challenges from what I think.&lt;/P&gt;</description>
      <pubDate>Thu, 25 Oct 2018 16:28:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/recommendation-when-putting-the-palo-alto-in-a-vwire-mode/m-p/237108#M67942</guid>
      <dc:creator>nson2139</dc:creator>
      <dc:date>2018-10-25T16:28:09Z</dc:date>
    </item>
    <item>
      <title>Re: recommendation when putting the Palo Alto in a vwire mode.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/recommendation-when-putting-the-palo-alto-in-a-vwire-mode/m-p/237116#M67943</link>
      <description>&lt;P&gt;Hey I checked and virtual wire allows multiple interfaces in it also using aggregates.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="virtual wire.JPG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/17297iD55031E5477F04DD/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="virtual wire.JPG" alt="virtual wire.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Oct 2018 17:03:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/recommendation-when-putting-the-palo-alto-in-a-vwire-mode/m-p/237116#M67943</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2018-10-25T17:03:58Z</dc:date>
    </item>
    <item>
      <title>Re: recommendation when putting the Palo Alto in a vwire mode.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/recommendation-when-putting-the-palo-alto-in-a-vwire-mode/m-p/237140#M67950</link>
      <description>&lt;P&gt;yes, I agree. But in my case the switches are on a single interface. There is no point using the aggregate interfaces. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;aggregate interface would be needed if they are also connected to the same switch ...right?&lt;/P&gt;</description>
      <pubDate>Thu, 25 Oct 2018 18:24:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/recommendation-when-putting-the-palo-alto-in-a-vwire-mode/m-p/237140#M67950</guid>
      <dc:creator>nson2139</dc:creator>
      <dc:date>2018-10-25T18:24:56Z</dc:date>
    </item>
    <item>
      <title>Re: recommendation when putting the Palo Alto in a vwire mode.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/recommendation-when-putting-the-palo-alto-in-a-vwire-mode/m-p/237141#M67951</link>
      <description>&lt;P&gt;It is not about switch. It is for Palo so that all packets both ways would be combined together into single virtual wire in Palo standpoint so it could correctly perform AppID and threat prevention.&lt;/P&gt;</description>
      <pubDate>Thu, 25 Oct 2018 18:22:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/recommendation-when-putting-the-palo-alto-in-a-vwire-mode/m-p/237141#M67951</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2018-10-25T18:22:08Z</dc:date>
    </item>
    <item>
      <title>Re: recommendation when putting the Palo Alto in a vwire mode.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/recommendation-when-putting-the-palo-alto-in-a-vwire-mode/m-p/237249#M67973</link>
      <description>&lt;P&gt;ok, understood. However, do you see a potential issue that could occur in the ealier design?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The firewall should still be able to keep session information if the packet comes inside over one path and goes out via the other, right?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Oct 2018 08:11:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/recommendation-when-putting-the-palo-alto-in-a-vwire-mode/m-p/237249#M67973</guid>
      <dc:creator>nson2139</dc:creator>
      <dc:date>2018-10-26T08:11:05Z</dc:date>
    </item>
    <item>
      <title>Re: recommendation when putting the Palo Alto in a vwire mode.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/recommendation-when-putting-the-palo-alto-in-a-vwire-mode/m-p/237338#M67995</link>
      <description>&lt;P&gt;When you create Aggregate Ethernet Interface in Palo you leave LACP disabled so switches are not aware that this traffic is merged in firewall.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How should firewall otherwise merge packets passing over different interfaces together into same session?&lt;/P&gt;</description>
      <pubDate>Fri, 26 Oct 2018 18:34:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/recommendation-when-putting-the-palo-alto-in-a-vwire-mode/m-p/237338#M67995</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2018-10-26T18:34:09Z</dc:date>
    </item>
    <item>
      <title>Re: recommendation when putting the Palo Alto in a vwire mode.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/recommendation-when-putting-the-palo-alto-in-a-vwire-mode/m-p/237341#M67998</link>
      <description>&lt;P&gt;Gave this another thought and you would need to test how traffic exits from vw. Might not exit from interface you need.&lt;/P&gt;&lt;P&gt;Do you have single firewall or HA pair.&lt;/P&gt;&lt;P&gt;If HA pair then maybe it can be designed using A/A setup.&lt;/P&gt;</description>
      <pubDate>Fri, 26 Oct 2018 18:42:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/recommendation-when-putting-the-palo-alto-in-a-vwire-mode/m-p/237341#M67998</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2018-10-26T18:42:22Z</dc:date>
    </item>
  </channel>
</rss>

