<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Vwire inbetween Cisco Asr router and Nexus 9K Switch in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/vwire-inbetween-cisco-asr-router-and-nexus-9k-switch/m-p/242059#M69290</link>
    <description>&lt;P&gt;By default virtual wire permits through only untagged packets.&lt;/P&gt;&lt;P&gt;Did you add 0-4094 (or you can be more specific to allow only vlans you want) into virtual wire Tag Allowed box?&lt;/P&gt;</description>
    <pubDate>Tue, 04 Dec 2018 15:43:08 GMT</pubDate>
    <dc:creator>Raido_Rattameister</dc:creator>
    <dc:date>2018-12-04T15:43:08Z</dc:date>
    <item>
      <title>Vwire inbetween Cisco Asr router and Nexus 9K Switch</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vwire-inbetween-cisco-asr-router-and-nexus-9k-switch/m-p/242051#M69288</link>
      <description>&lt;P&gt;I am having trouble with the following.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cisco ASR router with IP of 10.1.1.5 plugs into Cisco 9K switch into port eth 1/3, eth 1/3 is configured the follwoing way.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;interface TenGigabitEthernet0/0/1&lt;BR /&gt;&amp;nbsp;description LAS-9K-2&lt;BR /&gt;&amp;nbsp;ip address 10.1.1.5&lt;BR /&gt;&amp;nbsp;no ip redirects&lt;BR /&gt;&amp;nbsp;no ip unreachables&lt;BR /&gt;&amp;nbsp;no ip proxy-arp&lt;BR /&gt;&amp;nbsp;ip nbar protocol-discovery&lt;BR /&gt;&amp;nbsp;load-interval 30&lt;BR /&gt;&amp;nbsp;cdp enable&lt;BR /&gt;end&lt;/P&gt;&lt;P&gt;interface Ethernet1/3&lt;BR /&gt;switchport access vlan 852&lt;BR /&gt;no shutdown&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The Palo is configured as follows.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;L3-9K2-vwire&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ethernet1/19&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ethernet1/20&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; p&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0-4094&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Palo port 19 connected to 9K eth 1/15&lt;BR /&gt;&lt;BR /&gt;interface Ethernet1/15&lt;BR /&gt;&amp;nbsp; switchport access vlan 852&lt;BR /&gt;&amp;nbsp; no shutdown&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Palo port 20 Connected to 9k eth 1/16&lt;BR /&gt;&lt;BR /&gt;interface Ethernet1/16&lt;BR /&gt;&amp;nbsp; description Palo-Wan2-eth20&lt;BR /&gt;&amp;nbsp; no switchport&lt;BR /&gt;&amp;nbsp; speed 10000&lt;BR /&gt;&amp;nbsp; no ip redirects&lt;BR /&gt;&amp;nbsp; ip address 10.1.1.6&lt;BR /&gt;&amp;nbsp; no ip ospf passive-interface&lt;BR /&gt;&amp;nbsp; ip router ospf 1 area 0.0.0.0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The IP's above have been changed for this discussion.&amp;nbsp;&amp;nbsp; What is happening there is no traffic from the layer2 vlan 852 on the cisco switch.&amp;nbsp; In the palo traffic logs i can see 10.1.1.6 trying ping 10.1.1.5, but never 10.1.15 to 10.1.16&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am not sure what i am missing, I have done this before.&lt;/P&gt;</description>
      <pubDate>Tue, 04 Dec 2018 15:33:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vwire-inbetween-cisco-asr-router-and-nexus-9k-switch/m-p/242051#M69288</guid>
      <dc:creator>markk96</dc:creator>
      <dc:date>2018-12-04T15:33:19Z</dc:date>
    </item>
    <item>
      <title>Re: Vwire inbetween Cisco Asr router and Nexus 9K Switch</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vwire-inbetween-cisco-asr-router-and-nexus-9k-switch/m-p/242058#M69289</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Do you have security policies on the vwire allowing traffic in both directions? Check the traffic logs for any drops or denies in either direction.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Tue, 04 Dec 2018 15:38:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vwire-inbetween-cisco-asr-router-and-nexus-9k-switch/m-p/242058#M69289</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-12-04T15:38:37Z</dc:date>
    </item>
    <item>
      <title>Re: Vwire inbetween Cisco Asr router and Nexus 9K Switch</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vwire-inbetween-cisco-asr-router-and-nexus-9k-switch/m-p/242059#M69290</link>
      <description>&lt;P&gt;By default virtual wire permits through only untagged packets.&lt;/P&gt;&lt;P&gt;Did you add 0-4094 (or you can be more specific to allow only vlans you want) into virtual wire Tag Allowed box?&lt;/P&gt;</description>
      <pubDate>Tue, 04 Dec 2018 15:43:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vwire-inbetween-cisco-asr-router-and-nexus-9k-switch/m-p/242059#M69290</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2018-12-04T15:43:08Z</dc:date>
    </item>
    <item>
      <title>Re: Vwire inbetween Cisco Asr router and Nexus 9K Switch</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vwire-inbetween-cisco-asr-router-and-nexus-9k-switch/m-p/242062#M69291</link>
      <description>&lt;P&gt;The Policy rule is set for any any, with application default set to any.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The vwire is set to 0-4094 for tagging.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Dec 2018 16:13:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vwire-inbetween-cisco-asr-router-and-nexus-9k-switch/m-p/242062#M69291</guid>
      <dc:creator>markk96</dc:creator>
      <dc:date>2018-12-04T16:13:09Z</dc:date>
    </item>
  </channel>
</rss>

