<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Moving some connections to the New PA in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/moving-some-connections-to-the-new-pa/m-p/254824#M72324</link>
    <description>&lt;P&gt;Seems best way to do is&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;create vwire for both uplink connections.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;here we will have 2 pair of vwires- Vwire INT and Vwire EXT&lt;/P&gt;&lt;P&gt;Two Zones trust and untrust&lt;/P&gt;&lt;P&gt;PA will pass all the LAG traffic&amp;nbsp; to dis switch from both zone trust zones.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As PA is passing traffic from both source interfaces of trust Zone and allowing return traffic from 2 dis switches we need to enable the option where PA allows asymm traffic&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;set deviceconfig setting tcp asymmetric-path bypass&lt;BR /&gt;# set deviceconfig setting session tcp-reject-non-syn no&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 24 Mar 2019 17:26:43 GMT</pubDate>
    <dc:creator>MP18</dc:creator>
    <dc:date>2019-03-24T17:26:43Z</dc:date>
    <item>
      <title>Moving some connections to the New PA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/moving-some-connections-to-the-new-pa/m-p/254609#M72256</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have this setup for one site&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;------Dis sw--------------Edge switch stack of 3 ----------40 users&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;we need to move few users behind the PA&amp;nbsp; .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;what can be best design for this as we only need to have 5 to 10 users behind the PA&amp;nbsp; 850.?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Should we connect small switch to the existing stack of switch ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Mar 2019 01:05:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/moving-some-connections-to-the-new-pa/m-p/254609#M72256</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2019-03-22T01:05:49Z</dc:date>
    </item>
    <item>
      <title>Re: Moving some connections to the New PA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/moving-some-connections-to-the-new-pa/m-p/254620#M72260</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;How about a vlan and/or a subnet that routes via the PAN?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm sure there are many different options. I would also love to hear what the community has to say.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Fri, 22 Mar 2019 02:30:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/moving-some-connections-to-the-new-pa/m-p/254620#M72260</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2019-03-22T02:30:42Z</dc:date>
    </item>
    <item>
      <title>Re: Moving some connections to the New PA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/moving-some-connections-to-the-new-pa/m-p/254722#M72287</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/75039"&gt;@MP18&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;A dedicated VLAN that routes through the PA would be what I would do, as it doesn't require any additional hardware and should be easy to maintain and update. It also doesn't require that you have someone on-site to migrate connections over to the new switch, you simply update the port configuration and assign it to the new VLAN.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Mar 2019 18:52:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/moving-some-connections-to-the-new-pa/m-p/254722#M72287</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2019-03-22T18:52:33Z</dc:date>
    </item>
    <item>
      <title>Re: Moving some connections to the New PA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/moving-some-connections-to-the-new-pa/m-p/254731#M72289</link>
      <description>&lt;P&gt;can we put this PA in vwire mode between the switches?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;curently edge switch has 2 upliks that go to dis switch.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;for the vwire to work it work in pairs&lt;/P&gt;&lt;P&gt;can i work with single connection for send and receive traffic?&lt;/P&gt;</description>
      <pubDate>Fri, 22 Mar 2019 19:23:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/moving-some-connections-to-the-new-pa/m-p/254731#M72289</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2019-03-22T19:23:16Z</dc:date>
    </item>
    <item>
      <title>Re: Moving some connections to the New PA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/moving-some-connections-to-the-new-pa/m-p/254745#M72297</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Can you provide a basic diagram? Somthing like:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;switch--&amp;gt;router--&amp;gt;PAN&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please advise,&lt;/P&gt;</description>
      <pubDate>Fri, 22 Mar 2019 20:33:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/moving-some-connections-to-the-new-pa/m-p/254745#M72297</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2019-03-22T20:33:25Z</dc:date>
    </item>
    <item>
      <title>Re: Moving some connections to the New PA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/moving-some-connections-to-the-new-pa/m-p/254748#M72299</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/75039"&gt;@MP18&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;If you only have a single connection to use on the PA you would be looking at doing a network TAP, which has limited capabilities, so I would really recommend the vwire setup if you want to do that.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Mar 2019 20:44:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/moving-some-connections-to-the-new-pa/m-p/254748#M72299</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2019-03-22T20:44:15Z</dc:date>
    </item>
    <item>
      <title>Re: Moving some connections to the New PA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/moving-some-connections-to-the-new-pa/m-p/254750#M72300</link>
      <description>&lt;P&gt;But for Vwire I will need to set of cables right&amp;nbsp; but in current setup it is not possible right?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;here is diagram attached&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Mar 2019 21:04:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/moving-some-connections-to-the-new-pa/m-p/254750#M72300</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2019-03-22T21:04:49Z</dc:date>
    </item>
    <item>
      <title>Re: Moving some connections to the New PA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/moving-some-connections-to-the-new-pa/m-p/254751#M72301</link>
      <description>&lt;P&gt;how can i add visio or pdf diagram ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;system does not allow me&lt;/P&gt;</description>
      <pubDate>Fri, 22 Mar 2019 21:06:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/moving-some-connections-to-the-new-pa/m-p/254751#M72301</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2019-03-22T21:06:58Z</dc:date>
    </item>
    <item>
      <title>Re: Moving some connections to the New PA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/moving-some-connections-to-the-new-pa/m-p/254753#M72302</link>
      <description>&lt;P&gt;scrren shot of diagram&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/19195i3ACA887B9D19CB64/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Capture.PNG" alt="Capture.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Mar 2019 21:10:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/moving-some-connections-to-the-new-pa/m-p/254753#M72302</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2019-03-22T21:10:28Z</dc:date>
    </item>
    <item>
      <title>Re: Moving some connections to the New PA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/moving-some-connections-to-the-new-pa/m-p/254758#M72306</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Where is the PAN located in the diagram or is that your question?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please advies,&lt;/P&gt;</description>
      <pubDate>Fri, 22 Mar 2019 22:01:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/moving-some-connections-to-the-new-pa/m-p/254758#M72306</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2019-03-22T22:01:31Z</dc:date>
    </item>
    <item>
      <title>Re: Moving some connections to the New PA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/moving-some-connections-to-the-new-pa/m-p/254776#M72309</link>
      <description>&lt;P&gt;PAN will come between the edge switches and Dis switch.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 23 Mar 2019 14:59:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/moving-some-connections-to-the-new-pa/m-p/254776#M72309</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2019-03-23T14:59:25Z</dc:date>
    </item>
    <item>
      <title>Re: Moving some connections to the New PA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/moving-some-connections-to-the-new-pa/m-p/254778#M72311</link>
      <description>&lt;P&gt;I have attached the diagram.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PA will be in between edge and dis switch.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Currenly edge switch o&lt;STRONG&gt;&lt;FONT color="#FF0000"&gt;nly has 1 layer 3 interfac&lt;/FONT&gt;&lt;/STRONG&gt;e which is for sw management access.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;config on switch&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ip static-route 0.0.0.0/0 gateway 10.10.230.50-------------------------management network&lt;/P&gt;&lt;P&gt;10.10.230.x has vlan interface 3100&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Edge switch has trunk interface&amp;nbsp; with link agg to dis switch&amp;nbsp; carrying below vlans&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;show 802.1q 1&lt;/P&gt;&lt;P&gt;Tagged VLANS Internal Description&lt;BR /&gt;-------------+------------------------------------------+&lt;BR /&gt;851 Raw 192.168.200.0&lt;BR /&gt;3100 mgmt-subnet 10.10.230.0&lt;BR /&gt;3203 corp-data-subnet 10.63.24.0&lt;BR /&gt;3303 voice-subnet 10.63.26.0&lt;BR /&gt;3403 corp-video-subnet 10.63.25.0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;what config i will need on PA to allow traffic from edge switch to dis switch carrying trunk port with lacp?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 23 Mar 2019 16:12:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/moving-some-connections-to-the-new-pa/m-p/254778#M72311</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2019-03-23T16:12:26Z</dc:date>
    </item>
    <item>
      <title>Re: Moving some connections to the New PA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/moving-some-connections-to-the-new-pa/m-p/254811#M72317</link>
      <description>&lt;P&gt;I have same problems. Who can help me?&lt;/P&gt;</description>
      <pubDate>Sun, 24 Mar 2019 08:08:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/moving-some-connections-to-the-new-pa/m-p/254811#M72317</guid>
      <dc:creator>BorisJones</dc:creator>
      <dc:date>2019-03-24T08:08:54Z</dc:date>
    </item>
    <item>
      <title>Re: Moving some connections to the New PA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/moving-some-connections-to-the-new-pa/m-p/254824#M72324</link>
      <description>&lt;P&gt;Seems best way to do is&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;create vwire for both uplink connections.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;here we will have 2 pair of vwires- Vwire INT and Vwire EXT&lt;/P&gt;&lt;P&gt;Two Zones trust and untrust&lt;/P&gt;&lt;P&gt;PA will pass all the LAG traffic&amp;nbsp; to dis switch from both zone trust zones.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As PA is passing traffic from both source interfaces of trust Zone and allowing return traffic from 2 dis switches we need to enable the option where PA allows asymm traffic&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;set deviceconfig setting tcp asymmetric-path bypass&lt;BR /&gt;# set deviceconfig setting session tcp-reject-non-syn no&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 24 Mar 2019 17:26:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/moving-some-connections-to-the-new-pa/m-p/254824#M72324</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2019-03-24T17:26:43Z</dc:date>
    </item>
    <item>
      <title>Re: Moving some connections to the New PA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/moving-some-connections-to-the-new-pa/m-p/256453#M72755</link>
      <description>&lt;P&gt;did the vwire setup and it worked great.&lt;/P&gt;</description>
      <pubDate>Sat, 06 Apr 2019 21:45:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/moving-some-connections-to-the-new-pa/m-p/256453#M72755</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2019-04-06T21:45:22Z</dc:date>
    </item>
    <item>
      <title>Re: Moving some connections to the New PA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/moving-some-connections-to-the-new-pa/m-p/548721#M112018</link>
      <description>&lt;PRE&gt;set deviceconfig setting tcp asymmetric-path bypass&lt;/PRE&gt;
&lt;P&gt;This helped me with a similar setup today. Thanks for sharing this!&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jul 2023 06:53:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/moving-some-connections-to-the-new-pa/m-p/548721#M112018</guid>
      <dc:creator>PravinSingi</dc:creator>
      <dc:date>2023-07-10T06:53:06Z</dc:date>
    </item>
  </channel>
</rss>

