<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: extending vlan in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/extending-vlan/m-p/255722#M72535</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Same ip and same vlan tag&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Tue, 02 Apr 2019 05:04:46 GMT</pubDate>
    <dc:creator>simsim</dc:creator>
    <dc:date>2019-04-02T05:04:46Z</dc:date>
    <item>
      <title>extending vlan</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/extending-vlan/m-p/255567#M72500</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have two pa device , if . Both are in two differnet site . and I want to access the device in vlan10&amp;nbsp; from one site to another .&amp;nbsp;&lt;/P&gt;&lt;P&gt;How can i do that .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;vlan 10 ----fw1 --------------fw2---vlan 10&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 31 Mar 2019 06:56:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/extending-vlan/m-p/255567#M72500</guid>
      <dc:creator>simsim</dc:creator>
      <dc:date>2019-03-31T06:56:43Z</dc:date>
    </item>
    <item>
      <title>Re: extending vlan</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/extending-vlan/m-p/255575#M72502</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/59972"&gt;@simsim&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Are you refferring to L2 extention and will be using same network on both ends?( you are expecting a solution like psuedowire ?)&lt;/P&gt;</description>
      <pubDate>Sun, 31 Mar 2019 13:00:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/extending-vlan/m-p/255575#M72502</guid>
      <dc:creator>Abdul_Razaq</dc:creator>
      <dc:date>2019-03-31T13:00:15Z</dc:date>
    </item>
    <item>
      <title>Re: extending vlan</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/extending-vlan/m-p/255577#M72503</link>
      <description>&lt;P&gt;Do you have layer 2 or layer 3 connection between sites?&lt;/P&gt;&lt;P&gt;Is connection over internet and IPSec VPN?&lt;/P&gt;</description>
      <pubDate>Sun, 31 Mar 2019 16:49:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/extending-vlan/m-p/255577#M72503</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2019-03-31T16:49:58Z</dc:date>
    </item>
    <item>
      <title>Re: extending vlan</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/extending-vlan/m-p/255580#M72505</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am having l3 connection between sites&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 01 Apr 2019 05:04:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/extending-vlan/m-p/255580#M72505</guid>
      <dc:creator>simsim</dc:creator>
      <dc:date>2019-04-01T05:04:10Z</dc:date>
    </item>
    <item>
      <title>Re: extending vlan</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/extending-vlan/m-p/255583#M72506</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Not same network , the gateway is in site b.From site a&amp;nbsp; I want to reach site B&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Apr 2019 08:34:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/extending-vlan/m-p/255583#M72506</guid>
      <dc:creator>simsim</dc:creator>
      <dc:date>2019-04-01T08:34:23Z</dc:date>
    </item>
    <item>
      <title>Re: extending vlan</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/extending-vlan/m-p/255610#M72514</link>
      <description>&lt;P&gt;Assuming that you configure IPSec VPN between sites then you need to add route to peer site into virtual router and allow this traffic in security policy.&lt;/P&gt;</description>
      <pubDate>Mon, 01 Apr 2019 13:55:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/extending-vlan/m-p/255610#M72514</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2019-04-01T13:55:27Z</dc:date>
    </item>
    <item>
      <title>Re: extending vlan</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/extending-vlan/m-p/255658#M72520</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Are the vlans IP'ed the same way? i.e. 192.168.2.0/24 or do they have different subnets and just the same vlan tag?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please advise,&lt;/P&gt;</description>
      <pubDate>Mon, 01 Apr 2019 17:58:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/extending-vlan/m-p/255658#M72520</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2019-04-01T17:58:30Z</dc:date>
    </item>
    <item>
      <title>Re: extending vlan</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/extending-vlan/m-p/255690#M72525</link>
      <description>&lt;P&gt;The best way I've been able to do this is by having a different subnet at each location such as this: 10.10.1.0/24 and 10.30.1.0/24.&amp;nbsp; I create a L3-Interface on both firewalls and create the necessary routers.&amp;nbsp; I then created a rule in Panorama and applied it to both firewalls like so:&amp;nbsp; Trust=&amp;gt;RemoveOffices(10.10.1.0/24,10.30.1.0/24); App-ID: Any, Service: Any =&amp;gt; Trust=&amp;gt;RemoteOffices(10.10.1.0/24, 10.30.1.0/24); App-ID: Any, Service: Any.&amp;nbsp; When applied to both sets of firewalls you'll get a psuedo VLAN extention.&amp;nbsp; To make it scale a little, create an Address Group named something like: VLAN1.&amp;nbsp; Then reference that in any rule you create.&amp;nbsp; You must always include Remote-Office (To and/or From) as appropriate.&amp;nbsp; This will allow all traffic originated on VLAN1 on site1 to VLAN1 on site2 (simulates an extended VLAN between sites).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've used this and it works quite well.&amp;nbsp; The only gotcha you need to be careful of is when specifying the Interface between firewalls.&amp;nbsp; I use a dedicated Interface or Tunnel and keep my routes very specific only to the other site.&amp;nbsp; Any other routes should probably not traverse that link unless it absolutely needs to.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Good Luck!&lt;/P&gt;</description>
      <pubDate>Mon, 01 Apr 2019 21:59:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/extending-vlan/m-p/255690#M72525</guid>
      <dc:creator>ScottF</dc:creator>
      <dc:date>2019-04-01T21:59:28Z</dc:date>
    </item>
    <item>
      <title>Re: extending vlan</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/extending-vlan/m-p/255721#M72534</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Why do I need a virtual router ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 02 Apr 2019 05:03:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/extending-vlan/m-p/255721#M72534</guid>
      <dc:creator>simsim</dc:creator>
      <dc:date>2019-04-02T05:03:20Z</dc:date>
    </item>
    <item>
      <title>Re: extending vlan</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/extending-vlan/m-p/255722#M72535</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Same ip and same vlan tag&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 02 Apr 2019 05:04:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/extending-vlan/m-p/255722#M72535</guid>
      <dc:creator>simsim</dc:creator>
      <dc:date>2019-04-02T05:04:46Z</dc:date>
    </item>
    <item>
      <title>Re: extending vlan</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/extending-vlan/m-p/255815#M72556</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;They cannot be the same IP address for management. If you are doing HA A/P, then the interface will have the same IP but the passive will be shut down since they are 'passive'.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;</description>
      <pubDate>Tue, 02 Apr 2019 22:15:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/extending-vlan/m-p/255815#M72556</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2019-04-02T22:15:58Z</dc:date>
    </item>
    <item>
      <title>Re: extending vlan</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/extending-vlan/m-p/255876#M72566</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sorry for the confusion , I am not talking about the management ip . What I mean is&amp;nbsp; vlan is same in both sites&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 03 Apr 2019 08:03:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/extending-vlan/m-p/255876#M72566</guid>
      <dc:creator>simsim</dc:creator>
      <dc:date>2019-04-03T08:03:19Z</dc:date>
    </item>
    <item>
      <title>Re: extending vlan</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/extending-vlan/m-p/255884#M72568</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/59972"&gt;@simsim&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I feel there is a communication gap. hope you need to explain the requirment bit detail.&lt;/P&gt;&lt;P&gt;If you are using different ip segment in both locations, you can have ipsec between two sites, and route the segments through tunnel in both firewall and have a proper security policy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As vlan is just local to local network, you have L3 connectivity between two locations(and as per commends, you are using diffrent ip segments in both locations), need not to bother about vlan much.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But if you need a L2 extension like psuedowire ( L2VPN), i dont thing PA is having it now.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Apr 2019 08:21:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/extending-vlan/m-p/255884#M72568</guid>
      <dc:creator>Abdul_Razaq</dc:creator>
      <dc:date>2019-04-03T08:21:07Z</dc:date>
    </item>
    <item>
      <title>Re: extending vlan</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/extending-vlan/m-p/255894#M72571</link>
      <description>&lt;P&gt;If you have Layer 3 in between then it does not matter at all if vlan number is the same or not.&lt;/P&gt;&lt;P&gt;Important is if your IP subnet is the same. In your case it seems to be.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;All you have to do is to use NAT at both sides to overcome it.&lt;/P&gt;&lt;P&gt;&lt;A title="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClNxCAK" href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClNxCAK" target="_blank" rel="noopener"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClNxCAK&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Apr 2019 13:54:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/extending-vlan/m-p/255894#M72571</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2019-04-03T13:54:27Z</dc:date>
    </item>
  </channel>
</rss>

