<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Correct IP setting when two firewalls connected to one ISP. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/correct-ip-setting-when-two-firewalls-connected-to-one-isp/m-p/261084#M74008</link>
    <description>&lt;P&gt;It all seems to be working,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It's just the loggs showing IP's from the other firewall that are the concern.&amp;nbsp; There's a 3rd Device on that subnet that also connects to the ISP, I don't see it at all in the loggs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 15 May 2019 08:54:59 GMT</pubDate>
    <dc:creator>RobinClayton</dc:creator>
    <dc:date>2019-05-15T08:54:59Z</dc:date>
    <item>
      <title>Correct IP setting when two firewalls connected to one ISP.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/correct-ip-setting-when-two-firewalls-connected-to-one-isp/m-p/261067#M74004</link>
      <description>&lt;P&gt;We have two PA's connecting to one ISP. One is just being set up.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The ISP is "10.10.10.0/27"&lt;/P&gt;&lt;P&gt;Route is "10.10.10.5"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is it correct to have both firewall external vlan interfaces as such&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;FW1 "10.10.10.99/27"&lt;/P&gt;&lt;P&gt;FW2 "10.10.10.122/27"&lt;/P&gt;&lt;P&gt;&amp;nbsp;Vlan 140&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Vlan.jpg" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/20041i1DFD528B1CC6D71A/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Vlan.jpg" alt="Vlan.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And for the NAT&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="NAT.jpg" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/20042i361BC29016DE2797/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="NAT.jpg" alt="NAT.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;FW1 Main Nat "10.10.10.99/27"&lt;/P&gt;&lt;P&gt;FW2 Main Nat "10.10.10.122/27"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I ask, because the new firewall is logging packets for the old firewall. I am seeing "x.x.x.99" on the firewall with VIP "x.x.x.122"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="monitor.jpg" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/20043i0BECD382E34D0404/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="monitor.jpg" alt="monitor.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 May 2019 08:19:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/correct-ip-setting-when-two-firewalls-connected-to-one-isp/m-p/261067#M74004</guid>
      <dc:creator>RobinClayton</dc:creator>
      <dc:date>2019-05-15T08:19:56Z</dc:date>
    </item>
    <item>
      <title>Re: Correct IP setting when two firewalls connected to one ISP.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/correct-ip-setting-when-two-firewalls-connected-to-one-isp/m-p/261080#M74006</link>
      <description>&lt;P&gt;- If your ISP's subnet is 10.10.10.0/27 , you have usable IP addresses 10.10.10.1 to 10.10.10.30, so your firewalls would need to have an IP in that range&lt;/P&gt;
&lt;P&gt;- your vlans are untagged, you'll want to tag them and use proper vlans on your switches to prevent having one giant, and insecure broadcast domain&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;are there any other nat rules? it's possible your old firewall has taken ownership of all the IP's in that subnet if there's a NAT policy that allows it&lt;/P&gt;</description>
      <pubDate>Wed, 15 May 2019 08:33:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/correct-ip-setting-when-two-firewalls-connected-to-one-isp/m-p/261080#M74006</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2019-05-15T08:33:55Z</dc:date>
    </item>
    <item>
      <title>Re: Correct IP setting when two firewalls connected to one ISP.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/correct-ip-setting-when-two-firewalls-connected-to-one-isp/m-p/261082#M74007</link>
      <description>&lt;P&gt;The IP's were just an obscured example.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Both have the same "/27"&amp;nbsp; on the interface and&amp;nbsp;is that correct?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Neither firewall has overlapping NAT IP addresses. the NAT addresses are x.x.x.y/27&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have the VLANS tagged on the aggregate interface, I assume that is sufficient and does not need tagged on the VLAN aswell. The switches are VLANED.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ae2.jpg" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/20044iF6C217EE6684E63D/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="ae2.jpg" alt="ae2.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 May 2019 08:49:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/correct-ip-setting-when-two-firewalls-connected-to-one-isp/m-p/261082#M74007</guid>
      <dc:creator>RobinClayton</dc:creator>
      <dc:date>2019-05-15T08:49:54Z</dc:date>
    </item>
    <item>
      <title>Re: Correct IP setting when two firewalls connected to one ISP.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/correct-ip-setting-when-two-firewalls-connected-to-one-isp/m-p/261084#M74008</link>
      <description>&lt;P&gt;It all seems to be working,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It's just the loggs showing IP's from the other firewall that are the concern.&amp;nbsp; There's a 3rd Device on that subnet that also connects to the ISP, I don't see it at all in the loggs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 May 2019 08:54:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/correct-ip-setting-when-two-firewalls-connected-to-one-isp/m-p/261084#M74008</guid>
      <dc:creator>RobinClayton</dc:creator>
      <dc:date>2019-05-15T08:54:59Z</dc:date>
    </item>
    <item>
      <title>Re: Correct IP setting when two firewalls connected to one ISP.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/correct-ip-setting-when-two-firewalls-connected-to-one-isp/m-p/261168#M74039</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Are you running active/passive or active/active? A/P doesnt need an IP for each firewall as they are shared between the two.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Wed, 15 May 2019 15:43:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/correct-ip-setting-when-two-firewalls-connected-to-one-isp/m-p/261168#M74039</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2019-05-15T15:43:42Z</dc:date>
    </item>
    <item>
      <title>Re: Correct IP setting when two firewalls connected to one ISP.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/correct-ip-setting-when-two-firewalls-connected-to-one-isp/m-p/261169#M74040</link>
      <description>&lt;P&gt;Two independant firewall HA&amp;nbsp;stacks, one ISP Subnet.&lt;/P&gt;</description>
      <pubDate>Wed, 15 May 2019 15:50:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/correct-ip-setting-when-two-firewalls-connected-to-one-isp/m-p/261169#M74040</guid>
      <dc:creator>RobinClayton</dc:creator>
      <dc:date>2019-05-15T15:50:08Z</dc:date>
    </item>
    <item>
      <title>Re: Correct IP setting when two firewalls connected to one ISP.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/correct-ip-setting-when-two-firewalls-connected-to-one-isp/m-p/261217#M74047</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;My guess is that you have a policy somewhere that allows the 'untrust' zone to 'untrust' zone traffic and its set to log. This will catch any traffic that the interface picks up on.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Wed, 15 May 2019 19:15:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/correct-ip-setting-when-two-firewalls-connected-to-one-isp/m-p/261217#M74047</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2019-05-15T19:15:49Z</dc:date>
    </item>
    <item>
      <title>Re: Correct IP setting when two firewalls connected to one ISP.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/correct-ip-setting-when-two-firewalls-connected-to-one-isp/m-p/261300#M74082</link>
      <description>&lt;P&gt;"Intrazone-Default" is set to log as per Palo Best Practice.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I will stop worrying about it as I thought the configuration was correct and there are no issues.&lt;/P&gt;</description>
      <pubDate>Thu, 16 May 2019 07:53:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/correct-ip-setting-when-two-firewalls-connected-to-one-isp/m-p/261300#M74082</guid>
      <dc:creator>RobinClayton</dc:creator>
      <dc:date>2019-05-16T07:53:18Z</dc:date>
    </item>
    <item>
      <title>Re: Correct IP setting when two firewalls connected to one ISP.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/correct-ip-setting-when-two-firewalls-connected-to-one-isp/m-p/261541#M74149</link>
      <description>&lt;P&gt;May I ask why you are using VLAN interfaces to begin with?&amp;nbsp; I avoid this if at all possbile.&amp;nbsp; I would recommend using sub-interfaces at Layer 3.&amp;nbsp; It is easier to manage, easier to read and makes your zone/ruleset clean.&amp;nbsp; If you're not transporting Layer 2 traffic through the firewall, VLAN interfaces are almost unnecessary.&amp;nbsp; Thoughts?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Lab Example -&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="subinterfacesPANexample.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/20067i3524803879F1E9D1/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="subinterfacesPANexample.PNG" alt="subinterfacesPANexample.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 17 May 2019 20:09:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/correct-ip-setting-when-two-firewalls-connected-to-one-isp/m-p/261541#M74149</guid>
      <dc:creator>jeremy.larsen</dc:creator>
      <dc:date>2019-05-17T20:09:09Z</dc:date>
    </item>
    <item>
      <title>Re: Correct IP setting when two firewalls connected to one ISP.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/correct-ip-setting-when-two-firewalls-connected-to-one-isp/m-p/261615#M74167</link>
      <description>&lt;P&gt;TBH never realy thought about it too much, It was how our original firewall was configured and how I have built things in the test labs. Can't even reember how we did it during the training course.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can see it's a bit cleaner having converted it all over.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Not even sure why I did not twig it was a possibility as I am running a L3 single interface at the moment to the outside world&lt;/P&gt;</description>
      <pubDate>Mon, 20 May 2019 08:51:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/correct-ip-setting-when-two-firewalls-connected-to-one-isp/m-p/261615#M74167</guid>
      <dc:creator>RobinClayton</dc:creator>
      <dc:date>2019-05-20T08:51:41Z</dc:date>
    </item>
    <item>
      <title>Re: Correct IP setting when two firewalls connected to one ISP.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/correct-ip-setting-when-two-firewalls-connected-to-one-isp/m-p/262311#M74341</link>
      <description>&lt;P&gt;It's easy to get confused by Palo Alto's various uses of VLAN.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;A "VLAN" interface is different from a "Layer 3" interface that has 802.1q vlan tags enabled.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On a PA device "VLAN" interfaces are used to create a virtual switch using ports on the firewall, and allow them to operate as layer 2 interfaces without routing abilities.&amp;nbsp; Essentially, it create a bridged interface using all the VLAN interfaces.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you want to enabled tagged (or untagged) 802.1q vlans on interfaces, then configure them as "Layer 3" and create sub-interfaces with the vlan tag set there.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Would be nice if PA updated their UI to remove the ambiguous and confusing "VLAN" interface type.&amp;nbsp; "Bridge" would be more accurate.&lt;/P&gt;</description>
      <pubDate>Mon, 27 May 2019 17:56:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/correct-ip-setting-when-two-firewalls-connected-to-one-isp/m-p/262311#M74341</guid>
      <dc:creator>fjwcash</dc:creator>
      <dc:date>2019-05-27T17:56:31Z</dc:date>
    </item>
    <item>
      <title>Re: Correct IP setting when two firewalls connected to one ISP.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/correct-ip-setting-when-two-firewalls-connected-to-one-isp/m-p/262388#M74349</link>
      <description>&lt;P&gt;I couldn't agree with you more.&amp;nbsp; This really confused me the first time I used PAN and the documentation explaining this wasn't great.&lt;/P&gt;</description>
      <pubDate>Tue, 28 May 2019 13:23:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/correct-ip-setting-when-two-firewalls-connected-to-one-isp/m-p/262388#M74349</guid>
      <dc:creator>jeremy.larsen</dc:creator>
      <dc:date>2019-05-28T13:23:41Z</dc:date>
    </item>
  </channel>
</rss>

