<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Virtual wire with Vlan trunking and vlan mapping in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/virtual-wire-with-vlan-trunking-and-vlan-mapping/m-p/275360#M75264</link>
    <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I currently have a palo alto that is connected to my switches.&lt;/P&gt;&lt;P&gt;The palo alto is configured as a virtual wire, and the WAN side of the palo alto is connected to VLAN 10, the LAN side is connected to VLAN11&lt;/P&gt;&lt;P&gt;This allows me to quickly move customers in that VLAN in front of or behind the firewall by just changing their access port on the switch.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now I have another customer range that is using VLAN 20, and I want to create a firewalled VLAN 21 for them.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I put my virtual wire in trunking mode, is there any way to tell the Palo Alto that VLAN 10 needs to be "patched" to VLAN 11 only, and VLAN 20 needs to be "patched" to VLAN 21 only?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Otherwise my solution obviously is not going to work.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any recommendations?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 08 Jul 2019 15:13:36 GMT</pubDate>
    <dc:creator>CobaltGroup</dc:creator>
    <dc:date>2019-07-08T15:13:36Z</dc:date>
    <item>
      <title>Virtual wire with Vlan trunking and vlan mapping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/virtual-wire-with-vlan-trunking-and-vlan-mapping/m-p/275360#M75264</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I currently have a palo alto that is connected to my switches.&lt;/P&gt;&lt;P&gt;The palo alto is configured as a virtual wire, and the WAN side of the palo alto is connected to VLAN 10, the LAN side is connected to VLAN11&lt;/P&gt;&lt;P&gt;This allows me to quickly move customers in that VLAN in front of or behind the firewall by just changing their access port on the switch.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now I have another customer range that is using VLAN 20, and I want to create a firewalled VLAN 21 for them.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I put my virtual wire in trunking mode, is there any way to tell the Palo Alto that VLAN 10 needs to be "patched" to VLAN 11 only, and VLAN 20 needs to be "patched" to VLAN 21 only?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Otherwise my solution obviously is not going to work.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any recommendations?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jul 2019 15:13:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/virtual-wire-with-vlan-trunking-and-vlan-mapping/m-p/275360#M75264</guid>
      <dc:creator>CobaltGroup</dc:creator>
      <dc:date>2019-07-08T15:13:36Z</dc:date>
    </item>
    <item>
      <title>Re: Virtual wire with Vlan trunking and vlan mapping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/virtual-wire-with-vlan-trunking-and-vlan-mapping/m-p/275425#M75268</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Not sure what you mean by 'patched'. However if you are using multiple vlans, you could use sub-interfaces. I'm sure there is a reason you are using vwire instead of layer2 or 3?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jul 2019 20:01:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/virtual-wire-with-vlan-trunking-and-vlan-mapping/m-p/275425#M75268</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2019-07-08T20:01:51Z</dc:date>
    </item>
    <item>
      <title>Re: Virtual wire with Vlan trunking and vlan mapping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/virtual-wire-with-vlan-trunking-and-vlan-mapping/m-p/275526#M75273</link>
      <description>&lt;P&gt;To explain your question about patched, I have vlan 10 which is unprotected (in front of the palo) and vlan 11 which is protected (behind the palo)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So topology wise Switch&lt;/P&gt;&lt;P&gt;VLAN 10 &amp;lt;=&amp;gt; Palo Virtual Wire &amp;lt;=&amp;gt; Switch VLAN 11&lt;BR /&gt;Hosts in vlan 10 and vlan 11 use exactly the same IP addressen, and by simply changing the switch port on switch level, I can choose if the host needs to be firewalled yes or no,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The above example allow you to only connect vlan 10 to vlan 11.&lt;/P&gt;&lt;P&gt;Now what if I want to connect VLAN 10 to VLAN 11 and VLAN 20 to VLAN 21 over the same virtual wire&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Switch Trunk 10,20 &amp;lt;=&amp;gt; Palo Virtual Wire &amp;lt;=&amp;gt; Switch Trunk 11, 21&lt;/P&gt;&lt;P&gt;Is there any want to tell the virtual wire that VLAN 10 and 11 are connected to eachother, and VLAN 20 and 21.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope this clarifies my setup.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jul 2019 11:51:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/virtual-wire-with-vlan-trunking-and-vlan-mapping/m-p/275526#M75273</guid>
      <dc:creator>CobaltGroup</dc:creator>
      <dc:date>2019-07-09T11:51:42Z</dc:date>
    </item>
    <item>
      <title>Re: Virtual wire with Vlan trunking and vlan mapping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/virtual-wire-with-vlan-trunking-and-vlan-mapping/m-p/275538#M75276</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Then subinterfaces are the way to go.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/8-0/pan-os-admin/networking/configure-interfaces/virtual-wire-interfaces/virtual-wire-subinterfaces.html" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/8-0/pan-os-admin/networking/configure-interfaces/virtual-wire-interfaces/virtual-wire-subinterfaces.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jul 2019 13:22:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/virtual-wire-with-vlan-trunking-and-vlan-mapping/m-p/275538#M75276</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2019-07-09T13:22:03Z</dc:date>
    </item>
    <item>
      <title>Re: Virtual wire with Vlan trunking and vlan mapping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/virtual-wire-with-vlan-trunking-and-vlan-mapping/m-p/276600#M75363</link>
      <description>&lt;P&gt;Thank you for your answer. So today I was looking at how to design and I have a question about the approach&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have interface ethernet1/3 configured as virtual wire with subinterface .500 and .600&lt;/P&gt;&lt;P&gt;I have interface ethernet1/4 configured as virtual wire with subinterface .501 and .601&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Vlan 500 and 600 equal the internet/WAN side, vlan 501 and 601 equal the protected/firewall internal/LAN side&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;All traffic that arrives in VLAN 500 needs to be forwarded to VLAN 501&lt;/P&gt;&lt;P&gt;All traffic that arrives in VLAN 600 needs to be forwarded to VLAN 601&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Should I create 2 seperate virtual wires between&lt;/P&gt;&lt;P&gt;1) interface&amp;nbsp;ethernet1/3.500 and&amp;nbsp;ethernet1/3.501&lt;/P&gt;&lt;P&gt;2)&amp;nbsp;interface&amp;nbsp;ethernet1/4.600 and&amp;nbsp;ethernet1/3.601&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Or should I create 1 virtual wire between interface ethernet1/3 and interace ethernet1/4, where I will allow vlan 500 and 600 to be trunked.&lt;/P&gt;&lt;P&gt;But in this second case, how am I going to define the flow that traffic from VLAN 500 needs to go to VLAN501?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope my question is clear.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jul 2019 14:22:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/virtual-wire-with-vlan-trunking-and-vlan-mapping/m-p/276600#M75363</guid>
      <dc:creator>CobaltGroup</dc:creator>
      <dc:date>2019-07-15T14:22:35Z</dc:date>
    </item>
    <item>
      <title>Re: Virtual wire with Vlan trunking and vlan mapping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/virtual-wire-with-vlan-trunking-and-vlan-mapping/m-p/319013#M81858</link>
      <description>&lt;P&gt;I'm sure you found your answer but to close this out, you can't bridge vlans in a vWire implementation, what you are looking for is a Layer 2 implementation and you can bridge the vlans together. vWire send traffic out with the same tags which it receives.&lt;/P&gt;</description>
      <pubDate>Fri, 27 Mar 2020 12:26:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/virtual-wire-with-vlan-trunking-and-vlan-mapping/m-p/319013#M81858</guid>
      <dc:creator>jasloan</dc:creator>
      <dc:date>2020-03-27T12:26:41Z</dc:date>
    </item>
  </channel>
</rss>

