<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Firewall between host and gateway in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/firewall-between-host-and-gateway/m-p/10360#M7624</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi epeeler,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes. If the vwire zones are placed in different zones (trust and untrust), then you will require policy to allow the traffic to reach your gateway from host.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Ramya&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 24 Mar 2015 18:32:12 GMT</pubDate>
    <dc:creator>rrajendran</dc:creator>
    <dc:date>2015-03-24T18:32:12Z</dc:date>
    <item>
      <title>Firewall between host and gateway</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/firewall-between-host-and-gateway/m-p/10359#M7623</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry if this is really basic but...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have configuration where, we've added a gateway to a subnet that we only want one host to be able to access to get offsite.&amp;nbsp; The gateway is on the other side of a vwire in the same subnet space obviously but in a different zone on the firewall. We're only allowing inbound connections from a client on the other side of this gateway into the subnet. No hosts in the subnet would be initiating connections to the client.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My question is, since the FW is between the host and it's gateway, do I need a rule for the host inside the network to be able to arp for the gateway through the firewall and vice versa?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Or to make the question more generic I guess, do I need a rule to allow two hosts on the same subnet but separated by a vwire in different zones to be able to arp before a L3 connection gets established?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Mar 2015 16:43:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/firewall-between-host-and-gateway/m-p/10359#M7623</guid>
      <dc:creator>epeeler</dc:creator>
      <dc:date>2015-03-24T16:43:56Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall between host and gateway</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/firewall-between-host-and-gateway/m-p/10360#M7624</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi epeeler,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes. If the vwire zones are placed in different zones (trust and untrust), then you will require policy to allow the traffic to reach your gateway from host.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Ramya&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Mar 2015 18:32:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/firewall-between-host-and-gateway/m-p/10360#M7624</guid>
      <dc:creator>rrajendran</dc:creator>
      <dc:date>2015-03-24T18:32:12Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall between host and gateway</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/firewall-between-host-and-gateway/m-p/10361#M7625</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Ramya,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What's the best way to restrict traffic to only arp?&amp;nbsp; I don't want the two machines to do anything other than pass ethernet frames between each other.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Mar 2015 19:23:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/firewall-between-host-and-gateway/m-p/10361#M7625</guid>
      <dc:creator>epeeler</dc:creator>
      <dc:date>2015-03-24T19:23:51Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall between host and gateway</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/firewall-between-host-and-gateway/m-p/10362#M7626</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As per my knowledge, there isn't a way to restrict just the ARP traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Ramya&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Mar 2015 23:06:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/firewall-between-host-and-gateway/m-p/10362#M7626</guid>
      <dc:creator>rrajendran</dc:creator>
      <dc:date>2015-03-24T23:06:56Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall between host and gateway</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/firewall-between-host-and-gateway/m-p/10363#M7627</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yeah, it doesn't look like PanOS knows about ARP.&amp;nbsp; We are attempting a similar configuration with the PA in Layer 2 configuration.&amp;nbsp; It's not obvious how to create a policy that allows ARP to traverse the firewall.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 May 2015 21:52:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/firewall-between-host-and-gateway/m-p/10363#M7627</guid>
      <dc:creator>jsu2</dc:creator>
      <dc:date>2015-05-14T21:52:46Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall between host and gateway</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/firewall-between-host-and-gateway/m-p/10364#M7628</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I ended up not needing any specific rule for ARP. It just worked. The host is able to ARP for the gateway's IP address and respond to the allowed inbound L3 traffic from outside the firewall. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 May 2015 13:23:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/firewall-between-host-and-gateway/m-p/10364#M7628</guid>
      <dc:creator>epeeler</dc:creator>
      <dc:date>2015-05-15T13:23:40Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall between host and gateway</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/firewall-between-host-and-gateway/m-p/10365#M7629</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the quick feedback.&amp;nbsp; If link layer traffic is allowed to pass between security zones without policy in Vwire, then it should do the same in Layer 2 config.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 May 2015 21:43:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/firewall-between-host-and-gateway/m-p/10365#M7629</guid>
      <dc:creator>jsu2</dc:creator>
      <dc:date>2015-05-15T21:43:39Z</dc:date>
    </item>
  </channel>
</rss>

