<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Source MAC address white-list filtering on the  PA-220? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/source-mac-address-white-list-filtering-on-the-pa-220/m-p/283607#M76260</link>
    <description>&lt;P&gt;Thanks,&amp;nbsp; &amp;nbsp;I have&amp;nbsp; now sorted out the MAC address filtering on the core switches what the PA-220 connects to and have also gone with LACP between the PA-220&amp;nbsp; and the primary core switch stack. I will just&amp;nbsp; physicaly swap the cables over to the&amp;nbsp; backup stack with pre-configured ports if the&amp;nbsp; primary core switch stack ever goes wrong.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards: Elliott.&lt;/P&gt;</description>
    <pubDate>Mon, 19 Aug 2019 20:21:53 GMT</pubDate>
    <dc:creator>eveares</dc:creator>
    <dc:date>2019-08-19T20:21:53Z</dc:date>
    <item>
      <title>Source MAC address white-list filtering on the  PA-220?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/source-mac-address-white-list-filtering-on-the-pa-220/m-p/283201#M76201</link>
      <description>&lt;P&gt;Hi all, I am new here so sorry&amp;nbsp; if this is in the wrong place.&amp;nbsp; At my work place we&amp;nbsp; have a new single&amp;nbsp; &amp;nbsp;PA-220 firewall router that I am configuring to be used&amp;nbsp; as a router/gateway out for SIP traffic. The IP phones will use a interface on the PA-220 as their default&amp;nbsp;gateway.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What I want to know is it possible (and if so how) to configure&amp;nbsp; a source&amp;nbsp; MAC address&amp;nbsp; white-list&amp;nbsp;&amp;nbsp;&amp;nbsp; filter on the PA-220&amp;nbsp; so only authorised devices will be able to use the PA-220 as their default&amp;nbsp; gateway. Ideally&amp;nbsp;using a wild card filter for MAC addresses beginning&amp;nbsp;with a known&amp;nbsp; value.&amp;nbsp; That way only the&amp;nbsp; IP phones based on their&amp;nbsp;MAC address will be able to use the PA-220 as a default&amp;nbsp;gateway&amp;nbsp; out.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also (and if so how) , can one create a failover/floating interface from the PA-220 that goes to separate&amp;nbsp; &amp;nbsp;&amp;nbsp;core switch stacks, with one being active and the other being inactive unless the primary fails. As&amp;nbsp; &amp;nbsp;it is between different&amp;nbsp;switch stacks, LACP/Trunking can not be used.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Essentialy I want the PA-220 to&amp;nbsp; have a single link to our primary core switch stack and a single link our backup core switch stack, but only&amp;nbsp; a single&amp;nbsp; IP for the interface. If the link to the&amp;nbsp; &amp;nbsp;primary L3 core switch stack fails the link to the&amp;nbsp; backup&amp;nbsp;&amp;nbsp; L3 core switch stack becomes active instead. Again LACP/trunking&amp;nbsp; can not be used as&amp;nbsp; it&amp;nbsp; involves diffrent switch stacks. Basicly&amp;nbsp; &amp;nbsp;switch-independanmt teaming with a active/standby configuation.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards: Elliott.&lt;/P&gt;</description>
      <pubDate>Fri, 16 Aug 2019 17:28:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/source-mac-address-white-list-filtering-on-the-pa-220/m-p/283201#M76201</guid>
      <dc:creator>eveares</dc:creator>
      <dc:date>2019-08-16T17:28:12Z</dc:date>
    </item>
    <item>
      <title>Re: Source MAC address white-list filtering on the  PA-220?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/source-mac-address-white-list-filtering-on-the-pa-220/m-p/283508#M76241</link>
      <description>&lt;P&gt;hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/120135"&gt;@eveares&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;your first question is not possible, we don't filter on MAC addresses at the interface&lt;/P&gt;
&lt;P&gt;The second question you could possibly tackle by setting two interfaces to layer2 mode and then create a (virtual) vlan interface to be the Layer3 interface for the layer2 physical interfaces&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;both interfaces will be active, however. For failover capabilities you'd need to set up a cluster&lt;/P&gt;</description>
      <pubDate>Mon, 19 Aug 2019 12:56:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/source-mac-address-white-list-filtering-on-the-pa-220/m-p/283508#M76241</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2019-08-19T12:56:15Z</dc:date>
    </item>
    <item>
      <title>Re: Source MAC address white-list filtering on the  PA-220?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/source-mac-address-white-list-filtering-on-the-pa-220/m-p/283607#M76260</link>
      <description>&lt;P&gt;Thanks,&amp;nbsp; &amp;nbsp;I have&amp;nbsp; now sorted out the MAC address filtering on the core switches what the PA-220 connects to and have also gone with LACP between the PA-220&amp;nbsp; and the primary core switch stack. I will just&amp;nbsp; physicaly swap the cables over to the&amp;nbsp; backup stack with pre-configured ports if the&amp;nbsp; primary core switch stack ever goes wrong.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards: Elliott.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Aug 2019 20:21:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/source-mac-address-white-list-filtering-on-the-pa-220/m-p/283607#M76260</guid>
      <dc:creator>eveares</dc:creator>
      <dc:date>2019-08-19T20:21:53Z</dc:date>
    </item>
  </channel>
</rss>

