<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Multi VSYS, VRs and ARP tables? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/multi-vsys-vrs-and-arp-tables/m-p/297746#M78104</link>
    <description>&lt;P&gt;Thanks for your feedback Burce,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Are you also running multiple VRs? And how are you providing Internet access to your current both VSYS? Are you using the same ISP subnet? Which means that you would have an ARP entry for VSYSA, and another ARP entry for VSYSB?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind Regards,&lt;/P&gt;</description>
    <pubDate>Mon, 11 Nov 2019 20:01:51 GMT</pubDate>
    <dc:creator>AlexandroDelAngel</dc:creator>
    <dc:date>2019-11-11T20:01:51Z</dc:date>
    <item>
      <title>Multi VSYS, VRs and ARP tables?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/multi-vsys-vrs-and-arp-tables/m-p/297374#M78060</link>
      <description>&lt;P&gt;Hello team,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I will be deploying a couple of 3250s in HA and multi VSYS, and VRs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My main concern is that are we getting separate ARP tables per each VSYS/VR? Let me give you some more background about what we will try to achieve:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We want to create 4 VSYS with their corresponding VRs, for example: VSYSa/VRa, VSYSb/VRb, VSYSc/VRc, VSYSd/VRd.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm planning to allocate a dedicated "Untrust" interface for each VSYS/VR.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The thing is that we are using the same Public IP Addresses range from the ISP, so all of the 4 VSYS/VRs will send traffic to the same Default Gateway/ISP Router. That's the reason why I would like someone to help me to confirm if the PAs in multi-vsys/vrs mode will keep separate ARP tables just like tradditional VRFs or Virtual Contexts on CISCO routers and ASA firewalls (Apologize for the comparison). Otherwise the 4 VSYS/VRs would be in constant conflict by keeping the single ARP entry (if no multiple ARP tables supported).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It will be nice if someone could share a screenshot with me about ARP tables behavior in multi vsys/vrs mode, documentation about this kind of setup will also be greatly appreciated. Below an screenshot of what we are trying to achieve.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="clipboard_image_0.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/22205iC07B8018ED21590E/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="clipboard_image_0.png" alt="clipboard_image_0.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind Regards,&lt;/P&gt;</description>
      <pubDate>Fri, 08 Nov 2019 19:59:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/multi-vsys-vrs-and-arp-tables/m-p/297374#M78060</guid>
      <dc:creator>AlexandroDelAngel</dc:creator>
      <dc:date>2019-11-08T19:59:46Z</dc:date>
    </item>
    <item>
      <title>Re: Multi VSYS, VRs and ARP tables?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/multi-vsys-vrs-and-arp-tables/m-p/297401#M78062</link>
      <description>&lt;P&gt;This will be interesting to learn myself.&lt;/P&gt;&lt;P&gt;We have a couple of firewalls with two VSYS and the ARP table, with the "show arp all" command it does not have any distinction for VSYS, only interfaces. Thinking about it, the ARP table is showing layer 2 information, tied to interfaces, so I am not sure it would matter if there were separate tables.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Nov 2019 21:22:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/multi-vsys-vrs-and-arp-tables/m-p/297401#M78062</guid>
      <dc:creator>BruceBennett</dc:creator>
      <dc:date>2019-11-08T21:22:46Z</dc:date>
    </item>
    <item>
      <title>Re: Multi VSYS, VRs and ARP tables?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/multi-vsys-vrs-and-arp-tables/m-p/297746#M78104</link>
      <description>&lt;P&gt;Thanks for your feedback Burce,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Are you also running multiple VRs? And how are you providing Internet access to your current both VSYS? Are you using the same ISP subnet? Which means that you would have an ARP entry for VSYSA, and another ARP entry for VSYSB?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind Regards,&lt;/P&gt;</description>
      <pubDate>Mon, 11 Nov 2019 20:01:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/multi-vsys-vrs-and-arp-tables/m-p/297746#M78104</guid>
      <dc:creator>AlexandroDelAngel</dc:creator>
      <dc:date>2019-11-11T20:01:51Z</dc:date>
    </item>
    <item>
      <title>Re: Multi VSYS, VRs and ARP tables?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/multi-vsys-vrs-and-arp-tables/m-p/297798#M78108</link>
      <description>&lt;P&gt;We run multiple vsys with a separate vr for each vsys. Each interface is assigned to a specific vr. We use a single ISP subnet and multiple vsys do use the same gateway.&lt;/P&gt;&lt;P&gt;When you look at arp information in the CLI, you can look at 'sh arp all' or 'sh arp &amp;lt;interface&amp;gt;'.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;'sh arp &amp;lt;interface&amp;gt;' is like 'sh arp vrf &amp;lt;vrf&amp;gt;' and it will only show entries specific to that interface. 'sh arp all' is like the Nexus command 'sh ip arp vrf all' and will display all entries.&lt;/P&gt;&lt;P&gt;If you look at either, you'll see the same entry for the gateway present on different interfaces. So there are different entries per vsys.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;show arp ethernet1/1 | match .19&lt;BR /&gt;ethernet1/1 x.x.x.19 2c::::6f:00 ethernet1/1&lt;/P&gt;&lt;P&gt;show arp ethernet1/5 | match .19&lt;BR /&gt;ethernet1/5 x.x.x.19 2c::::6f:00 ethernet1/5&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;show arp all | match .19&lt;BR /&gt;ethernet1/1 x.x.x.19 2c::::6f:00 ethernet1/1&amp;nbsp;&lt;BR /&gt;ethernet1/5 x.x.x.19 2c::::6f:00 ethernet1/5&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Nov 2019 22:51:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/multi-vsys-vrs-and-arp-tables/m-p/297798#M78108</guid>
      <dc:creator>rmfalconer</dc:creator>
      <dc:date>2019-11-11T22:51:10Z</dc:date>
    </item>
    <item>
      <title>Re: Multi VSYS, VRs and ARP tables?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/multi-vsys-vrs-and-arp-tables/m-p/297907#M78124</link>
      <description>&lt;P&gt;This is awesome feedback Rmfalconer,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now I know that my approach will work with no issues. Thanks for confirming that we should be able to see the same entry for ISP gateway on different interfaces.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind Regards,&lt;/P&gt;</description>
      <pubDate>Tue, 12 Nov 2019 14:22:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/multi-vsys-vrs-and-arp-tables/m-p/297907#M78124</guid>
      <dc:creator>AlexandroDelAngel</dc:creator>
      <dc:date>2019-11-12T14:22:57Z</dc:date>
    </item>
    <item>
      <title>Re: Multi VSYS, VRs and ARP tables?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/multi-vsys-vrs-and-arp-tables/m-p/297971#M78132</link>
      <description>&lt;P&gt;Just to add to this -&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Different vRouters on the same vSYS will also have independent ARP tables (analogous to Cisco VRF or Juniper vRouters).&lt;/P&gt;</description>
      <pubDate>Tue, 12 Nov 2019 16:53:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/multi-vsys-vrs-and-arp-tables/m-p/297971#M78132</guid>
      <dc:creator>jeremy.larsen</dc:creator>
      <dc:date>2019-11-12T16:53:03Z</dc:date>
    </item>
    <item>
      <title>Re: Multi VSYS, VRs and ARP tables?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/multi-vsys-vrs-and-arp-tables/m-p/297988#M78134</link>
      <description>&lt;P&gt;Awesome Jeremy,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your feedback, just as expected even when the CLI output does not explicitly state that. However, we can figure this out when we see multiple entries for the same ISP Gateway through different interfaces.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind Regards,&lt;/P&gt;</description>
      <pubDate>Tue, 12 Nov 2019 17:05:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/multi-vsys-vrs-and-arp-tables/m-p/297988#M78134</guid>
      <dc:creator>AlexandroDelAngel</dc:creator>
      <dc:date>2019-11-12T17:05:01Z</dc:date>
    </item>
  </channel>
</rss>

