<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Layer 2 Interfaces together with Vlan Interfaces or Layer 3 Interfaces in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/layer-2-interfaces-together-with-vlan-interfaces-or-layer-3/m-p/301771#M78712</link>
    <description>&lt;P&gt;I'm looking to configure Layer 3 subinterfaces with the access layer switches pointing to the subinterface IP as it's gateway.&amp;nbsp; As this is East/West traffic, I am concerned about routing between the "East VLANs" routing to the "West network interfaces".&amp;nbsp; I have all the interfaces in the same virtual router.&amp;nbsp; The firewall isn't operational yet, but hope it works.&amp;nbsp; I cannot find much documentation on this type of configuration.&lt;/P&gt;</description>
    <pubDate>Mon, 02 Dec 2019 23:08:33 GMT</pubDate>
    <dc:creator>Todd_Benshoof</dc:creator>
    <dc:date>2019-12-02T23:08:33Z</dc:date>
    <item>
      <title>Layer 2 Interfaces together with Vlan Interfaces or Layer 3 Interfaces</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/layer-2-interfaces-together-with-vlan-interfaces-or-layer-3/m-p/274898#M75199</link>
      <description>&lt;P&gt;Hello Community&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am struggling to choose one of the following two configurations. Which concept would you choose?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a trunk between the Paloalto (PA-5060) and a switch.&lt;BR /&gt;In the first variant I would configure the trunk interface on the paloalto as a layer 3 interface (subinterfaces). The IP, vlan tag etc. are directly on the interface. In the secound variant I would configure the trunk interface as layer 2 which I assign a vlan interface.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Simplified the following network scheme:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="paloalto-l2-or-l3-interface.jpg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/20553iCE6C4FAEB40EF2AE/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="paloalto-l2-or-l3-interface.jpg" alt="paloalto-l2-or-l3-interface.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Are there any advantages/disadvantages about these the two variants? Are there some best practices about when to use L2 or L3 Interfaces?&lt;/P&gt;&lt;P&gt;One advantage of the L2 interface I thought about is, that unused Ports on the Paloalto are less difficult to integrate to an existing Vlan/network.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;BR /&gt;Dominik&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jul 2019 11:31:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/layer-2-interfaces-together-with-vlan-interfaces-or-layer-3/m-p/274898#M75199</guid>
      <dc:creator>iabueltm</dc:creator>
      <dc:date>2019-07-04T11:31:03Z</dc:date>
    </item>
    <item>
      <title>Re: Layer 2 Interfaces together with Vlan Interfaces or Layer 3 Interfaces</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/layer-2-interfaces-together-with-vlan-interfaces-or-layer-3/m-p/274907#M75200</link>
      <description>layer2 makes it possible to plop the firewall, using as many ports as you like, in the middle if a switched environment with the same broadcast domains east and west (you could bridge 3 switches all holding the same vlans, for example)
layer3 makes for a more traditional routed environment where each network requires routing to get to another network

from a security perspective having routing in the mix, prevents 'rogue' subnets in one vlan from being able to traverse onto a legitimate subnet in a different vlan, it also simplifies segregation</description>
      <pubDate>Thu, 04 Jul 2019 12:09:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/layer-2-interfaces-together-with-vlan-interfaces-or-layer-3/m-p/274907#M75200</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2019-07-04T12:09:39Z</dc:date>
    </item>
    <item>
      <title>Re: Layer 2 Interfaces together with Vlan Interfaces or Layer 3 Interfaces</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/layer-2-interfaces-together-with-vlan-interfaces-or-layer-3/m-p/275023#M75220</link>
      <description>&lt;P&gt;Hi Reaper&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your response.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In my situation there is only one aggregated link from the switching fabric to the firewall.&lt;BR /&gt;Therefore I dont need the firewall to switch packets. So i thought about configuring the link as L3.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The reason why I am still considering a L2 interface is that I can bind them to an vlan interface which is L3. With the Vlan interfaces i am able to route to different vlans/subnets with the virtual router from Palo. Also with this configuration i am still able to easily attach network devices to the Firewall.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Are there any drawbacks if I consider the L2 configuration method ?&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jul 2019 09:23:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/layer-2-interfaces-together-with-vlan-interfaces-or-layer-3/m-p/275023#M75220</guid>
      <dc:creator>iabueltm</dc:creator>
      <dc:date>2019-07-05T09:23:12Z</dc:date>
    </item>
    <item>
      <title>Re: Layer 2 Interfaces together with Vlan Interfaces or Layer 3 Interfaces</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/layer-2-interfaces-together-with-vlan-interfaces-or-layer-3/m-p/275024#M75221</link>
      <description>that works in layer3 mode as well, using tagged sub-interfaces
no real drawbacks in using Layer2 though, security wise all 3 modes are the same
Layer2 is a little more complex because you need to configure 3 different settings (vlan, vlan interface and physical interface/sub-interfaces) but that's basically the only difference</description>
      <pubDate>Fri, 05 Jul 2019 09:35:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/layer-2-interfaces-together-with-vlan-interfaces-or-layer-3/m-p/275024#M75221</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2019-07-05T09:35:11Z</dc:date>
    </item>
    <item>
      <title>Re: Layer 2 Interfaces together with Vlan Interfaces or Layer 3 Interfaces</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/layer-2-interfaces-together-with-vlan-interfaces-or-layer-3/m-p/275176#M75242</link>
      <description>&lt;P&gt;My preference is to use straight Layer-3 or Layer-3 + subinterfaces.&amp;nbsp; It is more simple &amp;amp; straight-forward to configure, and the great majority of the customers I've worked with use these L3 modes.&amp;nbsp; My rule of thumb is: "use L3 interfaces unless you can articulate the specific reasons why your deployment requires L2 w/ VLAN interfaces".&amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jul 2019 23:31:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/layer-2-interfaces-together-with-vlan-interfaces-or-layer-3/m-p/275176#M75242</guid>
      <dc:creator>jvalentine</dc:creator>
      <dc:date>2019-07-05T23:31:47Z</dc:date>
    </item>
    <item>
      <title>Re: Layer 2 Interfaces together with Vlan Interfaces or Layer 3 Interfaces</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/layer-2-interfaces-together-with-vlan-interfaces-or-layer-3/m-p/301771#M78712</link>
      <description>&lt;P&gt;I'm looking to configure Layer 3 subinterfaces with the access layer switches pointing to the subinterface IP as it's gateway.&amp;nbsp; As this is East/West traffic, I am concerned about routing between the "East VLANs" routing to the "West network interfaces".&amp;nbsp; I have all the interfaces in the same virtual router.&amp;nbsp; The firewall isn't operational yet, but hope it works.&amp;nbsp; I cannot find much documentation on this type of configuration.&lt;/P&gt;</description>
      <pubDate>Mon, 02 Dec 2019 23:08:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/layer-2-interfaces-together-with-vlan-interfaces-or-layer-3/m-p/301771#M78712</guid>
      <dc:creator>Todd_Benshoof</dc:creator>
      <dc:date>2019-12-02T23:08:33Z</dc:date>
    </item>
    <item>
      <title>Re: Layer 2 Interfaces together with Vlan Interfaces or Layer 3 Interfaces</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/layer-2-interfaces-together-with-vlan-interfaces-or-layer-3/m-p/301820#M78722</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/76305"&gt;@Todd_Benshoof&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;this sounds pretty straight forward, do you have a network design?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;if you have all L3 (sub)interfaces, and they're all in the same VR, routing will happen automagically (the routing table will be populated with 'connected' networks and route from the get-go)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Dec 2019 09:20:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/layer-2-interfaces-together-with-vlan-interfaces-or-layer-3/m-p/301820#M78722</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2019-12-03T09:20:08Z</dc:date>
    </item>
    <item>
      <title>Re: Layer 2 Interfaces together with Vlan Interfaces or Layer 3 Interfaces</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/layer-2-interfaces-together-with-vlan-interfaces-or-layer-3/m-p/595687#M118529</link>
      <description>&lt;P&gt;Good evening,&lt;BR /&gt;Please Help find solution with example with L2, L3 sub, L3. West solution.&lt;BR /&gt;I find&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClKMCA0" target="_blank"&gt;How to Configure a Layer 2 to Layer 3 Connection on the Palo Al... - Knowledge Base - Palo Alto Networks&lt;/A&gt;&lt;BR /&gt;But KB missing part of solution.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Aug 2024 20:02:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/layer-2-interfaces-together-with-vlan-interfaces-or-layer-3/m-p/595687#M118529</guid>
      <dc:creator>O.Oleg</dc:creator>
      <dc:date>2024-08-22T20:02:03Z</dc:date>
    </item>
  </channel>
</rss>

