<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Vwire connection between edge and distribution switch in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/vwire-connection-between-edge-and-distribution-switch/m-p/301932#M78741</link>
    <description>&lt;P&gt;Since your devices are using link aggregation, have you considered adding your vwire interfaces as an aggregate interfaces as well?&lt;BR /&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/networking/configure-interfaces/virtual-wire-interfaces/aggregated-interfaces-for-a-virtual-wire" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/networking/configure-interfaces/virtual-wire-interfaces/aggregated-interfaces-for-a-virtual-wire&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;If for whatever reason you can't do this, do you need to have four separate security zones?&amp;nbsp; Could you put both "outside" interfaces in one security zone, and both "inside" interfaces in another, and use a single security policy?&lt;/P&gt;</description>
    <pubDate>Tue, 03 Dec 2019 17:59:05 GMT</pubDate>
    <dc:creator>OwenFuller</dc:creator>
    <dc:date>2019-12-03T17:59:05Z</dc:date>
    <item>
      <title>Vwire connection between edge and distribution switch</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vwire-connection-between-edge-and-distribution-switch/m-p/301922#M78737</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have stack of 2 edge switch and stack of 2 distribution switches.&lt;/P&gt;&lt;P&gt;We have linkagg containing 2 ports running between them.&lt;/P&gt;&lt;P&gt;IT is layer 2 connection only between edge and distro.&lt;/P&gt;&lt;P&gt;Also we have MAnagement vlan on switch so that users can access it remotely&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Need to put PA in vwire mode.&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="vwire.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/22775i1EABFA53F11F91F7/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="vwire.png" alt="vwire.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;So for vwire&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I will have two pair of vwires and i will need to have&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;4 zones and two security polices to traffic flows from edge switch to distro.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;if i need to ssh to edge switch then traffic flow is via the distribution switch in that case i need to allow ssh rule from both vwires as i do not know PA will use which physical link right?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Dec 2019 17:20:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vwire-connection-between-edge-and-distribution-switch/m-p/301922#M78737</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2019-12-03T17:20:20Z</dc:date>
    </item>
    <item>
      <title>Re: Vwire connection between edge and distribution switch</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vwire-connection-between-edge-and-distribution-switch/m-p/301932#M78741</link>
      <description>&lt;P&gt;Since your devices are using link aggregation, have you considered adding your vwire interfaces as an aggregate interfaces as well?&lt;BR /&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/networking/configure-interfaces/virtual-wire-interfaces/aggregated-interfaces-for-a-virtual-wire" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/networking/configure-interfaces/virtual-wire-interfaces/aggregated-interfaces-for-a-virtual-wire&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;If for whatever reason you can't do this, do you need to have four separate security zones?&amp;nbsp; Could you put both "outside" interfaces in one security zone, and both "inside" interfaces in another, and use a single security policy?&lt;/P&gt;</description>
      <pubDate>Tue, 03 Dec 2019 17:59:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vwire-connection-between-edge-and-distribution-switch/m-p/301932#M78741</guid>
      <dc:creator>OwenFuller</dc:creator>
      <dc:date>2019-12-03T17:59:05Z</dc:date>
    </item>
    <item>
      <title>Re: Vwire connection between edge and distribution switch</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vwire-connection-between-edge-and-distribution-switch/m-p/301983#M78744</link>
      <description>&lt;P&gt;As far as i know vwire work in pairs.&lt;/P&gt;&lt;P&gt;So far have not like that putting different vwire in same zone.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do not know how that will work will see if someone recommend that ?&lt;/P&gt;&lt;P&gt;Benefit if having separte&amp;nbsp; zones is that then you can see which port in linkagg uses amount of traffic.&lt;/P&gt;&lt;P&gt;As switch is doing hashing to use both ports of the linkagg to send traffic.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Dec 2019 21:10:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vwire-connection-between-edge-and-distribution-switch/m-p/301983#M78744</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2019-12-03T21:10:38Z</dc:date>
    </item>
    <item>
      <title>Re: Vwire connection between edge and distribution switch</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vwire-connection-between-edge-and-distribution-switch/m-p/301993#M78747</link>
      <description>&lt;P&gt;Yes, your vwires would still have pairs of interfaces, but that doesn't mean you are required to use four zones.&amp;nbsp; To clarify my previous comment, you can have two separate vwires with the inside/outside Ethernet interfaces in the same zone:&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2019-12-03 15_48_10-PanoramaPWk01.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/22811iEF452BDBD40C9479/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="2019-12-03 15_48_10-PanoramaPWk01.png" alt="2019-12-03 15_48_10-PanoramaPWk01.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;You could also have one vwire with aggregate Ethernet interfaces:&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2019-12-03 16_09_34-PanoramaPWk01.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/22812iFFDF77C2FCBB5064/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="2019-12-03 16_09_34-PanoramaPWk01.png" alt="2019-12-03 16_09_34-PanoramaPWk01.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Each option offers some advantages and disadvantages of course, and may or may not work for your situation.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Dec 2019 22:18:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vwire-connection-between-edge-and-distribution-switch/m-p/301993#M78747</guid>
      <dc:creator>OwenFuller</dc:creator>
      <dc:date>2019-12-03T22:18:48Z</dc:date>
    </item>
    <item>
      <title>Re: Vwire connection between edge and distribution switch</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vwire-connection-between-edge-and-distribution-switch/m-p/303343#M78967</link>
      <description>&lt;P&gt;Many thanks for answering my question!&lt;/P&gt;</description>
      <pubDate>Thu, 12 Dec 2019 05:40:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vwire-connection-between-edge-and-distribution-switch/m-p/303343#M78967</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2019-12-12T05:40:51Z</dc:date>
    </item>
  </channel>
</rss>

