<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Manage Traffic within two vsys in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/manage-traffic-within-two-vsys/m-p/326320#M83166</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How to route traffic between two vsys on same firewall? Currently when I am trying to put policy, I am not able to see required destination under security policy which belongs to other vsys on same firewall.&amp;nbsp;Does it require some specific configuration?&lt;/P&gt;</description>
    <pubDate>Wed, 06 May 2020 11:44:24 GMT</pubDate>
    <dc:creator>Vikashh</dc:creator>
    <dc:date>2020-05-06T11:44:24Z</dc:date>
    <item>
      <title>Manage Traffic within two vsys</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/manage-traffic-within-two-vsys/m-p/326320#M83166</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How to route traffic between two vsys on same firewall? Currently when I am trying to put policy, I am not able to see required destination under security policy which belongs to other vsys on same firewall.&amp;nbsp;Does it require some specific configuration?&lt;/P&gt;</description>
      <pubDate>Wed, 06 May 2020 11:44:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/manage-traffic-within-two-vsys/m-p/326320#M83166</guid>
      <dc:creator>Vikashh</dc:creator>
      <dc:date>2020-05-06T11:44:24Z</dc:date>
    </item>
    <item>
      <title>Re: Manage Traffic within two vsys</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/manage-traffic-within-two-vsys/m-p/326329#M83168</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/134358"&gt;@Vikashh&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes, you can achieve it with the help of &lt;STRONG&gt;External Zone. &lt;/STRONG&gt;This type of zone is required&amp;nbsp; to allow traffic between zones in different Vsys. Such zones do not have any&amp;nbsp; interface or IP like normal security zones. These are only associated with specific Vsys. While creating such Zone, you need to select type as &lt;STRONG&gt;external &lt;/STRONG&gt;and configure desired &lt;STRONG&gt;Vsys&lt;/STRONG&gt;&amp;nbsp; under it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you have multiple Virtual Routers, you need to route traffic between Route-to-Router. You need&amp;nbsp; to add static Routes which will point to other VR as next hop.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Once your desired External zones are configured, you should see zone under Security Policy and have required communication between zones in different Vsys. As Traffic will get route from one vsys to other so you should have required security Policies and NAT (in any) under each Vsys.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope it helps!&lt;/P&gt;&lt;P&gt;Mayur&lt;/P&gt;</description>
      <pubDate>Wed, 06 May 2020 12:15:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/manage-traffic-within-two-vsys/m-p/326329#M83168</guid>
      <dc:creator>SutareMayur</dc:creator>
      <dc:date>2020-05-06T12:15:48Z</dc:date>
    </item>
    <item>
      <title>Re: Manage Traffic within two vsys</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/manage-traffic-within-two-vsys/m-p/326464#M83189</link>
      <description>&lt;P&gt;Thanks Mayur for detailed explanation. To be honest, I had some idea about external zone type. But never had experience on configuring and working around it. Now I am fully confident on the configuration part. Thank you again for your time and response. I will keep updated on this.&lt;/P&gt;</description>
      <pubDate>Wed, 06 May 2020 17:59:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/manage-traffic-within-two-vsys/m-p/326464#M83189</guid>
      <dc:creator>Vikashh</dc:creator>
      <dc:date>2020-05-06T17:59:54Z</dc:date>
    </item>
  </channel>
</rss>

