<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Computers in remote clinic need to communicate with on prem server in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/computers-in-remote-clinic-need-to-communicate-with-on-prem/m-p/339039#M85197</link>
    <description>&lt;P&gt;We have just brought some remote clinics online. We have a point-to-point between our PA5520 at the main hospital and a PA820 at our remote site. We're routing between P2P with static routing at the moment. Data/Voice is working, as the VLANs are on the remote site switches themselves. However, we've been asked to get another VLAN working that is at our main hospital. Here's a quick crude drawing I put together in like 5 minutes:&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Downtown_remoteclincs.jpg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/26839i1B83EFCD40D3460A/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Downtown_remoteclincs.jpg" alt="Downtown_remoteclincs.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Each one of the remote switches is also connected via a P2P, be it direct connect or layer 2 transport, so the only way I can think of getting the devices at the remote clinics talking, is more routing, or NATing somehow. Any guidance would be appreciated. I now wish I would've went layer 2 instead of layer 3 for this...&lt;/P&gt;</description>
    <pubDate>Thu, 16 Jul 2020 19:10:17 GMT</pubDate>
    <dc:creator>lsaintig</dc:creator>
    <dc:date>2020-07-16T19:10:17Z</dc:date>
    <item>
      <title>Computers in remote clinic need to communicate with on prem server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/computers-in-remote-clinic-need-to-communicate-with-on-prem/m-p/339039#M85197</link>
      <description>&lt;P&gt;We have just brought some remote clinics online. We have a point-to-point between our PA5520 at the main hospital and a PA820 at our remote site. We're routing between P2P with static routing at the moment. Data/Voice is working, as the VLANs are on the remote site switches themselves. However, we've been asked to get another VLAN working that is at our main hospital. Here's a quick crude drawing I put together in like 5 minutes:&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Downtown_remoteclincs.jpg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/26839i1B83EFCD40D3460A/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Downtown_remoteclincs.jpg" alt="Downtown_remoteclincs.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Each one of the remote switches is also connected via a P2P, be it direct connect or layer 2 transport, so the only way I can think of getting the devices at the remote clinics talking, is more routing, or NATing somehow. Any guidance would be appreciated. I now wish I would've went layer 2 instead of layer 3 for this...&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jul 2020 19:10:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/computers-in-remote-clinic-need-to-communicate-with-on-prem/m-p/339039#M85197</guid>
      <dc:creator>lsaintig</dc:creator>
      <dc:date>2020-07-16T19:10:17Z</dc:date>
    </item>
    <item>
      <title>Re: Computers in remote clinic need to communicate with on prem server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/computers-in-remote-clinic-need-to-communicate-with-on-prem/m-p/339103#M85203</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Agreed!&amp;nbsp; If you need VLAN 176, you may need to rethink your deployment.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You could be very easy to use a feature called VWire, to connect from the clinic switch, to the (upstream device) that is allowing P2P (some interconnecting switch or whatever.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Consider that Vwire is sort of like a "intelligent" repeater.&amp;nbsp; Whatever is plugged into (port 3) goes out port 4. A bump in the wire.&lt;/P&gt;
&lt;P&gt;No L2 or Layer3 addressing (no mac or spanning tree, and definitely no routing)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Just create a VWire object, and assign 2 ports (not your L3 interfaces) and create 2 more zones (untrusted-vwire and trusted-vwire)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You may need to create similar policies to mimic what you have.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you do this, then you would not even need routing, the traffic goes from vlan176 in the clinic, through the FW, through the P2P to the other side, by the hospital.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Just an idea.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jul 2020 00:03:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/computers-in-remote-clinic-need-to-communicate-with-on-prem/m-p/339103#M85203</guid>
      <dc:creator>S.Cantwell</dc:creator>
      <dc:date>2020-07-17T00:03:37Z</dc:date>
    </item>
  </channel>
</rss>

