<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic WAN interface Multiple IP addresses or sub interfaces? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/wan-interface-multiple-ip-addresses-or-sub-interfaces/m-p/371529#M88907</link>
    <description>&lt;P&gt;Hi - Looking for best practices advice on WAN interface. Currently the WAN interface has a /26 with multiple IP addresses for incoming web servers translated to different subnets behind the PAN.&amp;nbsp; Is there a default proxy arp working and is this the best practice or should the firewall have sub-interfaces?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 09 Dec 2020 13:36:55 GMT</pubDate>
    <dc:creator>stoff</dc:creator>
    <dc:date>2020-12-09T13:36:55Z</dc:date>
    <item>
      <title>WAN interface Multiple IP addresses or sub interfaces?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wan-interface-multiple-ip-addresses-or-sub-interfaces/m-p/371529#M88907</link>
      <description>&lt;P&gt;Hi - Looking for best practices advice on WAN interface. Currently the WAN interface has a /26 with multiple IP addresses for incoming web servers translated to different subnets behind the PAN.&amp;nbsp; Is there a default proxy arp working and is this the best practice or should the firewall have sub-interfaces?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Dec 2020 13:36:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wan-interface-multiple-ip-addresses-or-sub-interfaces/m-p/371529#M88907</guid>
      <dc:creator>stoff</dc:creator>
      <dc:date>2020-12-09T13:36:55Z</dc:date>
    </item>
    <item>
      <title>Re: WAN interface Multiple IP addresses or sub interfaces?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wan-interface-multiple-ip-addresses-or-sub-interfaces/m-p/373435#M88923</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/100004"&gt;@stoff&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;There's no reason to create additional sub-interfaces for your untrust interface if you don't need them. Just leave the interface with the /26 like you have now and use your NAT rulebase to assign them where needed.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Dec 2020 04:22:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wan-interface-multiple-ip-addresses-or-sub-interfaces/m-p/373435#M88923</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2020-12-10T04:22:15Z</dc:date>
    </item>
    <item>
      <title>Re: WAN interface Multiple IP addresses or sub interfaces?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wan-interface-multiple-ip-addresses-or-sub-interfaces/m-p/373480#M88929</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/100004"&gt;@stoff&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I, personally, am trying to avoid multiple IP address on the same interface like a plague. In some rear cased it is reasonable to do it, but in most cases there is a better way to accomplish your goal. I also agree with &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt; also that you don't need separate interface for each IP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When you use IP address in the NAT policy the firewall will automatically configure the proxy arp for that IP.&lt;/P&gt;&lt;P&gt;So my suggestion would be the same as &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt; :&lt;/P&gt;&lt;P&gt;- Configure your WAN interface with one IP from the /26 network&lt;/P&gt;&lt;P&gt;- Configure destination NAT policies with the rest of the addresses in the /26 network (or bi-directional static source nat, depending of your needs and nat policy). No need to have those addresses configured on firewall interface&lt;/P&gt;</description>
      <pubDate>Thu, 10 Dec 2020 10:08:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wan-interface-multiple-ip-addresses-or-sub-interfaces/m-p/373480#M88929</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2020-12-10T10:08:36Z</dc:date>
    </item>
    <item>
      <title>Re: WAN interface Multiple IP addresses or sub interfaces?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wan-interface-multiple-ip-addresses-or-sub-interfaces/m-p/374206#M89030</link>
      <description>&lt;P&gt;Thanks that make sense. I am going to get this cleaned up now.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Dec 2020 14:57:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wan-interface-multiple-ip-addresses-or-sub-interfaces/m-p/374206#M89030</guid>
      <dc:creator>stoff</dc:creator>
      <dc:date>2020-12-14T14:57:24Z</dc:date>
    </item>
  </channel>
</rss>

