<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Zone for vpn? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/zone-for-vpn/m-p/378618#M89498</link>
    <description>&lt;P&gt;Hello ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have currently three diffent zones defined .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Zone A vlan 100. For wired users&amp;nbsp;&lt;/P&gt;&lt;P&gt;Zone B vlan 200 for wireless users&amp;nbsp;&lt;/P&gt;&lt;P&gt;Zone V tunnel/ loopback interface for Global protect users.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;All the above users mentioned are corp users.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now customer wants to create. single zone called "All users" and want to put vlan 100 200 and loopback/ tunnel into it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is it wise to use same zone for GP users ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is it doable ? What are the challenges of we have a single common zone for user traffic ( wired+wireless+gp users )&lt;/P&gt;</description>
    <pubDate>Fri, 08 Jan 2021 12:54:12 GMT</pubDate>
    <dc:creator>AubreyCooper</dc:creator>
    <dc:date>2021-01-08T12:54:12Z</dc:date>
    <item>
      <title>Zone for vpn?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/zone-for-vpn/m-p/378618#M89498</link>
      <description>&lt;P&gt;Hello ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have currently three diffent zones defined .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Zone A vlan 100. For wired users&amp;nbsp;&lt;/P&gt;&lt;P&gt;Zone B vlan 200 for wireless users&amp;nbsp;&lt;/P&gt;&lt;P&gt;Zone V tunnel/ loopback interface for Global protect users.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;All the above users mentioned are corp users.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now customer wants to create. single zone called "All users" and want to put vlan 100 200 and loopback/ tunnel into it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is it wise to use same zone for GP users ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is it doable ? What are the challenges of we have a single common zone for user traffic ( wired+wireless+gp users )&lt;/P&gt;</description>
      <pubDate>Fri, 08 Jan 2021 12:54:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/zone-for-vpn/m-p/378618#M89498</guid>
      <dc:creator>AubreyCooper</dc:creator>
      <dc:date>2021-01-08T12:54:12Z</dc:date>
    </item>
    <item>
      <title>Re: Zone for vpn?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/zone-for-vpn/m-p/378779#M89512</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/167526"&gt;@AubreyCooper&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can assign same Interface to Multiple zones.&lt;/P&gt;
&lt;P&gt;But Interface can be assigned to Single Zone only at one time.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can assign same all 3 Interface to new zones.&lt;/P&gt;
&lt;P&gt;I never done this but it is doable.&lt;/P&gt;
&lt;P&gt;Also it is not recommended best practice as now if you want to segment the traffic between 3 different zones then you can not do that now.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Only thing if you have to worry about is VR if all 3 Interface are in same&amp;nbsp; VR then you are good if they are in different VR then you need to modify the static routing in 3 VR's.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Sat, 09 Jan 2021 21:18:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/zone-for-vpn/m-p/378779#M89512</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2021-01-09T21:18:21Z</dc:date>
    </item>
    <item>
      <title>Re: Zone for vpn?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/zone-for-vpn/m-p/378813#M89516</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/167526"&gt;@AubreyCooper&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Did you ask this question last week in the GlobalProtect forum? If not, you can find the same discussion there within the past week.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In short, the only thing that would technically prevent you from doing this is if you have mixed interface types. You can't have an L3 zone with L2 interfaces or an L2 zone with L3 interfaces for example. As long as that isn't an issue in your environment, there's nothing preventing you from including all three of your interfaces in the same zone.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Now for whether or not it is a good idea or not, most people would say no. General consensus would be that you have your VPN traffic terminate on its own zone so that you have full control and visibility into what is access by users. In general from a security aspect, the more segmented you make your zones the more control you have over what goes where and you can make finer access controls.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Now to be perfectly clear, it isn't that you can't include all three interfaces in the same zone and still have a secure network. You can still override your intrazone-default policy to deny and manually build out intrazone security rulebase entries to control traffic. That generally isn't advisable because it's easier to accidently over-provision access or have traffic not getting logged when crossing the firewall. By default, PAN firewalls don't track intrazone traffic, it doesn't get logged at all, and it automatically allows the traffic. If you design things carefully you can have this be just as secure as using multiple different zones, it just generally takes more effort to do so.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Jan 2021 05:11:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/zone-for-vpn/m-p/378813#M89516</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2021-01-10T05:11:48Z</dc:date>
    </item>
  </channel>
</rss>

