<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Best Placement Integration Approach in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/best-placement-integration-approach/m-p/382208#M89819</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/163084"&gt;@Nikko&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;With vwire you can achive your goal for inter-vlan traffic inspection/filtering. IMHO the only advantache of putting the PA in front of the core switch in vwire mode is that you will not have to change the default gateway for all of your vlans. You can event split the VLAN in separate sub-interfaces for the vwire &lt;A href="https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-admin/networking/configure-interfaces/virtual-wire-interfaces/virtual-wire-subinterfaces.html" target="_blank"&gt;Virtual Wire Subinterfaces (paloaltonetworks.com)&lt;/A&gt; - to have better control when building the policy.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;BUT&lt;/STRONG&gt;... The only problem with this approach would be that inter-vlan traffic will pass&lt;U&gt; twise &lt;/U&gt;over your firewall:&lt;/P&gt;&lt;P&gt;- once from host a (in vlan a) to core switch&lt;/P&gt;&lt;P&gt;- second from core switch to dest b (in vlan b)&lt;/P&gt;&lt;P&gt;So you have to take under the consideration when building your policy that you need two rules.&lt;/P&gt;&lt;P&gt;And eventually if the device can handle the performance.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 26 Jan 2021 21:50:15 GMT</pubDate>
    <dc:creator>aleksandar.astardzhiev</dc:creator>
    <dc:date>2021-01-26T21:50:15Z</dc:date>
    <item>
      <title>Best Placement Integration Approach</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/best-placement-integration-approach/m-p/382082#M89797</link>
      <description>&lt;P&gt;Hi Guys,&lt;/P&gt;&lt;P&gt;Just want to seek your inputs about what can be the best integration approach for this scenario.&lt;/P&gt;&lt;P&gt;Currently, the VLAN gateway is in my core switch and I will be introducing PA FW into my network. I want to have control and visibility for my intervlan switching, will the virtual-wire approach be the best for this scenario?&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am a bit not convinced if the virtual wire will be able to solve what I want for the intervlan because my current gateway is in the core switch.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jan 2021 04:25:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/best-placement-integration-approach/m-p/382082#M89797</guid>
      <dc:creator>Nikko</dc:creator>
      <dc:date>2021-01-26T04:25:48Z</dc:date>
    </item>
    <item>
      <title>Re: Best Placement Integration Approach</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/best-placement-integration-approach/m-p/382208#M89819</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/163084"&gt;@Nikko&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;With vwire you can achive your goal for inter-vlan traffic inspection/filtering. IMHO the only advantache of putting the PA in front of the core switch in vwire mode is that you will not have to change the default gateway for all of your vlans. You can event split the VLAN in separate sub-interfaces for the vwire &lt;A href="https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-admin/networking/configure-interfaces/virtual-wire-interfaces/virtual-wire-subinterfaces.html" target="_blank"&gt;Virtual Wire Subinterfaces (paloaltonetworks.com)&lt;/A&gt; - to have better control when building the policy.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;BUT&lt;/STRONG&gt;... The only problem with this approach would be that inter-vlan traffic will pass&lt;U&gt; twise &lt;/U&gt;over your firewall:&lt;/P&gt;&lt;P&gt;- once from host a (in vlan a) to core switch&lt;/P&gt;&lt;P&gt;- second from core switch to dest b (in vlan b)&lt;/P&gt;&lt;P&gt;So you have to take under the consideration when building your policy that you need two rules.&lt;/P&gt;&lt;P&gt;And eventually if the device can handle the performance.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jan 2021 21:50:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/best-placement-integration-approach/m-p/382208#M89819</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2021-01-26T21:50:15Z</dc:date>
    </item>
    <item>
      <title>Re: Best Placement Integration Approach</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/best-placement-integration-approach/m-p/382209#M89820</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/163084"&gt;@Nikko&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;If you're going to be using a v-wire configuration you need the traffic to actually cross the v-wire link. To really answer this you'll need to provide a network diagram and some additional information about how your network is actually configured.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jan 2021 21:50:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/best-placement-integration-approach/m-p/382209#M89820</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2021-01-26T21:50:18Z</dc:date>
    </item>
  </channel>
</rss>

