<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISP Router connection best practice in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/isp-router-connection-best-practice/m-p/387686#M90408</link>
    <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just looking for advise , pros vs cons about connecting an ISP internet feed directly to our core mpls/vpls switch. &amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;ISP Internet Router—&amp;gt;adva—&amp;gt;Core Switch(siteA)—&amp;gt;mpls/vpls—&amp;gt;Core Switch(siteB)—&amp;gt; Palo Alto&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The PA firewall will have a separate VR and will nat traffic from 10.x LAN to Public before routing out to Internet via core. &amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;There is ospf routing on all cores and distribution switches connecting to cores as well as L2/L3 traffic from other sites.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is this acceptable and what are the security concerns?&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 25 Feb 2021 01:22:56 GMT</pubDate>
    <dc:creator>MistryJa</dc:creator>
    <dc:date>2021-02-25T01:22:56Z</dc:date>
    <item>
      <title>ISP Router connection best practice</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/isp-router-connection-best-practice/m-p/387686#M90408</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just looking for advise , pros vs cons about connecting an ISP internet feed directly to our core mpls/vpls switch. &amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;ISP Internet Router—&amp;gt;adva—&amp;gt;Core Switch(siteA)—&amp;gt;mpls/vpls—&amp;gt;Core Switch(siteB)—&amp;gt; Palo Alto&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The PA firewall will have a separate VR and will nat traffic from 10.x LAN to Public before routing out to Internet via core. &amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;There is ospf routing on all cores and distribution switches connecting to cores as well as L2/L3 traffic from other sites.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is this acceptable and what are the security concerns?&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Feb 2021 01:22:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/isp-router-connection-best-practice/m-p/387686#M90408</guid>
      <dc:creator>MistryJa</dc:creator>
      <dc:date>2021-02-25T01:22:56Z</dc:date>
    </item>
    <item>
      <title>Re: ISP Router connection best practice</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/isp-router-connection-best-practice/m-p/387711#M90412</link>
      <description>&lt;P&gt;Hi Mate,&lt;/P&gt;&lt;P&gt;I am not sure about the other networks connected to your core, but the basic priniciple is to have your firewall as close to the perimeter as possible. Firewall is your first line of defence and not last.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It is a better design to filter all the traffic through firewall on site A, before being sent out to site B.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So what you have is feasible, but your call where you would like to have it. For me site A makes more sense.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Varun Rao&lt;/P&gt;</description>
      <pubDate>Thu, 25 Feb 2021 04:08:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/isp-router-connection-best-practice/m-p/387711#M90412</guid>
      <dc:creator>VarunRao</dc:creator>
      <dc:date>2021-02-25T04:08:14Z</dc:date>
    </item>
    <item>
      <title>Re: ISP Router connection best practice</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/isp-router-connection-best-practice/m-p/387721#M90414</link>
      <description>&lt;P&gt;Hello Varun,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Even if the static routing ensures that traffic gets routed directly to the firewall ?&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Feb 2021 05:54:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/isp-router-connection-best-practice/m-p/387721#M90414</guid>
      <dc:creator>MistryJa</dc:creator>
      <dc:date>2021-02-25T05:54:06Z</dc:date>
    </item>
  </channel>
</rss>

