<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Block and Allow internet access for VLAN in switches sitting behind PA FW in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/block-and-allow-internet-access-for-vlan-in-switches-sitting/m-p/437234#M97402</link>
    <description>&lt;P&gt;Thank you for reply&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/194770"&gt;@isentric89&lt;/a&gt; If you get stuck with anything else do not hesitate to ask.&lt;/P&gt;</description>
    <pubDate>Tue, 28 Sep 2021 23:17:43 GMT</pubDate>
    <dc:creator>PavelK</dc:creator>
    <dc:date>2021-09-28T23:17:43Z</dc:date>
    <item>
      <title>Block and Allow internet access for VLAN in switches sitting behind PA FW</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-and-allow-internet-access-for-vlan-in-switches-sitting/m-p/436748#M96300</link>
      <description>&lt;P&gt;Hi Support,&lt;/P&gt;&lt;P&gt;We have configured additional VLAN in our cisco core switches sitting behind PA FW.&lt;/P&gt;&lt;P&gt;I want to allow and block internet in certain VLAN, eg VLAN7 to allow and VLAN70 in the switches to block internet access.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any procedures and where to check for this kind setup of situation in PA?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks all !!&lt;/P&gt;</description>
      <pubDate>Mon, 27 Sep 2021 06:37:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-and-allow-internet-access-for-vlan-in-switches-sitting/m-p/436748#M96300</guid>
      <dc:creator>isentric89</dc:creator>
      <dc:date>2021-09-27T06:37:29Z</dc:date>
    </item>
    <item>
      <title>Re: Block and Allow internet access for VLAN in switches sitting behind PA FW</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-and-allow-internet-access-for-vlan-in-switches-sitting/m-p/436766#M96301</link>
      <description>&lt;P&gt;Thank you for posting the question&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/194770"&gt;@isentric89&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Probably the easiest way is to configure a new security policy and use as Source Address the subnet configured for Vlan 70 and application: "web-browsing" with the action: Deny, then place this rule on the top to make sure it will be hit first. If your default policy is to allow internet traffic, then you do not need to take any further action to explicitly allow internet for Vlan 7. If your default policy is to block everything, then do it over way around. Configure a new security policy and use as Source Address the subnet configured for Vlan 7 and application: "web-browsing" with the action: Allow.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can confirm the desired outcome of the configuration from Traffic log.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind Regards&lt;/P&gt;&lt;P&gt;Pavel&lt;/P&gt;</description>
      <pubDate>Mon, 27 Sep 2021 08:09:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-and-allow-internet-access-for-vlan-in-switches-sitting/m-p/436766#M96301</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2021-09-27T08:09:12Z</dc:date>
    </item>
    <item>
      <title>Re: Block and Allow internet access for VLAN in switches sitting behind PA FW</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-and-allow-internet-access-for-vlan-in-switches-sitting/m-p/437233#M97401</link>
      <description>&lt;P&gt;Hi Pavel,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the suggestion !! Appreciated it&lt;/P&gt;</description>
      <pubDate>Tue, 28 Sep 2021 22:57:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-and-allow-internet-access-for-vlan-in-switches-sitting/m-p/437233#M97401</guid>
      <dc:creator>isentric89</dc:creator>
      <dc:date>2021-09-28T22:57:18Z</dc:date>
    </item>
    <item>
      <title>Re: Block and Allow internet access for VLAN in switches sitting behind PA FW</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-and-allow-internet-access-for-vlan-in-switches-sitting/m-p/437234#M97402</link>
      <description>&lt;P&gt;Thank you for reply&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/194770"&gt;@isentric89&lt;/a&gt; If you get stuck with anything else do not hesitate to ask.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Sep 2021 23:17:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-and-allow-internet-access-for-vlan-in-switches-sitting/m-p/437234#M97402</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2021-09-28T23:17:43Z</dc:date>
    </item>
  </channel>
</rss>

