802.1q tagged sub-interfaces on PA-500 v6.1 not working

Reply
Highlighted
L0 Member

802.1q tagged sub-interfaces on PA-500 v6.1 not working

I'm trying to consolidate multiple Layer3 interfaces into a single Layer3 interface using subinterfaces and VLAN tagging, but it's not working.

I'm hoping someone can point out the error in my configuration.

The current working configuration:

FIREWALL
ethernet1/2 - 192.168.102.254, untagged, zone 102

ethernet1/3 - 192.168.103.254, untagged, zone 103

ethernet1/4 - 192.168.104.254, untagged, zone 104

ethernet1/5 - 192.168.105.254, untagged, zone 105

VirtualRouter1 - ethernet1/2, ethernet1/3, ethernet1/4, ethernet1/5

SecurityPolicy - rules in place that allow communication between zones.

SWITCH

port2 - access port, vlan 102 <-> ethernet1/2

port3 - access port, vlan 103 <-> ethernet1/3

port4 - access port, vlan 104 <-> ethernet1/4

port5 - access port, vlan 105 <-> ethernet1/5

I attempted the configuration below but after the commit nothing could be accessed through the firewall.

FIREWALL
ethernet1/2 - no IP address, no zone

ethernet1/3 - no IP address, Layer3

   ethernet1/3.102 - 192.168.102.254/24, tagged 102, zone 102.

   ethernet1/3.103 - 192.168.103.254/24, tagged 103, zone 103.

   ethernet1/3.104 - 192.168.104.254/24, tagged 104, zone 104.

   ethernet1/3.105 - 192.168.105.254/24, tagged 105, zone 105.

ethernet1/4 - no IP address, no zone

ethernet1/5 - no IP address, no zone

VirtualRouter1 - ethernet1/2, ethernet1/3, ethernet1/4, ethernet1/5, ethernet1/3.102, ethernet1/3.103, ethernet1/3.104, ethernet1/3.105

SecurityPolicy - same zone rules in place from working configuration.

SWITCH

port2 - shutdown

port3 - tagged vlans 102, 103, 104, 105

port4 - shutdown

port5 - shutdown

L7 Applicator

Re: 802.1q tagged sub-interfaces on PA-500 v6.1 not working

Conceptually, this all looks correct.  I've had similar configurations working.

What symptoms or errors do you have?

Is the interface link up?

Any errors on the switch or firewall?

Any logs?

Steve Puluka BSEET - IP Architect - DQE Communications (Metro Ethernet/ISP)
ACE PanOS 6; ACE PanOS 7; ASE 3.0; PSE 7.0 Foundations & Associate in Platform; Cyber Security; Data Center
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!