Configuring external connection through a switch

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Configuring external connection through a switch

L0 Member

Hi,


Initial config query! We currently have 2 leased lines going into a managed switch for failover capabilities with then a single cable going into our existing firewall (Zywall).

This weekend we would like to switch out the existing firewall with our new PA-850 but retain the managed failover switch within the dataflow (this will be replaced in a months' time so that both leased lines go directly into the PA-850).

On our current firewall, the port connected to the managed switch is configured as:
IP: xxx.xxx.xxx.21
Subnet Mask: 255.255.255.240
Gateway: xxx.xxx.xxx.17

As I try to configure the interface on the PA-850, I've assigned ethernet1/1 as a Layer3 interface with a static IP address using the same xxx.xxx.xxx.21 but am unsure if this is the best way and if I need to enter the subnet mask and gateway information anyway.

 

In terms of data flow:
Internet > ISP1 router + ISP2 router> Switch handling failover > Ethernet 1 on PA-850

 

Advice would be appreciated.

 

Many thanks in advance

4 REPLIES 4

Cyber Elite
Cyber Elite

Hello,

While I cant recall ever doing it with one port, it might be possible if you use sub-interfaces.

 

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PLL8CAO

 

I tend to make my physical ports layer2 and then make a layer 3 vlan, but thats more preference than anything.

 

Hope that helps.

Hi@OtakarKlier ,

 

Are you suggesting to give VLAN tagging on firewall sub interfaces?

 

Mayur

M

Cyber Elite
Cyber Elite

Hi @fa2019 , configuration that you have planned should be fine. It'll work as expected.

 

Mayur

M

Yes it should work.

  • 3391 Views
  • 4 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!