Firewall between host and gateway

Reply
Highlighted
L2 Linker

Firewall between host and gateway

Sorry if this is really basic but...

I have configuration where, we've added a gateway to a subnet that we only want one host to be able to access to get offsite.  The gateway is on the other side of a vwire in the same subnet space obviously but in a different zone on the firewall. We're only allowing inbound connections from a client on the other side of this gateway into the subnet. No hosts in the subnet would be initiating connections to the client. 

My question is, since the FW is between the host and it's gateway, do I need a rule for the host inside the network to be able to arp for the gateway through the firewall and vice versa?

Or to make the question more generic I guess, do I need a rule to allow two hosts on the same subnet but separated by a vwire in different zones to be able to arp before a L3 connection gets established?

Thanks in advance.

Not applicable

Re: Firewall between host and gateway

Hi epeeler,

Yes. If the vwire zones are placed in different zones (trust and untrust), then you will require policy to allow the traffic to reach your gateway from host.

Regards,

Ramya

L2 Linker

Re: Firewall between host and gateway

Thanks Ramya,

What's the best way to restrict traffic to only arp?  I don't want the two machines to do anything other than pass ethernet frames between each other.

Not applicable

Re: Firewall between host and gateway

Hi,

As per my knowledge, there isn't a way to restrict just the ARP traffic.

Regards,

Ramya

L1 Bithead

Re: Firewall between host and gateway

Yeah, it doesn't look like PanOS knows about ARP.  We are attempting a similar configuration with the PA in Layer 2 configuration.  It's not obvious how to create a policy that allows ARP to traverse the firewall.

L2 Linker

Re: Firewall between host and gateway

I ended up not needing any specific rule for ARP. It just worked. The host is able to ARP for the gateway's IP address and respond to the allowed inbound L3 traffic from outside the firewall.

L1 Bithead

Re: Firewall between host and gateway

Thanks for the quick feedback.  If link layer traffic is allowed to pass between security zones without policy in Vwire, then it should do the same in Layer 2 config.

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!