- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
02-14-2020 06:42 AM - edited 02-14-2020 07:10 AM
Hi,
Initial config query! We currently have 2 leased lines going into a managed switch for failover capabilities with then a single cable going into our existing firewall (Zywall).
This weekend we would like to switch out the existing firewall with our new PA-850 but retain the managed failover switch within the dataflow (this will be replaced in a months' time so that both leased lines go directly into the PA-850).
On our current firewall, the port connected to the managed switch is configured as:
IP: xxx.xxx.xxx.21
Subnet Mask: 255.255.255.240
Gateway: xxx.xxx.xxx.17
As I try to configure the interface on the PA-850, I've assigned ethernet1/1 as a Layer3 interface with a static IP address using the same xxx.xxx.xxx.21 but am unsure if this is the best way and if I need to enter the subnet mask and gateway information anyway.
In terms of data flow:
Internet > ISP1 router + ISP2 router> Switch handling failover > Ethernet 1 on PA-850
Advice would be appreciated.
Many thanks in advance
02-14-2020 09:44 AM
Hello,
While I cant recall ever doing it with one port, it might be possible if you use sub-interfaces.
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PLL8CAO
I tend to make my physical ports layer2 and then make a layer 3 vlan, but thats more preference than anything.
Hope that helps.
02-15-2020 09:25 AM
Hi@OtakarKlier ,
Are you suggesting to give VLAN tagging on firewall sub interfaces?
Mayur
02-15-2020 09:26 AM
Hi @fa2019 , configuration that you have planned should be fine. It'll work as expected.
Mayur
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!