- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
08-30-2016 10:02 PM
Hi there,
On Palo Alto I have configured L3 interface and assgined ip address to it. I would like to connect this interface to the switch. The switch has an SVI configured with the port in the same vlan as the SVI. Can I connect the Palo Alto interface to the switch port which is configured with a vlan or do I need to make the switch port as a routing port.
Thanks Guys
08-31-2016 01:49 AM
Hi!
the firewall does not participate in STP so layer2 SVI bridging does not work, you can choose either
hope this helps
08-31-2016 03:37 PM
@harmander wrote:Hi there,
On Palo Alto I have configured L3 interface and assgined ip address to it. I would like to connect this interface to the switch. The switch has an SVI configured with the port in the same vlan as the SVI. Can I connect the Palo Alto interface to the switch port which is configured with a vlan or do I need to make the switch port as a routing port.
Thanks Guys
I do exactly that on my core switches to allow for the HA configuration.
Firewall is configured with an L3 interface, switch cluster is configured with an RVI (Juniper speak, not Cisco), each port for the firewall is a simple access port in the associated VLAN for the RVI. I just post routes to the RVI address.
That way, it doesn't matter which firewall is active at the time - both are connected into the same routes, and an ARP flood when HA failover occurs means I rarely even lose a packet in the event of a HA event.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!