Experience/feedback with VLAN insertion design for East-West traffic segregation

cancel
Showing results for 
Search instead for 
Did you mean: 

Experience/feedback with VLAN insertion design for East-West traffic segregation

L1 Bithead

Experience/feedback with VLAN insertion design for East-West traffic segregation

 

We are planning to leverage the VLAN insertion design for achieving micro segmentation in out OT network. 

 

just thought of checking within the Live community team for any feedback, caveats  based on your experience with similar implemetation. Thank you.

 

https://www.paloaltonetworks.com/resources/whitepapers/applying-vlan-insertion-in-ics-scada 

 

PratheeshP_0-1633468112522.jpeg

 

2 REPLIES 2

Cyber Elite
Cyber Elite

Hello,

On some devices, I started with something like the following:

Source Zone: trust, Source User: AD group that has access, Destination, Zone and IP address of scada/device, enable threat prevention and disable url filtering.

With this I can limit the traffic to those who have access and then watch and see what applications if any are being discovered, then tune from there.

 

The other thing I have seen is that some PAN models is that the amount of zones is limited. So I created a zone called something like IOT, and then set policies of source and destination IP's/subnets. Since I have a DENY ALL policy as my last rule, the intra zone traffic is blocked. 

 

Hope that helps a bit.

thank you for your reply. I agree with your comment on the Zone dependency per FW hardware.

Based on your experience, any comment on the below items:

  • What will be the SVI for VLAN for Layer 3 communication to outside segments?
    • I am planning to configure all my OT systems in the current segment to a dedicated VLAN per connected port, trunked to FW (VLAN insertion). Not sure how the SVI Gateway (Layer 3) will be required on the FW?
  • How broadcast and multi-cast will be handled?
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!