Expressway-E and C and NAT and VW

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Expressway-E and C and NAT and VW

L4 Transporter

Hi,

 

I have deployed Expressway (cisco ToIP) E and C  as per the diagram below .PA is in VW mode .

Does it work  without any changes in the PA ? 

Or Is there any policy must be created ? 

 

Thanks PA.png

1 accepted solution

Accepted Solutions

Cyber Elite
Cyber Elite

@simsim,

This really depends on how you actually have the VWIRE setup. Without knowing what you config actually looks like it's kind of hard to say. 

Couple different scenarios

1) You have security policies on the Palo Alto that actually limit source/destinaton and the applications allowed to pass through the vwire. In this situation yes, you'd likely need to create some additional policy. 

2) You have the most basic vwire setup where the traffic is simply inspected but by default will allow everything to pass. In this situaiton you wouldn't need to create any additional policies. 

 

Really depends on your configuration, with the information given it's pretty much impossible to tell. 

View solution in original post

1 REPLY 1

Cyber Elite
Cyber Elite

@simsim,

This really depends on how you actually have the VWIRE setup. Without knowing what you config actually looks like it's kind of hard to say. 

Couple different scenarios

1) You have security policies on the Palo Alto that actually limit source/destinaton and the applications allowed to pass through the vwire. In this situation yes, you'd likely need to create some additional policy. 

2) You have the most basic vwire setup where the traffic is simply inspected but by default will allow everything to pass. In this situaiton you wouldn't need to create any additional policies. 

 

Really depends on your configuration, with the information given it's pretty much impossible to tell. 

  • 1 accepted solution
  • 2395 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!