Firewall between host and gateway

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Firewall between host and gateway

L2 Linker

Sorry if this is really basic but...

I have configuration where, we've added a gateway to a subnet that we only want one host to be able to access to get offsite.  The gateway is on the other side of a vwire in the same subnet space obviously but in a different zone on the firewall. We're only allowing inbound connections from a client on the other side of this gateway into the subnet. No hosts in the subnet would be initiating connections to the client. 

My question is, since the FW is between the host and it's gateway, do I need a rule for the host inside the network to be able to arp for the gateway through the firewall and vice versa?

Or to make the question more generic I guess, do I need a rule to allow two hosts on the same subnet but separated by a vwire in different zones to be able to arp before a L3 connection gets established?

Thanks in advance.

6 REPLIES 6

Not applicable

Hi epeeler,

Yes. If the vwire zones are placed in different zones (trust and untrust), then you will require policy to allow the traffic to reach your gateway from host.

Regards,

Ramya

Thanks Ramya,

What's the best way to restrict traffic to only arp?  I don't want the two machines to do anything other than pass ethernet frames between each other.

Hi,

As per my knowledge, there isn't a way to restrict just the ARP traffic.

Regards,

Ramya

L1 Bithead

Yeah, it doesn't look like PanOS knows about ARP.  We are attempting a similar configuration with the PA in Layer 2 configuration.  It's not obvious how to create a policy that allows ARP to traverse the firewall.

I ended up not needing any specific rule for ARP. It just worked. The host is able to ARP for the gateway's IP address and respond to the allowed inbound L3 traffic from outside the firewall.

Thanks for the quick feedback.  If link layer traffic is allowed to pass between security zones without policy in Vwire, then it should do the same in Layer 2 config.

  • 3430 Views
  • 6 replies
  • 1 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!