03-24-2015 09:43 AM
Sorry if this is really basic but...
I have configuration where, we've added a gateway to a subnet that we only want one host to be able to access to get offsite. The gateway is on the other side of a vwire in the same subnet space obviously but in a different zone on the firewall. We're only allowing inbound connections from a client on the other side of this gateway into the subnet. No hosts in the subnet would be initiating connections to the client.
My question is, since the FW is between the host and it's gateway, do I need a rule for the host inside the network to be able to arp for the gateway through the firewall and vice versa?
Or to make the question more generic I guess, do I need a rule to allow two hosts on the same subnet but separated by a vwire in different zones to be able to arp before a L3 connection gets established?
Thanks in advance.
03-24-2015 11:32 AM
Yes. If the vwire zones are placed in different zones (trust and untrust), then you will require policy to allow the traffic to reach your gateway from host.
03-24-2015 12:23 PM
What's the best way to restrict traffic to only arp? I don't want the two machines to do anything other than pass ethernet frames between each other.
03-24-2015 04:06 PM
As per my knowledge, there isn't a way to restrict just the ARP traffic.
05-14-2015 02:52 PM
Yeah, it doesn't look like PanOS knows about ARP. We are attempting a similar configuration with the PA in Layer 2 configuration. It's not obvious how to create a policy that allows ARP to traverse the firewall.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!