03-24-2015 09:43 AM
Sorry if this is really basic but...
I have configuration where, we've added a gateway to a subnet that we only want one host to be able to access to get offsite. The gateway is on the other side of a vwire in the same subnet space obviously but in a different zone on the firewall. We're only allowing inbound connections from a client on the other side of this gateway into the subnet. No hosts in the subnet would be initiating connections to the client.
My question is, since the FW is between the host and it's gateway, do I need a rule for the host inside the network to be able to arp for the gateway through the firewall and vice versa?
Or to make the question more generic I guess, do I need a rule to allow two hosts on the same subnet but separated by a vwire in different zones to be able to arp before a L3 connection gets established?
Thanks in advance.
03-24-2015 11:32 AM
Yes. If the vwire zones are placed in different zones (trust and untrust), then you will require policy to allow the traffic to reach your gateway from host.
03-24-2015 12:23 PM
What's the best way to restrict traffic to only arp? I don't want the two machines to do anything other than pass ethernet frames between each other.
03-24-2015 04:06 PM
As per my knowledge, there isn't a way to restrict just the ARP traffic.
05-14-2015 02:52 PM
Yeah, it doesn't look like PanOS knows about ARP. We are attempting a similar configuration with the PA in Layer 2 configuration. It's not obvious how to create a policy that allows ARP to traverse the firewall.
05-15-2015 06:23 AM
I ended up not needing any specific rule for ARP. It just worked. The host is able to ARP for the gateway's IP address and respond to the allowed inbound L3 traffic from outside the firewall.
05-15-2015 02:43 PM
Thanks for the quick feedback. If link layer traffic is allowed to pass between security zones without policy in Vwire, then it should do the same in Layer 2 config.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!