Help With Configure PA-220

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Help With Configure PA-220

L1 Bithead

I am trying to build firewall from scratch. Our use case is to secure 3 servers with separate DSP connected to PA-220. We do not have any managed switch or router between ISP to firewall. It is direct from modem to firewall.

 

Can anyone help with this? Palo Alto's documentation isnt helpful as I am not network guru.

6 REPLIES 6

Community Team Member

Hi @PranamShah ,

 

That a broad request.  I'd recommend checking out some of the getting started guides.  You'll find plenty of those on our LIVEcommunity YouTube channel over a variety of different topics.

 

There's also the getting started documentation DOC which provides detailed steps to help you deploy a new Palo Alto Networks next-generation firewall.

 

These should definitely help to get you started.

 

Cheers,

-Kiwi.

 
LIVEcommunity team member, CISSP
Cheers,
Kiwi
Don't forget to hit that Like button if a post is helpful to you!

Thanks Kiwi.

 

Do you know if my use case as below is Valid?

 

  • 3 servers
  • ISP (Modem) to PA-220 directly
  • No router or switch

 

Do I need to have Switch (L3) / Router (L3) between my servers and PA-220 or can I directly plug in Servers to PA-220?

 

L5 Sessionator

A switch would be L2, not L3. You can connect the servers directly to the PA-220, but you will need to decide if each port will be its own network (L3 routing thru the PaloAlto between servers), or if you will try to bridge all 3 server ports together into a single L2 network. See this for bridging L2 ports:

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClRqCAK

L1 Bithead

Thanks Adrian.

 

L2 switch is an unmanaged switch isn't it? Managed switch would be L3?

 

So basically I can not connect Server/VM Hosts directly to one one of 8 available interfaces on PA-220? Do I have to have a switch? And if yes, will unmanaged switch work or do I have to buy a managed switch?

 

Also for the internet to PA-220, can I connect ISP Modem directly to PA-220 and configure public IP on either management port or one of the interfaces?

 

Something like below is what I want to achieve. Is it viable?

 

palo-alto-flow.png

Sorry to ask some basics but I am a bit new to this.

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!