- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
Enhanced Security Measures in Place: To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.
11-28-2017 04:00 AM
Hello
this may sound like a stupid question but i could not somehow find a definitive answer to this in the PAN OS Guide:
We have to configure a 3050 iun multi-vsys configuration. We would be needing 2 interfaces per vsys and we wil be having 2 vsys only. All the interfaces wil be L3.
Regarding "physical" interface assignment, what is ALLOWED and recommended?
1. One physical interface assigned to one vsys. No sharing of interfaces.
OR
2. One physical interface without subinterfaces added in both the vsys. (Not sure if it is allowed)
OR
3. Subinterfaces created on one interface and then each subinterface to be assigned for each vsys. (We dont have any vlan tagging actually.)
(P.S. Option 1 is feasible but we would also like to spare physical interfaces for future use.)
Thanks and Regards
R
11-28-2017 04:48 AM
a single interface can only belong to one vsys, subinterfaces are counted as separate entities
so in your scenario where you'll only have 2 interfaces per vsys and only 2 vsys, you'd be set with 4 interfaces in total, so there's plenty of room to work with
but what does your network look like, are the 2 network environments also split up in vlans on one physical switching environment or are does each network have their own physical switch?
Sharing a single physical interface over multiple sub-interfaces makes management more wasy as you'll only need to manage a trunk from the switch and add tagged subinterfaces, but may impose bandwidth restrictions as all the subinterfaces share the same physical interfaces (this in itself can be fixed by creating aggregate interfaces.
#1 is a viable option, option #2 is not possible, option #3 will require you to start using vlan tagging, but will spare the number of physical interfaces used and allows for easy future expansion
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!