Enhanced Security Measures in Place:   To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.

Layer 2 Palo Alto to 802.1q subinterface on Cisco ISR

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Layer 2 Palo Alto to 802.1q subinterface on Cisco ISR

L3 Networker

I am thinking to put a small pan between an Internet connected Cisco 4331 ISR and a Meraki switch. Will the PAN just pass all the tagged frames along and will the PAN be able to process the traffic from all those VLANs/tagged frames? Or would I need to configure VLANs on the PAN?

 

 

[Cisco ISR 4331]-Int Gi0/0 0/0.1 0/0.2 0/0/3------[L2 PAN]-----------802.1q Trunk[Meraki 225]

2 accepted solutions

Accepted Solutions

Cyber Elite
Cyber Elite

Hello,

Its better to either use v-wire or a Layer3 interface. I think you would like little disruption to your design so vwire is probably the best way to go.

 

Here is some information overload ;).

 

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClS2CAK

https://live.paloaltonetworks.com/t5/Blogs/Getting-Started-Palo-Alto-Networks-Firewall-Series/ba-p/6...

 

Cheers!

View solution in original post

4 REPLIES 4

Cyber Elite
Cyber Elite

Hello,

Its better to either use v-wire or a Layer3 interface. I think you would like little disruption to your design so vwire is probably the best way to go.

 

Here is some information overload ;).

 

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClS2CAK

https://live.paloaltonetworks.com/t5/Blogs/Getting-Started-Palo-Alto-Networks-Firewall-Series/ba-p/6...

 

Cheers!

So on this new gig my predecessor actually setup virtual wires behind an ASA. But in 

that setup the wires to the ASA and to the switch behind it have no trunking, just a 

single VLAN. If I put trunking on the upstream ASA and downstream switch, would

the PAN be able to see the traffic for all the different VLANs and process rules

accordingly?

Hello,

Yes this is possible. Check out this article.

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClFwCAK

 

Regards,

Very helpful! Thank you.

  • 2 accepted solutions
  • 3954 Views
  • 4 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!