Layer 2 subinterfaces w/ Vlan interface for routing.....

Showing results for 
Show  only  | Search instead for 
Did you mean: 

Layer 2 subinterfaces w/ Vlan interface for routing.....

L1 Bithead

Say I want to connect this port to a switch downstream (trunk), with clients hanging off of switch on access ports and use vlan interfaces for routing. Switch is set to trunk allowing relevant vlans, the firewall interface is subinterfaced (layer2) with the respective tag and vlan assigned. This is not working. DHCP does not work at all. Can someone let me know if I am doing this correctly? I am having trouble getting this configured.


FW <trunk>Switch<access>Client

FW eth1/3 subinterfaced (eth1/3.600 - layer2) with tag and vlan. Vlan exists and is pointing to the vlan.600 interface.


When I have a physical interface assigned to a vlan, and a client directly plugged into the firewall port, DHCP/traffic works as expected.


I am accustomed to using layer3 subinterfaces, but this had me curious so I wanted to try it.


Cyber Elite
Cyber Elite

you need to have 2 "vlans" (it's a bit of unfortunate naming on Palo's side)


one is a layer2 vlan assigned to your subinterface that determines which interfaces belong to the same vlan and zone regardles of their tag (this is virtual layer 2 inside the chassis)


the other is the vlan interface, which is like a VRF (found in the interfaces > vlan tab). this is where you set a vlan interface up with an ip address so it can function as a default route, and this interface can be used to attach a DHCP server

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization
  • 1 replies
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!