Enhanced Security Measures in Place:   To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.

one leg setup clarification ..

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

one leg setup clarification ..

L3 Networker

hi all,

i need to setup two PA-2050 ( HA mode ) but am not sure about the design were i need some help her, the customer network is devided into vlans and they all communicato to each other through the corre switch ( cisco 6500) and if they require internet access the core switch will route them to a firewall ( firewall module in the core sw ) , now obviously i cant setup the appliances in vwire mode since there are no physical cables ( all virtual links and vlan ) so i was thinking to make a defult route on the customer switch to redirect internet traffic to the PA device then it routes back to the core sw , not wccp as i know they call this one leg setup am just wondering if it can achieved by the PA appliance .

am attaching a diagram of what am looking for .

Dasman_setup.jpg

4 REPLIES 4

L6 Presenter

Hi...To do the one arm routing, we would have to redirect traffic from the VLANs to the PA device before it reaches the fw module.  We then have to NAT at the PA device to ensure the return packets come back to the PA device, or redirect the inbound traffic at the sw as well.  Otherwise the fw module would forward the replies to the users and bypass the PA device.  We need to maintain session state on the PA device.

Another option is to do L2 bridging and configure the PA device in vwire mode.  Put the fw module on a standalone vlan and aggregate the user vlans onto a 2nd standalone vlan.  Use the vwire to bridge the two standalone vlans.

Thanks.

if we can do in vwire it would be great , but can you explain more please..

For the vwire option, we would need to use a vlan bridge as shown in the attached diagram.  We need to create 2 isolated vlans and they are depicted as untrust and trust vlans.The vwire would act as a bridge and traffic would flow through the PAN device.  Thanks.

AM testing the one arm routing do I need to have PBF to instruct the traffic to leave from the same interface again because it's reaching the PA but it drops then .

Thanks.

  • 4278 Views
  • 4 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!