one leg setup clarification ..

Announcements

ATTENTION Customers, All Partners and Employees: The Customer Support Portal (CSP) will be undergoing maintenance and unavailable on Saturday, November 7, 2020, from 11 am to 11 pm PST. Please read our blog for more information.

Reply
Highlighted
L3 Networker

one leg setup clarification ..

hi all,

i need to setup two PA-2050 ( HA mode ) but am not sure about the design were i need some help her, the customer network is devided into vlans and they all communicato to each other through the corre switch ( cisco 6500) and if they require internet access the core switch will route them to a firewall ( firewall module in the core sw ) , now obviously i cant setup the appliances in vwire mode since there are no physical cables ( all virtual links and vlan ) so i was thinking to make a defult route on the customer switch to redirect internet traffic to the PA device then it routes back to the core sw , not wccp as i know they call this one leg setup am just wondering if it can achieved by the PA appliance .

am attaching a diagram of what am looking for .

Dasman_setup.jpg

Highlighted
L6 Presenter

Hi...To do the one arm routing, we would have to redirect traffic from the VLANs to the PA device before it reaches the fw module.  We then have to NAT at the PA device to ensure the return packets come back to the PA device, or redirect the inbound traffic at the sw as well.  Otherwise the fw module would forward the replies to the users and bypass the PA device.  We need to maintain session state on the PA device.

Another option is to do L2 bridging and configure the PA device in vwire mode.  Put the fw module on a standalone vlan and aggregate the user vlans onto a 2nd standalone vlan.  Use the vwire to bridge the two standalone vlans.

Thanks.

Highlighted
L3 Networker

if we can do in vwire it would be great , but can you explain more please..

Highlighted
L6 Presenter

For the vwire option, we would need to use a vlan bridge as shown in the attached diagram.  We need to create 2 isolated vlans and they are depicted as untrust and trust vlans.The vwire would act as a bridge and traffic would flow through the PAN device.  Thanks.

Highlighted
L3 Networker

AM testing the one arm routing do I need to have PBF to instruct the traffic to leave from the same interface again because it's reaching the PA but it drops then .

Thanks.

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!