Palo FW setup site to site

Showing results for 
Show  only  | Search instead for 
Did you mean: 

Palo FW setup site to site

L1 Bithead

Hi All,

We have a HA fw 3220 in our environment and our partner want to access some of our resources. They propose a PA-440 fw +  small 12-port-Cisco 3560 in between the two sites by dark fiber.

Just wonder if you can setup FWs back to back instead of having a switch in between ie a extra point of failure?

is the Gateway going to be the switch or the FW440 behind it?

Any suggestion are much appreciated.





Does it mean we need to have ACL on the 12 port switch ?

Because we only want them to access certain resources.



You can control the access in your end Firewall 3220. 

Your partner network have dedicated fiber line till your network right. Then just create a VLAN in PA3220 assign it to security zone for ACL rule creation and extend it to your partner network switch.

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!