- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
10-09-2018 01:28 AM
Hi Experts,
Could you please suggest how to find Relevant Zone for an IP addresses in V Wire mode. When configuring security policy, we need to mention the source and destination zone.
We've PA firewalls only configured in Vwire with multiple zones.
Please suggest is there any way we could check it from GUI or from CLI an relevant zone for an IP address.
10-09-2018 01:57 PM
Hello,
Would you be able to clarify/expand on what is meant by 'relevant zone for an IP address'.
Regards,
10-10-2018 12:35 AM
Hi Klier,
When confuring access rules we'll be specifying the zones for the source and destination addresses. In L3 mode, we'll find the appopriate zones by looking at the Routing table.
Since Vwire acts as bump in the wire (L2) and no routing table is populated, not sure how to calcuate the zones for the source and destination addresses.
Could you please assist.
10-10-2018 06:46 AM
I guess generally most people would just know this information without having to look it up. You could put the IPs in as a comment on the associated interface; or you could set them up in the User-ID 'Included Networks' for that zone.
10-10-2018 06:57 AM
Hello,
I have always used a special zone for vwires, that way since traffic is flowing 'between' zones, I can create policies around it to allow/block specific traffic, etc. Here is a guide that may help out.
https://www.paloaltonetworks.com/documentation/71/pan-os/pan-os/networking/virtual-wire-deployments
I usually use vwires for external devices, say video conference equipment. Then I create zones for the vwire, vwire-external and vwire-internal. Then just create your policies on source and/or desitnation zones.
Hope that helps.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!