Enhanced Security Measures in Place:   To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.

Traffic from one zone to another

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Traffic from one zone to another

L1 Bithead

Hello.

We have two virtual wires called 'eduroam' and 'live'. There are two zones linked to eduroam, namely 'eduroam_tr' and 'eduroam_untr'. There are also two zones linked to 'live', called 'live_tr' and 'live_untr'. We would like to allow communication of machines residing in 'live_tr' zone between a machine residing in 'eduroam_tr' zone. Do I need to enable routing to allow that, or is there another way?

Thank you for your help.

Best wishes,


Marcin

3 REPLIES 3

Cyber Elite
Cyber Elite

Hi Marcin

Vwires are different from L2 and L3 interfaces in that they should basically be regarded as an extention of the physical wire. This means in your case you would need to physically connect the two IP domains so they would be able to reach eachother, for example by adding a switch on the untrust side of both vwires.

As an alternative, if you are considering interconnecting both domains more in the future, you could consider reconfiguring your interfaces as either L2 or L3 so you'd be able to make those connections through configuration rather than physical wired or switched

hope this helps

Tom

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

L5 Sessionator

Hi,

Keep in mind that Vwire is like ... a wire. Not possible to jump from a wire to another wire.

Then traffic on eduroam stay on eduroam and traffic on live stay on live. the two wire are completelly isolated.

If you want to allow communication between both, you have to do that from another device on your lan (routing ...)

Hope help.

V.

L7 Applicator

If you want to keep v-wire mode and don't want to convert to L3 or L2, your other option is to create and insert another v-wire for this traffic.

You will choose which router in your environment will link these two routing zones.  Then place another v-wire on the line where this traffic must transit from that router to one of the two zones.  This way one side of the new v-wire is live-tr and the other side is eduroam-tr.  You can use these same zones on the new v-wire.

Now you can add the access rules you desire between the zones.

Steve Puluka BSEET - IP Architect - DQE Communications (Metro Ethernet/ISP)
ACE PanOS 6; ACE PanOS 7; ASE 3.0; PSE 7.0 Foundations & Associate in Platform; Cyber Security; Data Center
  • 2059 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!