Enhanced Security Measures in Place:   To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.

V-Wire Mode with trunk

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

V-Wire Mode with trunk

L3 Networker

Hey Guys,

i am about to deploy PaloAlto 5020 in a v-wire mode with trunk on them, does any one has any known issues that i may encounter

here is the topology

Current: switch ====(trunk)===== cisco firewall

new: switch======(trunk)=====PaloAlto (vwire)=====(trunk)====Cisco firewall.

Any help would be appreciated.

Regards,

~Harry

2 REPLIES 2

L7 Applicator

L7 Applicator

I setup v-wire with q tag trunk ports on the 5000 series for a data center deployment.

this can be as simple as outlined in this document.  Where there is only two zones and all tags are just permitted through the v-wire.

Trunked Traffic in a V-Wire

If you want more control, you can create a subinterface for each q tag on the v-wire.  These can then be placed onto their own v-wire pipe and assigned zones separately from the other q tags on the trunk port.  This also prevents the automatic passing of additional tagged frames on the trunk without the explicit configuration of the sub-interface and v-wire pair.

  • Create the v-wire for the tag
  • Create the sub-interface on both physical interfaces and assign the tag and the v-wire
  • Assign each side of the v-wire to the desired zones
  • Rules will then apply by zone assignment of the particular v-wire pairs
Steve Puluka BSEET - IP Architect - DQE Communications (Metro Ethernet/ISP)
ACE PanOS 6; ACE PanOS 7; ASE 3.0; PSE 7.0 Foundations & Associate in Platform; Cyber Security; Data Center
  • 1991 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!