- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
12-03-2019 09:20 AM
We have stack of 2 edge switch and stack of 2 distribution switches.
We have linkagg containing 2 ports running between them.
IT is layer 2 connection only between edge and distro.
Also we have MAnagement vlan on switch so that users can access it remotely
Need to put PA in vwire mode.
So for vwire
I will have two pair of vwires and i will need to have
4 zones and two security polices to traffic flows from edge switch to distro.
if i need to ssh to edge switch then traffic flow is via the distribution switch in that case i need to allow ssh rule from both vwires as i do not know PA will use which physical link right?
12-03-2019 02:18 PM
Yes, your vwires would still have pairs of interfaces, but that doesn't mean you are required to use four zones. To clarify my previous comment, you can have two separate vwires with the inside/outside Ethernet interfaces in the same zone:
You could also have one vwire with aggregate Ethernet interfaces:
Each option offers some advantages and disadvantages of course, and may or may not work for your situation.
12-03-2019 09:59 AM
Since your devices are using link aggregation, have you considered adding your vwire interfaces as an aggregate interfaces as well?
https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/networking/configure-interfaces/virtual-wi...
If for whatever reason you can't do this, do you need to have four separate security zones? Could you put both "outside" interfaces in one security zone, and both "inside" interfaces in another, and use a single security policy?
12-03-2019 01:10 PM
As far as i know vwire work in pairs.
So far have not like that putting different vwire in same zone.
Do not know how that will work will see if someone recommend that ?
Benefit if having separte zones is that then you can see which port in linkagg uses amount of traffic.
As switch is doing hashing to use both ports of the linkagg to send traffic.
12-03-2019 02:18 PM
Yes, your vwires would still have pairs of interfaces, but that doesn't mean you are required to use four zones. To clarify my previous comment, you can have two separate vwires with the inside/outside Ethernet interfaces in the same zone:
You could also have one vwire with aggregate Ethernet interfaces:
Each option offers some advantages and disadvantages of course, and may or may not work for your situation.
12-11-2019 09:40 PM
Many thanks for answering my question!
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!