VWIRE Physical Connecivity to Current Virtual Firewall

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

VWIRE Physical Connecivity to Current Virtual Firewall

L2 Linker

Hi,

 

I am trying to get my head around VWIRE and how it supposed to work.

 

We have the following scenario

 

SWITCH -> VIRTUAL FIREWALL (ON SHARED HOST) -> INTERNET

 

We are now looking to do

 

SWITCH -> PALO ALTO -> VIRTUAL FIREWALL (ON SHARED HOST) -> INTERNET

 

I am thinking how this would work physically. The virtual firewall sits on a VM host (shared with other VMs) which plugs directly into the switch.  It is a flat network.  Therefore both e1/1 and 1/2 on the palo will go into the same VLAN.  How would the Palo know how to intercept the traffic with the client machines default gateway being the virtual firewall which also sits in the same VLAN and also on the same switch.  I have seen articles that e1/1 and e1/2 should be connected to the same VLAN either side be it an access or trunk port, then I have seen articles were e1/1 and e1/2 are in different VLANs.   The physical architecure iof vWIRE in terms how to cable this up is not documented anywhere really.


Some feedback would be very much appreciated.  Thanks

2 accepted solutions

Accepted Solutions

Cyber Elite
Cyber Elite

to be able to 'force' traffic over the vwire, the virtual firewall will need to be on a different vlan than the clients so the switch is unable to bridge the 2 together

 

that or the server needs to be physically connected to one side of the vwire

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

View solution in original post

L5 Sessionator

Check the following topology.

 

IPS.jpg

 

We have made the traffic to pass through the firewall by the help of VLAN.

Note that if the port 4 and port 1 become part of same VLAN the traffic will not pass through PA firewall.

View solution in original post

2 REPLIES 2

Cyber Elite
Cyber Elite

to be able to 'force' traffic over the vwire, the virtual firewall will need to be on a different vlan than the clients so the switch is unable to bridge the 2 together

 

that or the server needs to be physically connected to one side of the vwire

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

L5 Sessionator

Check the following topology.

 

IPS.jpg

 

We have made the traffic to pass through the firewall by the help of VLAN.

Note that if the port 4 and port 1 become part of same VLAN the traffic will not pass through PA firewall.

  • 2 accepted solutions
  • 2114 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!