vwire policies

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

vwire policies

L3 Networker

HI all,

when we deploy the paloalto firewall in vwire mode and we have multiple zones (system zone, application zone, bdd zone), can we create rules to permit traffic between these zones through pan firewall ??

thank's in advance

1 accepted solution

Accepted Solutions

To further add to Sandeep's answer. If you are only using vwire you will only control access between the zones defined in the vwire interfaces that are part of the same vwire object.

So if you had ethernet1/1 and ethernet1/8 in a pair, which are defined as Trust and Untrust respectively, then you could create a security policy to control traffic from Trust to Untrust or from Untrust to Trust. A security policy from Trust to DMZ would never be hit as it's not possible for the PAN to forward the traffic to the DMZ zone.

If however you are using V5.0 you can implement vwire sub-interfaces which allows you to put a VLAN into a vwire sub-interface and thus put it into it's own zone which means you then have to create a policy to allow the traffic.

So if we created a vwire sub-interface on ethernet1/8 which had the zone of DMZ, then we could configure a policy to control traffic from Trust to Untrust and another from Trust to DMZ.

Hope that makes things a bit clearer.

View solution in original post

4 REPLIES 4

L6 Presenter

You can configure rules to allow/deny traffic between V-wire zones. You can also make use of other features like anti-virus filtering, url filtering, NAT and almost every other feature done by regular L3-traffic.

Here are some documents that can help you with Vwire config.

How to Configure Virtual Wire (VWire)

Video Link : 1005

Thanks,

Sandeep T

To further add to Sandeep's answer. If you are only using vwire you will only control access between the zones defined in the vwire interfaces that are part of the same vwire object.

So if you had ethernet1/1 and ethernet1/8 in a pair, which are defined as Trust and Untrust respectively, then you could create a security policy to control traffic from Trust to Untrust or from Untrust to Trust. A security policy from Trust to DMZ would never be hit as it's not possible for the PAN to forward the traffic to the DMZ zone.

If however you are using V5.0 you can implement vwire sub-interfaces which allows you to put a VLAN into a vwire sub-interface and thus put it into it's own zone which means you then have to create a policy to allow the traffic.

So if we created a vwire sub-interface on ethernet1/8 which had the zone of DMZ, then we could configure a policy to control traffic from Trust to Untrust and another from Trust to DMZ.

Hope that makes things a bit clearer.

thank's for your reply

thnak's for your help

  • 1 accepted solution
  • 4564 Views
  • 4 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!