- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
02-17-2013 02:54 AM
HI all,
when we deploy the paloalto firewall in vwire mode and we have multiple zones (system zone, application zone, bdd zone), can we create rules to permit traffic between these zones through pan firewall ??
thank's in advance
02-18-2013 12:51 AM
To further add to Sandeep's answer. If you are only using vwire you will only control access between the zones defined in the vwire interfaces that are part of the same vwire object.
So if you had ethernet1/1 and ethernet1/8 in a pair, which are defined as Trust and Untrust respectively, then you could create a security policy to control traffic from Trust to Untrust or from Untrust to Trust. A security policy from Trust to DMZ would never be hit as it's not possible for the PAN to forward the traffic to the DMZ zone.
If however you are using V5.0 you can implement vwire sub-interfaces which allows you to put a VLAN into a vwire sub-interface and thus put it into it's own zone which means you then have to create a policy to allow the traffic.
So if we created a vwire sub-interface on ethernet1/8 which had the zone of DMZ, then we could configure a policy to control traffic from Trust to Untrust and another from Trust to DMZ.
Hope that makes things a bit clearer.
02-17-2013 08:47 AM
You can configure rules to allow/deny traffic between V-wire zones. You can also make use of other features like anti-virus filtering, url filtering, NAT and almost every other feature done by regular L3-traffic.
Here are some documents that can help you with Vwire config.
How to Configure Virtual Wire (VWire)
Thanks,
Sandeep T
02-18-2013 12:51 AM
To further add to Sandeep's answer. If you are only using vwire you will only control access between the zones defined in the vwire interfaces that are part of the same vwire object.
So if you had ethernet1/1 and ethernet1/8 in a pair, which are defined as Trust and Untrust respectively, then you could create a security policy to control traffic from Trust to Untrust or from Untrust to Trust. A security policy from Trust to DMZ would never be hit as it's not possible for the PAN to forward the traffic to the DMZ zone.
If however you are using V5.0 you can implement vwire sub-interfaces which allows you to put a VLAN into a vwire sub-interface and thus put it into it's own zone which means you then have to create a policy to allow the traffic.
So if we created a vwire sub-interface on ethernet1/8 which had the zone of DMZ, then we could configure a policy to control traffic from Trust to Untrust and another from Trust to DMZ.
Hope that makes things a bit clearer.
02-19-2013 12:33 AM
thank's for your reply
02-19-2013 12:33 AM
thnak's for your help
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!