WAN interface Multiple IP addresses or sub interfaces?

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

WAN interface Multiple IP addresses or sub interfaces?

L0 Member

Hi - Looking for best practices advice on WAN interface. Currently the WAN interface has a /26 with multiple IP addresses for incoming web servers translated to different subnets behind the PAN.  Is there a default proxy arp working and is this the best practice or should the firewall have sub-interfaces?

 

Thanks 

 

 

1 accepted solution

Accepted Solutions

Hi @stoff ,

 

I, personally, am trying to avoid multiple IP address on the same interface like a plague. In some rear cased it is reasonable to do it, but in most cases there is a better way to accomplish your goal. I also agree with @BPry also that you don't need separate interface for each IP.

 

When you use IP address in the NAT policy the firewall will automatically configure the proxy arp for that IP.

So my suggestion would be the same as @BPry :

- Configure your WAN interface with one IP from the /26 network

- Configure destination NAT policies with the rest of the addresses in the /26 network (or bi-directional static source nat, depending of your needs and nat policy). No need to have those addresses configured on firewall interface

View solution in original post

3 REPLIES 3

Cyber Elite
Cyber Elite

@stoff,

There's no reason to create additional sub-interfaces for your untrust interface if you don't need them. Just leave the interface with the /26 like you have now and use your NAT rulebase to assign them where needed. 

Hi @stoff ,

 

I, personally, am trying to avoid multiple IP address on the same interface like a plague. In some rear cased it is reasonable to do it, but in most cases there is a better way to accomplish your goal. I also agree with @BPry also that you don't need separate interface for each IP.

 

When you use IP address in the NAT policy the firewall will automatically configure the proxy arp for that IP.

So my suggestion would be the same as @BPry :

- Configure your WAN interface with one IP from the /26 network

- Configure destination NAT policies with the rest of the addresses in the /26 network (or bi-directional static source nat, depending of your needs and nat policy). No need to have those addresses configured on firewall interface

Thanks that make sense. I am going to get this cleaned up now. 

  • 1 accepted solution
  • 4795 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!