Hi, I’ve recently got a PA-440, and trying to make sense of the VLAN logic on PAN-OS has got me stumped. First of all, I get creating a layer 3 sub interface and assigning a VLAN tag, easy. A bit odd that the 'tag' doesn't then show up as a VLAN under Network > VLANs, but I can let that slide.
It's an access port where things really don't make sense. I follow the steps below, and even though it works it just doesn't make sense.
Mark an interface as layer 2, and assign a layer 2 zone to it, ok.
Create a VLAN (Network > VLANs) - sure, but you don’t specify a VLAN ID, just a name. What is the point of this construct?
Assign created VLAN (from step 2) to the physical layer 2 interface - again, ok, but given the VLAN hasn’t got an ID, does this achieve anything?
Create a VLAN Interface (with an ID between 1-9999) and assign a VLAN to it. I assume this is like an SVI, but I don’t need a layer 3 VLAN interface, why is this necessary? Also, it seems like the ID is meant to be the VLAN tag (but the range is not right, 1-9999 rather than 1-4094)?
I'm hoping someone can explain this to be, as the documentation isn't clear.
What is the point of VLANs under Network > VLANs? Given you don't specify a VLAN ID.
Is the ID under the VLAN interface actually a VLAN tag, rather than an interface ID? If so, why is the range 1-9999 (rather than 1-4094)?
Thanks for any help.
... View more