Hi There, I have a generic question about the Palo alto way of treating sub interfaces? Can I do sub interface on one of the physical interface for one netwrok address? for example, I did sub interface the ethernet1/5 as ethernet 1/5.123 and configured the netwrok 10.11.12.13/24 and no other networks exist on overall that physical interface. Connection to downstream switch is trunk by the way with allowing native vlan and vlan 123? I believe we can do this, as I couldn't recall exactly what I did preaviuosly, but I did ran into issues with Cisco ASA firewall, when I ran a trunk from switch to ASA and allowing only native and one custom vlan, ASA didn't accept the packets coming from the custom vlan when I did subinterface for that one vlan.
... View more