Return to Level1Techs.com

Palo Alto L2 & L3 interfaces


#1

Hi network people of the forum.
Lets get right into it.
I have to configure a palo alto firewall for the first time and it should look something like this:
Gi 0/1 Office uplink 1
Gi 0/2 Office uplink 2
Gi 0/4 Vlan 763
Gi 0/8 Trunk with vlan 763 in it.

Interface 1 and 2 are L2-interfaces in the same Vlan linked to 2 asa firewall’s that are active/passive. Its supposed to function as a failover.
The configuration of these 2 links seems to work.

Now I defined Gi 0/8 as a L2 interface with subinterfaces for every vlan.
Gi0/4 is also a L2 interface but only vlan 763 , so like an access port.
Every other port is L3 and seems to do fine.

My issue is that I can’t seem to get the communication between the subinterface on Gi 0/8 and Gi 0/4 working. I added policies to allow intra-zone traffic n an L3 level (SVI of the vlan) and on the L2 level.

I have done some basic firewall stuff, mostly just adding some extra rules in existing juniper’s. This is the first time I’m doing a full config from 0 in a firewall and my first experience with palo alto. I could use all the help I can get :smiley:

P.S. Almost forgot, I configured 2 unused ports as L2, made a vlan for them, a zone etc and tried to get it to work by switching around vlan’s, zone’s,policies,…
If anyone has some screenshots or config file of a working setup of something similar to this I’d be very grateful :slight_smile:

-A networking newbie-