Multiple options to integrate the Palo Alto Firewall into your:

  • Network
  • Layer 2 interfaces and VLAN interfaces
  • Layer 3 interfaces
  • Tap interfaces
  • Loopback and tunnel interfaces
  • HA interfaces

Type 1 - Layer 2 interfaces:

  • Allows a Trunk interface to transmit
  • Tagged VLAN's which can be assigned to VLAN interfaces
  • Can be allocated in port channels (link aggregation with LACP)

Cyber Security - Palo Alto Firewall Interface Types-LMLPHP

Configure a Layer2 interface with Wired-VLAN20.Cyber Security - Palo Alto Firewall Interface Types-LMLPHP

Add a layer2 subinterface.

Cyber Security - Palo Alto Firewall Interface Types-LMLPHP

Add a Wireless-VLAN30 subinterface.

Cyber Security - Palo Alto Firewall Interface Types-LMLPHP

Type2 - Layer 3 interfaces:

  • Carries end-to-end Layer 3 traffic with an assigned IP address.
  • Can be allocated in port channels(link aggregation with LACP)
  • Can be sub-divided in L3 Subinterfaces.

Cyber Security - Palo Alto Firewall Interface Types-LMLPHP

Add a layer3 interface.

Cyber Security - Palo Alto Firewall Interface Types-LMLPHP

Cyber Security - Palo Alto Firewall Interface Types-LMLPHP

Cyber Security - Palo Alto Firewall Interface Types-LMLPHP

Type3 - Tunnel and loopback interfaces:

  • Used to logically assign attributes to tunnel entry/exit points
  • Loopbacks: Create always-on logical interfaces for required applications.

Cyber Security - Palo Alto Firewall Interface Types-LMLPHP

Configure a tunnel.Cyber Security - Palo Alto Firewall Interface Types-LMLPHP

Confiture Loopback

Cyber Security - Palo Alto Firewall Interface Types-LMLPHP

Cyber Security - Palo Alto Firewall Interface Types-LMLPHP

Cyber Security - Palo Alto Firewall Interface Types-LMLPHP

Configure Virtual Router

Cyber Security - Palo Alto Firewall Interface Types-LMLPHP

Configure IPsec Tunnels here.

Cyber Security - Palo Alto Firewall Interface Types-LMLPHP

Typer 4 - HA(High availability interfaces):

  • Allows connectively between two Palo Alto Firewalls to establish a highly available Firewall setup
  • HA links will carry required information to build the cluster, and sync routing/configuration across the members.

Cyber Security - Palo Alto Firewall Interface Types-LMLPHP

Configure HA interface.Cyber Security - Palo Alto Firewall Interface Types-LMLPHP

Enable HA setup.

Cyber Security - Palo Alto Firewall Interface Types-LMLPHP

Configure the Control Link.Cyber Security - Palo Alto Firewall Interface Types-LMLPHP

https://docs.paloaltonetworks.com/pan-os/7-1/pan-os-admin/high-availability/set-up-activepassive-ha/configure-activepassive-ha

05-22 14:26