Professional Documents
Culture Documents
PANOS 4.0
October 2011
Tap Mode Deployment (1)
Internet
SPAN port
on switch
Tap port on
firewall
Internet
Outbound Inbound
flow flow
Tap ports
on firewall
SPAN port
on switch
Internet
Tap port on
firewall
Tap port on
firewall
Internet/Network A
Router A Router B
E1/1
E1/1
HA1
A/P firewall 1 HA2 A/P firewall 2
E1/2
E1/2
Router C Router D
Network B
Internet/Network A
Router A Router B
1.1.1.1 1.1.1.2
HA1
HA2
HA3
Router C
Router D
Network B
Internal Network
Switch 1 Switch 2
Switch 3 Switch 4
Internal Network
Internal Network
Switch 1 Switch 2
HA1
HA2
HA3
Switch 3 Switch 4
Internal Network
HA1
HA2
HA3
EX Virtual Chassis
EX4200 EX4200
Internal Network
Internet
Internet Gateway
.254
Bypass Switch
198.51.100.0/24
192.168.1.1
Load Balancer
Vlan10: 10.10.10.1
VLAN Vlan20: 10.10.20.1
Trunk Vlan30: 10.10.30.1
vwire
eth1/2
192.168.2.1
10G 10G
DMZ DMZ
10G
Internal
Network
HA1
HA2
VLAN101 VLAN101
HA1
HA2
802.1Q 802.1Q
Trunk Trunk
VLAN102 VLAN102
L3 segment
L2 segments
Direct connections &
VLAN trunks
L2 segment L2 segment
L2 segment
192.168.50.0/24 L3 segment
Virtual IP 192.168.1.0/24
IP-BC zone Ethernet1/3
Intranet zone
L2 segment
192.168.50.0/24
L2 segment
Ethernet1/1
192.168.50.0/24
Engineering zone
Ethernet1/2
Prod-management zone
Internet
192.0.2.33/30 192.0.2.34/30
edge router A edge router B
192.0.2.1/29 192.0.2.2/29
192.0.2.3/29
A/P firewall 1 HA1 A/P firewall 2
RID: 192.0.2.17 HA2
(same IP addresses as
the other firewall)
192.0.2.11/29
192.0.2.9/29 192.0.2.10/29
192.0.2.33/30 192.0.2.34/30
edge router A edge router B
192.0.2.9/30 192.0.2.13/30
192.0.2.1/30 192.0.2.5/30
Internet
ISP A ISP B
eBGP
eBGP
perimeter
perimeter
firewall
firewall
Internal Network
Internet
ISP A ISP B
AS 40001 AS 50001
RID 198.51.100.1 RID 192.0.2.1
198.51.100.5 192.0.2.5
198.51.100.1 192.0.2.1
198.51.100.2
Internal Network
Internet
ISP A ISP B
AS 40001 AS 50001
RID 198.51.100.1 RID 192.0.2.1
198.51.100.5 192.0.2.5
198.51.100.1 192.0.2.1
198.51.100.2
192.0.2.2
A/A Firewall 1 192.0.2.6 198.51.100.6
A/A Firewall 2
HA1
AS: 40000 AS: 40000
HA2
RID: 198.51.100.2 RID: 198.51.100.6
HA3
203.0.113.2 203.0.113.3
Internal VIP:
203.0.113.1
Internal Network
Layer 3 Routed
•Router VIP 203.0.113.1/24 Boundary
•Layer 2 switch
•Layer 2 Switch
Firewall A- Primary
Aggregate Ethernet Groups:
ae1 - e1/1 and e1/2 ae1 203.0.113.2/24 ae1
ae2 – e1/9 and e1/10 HA1 Firewall B-Secondary
HA2 Same config as active fw
All VLANs (100, 101 & 102) HA1 – 192.168.1.2/30
802.1q trunked to PA-5050s 10.1.100.1/24 ae2
ae2 10.1.101.1/24
via ae2
10.1.102.1/24
ae1 - 203.0.113.1/24
ae2.100 – 10.1.100.1/24
ae2.101 – 10.1.101.1/24
Virtual Switch- Pair of
ae2.102 – 10.1.102.1/24
switches in a virtual switch
HA1 – 192.168.1.1/30
configuration. VLAN 100,
VLAN 101, VLAN102 all
802.1Q tagged up single link
aggregated trunk port.
L2 segment
10.0.0.1/24
VLAN20 zone
L2 segment
192.168.1.2/24 VLAN Trunk
VLAN10 zone Ethernet1/8
Sub-interface 1/8.10 zone VLAN10
Sub-interface 1/8.20 zone VLAN20
L2 segment
VLAN 20