DesigningNetworkswithPaloAltoNetworksFirewallsSuggestedDesignsforPotentialandExistingCustomersRevisionB©2012,PaloAltoNetworks,Inc.:TapMode..................................................................................................................7Section2:Virtual-wireDeploymentScenarios........................................................................................................132.1OperationofVirtualWireInterfaces........................................................................................................132.2ExampleScenario:VirtualWirewithActive/PassiveHA.........................................................................152.3ExampleScenario:VirtualWirewithActive/ActiveHA............................................................................242.4ExampleScenario:VirtualWirewithA/AHAandLinkAggregationonAdjacentSwitches....................332.5ExampleScenario:VirtualWirewithBypassSwitch(“fail-open”scenario)............................................452.6ExampleScenario:HorizontalScalingwithLoadBalancers...................................................................52Section3:Layer2DeploymentScenarios...............................................................................................................593.1OperationofL2Interfaces.......................................................................................................................593.2ExampleScenario:Layer2Active/PassiveHA.......................................................................................603.3ExampleScenario:CombinationLayer2andLayer3Topology............................................................68Section4:Layer3DeploymentScenarios...............................................................................................................754.1OperationofL3Interfaces.......................................................................................................................754.2ExampleScenario:Layer3Active/PassiveHAwithOSPF.....................................................................764.3ExampleScenario:Layer3Active/ActiveHAwithOSPF.......................................................................774.4ExampleScenario:Layer3Active/PassiveHAwithBGP.......................................................................784.5ExampleScenario:Layer3Active/ActiveHAwithBGP..........................................................................794.6ExampleScenario:Layer3Active/PassivewithLinkAggregation.........................................................804.8ExampleScenario:FirewallonaStick....................................................................................................99AppendixA:ReviewofUser-IDOperation............................................................................................................107RevisionHistory.....................................................................................................................................................110©2012,PaloAltoNetworks,Inc.[2]IntroductionHowtoUsethisDocumentThepurposeofthisdocumentistohelppeoplechoosehowtodeployPaloAltoNetworksdevicesintotheirnetwork.Variousscenariosaredescribed,aswellastheirconfiguration.Allofthesescenariosweretestedinthefield,runningPAN-OS5.0.2.PrerequisiteknowledgeThisdocumentisnotastep-by-stephow-todocument,butgivesasummaryoftheconfigurationneededtoimplementeachscenario.ItisassumedthatthereaderhastheknowledgetocompletethefollowingtasksonaPAfirewall:oConfigureinterfacesettings,suchasinterfacetype,duplex,speed,zoneoCreateandconfigurezonesoCreateandconfigurepoliciesoCreate/deletevirtualwiresoConfigurevirtualroutersWheredoIstart?Thebestplacetostartistoreviewdifferentdeploymentmodesbelow,andthenusethetableofcontentstodeterminewhichscenariosyoumightconsider.The4interfacemodes/deploymentscenariosare:•Tapmode•Virtualwiremode•Layer2mode•Layer3modeTapModeDeploymentsWhereasanetworktapisadevicethatprovidesawaytoaccessdataflowingacrossacomputernetwork,“tapmodedeployment”ofthePaloAltoNetworksfirewallsallowsyoutopassivelymonitortrafficflowsacrossanetworkbywayofataporswitchSPAN/mirrorport.TheSPANormirrorportpermitsthecopyingoftrafficfromotherportsontheswitch.BydesignatinganinterfaceonthefirewallasatapmodeinterfaceandconnectingittoaswitchSPANport,theswitchSPANportprovidesthefirewallwiththemirroredtraffic.Thisprovidesapplicationvisibilitywithinthenetworkwithoutbeingintheflowofnetworktraffic.Advantages:•Visibilityintothenetworktraffi