Professional Documents
Culture Documents
o Interface configurations of firewall data ports enable traffic to enter & exit Firewall.
o Firewall interfaces (Ports) enable a Firewall to connect with other network devices.
o Firewall interfaces also enable Firewall to connect with other interfaces within Firewall.
o Palo Alto Networks Firewall can operate in multiple deployments simultaneously.
o You can Configure the PA Interfaces to support different deployments methods.
o Can configure Ethernet interfaces for Virtual-Wire, Layer 2, 3, & tap mode deployment.
o The interfaces that the Firewall supports are Physical Interfaces and Logical Interfaces.
o The Firewall supports two kinds of Physical Interfaces media—Copper and Fiber Optic.
o Logical Interfaces include VLAN interfaces, loopback interfaces, and tunnel interfaces.
o The Physical interface name is predefined, and you cannot change the name it is fix.
o Interface Type, Tap, HA, Decrypt Mirror, Virtual Wire, L2, L3 and Aggregate Ethernet.
Option Description
Link Speed Select the Interface speed in Mbps (10, 100, or 1000) or select auto.
Link Duplex Select whether the interface transmission mode is full-duplex (full), half-
duplex (half), or negotiated automatically (auto).
Link State Select whether the interface status is enabled (up), disabled (down), or
determined automatically (auto).
Management Select a profile that defines the protocols (for example, SSH, Telnet, and
Profile HTTP) you can use to manage the firewall over this interface.
MTU Enter MTU in bytes for packets sent on this interface default is 1500.
Adjust TCP MSS Select to adjust the maximum segment size (MSS) to accommodate bytes
for any headers within the interface MTU byte size.
Untagged Specifies that all subinterfaces belonging to this Layer 3 interface are
Subinterface untagged.
Option Description
VLAN To enable switching between Layer 2 interfaces or to enable routing
through VLAN interface, select existing VLAN or click VLAN to define new
Security Zone Select Security Zone for the interface or click Zone to define a new zone.
Option Description
Virtual Wire Select a virtual wire or click Virtual Wire to define a new one.
Security Zone Select Security Zone for the interface or click Zone to define a new zone.
Go to Palo Alto Networks firewall WebUI and select Network>Zones and then click Add to
create a new zone, Provide the name for the new Zone and select the zone type and click OK.
In a similar manner we can repeat to create Tap, Virtual Wire or Layer 2 Security Zones.
Click Add and create a Zone and name it DMZ and type should be Layer 3. Assign an interface to
the newly created zone by clicking Add and then select the interface and click OK.