Palo Alto Firewall is next-generation firewalls. Palo Alto firewall provides a flexible networking architecture with Application filtering, Malware protection, dynamic routing, switching and VPN connectivity. Palo Alto Multiple Interface type provide flexible to deploy Palo Alto firewall in Network
Palo Alto interface Type: –
- Virtual Wire
- Layer 3
Tap mode Interface type deployment use to monitor network traffic, it allows you to passively monitor traffic flows across a network with the help of switch SPAN or mirror port. Switch makes a copy of data which received on switch interface and forward that copy of data on SPAN and Mirror port. Switch SPAN and mirror port connected to Palo Alto TAP interface type and Firewall can monitor that data.
Palo Alto HA type interface are you to configure high availability between 2 firewall devices. For HA, we have 2 link 1 for Control link another one for Data link. For Control link, we can use Management interface or Ethernet interface. For Data link, we can use Ethernet link.
3) Virtual Wire
Virtual Wire Interface Type is use to deploy firewall as Transparent Firewall “Bump in the Wire”. To deploy Palo Alto Firewall Transparent mode, we use 2 interfaces as a Virtual Wire Type. Virtual Wire interface type no need to configure IP Address and MAC Address.
Palo Alto firewall Interface Layer 2 type deployment provides switching between interfaces. If we have layer 2 sub-interface that time firewall performs LVAN tag switching. If not have sub-interfaced in that case All interface must be assigned to a VLAN.
5) Layer 3
Layer 3 Interface type Deployment, must assign an IP address, Routing on each physical Layer 3 interface, without IP address we can’t use Layer 3 Interface. All network traffic is going through Layer 3 Deployment; we must have configured virtual router with routing protocols dynamic routing or static routing. We can also create multiple virtual routers.