{"id":1302,"date":"2026-01-28T15:33:47","date_gmt":"2026-01-28T20:33:47","guid":{"rendered":"https:\/\/pressbooks.bccampus.ca\/paloalto\/?post_type=chapter&#038;p=1302"},"modified":"2026-02-19T15:36:04","modified_gmt":"2026-02-19T20:36:04","slug":"subinterfaces-and-vlans","status":"publish","type":"chapter","link":"https:\/\/pressbooks.bccampus.ca\/paloalto\/chapter\/subinterfaces-and-vlans\/","title":{"raw":"2.5 SubInterfaces and Vlans","rendered":"2.5 SubInterfaces and Vlans"},"content":{"raw":"<div class=\"textbox textbox--learning-objectives\"><header class=\"textbox__header\">\r\n<p class=\"textbox__title\">Learning Objectives<\/p>\r\n\r\n<\/header>\r\n<div class=\"textbox__content\">\r\n<ul>\r\n \t<li>Identify sub interface in Palo Alto<\/li>\r\n \t<li>Configure sub Interfaces<\/li>\r\n \t<li>Separate the traffic in different Vlans<\/li>\r\n<\/ul>\r\n<\/div>\r\n<\/div>\r\n\r\n[caption id=\"attachment_1305\" align=\"aligncenter\" width=\"1125\"]<img class=\"wp-image-1305 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-28-123537.png\" alt=\"\" width=\"1125\" height=\"489\" \/> Figure 2.60: Main scenario[\/caption]\r\n\r\n&nbsp;\r\n<div align=\"left\">\r\n<table style=\"width: 100%\"><caption>Table 2.14: IP Addresses list<\/caption>\r\n<tbody>\r\n<tr>\r\n<td><strong>Device<\/strong><\/td>\r\n<td><strong>Configuration<\/strong><\/td>\r\n<\/tr>\r\n<tr>\r\n<td>Palo Alto<\/td>\r\n<td>Ethernet 1\/1: DHCP Client \u2013 Type: Layer3\r\n\r\nEthernet 1\/2: \u2013 Type: Layer3\r\n\r\nManagement: 192.168.1.1\/24\u2013 Type: Layer3<\/td>\r\n<\/tr>\r\n<tr>\r\n<td>WebTerm1-Management<\/td>\r\n<td>192.168.1.2\/24<\/td>\r\n<\/tr>\r\n<tr>\r\n<td>WebTerm2-Vlan6<\/td>\r\n<td>IPV4: 10.6.6.25\/24 \u00a0 GW: 10.6.6.1\u00a0 DNS: 8.8.8.8<\/td>\r\n<\/tr>\r\n<tr>\r\n<td>WebTerm3-Vlan10<\/td>\r\n<td>IPV4: 10.10.10.28\/24 \u00a0 GW: 10.10.10.1\u00a0 DNS: 8.8.8.8<\/td>\r\n<\/tr>\r\n<\/tbody>\r\n<\/table>\r\n<\/div>\r\nTo Add subinterfaces, first select Ethernet 1\/ 2 as a Layer 3 and then select Ethernet1\/ 2&gt; Add Subinterface:\r\n<div align=\"left\">\r\n<table style=\"height: 54px;width: 100%\"><caption>Table 2.15: SubInterfaces<\/caption>\r\n<tbody>\r\n<tr style=\"height: 18px\">\r\n<td style=\"height: 18px;width: 226.375px\"><strong>InterfaceName<\/strong><\/td>\r\n<td style=\"height: 18px;width: 67.5625px\"><strong>Tag<\/strong><\/td>\r\n<td style=\"height: 18px;width: 224.312px\"><strong>Virtual Router<\/strong><\/td>\r\n<td style=\"height: 18px;width: 212.703px\"><strong>Security Zone<\/strong><\/td>\r\n<td style=\"height: 18px;width: 198.078px\"><strong>IPV4<\/strong><\/td>\r\n<\/tr>\r\n<tr>\r\n<td style=\"width: 226.375px\">Ethernet1\/2<\/td>\r\n<td style=\"width: 67.5625px\">-<\/td>\r\n<td style=\"width: 224.312px\">Default<\/td>\r\n<td style=\"width: 212.703px\">-<\/td>\r\n<td style=\"width: 198.078px\">-<\/td>\r\n<\/tr>\r\n<tr style=\"height: 18px\">\r\n<td style=\"height: 18px;width: 226.375px\">Ethernet 1 \/2.6<\/td>\r\n<td style=\"height: 18px;width: 67.5625px\">6<\/td>\r\n<td style=\"height: 18px;width: 224.312px\">Default<\/td>\r\n<td style=\"height: 18px;width: 212.703px\">Guest<\/td>\r\n<td style=\"height: 18px;width: 198.078px\">10.6.6.1\/24<\/td>\r\n<\/tr>\r\n<tr style=\"height: 18px\">\r\n<td style=\"height: 18px;width: 226.375px\">Ethernet 1\/2.10<\/td>\r\n<td style=\"height: 18px;width: 67.5625px\">10<\/td>\r\n<td style=\"height: 18px;width: 224.312px\">Default<\/td>\r\n<td style=\"height: 18px;width: 212.703px\">Secure<\/td>\r\n<td style=\"height: 18px;width: 198.078px\">10.10.10.1\/24<\/td>\r\n<\/tr>\r\n<\/tbody>\r\n<\/table>\r\n<\/div>\r\n\r\n[caption id=\"attachment_1311\" align=\"aligncenter\" width=\"822\"]<img class=\"wp-image-1311 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-28-125122.png\" alt=\"\" width=\"822\" height=\"245\" \/> Figure 2.61: Sub-interfaces[\/caption]\r\n\r\n&nbsp;\r\n<div align=\"left\">\r\n<table style=\"width: 100%\"><caption>Table 2.16: Zones<\/caption>\r\n<tbody>\r\n<tr>\r\n<td style=\"width: 43.0975%\"><strong>Parameters<\/strong><\/td>\r\n<td style=\"width: 56.853%\"><strong>Value<\/strong><\/td>\r\n<\/tr>\r\n<tr>\r\n<td style=\"width: 43.0975%\">Guest<\/td>\r\n<td style=\"width: 56.853%\">Ethernet 1 \/2.6<\/td>\r\n<\/tr>\r\n<tr>\r\n<td style=\"width: 43.0975%\">Secure<\/td>\r\n<td style=\"width: 56.853%\">Ethernet 1\/2.10<\/td>\r\n<\/tr>\r\n<tr>\r\n<td style=\"width: 43.0975%\">Outside<\/td>\r\n<td style=\"width: 56.853%\">Ethernet 1\/1<\/td>\r\n<\/tr>\r\n<\/tbody>\r\n<\/table>\r\n<\/div>\r\n&nbsp;\r\n\r\nRight click on the <strong>Switch&gt; Configure<\/strong>, delete all interfaces except eth0,eth1 and eth 2 and configure the interfaces as below:\r\n<div align=\"left\">\r\n<table style=\"width: 100%\"><caption>Table 2.17: Switch ports list<\/caption>\r\n<tbody>\r\n<tr>\r\n<td style=\"width: 271.344px\"><strong>Port<\/strong><\/td>\r\n<td style=\"width: 298.375px\"><strong>Vlan<\/strong><\/td>\r\n<td style=\"width: 391.5px\"><strong>Type<\/strong><\/td>\r\n<\/tr>\r\n<tr>\r\n<td style=\"width: 271.344px\">0<\/td>\r\n<td style=\"width: 298.375px\">1<\/td>\r\n<td style=\"width: 391.5px\">Dot1q<\/td>\r\n<\/tr>\r\n<tr>\r\n<td style=\"width: 271.344px\">1<\/td>\r\n<td style=\"width: 298.375px\">6<\/td>\r\n<td style=\"width: 391.5px\">Access<\/td>\r\n<\/tr>\r\n<tr>\r\n<td style=\"width: 271.344px\">2<\/td>\r\n<td style=\"width: 298.375px\">10<\/td>\r\n<td style=\"width: 391.5px\">Access<\/td>\r\n<\/tr>\r\n<\/tbody>\r\n<\/table>\r\n<\/div>\r\n\r\n[caption id=\"attachment_1308\" align=\"aligncenter\" width=\"686\"]<img class=\"wp-image-1308 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-28-124036.png\" alt=\"\" width=\"686\" height=\"480\" \/> Figure 2.62: Switch configuration[\/caption]\r\n\r\n1. In Palo Alto, create a default route 0.0.0.0 0.0.0.0 [Default Gateway]\r\n\r\n[caption id=\"attachment_1313\" align=\"aligncenter\" width=\"595\"]<img class=\"wp-image-1313 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-28-125759.png\" alt=\"\" width=\"595\" height=\"546\" \/> Figure 2.63: static route[\/caption]\r\n\r\n2. Create a Source NAT from Guest to Outside.\r\n\r\n[caption id=\"attachment_1314\" align=\"aligncenter\" width=\"797\"]<img class=\"wp-image-1314 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-28-125941.png\" alt=\"\" width=\"797\" height=\"398\" \/> Figure 2.64: Source NAT- From Guest to outside[\/caption]\r\n\r\n[caption id=\"attachment_1315\" align=\"aligncenter\" width=\"1020\"]<img class=\"wp-image-1315 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-28-130015.png\" alt=\"\" width=\"1020\" height=\"790\" \/> Figure 2.65: Source NAT- setting Translated IP[\/caption]\r\n\r\n3. Create a Policy from Guest to Outside. Only DNS, Web-browsing, dns-over-https and SSL applications should be allowed.\r\n\r\n[caption id=\"attachment_1316\" align=\"aligncenter\" width=\"1001\"]<img class=\"wp-image-1316 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-28-130329.png\" alt=\"\" width=\"1001\" height=\"186\" \/> Figure 2.66: Set a policy from Guest to Outside[\/caption]\r\n\r\n4. Verify your configuration in Vlan 6. You shouldn\u2019t be able to ping 8.8.8.8. You should be able to reach Talebi.ca.\r\n\r\n[caption id=\"attachment_1324\" align=\"aligncenter\" width=\"952\"]<img class=\"wp-image-1324 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-28-131534.png\" alt=\"\" width=\"952\" height=\"747\" \/> Figure 2.67: Verify configuration[\/caption]\r\n\r\n5. Create a Source NAT from Secure to Outside\r\n\r\n[caption id=\"attachment_1318\" align=\"aligncenter\" width=\"714\"]<img class=\"wp-image-1318 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-28-130818.png\" alt=\"\" width=\"714\" height=\"354\" \/> Figure 2.68: Source NAT- Secure to outside zone[\/caption]\r\n\r\n[caption id=\"attachment_1319\" align=\"aligncenter\" width=\"715\"]<img class=\"wp-image-1319 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-28-130848.png\" alt=\"\" width=\"715\" height=\"253\" \/> Figure 2.69: Source NAT- Translated IP packet[\/caption]\r\n\r\n6. Create a Policy from Secure to Outside. Only Ping,DNS, YouTube, Goolge-base applications should be allowed.\r\n\r\n[caption id=\"attachment_1320\" align=\"aligncenter\" width=\"863\"]<img class=\"wp-image-1320 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-28-131113.png\" alt=\"\" width=\"863\" height=\"302\" \/> Figure 2.70: Create a policy from Secure to outside zone[\/caption]\r\n\r\n7. Verify your configuration in Vlan 10. You should be able to ping 8.8.8.8. You should be able to reach YouTube.com\r\n\r\n[caption id=\"attachment_1323\" align=\"aligncenter\" width=\"997\"]<img class=\"wp-image-1323 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-28-131514.png\" alt=\"\" width=\"997\" height=\"777\" \/> Figure 2.71: Verify configuration[\/caption]\r\n\r\n&nbsp;\r\n\r\n&nbsp;\r\n\r\n&nbsp;\r\n\r\n&nbsp;\r\n\r\n&nbsp;\r\n\r\n&nbsp;\r\n\r\n&nbsp;\r\n\r\n&nbsp;\r\n\r\n&nbsp;\r\n\r\n&nbsp;\r\n\r\n&nbsp;\r\n\r\n&nbsp;\r\n\r\n&nbsp;\r\n\r\n&nbsp;\r\n\r\n&nbsp;\r\n\r\n&nbsp;\r\n\r\n&nbsp;","rendered":"<div class=\"textbox textbox--learning-objectives\">\n<header class=\"textbox__header\">\n<p class=\"textbox__title\">Learning Objectives<\/p>\n<\/header>\n<div class=\"textbox__content\">\n<ul>\n<li>Identify sub interface in Palo Alto<\/li>\n<li>Configure sub Interfaces<\/li>\n<li>Separate the traffic in different Vlans<\/li>\n<\/ul>\n<\/div>\n<\/div>\n<figure id=\"attachment_1305\" aria-describedby=\"caption-attachment-1305\" style=\"width: 1125px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-1305 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-28-123537.png\" alt=\"\" width=\"1125\" height=\"489\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-28-123537.png 1125w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-28-123537-300x130.png 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-28-123537-1024x445.png 1024w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-28-123537-768x334.png 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-28-123537-65x28.png 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-28-123537-225x98.png 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-28-123537-350x152.png 350w\" sizes=\"auto, (max-width: 1125px) 100vw, 1125px\" \/><figcaption id=\"caption-attachment-1305\" class=\"wp-caption-text\">Figure 2.60: Main scenario<\/figcaption><\/figure>\n<p>&nbsp;<\/p>\n<div style=\"text-align: left;\">\n<table style=\"width: 100%\">\n<caption>Table 2.14: IP Addresses list<\/caption>\n<tbody>\n<tr>\n<td><strong>Device<\/strong><\/td>\n<td><strong>Configuration<\/strong><\/td>\n<\/tr>\n<tr>\n<td>Palo Alto<\/td>\n<td>Ethernet 1\/1: DHCP Client \u2013 Type: Layer3<\/p>\n<p>Ethernet 1\/2: \u2013 Type: Layer3<\/p>\n<p>Management: 192.168.1.1\/24\u2013 Type: Layer3<\/td>\n<\/tr>\n<tr>\n<td>WebTerm1-Management<\/td>\n<td>192.168.1.2\/24<\/td>\n<\/tr>\n<tr>\n<td>WebTerm2-Vlan6<\/td>\n<td>IPV4: 10.6.6.25\/24 \u00a0 GW: 10.6.6.1\u00a0 DNS: 8.8.8.8<\/td>\n<\/tr>\n<tr>\n<td>WebTerm3-Vlan10<\/td>\n<td>IPV4: 10.10.10.28\/24 \u00a0 GW: 10.10.10.1\u00a0 DNS: 8.8.8.8<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<p>To Add subinterfaces, first select Ethernet 1\/ 2 as a Layer 3 and then select Ethernet1\/ 2&gt; Add Subinterface:<\/p>\n<div style=\"text-align: left;\">\n<table style=\"height: 54px;width: 100%\">\n<caption>Table 2.15: SubInterfaces<\/caption>\n<tbody>\n<tr style=\"height: 18px\">\n<td style=\"height: 18px;width: 226.375px\"><strong>InterfaceName<\/strong><\/td>\n<td style=\"height: 18px;width: 67.5625px\"><strong>Tag<\/strong><\/td>\n<td style=\"height: 18px;width: 224.312px\"><strong>Virtual Router<\/strong><\/td>\n<td style=\"height: 18px;width: 212.703px\"><strong>Security Zone<\/strong><\/td>\n<td style=\"height: 18px;width: 198.078px\"><strong>IPV4<\/strong><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 226.375px\">Ethernet1\/2<\/td>\n<td style=\"width: 67.5625px\">&#8211;<\/td>\n<td style=\"width: 224.312px\">Default<\/td>\n<td style=\"width: 212.703px\">&#8211;<\/td>\n<td style=\"width: 198.078px\">&#8211;<\/td>\n<\/tr>\n<tr style=\"height: 18px\">\n<td style=\"height: 18px;width: 226.375px\">Ethernet 1 \/2.6<\/td>\n<td style=\"height: 18px;width: 67.5625px\">6<\/td>\n<td style=\"height: 18px;width: 224.312px\">Default<\/td>\n<td style=\"height: 18px;width: 212.703px\">Guest<\/td>\n<td style=\"height: 18px;width: 198.078px\">10.6.6.1\/24<\/td>\n<\/tr>\n<tr style=\"height: 18px\">\n<td style=\"height: 18px;width: 226.375px\">Ethernet 1\/2.10<\/td>\n<td style=\"height: 18px;width: 67.5625px\">10<\/td>\n<td style=\"height: 18px;width: 224.312px\">Default<\/td>\n<td style=\"height: 18px;width: 212.703px\">Secure<\/td>\n<td style=\"height: 18px;width: 198.078px\">10.10.10.1\/24<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<figure id=\"attachment_1311\" aria-describedby=\"caption-attachment-1311\" style=\"width: 822px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-1311 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-28-125122.png\" alt=\"\" width=\"822\" height=\"245\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-28-125122.png 822w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-28-125122-300x89.png 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-28-125122-768x229.png 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-28-125122-65x19.png 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-28-125122-225x67.png 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-28-125122-350x104.png 350w\" sizes=\"auto, (max-width: 822px) 100vw, 822px\" \/><figcaption id=\"caption-attachment-1311\" class=\"wp-caption-text\">Figure 2.61: Sub-interfaces<\/figcaption><\/figure>\n<p>&nbsp;<\/p>\n<div style=\"text-align: left;\">\n<table style=\"width: 100%\">\n<caption>Table 2.16: Zones<\/caption>\n<tbody>\n<tr>\n<td style=\"width: 43.0975%\"><strong>Parameters<\/strong><\/td>\n<td style=\"width: 56.853%\"><strong>Value<\/strong><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 43.0975%\">Guest<\/td>\n<td style=\"width: 56.853%\">Ethernet 1 \/2.6<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 43.0975%\">Secure<\/td>\n<td style=\"width: 56.853%\">Ethernet 1\/2.10<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 43.0975%\">Outside<\/td>\n<td style=\"width: 56.853%\">Ethernet 1\/1<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<p>&nbsp;<\/p>\n<p>Right click on the <strong>Switch&gt; Configure<\/strong>, delete all interfaces except eth0,eth1 and eth 2 and configure the interfaces as below:<\/p>\n<div style=\"text-align: left;\">\n<table style=\"width: 100%\">\n<caption>Table 2.17: Switch ports list<\/caption>\n<tbody>\n<tr>\n<td style=\"width: 271.344px\"><strong>Port<\/strong><\/td>\n<td style=\"width: 298.375px\"><strong>Vlan<\/strong><\/td>\n<td style=\"width: 391.5px\"><strong>Type<\/strong><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 271.344px\">0<\/td>\n<td style=\"width: 298.375px\">1<\/td>\n<td style=\"width: 391.5px\">Dot1q<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 271.344px\">1<\/td>\n<td style=\"width: 298.375px\">6<\/td>\n<td style=\"width: 391.5px\">Access<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 271.344px\">2<\/td>\n<td style=\"width: 298.375px\">10<\/td>\n<td style=\"width: 391.5px\">Access<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<figure id=\"attachment_1308\" aria-describedby=\"caption-attachment-1308\" style=\"width: 686px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-1308 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-28-124036.png\" alt=\"\" width=\"686\" height=\"480\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-28-124036.png 686w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-28-124036-300x210.png 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-28-124036-65x45.png 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-28-124036-225x157.png 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-28-124036-350x245.png 350w\" sizes=\"auto, (max-width: 686px) 100vw, 686px\" \/><figcaption id=\"caption-attachment-1308\" class=\"wp-caption-text\">Figure 2.62: Switch configuration<\/figcaption><\/figure>\n<p>1. In Palo Alto, create a default route 0.0.0.0 0.0.0.0 [Default Gateway]<\/p>\n<figure id=\"attachment_1313\" aria-describedby=\"caption-attachment-1313\" style=\"width: 595px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-1313 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-28-125759.png\" alt=\"\" width=\"595\" height=\"546\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-28-125759.png 595w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-28-125759-300x275.png 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-28-125759-65x60.png 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-28-125759-225x206.png 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-28-125759-350x321.png 350w\" sizes=\"auto, (max-width: 595px) 100vw, 595px\" \/><figcaption id=\"caption-attachment-1313\" class=\"wp-caption-text\">Figure 2.63: static route<\/figcaption><\/figure>\n<p>2. Create a Source NAT from Guest to Outside.<\/p>\n<figure id=\"attachment_1314\" aria-describedby=\"caption-attachment-1314\" style=\"width: 797px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-1314 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-28-125941.png\" alt=\"\" width=\"797\" height=\"398\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-28-125941.png 797w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-28-125941-300x150.png 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-28-125941-768x384.png 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-28-125941-65x32.png 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-28-125941-225x112.png 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-28-125941-350x175.png 350w\" sizes=\"auto, (max-width: 797px) 100vw, 797px\" \/><figcaption id=\"caption-attachment-1314\" class=\"wp-caption-text\">Figure 2.64: Source NAT- From Guest to outside<\/figcaption><\/figure>\n<figure id=\"attachment_1315\" aria-describedby=\"caption-attachment-1315\" style=\"width: 1020px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-1315 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-28-130015.png\" alt=\"\" width=\"1020\" height=\"790\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-28-130015.png 1020w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-28-130015-300x232.png 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-28-130015-768x595.png 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-28-130015-65x50.png 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-28-130015-225x174.png 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-28-130015-350x271.png 350w\" sizes=\"auto, (max-width: 1020px) 100vw, 1020px\" \/><figcaption id=\"caption-attachment-1315\" class=\"wp-caption-text\">Figure 2.65: Source NAT- setting Translated IP<\/figcaption><\/figure>\n<p>3. Create a Policy from Guest to Outside. Only DNS, Web-browsing, dns-over-https and SSL applications should be allowed.<\/p>\n<figure id=\"attachment_1316\" aria-describedby=\"caption-attachment-1316\" style=\"width: 1001px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-1316 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-28-130329.png\" alt=\"\" width=\"1001\" height=\"186\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-28-130329.png 1001w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-28-130329-300x56.png 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-28-130329-768x143.png 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-28-130329-65x12.png 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-28-130329-225x42.png 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-28-130329-350x65.png 350w\" sizes=\"auto, (max-width: 1001px) 100vw, 1001px\" \/><figcaption id=\"caption-attachment-1316\" class=\"wp-caption-text\">Figure 2.66: Set a policy from Guest to Outside<\/figcaption><\/figure>\n<p>4. Verify your configuration in Vlan 6. You shouldn\u2019t be able to ping 8.8.8.8. You should be able to reach Talebi.ca.<\/p>\n<figure id=\"attachment_1324\" aria-describedby=\"caption-attachment-1324\" style=\"width: 952px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-1324 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-28-131534.png\" alt=\"\" width=\"952\" height=\"747\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-28-131534.png 952w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-28-131534-300x235.png 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-28-131534-768x603.png 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-28-131534-65x51.png 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-28-131534-225x177.png 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-28-131534-350x275.png 350w\" sizes=\"auto, (max-width: 952px) 100vw, 952px\" \/><figcaption id=\"caption-attachment-1324\" class=\"wp-caption-text\">Figure 2.67: Verify configuration<\/figcaption><\/figure>\n<p>5. Create a Source NAT from Secure to Outside<\/p>\n<figure id=\"attachment_1318\" aria-describedby=\"caption-attachment-1318\" style=\"width: 714px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-1318 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-28-130818.png\" alt=\"\" width=\"714\" height=\"354\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-28-130818.png 714w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-28-130818-300x149.png 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-28-130818-65x32.png 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-28-130818-225x112.png 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-28-130818-350x174.png 350w\" sizes=\"auto, (max-width: 714px) 100vw, 714px\" \/><figcaption id=\"caption-attachment-1318\" class=\"wp-caption-text\">Figure 2.68: Source NAT- Secure to outside zone<\/figcaption><\/figure>\n<figure id=\"attachment_1319\" aria-describedby=\"caption-attachment-1319\" style=\"width: 715px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-1319 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-28-130848.png\" alt=\"\" width=\"715\" height=\"253\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-28-130848.png 715w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-28-130848-300x106.png 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-28-130848-65x23.png 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-28-130848-225x80.png 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-28-130848-350x124.png 350w\" sizes=\"auto, (max-width: 715px) 100vw, 715px\" \/><figcaption id=\"caption-attachment-1319\" class=\"wp-caption-text\">Figure 2.69: Source NAT- Translated IP packet<\/figcaption><\/figure>\n<p>6. Create a Policy from Secure to Outside. Only Ping,DNS, YouTube, Goolge-base applications should be allowed.<\/p>\n<figure id=\"attachment_1320\" aria-describedby=\"caption-attachment-1320\" style=\"width: 863px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-1320 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-28-131113.png\" alt=\"\" width=\"863\" height=\"302\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-28-131113.png 863w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-28-131113-300x105.png 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-28-131113-768x269.png 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-28-131113-65x23.png 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-28-131113-225x79.png 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-28-131113-350x122.png 350w\" sizes=\"auto, (max-width: 863px) 100vw, 863px\" \/><figcaption id=\"caption-attachment-1320\" class=\"wp-caption-text\">Figure 2.70: Create a policy from Secure to outside zone<\/figcaption><\/figure>\n<p>7. Verify your configuration in Vlan 10. You should be able to ping 8.8.8.8. You should be able to reach YouTube.com<\/p>\n<figure id=\"attachment_1323\" aria-describedby=\"caption-attachment-1323\" style=\"width: 997px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-1323 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-28-131514.png\" alt=\"\" width=\"997\" height=\"777\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-28-131514.png 997w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-28-131514-300x234.png 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-28-131514-768x599.png 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-28-131514-65x51.png 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-28-131514-225x175.png 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-28-131514-350x273.png 350w\" sizes=\"auto, (max-width: 997px) 100vw, 997px\" \/><figcaption id=\"caption-attachment-1323\" class=\"wp-caption-text\">Figure 2.71: Verify configuration<\/figcaption><\/figure>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"author":1562,"menu_order":5,"template":"","meta":{"pb_show_title":"on","pb_short_title":"","pb_subtitle":"","pb_authors":[],"pb_section_license":""},"chapter-type":[],"contributor":[],"license":[],"class_list":["post-1302","chapter","type-chapter","status-publish","hentry"],"part":115,"_links":{"self":[{"href":"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-json\/pressbooks\/v2\/chapters\/1302","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-json\/pressbooks\/v2\/chapters"}],"about":[{"href":"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-json\/wp\/v2\/types\/chapter"}],"author":[{"embeddable":true,"href":"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-json\/wp\/v2\/users\/1562"}],"version-history":[{"count":16,"href":"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-json\/pressbooks\/v2\/chapters\/1302\/revisions"}],"predecessor-version":[{"id":1330,"href":"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-json\/pressbooks\/v2\/chapters\/1302\/revisions\/1330"}],"part":[{"href":"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-json\/pressbooks\/v2\/parts\/115"}],"metadata":[{"href":"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-json\/pressbooks\/v2\/chapters\/1302\/metadata\/"}],"wp:attachment":[{"href":"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-json\/wp\/v2\/media?parent=1302"}],"wp:term":[{"taxonomy":"chapter-type","embeddable":true,"href":"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-json\/pressbooks\/v2\/chapter-type?post=1302"},{"taxonomy":"contributor","embeddable":true,"href":"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-json\/wp\/v2\/contributor?post=1302"},{"taxonomy":"license","embeddable":true,"href":"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-json\/wp\/v2\/license?post=1302"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}