Complete the following procedure to enable
the CN-Series firewall to inspect tagged VLAN traffic. To inspect
VLAN tagged traffic, you must update the configuration of all virtual
wires on Panorama to allow all VLAN tags. Then you must annotate
your application pod YAML file to assign VLAN tags to the app pod
interfaces. This annotation tells the CN-NGFW which tags are applied
to packets that are sent through the firewall.
VLAN tagging is not supported.
Enable all VLANs on all interfaces of CN-NGFW.
Log in to Panorama.
Select the first virtual wire.
Repeat this procedure for each virtual wire.
Append the application pod YAML file with the following
annotations to apply a static VLAN ID per interface.