Use a Virtual Wire interface to capture DHCP traffic to send to the data lake for
Device Security to access.
| Where Can I Use This? | What Do I Need? |
|
|
One of the following subscriptions:
Device Security subscription for an advanced
Device Security product (Enterprise,
OT, or Medical)
Device Security X subscription
|
To gain complete visibility of DHCP traffic, deploy a Virtual Wire (vWire) in
front of the DHCP server. This
guide assumes familiarity with
PAN-OS configuration, including Virtual
Wire configuration. For details on configuring Virtual Wire interfaces,
see the
PAN-OS Networking Administrator’s Guide.
Network Architecture
This solution is for networks where a DHCP server is on the same network segment
as the firewall interface, as shown in the figure below.
For full
visibility of all four DHCP messages, place the DHCP server behind
a Virtual Wire interface. Doing so enables the firewall to generate
Enhanced Application logs (EALs) for all packets in the exchange.
After proper configuration and physical network changes, the network
looks similar to the following illustration:
Configuration