You can configure a routed Layer 3 security chain after you prepare to deploy Network
Packet Broker.
| Where Can I Use This? | What Do I Need? |
- NGFW (Managed by PAN-OS or Panorama)
| |
A routed layer 3 security chain forwards traffic to a series of data inspection and
processing security devices and then back to the firewall using two dedicated
forwarding interfaces on the firewall.
Before you configure a routed layer 3 security chain, take the steps to
Prepare to Deploy Network Packet Broker, including ensuring that the physical connections between the
firewall and the security chain devices are correct and that you allow the firewall
to forward decrypted content. Check to ensure that you have enough free Ethernet
interfaces on the firewall for the topology you want to configure.
Each routed layer 3 security chain that you configure on the firewall requires two
dedicated layer 3 Ethernet interfaces, which can connect to one layer 3 security
chain or distribute sessions (load balance) to up to 64 layer 3 security chains with
a properly configured router, switch, or similar device between the firewall and the
security chains.
Network Packet Broker cannot forward IPv6 traffic on a routed layer 3 security
chain. To forward IPv6 traffic, use a Transparent Bridge (layer 1) security
chain.