Thank you for this content, I have a question related to the E/W traffic between the segments attached to the isolated T1. Does this PA NVA help on monitoring and controlling this kind of traffic ?
The Palo Alto in this configuration will not filter that traffic unless you put a NIC in each segment. However, you could create another T1 and create another "Security Zone" with separate segments in it. This would also have a transit segment for the Palo interferface. NSX-T can be used for East West traffic as well.
To what Ryan was saying, there are essentially two ways to deploy a 3rd party NVA. Check out the Microsoft blog in the description to understand the "option 1" and "option 2" and the trade-off's on each.
Thank you for this content, I have a question related to the E/W traffic between the segments attached to the isolated T1. Does this PA NVA help on monitoring and controlling this kind of traffic ?
The Palo Alto in this configuration will not filter that traffic unless you put a NIC in each segment. However, you could create another T1 and create another "Security Zone" with separate segments in it. This would also have a transit segment for the Palo interferface. NSX-T can be used for East West traffic as well.
To what Ryan was saying, there are essentially two ways to deploy a 3rd party NVA. Check out the Microsoft blog in the description to understand the "option 1" and "option 2" and the trade-off's on each.
Thanks