Palo Alto Networks Virtual Wire (vWire) Interfaces Overview

Virtual Wire (vWire) interfaces allow Palo Alto Networks firewalls to be deployed transparently in a network, acting as a "bump in the wire" without requiring any Layer 2 or Layer 3 addressing. This setup enables the firewall to inspect and enforce policies on traffic passing through it without participating in switching or routing.

Key Characteristics

Supported Features

Limitations

High Availability Considerations

In Active/Passive High Availability (HA) deployments, you can configure the passive firewall to allow peer devices on either side of the firewall to pre-negotiate LLDP and LACP over a vWire before an HA failover occurs. This pre-negotiation speeds up HA failovers by reducing the time required for neighboring devices to detect the firewall's presence and re-establish LACP links.

Additional Resources