Every PAN-OS deployment starts with a decision about how each physical port behaves. The interface type decides whether the firewall routes, switches, sits invisibly in the path, or only watches. Picking the right type matters because it controls which features you can use later: routing protocols, GlobalProtect and IPsec termination need Layer 3 interfaces, most Network Address Translation (NAT) designs use them, and a tap interface can never block anything. When you inherit a firewall, the first screen to read is Network > Interfaces, whose Ethernet, VLAN, Loopback and Tunnel tabs show each port's type, zone and router at a glance.
A Layer 3 interface has an IP address, belongs to a virtual router (or logical router) and a Layer 3 zone, and forwards by routing. It is the most common type and the only physical type that supports a DHCP (Dynamic Host Configuration Protocol) server, dynamic routing protocols and VPN (virtual private network) termination, and it is the usual home for NAT. A Layer 2 interface has no IP address; the firewall switches frames between Layer 2 interfaces that share a VLAN object, while still applying security policy between Layer 2 zones. A virtual wire (vwire) binds exactly two interfaces together as a 'bump in the wire': no IP addresses, no MAC (media access control) learning and no routing. You drop it into an existing link without re-addressing anything, yet you still get App-ID, threat prevention and security policy. A vwire can pass tagged traffic, and its Tag Allowed field limits which VLAN tags it accepts. A tap interface receives a copy of traffic from a switch SPAN (Switched Port Analyzer) or mirror port. It gives visibility, such as App-ID and threat logs, but cannot block, because the firewall is not in the forwarding path.
Several interfaces are logical rather than physical. A loopback interface is a Layer 3 interface that is always up, useful for management access, DNS proxy, a GlobalProtect portal or a stable source address that does not depend on one cable. A tunnel interface, for example tunnel.1, is the logical endpoint for route-based IPsec, GlobalProtect or GRE (Generic Routing Encapsulation); you assign it to a zone and a router just like a physical Layer 3 port, and routes that point at it send traffic into the tunnel. A VLAN interface gives a Layer 2 VLAN an IP address so hosts in that VLAN can be routed to Layer 3 networks, much like a switched virtual interface on a switch.
An aggregate Ethernet (AE) interface, such as ae1, bundles several physical ports of the same speed and media into one logical link for more bandwidth and redundancy. You create the group under Network > Interfaces > Ethernet > Add Aggregate Group, then set each member port's Interface Type to Aggregate Ethernet and assign it to the group. Link Aggregation Control Protocol (LACP) is optional but recommended: it negotiates membership with the switch and detects a misconnected or failed member, so traffic is not black-holed. The AE group itself then gets a type, such as Layer 3, Layer 2 or virtual wire, and all configuration (IP, zone, subinterfaces) is done on the group, not on the members.
Subinterfaces let one physical or AE port carry many networks using IEEE 802.1Q VLAN tags. On a Layer 3 port you create ethernet1/3.20 with tag 20 and its own IP, zone and router, which is the classic 'router on a stick' design facing a trunk port on a switch. Layer 2 and vwire interfaces support subinterfaces too; on a vwire they let you put different VLANs into different zones. By convention the subinterface number matches the tag, but it is the tag field that actually matters. The distinction the exam tests is which type fits which requirement: routing, NAT or VPN means Layer 3; switching between hosts in one subnet means Layer 2; inline inspection with no network change means virtual wire; observe only means tap.
Consider a worked example. A hospital wants threat prevention on the link between its core switch and an old router, but nobody can re-address the router this quarter. You configure ethernet1/5 and ethernet1/6 as a virtual wire, place each side in its own Virtual Wire zone, and cable the firewall inline. The firewall immediately enforces App-ID and threat profiles without any IP or routing change. Later the hospital adds a guest network on the same trunk, so you add vwire subinterfaces with tag 50 in a separate Guest zone, and guest traffic now gets its own rules while the clinical VLANs keep theirs.
Common mistakes: expecting a tap interface to block (it only observes), trying to configure an IP address on AE member ports instead of on the ae group, putting a subinterface in a different VLAN from the switch's trunk tag so traffic never arrives, and assuming a loopback or tunnel interface works without a zone and router assignment.
Exam questions usually describe a requirement and ask for the interface type. 'No network changes', 'no IP addresses' or 'transparent inline' point to virtual wire. 'Only monitor', 'SPAN port' or 'must never affect traffic' point to tap. 'Route between subnets', 'NAT', 'IPsec' or 'GlobalProtect' point to Layer 3. 'Bundle ports for bandwidth and failover' points to aggregate Ethernet with LACP, and 'several VLANs on one physical port with different zones' points to subinterfaces with 802.1Q tags.
Key terms
- Virtual wire
- A pair of interfaces bound together so the firewall inspects traffic transparently with no IP addresses, routing or switching.
- Tap interface
- An interface fed by a switch SPAN or mirror port that gives visibility and logging but cannot enforce or block.
- Aggregate Ethernet (AE)
- A logical interface bundling several same-speed physical ports, optionally negotiated with LACP, for bandwidth and redundancy.
- LACP
- Link Aggregation Control Protocol, which negotiates an aggregate bundle with the peer and removes failed or misconnected members.
- Subinterface
- A logical interface on a parent port that handles one 802.1Q VLAN tag, with its own zone and addressing.
- Tunnel interface
- A logical Layer 3 interface used as the endpoint of a route-based IPsec, GRE or GlobalProtect tunnel.
- Loopback interface
- An always-up logical Layer 3 interface used for services such as management, DNS proxy or a GlobalProtect portal.
- VLAN interface
- A Layer 3 interface attached to a Layer 2 VLAN so its hosts can be routed to other networks.
A hospital wants threat prevention on the link between its core switch and an old router, but nobody can re-address the router this quarter. You configure ethernet1/5 and ethernet1/6 as a virtual wire in two Virtual Wire zones, cable the firewall inline, and it begins enforcing App-ID and threat profiles without any IP or routing change. When a guest VLAN is added to the same trunk, vwire subinterfaces with its tag place guests in their own zone.
Check yourself
Which interface type provides visibility only and can never block traffic?
Tap, because it receives a mirrored copy of traffic from a SPAN port and is not in the forwarding path.
What does LACP add to an aggregate Ethernet group?
It negotiates the bundle with the peer switch and detects failed or misconnected member links so they are removed from use.
How do you carry VLAN 30 and VLAN 40 on one Layer 3 port with separate zones?
Create two Layer 3 subinterfaces (for example ethernet1/2.30 and ethernet1/2.40) with 802.1Q tags 30 and 40, each with its own IP address and zone.
Where do you configure the IP address for an aggregate Ethernet bundle?
On the ae interface (or its subinterfaces), not on the member ports, which are set to type Aggregate Ethernet.