<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Recommended config for Globalprotect on Azure active-active LB sandwich architecture? in VM-Series in the Public Cloud</title>
    <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/recommended-config-for-globalprotect-on-azure-active-active-lb/m-p/459571#M1429</link>
    <description>&lt;P&gt;We are running two active-active VM-300s at Azure using the common firewall architecture reference doc (two Azure standard load balancer sandwich). Now looking to enable Globalprotect gateways and was wondering what best practice would be for external access - use a single address on external Azure load balancers and load balance to VM-300s with floating IP configured on firewall loopback, or bypass the Azure LB and go directly to the Azure external IPs on each VM-300 for gateway access? From what I've read it appears both approaches have been used. Any comments/experiences are appreciated - thanks.&lt;/P&gt;</description>
    <pubDate>Wed, 19 Jan 2022 16:19:35 GMT</pubDate>
    <dc:creator>golubadmin</dc:creator>
    <dc:date>2022-01-19T16:19:35Z</dc:date>
    <item>
      <title>Recommended config for Globalprotect on Azure active-active LB sandwich architecture?</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/recommended-config-for-globalprotect-on-azure-active-active-lb/m-p/459571#M1429</link>
      <description>&lt;P&gt;We are running two active-active VM-300s at Azure using the common firewall architecture reference doc (two Azure standard load balancer sandwich). Now looking to enable Globalprotect gateways and was wondering what best practice would be for external access - use a single address on external Azure load balancers and load balance to VM-300s with floating IP configured on firewall loopback, or bypass the Azure LB and go directly to the Azure external IPs on each VM-300 for gateway access? From what I've read it appears both approaches have been used. Any comments/experiences are appreciated - thanks.&lt;/P&gt;</description>
      <pubDate>Wed, 19 Jan 2022 16:19:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/recommended-config-for-globalprotect-on-azure-active-active-lb/m-p/459571#M1429</guid>
      <dc:creator>golubadmin</dc:creator>
      <dc:date>2022-01-19T16:19:35Z</dc:date>
    </item>
  </channel>
</rss>

