<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Configuration VM-Series on Azure cloud in VM-Series in the Public Cloud</title>
    <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/configuration-vm-series-on-azure-cloud/m-p/518361#M1714</link>
    <description>&lt;P&gt;hard to say without knowing your environment, but what I've done in the past is to make the "spokes" separate vnets. Palo's in their own vnet with peering all the spoke vnets with this one, and using a LB sandwich on each side.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 19 Oct 2022 13:42:05 GMT</pubDate>
    <dc:creator>ccscott</dc:creator>
    <dc:date>2022-10-19T13:42:05Z</dc:date>
    <item>
      <title>Configuration VM-Series on Azure cloud</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/configuration-vm-series-on-azure-cloud/m-p/516879#M1683</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm deploying my first Palo Alto on Azure (I already deployed physical appliance) but I'm blocked.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would like to deploy this type of design. The global network defined is 10.200.0.0/16 who are splitted in serverals sub-networks. I have one Untrust zone for Internet access and several zone for networks where we host our servers for IT needs, projects needs.. On Azure configuration during the VM deployment, the setup request to configure Untrust zone, Trust zone and Management zone. So I understand how to configure Untrust and Management zone and define the subnet attached for these zones, but for Trust zone, in my case, I don't see how to configure it.... I have no a dedicated Trust zone with a subnet dedicated..&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Sorry if my question is stupid..&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Jerome&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jeromecarrier_1-1664963571129.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/44411i12D6362C37455502/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="jeromecarrier_1-1664963571129.png" alt="jeromecarrier_1-1664963571129.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Oct 2022 09:58:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/configuration-vm-series-on-azure-cloud/m-p/516879#M1683</guid>
      <dc:creator>jeromecarrier</dc:creator>
      <dc:date>2022-10-05T09:58:10Z</dc:date>
    </item>
    <item>
      <title>Re: Configuration VM-Series on Azure cloud</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/configuration-vm-series-on-azure-cloud/m-p/517215#M1691</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;No answer ? I would like to know in Azure how configure differents networks for each type of server (dmz, Web server,&amp;nbsp; infra servers...).. Is-it better to create one vnet with several subnets inside the vnet? Or create one vnet per type of server (dmz, infra, Web servers) and create vnet peering ? And in both cases, can I create zone in Palo Alto for each type or it's not possible ? And how to configure for trafic goes via Palo Alto to Internet or to allow specific trafic between différents zone/vnet?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BR&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BR&lt;/P&gt;</description>
      <pubDate>Sun, 09 Oct 2022 16:02:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/configuration-vm-series-on-azure-cloud/m-p/517215#M1691</guid>
      <dc:creator>jeromecarrier</dc:creator>
      <dc:date>2022-10-09T16:02:06Z</dc:date>
    </item>
    <item>
      <title>Re: Configuration VM-Series on Azure cloud</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/configuration-vm-series-on-azure-cloud/m-p/517481#M1694</link>
      <description>&lt;P&gt;Have a look at the Reference Architecture guide as well as the Deployment Guide for Azure, I think it will help you work through this scenario as well as understand the best practices for setting up in Azure.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/resources/reference-architectures/azure" target="_blank"&gt;https://www.paloaltonetworks.com/resources/reference-architectures/azure&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Oct 2022 16:32:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/configuration-vm-series-on-azure-cloud/m-p/517481#M1694</guid>
      <dc:creator>sthornton</dc:creator>
      <dc:date>2022-10-11T16:32:30Z</dc:date>
    </item>
    <item>
      <title>Re: Configuration VM-Series on Azure cloud</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/configuration-vm-series-on-azure-cloud/m-p/517501#M1695</link>
      <description>&lt;P&gt;It depends on your ultimate goal. Personally I usually deploy multiple vnets and that way the traffic between them can be forced through the vm series firewall, even if it it intrazone. Or you could still do it this way and have multiple interfaces zones. Putting all subnets within one vnet is the thing I would not do in this case.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Oct 2022 18:30:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/configuration-vm-series-on-azure-cloud/m-p/517501#M1695</guid>
      <dc:creator>ccscott</dc:creator>
      <dc:date>2022-10-11T18:30:44Z</dc:date>
    </item>
    <item>
      <title>Re: Configuration VM-Series on Azure cloud</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/configuration-vm-series-on-azure-cloud/m-p/517866#M1699</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you. I configured my architecture based on hub/spoke topology. I have à central zone (hub) where is deployed my FW. And I deployed spoke for each other "zone" such as DMZ or Project for project servers. From these zones, they will use corporate services such as AD, DNS, DHCP,... Is-it better to create a spoke name INFRA where AD,DNS,DHCP will be deployed? Or these servers are mutualized for all spokes and it's better to create a dedicated subnet under HUB ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Thu, 13 Oct 2022 21:02:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/configuration-vm-series-on-azure-cloud/m-p/517866#M1699</guid>
      <dc:creator>jeromecarrier</dc:creator>
      <dc:date>2022-10-13T21:02:24Z</dc:date>
    </item>
    <item>
      <title>Re: Configuration VM-Series on Azure cloud</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/configuration-vm-series-on-azure-cloud/m-p/518361#M1714</link>
      <description>&lt;P&gt;hard to say without knowing your environment, but what I've done in the past is to make the "spokes" separate vnets. Palo's in their own vnet with peering all the spoke vnets with this one, and using a LB sandwich on each side.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Oct 2022 13:42:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/configuration-vm-series-on-azure-cloud/m-p/518361#M1714</guid>
      <dc:creator>ccscott</dc:creator>
      <dc:date>2022-10-19T13:42:05Z</dc:date>
    </item>
  </channel>
</rss>

