<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Monitoring of external ip configured for vpn in Palo Alto vm firewalls deployed in Azure in VM-Series in the Public Cloud</title>
    <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/monitoring-of-external-ip-configured-for-vpn-in-palo-alto-vm/m-p/531974#M1801</link>
    <description>&lt;P&gt;I'm afraid I can't help with this, I don't have experience of VM Palos in cloud environments, sorry.&lt;/P&gt;</description>
    <pubDate>Wed, 22 Feb 2023 13:56:48 GMT</pubDate>
    <dc:creator>djr</dc:creator>
    <dc:date>2023-02-22T13:56:48Z</dc:date>
    <item>
      <title>Monitoring of external ip configured for vpn in Palo Alto vm firewalls deployed in Azure</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/monitoring-of-external-ip-configured-for-vpn-in-palo-alto-vm/m-p/531774#M1799</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have 2 Palo Alto VM firewalls (A: Primary &amp;amp; B: Secondary) deployed in Active/Passive mode for high-availability. These firewalls are deployed in Azure cloud and have multiple site to site IPSEC VPN tunnels configured with multiple vendors. Recently, we faced an issue when we were performing PAN OS upgrade on both the firewalls.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After we upgraded secondary firewall B, we failed over the traffic from A to B so that we can upgrade A:Primary one, the failover happened successfully from A to B but the floating IP did not move from A to B. Hence, we had to roll back the changes as external IP remained on suspended firewall A: Primary and VPN tunnels went down which led to outage. So, as a resolution we had to manually attach the floating IP from firewall A to firewall B, which became active after manual failover.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can someone please help me in below,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1. How can we avoid the situation so that floating Ip moves whenever there is failover triggered between Active &amp;amp; Passive for Palo Alto VM firewalls in Azure?&lt;/P&gt;
&lt;P&gt;2. How can we setup monitor for external public IP which is attached to the floating IP in Azure so that we know that VPNs with multiple vendors are up and running fine?&lt;/P&gt;
&lt;P&gt;3. What is the best architecture design solution for site to site VPN tunnels setup configured in Palo Alto VMs in Azure?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks &amp;amp; Regards,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Bilal&lt;/P&gt;</description>
      <pubDate>Mon, 20 Feb 2023 17:43:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/monitoring-of-external-ip-configured-for-vpn-in-palo-alto-vm/m-p/531774#M1799</guid>
      <dc:creator>BilalM</dc:creator>
      <dc:date>2023-02-20T17:43:12Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring of external ip configured for vpn in Palo Alto vm firewalls deployed in Azure</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/monitoring-of-external-ip-configured-for-vpn-in-palo-alto-vm/m-p/531957#M1800</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/20958"&gt;@djr&lt;/a&gt; / &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/143315"&gt;@SebRupik&lt;/a&gt;&amp;nbsp;, can you please help me here, any suggestions?&lt;/P&gt;</description>
      <pubDate>Wed, 22 Feb 2023 08:09:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/monitoring-of-external-ip-configured-for-vpn-in-palo-alto-vm/m-p/531957#M1800</guid>
      <dc:creator>BilalM</dc:creator>
      <dc:date>2023-02-22T08:09:22Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring of external ip configured for vpn in Palo Alto vm firewalls deployed in Azure</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/monitoring-of-external-ip-configured-for-vpn-in-palo-alto-vm/m-p/531974#M1801</link>
      <description>&lt;P&gt;I'm afraid I can't help with this, I don't have experience of VM Palos in cloud environments, sorry.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Feb 2023 13:56:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/monitoring-of-external-ip-configured-for-vpn-in-palo-alto-vm/m-p/531974#M1801</guid>
      <dc:creator>djr</dc:creator>
      <dc:date>2023-02-22T13:56:48Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring of external ip configured for vpn in Palo Alto vm firewalls deployed in Azure</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/monitoring-of-external-ip-configured-for-vpn-in-palo-alto-vm/m-p/532431#M1815</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;&amp;nbsp;, any suggestions for my query.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Feb 2023 08:31:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/monitoring-of-external-ip-configured-for-vpn-in-palo-alto-vm/m-p/532431#M1815</guid>
      <dc:creator>BilalM</dc:creator>
      <dc:date>2023-02-28T08:31:01Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring of external ip configured for vpn in Palo Alto vm firewalls deployed in Azure</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/monitoring-of-external-ip-configured-for-vpn-in-palo-alto-vm/m-p/532974#M1828</link>
      <description>&lt;P&gt;for 1. i'd use 2 standalone VMs with loadbalancing instead of a HA cluster&lt;/P&gt;
&lt;P&gt;2. there's monitoring tools in azure for that&lt;/P&gt;
&lt;P&gt;3. if you go with the standalone VMs you can setup 2 tunnels and use these for failover (pbf/bgp/...)&lt;/P&gt;</description>
      <pubDate>Thu, 02 Mar 2023 15:47:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/monitoring-of-external-ip-configured-for-vpn-in-palo-alto-vm/m-p/532974#M1828</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2023-03-02T15:47:20Z</dc:date>
    </item>
  </channel>
</rss>

