<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to add a Firewall for ALB which is connected to Global accelerator in AWS in VM-Series in the Public Cloud</title>
    <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/how-to-add-a-firewall-for-alb-which-is-connected-to-global/m-p/546523#M1915</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/295932"&gt;@KimSiah&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;I don't have experience with Global Accelerator, but when reading AWS docs it is basically an Anycast public address. Which if I could just simplify - traffic to the Global Accelerator IP will be "forwarded" to the ALB, but again over the Internet Gateway.&lt;/P&gt;
&lt;P&gt;I am assuming the anycast IP will use ALB public IP and for that will also need IGW to be deployed, which means same GWLBendpoint should be sufficient.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am curious if have tested it and what is the result.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 20 Jun 2023 15:08:39 GMT</pubDate>
    <dc:creator>aleksandar.astardzhiev</dc:creator>
    <dc:date>2023-06-20T15:08:39Z</dc:date>
    <item>
      <title>How to add a Firewall for ALB which is connected to Global accelerator in AWS</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/how-to-add-a-firewall-for-alb-which-is-connected-to-global/m-p/545937#M1910</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have implemented a security service VPC using VM series and Gateway Load balancer. in the case where traffic is coming thru the IGW, I am able to route incoming traffic from IGW to security VPC for inspection and then back the application ALB.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;However, I am not sure how to do this if my ALB is connected to a Global Accelerator (when traffic does not pass thru IGW). where and how could I insert the GWLB endpoint ?&lt;/P&gt;
&lt;P&gt;The diagram to illustrate the connectivity&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="KimSiah_1-1686721882301.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/50910i08FCEF2C52182B58/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="KimSiah_1-1686721882301.png" alt="KimSiah_1-1686721882301.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please enlighten. Thanks.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;KS&lt;/P&gt;</description>
      <pubDate>Wed, 14 Jun 2023 05:53:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/how-to-add-a-firewall-for-alb-which-is-connected-to-global/m-p/545937#M1910</guid>
      <dc:creator>KimSiah</dc:creator>
      <dc:date>2023-06-14T05:53:33Z</dc:date>
    </item>
    <item>
      <title>Re: How to add a Firewall for ALB which is connected to Global accelerator in AWS</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/how-to-add-a-firewall-for-alb-which-is-connected-to-global/m-p/546523#M1915</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/295932"&gt;@KimSiah&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;I don't have experience with Global Accelerator, but when reading AWS docs it is basically an Anycast public address. Which if I could just simplify - traffic to the Global Accelerator IP will be "forwarded" to the ALB, but again over the Internet Gateway.&lt;/P&gt;
&lt;P&gt;I am assuming the anycast IP will use ALB public IP and for that will also need IGW to be deployed, which means same GWLBendpoint should be sufficient.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am curious if have tested it and what is the result.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 20 Jun 2023 15:08:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/how-to-add-a-firewall-for-alb-which-is-connected-to-global/m-p/546523#M1915</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2023-06-20T15:08:39Z</dc:date>
    </item>
    <item>
      <title>Re: How to add a Firewall for ALB which is connected to Global accelerator in AWS</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/how-to-add-a-firewall-for-alb-which-is-connected-to-global/m-p/559305#M1988</link>
      <description>&lt;P&gt;GA does not send traffic via IGW, GA traffic is not even controlled by the VPC NACL. I have removed the GA, instead, I used a NLB in front of the ALB and made IGW send traffic for the NLB to the GWLB endpoint&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Sep 2023 08:13:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/how-to-add-a-firewall-for-alb-which-is-connected-to-global/m-p/559305#M1988</guid>
      <dc:creator>KimSiah</dc:creator>
      <dc:date>2023-09-25T08:13:38Z</dc:date>
    </item>
  </channel>
</rss>

