<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Looking for a recommendation for Azure &amp;quot;internal Load balancer&amp;quot; when using PA redundan in VM-Series in the Public Cloud</title>
    <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/looking-for-a-recommendation-for-azure-quot-internal-load/m-p/191369#M193</link>
    <description>&lt;P&gt;ECMP should return traffic on same tunnel correct? How wouldn't the GP gateway need to be behind LB to?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Tue, 12 Dec 2017 18:12:11 GMT</pubDate>
    <dc:creator>junior_r</dc:creator>
    <dc:date>2017-12-12T18:12:11Z</dc:date>
    <item>
      <title>Looking for a recommendation for Azure "internal Load balancer" when using PA redundant Firewalls</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/looking-for-a-recommendation-for-azure-quot-internal-load/m-p/172858#M102</link>
      <description>&lt;P&gt;Hi,&amp;nbsp; I have deployed redundant PA Firewalls with the internal Azure load balancer to provide resiliance - thos is working however the "internal load balancer has significant limitations.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am looking to see if anyone has any recommendations for 3rd party load balancer (taking into account cost and operation in this environment)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The limitations of the free Azure load balancer are as far as I can see&lt;/P&gt;&lt;P&gt;a.&amp;nbsp; a limitation of a maximum 250 ports&lt;/P&gt;&lt;P&gt;b. no support for port ranges - therefore each port to be foirwarded bust be statically defined&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any pointers/recommendations would be greatly appreciated&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Andrew&lt;/P&gt;</description>
      <pubDate>Wed, 23 Aug 2017 15:01:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/looking-for-a-recommendation-for-azure-quot-internal-load/m-p/172858#M102</guid>
      <dc:creator>alosty</dc:creator>
      <dc:date>2017-08-23T15:01:57Z</dc:date>
    </item>
    <item>
      <title>Re: Looking for a recommendation for Azure "internal Load balancer" when using PA redundan</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/looking-for-a-recommendation-for-azure-quot-internal-load/m-p/174110#M109</link>
      <description>&lt;P&gt;Due to the nature of Azure networking, another loadbalancer won't probably fix this&amp;nbsp;problem.&lt;BR /&gt;When using another LB solution and making this HA, you probably going to need a Azure Internal LB.&lt;/P&gt;&lt;P&gt;See this reference documentation:&amp;nbsp;&lt;A href="https://docs.microsoft.com/en-us/azure/architecture/reference-architectures/dmz/nva-ha" target="_blank"&gt;https://docs.microsoft.com/en-us/azure/architecture/reference-architectures/dmz/nva-ha&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I created a feature request at MS, you can upvote.&lt;BR /&gt;&lt;A href="https://feedback.azure.com/forums/217313-networking/suggestions/31116808-loadbalancer-multiple-ports-in-one-frontend-rule" target="_blank"&gt;https://feedback.azure.com/forums/217313-networking/suggestions/31116808-loadbalancer-multiple-ports-in-one-frontend-rule&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;A (dirty) work-around can be using multiple internal loadbalancer, as far as the client doesn't use over 150 ports (the limit is actually 150).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Unfortunately no (real) solution, but hopefully it will clear things up.&lt;/P&gt;</description>
      <pubDate>Thu, 31 Aug 2017 12:48:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/looking-for-a-recommendation-for-azure-quot-internal-load/m-p/174110#M109</guid>
      <dc:creator>robmaas</dc:creator>
      <dc:date>2017-08-31T12:48:45Z</dc:date>
    </item>
    <item>
      <title>Re: Looking for a recommendation for Azure "internal Load balancer" when using PA redundan</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/looking-for-a-recommendation-for-azure-quot-internal-load/m-p/174123#M110</link>
      <description>&lt;P&gt;Thanks Rob! Just upvoted it several times &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt; Let's hope M$ is going to listen this time. This has been a feature request since 2013 and isput on the feature backlog since november 2016&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://feedback.azure.com/forums/217313-networking/suggestions/4338247-endpoints-can-accept-a-port-range-instead-of-ente" target="_blank"&gt;https://feedback.azure.com/forums/217313-networking/suggestions/4338247-endpoints-can-accept-a-port-range-instead-of-ente&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Michel van Kessel&lt;/P&gt;</description>
      <pubDate>Thu, 31 Aug 2017 13:22:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/looking-for-a-recommendation-for-azure-quot-internal-load/m-p/174123#M110</guid>
      <dc:creator>michelvankessel</dc:creator>
      <dc:date>2017-08-31T13:22:43Z</dc:date>
    </item>
    <item>
      <title>Re: Looking for a recommendation for Azure "internal Load balancer" when using PA redundan</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/looking-for-a-recommendation-for-azure-quot-internal-load/m-p/179176#M139</link>
      <description>&lt;P&gt;As of September 2017 Azure Load Balancer &lt;EM&gt;HA Ports&lt;/EM&gt; capability is in preview. Allows the use of &lt;STRONG&gt;0 &lt;/STRONG&gt;for port number and &lt;STRONG&gt;All&lt;/STRONG&gt; for protocol type which is shorthand for all ports, all protocols -- very useful for forwarding all traffic hitting the load balancer VIP to the back-end VM-series pool members (for both inbound and outbound use cases) -- &lt;EM&gt;in a single load balancer rule.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;A href="https://docs.microsoft.com/en-us/azure/load-balancer/load-balancer-ha-ports-overview" target="_blank"&gt;https://docs.microsoft.com/en-us/azure/load-balancer/load-balancer-ha-ports-overview&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A href="https://docs.microsoft.com/en-us/azure/load-balancer/load-balancer-configure-ha-ports" target="_blank"&gt;https://docs.microsoft.com/en-us/azure/load-balancer/load-balancer-configure-ha-ports&lt;/A&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Before &lt;EM&gt;HA Ports&lt;/EM&gt; capability hits GA, request access to it (link above) and mind the regions where it is available.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;-John&lt;/P&gt;</description>
      <pubDate>Thu, 28 Sep 2017 14:36:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/looking-for-a-recommendation-for-azure-quot-internal-load/m-p/179176#M139</guid>
      <dc:creator>JohnUrbanek</dc:creator>
      <dc:date>2017-09-28T14:36:41Z</dc:date>
    </item>
    <item>
      <title>Re: Looking for a recommendation for Azure "internal Load balancer" when using PA redundan</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/looking-for-a-recommendation-for-azure-quot-internal-load/m-p/190959#M182</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When using multiple PA firewalls on Azure how are you syncing the polices? Also for IPSEC are you terminated on PA or on Azure&lt;/P&gt;&lt;P&gt;VPN gateway?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Sun, 10 Dec 2017 21:50:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/looking-for-a-recommendation-for-azure-quot-internal-load/m-p/190959#M182</guid>
      <dc:creator>junior_r</dc:creator>
      <dc:date>2017-12-10T21:50:25Z</dc:date>
    </item>
    <item>
      <title>Re: Looking for a recommendation for Azure "internal Load balancer" when using PA redundan</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/looking-for-a-recommendation-for-azure-quot-internal-load/m-p/190961#M183</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The easiest way to synchronize polices on multiple&amp;nbsp;Palo Alto Networks firewalls is to use Panorama (our management station) to push policy.&amp;nbsp; This works for all of our physical and virtual firewalls.&amp;nbsp; Config elements can be shared or completely independant by device groups.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Another option is to use a thrid party tool like Ansible to push configs to multiple firewalls.&amp;nbsp; We have some sample Ansible plabooks available:&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/Ansible/ct-p/Ansible" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Ansible/ct-p/Ansible&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The VM-Series firewalls can terminate IPsec tunnels very well.&amp;nbsp; The decision to use the VM-Series versus the Azure VPN gateways should be based on the architecture, routing, performance, etc.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;HTH,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Warby&lt;/P&gt;</description>
      <pubDate>Sun, 10 Dec 2017 22:45:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/looking-for-a-recommendation-for-azure-quot-internal-load/m-p/190961#M183</guid>
      <dc:creator>Warby</dc:creator>
      <dc:date>2017-12-10T22:45:29Z</dc:date>
    </item>
    <item>
      <title>Re: Looking for a recommendation for Azure "internal Load balancer" when using PA redundan</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/looking-for-a-recommendation-for-azure-quot-internal-load/m-p/190971#M184</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/22138"&gt;@Warby&lt;/a&gt; wrote:&lt;BR /&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The easiest way to synchronize polices on multiple&amp;nbsp;Palo Alto Networks firewalls is to use Panorama (our management station) to push policy.&amp;nbsp; This works for all of our physical and virtual firewalls.&amp;nbsp; Config elements can be shared or completely independant by device groups.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Another option is to use a thrid party tool like Ansible to push configs to multiple firewalls.&amp;nbsp; We have some sample Ansible plabooks available:&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/Ansible/ct-p/Ansible" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Ansible/ct-p/Ansible&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The VM-Series firewalls can terminate IPsec tunnels very well.&amp;nbsp; The decision to use the VM-Series versus the Azure VPN gateways should be based on the architecture, routing, performance, etc.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;HTH,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Warby&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hi Warby,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the reply the client don’t have&amp;nbsp;Panorama. I guess I will explore the Ansible playbook route.&amp;nbsp;If I have multiple FWs on Azure how would I create the IPSEC tunnel from high level? Wouldn't&amp;nbsp;External LB&amp;nbsp;Break the IPSEC tunnel? I could use multiple public IPs and tunnel monitor but that would mean only one tunnel will be up at a time. Also what is the performance impact of PAN IPSEC tunnel VS Azure VPN Gateway? What about Global Protect? Would it work with External LB? Would you assign two GP pools? One for FW1 and one for FW2 so the destinations know which firewall to return traffic to?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Dec 2017 03:30:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/looking-for-a-recommendation-for-azure-quot-internal-load/m-p/190971#M184</guid>
      <dc:creator>junior_r</dc:creator>
      <dc:date>2017-12-11T03:30:41Z</dc:date>
    </item>
    <item>
      <title>Re: Looking for a recommendation for Azure "internal Load balancer" when using PA redundan</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/looking-for-a-recommendation-for-azure-quot-internal-load/m-p/191323#M191</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyone?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 12 Dec 2017 13:32:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/looking-for-a-recommendation-for-azure-quot-internal-load/m-p/191323#M191</guid>
      <dc:creator>junior_r</dc:creator>
      <dc:date>2017-12-12T13:32:41Z</dc:date>
    </item>
    <item>
      <title>Re: Looking for a recommendation for Azure "internal Load balancer" when using PA redundan</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/looking-for-a-recommendation-for-azure-quot-internal-load/m-p/191352#M192</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/56277"&gt;@junior_r&lt;/a&gt; wrote:&lt;BR /&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/22138"&gt;@Warby&lt;/a&gt; wrote:&lt;BR /&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The easiest way to synchronize polices on multiple&amp;nbsp;Palo Alto Networks firewalls is to use Panorama (our management station) to push policy.&amp;nbsp; This works for all of our physical and virtual firewalls.&amp;nbsp; Config elements can be shared or completely independant by device groups.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Another option is to use a thrid party tool like Ansible to push configs to multiple firewalls.&amp;nbsp; We have some sample Ansible plabooks available:&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/Ansible/ct-p/Ansible" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Ansible/ct-p/Ansible&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The VM-Series firewalls can terminate IPsec tunnels very well.&amp;nbsp; The decision to use the VM-Series versus the Azure VPN gateways should be based on the architecture, routing, performance, etc.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;HTH,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Warby&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hi Warby,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the reply the client don’t have&amp;nbsp;Panorama. I guess I will explore the Ansible playbook route.&amp;nbsp;If I have multiple FWs on Azure how would I create the IPSEC tunnel from high level? Wouldn't&amp;nbsp;External LB&amp;nbsp;Break the IPSEC tunnel? I could use multiple public IPs and tunnel monitor but that would mean only one tunnel will be up at a time. Also what is the performance impact of PAN IPSEC tunnel VS Azure VPN Gateway? What about Global Protect? Would it work with External LB? Would you assign two GP pools? One for FW1 and one for FW2 so the destinations know which firewall to return traffic to?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;I would connect the IPSEC tunnel(s) directly&amp;nbsp;on the firewalls. If you have multiple firewalls within Azure, with the same back-end, you can use OSPF and ECMP to utilize both tunnels.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For GP I would use the same approach and terminate the GP GW directly on the firewall and only put the GP Portal behind the LB.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Dec 2017 17:10:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/looking-for-a-recommendation-for-azure-quot-internal-load/m-p/191352#M192</guid>
      <dc:creator>robmaas</dc:creator>
      <dc:date>2017-12-12T17:10:25Z</dc:date>
    </item>
    <item>
      <title>Re: Looking for a recommendation for Azure "internal Load balancer" when using PA redundan</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/looking-for-a-recommendation-for-azure-quot-internal-load/m-p/191369#M193</link>
      <description>&lt;P&gt;ECMP should return traffic on same tunnel correct? How wouldn't the GP gateway need to be behind LB to?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 12 Dec 2017 18:12:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/looking-for-a-recommendation-for-azure-quot-internal-load/m-p/191369#M193</guid>
      <dc:creator>junior_r</dc:creator>
      <dc:date>2017-12-12T18:12:11Z</dc:date>
    </item>
    <item>
      <title>Re: Looking for a recommendation for Azure "internal Load balancer" when using PA redundan</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/looking-for-a-recommendation-for-azure-quot-internal-load/m-p/192917#M207</link>
      <description>&lt;P&gt;The Portal will inform the client of the available gateways.&lt;/P&gt;&lt;P&gt;The client will then connect with one of the available gateways, therefore Azure LB is not necessary for this to work.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Dec 2017 17:50:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/looking-for-a-recommendation-for-azure-quot-internal-load/m-p/192917#M207</guid>
      <dc:creator>robmaas</dc:creator>
      <dc:date>2017-12-22T17:50:16Z</dc:date>
    </item>
  </channel>
</rss>

