<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Multiple Static Route(s) for PA-VM in Azure in VM-Series in the Public Cloud</title>
    <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/multiple-static-route-s-for-pa-vm-in-azure/m-p/558374#M1985</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/298926"&gt;@FreddyCalderon&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;The separate VRs are required depending if you are using internal and external LBs.&lt;/P&gt;
&lt;P&gt;Azure LB is using same IP 168.63.129.16 to source LB healt probes. I am guessin the videos you have looked they are deploying redundant pair of standalone firewalls. Where using internal LB traffic is routed over the firewalls. If you need inbound traffic you will to deploy extenal LB as well. &lt;/P&gt;
&lt;P&gt;So if you use single VR your probes will fail (because the FW will not know to which interface it should send the response). For that reason you configure two VRs and put static route for 168.63.129.16 pointing to the respectful interface.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There is no other real reason to create separate VRs. If you don't use LBs you don't need separate VRs.&lt;/P&gt;</description>
    <pubDate>Mon, 18 Sep 2023 13:43:42 GMT</pubDate>
    <dc:creator>aleksandar.astardzhiev</dc:creator>
    <dc:date>2023-09-18T13:43:42Z</dc:date>
    <item>
      <title>Multiple Static Route(s) for PA-VM in Azure</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/multiple-static-route-s-for-pa-vm-in-azure/m-p/558264#M1984</link>
      <description>&lt;P&gt;Hello all!&lt;/P&gt;
&lt;P&gt;I have successfully deployed a PA VM-300 in our Azure environment and I am a bit confused when it comes to setting up the virtual router for the networks. I've seen a few YouTube videos where people configure one VR with two or more static routes and others with multiple VRs, for example. Untrusted-vr &amp;amp; trust-vr. I have listed a few screenshots of what I have configured but I am still unsure.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;PA MGMT (eth 0 in Azure) IP: 172.27.192.0 /23&lt;/P&gt;
&lt;P&gt;PA Untrusted Eth1 (eth 1 in Azure) IP: 172.27.194.0 /23&lt;/P&gt;
&lt;P&gt;PA Trusted Eth 2 (eth 2 in Azure) IP: 172.27.196.0 /23&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For those who have successfully done a PA VM in Azure before, could you kindly share your experience and configuration, please?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 18 Sep 2023 02:49:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/multiple-static-route-s-for-pa-vm-in-azure/m-p/558264#M1984</guid>
      <dc:creator>FreddyCalderon</dc:creator>
      <dc:date>2023-09-18T02:49:05Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Static Route(s) for PA-VM in Azure</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/multiple-static-route-s-for-pa-vm-in-azure/m-p/558374#M1985</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/298926"&gt;@FreddyCalderon&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;The separate VRs are required depending if you are using internal and external LBs.&lt;/P&gt;
&lt;P&gt;Azure LB is using same IP 168.63.129.16 to source LB healt probes. I am guessin the videos you have looked they are deploying redundant pair of standalone firewalls. Where using internal LB traffic is routed over the firewalls. If you need inbound traffic you will to deploy extenal LB as well. &lt;/P&gt;
&lt;P&gt;So if you use single VR your probes will fail (because the FW will not know to which interface it should send the response). For that reason you configure two VRs and put static route for 168.63.129.16 pointing to the respectful interface.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There is no other real reason to create separate VRs. If you don't use LBs you don't need separate VRs.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Sep 2023 13:43:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/multiple-static-route-s-for-pa-vm-in-azure/m-p/558374#M1985</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2023-09-18T13:43:42Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Static Route(s) for PA-VM in Azure</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/multiple-static-route-s-for-pa-vm-in-azure/m-p/560986#M2005</link>
      <description>&lt;P&gt;Hi Aleksandar,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for much for your explanation. Makes sense now. I appreciate your input.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2023 21:14:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/multiple-static-route-s-for-pa-vm-in-azure/m-p/560986#M2005</guid>
      <dc:creator>FreddyCalderon</dc:creator>
      <dc:date>2023-10-09T21:14:22Z</dc:date>
    </item>
  </channel>
</rss>

