<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VM Series FW - Traffic from Cloudflare in VM-Series in the Public Cloud</title>
    <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/vm-series-fw-traffic-from-cloudflare/m-p/567889#M2045</link>
    <description>&lt;P&gt;PANW supports GRE tunnels and IPSec, so yes you could terminate it on a load balancer or directly onto the box, if you wanted.&lt;/P&gt;</description>
    <pubDate>Fri, 01 Dec 2023 02:53:09 GMT</pubDate>
    <dc:creator>LAYER_8</dc:creator>
    <dc:date>2023-12-01T02:53:09Z</dc:date>
    <item>
      <title>VM Series FW - Traffic from Cloudflare</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/vm-series-fw-traffic-from-cloudflare/m-p/567713#M2041</link>
      <description>&lt;P&gt;Dear Members,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope you are doing well.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We are looking to protect our 2 internet facing VM series firewall by using cloudflare. The plan is use the magic transit tunnel from cloudflare and pass the traffic to internet facing vm series.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Once i create the magic transit tunnel at cloud flare side, what should be the end of the tunnel connected to in Azure? Will it be VPN gateway which than direct the traffic to public load balancer managing VM series fw&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please advice&lt;/P&gt;</description>
      <pubDate>Thu, 30 Nov 2023 04:44:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/vm-series-fw-traffic-from-cloudflare/m-p/567713#M2041</guid>
      <dc:creator>N-Open</dc:creator>
      <dc:date>2023-11-30T04:44:20Z</dc:date>
    </item>
    <item>
      <title>Re: VM Series FW - Traffic from Cloudflare</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/vm-series-fw-traffic-from-cloudflare/m-p/567889#M2045</link>
      <description>&lt;P&gt;PANW supports GRE tunnels and IPSec, so yes you could terminate it on a load balancer or directly onto the box, if you wanted.&lt;/P&gt;</description>
      <pubDate>Fri, 01 Dec 2023 02:53:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/vm-series-fw-traffic-from-cloudflare/m-p/567889#M2045</guid>
      <dc:creator>LAYER_8</dc:creator>
      <dc:date>2023-12-01T02:53:09Z</dc:date>
    </item>
    <item>
      <title>Re: VM Series FW - Traffic from Cloudflare</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/vm-series-fw-traffic-from-cloudflare/m-p/568050#M2048</link>
      <description>&lt;P&gt;Dear&amp;nbsp;&lt;A id="link_27" class="lia-link-navigation lia-page-link lia-user-name-link" href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/160615" target="_self" aria-label="View Profile of LAYER_8"&gt;&lt;SPAN class=""&gt;LAYER_8&lt;/SPAN&gt;&lt;/A&gt;,&lt;/P&gt;
&lt;P&gt;Thanks for the reply. What is recommended place to terminate the tunnel please on Azure?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Will it be Azure VPN Gateway or Azure private load balancer or Palo alto VM series?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any specific requirements to terminate the tunnel like public IP???&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please advice.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 01 Dec 2023 15:33:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/vm-series-fw-traffic-from-cloudflare/m-p/568050#M2048</guid>
      <dc:creator>N-Open</dc:creator>
      <dc:date>2023-12-01T15:33:49Z</dc:date>
    </item>
    <item>
      <title>Re: VM Series FW - Traffic from Cloudflare</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/vm-series-fw-traffic-from-cloudflare/m-p/568068#M2049</link>
      <description>&lt;P&gt;This is a question on your requirements, not my recommendation.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Terminating the tunnel on a VPN gateway allows for resiliency (for example, using OSPF/eBGP for anycast to distribute traffic across global infrastructure of many firewalls sharing the same interfaces) by having hot/hot datacenter configuration.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Terminating the tunnel on a load balancer allows for redundancy (multiple tunnels always up, potentially allowing for auto-scaling) across multiple sites and better application performance/scalability.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There aren't specific requirements to terminate the tunnel on public IP assuming CloudFlare and PANW share the same IPSec Crypto libraries and algorithms, which I am quite sure they do (AES, GCM, GBC, ECC, DHE, etc). You would just get an elastic IP attached to the VM series, and then add a tunnel interface to the Palo Alto with the IP information of CloudFlare and they will do the handshake and then your Palo Alto will allow traffic based off your policies.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What are your requirements? Auto-scaling? Disaster recovery? Cost optimization? Hybrid on-site and cloud? Either, or both, can be suitable depending on what the intended outcomes of the project are.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 01 Dec 2023 18:57:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/vm-series-fw-traffic-from-cloudflare/m-p/568068#M2049</guid>
      <dc:creator>LAYER_8</dc:creator>
      <dc:date>2023-12-01T18:57:44Z</dc:date>
    </item>
    <item>
      <title>Re: VM Series FW - Traffic from Cloudflare</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/vm-series-fw-traffic-from-cloudflare/m-p/568072#M2051</link>
      <description>&lt;P&gt;Dear Layer 8,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for the reply. Appreciated.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We are planning to use Cloudflare services to host the DDoS protection and WAF protection for Azure tenent. The plan is to create a tunnel (Cloudflare magic transit) between Cloudflare and Palo Alto hosted in Azure tenent.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What configuration I will need at the palo alto end please? Can I front end the Palo alto with a Azure application gateway which can load balance the 2 palo alto HA VMs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There is going to be traffic of 10,000 users concurrnelty going through Palo Alto for different works - like web applications access.&amp;nbsp; What memory and cpu spec do you suggest for palo alto VM-series firewall for this requirements.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 01 Dec 2023 19:29:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/vm-series-fw-traffic-from-cloudflare/m-p/568072#M2051</guid>
      <dc:creator>N-Open</dc:creator>
      <dc:date>2023-12-01T19:29:14Z</dc:date>
    </item>
    <item>
      <title>Re: VM Series FW - Traffic from Cloudflare</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/vm-series-fw-traffic-from-cloudflare/m-p/568074#M2053</link>
      <description>&lt;P&gt;Dear&amp;nbsp;&lt;A id="inResponseTo_0" class="lia-link-navigation lia-message-reply-in-response-to" href="https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/vm-series-fw-traffic-from-cloudflare/m-p/568068/highlight/true#M2049" target="_blank"&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="lia-message-in-response-to-username"&gt;LAYER_8&lt;/SPAN&gt;&lt;/A&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I need your advice on another point.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Our old employee has left the company and we have received below configuration from palo alto based on the requirements, Below is the spec.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Install 6 VM NGFWs with 8 vCPUs, Each virtual firewall will have &lt;BR /&gt;the following licenses: Advanced Threat Prevention, Advanced &lt;BR /&gt;URL Filtering ,Advanced Wildfire, DNS Security, Global &lt;BR /&gt;Protect,Data Loss Protection (DLP), with Premium Support, &lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;it says 6 VMs with 8 vCPU.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is it 8 vCPU for each VM?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can we have 12 VMs with 4 vCPU each? Please advice.&lt;/P&gt;</description>
      <pubDate>Fri, 01 Dec 2023 19:34:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/vm-series-fw-traffic-from-cloudflare/m-p/568074#M2053</guid>
      <dc:creator>N-Open</dc:creator>
      <dc:date>2023-12-01T19:34:01Z</dc:date>
    </item>
  </channel>
</rss>

