<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AWS ELB one to one relationship with backend in VM-Series in the Public Cloud</title>
    <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/aws-elb-one-to-one-relationship-with-backend/m-p/215549#M336</link>
    <description>&lt;P&gt;I see that no one answered you question and I can try to help, but it is not quite clear what are you trying to do.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am not sure where you had that from, but taken out of context both statements are not necessary correct. You can surely protect multiple webservers with a single firewall without using load balancer. Also strictly speaking you can have more than one ENI per subnet.&lt;/P&gt;</description>
    <pubDate>Sat, 26 May 2018 12:28:54 GMT</pubDate>
    <dc:creator>BatD</dc:creator>
    <dc:date>2018-05-26T12:28:54Z</dc:date>
    <item>
      <title>AWS ELB one to one relationship with backend</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/aws-elb-one-to-one-relationship-with-backend/m-p/209868#M262</link>
      <description>&lt;P&gt;According to the documentation, if you don't have an ELB sandwich then there is a one to one relationship between the firewall and the back end server. I spoke to support and the answer was the fact that you can only have one ENI attached per subnet. My customer has an existing IAAS stack and wanted only 1 FW per AZ. But the proxy servers in the private subnet autoscale.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This does not appear possible. Can someone explain in more detail how this constraint works? Options would be to put an internal ELB&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="from the documentation" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/14719i05D7F95743174238/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Screenshot 2018-04-12 14.29.35.png" alt="from the documentation" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;from the documentation&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Apr 2018 19:09:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/aws-elb-one-to-one-relationship-with-backend/m-p/209868#M262</guid>
      <dc:creator>PerryK</dc:creator>
      <dc:date>2018-04-12T19:09:33Z</dc:date>
    </item>
    <item>
      <title>Re: AWS ELB one to one relationship with backend</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/aws-elb-one-to-one-relationship-with-backend/m-p/215549#M336</link>
      <description>&lt;P&gt;I see that no one answered you question and I can try to help, but it is not quite clear what are you trying to do.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am not sure where you had that from, but taken out of context both statements are not necessary correct. You can surely protect multiple webservers with a single firewall without using load balancer. Also strictly speaking you can have more than one ENI per subnet.&lt;/P&gt;</description>
      <pubDate>Sat, 26 May 2018 12:28:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/aws-elb-one-to-one-relationship-with-backend/m-p/215549#M336</guid>
      <dc:creator>BatD</dc:creator>
      <dc:date>2018-05-26T12:28:54Z</dc:date>
    </item>
    <item>
      <title>Re: AWS ELB one to one relationship with backend</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/aws-elb-one-to-one-relationship-with-backend/m-p/215625#M337</link>
      <description>&lt;P&gt;We definitely need more context. You can have one ENI per subnet but in that subnet you can have multiple backend resources. So as&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/74884"&gt;@BatD&lt;/a&gt;&amp;nbsp;referrenced you can secure multiple servers with a firewall. If you have multiple resources in multiple subnets and you would like to secure them via the firewall then you need to add more ENI's and configure multiple zones. the VM-Series can have up to 7 Dataplane interfaces + 1 the management interface depending on the machine type used in AWS&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/71/virtualization/virtualization/set-up-the-vm-series-firewall-in-aws/review-system-requirements-and-limitations-for-vm-series-in-aws" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/71/virtualization/virtualization/set-up-the-vm-series-firewall-in-aws/review-system-requirements-and-limitations-for-vm-series-in-aws&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 28 May 2018 17:12:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/aws-elb-one-to-one-relationship-with-backend/m-p/215625#M337</guid>
      <dc:creator>jperry1</dc:creator>
      <dc:date>2018-05-28T17:12:36Z</dc:date>
    </item>
  </channel>
</rss>

