<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Auto Scaling the VM-Series on AWS feature in VM-Series in the Public Cloud</title>
    <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/auto-scaling-the-vm-series-on-aws-feature/m-p/226603#M385</link>
    <description>&lt;P&gt;So, Is it basically replacing the external ALB from V.2 autoscalling template with manually built NLB?&lt;/P&gt;</description>
    <pubDate>Thu, 09 Aug 2018 14:31:19 GMT</pubDate>
    <dc:creator>hsong</dc:creator>
    <dc:date>2018-08-09T14:31:19Z</dc:date>
    <item>
      <title>Auto Scaling the VM-Series on AWS feature</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/auto-scaling-the-vm-series-on-aws-feature/m-p/226542#M383</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would like to know if &lt;SPAN&gt;&amp;nbsp;Auto Scaling the VM-Series on AWS feature&lt;/SPAN&gt; and load balancing feature is supporting&amp;nbsp; for non-http/https traffic or not?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;Traffic flow:-&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;&lt;P&gt;NLB--&amp;gt;&lt;SPAN&gt;Auto Scaling the VM-Series--&amp;gt;backend server&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Aug 2018 04:50:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/auto-scaling-the-vm-series-on-aws-feature/m-p/226542#M383</guid>
      <dc:creator>8kmiles</dc:creator>
      <dc:date>2018-08-09T04:50:53Z</dc:date>
    </item>
    <item>
      <title>Re: Auto Scaling the VM-Series on AWS feature</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/auto-scaling-the-vm-series-on-aws-feature/m-p/226602#M384</link>
      <description>&lt;P&gt;Yes, you can deploy our V2.0 Autoscaling template from GitHub, you will have an ALB externally with an&amp;nbsp;autoscale group (ASG)&amp;nbsp;for the firewall.&amp;nbsp; You can then manually create the NLB with a Target Group pointing to the firewall.&amp;nbsp; You would then update the ASG with the new target group.&amp;nbsp; Any autoscaling events that occur will add or remove the firewall from the NLB's target group.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://github.com/PaloAltoNetworks/aws-elb-autoscaling" target="_blank"&gt;https://github.com/PaloAltoNetworks/aws-elb-autoscaling&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Aug 2018 14:10:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/auto-scaling-the-vm-series-on-aws-feature/m-p/226602#M384</guid>
      <dc:creator>jmeurer</dc:creator>
      <dc:date>2018-08-09T14:10:29Z</dc:date>
    </item>
    <item>
      <title>Re: Auto Scaling the VM-Series on AWS feature</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/auto-scaling-the-vm-series-on-aws-feature/m-p/226603#M385</link>
      <description>&lt;P&gt;So, Is it basically replacing the external ALB from V.2 autoscalling template with manually built NLB?&lt;/P&gt;</description>
      <pubDate>Thu, 09 Aug 2018 14:31:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/auto-scaling-the-vm-series-on-aws-feature/m-p/226603#M385</guid>
      <dc:creator>hsong</dc:creator>
      <dc:date>2018-08-09T14:31:19Z</dc:date>
    </item>
    <item>
      <title>Re: Auto Scaling the VM-Series on AWS feature</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/auto-scaling-the-vm-series-on-aws-feature/m-p/226605#M386</link>
      <description>&lt;P&gt;I would set it up in parallel, there are some other automations that you could impact by deleting the ALB entirely.&amp;nbsp; You can delete the Listener rule so it does not handle any traffic.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Aug 2018 14:59:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/auto-scaling-the-vm-series-on-aws-feature/m-p/226605#M386</guid>
      <dc:creator>jmeurer</dc:creator>
      <dc:date>2018-08-09T14:59:00Z</dc:date>
    </item>
    <item>
      <title>Re: Auto Scaling the VM-Series on AWS feature</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/auto-scaling-the-vm-series-on-aws-feature/m-p/226669#M387</link>
      <description>&lt;P&gt;I have already&amp;nbsp;&lt;SPAN&gt;deployed V2.0 Autoscaling template from GitHub for http/https traffic. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Like&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;ALB---&amp;gt;Auto-Scale Palo Alto firewall ---&amp;gt;NLB---&amp;gt;Backend Server&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;But now my requirement is for non-http/https traffic whether Autoscaling features will support or not? If yes can you just let me know how to deploy or any template need to use.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Proposed Traffic flow:-&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;NLB---&amp;gt;Auto-Scale Palo Alto firewall---&amp;gt;Backend server&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;OR&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;NLB---&amp;gt;Auto-Scale Palo Alto firewall---&amp;gt;NLB--&amp;gt;Backend server&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Aug 2018 05:31:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/auto-scaling-the-vm-series-on-aws-feature/m-p/226669#M387</guid>
      <dc:creator>8kmiles</dc:creator>
      <dc:date>2018-08-10T05:31:28Z</dc:date>
    </item>
    <item>
      <title>Re: Auto Scaling the VM-Series on AWS feature</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/auto-scaling-the-vm-series-on-aws-feature/m-p/226719#M388</link>
      <description>&lt;P&gt;Either of the proposed flow will work, it just depends on if you need LB in front of your backend servers.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As for what to change.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. Create the front door NLB.&lt;/P&gt;&lt;P&gt;2. Add the Firewall Untrust side to the Target Group of the newly created NLB.&lt;/P&gt;&lt;P&gt;3. Add the newly created Target Group to the "Target Groups" field on the Details tab of the Firewall Autoscale Groups created by the ALB CFT.&lt;/P&gt;</description>
      <pubDate>Fri, 10 Aug 2018 12:50:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/auto-scaling-the-vm-series-on-aws-feature/m-p/226719#M388</guid>
      <dc:creator>jmeurer</dc:creator>
      <dc:date>2018-08-10T12:50:09Z</dc:date>
    </item>
    <item>
      <title>Re: Auto Scaling the VM-Series on AWS feature</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/auto-scaling-the-vm-series-on-aws-feature/m-p/226996#M389</link>
      <description>&lt;P&gt;Done the same thing but getting as "&lt;SPAN&gt;None of these Availability Zones contains a healthy target. Requests are being routed to all targets.&lt;/SPAN&gt;"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. Created NLB in frontdoor and backend.&lt;/P&gt;&lt;P&gt;2. Deployed the VM-Series Auto Scaling Template for AWS (v2.0)&lt;/P&gt;&lt;P&gt;3. Remove the listener rules in ALB.&lt;/P&gt;&lt;P&gt;4. Frontdoor NLB has routed to Auto Scaling group.&lt;/P&gt;&lt;P&gt;5. Backend NLB routed to backend target group.&lt;/P&gt;&lt;P&gt;6. Tested from Internal backend NLB to backed target gorup which is working perfectly.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What i found is that from Auto scaling group to backend NLB integration which i stuck. How to do that? and why unhealthy status is showing due to&amp;nbsp;&lt;SPAN&gt;Auto scaling group to backend NLB integration or some other reason?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;Traffic Flow:-&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;NLB--&amp;gt;VM-Series Auto Scaling--&amp;gt;NLB--&amp;gt;Target Group backend server&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;KS&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Aug 2018 05:35:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/auto-scaling-the-vm-series-on-aws-feature/m-p/226996#M389</guid>
      <dc:creator>8kmiles</dc:creator>
      <dc:date>2018-08-14T05:35:41Z</dc:date>
    </item>
    <item>
      <title>Re: Auto Scaling the VM-Series on AWS feature</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/auto-scaling-the-vm-series-on-aws-feature/m-p/227020#M390</link>
      <description>&lt;P&gt;Did you create a Security policy allowing the traffic and a corresponding NAT rule to map the traffic to the internal NLB? &amp;nbsp;The NLB sends the health probes on the port that the backend servers are configured on unless you have overridden that port. &amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Aug 2018 12:48:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/auto-scaling-the-vm-series-on-aws-feature/m-p/227020#M390</guid>
      <dc:creator>jmeurer</dc:creator>
      <dc:date>2018-08-14T12:48:30Z</dc:date>
    </item>
    <item>
      <title>Re: Auto Scaling the VM-Series on AWS feature</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/auto-scaling-the-vm-series-on-aws-feature/m-p/227152#M391</link>
      <description>&lt;P&gt;Finally, it works for me after configured Destination NAT and Security Policy, Swapping mgmt interface in one of the Auto Scaling Palo Alto instance.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But this won’t full fill our expectation by mixing template and manual configuration, which is not compatibility with each other.&lt;/P&gt;&lt;P&gt;Because there are many things we need to change during scaling in and out.&lt;/P&gt;&lt;P&gt;Like I’m giving one example below:&lt;/P&gt;&lt;P&gt;Whenever scaling in will happened we have to register those scaling in instance to the front door NLB listener rules to be working. So in real time in production environment its not possible to monitor when scaling will happened and we will have to add it immediately.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Manually both NLB can be configured but not auto scaling features of palo alto firewall.&lt;/P&gt;&lt;P&gt;Is there any Template is availble for end to end solution i.e External NLB--&amp;gt;Auto Scalaing Palo Alto--&amp;gt;Internal NLB&lt;/P&gt;&lt;P&gt;or in coming future it will be release.&lt;/P&gt;&lt;P&gt;That will be more usefull for everyone for deploying in Prod environment.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;KS&lt;/P&gt;</description>
      <pubDate>Wed, 15 Aug 2018 12:36:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/auto-scaling-the-vm-series-on-aws-feature/m-p/227152#M391</guid>
      <dc:creator>8kmiles</dc:creator>
      <dc:date>2018-08-15T12:36:35Z</dc:date>
    </item>
    <item>
      <title>Re: Auto Scaling the VM-Series on AWS feature</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/auto-scaling-the-vm-series-on-aws-feature/m-p/227163#M392</link>
      <description>&lt;P&gt;The final bits that you have encountered are possible with modification to Lambda code and either an update to the bootstrap file or integration with panorama.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Your first example of a scale in/out events registering with the NLB is my early point of adding the NLB's target group to the Firewall's autoscale group.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The piece that you will need to incorporate into your environment is the addition of the security and NAT policy for the NLB.&amp;nbsp; That is where either addition to the bootstrap or integration with&amp;nbsp;a Panorama Template come into play.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Our PS and Partner community can assist with formalizing a solution for you.&amp;nbsp; I would suggest reaching out to your SE for an introduction.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Aug 2018 13:43:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/auto-scaling-the-vm-series-on-aws-feature/m-p/227163#M392</guid>
      <dc:creator>jmeurer</dc:creator>
      <dc:date>2018-08-15T13:43:40Z</dc:date>
    </item>
    <item>
      <title>Re: Auto Scaling the VM-Series on AWS feature</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/auto-scaling-the-vm-series-on-aws-feature/m-p/227400#M393</link>
      <description>&lt;P&gt;To Manage all those firewall instance Panorama is required. So i deployed the Panorama but here the question comes how to configure NAT rules in Panorama which will push to all the Palo Alto instances.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Earlier i tried it with one instance and manual i put destination NAT and it works, But in Panoroma how to do it and how it will applicable for all new instance which will create in scaling in time.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;KS&lt;/P&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Fri, 17 Aug 2018 04:02:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/auto-scaling-the-vm-series-on-aws-feature/m-p/227400#M393</guid>
      <dc:creator>8kmiles</dc:creator>
      <dc:date>2018-08-17T04:02:34Z</dc:date>
    </item>
    <item>
      <title>Re: Auto Scaling the VM-Series on AWS feature</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/auto-scaling-the-vm-series-on-aws-feature/m-p/227401#M394</link>
      <description>&lt;P&gt;To Manage all those firewall instance Panorama is required. So i deployed the Panorama but here the question comes how to configure NAT rules in Panorama which will push to all the Palo Alto instances.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Earlier i tried it with one instance and manual i put destination NAT and it works, But in Panoroma how to do it and how it will applicable for all new instance which will create in scaling in time.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;KS&lt;/P&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Fri, 17 Aug 2018 05:44:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/auto-scaling-the-vm-series-on-aws-feature/m-p/227401#M394</guid>
      <dc:creator>8kmiles</dc:creator>
      <dc:date>2018-08-17T05:44:45Z</dc:date>
    </item>
    <item>
      <title>Re: Auto Scaling the VM-Series on AWS feature</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/auto-scaling-the-vm-series-on-aws-feature/m-p/227562#M395</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm able to deploy panorama to manage all the instance's when scaling in happened.&amp;nbsp;&lt;/P&gt;&lt;P&gt;In Panorama configured the device group and assigned the template stack name which i deployed.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also checked connectivity is fine by doing ping test from panorama. But still insatnce's are not updating automatically to Panorama.&lt;/P&gt;&lt;P&gt;Could you please help on this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;KS&lt;/P&gt;</description>
      <pubDate>Mon, 20 Aug 2018 06:41:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/auto-scaling-the-vm-series-on-aws-feature/m-p/227562#M395</guid>
      <dc:creator>8kmiles</dc:creator>
      <dc:date>2018-08-20T06:41:44Z</dc:date>
    </item>
  </channel>
</rss>

