<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Azure AppGateway thinks VM Series firewall is unhealthy in VM-Series in the Public Cloud</title>
    <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/azure-appgateway-thinks-vm-series-firewall-is-unhealthy/m-p/236702#M437</link>
    <description>&lt;P&gt;&lt;SPAN&gt;If this is a default build in Github then you should be able to reach out to Palo Alto NEtworks TAC for support. The GitHub Read me page will list the support policy of whether the GitHub template you are deploying is community supported or Officially TAC supported.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 23 Oct 2018 16:12:31 GMT</pubDate>
    <dc:creator>jperry1</dc:creator>
    <dc:date>2018-10-23T16:12:31Z</dc:date>
    <item>
      <title>Azure AppGateway thinks VM Series firewall is unhealthy</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/azure-appgateway-thinks-vm-series-firewall-is-unhealthy/m-p/231918#M432</link>
      <description>&lt;P&gt;I am implementing this scenrio&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://github.com/PaloAltoNetworks/azure-applicationgateway" target="_blank"&gt;https://github.com/PaloAltoNetworks/azure-applicationgateway&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is the flow of traffic&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;internet-&amp;gt;App Gateway(public ip)-&amp;gt;VM Series-&amp;gt; ILB-&amp;gt;Web Servers(4)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I only have 1 firewall appliance for now.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Azure application gateway connects with Palo Alto VM Series over port 80.&lt;/P&gt;&lt;P&gt;Application gateway keeps on thinking that firewall VM is unhealthy.&lt;/P&gt;&lt;P&gt;There is no custom probe configured in the template above.&lt;/P&gt;&lt;P&gt;So it expects HTTP 200 but is not getting it.&lt;/P&gt;&lt;P&gt;AppGateway only supports HTTP and HTTPS in the backend.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Perhaps this error is due to missing configuration in the firewall.&lt;/P&gt;&lt;P&gt;What type of configuration do I need to do in the firewall to return valid response over port 80 so it appears healthy to app gateway.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have define UnTrust and Trust zones&lt;/P&gt;&lt;P&gt;I have configured the Interfaces&lt;/P&gt;&lt;P&gt;I have configured NAT with a static route.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I created a linux VM in the same subnet as the internal load balancer and web servers.&lt;/P&gt;&lt;P&gt;I can curl successfully to the website and get HTTP 200.&lt;/P&gt;&lt;P&gt;I have verified that VM Series firewall VM does allow&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What needs to happen in the firewall VM it it respond with http 200 to the health checks from application gateway?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Sat, 22 Sep 2018 21:50:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/azure-appgateway-thinks-vm-series-firewall-is-unhealthy/m-p/231918#M432</guid>
      <dc:creator>rajindersingh</dc:creator>
      <dc:date>2018-09-22T21:50:29Z</dc:date>
    </item>
    <item>
      <title>Re: Azure AppGateway thinks VM Series firewall is unhealthy</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/azure-appgateway-thinks-vm-series-firewall-is-unhealthy/m-p/236702#M437</link>
      <description>&lt;P&gt;&lt;SPAN&gt;If this is a default build in Github then you should be able to reach out to Palo Alto NEtworks TAC for support. The GitHub Read me page will list the support policy of whether the GitHub template you are deploying is community supported or Officially TAC supported.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Oct 2018 16:12:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/azure-appgateway-thinks-vm-series-firewall-is-unhealthy/m-p/236702#M437</guid>
      <dc:creator>jperry1</dc:creator>
      <dc:date>2018-10-23T16:12:31Z</dc:date>
    </item>
  </channel>
</rss>

