<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Ideas for On Demand NAT Allocation (AWS-Elastic IPs) in VM-Series in the Public Cloud</title>
    <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/ideas-for-on-demand-nat-allocation-aws-elastic-ips/m-p/303888#M732</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;We are looking to start production in AWS and will be spinning up Hosts that need to have Ingress Traffic to Hosts on a TGW. I am looking to do the PAN AWS Sandwich (Good Idea?) for High Availability. But I need some ideas on how to quickly allocated and build NAT Rules as the operations team spins up new Hosts. I am thinking something might could be done with Dynamic Groups In PANs and Tags in AWS. So that when they spin up and tag a new server somehow the rules/NAt's get built in PANs..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any ideas or feedback on the Sandwich right way for hosting inbound traffic and how to automate or quickly build NAT's would be GREATLY appreciated!&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
    <pubDate>Mon, 16 Dec 2019 14:27:51 GMT</pubDate>
    <dc:creator>Justin_Payne</dc:creator>
    <dc:date>2019-12-16T14:27:51Z</dc:date>
    <item>
      <title>Ideas for On Demand NAT Allocation (AWS-Elastic IPs)</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/ideas-for-on-demand-nat-allocation-aws-elastic-ips/m-p/303888#M732</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;We are looking to start production in AWS and will be spinning up Hosts that need to have Ingress Traffic to Hosts on a TGW. I am looking to do the PAN AWS Sandwich (Good Idea?) for High Availability. But I need some ideas on how to quickly allocated and build NAT Rules as the operations team spins up new Hosts. I am thinking something might could be done with Dynamic Groups In PANs and Tags in AWS. So that when they spin up and tag a new server somehow the rules/NAt's get built in PANs..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any ideas or feedback on the Sandwich right way for hosting inbound traffic and how to automate or quickly build NAT's would be GREATLY appreciated!&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 16 Dec 2019 14:27:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/ideas-for-on-demand-nat-allocation-aws-elastic-ips/m-p/303888#M732</guid>
      <dc:creator>Justin_Payne</dc:creator>
      <dc:date>2019-12-16T14:27:51Z</dc:date>
    </item>
    <item>
      <title>Re: Ideas for On Demand NAT Allocation (AWS-Elastic IPs)</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/ideas-for-on-demand-nat-allocation-aws-elastic-ips/m-p/303893#M733</link>
      <description>&lt;P&gt;You can find the build-out of the LB sandwich with TGW in our reference architecture.&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/resources/reference-architectures/aws" target="_blank"&gt;https://www.paloaltonetworks.com/resources/reference-architectures/aws&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As far as automation goes, we do have tag monitoring with DAG update capabilities native to the firewall in AWS.&amp;nbsp; That will not solve your NAT Policy question though.&amp;nbsp; Other customers typically build the firewall API calls into their CI/CD pipeline when the back end is built.&amp;nbsp; An example of this flow can be found in our autoscale 2.0/2.1 templates.&amp;nbsp; You can extract the PY code to incorporate it into your DevOps process.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://github.com/PaloAltoNetworks/aws-elb-autoscaling" target="_blank"&gt;https://github.com/PaloAltoNetworks/aws-elb-autoscaling&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Dec 2019 14:33:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/ideas-for-on-demand-nat-allocation-aws-elastic-ips/m-p/303893#M733</guid>
      <dc:creator>jmeurer</dc:creator>
      <dc:date>2019-12-16T14:33:18Z</dc:date>
    </item>
  </channel>
</rss>

