With AWS ingress routing, the HA pair of ngfw-vm can be leverage to inspect all ingress and egress traffic without ELB to mess up ports/IPs, just like the old days of private datacenter. See https://aws.amazon.com/blogs/aws/new-vpc-ingress-routing-simplifying-integration-of-third-party-appl...
However the terraform pan-os provider does not support HA pair config. Basically I have to find out which FW is active in the HA pair, otherwise the commit will fail.
Anyone has better idea how to use terraform to deal with active-passive HA pair? This option is really more attractive compared with any other solution with ELB!!
Suggestion and ideas please. Anyone is making decision for pan-os terraform provider, it would be great to add HA support for terraform!
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!