AWS
Welcome to the Palo Alto Networks VM-Series on AWS resource page. Here you will find resources about VM-Series on AWS to help you get started with advanced architecture designs and other tools to help accelerate your VM-Series deployment. Engage the community and ask questions in the discussion forum below.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

VM-Series on AWS Deployment Resources

Welcome to the Palo Alto Networks VM-Series on AWS resource page. Here you will find resources about VM-Series on AWS to help you get started with advanced architecture designs and other tools to help accelerate your VM-Series deployment. Engage the community and ask questions in the discussion forum below.

Note: In order to view ALL of the articles in this section and to engage in discussions on this platform, you must register for an account on LIVEcommunity. Some articles may not be viewable to unregistered users.

Register for a LIVEcommunity account

Customer Support Portal Resource

Note: In order to create a case, please create or active an account and register your device, which can be done in the Customer Support Portal. This area provides product support for all Palo Alto Networks Customers.

Login to the Customer Support Portal

Digital Learning Courses

Visit Palo Alto Networks' learning platform, Beacon, for free technical knowledge and educational resources related to all of our products.

Please note: You need to be logged into SSO in order to view this content.

Templates, Scripts and Deployment Resources

Amazon GuardDuty to VM-Series Integration

Uses an AWS Lambda function to feed Amazon GuardDuty threat intelligence to the VM-Series for security policy execution.

Palo Alto Networks Community Supported

Auto Scaling the VM-Series on AWS

A set of templates and scripts that deploys an AWS Load Balancer sandwich and the VM-Series firewalls to deliver an Auto Scaling solution for securing internet facing applications.

Auto Scaling the VM-Series on AWS

A set of templates and scripts that deploys an AWS Load Balancer sandwich and the VM-Series firewalls to deliver an Auto Scaling solution for securing internet facing applications.

Auto Scaling the VM-Series on AWS

A set of templates and scripts that deploys an AWS Load Balancer sandwich and the VM-Series firewalls to deliver an Auto Scaling solution for securing internet facing applications.

Auto Scaling VM-Series firewalls on AWS Version 2.1

A set of templates and scripts that deploys AWS Load Balancers and the VM-Series firewalls to deliver an Auto Scaling solution for securing internet facing applications. New in this version is the ability to protect existing workloads as well as net new.

Auto Scaling GlobalProtect on AWS

A sample prototype for Auto Scaling GlobalProtect on AWS.

Palo Alto Networks Community Supported

Auto Scaling the VM-Series on AWS with Terraform

Terraform Template that deploys an AWS Load Balancer sandwich and the VM-Series firewalls to enable Auto Scaling.

Palo Alto Networks Community Supported

ALB/NLB Load Balancer sandwich for managed scale/high availability

Templates and scripts that deploy an AWS ALB/NLB Load Balancer sandwich and two VM-Series firewalls to deliver managed scale and high availability for inbound applications.

Palo Alto Networks Community Supported

Palo Alto Networks NAT Rule Updater

A process for keeping NAT rule destination IPs in sync with changing Elastic Load Balancer VIPs. A Lambda function is used to retrieve the latest ELB VIPs and updates the NAT destination IP if necessary. The process uses naming conventions and instance tagging for configuration.

Partner Community Supported

Hybrid arch/two tier application environment protected by VM-Series

Sample AWS CloudFormation Template that deploys a two-tiered web/DB application environment secured by a VM-Series firewall.

AWS two-tier sample deployed with Terraform

Terraform template that deploys a two-tier web/DB application on AWS secured by a bootstrapped VM-Series firewall.

Palo Alto Networks Community Supported

AWS two-tier sample deployed with Terraform & Ansible

Deploys a two-tiered web/DB and bootstrapped VM-Series firewall using a Terraform Template. The VM-Series is then configured using Ansible scripts.

Palo Alto Networks Community Supported

Transit VPC with the VM-Series on AWS

The AWS Transit VPC is a highly scalable architecture that provides centralized security and connectivity services. Our VM-Series integration with the Transit VPC allows for a fully automated method of securely attaching subscribing (spoke) VPCs to the transit VPC.

Palo Alto Networks Community Supported

Transit VPC Manual Build Step-by-Step Guide

Guides user through the process of building a Transit VPC with the VM-Series. Once completed, the user will have built a Hub, and 3 subscribing VPC spokes.

Palo Alto Networks Community Supported

AWS Transit Gateway – Manual Build

Step by step guide to deploying a Transit Gateway within a Transit VPC with the VM-Series.

Palo Alto Networks Community Supported

Transit VPC CloudFormation Template

CloudFormation Template that a automates the deployment of a Transit Gateway within a Transit VPC with the VM-Series.

Transit Gateway Deployment for North/South and East/West Inspection

Terraform Template that a automates the deployment of a Transit Gateway within a Transit VPC with the VM-Series.

Using User-ID to block malicious source IPs

Enables the VM-Series to block malicious source IP addresses when deployed behind a Source NAT device like an AWS ALB by feeding X-Forward-For header to User-ID.

Discussions

Author Topic Views Replies
03-06-2024

VM Series Licensing Methods

Hi Team, I have an doubt regrds the BYOL and PAY AS YOU GO methods in VM series. First can i use the credits in both the methods BYOL PAYG? I...

179 2
02-07-2024

AWS cloud PA VM deployment time can we select required PAN OS Version ?

Hi, AWS cloud PA VM deployment time i tried to particular os version but i didn't find any option its automatically take any random os version. i...

211 0
02-04-2024

Clarity on Overlay routing with GWLB for Combined (Centralized Egress + Distributed Ingress) deployment model

Hi, I am looking for some clarity on the Overlay routing feature on VM Series FW. I am using the Combined (Centralized Egress + Distributed Ingre...

413 2
01-30-2024

AWS Reference Architecture, Subnet Sizes and Automation

1. The AWS Reference Architectures (AWS - Palo Alto Networks) and associated automation libraries all use a /16 CIDR for the Security VPC and a /24...

391 1
01-30-2024

Paloalto GWLB cluster IPsec tunnels with on-prem

Dear Team, I want to deploy Paloalto 2 - VM-300 with integration of GWLB on AWS. both will be active and passing the traffic. However i have ...

286 1
01-25-2024

AWS: GWLB endpoint mapping in Central Design Model

I'm trying to understand the use of GWLB endpoint mapping in an AWS Central Design Model deployment, other than separating VPC traffic flows from t...

304 0
01-23-2024

How Do I create Multiple IPSec Tunnels in VM-Series on AWS from One VM to another VM In Azure?

Hi, I am interested in knowing if we can create multiple IPSec Tunnels from a Palo Alto VM FW in one cloud to a Palo Alto VM FW in another cloud...

279 0

Blogs

New Features in the August 2022 Cloud Integration Releases

09-20-2022 — Find out about the new features of the August 2022 Cloud Integration Release. — Read more

Labels: AWS Cisco ACI Cloud CN-Series gcp Panorama plugin
3341 1 by in Community Blogs

Defense-in-Depth Strategy With WAF and VM-Series NGFW

08-25-2022 — A look at the capabilities of web application firewalls (WAS) and Palo Alto Networks' VM-Series NGFW when working together and apart. — Read more

Labels: AWS Azure Cloud NGFW VM-Series
7856 6 by in Community Blogs

Getting Started with Prisma Cloud - “Cloud Network Analyzer”

07-27-2022 — The Cloud Network Analyzer engine on Prisma Cloud helps determine the Network exposure of your cloud assets and secure them from Network threats by providing an end-to-end path analysis. At the time of this blog, the Network Analyzer is only suppo... — Read more

Labels: AWS Azure Cloud Security Compute Edition Investigation Misconfiguration Network Exposure Network Perimeter Path Visibility Prisma Cloud RQL
4395 1 by in Community Blogs

Cloud NGFW Versus VM-Series: Comparison Chart

06-23-2022 — Find out how Palo Alto Networks’ Cloud NGFW for AWS and VM-Series compare when it comes to elevating your security posture. Find out how Palo Alto Networks’ Cloud NGFW for AWS and VM-Series compare when it comes to elevating your security posture. — Read more

Labels: AWS Cloud NGFW Cloud NGFW for AWS VM-Series VM-Series on AWS
9217 1 3 by in Community Blogs

What's New in Cloud NGFW for AWS

06-10-2022 — Palo Alto Networks recently added region expansion, a free trial, and programmatic access to its Cloud NGFW for AWS. — Read more

Labels: AWS Cloud Cloud NGFW for AWS
3123 by in Community Blogs

Articles

Upgrading VM Series Firewalls Behind Load Balancer in AWS

09-28-2023 — This blog outlines the best practices for upgrading the VM series firewalls in AWS. — Read more

Labels: AWS Best Practices Firewall Gateway Load Balancer VM Series VM-Series VM-Series on AWS
2129 1 by in General Articles

Get Started with VM-Series with AWS Gateway Load Balancer - A PoC Playbook Guide

09-06-2023 — This article provides the steps to setup, demonstrate and teardown the Palo Alto Networks' VM-Series Next Generation Firewalls on AWS in integration with the AWS Gateway Load Balancer. — Read more

Labels: AWS Cloud Automation Gateway Load Balancer Security automation Terraform VM-Series VM-Series on AWS
2505 by in General Articles

VM-Series with Alibaba Cloud HAVIP

09-09-2021 — Alibaba Cloud recently introduced a feature called HAVIP allow VM-Series firewalls to be deployed in active/standby mode. — Read more

Labels: Alibaba Alibaba Cloud VM-Series VM-Series on AWS
5987 1 by in General Articles

VM-Series with Alibaba Cloud CEN Transit Router

09-09-2021 — With CEN-TR, VM-Series firewalls can be deployed in a Security VPC to protect inbound, outbound and east/west traffic between a large number of VPCs on Alibaba Cloud. — Read more

Labels: Alibaba Alibaba Cloud VM-Series VM-Series on AWS
5399 1 by in General Articles

Packet Flow in the AWS Gateway Load Balancer—Outbound

06-10-2021 — A step-by-step walkthrough of a connection from a client in an AWS environment utilizing the Transit Gateway and Gateway Load Balancer to an internet-based server. — Read more

Labels: AWS Gateway Load Balancer GWLB TGW Transit Gateway VM-Series on AWS
9164 1 3 by in General Articles