AWS

VM-Series on AWS Deployment Resources

Welcome to the Palo Alto Networks VM-Series on AWS resource page. Here you will find resources about VM-Series on AWS to help you get started with advanced architecture designs and other tools to help accelerate your VM-Series deployment. Engage the community and ask questions in the discussion forum below.

How to Videos and Tutorials

Templates, Scripts and Deployment Resources

Amazon GuardDuty to VM-Series Integration

Uses an AWS Lambda function to feed Amazon GuardDuty threat intelligence to the VM-Series for security policy execution.

Palo Alto Networks Community Supported

Auto Scaling the VM-Series on AWS

A set of templates and scripts that deploys an AWS Load Balancer sandwich and the VM-Series firewalls to deliver an Auto Scaling solution for securing internet facing applications.

Auto Scaling the VM-Series on AWS

A set of templates and scripts that deploys an AWS Load Balancer sandwich and the VM-Series firewalls to deliver an Auto Scaling solution for securing internet facing applications.

Auto Scaling the VM-Series on AWS

A set of templates and scripts that deploys an AWS Load Balancer sandwich and the VM-Series firewalls to deliver an Auto Scaling solution for securing internet facing applications.

Auto Scaling VM-Series firewalls on AWS Version 2.1

A set of templates and scripts that deploys AWS Load Balancers and the VM-Series firewalls to deliver an Auto Scaling solution for securing internet facing applications. New in this version is the ability to protect existing workloads as well as net new.

Auto Scaling GlobalProtect on AWS

A sample prototype for Auto Scaling GlobalProtect on AWS.

Palo Alto Networks Community Supported

Auto Scaling the VM-Series on AWS with Terraform

Terraform Template that deploys an AWS Load Balancer sandwich and the VM-Series firewalls to enable Auto Scaling.

Palo Alto Networks Community Supported

ALB/NLB Load Balancer sandwich for managed scale/high availability

Templates and scripts that deploy an AWS ALB/NLB Load Balancer sandwich and two VM-Series firewalls to deliver managed scale and high availability for inbound applications.

Palo Alto Networks Community Supported

Palo Alto Networks NAT Rule Updater

A process for keeping NAT rule destination IPs in sync with changing Elastic Load Balancer VIPs. A Lambda function is used to retrieve the latest ELB VIPs and updates the NAT destination IP if necessary. The process uses naming conventions and instance tagging for configuration.

Partner Community Supported

Hybrid arch/two tier application environment protected by VM-Series

Sample AWS CloudFormation Template that deploys a two-tiered web/DB application environment secured by a VM-Series firewall.

AWS two-tier sample deployed with Terraform

Terraform template that deploys a two-tier web/DB application on AWS secured by a bootstrapped VM-Series firewall.

Palo Alto Networks Community Supported

AWS two-tier sample deployed with Terraform & Ansible

Deploys a two-tiered web/DB and bootstrapped VM-Series firewall using a Terraform Template. The VM-Series is then configured using Ansible scripts.

Palo Alto Networks Community Supported

Transit VPC with the VM-Series on AWS

The AWS Transit VPC is a highly scalable architecture that provides centralized security and connectivity services. Our VM-Series integration with the Transit VPC allows for a fully automated method of securely attaching subscribing (spoke) VPCs to the transit VPC.

Palo Alto Networks Community Supported

Transit VPC Manual Build Step-by-Step Guide

Guides user through the process of building a Transit VPC with the VM-Series. Once completed, the user will have built a Hub, and 3 subscribing VPC spokes.

Palo Alto Networks Community Supported

AWS Transit Gateway – Manual Build

Step by step guide to deploying a Transit Gateway within a Transit VPC with the VM-Series.

Palo Alto Networks Community Supported

Transit VPC CloudFormation Template

CloudFormation Template that a automates the deployment of a Transit Gateway within a Transit VPC with the VM-Series.

Transit Gateway Deployment for North/South and East/West Inspection

Terraform Template that a automates the deployment of a Transit Gateway within a Transit VPC with the VM-Series.

Using User-ID to block malicious source IPs

Enables the VM-Series to block malicious source IP addresses when deployed behind a Source NAT device like an AWS ALB by feeding X-Forward-For header to User-ID.

Join a Discussion and get your Questions Answered

Have questions? Join the Live Community to post your questions and get answers.
Author Topic Views Replies
yesterday

Aws Tagging broken in Gov Cloud

Sorry if this isn't the perfect fit for this forum (I know it says public cloud). But here is the deal, we are currently attempting to use aws tags to...

65 0
05-05-2020

Autoscaling in AWS version 2.1 -Getting error with Application Template

Getting the below error while launching the application Template. Not sure what could be the reason behind it. Embedded stack arn:aws:cloudformation:us-east-1:632512868473:stack/application-exp-13-DeployNLBLambda-4AMN36HWPBE7/d2898ee0-8c89-11ea-a806-12301089d57f was...

271 1
04-29-2020

HA on AWS

Hi, I would like to ask about PA FW HA on AWS.I am confused AWS said if we use loadbalancer or ELB ,we can not do PA HA.That mean even though I put PA...

392 1
02-11-2020

Security Policy in VM-Series - Container and DAGs

In AWS environment we have containers that do the job and then terminate. How is is possible to do a security policy on containers? DAG is not detecting...

593 0
02-11-2020

Default route is not distributed to subscriber VPC - Bgp/Dynamic routing

Hello, currently doing a POC for Transit VPC setup in AWS with VM-Series firewalls and noticed that default route is not propagated on subscriber VPC...

2412 7
02-03-2020

Trial AWS VM not logging any statistics....

I'm running a trial of the AWS PA-VM product, and am not getting any statistics logged: Logging statistics------------------------------ -----------Log...

888 1
02-05-2020

DMZ setup on Transit VPC (AWS)

I'm just wondering if anyone setup a DMZ on Transit firewalls in Transit VPC on AWS? Basically we need to have outbound to inbound NAT rule with a elastic...

1975 5

Note: In order to view ALL of the articles in this section and to engage in discussions on this platform, you must register for an account on Live Community. Some articles may not be viewable to unregistered users.

Register for a Live Community account

Customer Support Portal Resource

Note: In order to create a case, please create or active an account and register your device, which can be done in the Customer Support Portal. This area provides product support for all Palo Alto Networks Customers.

Login to the Customer Support Portal