AWS
Welcome to the Palo Alto Networks VM-Series on AWS resource page. Here you will find resources about VM-Series on AWS to help you get started with advanced architecture designs and other tools to help accelerate your VM-Series deployment. Engage the community and ask questions in the discussion forum below.
cancel
Showing results for 
Search instead for 
Did you mean: 

VM-Series on AWS Deployment Resources

Welcome to the Palo Alto Networks VM-Series on AWS resource page. Here you will find resources about VM-Series on AWS to help you get started with advanced architecture designs and other tools to help accelerate your VM-Series deployment. Engage the community and ask questions in the discussion forum below.

How to Videos and Tutorials

Note: In order to view ALL of the articles in this section and to engage in discussions on this platform, you must register for an account on LIVEcommunity. Some articles may not be viewable to unregistered users.

Register for a LIVEcommunity account

Customer Support Portal Resource

Note: In order to create a case, please create or active an account and register your device, which can be done in the Customer Support Portal. This area provides product support for all Palo Alto Networks Customers.

Login to the Customer Support Portal

Additional Resources on Beacon

Visit Palo Alto Networks' learning platform, Beacon, for technical knowledge and educational resources related to all of our products.

Please note: You need to be logged into SSO in order to view this content.

Templates, Scripts and Deployment Resources

Amazon GuardDuty to VM-Series Integration

Uses an AWS Lambda function to feed Amazon GuardDuty threat intelligence to the VM-Series for security policy execution.

Palo Alto Networks Community Supported

Auto Scaling the VM-Series on AWS

A set of templates and scripts that deploys an AWS Load Balancer sandwich and the VM-Series firewalls to deliver an Auto Scaling solution for securing internet facing applications.

Auto Scaling the VM-Series on AWS

A set of templates and scripts that deploys an AWS Load Balancer sandwich and the VM-Series firewalls to deliver an Auto Scaling solution for securing internet facing applications.

Auto Scaling the VM-Series on AWS

A set of templates and scripts that deploys an AWS Load Balancer sandwich and the VM-Series firewalls to deliver an Auto Scaling solution for securing internet facing applications.

Auto Scaling VM-Series firewalls on AWS Version 2.1

A set of templates and scripts that deploys AWS Load Balancers and the VM-Series firewalls to deliver an Auto Scaling solution for securing internet facing applications. New in this version is the ability to protect existing workloads as well as net new.

Auto Scaling GlobalProtect on AWS

A sample prototype for Auto Scaling GlobalProtect on AWS.

Palo Alto Networks Community Supported

Auto Scaling the VM-Series on AWS with Terraform

Terraform Template that deploys an AWS Load Balancer sandwich and the VM-Series firewalls to enable Auto Scaling.

Palo Alto Networks Community Supported

ALB/NLB Load Balancer sandwich for managed scale/high availability

Templates and scripts that deploy an AWS ALB/NLB Load Balancer sandwich and two VM-Series firewalls to deliver managed scale and high availability for inbound applications.

Palo Alto Networks Community Supported

Palo Alto Networks NAT Rule Updater

A process for keeping NAT rule destination IPs in sync with changing Elastic Load Balancer VIPs. A Lambda function is used to retrieve the latest ELB VIPs and updates the NAT destination IP if necessary. The process uses naming conventions and instance tagging for configuration.

Partner Community Supported

Hybrid arch/two tier application environment protected by VM-Series

Sample AWS CloudFormation Template that deploys a two-tiered web/DB application environment secured by a VM-Series firewall.

AWS two-tier sample deployed with Terraform

Terraform template that deploys a two-tier web/DB application on AWS secured by a bootstrapped VM-Series firewall.

Palo Alto Networks Community Supported

AWS two-tier sample deployed with Terraform & Ansible

Deploys a two-tiered web/DB and bootstrapped VM-Series firewall using a Terraform Template. The VM-Series is then configured using Ansible scripts.

Palo Alto Networks Community Supported

Transit VPC with the VM-Series on AWS

The AWS Transit VPC is a highly scalable architecture that provides centralized security and connectivity services. Our VM-Series integration with the Transit VPC allows for a fully automated method of securely attaching subscribing (spoke) VPCs to the transit VPC.

Palo Alto Networks Community Supported

Transit VPC Manual Build Step-by-Step Guide

Guides user through the process of building a Transit VPC with the VM-Series. Once completed, the user will have built a Hub, and 3 subscribing VPC spokes.

Palo Alto Networks Community Supported

AWS Transit Gateway – Manual Build

Step by step guide to deploying a Transit Gateway within a Transit VPC with the VM-Series.

Palo Alto Networks Community Supported

Transit VPC CloudFormation Template

CloudFormation Template that a automates the deployment of a Transit Gateway within a Transit VPC with the VM-Series.

Transit Gateway Deployment for North/South and East/West Inspection

Terraform Template that a automates the deployment of a Transit Gateway within a Transit VPC with the VM-Series.

Using User-ID to block malicious source IPs

Enables the VM-Series to block malicious source IP addresses when deployed behind a Source NAT device like an AWS ALB by feeding X-Forward-For header to User-ID.

AWS Discussions

Author Topic Views Replies
05-23-2022

New interface at Palo-alto VM in AWS EC2 instance not turning UP

On a PA-VM (VM500, SW ver- 10.0.8-h8.) in Amazon cloud EC2 instance, i am struggling to create a new interface and bring it up, tried below steps a...

110 1
05-06-2022

Palo in AWS to Azure VPN Gateway

Hi All, I am trying to setup a site-to-to site VPN between Palo (v9.0.1) and Azure VPN gateway. I have a question and an issue that I am trying ...

46 0
05-06-2022

This is a customer inquiry using the vm-100 firewall.

This is a customer inquiry using the vm-100 firewall. The customer is using the Paloalto vm100 firewall, and is using aws nat vpc by assigning one...

111 0
04-26-2022

#Elastic IP in AWS not reachable for paloalto external interface

Hi All, I have deployed Paloalto single vm in AWS and established IPSEC tunnel to onpremise successfully Then configured Global protect when trie...

136 0
04-07-2022

AWS Gateway Load Balancer Target Group Instances Remain Unhealthy

We've deployed VM-Series into AWS INSPECTION VPC implementing the documented approach around use of a Gateway Load Balancer (GWLB) as an Endpoint S...

220 0
03-21-2022

Using the PALOs internal IP as an injected header

Hello I'm very new to Palo, but not new to firewalls and my background is more with applications. This is to do with HTTP(S) traffic with a GET ...

300 1
03-11-2022

Zero trust in AWS issue with ALB

We are trying to implement a zero trust environment inside our AWS cloud. We are using a transit gateway deployment, and have all traffic going thr...

405 1

AWS Blogs

New Digital Course for Cloud NGFW for AWS in Beacon!

04-13-2022 — Check out this new hour-and-a-half long digital course for Cloud NGFW for AWS to learn about the service, how to deploy it, and how to configure a rulestack.

Tags: aws Beacon Cloud NGFW for AWS educational services NGFW
Labels: AWS Beacon Cloud NGFW Cloud NGFW for AWS Educational Services NGFW
486 5 by in Blogs

New Cloud NGFW for AWS Help Center on LIVEcommunity!

03-30-2022 — Head to LIVEcommunity's new Cloud NGFW for AWS technology page for blogs, articles, videos, and more related to Cloud NGFW for AWS.

Tags: aws Cloud NGFW for AWS Advanced URL Filtering app-id blog cloud Cloud NGFW Cloud Security devops Enabling enterprise agility Live Community Help network Network Architects network security NGFW pan-os technologies threat prevention
Labels: AWS Cloud Cloud NGFW for AWS Live Community Help NGFW Pan-OS Technologies
587 4 by in Blogs

Software Firewalls at AWS re:Invent: Secure Your Cloud Migration and Beyond

11-22-2021 — Stop by Palo Alto Networks booth at AWS re:Invent to learn about the latest advancements and tips on how to more efficiently and securely run in the cloud.

Tags: aws
Labels: AWS Events
5228 by in Blogs

October VM-Series and CN-Series Updates

10-21-2021 — This month’s VM-Series and CN-Series firewalls update is full of useful information about optimizing our virtual and container firewalls across a range of environments so that you can secure data, workloads, and applications wherever they reside.

Tags: aws CN-Series vm-series azure panorama
Labels: AWS Azure CN-Series Panorama VM-Series
822 by in Blogs

Prisma SD-WAN Integrated with AWS Transit Gateway Connect

09-09-2021 — When it comes to SD-WAN, legacy solutions are falling behind. Find out how Palo Alto Networks' next-generation Prisma SD-WAN can help your organization embrace the cloud.

Tags: aws Prisma SD-WAN cloud SD-WAN
Labels: AWS Cloud Prisma SD-WAN SD-WAN
1123 by in Blogs

AWS Articles

VM-Series with Alibaba Cloud HAVIP

09-09-2021 — Alibaba Cloud recently introduced a feature called HAVIP allow VM-Series firewalls to be deployed in active/standby mode.

Labels: Alibaba Alibaba Cloud VM-Series VM-Series on AWS
1043 by in General Articles

VM-Series with Alibaba Cloud CEN Transit Router

09-09-2021 — With CEN-TR, VM-Series firewalls can be deployed in a Security VPC to protect inbound, outbound and east/west traffic between a large number of VPCs on Alibaba Cloud.

Labels: Alibaba Alibaba Cloud VM-Series VM-Series on AWS
932 1 by in General Articles

Packet Flow in the AWS Gateway Load Balancer—Outbound

06-10-2021 — A step-by-step walkthrough of a connection from a client in an AWS environment utilizing the Transit Gateway and Gateway Load Balancer to an internet-based server.

Labels: AWS Gateway Load Balancer GWLB TGW Transit Gateway VM-Series on AWS
2823 1 2 by in General Articles

Packet Flow in the AWS Gateway Load Balancer—Inbound

06-10-2021 — A step-by-step walkthrough of a connection from an internet-based client to a server in the AWS environment that utilizes the Transit Gateway and Gateway Load Balancer.

Labels: AWS Gateway Loadbalancer GWLB TGW VM-Series on AWS
1977 2 by in General Articles

Prisma Cloud Data Security is LIVE!

02-16-2021 — Prisma™ Cloud Data Security is purpose-built to address the challenges of discovering and protecting data at the scale and velocity common in public cloud environments. (view in My Videos) The Palo Alto Networks Prisma Cloud Data Security cour...

Labels: AWS VM-Series on AWS
867 by in Digital Learning Articles