Cloud Integration

The scripts, templates and resources on this page are contributions from Palo Alto Networks and from the community at large – both customers and partners. They are intended to help streamline your deployment of the VM-Series in the public cloud and your virtualized data center.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Cloud Integration

The scripts, templates and resources on this page are contributions from Palo Alto Networks and from the community at large – both customers and partners. They are intended to help streamline your deployment of the VM-Series in the public cloud and your virtualized data center.

AWS Scripts and Templates

Amazon GuardDuty to VM-Series Integration

Uses an AWS Lambda function to feed Amazon GuardDuty threat intelligence to the VM-Series for security policy execution.

Palo Alto Networks Community Supported

Star6
Fork3

Auto Scaling the VM-Series on AWS

A set of templates and scripts that deploys an AWS Load Balancer sandwich and the VM-Series firewalls to deliver an Auto Scaling solution for securing internet facing applications.

Star58
Fork64

Auto Scaling the VM-Series on AWS

A set of templates and scripts that deploys an AWS Load Balancer sandwich and the VM-Series firewalls to deliver an Auto Scaling solution for securing internet facing applications.

Star58
Fork64

Auto Scaling the VM-Series on AWS

A set of templates and scripts that deploys an AWS Load Balancer sandwich and the VM-Series firewalls to deliver an Auto Scaling solution for securing internet facing applications.

Star58
Fork64

Auto Scaling VM-Series firewalls on AWS Version 2.1

A set of templates and scripts that deploys AWS Load Balancers and the VM-Series firewalls to deliver an Auto Scaling solution for securing internet facing applications. New in this version is the ability to protect existing workloads as well as net new.

Star58
Fork64

Auto Scaling GlobalProtect on AWS

A sample prototype for Auto Scaling GlobalProtect on AWS.

Palo Alto Networks Community Supported

Star79
Fork83

Auto Scaling the VM-Series on AWS with Terraform

Terraform Template that deploys an AWS Load Balancer sandwich and the VM-Series firewalls to enable Auto Scaling.

Palo Alto Networks Community Supported

Star151
Fork154

ALB/NLB Load Balancer sandwich for managed scale/high availability

Templates and scripts that deploy an AWS ALB/NLB Load Balancer sandwich and two VM-Series firewalls to deliver managed scale and high availability for inbound applications.

Palo Alto Networks Community Supported

Star13
Fork13

Palo Alto Networks NAT Rule Updater

A process for keeping NAT rule destination IPs in sync with changing Elastic Load Balancer VIPs. A Lambda function is used to retrieve the latest ELB VIPs and updates the NAT destination IP if necessary. The process uses naming conventions and instance tagging for configuration.

Partner Community Supported

Something went wrong...error
Star ?
Fork ?

Hybrid arch/two tier application environment protected by VM-Series

Sample AWS CloudFormation Template that deploys a two-tiered web/DB application environment secured by a VM-Series firewall.

Star79
Fork83

AWS two-tier sample deployed with Terraform

Terraform template that deploys a two-tier web/DB application on AWS secured by a bootstrapped VM-Series firewall.

Palo Alto Networks Community Supported

Star151
Fork154

AWS two-tier sample deployed with Terraform & Ansible

Deploys a two-tiered web/DB and bootstrapped VM-Series firewall using a Terraform Template. The VM-Series is then configured using Ansible scripts.

Palo Alto Networks Community Supported

Star151
Fork154

Transit VPC with the VM-Series on AWS

The AWS Transit VPC is a highly scalable architecture that provides centralized security and connectivity services. Our VM-Series integration with the Transit VPC allows for a fully automated method of securely attaching subscribing (spoke) VPCs to the transit VPC.

Palo Alto Networks Community Supported

Star41
Fork34

Transit VPC Manual Build Step-by-Step Guide

Guides user through the process of building a Transit VPC with the VM-Series. Once completed, the user will have built a Hub, and 3 subscribing VPC spokes.

Palo Alto Networks Community Supported

AWS Transit Gateway – Manual Build

Step by step guide to deploying a Transit Gateway within a Transit VPC with the VM-Series.

Palo Alto Networks Community Supported

Transit VPC CloudFormation Template

CloudFormation Template that a automates the deployment of a Transit Gateway within a Transit VPC with the VM-Series.

Star35
Fork30

Transit Gateway Deployment for North/South and East/West Inspection

Terraform Template that a automates the deployment of a Transit Gateway within a Transit VPC with the VM-Series.

Star47
Fork76

Using User-ID to block malicious source IPs

Enables the VM-Series to block malicious source IP addresses when deployed behind a Source NAT device like an AWS ALB by feeding X-Forward-For header to User-ID.

Star7
Fork1

Azure Scripts and Templates

Terraform Template that deploys a two-tier containerized application on AKS secured by VM-Series

Uses a Terraform template to deploy (2) two-tiered containerized applications (Guestbook app and a WordPress server) within an AKS cluster that is protected by the VM-Series in an Application Gateway/Load Balancer sandwich.

Palo Alto Networks Community Supported

Star6
Fork6

Azure-FW-4-Interfaces

Deploys a VM-Series with 4 interfaces into an existing Microsoft Azure environment.

Palo Alto Networks Community Supported

Something went wrong...error
Star ?
Fork ?

Azure-FW-3-Interfaces

Deploys a VM-Series with 3 interfaces (1-MGMT and 2-Dataplane) into an existing Microsoft Azure environment.

Palo Alto Networks Community Supported

Something went wrong...error
Star ?
Fork ?

Multiple Azure interface variations

Several ARM templates for the VM-Series with varying options including multiple interfaces.

Palo Alto Networks Community Supported

Star5
Fork1

Azure-2-Firewalls-Public-Load-Balancer

Deploys a Public Azure Load Balancer in front of 2 VM-Series firewalls with the following features:

  • The 2 firewalls are deployed with 4-8 interfaces. 1 MGMT and 3-7 data plane.
  • Static IP addresses are assigned to the interfaces based on the input in the starting ip address fields.

Note: This template deploys into existing VNETs and storage accounts within the same region. As a result, the storage account and VNET must be created before deploying this template.

Palo Alto Networks Community Supported

Star5
Fork10

Managed Scale and Resiliency for the VM-Series on Microsoft Azure

An ARM template that deploys two VM-Series firewalls between a pair of Azure load balancers to deliver managed scale and high availability for internet facing applications.

Star27
Fork52

Using VM-Series Firewalls to Secure Internet-Facing Web Workloads

This template creates a highly available VM-Series security solution for Azure for both inbound traffic and outbound traffic. It uses VM-Series firewall pairs coupled with Azure load balancers for a fully redundant security solution.

Star4
Fork8

Auto Scaling the VM-Series-firewall on Azure v1.0

Templates and scripts that deploy Azure Load Balancers and the VM-Series firewalls to deliver security for internet facing applications. Allows for protecting of new or existing workloads.

Star17
Fork39

Azure Transit VNet with the VM-Series

Deploys a Hub and Spoke architecture to centralize commonly used services such as security and secure connectivity. All traffic to and from the Spokes will 'transit' the Hub VNet and will be protected by the VM-Series next generation firewall.

Star20
Fork37

Azure Transit VNET architecture with auto scaling VM-Series in application spoke

Deploys a Hub and Spoke architecture to centralize commonly used services such as security and secure connectivity. All traffic to and from the Spokes will 'transit' the Hub VNET and will be protected by the VM-Series next generation firewall. Version 1.1 adds ability to do auto scaling for VM-Series to protect Internet facing applications running in a spoke VNET.

Star20
Fork37

Two tier application environment protected by VM-Series

ARM template that deploys a two-tiered web/DB application environment secured by a VM-Series firewall. Template includes relevant User-Defined Route (UDR) tables to send all traffic through the VM-Series firewall.

Star121
Fork156

Terraform two tier application environment protected by VM-Series

A Terraform Template that deploys two-tiered web/DB application environment secured by a VM-Series firewall.

Palo Alto Networks Community Supported

Star151
Fork154

Azure VM Monitoring

Python script that harvests Azure VM properties and publishes them as IP-tag mappings that can be used in a Dynamic Address Group.

Star3
Fork2

Google Cloud Platform

Load balancer sandwich with the VM-Series

Uses a Terraform template to a load balancer sandwich, web servers and VM-Series firewalls.

Palo Alto Networks Community Supported

Star16
Fork27

GKE load balancer sandwich with the VM-Series

Uses a Terraform template to a GKE load balancer sandwich and VM-Series firewalls.

Palo Alto Networks Community Supported

Star16
Fork27

Two-Tier containerized application on GKE secured by VM-Series

This provides the instructions and Terraform template to deploy a GKE cluster and VM-Series firewall in a GCP project. It then guides users through the process of deploying a 2-tier containerized application with an internal load balancer. Finally the lab shows how both North/South and East/West visibilty can be achieved via the VM-Series firewall located in the same GCP project as the GKE cluster.

Palo Alto Networks Community Supported

Star8
Fork7

Two tier application environment protected by VM-Series

Uses a GCP template to deploy a two-tiered web server/DB application environment protected by a bootstrapped VM-Series firewall.

Star11
Fork10

Two tier application environment protected by VM-Series

Uses a Terraform template to deploy a two-tiered web server/DB application environment protected by a bootstrapped VM-Series firewall.

Palo Alto Networks Community Supported

Star16
Fork27

Private Cloud

Device Package for Cisco ACI

Device Package for Cisco ACI that integrates Palo Alto Networks Next-Generation Firewalls and Panorama centralized manager into the Cisco Application Centric Infrastructure for automated deployments of application-based network and security policy.

Palo Alto Networks Palo Alto Networks and Community Supported

VM-Series Heat Orchestration Templates

This is an OpenStack Heat Orchestration Template (HOT) repository to deploy and/or configure Palo Alto Networks VM-Series virtualized next-generation firewall in an OpenStack cloud. In this repository, there are sample templates that should be used as a reference and customized for your network security design.

Palo Alto Networks Palo Alto Networks and Community Supported

Star19
Fork10

All Cloud

Palo Alto Networks Ansible Modules

Ansible collection for easy automation of Palo Alto Networks next generation firewalls and Panorama, in both physical and virtual form factors.

Palo Alto Networks pan.dev Supported

Star214
Fork99

Palo Alto Networks PAN-OS Python

The PAN-OS SDK for Python is a package to help interact with Palo Alto Networks devices (including physical and virtualized Next-generation Firewalls and Panorama). The pan-os-python SDK is object oriented and mimics the traditional interaction with the device via the GUI or CLI/API.

Palo Alto Networks pan.dev Supported

Star353
Fork175

Provider for PAN-OS

Automates various configuration and policy aspects of the Palo Alto Networks physical or virtualized next generation firewalls and Panorama.

Palo Alto Networks pan.dev Supported

Palo Alto Networks Repository of Terraform Modules

Palo Alto Networks pan.dev Supported

Discussions

Author Topic Views Replies
01-15-2025

Welcome to the VM-Series in the Public Cloud Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be...

104 0
01-01-2025

Solved! Paloalto VM series ha into AWS cloud

Hi Experts, I need to update my firewall which is hosted into AWS. How can I make sure failover mode is secondary IP not interface move. I need ...

341 1
12-26-2024

Can VM-FW in Azure provide IPv6? Contains a hyperlink

Hello, I would like use VM-FW on Azure for IPv6?I looked at the following document. https://docs.paloaltonetworks.com/vm-series/11-1/vm-series-...

508 1
10-26-2024

Palo Alto VM series deployment in Azure Cloud

Hello Everyone, We are planning to deploy two VM series firewalls in our Azure landing zone. In our case, Palo Alto firewall is like a data c...

526 1
10-16-2024

PaloAlto integration with Azure GWLB Contains an attachment Contains a hyperlink

Hello!i'm trying to integrate 2 PaloAlto VMs with Azure GWLB. i found out this guide from PaloAlto: https://docs.paloaltonetworks.com/vm-series/11...

398 0
12-07-2024

Cloud PKI and Global Protect user authentication

Hi, We are trying to deploy the user authentication for Global Protect using Cloud pki Azure certificate. Anyone has deployed this successfully....

614 1
09-10-2024

Firewall deployed on Azure is showing MP constantly high Contains an image Contains a hyperlink

Hi Team,Please be informed that we have Palo Alto firewall deployed on Azure platform with below details.family: vmmodel: PA-VMvm-license: VM-SERIE...

880 1