Use onprem hosted EDL from AWS CNGFW

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Use onprem hosted EDL from AWS CNGFW

L4 Transporter

Is it somehow possible to load an EDL from a server located in onprem network (not reachable from Internet)? From which interface / IP address does the AWS CNGFW tries to connect to EDL server? Can it make connection from an interface / IP address located in customer VPC? Could not find any documentation for this specific topic.

7 REPLIES 7

Cyber Elite

Why don't you just test it and see if it can?

 

Is your setup Centralized deployment in Security VPC Cloud NGFW for AWS Centralized Deployments ?

L4 Transporter

Actually tested it and confirmed by Palo Alto account engineer:

CNGFW AWS does not support EDL loading from customer network. All EDLs must be hosted in public reachable Internet.

CNGFW Azure supports usage of loopback IP in customer VNET for connection to EDL host

 

What about having Panorama to manage the cloud WAF and have the panorama as a VM on-prem as to fetch the EDL to and a VPN tunnel between on-prem and AWS to be able to push the EDL?

 

You can then connect it to Strata Cloud Manager Panorama CloudConnector Plugin as to have policies in a single place as Panorama is just the middle man in this case.

L4 Transporter

We actually used Panorama plugin to manage CNGFW (both AWS and Azure), but for the EDL download it does not matter as this connection is made from the firewall device itself to configured edl host. In case of AWS, only public reachable edl hosts can be used. For Azure, the edl connection can use service connection via vnet interface (this is not possible in AWS).

Maybe then you can limit access on the on-prem fw based on the source IP address (Elastic IP.) that the cloud NGFW in AWS will use to connect to your on-prem server? This way nothing else will will be allowed to reach the on prem feed server. You just need DNS record to a public on-prem ip address probably on a firewall or even router with ACL capabilities.

 

LIVEcommunity - New Deployment Model: Integrating Cloud NGFW for AWS with Regional NAT Gateway - LIV...

 

Maybe this limitation comes as the AWS Cloud NGFW is from what I researched  based on AWS Gateway Load Balancer setup while the azure cloud NGFW is based on internal and external Azure LB and Palo Alto VM instances between them. Who knows.

L4 Transporter

Of course there would be options to make onprem EDL host reachable over internet and limit it somehow. But in the end we decided to use self managed VM series anyway. CNGFW had too many limitations and management sacrifices for us.

Outside of that in the future if you still go with AWS cloud NGFW the REST-API can be a nice option Create a PrefixList | Develop with Palo Alto Networks

  • 1889 Views
  • 7 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!