Deploying the Hyperscale Security Fabric (HSF) on KVM

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Community Blogs
2 min read
Community Team Member

Enterprise datacenters often face the challenging task of predicting network security capacity due to shifting cloud migration strategies and fluctuating on-premise growth. Palo Alto Networks Hyperscale Security Fabric (HSF) addresses this uncertainty by delivering an active-active, software firewall clustering solution that seamlessly scales on-premise datacenter protection from 1 Gbps up to 200 Gbps.

 

If you are evaluating or planning a Proof of Concept (POC) for HSF in a Linux KVM environment, we have released a comprehensive HSF POC QuickStart Guide for KVM to streamline your deployment.

 

Because KVM deployments rely on Terraform templates generated from Strata Cloud Manager (SCM) rather than a Panorama orchestration plugin, having a clear baseline architecture is critical.

 

What’s Inside the Attachment:

 

  • Architectural Overview: Deep dive into how HSF leverages Persistent Nodes (P-Nodes) and Scale Nodes (S-Nodes) to separate load balancing and firewall compute.
  • Pre-Deployment & Sizing Checklists: Minimum vCPU/RAM allocations, mandatory BIOS configurations (Hyper-Threading, C-States, P-States), and kernel isolation constraints.
  • Step-by-Step Orchestration Workflow: Complete walkthrough covering KVM host network preparation (OVS bridges, SR-IOV Virtual Functions), Panorama baseline configurations, and SCM Terraform template execution.
  • Functional Test Cases: Detailed validation steps for testing East-West traffic flows, session resiliency node failures, and AI-Runtime threat block scenarios.
  • Day-2 Lifecycle Operations: Manual methods for horizontal scaling (scale-out/scale-in) and mandatory CLI routines for cluster updates.
  • Advanced Troubleshooting Matrix: A comprehensive command reference for diagnosing node isolation ("Unknown" state), corosync leader election instability, and configuration sync mismatches.

 

Download the attached document below to access the complete technical deployment blueprint, configuration templates, and operational validation commands.

  • 19 Views
  • 0 comments
  • 0 Likes
Labels
Contributors