- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
Organizations are increasingly embracing cloud environments for their flexibility, scalability, and cost-effectiveness. However, securing and optimizing connectivity across these distributed locations can be a challenge. This is where Palo Alto Networks® (PAN) OS SD- WAN with VM-Series firewalls deployed on Oracle Cloud Infrastructure (OCI) comes in.
This document describes different deployment options which can be used to connect an on- prem branch/datacenter to a cloud environment, and connectivity between multi cloud infrastructure.
The SD-WAN plugin is integrated with PAN-OS, so that you get the security features of a PAN- OS firewall and SD-WAN functionality from a single vendor.
The SD-WAN overlay supports dynamic, intelligent path selection based on applications and services and the conditions of links that each application or service is allowed to use. The path health monitoring for each link includes latency, jitter, and packet loss.
Granular application and service controls allow you to prioritize applications based on whether the application is mission-critical, latency-sensitive, or meets certain health criteria, for example.
Dynamic path selection avoids brownout and node failure problems because sessions fail over to a better performing path in less than one second.
PANOS SD-WAN is a software solution that delivers intelligent path selection, application-aware routing, and dynamic orchestration for WAN connections. It empowers you to:
The Palo Alto VM-Series firewall is a next-generation security solution available as a virtual appliance. Deploying VM-Series on OCI offers several advantages:
Scalability: Easily scale your security resources up or down to meet your changing needs.
Cost-effectiveness: Pay only for the resources you use, reducing upfront costs.
High availability: Leverage OCI's robust infrastructure for increased uptime and redundancy.
Seamless integration: VM-Series integrates seamlessly with other OCI services like Virtual Cloud Networks (VCNs) and Flexible Network Load Balancers.
Deploying VM-Series on OCI can be achieved through the OCI Console or by leveraging Infrastructure as Code (IaC) tools like Terraform.
Above architecture shows, two PA-VM in HA acting as a HUB over OCI Platform and one Branch VM deployed on-prem.
We have created SDWAN tunnels between Hub-Spoke Firewall to achieve resiliency, scalable and secure channel to communicate.
For detailed instructions, refer to the Palo Alto Networks documentation: VM-Series Deployment Guide.
While not all PANOS SD-WAN features are supported on VM-Series, key functionalities like:
PANOS SD-WAN with Palo Alto Networks VM-Series on OCI provides a powerful and secure solution for optimizing and protecting your cloud connectivity. This combination delivers the scalability, cost-efficiency, and security needed for organizations of all sizes to thrive in today's dynamic cloud environment.
Palo Alto Networks VM-Series on OCI Documentation: Link
VM-Series Deployment Guide: Link
How VM-Series Integrates with OCI Flexible Network Load Balancer: Link
System Requirement for SDWAN: Link
Set-up Panorama & Firewall for SDWAN: Link
Troubleshoot App Performance
Troubleshoot Link Performance
Upgrading SD-WAN Firewalls
Upgrading SD-WAN Plugin
Uninstalling SD-WAN Plugin
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Subject | Likes |
---|---|
5 Likes | |
2 Likes | |
2 Likes | |
2 Likes | |
1 Like |