Terraform - Automate and Secure Cloud Applications with Palo Alto Networks Next-Gen Firewall

About Terraform

Terraform is a powerful open source tool that is used to build and deploy infrastructure safely and efficiently. The advantage of Terraform is that it is cloud platform agnostic (unlike AWS CFT’s or Azure ARM templates), provides for the definition of infrastructure as code, and produces immutable infrastructure deployments. The Palo Alto Networks Terraform automation project offers Terraform templates to assist in deploying agile infrastructures based on the Palo Alto Networks next generation firewalls in the cloud.

Note: This is a community supported project. Please do not contact the Palo Alto Networks support team, as they will only direct you here for assistance. We encourage you to post your topics and questions in the discussion forums. Thank you!

Terraform Blogs

Terraform Provider Version 1.6.0 Released

post time: 08-30-2019

The 1.6.0 release contains support for aggregate interfaces, subinterfaces, VLANs, policy based forwarding rules, multiple profile types, and the Google Cloud Platform (GCP) Panorama plugin.

Terraform Provider Version 1.5.0 Released

post time: 02-04-2019

The 1.5.0 release contains support for BGP, BFD profiles, an enhanced NAT rule resource, and various user requested enhancements.

Terraform Provider Version 1.4.0 Released

post time: 08-27-2018

The 1.4.0 release includes expanded support for Panorama (such as ethernet interfaces, templates, and template variables), IPSec tunnels, IKE gateways, firewall licensing, and much more.

Terraform Provider Version 1.2.0 Released

post time: 06-19-2018

The 1.2.0 release includes support for security policy groups, PAN-OS 8.1's FQDN destination address translations, and telemetry sharing with Palo Alto Networks.

Terraform Provider Version 1.1.0 Released

post time: 05-01-2018

The 1.1.0 release includes Panorama support, an alternative method for specifying device credentials, and many new resources.



Have questions about how to utilize Terraform to automate your Palo Alto Networks deployments? Join the Live Community to post your questions and get answers.
Author Topic Views Replies
posted: 3 hours ago updated: 2 hours ago

Changing Metric of Static Route using API

All, trying to send a command via the API to change the metric value of a static route, this is because occassionally my primary connection is extreme...

51 1
posted: Thursday updated: yesterday

Unable to add static route using Ansible module panos_static_route

Hello Experts, I am trying to add a static route in a PAN FW using the Palo Alto module panos_static_route. Here is the variable file: ...

190 3
posted: Tuesday updated: Tuesday

When I use the API to pull the device-state - am I getting the latest ?

In another article here, from 2014 (precambrian issues) - they broke down some of the insides of the device state config backup.One of the commands li...

150 0
posted: Monday updated: Monday

Traffic log query using curl and retrieval

Hi Team, I presume pan devices allow API requests for traffic query using curl. Attempted following query using curl with no success. Got a promp...

98 0
posted: a week ago updated: a week ago

Module for puppet/ chef for updating HIP opjects?

Hi, has anyone came across modules as such? I basically wanted to remove certain patch version number (eg MS KB number) from the current HIP object an...

124 0