Today, Palo Alto Networks is excited to announce support for EC2 Auto Scaling Warm Pools . Warm Pools can reduce the in-service time for VM-Series firewalls by up to 80 percent by staging instances in a stopped state after the bootstrapping process. When an Auto Scaling action triggers a scaling event, the warmed instance is simply started from the already staged warm state. This staging is made possible by adding new lifecycle actions to trigger automation which validates the readiness of an instance.
Here’s why this is important: For more than four years, Palo Alto Networks customers have been using VM-Series Next Generation Firewalls (NGFWs) with Amazon's EC2 Auto Scaling to create scalable and robust network security on AWS. Auto Scaling in AWS solves three major challenges:
Right-sizing capacity based on demand
Resiliency across Availability Zones
Self-healing unhealthy instances
Enhancing VM-Series Auto Scaling in AWS
While VM-Series and EC2 Auto Scale provide several benefits for our customers, there is still some unavoidable latency with the VM-Series NGFW bootstrap process. As an Auto Scaling Group begins to scale out new EC2 instances running PAN-OS, the initial boot process of the new instance(s) can take several minutes. Many customers have historically worked around this by over-provisioning NGFW instances on AWS; however, this leads to increased costs and wasted compute.
Key benefits of Warm Pools:
Reduces EC2 cost by keeping the warmed instance in a stopped state. Cost is reduced to just the EBS storage cost.
Dramatically reduces the time necessary for a firewall to become available to the load balance.
Provides dedicated lifecycle actions which can occur when an instance is built or moved from warm to running, including integrations with Amazon EventBridge and Amazon CloudWatch.
Figure 1: Lifecycle Hook Flow Diagram
Figure 1: Lifecycle Hook Flow Diagram
Licensing Considerations
Warms Pools works with both PayGo and our flexible consumption licensing model . When utilizing PayGo, no additional costs are incurred, as the firewall will not incur EC2 usage charges. Additional licenses will be consumed by the stopped firewalls when utilizing BYOL/FW-Flex.
To learn more, we encourage you to follow these links:
EC2 Auto Scaling Warm Pools
VM-Series in AWS Marketplace
GitHub repository with sample VM-Series configuration for Warm Pools
VM-Series with Gateway Load Balancer
Palo Alto Networks VM-Series Reference Architecture for AWS
Learn more about VM-Series
... View more