2 Palo Alto VM-Serie for IPsec VPN

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

2 Palo Alto VM-Serie for IPsec VPN

L3 Networker

Hello

 

We deploy 2 VM-Series on Azure as recommanded by PA. These 2 FW manage Inbound/Outbound traffic and between our internals zones. A public load balancer have been configured. We need to connect our Azure infrastructure with our local datacenter via IPsec VPN between PA on Azure and firewall on our datacenter.

 

Do you know if it's possible to configure an IPsec tunnel between our FW in datacenter and our 2 VM-Serie on Azure to avoid lost communication between Azure and datacenter  when one of PA reboots?

 

Regards

Jérôme

 

 

 

 

3 REPLIES 3

L6 Presenter

@jeromecarrier  I do not see any issues on configuring the IPSEC tunnel between your DC and Azure PAs as at the end, it will be tunnel between your DC and the Palo Alto only. You just need to make sure about the reachability between the peers and the routing for the encryption domain.

 

In regard to your 2nd query, how are the both Palo Altos configured ? Are those in HA or Individual firewalls ?

M

Check out my YouTube channel - https://www.youtube.com/@NetworkTalks

It's 2 individual firewall with azure LB in Frontend for inbound trafic to our internal Web servers. 

 

But for VPN Ipsec HA, I don't see how to configure my 2 FW to keep the communication between our servers in Azure and our local site when I have one FW unavailable...

 

BR

Hi @jeromecarrier ,

Any particular reason you want to use the PA FWs in Azure as IPsec peers?

I would suggest you to use Azure native components - Azure VPN gateway. It is more simple and convenient instead of wondering how to handle firewall failover.

 

Depending on your Azure setup you may decide to pass this traffic over Azure PA FW, or not.

  • 2404 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!