- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
Enhanced Security Measures in Place: To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.
11-29-2022 01:35 PM
Hello
We deploy 2 VM-Series on Azure as recommanded by PA. These 2 FW manage Inbound/Outbound traffic and between our internals zones. A public load balancer have been configured. We need to connect our Azure infrastructure with our local datacenter via IPsec VPN between PA on Azure and firewall on our datacenter.
Do you know if it's possible to configure an IPsec tunnel between our FW in datacenter and our 2 VM-Serie on Azure to avoid lost communication between Azure and datacenter when one of PA reboots?
Regards
Jérôme
11-30-2022 04:24 AM
@jeromecarrier I do not see any issues on configuring the IPSEC tunnel between your DC and Azure PAs as at the end, it will be tunnel between your DC and the Palo Alto only. You just need to make sure about the reachability between the peers and the routing for the encryption domain.
In regard to your 2nd query, how are the both Palo Altos configured ? Are those in HA or Individual firewalls ?
12-03-2022 04:59 AM
It's 2 individual firewall with azure LB in Frontend for inbound trafic to our internal Web servers.
But for VPN Ipsec HA, I don't see how to configure my 2 FW to keep the communication between our servers in Azure and our local site when I have one FW unavailable...
BR
12-03-2022 09:43 AM
Hi @jeromecarrier ,
Any particular reason you want to use the PA FWs in Azure as IPsec peers?
I would suggest you to use Azure native components - Azure VPN gateway. It is more simple and convenient instead of wondering how to handle firewall failover.
Depending on your Azure setup you may decide to pass this traffic over Azure PA FW, or not.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!