We deploy 2 VM-Series on Azure as recommanded by PA. These 2 FW manage Inbound/Outbound traffic and between our internals zones. A public load balancer have been configured. We need to connect our Azure infrastructure with our local datacenter via IPsec VPN between PA on Azure and firewall on our datacenter.
Do you know if it's possible to configure an IPsec tunnel between our FW in datacenter and our 2 VM-Serie on Azure to avoid lost communication between Azure and datacenter when one of PA reboots?
@jeromecarrier I do not see any issues on configuring the IPSEC tunnel between your DC and Azure PAs as at the end, it will be tunnel between your DC and the Palo Alto only. You just need to make sure about the reachability between the peers and the routing for the encryption domain.
In regard to your 2nd query, how are the both Palo Altos configured ? Are those in HA or Individual firewalls ?
Hi @jeromecarrier ,
Any particular reason you want to use the PA FWs in Azure as IPsec peers?
I would suggest you to use Azure native components - Azure VPN gateway. It is more simple and convenient instead of wondering how to handle firewall failover.
Depending on your Azure setup you may decide to pass this traffic over Azure PA FW, or not.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!