AWS ALB/ALB Sandwich - Active/Active vm-series (9.0.5)

Showing results for 
Show  only  | Search instead for 
Did you mean: 

AWS ALB/ALB Sandwich - Active/Active vm-series (9.0.5)

L1 Bithead

External ALB -> VM-series 300 -> Internal ALB -> server (listening on tcp/15000)

Having issues routing from external ALB to the server over port 15000 ?


Added listener port http:15000 on the ALB and forwarded it to the target group containing the firewall

Created destination NAT (untrusted to untrusted) on the firewall with source address translation (comes out of the trusted)

Created a policy to pass any traffic to the internal load balancer

Added a listener port http:15000 on the internal ALB to forward to the server.

no blocks on the security groups


Still having issues connecting 




L4 Transporter


In reviewing this and your other post which seems to be somewhat related, I would encourage you to engage your Palo Alto Networks SE.  We have resources that can assist with straightening this out.  Your external ALB should have a listener on the proper app port such as 443 and the target group mapping is port 15000 which the firewall is listening on.  The NAT rule on the firewall will then have original source port of 15000 and a destination NAT of the internal ALB listener.

Ok thanks. I have opened a case with palo alto. 

  • 2 replies
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!