VM-Series in the Public Cloud
The VM-Series is the virtualized form factor of the next-generation firewall. Use this discussion as a resource to discuss VM-Series deployments across public clouds like AWS, Microsoft Azure, Google Cloud Platform, Oracle Cloud, and Alibaba.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
VM-Series in the Public Cloud
The VM-Series is the virtualized form factor of the next-generation firewall. Use this discussion as a resource to discuss VM-Series deployments across public clouds like AWS, Microsoft Azure, Google Cloud Platform, Oracle Cloud, and Alibaba.
About VM-Series in the Public Cloud

Welcome to the VM-Series in the Public Cloud discussion forum! This community exists as a resource for you to discuss VM-Series deployments on AWS, Microsoft Azure, Google Cloud Platform, Oracle Cloud and Alibaba. We encourage you to engage in this rapidly growing community to share ideas, pose questions, and propose real-world solutions to any challenges that may arise.

Disclaimer:
This forum is provided for Live Community members to discuss and share information pertaining to the VM-Series deployments on AWS, Microsoft Azure, Google Cloud Platform Oracle Cloud and Alibaba. Please use the information from this forum at your own risk and make sure to test and verify proposed solutions presented here. For information on contacting Palo Alto Networks support, click here.

Discussions

Welcome to the VM-Series in the Public Cloud Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 3673 Views
  • 0 replies
  • 0 Likes

Splunk and Palo Alto Networks Integration in AWS: Log Data Discrepancies

Hello, Recently, in our organization, we undertook the task of integrating Splunk with our existing Palo Alto Networks infrastructure within our AWS environment. The integration process was fairly smooth, and we were eager to begin monitoring and analyzing our network logs using Splunk's capabilities. However, as we started to deep dive into t...

How to configure ingress to Azure Load Balancers with PaloAlto-secured network

Hi, I am looking to deploy external load public load balancer for controlling ingress traffic from Internet to Palo Alto VM-series deployed as active/active behind this load balancer. What will be the configurations on external load balancer and how will the NAT configurations if I am exposing application sitting behin my internal load balancer....

BilalMohd_0-1692814047644.png

VM-100 model cannot download software.

Hi, Recently, two VM-100s in my operating environment have encountered the problem of not being able to download software through the GUI.The situation I encountered is that the download speed is very slow, and then the result will fail.Other external updates of the firewall, such as app-id update and clicking "check now" to check the software v...

DevonFan by L1 Bithead
  • 2363 Views
  • 1 replies
  • 0 Likes

AWS GWLB integration with Palo VM and PBF to tunnel interface

AWS Palo VM can integrate fine with AWS GWLB. It can receive GENEVE packet on eth0 and overlay route to untrust interface to reach internet. when we try to steer the 80 and 443 traffic to a tunnel on that Palo VM for proxy inspection, our packets are not leaving tunnel interface on the firewall. TAC found its a bug . Does any one able to ac...

Can I make a security rule with XFF IP in source address?

Hi Community, I already set XFF configuration via guide documents. So I can look at XFF IP in Traffic logs and URL Logs. I would like to make a security rule to allow only A.B.C.D XFF IP in source address. Unfortunately, I don't know how to set it. And there isn't any document detailed. Can you help me to fix it? Thanks in advance.

Palo Alto On AWS - Ipsec VPN IPSEC Site to Site connection - NAT-T - IP Mapping

Hello Live Community, how's it going, I hope it's going well. One question, I have the following doubt. Soon I have to generate a Site to Site VPN connection, between a Palo Alto On-prem and another Palo Alto that is in AWS. I understand that the Palo Alto on the AWS side, the Palo Alto does not have a direct public IP on the interface, ther...

Metgatz by L4 Transporter
  • 4948 Views
  • 1 replies
  • 0 Likes

PANOS upgrade VM-100 over KVM Virtual environment

This is the our internet firewall hosted by our ISP in the cloud. I am currently in PANOS Version 8.1.3 on PA-VM-100. The VM mode is KVM. And now they have the new PANOS version 9.0.0, when I tried to download, it reaches half way and fails with: Failed to download due to generic communication error. Please try again later.Does anybody has solu...

AWS PA, error on SSL forward decrypt

Dear all I am trying to configure SSL inspection on a Palo Alto in AWS. Despite the configuration with client certificate and device CA and SubCA is (as far as I can verify) the same as the one on the on-premises environment, I still get errors like. Received a fatal warning CertificateUnknown from the client. Received a fatal warning UnknownCA ...

Hosting a private python package manager in Azure or AWS

I work in a small team of Python developers and our aim is to create a private package manager to store our packages. I came cross pypicloud and following its tutorial I've successfully been able to upload and install packages stored in AWS-S3. That's fantastic.However, the private package manager is launched and hosted locally typing pserve ser...

leviya by L0 Member
  • 4485 Views
  • 3 replies
  • 1 Likes

Errors pushing template to firewall -can't find interface in 'vr-private-trust' for next hop - - New Build

Im having a hard time figuring this out, the interafces exist in the template, also exist in the vmseries firewalls themselves and I confirgured them to L3 on the firewalls... 2023-07-12 11:38:39.903 -0500 Error: pan_conn_mgr_callback_expiry_async(cs_conn.c:8788): connmgr: Expired Request. entry:1024, msgno=0 devid=007957000386926-log-collec...

Palo Alto VM series on Microsoft Azure with a Azure load balancer failover?

As the Azure failover based on the plugin is much slower than the same failover in AWS as the Azure API is much slower I am wondering if I can use floating IP address and azure load balancer infront of it? I have done the same for F5 BIG-IP devices and I know that the Azure Load balancer main pool can be the virtual machine local private ip ad...

  • 530 Posts
  • 107 Subscriptions
Labels