VM-Series in the Public Cloud
The VM-Series is the virtualized form factor of the next-generation firewall. Use this discussion as a resource to discuss VM-Series deployments across public clouds like AWS, Microsoft Azure, Google Cloud Platform, Oracle Cloud, and Alibaba.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
VM-Series in the Public Cloud
The VM-Series is the virtualized form factor of the next-generation firewall. Use this discussion as a resource to discuss VM-Series deployments across public clouds like AWS, Microsoft Azure, Google Cloud Platform, Oracle Cloud, and Alibaba.
About VM-Series in the Public Cloud

Welcome to the VM-Series in the Public Cloud discussion forum! This community exists as a resource for you to discuss VM-Series deployments on AWS, Microsoft Azure, Google Cloud Platform, Oracle Cloud and Alibaba. We encourage you to engage in this rapidly growing community to share ideas, pose questions, and propose real-world solutions to any challenges that may arise.

Disclaimer:
This forum is provided for Live Community members to discuss and share information pertaining to the VM-Series deployments on AWS, Microsoft Azure, Google Cloud Platform Oracle Cloud and Alibaba. Please use the information from this forum at your own risk and make sure to test and verify proposed solutions presented here. For information on contacting Palo Alto Networks support, click here.

Discussions

Welcome to the VM-Series in the Public Cloud Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 3527 Views
  • 0 replies
  • 0 Likes

VM-Series on - Sizing, Internet traffic, Scalability Considerations

Dear Members, Hope you are doing well. We need your support for VM-series FW setup on Azure and considerations. We are planning to use 2 VM series in internet facing traffic and 2 VM series for internal traffic management. When deploying these VMs what points we need to keep in mind so that we can expand these in the future based on the tr...

N-Open by L1 Bithead
  • 1291 Views
  • 1 replies
  • 0 Likes

How to take VM series BYOL trial License?

Hello experts! I want to take a trial license for BYOL for the VM series next-generation firewall in Azure. Can you please let me know if we can have a trial license from Support? My second question is, can you provide me the link from where I can contact support for BYOL license purchasing? Thanks! Nidhi

Issues with Overlay Routing and AWS Gateway Load Balancer

Hey Folks, I am having difficulties to get Overlay routing working with AWS GWLB and I was wondering is it something that I am doing wrong or missing some configuration element... Any of you using AWS GWLB with overlay routing enabled? In my test setup when overlay routing is enabled the test VM is able to reach internet over the PAN FW - ...

SSL Forward Proxy Configuration Question

Trying to get SSL Forward Proxy configured for one of my sites and had a quick question around the configuration. For the certificate I need to put the IP address for the trust side of open flame-grilled. The problem is I am not sure which Interface IP address to use validation code... MYBKExperience All of my internal subnets and VLANs have int...

Rekey causes VPN tunnel to stop sending network traffic

Hello everybody, I'm having a weird issue with VPNs between a Palo Alto Cloud Firewall (PanOS9.1.3h) and Cisco Meraki Z3.All VPN Tunnels are established propely, but after a random period of time during the rekey step, a tunnel stays online, but network traffic can't be send anymore. We are currently having 5 of these connections with the same i...

PA VM-Series syslog ingest log to Azure log analytic workspace

Hi all, May i know if anyone had experience setting up VM Series FW to ingest the syslog to Azure log analytic? Is it the only is to setup a new intermediate syslog server install with Azure AMA, the VM series will send syslog to the new syslog server and AMA will ingest the log to log analytic ? Thanks for the help 🙂 Thank you, Meng Kiat

How to correlate AMI IDs and/or ProductCodeID with Palo Alto Bundles

Trying to figure out the ProductCodeID for each Palo Alto AMI on AWS Marketplace. On AWS, there are four of these: e9yfvyj3uag5uo5j2hjikv74n, a23dm9js55dw4ey8bzjcoq59u, 6njl1pau431dv1qxipg63mvah, hd44w1chf26uv4p52cdynb2o. On AWS GovCloud, there are six of these: e9yfvyj3uag5uo5j2hjikv74n, ds9pzkfhyprkziz6md6p6zry9, hd44w1chf26uv4p52cdynb2o, eyvc...

badnewty by L0 Member
  • 1076 Views
  • 0 replies
  • 0 Likes

Resolved! AWS NAT not coming back

Hello,I tried to setup the nat, I can see my NAT and Security rule are being hit, but traffic is not flowing Bundle 1Interface Swap (tested this with no swap too, and it didn;t work)All of the 3 interfaces disabled src destinationall of them same sg, 0.0.0.0./0eth0 and eth1 are on the same subnet (public) with a route 0.0.0.0/0 to igweth0 and et...

Screen Shot 2019-11-13 at 10.03.52 PM.png
Screen Shot 2019-11-13 at 10.13.30 PM.png
Screen Shot 2019-11-13 at 10.23.49 PM.png
nronica by L1 Bithead
  • 11201 Views
  • 7 replies
  • 0 Likes

SSL Forward Proxy for custom url with host and path

SSL decrytion works if i set custom url with host only like www.example.local, but failed to decrypt if i set it as 'www.example.local/image/' i found article below, it should support custom url with host+path, but now i suspect will pan really support host+path decrption https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g0000...

Active FTP in AWS

I'm looking for some assistance on this issue whilst I progress a support case. Has anyone managed to get Active FTP working through a Palo VM-Series in AWS. I am getting a problem whereby the control connection outbound on port 21 is successful (you can login to the FTP servers) but the pinhole/predictive session for the ftp data connection b...

Expanding a PANOS Firewall VM log file on KVM

There's plenty of discussions here and a couple of KB articles on adding disks to PAN VMs for extra logging space, but the only articles around for extending/increasing the size of the logging disk say to delete it and add a new one in its place. Downside to that is that you lose the logs that were on the disk at the time. I raised this with TAC...

Site-to-Site IPSEC between AWS and Azure (VM-Series)

I am trying to setup an IPSEC Site-to-Site VPN between our azure and aws environment, both of which have VM-300 series fw's running. I am able to get the tunnel up and see traffic coming across the link, but when i try and reach a resource on either end via PING/TRACE etc.. there is no response. I see the requests for the traffic in the PA going...

sscarola by L0 Member
  • 1862 Views
  • 1 replies
  • 0 Likes

Resolved! Equivalent of VLAN within Azure..

Probably one of the most simple questions going, but coming from a large on prem environment, I'm trying to understand how its meant to look from an AzurePOV.Typically, when we have a new server in say a /29 , i create a new sub interface for that vlan on the firewall, add a zone to it etc and crack on.Am i right in thinking that the "azure" way...

Downgrade from VM-300 to VM-100 on AWS (PAYG)

I have changed the instance type on my ec2 running PA-VM 10.2.4 from c5.2xlarge to c5.xlarged. As I know the VM license will be changed from VM-300 to VM-100 as well. After I changed, the VM License value on the dashboard was blank and the license was still VM-300. PS. I'm using a license from AWS Marketplace.

Tutchapon_0-1698655182444.png
Tutchapon_1-1698655383883.png
  • 709 Posts
  • 107 Subscriptions
Top Solution Authors
Top Liked Authors
Labels