Second VMSeries on Azure in the same Resource group/VNET
Any one knows, How to deploy a second VMseries on the same Resource group/VNET?
Welcome to the VM-Series in the Public Cloud discussion forum! This community exists as a resource for you to discuss VM-Series deployments on AWS, Microsoft Azure, Google Cloud Platform, Oracle Cloud and Alibaba. We encourage you to engage in this rapidly growing community to share ideas, pose questions, and propose real-world solutions to any challenges that may arise.
Disclaimer:
This forum is provided for Live Community members to discuss and share information pertaining to the VM-Series deployments on AWS, Microsoft Azure, Google Cloud Platform Oracle Cloud and Alibaba. Please use the information from this forum at your own risk and make sure to test and verify proposed solutions presented here. For information on contacting Palo Alto Networks support, click here.
Any one knows, How to deploy a second VMseries on the same Resource group/VNET?
Hello.
I have built a simple sandwich structure test environment on GCP Cloud.
ALB
↙ ↘
FW1 FW2
↘ ↙
NLB
↙ ↘
SV1 SV2
However, in the PAN traffic log, XFF IP is only the IP of the upper ALB.
GCP's official documentation confirmed that the XFF h
...
Good Day,
Does azure deployment support PA in active-active HA setup? documents in PA end refers only active-passive setup. Has anyone deployed it as A-A in azure?
any pointers will be helpful.
Hi all,
I've setup 2 VM series in HA in Azure for north-south traffic and it works well with the floating IP moving after a few minutes during failover.
We want to add east west traffic flows with extra zones.
Does the extra zones require the same
...
Hi,
We have a pair of Panorama devices for managing couple of pairs of Firewalls ( in HA ) all in Azure. We have scheduled the config export which is scheduled everyday to store the config backups of Panorama+Firewalls in a server.
If there were a
...
Tested traffic within a same VPC it's working fine, use ENI of paloalto's LAN interface as a target
But I have no idea, when we have 2 VPC (VPC-A and VPC-B) and we installed paloalto on VPC-A
How to direct traffic from VPC-B to paloalto and then ac
...
Hello Community,
We need to upgrade from perpetual licenses to credit licenses, currently the firewall is in PAN OS version 9.1.14, according to the Palo Alto documentation the minimum version of PAN OS for credits license is 10.0.4. Is it necessary u
Hi All,
We have a requirement to do a static NAT on our Palo Alto firewalls hosted in Microsoft Azure Public Cloud.
Need suggestions if it is possible to do it or not, Below is the exact requirement.
Requirement:
Hello Everyone,
We have deployed Two PA-VM in GCP.
In GCP we have created External HTTP Load Balance (ELB) & Internal Load Balance.
Via external load balance we want to public application, for which we created NAT Rule & Security Policy.
Unable t
...
From what i can tell this is normal but would like to validate that this is correct. The speed and duplex show ukn/ukn.. I believe this is okay as the vswitch determines those things and we wont have any bandwidth issues going above 1G or anything. t
...
I am trying to boot and auto-attach a VM series FW to Panorama in AWS. I am specifying the user-data as follows:
type=dhcp-client
hostname=aws-palo-1
panorama-server=a.b.c.d
tplname=lz-firewall
dgname=lz-firewall
dns-primary=8.8.8.8
dns-secondary=8.8.4.4
Dear and valuable Live Community Members,
One of our customers came to us with some questions about Azure Bootstrap Package, but I couldn't find the requested information for that.
We've checked the article where the steps to create new firewalls i
...
If I have an Azure Gateway Load Balancer set up with my NGFWs (Interface eth1/1), do I have to use a separate interface for traffic originating inside Azure to point to? I would assume yes since GWLB technically uses vxlan and so I'd need a separate
...
Hello Community,
I want to deploy Palo Alto VM Series firewall Infront of some workloads already existing on my Azure tenant and still ensure that services calling the workloads use the existing public IP Addresses assigned to these workloads when
...
Upgrading a VM-series firewall requires an API key to be configured on the firewall. Please enable this configuration and try again.
May i know what problem? thanks