VM-Series in the Public Cloud
The VM-Series is the virtualized form factor of the next-generation firewall. Use this discussion as a resource to discuss VM-Series deployments across public clouds like AWS, Microsoft Azure, Google Cloud Platform, Oracle Cloud, and Alibaba.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
VM-Series in the Public Cloud
The VM-Series is the virtualized form factor of the next-generation firewall. Use this discussion as a resource to discuss VM-Series deployments across public clouds like AWS, Microsoft Azure, Google Cloud Platform, Oracle Cloud, and Alibaba.
About VM-Series in the Public Cloud

Welcome to the VM-Series in the Public Cloud discussion forum! This community exists as a resource for you to discuss VM-Series deployments on AWS, Microsoft Azure, Google Cloud Platform, Oracle Cloud and Alibaba. We encourage you to engage in this rapidly growing community to share ideas, pose questions, and propose real-world solutions to any challenges that may arise.

Disclaimer:
This forum is provided for Live Community members to discuss and share information pertaining to the VM-Series deployments on AWS, Microsoft Azure, Google Cloud Platform Oracle Cloud and Alibaba. Please use the information from this forum at your own risk and make sure to test and verify proposed solutions presented here. For information on contacting Palo Alto Networks support, click here.

Discussions

Welcome to the VM-Series in the Public Cloud Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 3650 Views
  • 0 replies
  • 0 Likes

AWS VM Series Gateway Load Balancers not working

Hi AllHas anyone else had a play with the GWLB on AWS?I know it must be PAN-OS 10.0.2 or higher to work,I have tested with multiple instances, As a bump in the wire it works fine. until you apply NAT, then it doesn't work at all for any traffic that is NAT'd. I have an open TAC for this, they are replicating the fault to work it out but surely t...

Impossible to connect to panorama on Azure - Login prompt doesn't appear

Hello Everyone, How are you? I have a big problem with my panorama. Context: I have set up a Panorama on Azure ( FREE TRIAL ACCOUNT), I upgraded it from 8.1.0 to 9.0.4 and I added Prisma License and install cloud service plugin. Everything was great at this time no problem. I Stopped the VM on Azure during the night and when I have reboote...

2020-01-27 12_02_21Microsoft Teams.png
2020-01-27 11_25_02-52.225.192.199.png
2020-01-27 11_39_21-Login.png

Resolved! VM-100 on Azure doesn't load Tags on Dynamic Groups

Hi Community, we deployed a VM-100 on Azure with a lab license to play around with PAN-OS and to test some azure designs. We noticed, when creating a dynamic address group, the add section doesn't show any tags - but tags are existent are used on policies and objects. Even when writing the tag-filter manually, the address group won't show any ...

Schoen by L0 Member
  • 2568 Views
  • 2 replies
  • 0 Likes

Resolved! USER-ID policies + FULL azure ad

Hello everyone , I'm having a problem that I can't solve. I'll explain the context.I am in full AZURE AD.My computers are enrolled via INTUNE I would like to be able to set up user-based firewall rules.I set up the "cloud identity engine" (linked to azure ad), I can see my groups and my users in the palo alto.When I create a firewall rule and I ...

LCutman by L1 Bithead
  • 8260 Views
  • 8 replies
  • 0 Likes

Palo Alto active-active HA setup in MS Azure

Hello Team, Greetings, Does azure deployment support Palo Alto in active-active HA setup? documents in PA end refers only active-passive setup. Also is Panorama really require to deployed it as Active-Active in azure ? Please share your thoughts to deployed it as Active-Active in azure? Thank You Brajesh

Routing public websites via Palo in Azure?

I have a pair of VM-300 in a load balancer sandwich configuration in Azure. An internal load balancer is on the inside and handles outbound traffic. An external load balancer is on the outside and is intended for inbound traffic from internet. I can assign a public IP as the front end of the external load balancer. My first question - can a sin...

Site to Site VPN Unable to Ping Azure VM

Hello. I recently setup our Site to Site VPN to Azure and am having an issue with pinging to Azure from OnPrem. The tunnel shows connected and I can ping my on Prem devices from Azure without issue. I used this article to setup the connection: https://thetechl33t.com/2020/11/18/azure-site-to-site-vpn-with-palo-alto-firewall/ I setup the ...

How to secure outbound traffic from Azure?

This question might sound stupid but I'm banging my head against the wall trying to figure out how to make this work and I cannot find any documentation anywhere on this website that answers this (simple) question. I'm trying to setup a VM Series Palo Alto firewall in Azure, to secure outbound (not inbound) traffic from my Azure virtual machin...

Resolved! Active/active gateways in Azure and Panorama

I have two gateways in Azure operating as an active/active pair. They use the load balancer sandwich topology. I'd like to manage the pair from Panorama. Having a shared policy appears to be difficult. The two can share a security policy easily enough. But the rules in a NAT policy reference IP addresses specific to a firewall. Example; a sourc...

Backup settings for firewalls

Hi Guys, I have a few firewalls VM series e and they are in production. The virtual firewalls' configs are being backup by panorama. Since we have multiple admins (systems & networks & managers) who can access portal and are able to create/modify network settings are there ways to prevent people from modifying the production settings...

tinhnho by L3 Networker
  • 2163 Views
  • 2 replies
  • 0 Likes

Set Password via AWS bootstrap

The documentation seems (to me) to be unclear on how to set a password when bootstrap'ing the configuration. It seems to be that you simply need to set a valid bootstrap config and it should take, however that is not working. It seems to be that the config took (we are setting IP statically on mgmt port) but the password configuration is not wor...

Resolved! Arm template azure-different zone

Has anybody successfully deployed VM's in Azure for palo alto? I have used the template, but no matter what I can't seem to put a fw in zone 2. Any help is appreciated. I've changed around the code, but can't get this fw into a zone: "variables": { "apiVersion": "2015-06-15", "imagePublisher": "paloaltonetworks", "...

WPhinney by L1 Bithead
  • 2256 Views
  • 1 replies
  • 0 Likes

HA A/P on AZURE IP floating

Hello, i configured HA actif / passif on azure when the failovor occurs the floating IP still on the First Firewall, she not move for the seconf that he becomes Actif. - all permiissions are gived -configuration is a same to the Knowledge base -test plugin is passed in logs i see that and i dont know what that's mean : 2022-06-29 17:41:54....

IMADHA by L0 Member
  • 4938 Views
  • 4 replies
  • 0 Likes
  • 526 Posts
  • 107 Subscriptions
Labels