VM-Series in the Public Cloud
The VM-Series is the virtualized form factor of the next-generation firewall. Use this discussion as a resource to discuss VM-Series deployments across public clouds like AWS, Microsoft Azure, Google Cloud Platform, Oracle Cloud, and Alibaba.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
VM-Series in the Public Cloud
The VM-Series is the virtualized form factor of the next-generation firewall. Use this discussion as a resource to discuss VM-Series deployments across public clouds like AWS, Microsoft Azure, Google Cloud Platform, Oracle Cloud, and Alibaba.
About VM-Series in the Public Cloud

Welcome to the VM-Series in the Public Cloud discussion forum! This community exists as a resource for you to discuss VM-Series deployments on AWS, Microsoft Azure, Google Cloud Platform, Oracle Cloud and Alibaba. We encourage you to engage in this rapidly growing community to share ideas, pose questions, and propose real-world solutions to any challenges that may arise.

Disclaimer:
This forum is provided for Live Community members to discuss and share information pertaining to the VM-Series deployments on AWS, Microsoft Azure, Google Cloud Platform Oracle Cloud and Alibaba. Please use the information from this forum at your own risk and make sure to test and verify proposed solutions presented here. For information on contacting Palo Alto Networks support, click here.

Discussions

Welcome to the VM-Series in the Public Cloud Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by • Community Team Member
  • 3695 Views
  • 0 replies
  • 0 Likes

Resolved! API keys for Autoscale with GWLB deployment

We are attempting to deploy Cloud Formation Templates to create the autoscaling groups and firewalls but there are some steps around API keys that are confusing. From the pictures seen below, we are being asked for API keys for the panorama, and for the firewalls, and then the csp lisence key. My confusion points are as follows: 1. For the fir...

Verac22_1-1677589320646.png
Verac22_0-1677589313584.png
Verac22 by • L2 Linker
  • 2724 Views
  • 1 replies
  • 0 Likes

Azure internal load balancer and VM firewalls not working

We are attempting to internal load balance a pair of VM firewalls in Azure. The firewalls work when traffic is sent directly to the firewalls. But when the Azure internal load balancer is added into the mix no traffic hits the firewall. I have searched all over the Palo web sites, the live community and Internet, but have not found instructions...

Joel_W by • L1 Bithead
  • 7687 Views
  • 3 replies
  • 0 Likes

Monitoring of external ip configured for vpn in Palo Alto vm firewalls deployed in Azure

Hi All, We have 2 Palo Alto VM firewalls (A: Primary & B: Secondary) deployed in Active/Passive mode for high-availability. These firewalls are deployed in Azure cloud and have multiple site to site IPSEC VPN tunnels configured with multiple vendors. Recently, we faced an issue when we were performing PAN OS upgrade on both the firewalls. ...

BilalM by • L1 Bithead
  • 3410 Views
  • 4 replies
  • 0 Likes

Resolved! PAN-VM x-forwarded-for feature question in gcp cloud

Hello.I have built a simple sandwich structure test environment on GCP Cloud. ALB ↙ ↘FW1 FW2 ↘ ↙ NLB ↙ ↘SV1 SV2 However, in the PAN traffic log, XFF IP is only the IP of the upper ALB.GCP's official documentation confirmed that the XFF header contains both the client IP and the LB IP.I actually did a packet capture from the PAN, bot...

ttak87_0-1627279983422.png
ttak87_1-1627280162423.png
ttak87_2-1627280344002.png
ttak87 by • L1 Bithead
  • 11234 Views
  • 9 replies
  • 0 Likes

Resolved! How to schedule a backup of the Device State for VM-Series Firewalls ( managed by Panorama ) Azure.

Hi, We have a pair of Panorama devices for managing couple of pairs of Firewalls ( in HA ) all in Azure. We have scheduled the config export which is scheduled everyday to store the config backups of Panorama+Firewalls in a server. If there were a scenario ( I know its very unlikely on Azure since there are Availabilty Zones configured ) but i...

Resolved! Upgrade VM-series license

Hello Community,We need to upgrade from perpetual licenses to credit licenses, currently the firewall is in PAN OS version 9.1.14, according to the Palo Alto documentation the minimum version of PAN OS for credits license is 10.0.4. Is it necessary upgrade PAN OS version before upgrade the license?

NG25_1 by • L0 Member
  • 2851 Views
  • 1 replies
  • 0 Likes

Static NAT configuration on PA VMs hosted in Microsoft Azure

Hi All, We have a requirement to do a static NAT on our Palo Alto firewalls hosted in Microsoft Azure Public Cloud. Need suggestions if it is possible to do it or not, Below is the exact requirement. Requirement:We have a requirement to host an SAP router on SAP subscription. SAP router will receive incoming traffic from SAP vendor on TCP port ...

AWS VM-Series GWLB - Interface Unknown

From what i can tell this is normal but would like to validate that this is correct. The speed and duplex show ukn/ukn.. I believe this is okay as the vswitch determines those things and we wont have any bandwidth issues going above 1G or anything. they are on C5.9xlarge instances. The ability to change these values is greyed out which i also be...

jonswick_0-1672968695193.png

Resolved! Auto-attaching VM series to Panorama in AWS

I am trying to boot and auto-attach a VM series FW to Panorama in AWS. I am specifying the user-data as follows: type=dhcp-clienthostname=aws-palo-1panorama-server=a.b.c.dtplname=lz-firewalldgname=lz-firewalldns-primary=8.8.8.8dns-secondary=8.8.4.4op-command-modes=mgmt-interface-swapdhcp-send-hostname=yesdhcp-send-client-id=yesdhcp-accept-serv...

BBartik by • L2 Linker
  • 2842 Views
  • 1 replies
  • 0 Likes

Queries regarding the Azure Bootstrap Package

Dear and valuable Live Community Members, One of our customers came to us with some questions about Azure Bootstrap Package, but I couldn't find the requested information for that. We've checked the article where the steps to create new firewalls in Azure are explained (https://docs.paloaltonetworks.com/vm-series/9-1/vm-series-deployment/boots...

NGFW with azure gateway load balancer

If I have an Azure Gateway Load Balancer set up with my NGFWs (Interface eth1/1), do I have to use a separate interface for traffic originating inside Azure to point to? I would assume yes since GWLB technically uses vxlan and so I'd need a separate interface to stick in the backend pool of an internal LB I have set up (where all the default rou...

How to retain Public IP Address Assigned to a host on VMSeries Firewall on Azure

Hello Community, I want to deploy Palo Alto VM Series firewall Infront of some workloads already existing on my Azure tenant and still ensure that services calling the workloads use the existing public IP Addresses assigned to these workloads when the traffic passes through the VM Series firewall. It is easier to deploy when workloads haven'...

ORufai by • L0 Member
  • 2865 Views
  • 1 replies
  • 0 Likes

2 Palo Alto VM-Serie for IPsec VPN

Hello We deploy 2 VM-Series on Azure as recommanded by PA. These 2 FW manage Inbound/Outbound traffic and between our internals zones. A public load balancer have been configured. We need to connect our Azure infrastructure with our local datacenter via IPsec VPN between PA on Azure and firewall on our datacenter. Do you know if it's possibl...

  • 532 Posts
  • 107 Subscriptions
Labels