VM-Series in the Public Cloud
The VM-Series is the virtualized form factor of the next-generation firewall. Use this discussion as a resource to discuss VM-Series deployments across public clouds like AWS, Microsoft Azure, Google Cloud Platform, Oracle Cloud, and Alibaba.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
VM-Series in the Public Cloud
The VM-Series is the virtualized form factor of the next-generation firewall. Use this discussion as a resource to discuss VM-Series deployments across public clouds like AWS, Microsoft Azure, Google Cloud Platform, Oracle Cloud, and Alibaba.
About VM-Series in the Public Cloud

Welcome to the VM-Series in the Public Cloud discussion forum! This community exists as a resource for you to discuss VM-Series deployments on AWS, Microsoft Azure, Google Cloud Platform, Oracle Cloud and Alibaba. We encourage you to engage in this rapidly growing community to share ideas, pose questions, and propose real-world solutions to any challenges that may arise.

Disclaimer:
This forum is provided for Live Community members to discuss and share information pertaining to the VM-Series deployments on AWS, Microsoft Azure, Google Cloud Platform Oracle Cloud and Alibaba. Please use the information from this forum at your own risk and make sure to test and verify proposed solutions presented here. For information on contacting Palo Alto Networks support, click here.

Discussions

Welcome to the VM-Series in the Public Cloud Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 3650 Views
  • 0 replies
  • 0 Likes

VM-500: HA1 Down, HA1 Backup Up, HA2 Up.

NOTE: This appears to have been an issue in the Cloud space. I suspect a VMotion or reboot of the VM Host resolved the problem as an unrelated issue with spinning up access to the VM was resolved at the same time this HA issue was resolved and no configuration changes were made. ------------------------------------------------------------------...

Configuration VM-Series on Azure cloud

Hello I'm deploying my first Palo Alto on Azure (I already deployed physical appliance) but I'm blocked. I would like to deploy this type of design. The global network defined is 10.200.0.0/16 who are splitted in serverals sub-networks. I have one Untrust zone for Internet access and several zone for networks where we host our servers for I...

jeromecarrier_1-1664963571129.png

Resolved! D-NAT not working in GCP

Hello Everyone, I have deployed PA-VM in GCP. In that we have configured 3 VPCs (MGMT, Untrust & Trust). In the Trust VPC we have created Windows Server 2016, in PA we created D-NAT & Security policy. In GCP, Under Trust VPC Firewall Ingress traffic is allowed & Route is forwarded to PA-VM instance with 500 priority. For Untr...

Packets being denied intermittently.

My company has had an issue for over a year and Palo Alto cant figure it out. We're using Azure's Palo Alto offering. * We have a security rule that is sourced from our trusted paas and destined to Azures Paas storage. Port 1433 app id: mssql db encrypted.* Multiple times a week traffic all of a sudden goes from being allowed under a specifi...

AWS and Inbound SSL Inspection

Hello all, After some help as not getting much from support. We have a customer with an Amazon AWS solution. We have a web server in the trust zone and we have been asked to set up inbound ssl inspection. There is a load balancer after the firewalls. The client uses an Amazon cert of some sort and we have created a cert and private key on the ...

how to setup palo alto for dual stack for IPv6 internet

Hi, I have configured PAVM in azure with IPv4 and everything is working fine. so I decided to add IPv6 as a Dual stack. And Azure provided me single Public IPv6 and it configures on the Azure load balancer and mapped with an untrust interface on the firewall with my private IPv6 range fd6e:8b94:25ca:b001::/64, and on trust interface range is fd6...

Azure multiple public front ends on load balancer

Using multiple front end IPs to split my internet facing applications. Seemed to solve the health probe issue with splitting static 168.63.129.16/32 azure routes between virtual routers, but inbound traffic doesn't seem to know where to go. Single public application worked no problem, as soon as second front end IP is added, the VM series stops ...

joeritt by L0 Member
  • 5789 Views
  • 2 replies
  • 0 Likes

FTP Server behind Palo Alto pair and Azure External Load Balancer Not getting directory

I have a "HA" pair of firewalls in Azure sitting behind an external Load Balancer. I have a FTP server that I have to configure behind the firewalls. I am able to connect locally to the FTP server and it works as expected, but when I point the FTP client to the Public IP address of the LB, I am able to connect, but not get the directory. I am ...

Azure NAT Rule closing VPN Tunnel

Good Afternoon,We have a VPN tunnel established b/t an Azure VPN GW and a PA 3020 running 9.1.10.We need to add a NAT rule on the Azure side. When we apply the NAT rule, the tunnel closes.Azure docs on this topic are less than helpful and I have not found an article or guide here yet. Appreciate any recommendations. Thanks.

Cannot connect VM series firewall to Panorama in AWS

   Hello, We are trying to set up a new deployment in AWS consisting of two firewalls managed by a Panorama server. For starters, we deployed one firewall and one Panorama instance. They are in the same VPC, different subnets. Security groups currently allow all TCP to/from the Panorama server and the firewall. Both Panorama and the firewall ha...

fwlogs.png
panlogs.png
broke.png

Deploying a VM-Series in Azure using Terraform and Bootstrap

I have to admit it, I love to create good examples that others can follow. I know the PAN team has published some great examples up on Github. But I figured I would publish my own example of how to deploy a VM-Series firewall in Azure using Terraform and Bootstrap. I hope someone finds it useful. It can be found here: https://github.com/dustint...

DTG123 by L1 Bithead
  • 10556 Views
  • 1 replies
  • 6 Likes

Resolved! HA on AWS Using a Secondary IP

Hi, Just checking if anyone has successfully deployed the latest HA mode "secondary-ip". Unfotunately the deployment guides can be described more as "guides" rather than detailed instructions. Furthermore they are fragmented so one has to scramble over different places and review pages, sometimes unrelated to the new mode 😅. Anyway my issue...

ha_secondary_ip.drawio.png

Resolved! Elastic IP's not responding on Palo Alto VM

Greetings All, I have a very basic question and basic issue. I have Palo Alto up and running in my lab on AWS. I can connect to the Management Interface just fine. I have added eth1 to the the PA and configured the access for ping, ssh, https, etc. Also created the zone. I am using the default virtual router. From within my VPC using anothe...

Hitting IPsec Tunnel Limit on M-300

We are hitting a software limitation on the max number of IPsec Tunnels allowed for our VM-Series Next-Generation Firewall Bundle 2. This was purchased through AWS Marketplace and there is no clearly defined upgrade path for us to follow. The Palo Alto website shows that we can get from the M-300 to the M-500 or M-700... No mention on how to do ...

rpwags by L0 Member
  • 2055 Views
  • 1 replies
  • 0 Likes
  • 526 Posts
  • 107 Subscriptions
Labels