VM-Series in the Public Cloud
The VM-Series is the virtualized form factor of the next-generation firewall. Use this discussion as a resource to discuss VM-Series deployments across public clouds like AWS, Microsoft Azure, Google Cloud Platform, Oracle Cloud, and Alibaba.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
VM-Series in the Public Cloud
The VM-Series is the virtualized form factor of the next-generation firewall. Use this discussion as a resource to discuss VM-Series deployments across public clouds like AWS, Microsoft Azure, Google Cloud Platform, Oracle Cloud, and Alibaba.
About VM-Series in the Public Cloud

Welcome to the VM-Series in the Public Cloud discussion forum! This community exists as a resource for you to discuss VM-Series deployments on AWS, Microsoft Azure, Google Cloud Platform, Oracle Cloud and Alibaba. We encourage you to engage in this rapidly growing community to share ideas, pose questions, and propose real-world solutions to any challenges that may arise.

Disclaimer:
This forum is provided for Live Community members to discuss and share information pertaining to the VM-Series deployments on AWS, Microsoft Azure, Google Cloud Platform Oracle Cloud and Alibaba. Please use the information from this forum at your own risk and make sure to test and verify proposed solutions presented here. For information on contacting Palo Alto Networks support, click here.

Discussions

Welcome to the VM-Series in the Public Cloud Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by • Community Team Member
  • 3703 Views
  • 0 replies
  • 0 Likes

Cannot connect VM series firewall to Panorama in AWS

   Hello, We are trying to set up a new deployment in AWS consisting of two firewalls managed by a Panorama server. For starters, we deployed one firewall and one Panorama instance. They are in the same VPC, different subnets. Security groups currently allow all TCP to/from the Panorama server and the firewall. Both Panorama and the firewall ha...

fwlogs.png
panlogs.png
broke.png

Deploying a VM-Series in Azure using Terraform and Bootstrap

I have to admit it, I love to create good examples that others can follow. I know the PAN team has published some great examples up on Github. But I figured I would publish my own example of how to deploy a VM-Series firewall in Azure using Terraform and Bootstrap. I hope someone finds it useful. It can be found here: https://github.com/dustint...

DTG123 by • L1 Bithead
  • 10648 Views
  • 1 replies
  • 6 Likes

Resolved! HA on AWS Using a Secondary IP

Hi, Just checking if anyone has successfully deployed the latest HA mode "secondary-ip". Unfotunately the deployment guides can be described more as "guides" rather than detailed instructions. Furthermore they are fragmented so one has to scramble over different places and review pages, sometimes unrelated to the new mode 😅. Anyway my issue...

ha_secondary_ip.drawio.png

Resolved! Elastic IP's not responding on Palo Alto VM

Greetings All, I have a very basic question and basic issue. I have Palo Alto up and running in my lab on AWS. I can connect to the Management Interface just fine. I have added eth1 to the the PA and configured the access for ping, ssh, https, etc. Also created the zone. I am using the default virtual router. From within my VPC using anothe...

Hitting IPsec Tunnel Limit on M-300

We are hitting a software limitation on the max number of IPsec Tunnels allowed for our VM-Series Next-Generation Firewall Bundle 2. This was purchased through AWS Marketplace and there is no clearly defined upgrade path for us to follow. The Palo Alto website shows that we can get from the M-300 to the M-500 or M-700... No mention on how to do ...

rpwags by • L0 Member
  • 2077 Views
  • 1 replies
  • 0 Likes

PA-VM Upgrade steps

PA-VMVM-3009.0.8 to 9.0.10vm_series-1.0.11 Sorry for the (probably) simple question, but I've never done a Software Version upgrade on a Palo VM before. Other than the usual steps to update, what other considerations do I need to take into account? How do i know if I need to update the plug-in or not? If so, do I update the plug0in first? Any...

Azure Deployment instructions don't work - web interface won't load

I tried deploying the vm series firewall in an Azure environment using the steps here https://docs.paloaltonetworks.com/vm-series/9-1/vm-series-deployment/set-up-the-vm-series-firewall-on-azure/deploy-the-vm-series-firewall-on-azure-solution-template#ide37bac08-683a-4245-a412-2f74a56855fa I followed every step exactly as indicated but when I g...

GWLB Sub-Interface

Hello, Question about GWLB and sub-interface mapping. If I have 2 VPCs (VPC-Shared and VPC-Production) and I associate VPC-Shared with a GWLB Endpoint to sub-interface e1/1.100 on a zone also named VPC-Shared and VPC-Production with an endpoint to e1/1.200 on zone called VPC-Production. When I send traffic from the VPC-Production to VPC-Shared...

IPv6 support in Azure/AWS

Anyone already succeeded in getting IPv6 addresses working on our FW in Azure or AWS? Trying to get the mgmt-interface use an IPv6 address in order to connect to IPv6 Panorama.If required this can also be done via DP interface and service routing. Tried using the LB in Azure (which seems to be required). However, haven't been succesfull to far.I...

Moving public IP from VM to Palo Alto in Azure

We deployed a Palo Alto VM-300 in an existing Azure tenancy. During the process to move public IP Addresses from the Virtual Machine to the Palo Alto Untrusted Interface we ran into the following error. "Network interface associated with virtual machine does not allow different SKU type for public IP Address in IP configurations" The public I...

estoltz by • L0 Member
  • 5247 Views
  • 2 replies
  • 0 Likes

When adding public ips to vm firewall, I want to know the maximum number of ips that can be added.

helloThere was a request from a customer to use the PaloAlto VM firewall.In response to the customer's request, the contents of the link below have been delivered to the customer.https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PLlVCAWAfter checking the contents of the above link, the customer has asked us additional que...

Zero trust in AWS issue with ALB

We are trying to implement a zero trust environment inside our AWS cloud. We are using a transit gateway deployment, and have all traffic going through a secuirty vpc which houses a pair of PA-VM's. These firewalls are reached by the other VPC's through GWLB's. Because of this architecture when we are allowing inbound web traffic to our ALB's we...

nelsonc0 by • L1 Bithead
  • 3498 Views
  • 2 replies
  • 1 Likes

Palo in AWS to Azure VPN Gateway

Hi All, I am trying to setup a site-to-to site VPN between Palo (v9.0.1) and Azure VPN gateway. I have a question and an issue that I am trying to resolve... NAT-T should be enabled in the gateway settings since AWS NATs everything? This is the error I keep getting... 2022-05-06 15:09:24.235 -0700 [INFO]: { 3: }: received IKE request 21.50.80.20...

  • 532 Posts
  • 107 Subscriptions
Labels