VM-Series in the Public Cloud
The VM-Series is the virtualized form factor of the next-generation firewall. Use this discussion as a resource to discuss VM-Series deployments across public clouds like AWS, Microsoft Azure, Google Cloud Platform, Oracle Cloud, and Alibaba.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
VM-Series in the Public Cloud
The VM-Series is the virtualized form factor of the next-generation firewall. Use this discussion as a resource to discuss VM-Series deployments across public clouds like AWS, Microsoft Azure, Google Cloud Platform, Oracle Cloud, and Alibaba.
About VM-Series in the Public Cloud

Welcome to the VM-Series in the Public Cloud discussion forum! This community exists as a resource for you to discuss VM-Series deployments on AWS, Microsoft Azure, Google Cloud Platform, Oracle Cloud and Alibaba. We encourage you to engage in this rapidly growing community to share ideas, pose questions, and propose real-world solutions to any challenges that may arise.

Disclaimer:
This forum is provided for Live Community members to discuss and share information pertaining to the VM-Series deployments on AWS, Microsoft Azure, Google Cloud Platform Oracle Cloud and Alibaba. Please use the information from this forum at your own risk and make sure to test and verify proposed solutions presented here. For information on contacting Palo Alto Networks support, click here.

Discussions

Welcome to the VM-Series in the Public Cloud Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 3673 Views
  • 0 replies
  • 0 Likes

Resolved! VM-Series Firewall with Flexible vCPUs throughput

VM-Series firewall can deploy with Flexible vCPUs model. Is it any reference to determine the throughput with different number of CPU such as "throughput versus CPU" table? As I know when the throughput needs change, I can simply allocate additional cores to scale the software firewall up.However, when I initial deploy the firewall, I would like...

JoeKwok by L2 Linker
  • 6005 Views
  • 1 replies
  • 0 Likes

New interface at Palo-alto VM in AWS EC2 instance not turning UP

On a PA-VM (VM500, SW ver- 10.0.8-h8.) in Amazon cloud EC2 instance, i am struggling to create a new interface and bring it up, tried below steps already-1. Created an ENI and attached to the respective EC2 instance.2. Source/Destination check disabled.3. Tried configuring different eth1/3-6 with same IP/Subnet as ENI.4. Tried multiple times but...

IT.OPS by L0 Member
  • 4137 Views
  • 2 replies
  • 0 Likes

Palo HA in Azure - traffic flow

I have a pair of VM300 gateways running 9.1.13 in Azure. I'm using a 'load balancer sandwich' approach to provide active active HA.The public load balancer in front of the firewalls does a good job of delivering inbound traffic. However, routing to the internal destinations from the inside of the firewalls isnt ideal currently. I find i have t...

How to upgrade PA on AWS and How much downtime do we need ?

Hi,I have the experience how to upgrade PAN os with ON-PRIMES .But I don't know how different on AWS and what is impact.I would like to upgrade my PA on AWS.my pan-os is 8.1.So It is very old . I would like to upgrade latest version. So let me know what is the best practice to upgrade PA on AWS.How much downtime i need to upgrade ?I noticed in d...

crypto by L2 Linker
  • 3517 Views
  • 2 replies
  • 0 Likes

Not displaying palo alto login page

Hi all,When i typed in my default gateway IP address it is displaying BT Smart Hub Manager page instead of Palo Alto login page.I did all the configuration connecting VirtualBox and Palo alto. Do I missing something why isn't displaying palo alto login page? It has been few days i am trying to find the solution. Help please.

Dilton111 by L1 Bithead
  • 13691 Views
  • 15 replies
  • 0 Likes

PA-VM hanging on Azure

Hi All, I have an outage issue on our PA-VM hosted in azure. We are unable event to remote the console. All network seems down, and by azure support, it is caused by OS inside. How can we analyze what happened during the moment? Does PA-VM have a log file so we can analyze it?PAN OS 9.0.9-h1 Thank you

gmcchris by L0 Member
  • 2019 Views
  • 1 replies
  • 0 Likes

Deploy Palo-Alto VMs into AWS ASG with 3 NICs (Trust, untrust and management)

We’re looking for the best way to deploy Palo Alto firewalls with trust, untrust and management NICs in an autoscaling group in AWS that’s aligned to best practice. Autoscaling groups for EC2 instances are limited to one network and we see the latest version of the Palo Alto template in Git (ASG with warm pools) caters for this but creates a fir...

Any Plan to Support VM HA (HAVIP) on Alibaba Cloud

Hi PLM and Experts We have any plan to support VM HA (HAVIP) on Alibaba Cloud. I have a customer plans to deploy VMs in Alibaba Cloud ,but because we don't support VIP (HA high availability) due to reliability and redundancy, which makes it impossible to specify a virtual gateway inside the VPC. Customers want us to provide HA solutions. Ali Clo...

1.png
xiwang by L0 Member
  • 6967 Views
  • 3 replies
  • 1 Likes

Using the PALOs internal IP as an injected header

Hello I'm very new to Palo, but not new to firewalls and my background is more with applications. This is to do with HTTP(S) traffic with a GET verb and Health Checks in AWS. This is a pre-existing system deployed in AWS as EC2s and I'm wondering if I'm missing something obvious. I'm trying to see if there is a way of injecting something unique...

Resolved! VM-series deployment issue via Panorama Orchestration

HelloI've tried to deploy the VM-Series in Azure via Panorama Orchestration mode (Panorama is deployed in a RG in Azure),I have only NAT GW and IP Public prefixes which are implemented (see screenshot below).The rest of the components are not deployed in Azure. Despite the 'success' message in Panorama.Anyone be faced with this behavior?I put th...

2022-03-14_16h03_25.png
2022-03-14_16h03_15.png
2022-03-14_16h03_06.png
2022-03-14_16h35_12.png
FatihT by L1 Bithead
  • 3512 Views
  • 2 replies
  • 0 Likes

Azure VM Series - Peered VNET traffic does not go outbound

I have created a VM series in Azure. I could see that the traffic from trusted subnet (from VM1 in the below diagram) is able to go outbound to internet, however traffic from a peered VNET (from VMs in the subnet1 in the peered VNET in the below diagram) shows "incomplete" status in the logs. I have a route table that routes the traffic from the...

Palo-Arch.png
msazure by L0 Member
  • 3908 Views
  • 2 replies
  • 0 Likes

Resolved! PA in Azure and Public front LB

HelloI'm considering to implement PaloAlto VM-series in Azure in 'autoscaling' mode.This involves to have an App GW and a Standard LB in front of the firewalls.My questions are, as follows:In addition the deployed Azure App GW, is it possible to have additional Azure App GW?the aim is to have multiple public IP address (by default App GW can hav...

2022-03-04_15h13_13.png
FatihT by L1 Bithead
  • 3540 Views
  • 1 replies
  • 0 Likes
  • 530 Posts
  • 107 Subscriptions
Labels