VM-Series in the Public Cloud
The VM-Series is the virtualized form factor of the next-generation firewall. Use this discussion as a resource to discuss VM-Series deployments across public clouds like AWS, Microsoft Azure, Google Cloud Platform, Oracle Cloud, and Alibaba.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
VM-Series in the Public Cloud
The VM-Series is the virtualized form factor of the next-generation firewall. Use this discussion as a resource to discuss VM-Series deployments across public clouds like AWS, Microsoft Azure, Google Cloud Platform, Oracle Cloud, and Alibaba.
About VM-Series in the Public Cloud

Welcome to the VM-Series in the Public Cloud discussion forum! This community exists as a resource for you to discuss VM-Series deployments on AWS, Microsoft Azure, Google Cloud Platform, Oracle Cloud and Alibaba. We encourage you to engage in this rapidly growing community to share ideas, pose questions, and propose real-world solutions to any challenges that may arise.

Disclaimer:
This forum is provided for Live Community members to discuss and share information pertaining to the VM-Series deployments on AWS, Microsoft Azure, Google Cloud Platform Oracle Cloud and Alibaba. Please use the information from this forum at your own risk and make sure to test and verify proposed solutions presented here. For information on contacting Palo Alto Networks support, click here.

Discussions

Welcome to the VM-Series in the Public Cloud Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 3653 Views
  • 0 replies
  • 0 Likes

Jumbo Frames

Hi,I need small information on Jumbo Frames. If I disable the Jumbo Frames in PA-VM (VM-300) in device --- Setup --- session, will it be there any traffic impact or will firewall reboot.?please suggest me on this,.Thank you,

Azure HA Failover not working

Hello, We have a pair of VM300 PAs in Azure set up in Active-Passive. They are running 9.0.7 code with VM Series plug in 1.0.8. There was an issue in Azure on 19/10/20 which caused a failover and recovery (we use pre-emption). Post this issue the PAs were up and running but not passing traffic. we found that the secondary IP addresses (i.e. ...

Resolved! Azure multiple VM-series with UDR and Load balancers

Hello, At this moment I am doing a PoC for a client in Azure with two VM-300 in the so called "Sandwich" mode. So for traffic coming from the internet I have the following path: ELB > VM-300 (x2) > ILB > Webserver (x2). Both VM-300 and Webservers are both in a seperate availabilty set. I managed to load balance the traffic from the int...

Knipsel.PNG

AWS interface limits

Is the AWS VM limited to only 3 interfaces or can we add 3 more? I was reading there may be limitations associated with machine type but wanted to be sure before we went down the path of changing that.

Resolved! Azure Palo Alto VM to campus network via ExpressRoute

Quick question for the community. I have setup and configured the Palo Alto VM series in Azure. Along with the management interface, the VM has “trust” and “untrust” interfaces. I have basically copied the rules over from our office Palo Alto devices, and my test VM is working great through the Palo Alto VM. However, I’m having a problem that I ...

Resolved! NGFW on Azure cannot be deployed successful

Hi all, I got a weird situation when I deploy the PA NGFW on Azure, could you please give me some suggestions for resloving this weird situation? After deployment, the VM will be restared and restared by itself with unknown reason, I try to connect to Serial Console, the final screen is in Maintenance mode. I check the Activity Log, but no any v...

GlobalProtect with SAML to Azure AD - selecting account when activating GP

Hello Community, we´ve configured GP to authenticate via SAML to our Azure AD service so that we can use MFA on GP.GP is only used by IT employees with their "admin" accounts.So far, it seems to work fine how its configured. The only problem we are facing is, that some users are not asked which Microsoft account they want to use in GP when they ...

MStork by L0 Member
  • 7691 Views
  • 3 replies
  • 0 Likes

FIPS mode in Azure Government

Has anyone been successful in converting their VM-series appliances running in Azure Government to FIPS-CC mode? The SSH keys I created and allowed for FW management prior to the conversion were wiped out and resetting the keys via the Azure portal doesn't work (although the agent is running). I cannot get into the GUI either since admin is not ...

cl625410 by L0 Member
  • 4152 Views
  • 1 replies
  • 0 Likes

Resolved! NGFW HA on AWS with different AZ

Hi All, I want to configure Active/Passive HA on AWS, but both the PA-Instance should be in different AZ. How can we achieve this?I have referred below article: https://docs.paloaltonetworks.com/vm-series/9-1/vm-series-deployment/set-up-the-vm-series-firewall-on-aws/high-availability-for-vm-series-firewall-on-aws/configure-activepassive-ha-on-aw...

Azure Network Watcher

Hello, i want to do a packet capture on a VM interface using Network Watcher for some traffic on our VM-300 series NGFW but our CSP advises this is not possible. The extensions section in Azure seems to confirm this. can anyone advise if this feature is available? we are having issues with a flow of traffic not being received at the far end b...

RyanJohnstone1144_0-1633536096660.png

Public IPs with NAT in IPSEC

I've got a rather bizarre setup that I'm trying to integrate with a new customer using a vm-series 300 in AWS. I have setup and established an IPSEC tunnel (that even comes up when we attempt to send traffic over the tunnel). Where it gets complicated is that their expectation is that we NAT all traffic using public IPs and send the traffic thr...

NAT plan - Copy of Page 1.png

Inbound Traffic to Azure Public Load Balancer

I've become stuck on an issue getting inbound traffic working to a resource in a subscriber VNET behind a transit VNET where firewalls are configured. I think I'm missing something obvious, and thought I would bounce ideas off of the community here. Here's a summary of the configurations relevant. Public Load Balancer listens on public IP 1.2.3....

dashnet by L0 Member
  • 7809 Views
  • 2 replies
  • 0 Likes

Zone Protection profile pushed from Panorama to VM-100 in Azure

Hi all, I am having recurring issues deploying zone protection profiles for VM series firewalls in Azure, from Panorama templates, revolving around SCTP settings, whenever I try to push the template the commits are failing with the below error - Details:. Validation Error:. network -> profiles -> zone-protection-profile -> Untrusted_Zon...

Does the HA Passive PA-VM Firewall forwards the logs to syslog server

Team, We have the pair of PA-VM deployed in HA A-P mode. The log-forwarding facility is enabled and the logs are being forwarded to the external Syslog-Server. It is noticed that the Passive node is not sending any logs to the Syslog-Server. Only the Active node is sending the logs. I am trying to understand that all the configurations are ident...

  • 526 Posts
  • 107 Subscriptions
Labels