VM-Series in the Public Cloud
The VM-Series is the virtualized form factor of the next-generation firewall. Use this discussion as a resource to discuss VM-Series deployments across public clouds like AWS, Microsoft Azure, Google Cloud Platform, Oracle Cloud, and Alibaba.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
VM-Series in the Public Cloud
The VM-Series is the virtualized form factor of the next-generation firewall. Use this discussion as a resource to discuss VM-Series deployments across public clouds like AWS, Microsoft Azure, Google Cloud Platform, Oracle Cloud, and Alibaba.
About VM-Series in the Public Cloud

Welcome to the VM-Series in the Public Cloud discussion forum! This community exists as a resource for you to discuss VM-Series deployments on AWS, Microsoft Azure, Google Cloud Platform, Oracle Cloud and Alibaba. We encourage you to engage in this rapidly growing community to share ideas, pose questions, and propose real-world solutions to any challenges that may arise.

Disclaimer:
This forum is provided for Live Community members to discuss and share information pertaining to the VM-Series deployments on AWS, Microsoft Azure, Google Cloud Platform Oracle Cloud and Alibaba. Please use the information from this forum at your own risk and make sure to test and verify proposed solutions presented here. For information on contacting Palo Alto Networks support, click here.

Discussions

Welcome to the VM-Series in the Public Cloud Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 3524 Views
  • 0 replies
  • 0 Likes

How does the Azure Virtual Network discovers that there is Palo Alto Gateway Interface

Hello, I am trying to wrap my head around the PA deployment in azure using PA Series. I am basically following this video on setting up 2 zones, 2 Virtual routers, and route rules.In my setup the two spoke vnets have UDR with 0.0.0.0/0 route to the trust interface of the PANFW. I created two VRs and associated with the Interfaces. I have also a...

rswarnkar_0-1766036895351.jpeg

Unable to deploy VM Series bundle1 and Marketplace agreement fails with ResourcePurchaseValidationFailed

Hello, I am working on a PoC setup having bundle1 Vm series PAFW for a client using Terraform in Azure but no matter what I do I always blocked by Marketplace license. When I create the VM with Marketplace agreement, the terraform api for Azure complaints that License agreement resource already existWhen I create the VM with Market place agreeme...

Log forwarding from Cloud NGFW in Azure to Log Analytics Workspace for Sentinel

Hi I’m planning to replace Azure Firewall with Cloud NGFW in Azure, managed through SCM. In addition to using Strata Logging Service (SLS), we also need to forward firewall logs to an Azure Log Analytics Workspace for Microsoft Sentinel (SIEM/SOAR). Based on my research, there appear to be two possible approaches: Option 1 - Cloud NGFW f...

A.Hwang by L0 Member
  • 660 Views
  • 0 replies
  • 0 Likes

Data Plane CPU utilization Reaches more than 90 %

model: PA-VMvm-license: VM-SERIES-4vm-cap-tier: T2-14GBvm-cpu-count: 4 Data Plane CPU utilization Reaches more than 90 % . Is there any Limit on PPS for Azure VM-SERIES-4 . I think 525895 Kbps is well under the limit . Is PPS causing the issue ? . Session table: 1% , Packet buffer: 10% , Packet descriptor: 0% , SW tag descriptors: low all seems ...

Help Needed: NAT & Security Policy Configuration for Azure LB → Palo Alto → DMZ Webserver (Public IP)

Hello Team,Goal:I want to access the DMZ Webserver (Public IP) via the Azure Load Balancer Public IP.Current Setup:Azure Public Load Balancer is created with Frontend IP, Backend Pool, and Health Probe.Palo Alto Firewall VM is added to the backend pool.DMZ VM (Webserver) is running with a Public IP.Issue:Load Balancer backend pool is correctly f...

ARM Template fails due to Availability Set

Hi All, I am trying to deploy Azure-1FW-3-Interfaces-existing-environment using following ARM template https://github.com/PaloAltoNetworks/ReferenceArchitectures/tree/master/Azure-1FW-3-interfaces-existing-environment However, deployment fails due to following error. Availability set created with 'Aligned' SKU and Managed 'YES' "code": "Op...

VM Series Azure Active/Active Deployment

Hi All, I want to deploy two PA firewall in Azure, in an existing resource group in an Active / Active scenario. Inside Load Balancer will be used to distribute traffic. Should I also setup HA to store active session, NAT, etc. In case one VM goes down existing session switchover to second VM. Is there any reference guide for Active/Active depl...

Resolved! VM-Series active/passive deployment over GitHub fails

Hello Community, I am currently trying to perform an HA deployment in Azure.To do this, I am using the ‘Azure HA Deployment’ via GitHub and the embedded link where I can then deploy the VM series in the Azure Portal. Here are the links to the topic: https://docs.paloaltonetworks.com/vm-series/11-1/vm-series-deployment/set-up-the-vm-series-fi...

Resolved! VMSeries on Azure using Existing Resource group and VNET

Hi All, I am trying to setup a new VM series PA firwall in Azure. However, I want to use existing resource group and VNET. I wonder which ARM template (Github) will best fit in my scenario? Can I deploy first firewall using "Azure-HA-Deployment" https://github.com/PaloAltoNetworks/Azure-HA-Deployment or I need to modify "two-tier-sample" ARM...

VM-Series Next Generation Firewall in Azure

Hi All, Can you please share any official document that guide VM-Series Next Generation Firewall (Virtual machine) with BYOL option. I need your help around this as I couldn't get any dedicated document to build steps. Only document I could find is "Deploy the VM-Series Firewall from the Azure Marketplace (Solution Template)" which reflects a...

AWS GWLB with secondary appliance in chain

I'm working with a dedicated inspection VPC+GWLB for the first time. I have the TGW, GWLB, and general routing working with just the Palo in play. East west traffic from vpc1 to vpc2 is correctly going into the inspection VPC and I can see the traffic in the Palo logs, etc...My question is: we want to add a second device in the chain. On prem we...

scotto by L0 Member
  • 2732 Views
  • 1 replies
  • 0 Likes

Multi-Zone PA-VM in Azure using different Front-End IP

I'm trying to come up with a architecture design using PA-VM in Azure on a Transit-VNET. I'm familiar with the reference architecture but this limits me to only Trust & Untrust zone. I also understand that doing PA-VM in cloud recommends using Azure service tag with DAG rather than the old mindset of Zone-based. For the sake of discussion,...

F.Eisma by L0 Member
  • 1307 Views
  • 0 replies
  • 0 Likes
  • 709 Posts
  • 107 Subscriptions
Top Solution Authors
Top Liked Authors
Labels