VM-Series in the Public Cloud
The VM-Series is the virtualized form factor of the next-generation firewall. Use this discussion as a resource to discuss VM-Series deployments across public clouds like AWS, Microsoft Azure, Google Cloud Platform, Oracle Cloud, and Alibaba.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
VM-Series in the Public Cloud
The VM-Series is the virtualized form factor of the next-generation firewall. Use this discussion as a resource to discuss VM-Series deployments across public clouds like AWS, Microsoft Azure, Google Cloud Platform, Oracle Cloud, and Alibaba.
About VM-Series in the Public Cloud

Welcome to the VM-Series in the Public Cloud discussion forum! This community exists as a resource for you to discuss VM-Series deployments on AWS, Microsoft Azure, Google Cloud Platform, Oracle Cloud and Alibaba. We encourage you to engage in this rapidly growing community to share ideas, pose questions, and propose real-world solutions to any challenges that may arise.

Disclaimer:
This forum is provided for Live Community members to discuss and share information pertaining to the VM-Series deployments on AWS, Microsoft Azure, Google Cloud Platform Oracle Cloud and Alibaba. Please use the information from this forum at your own risk and make sure to test and verify proposed solutions presented here. For information on contacting Palo Alto Networks support, click here.

Discussions

Welcome to the VM-Series in the Public Cloud Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 3526 Views
  • 0 replies
  • 0 Likes

Are you using certificate profiles for Azure SAML authentication?

Setting up SAML authentication for the first time from a new Azure instance and having multiple issues. I had an idea how it would work, that Azure would provide an internal CA and SAML gateway (IDP) certificate, and then assign us a certificate (w/private key) to use on the firewall. However, we are only getting a self-signed certificate for th...

Overlay routing for specific VPC

In AWS, I know how to enable overlay routing using the following commands: request plugins vm_series overlap-routing enable yes, but can we have VPCs in a specific account handle overlay routing and VPCs handle overlay routing?Is there only an option to handle full overlay routing?https://docs.paloaltonetworks.com/vm-series/10-1/vm-series-deploy...

Can we use Azure AD(SAML) with Palo alto VM configured in Equinix cloud and AWS cloud

Hi Team, we are deploying Palo alto firewall in Azure, AWS and Equinix cloud, Clouds are connected via express route and direct connect. while looking for MFA solution we want to use Azure Active directory. https://docs.microsoft.com/en-us/azure/active-directory/saas-apps/paloaltoadmin-tutorial we have firewalls in each cloud and want to use s...

Deploying a VM-Series in Azure using Terraform and Bootstrap

I have to admit it, I love to create good examples that others can follow. I know the PAN team has published some great examples up on Github. But I figured I would publish my own example of how to deploy a VM-Series firewall in Azure using Terraform and Bootstrap. I hope someone finds it useful. It can be found here: https://github.com/dustint...

DTG123 by L1 Bithead
  • 10192 Views
  • 1 replies
  • 6 Likes

Resolved! HA on AWS Using a Secondary IP

Hi, Just checking if anyone has successfully deployed the latest HA mode "secondary-ip". Unfotunately the deployment guides can be described more as "guides" rather than detailed instructions. Furthermore they are fragmented so one has to scramble over different places and review pages, sometimes unrelated to the new mode 😅. Anyway my issue...

ha_secondary_ip.drawio.png

Resolved! Elastic IP's not responding on Palo Alto VM

Greetings All, I have a very basic question and basic issue. I have Palo Alto up and running in my lab on AWS. I can connect to the Management Interface just fine. I have added eth1 to the the PA and configured the access for ping, ssh, https, etc. Also created the zone. I am using the default virtual router. From within my VPC using anothe...

Hitting IPsec Tunnel Limit on M-300

We are hitting a software limitation on the max number of IPsec Tunnels allowed for our VM-Series Next-Generation Firewall Bundle 2. This was purchased through AWS Marketplace and there is no clearly defined upgrade path for us to follow. The Palo Alto website shows that we can get from the M-300 to the M-500 or M-700... No mention on how to do ...

rpwags by L0 Member
  • 1989 Views
  • 1 replies
  • 0 Likes

PA-VM Upgrade steps

PA-VMVM-3009.0.8 to 9.0.10vm_series-1.0.11 Sorry for the (probably) simple question, but I've never done a Software Version upgrade on a Palo VM before. Other than the usual steps to update, what other considerations do I need to take into account? How do i know if I need to update the plug-in or not? If so, do I update the plug0in first? Any...

Sync Cloud PA between 2 FWs in AWS

We have 2 fw PA on AWS cloud. Each firewall is on their respective Zone. Currently, Zone B is shutdown. The question is: We need to avoid turn on components in the zone B (due to our limited resources), but, we need to sync up boths firewalls. Requirement is that load balancer must not be detect that firewall A is down. This load balancer is d...

apazmino by L1 Bithead
  • 1927 Views
  • 0 replies
  • 0 Likes

Approches for certificate deployment for SSL decryption in public cloud?

I would like to hear which approaches could be used to deploy and automatically deploy trusted root certificates for servers in the public cloud (Containers, Virtual machines, serverless functions) in order to decrypt its traffic.Approved images for deployment that includes the certificate?Ansible?Auto-remediation with prisma cloud? Thanks!

Subnet to Subnet communication through PA-VM

G'day All, I was wondering if anyone can guide me with an issue I am facing. We have Hub & Spoke model and want to have all Subnet to Subnet as well as VNET to VNET traffic to pass through PA. SUBNETS: Do I need to add them to the already existing Interfaces below? Or make changes to the routing table?

SUBNET.png
FW.png
  • 709 Posts
  • 107 Subscriptions
Top Solution Authors
Top Liked Authors
Labels