VM-Series in the Public Cloud
The VM-Series is the virtualized form factor of the next-generation firewall. Use this discussion as a resource to discuss VM-Series deployments across public clouds like AWS, Microsoft Azure, Google Cloud Platform, Oracle Cloud, and Alibaba.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
VM-Series in the Public Cloud
The VM-Series is the virtualized form factor of the next-generation firewall. Use this discussion as a resource to discuss VM-Series deployments across public clouds like AWS, Microsoft Azure, Google Cloud Platform, Oracle Cloud, and Alibaba.
About VM-Series in the Public Cloud

Welcome to the VM-Series in the Public Cloud discussion forum! This community exists as a resource for you to discuss VM-Series deployments on AWS, Microsoft Azure, Google Cloud Platform, Oracle Cloud and Alibaba. We encourage you to engage in this rapidly growing community to share ideas, pose questions, and propose real-world solutions to any challenges that may arise.

Disclaimer:
This forum is provided for Live Community members to discuss and share information pertaining to the VM-Series deployments on AWS, Microsoft Azure, Google Cloud Platform Oracle Cloud and Alibaba. Please use the information from this forum at your own risk and make sure to test and verify proposed solutions presented here. For information on contacting Palo Alto Networks support, click here.

Discussions

Welcome to the VM-Series in the Public Cloud Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 3650 Views
  • 0 replies
  • 0 Likes

VM firewall HA on AWS

Hello,We need to deploy two VM series firewalls on AWS cloud in HA. Both firewalls will be in different AZ. I have below questions-1. Is it possible to do such configuration?2. If yes, please share any reference guide? Thank you in advance

BK0007 by L2 Linker
  • 2406 Views
  • 1 replies
  • 0 Likes

Azure Network Watcher VM extension?

Hello... is it possible to install that Azure Network Watcher VM extension to enable traces and packet captures from the PA VM to the Azure gateway? It would be handy to help troubleshoot connectivity issues between the PA and the GW. Thank you.

eosminer by L1 Bithead
  • 7881 Views
  • 4 replies
  • 0 Likes

ESXI Server - Inside Host is on Same Port Group as Palo Alto FW Inside Interface and Pings are failing from all inside hosts

I have a ESXI Server with firewall (Inside, DMZ and Outside) zones Palo Alto has a rule to allow interzone traffice from inside to outside Palo Alto has NAT configured for Outside Interface When I try to ping from host to host on in the same port group...all is good. When I try to ping to the Inside Firewall Interface, the ping times out..."De...

ETate by L1 Bithead
  • 2471 Views
  • 1 replies
  • 0 Likes

problems to configure internal load balancer on GCP

Hi team, we are working in a lab environment, following the recommended architecture manual:https://www.paloaltonetworks.com/apps/pan/public/downloadResource?pagePath=/content/pan/en_US/resources/guides/gcp-shared-vcp-deployment-guideWe have followed the procedure, but we have been experiencing issues on the GCP internal load balancer deployment...

AJuarez by L0 Member
  • 3343 Views
  • 2 replies
  • 0 Likes

Incomplete error

I have a Linux VM trying to send traffic over port 25 smtp and I am getting an incomplete message on the PAN-VM. I have done a few tests with port 587 and works fine, I have gone through the rules in focus detail to verify the rule should allow it but still no go. Any ideas where else I can look or tools to use to narrow down this issue? Thanks

VM-Series License limits - VIrtual Routers

I have seen documentation outlining the differences in the number of Rules, VPNs, sessions and zones for each VM-Series license, but i think there are also limits on the number of Virtual Routers you can create on each VM license.Is there any documentation to illustrate this difference?This is necessary information if you are deploying the Load ...

VM-Series firewalls in Azure with multiple private zone NICs behind Internal LB not maintaining session

I have a use-case: There are 2 VM-Series Palo-alto firewalls deployed in Azure behind Internal Load Balancer. Each firewall has 3 private zone interfaces and Internal LB has 3 Frontend-IPs, one for each firewall interface subnet, the request traffic from one private azure subnet lands on Internal LB Frontend-IP1 and distributed to firewall1 inte...

Site to site VPN tunnel in Azure

We need to build a site to site tunnel between on premise and Azure cloud so we are planning to use Palo Alto firewall in Azure, since we have a requirement to hide VNET subnet in cloud as well as in on premise subnets from each other while sending traffic between them, can we configure Port address translation.

VM-Series High Availability on ESXi?

Hi there, I am really new in network virtualization. I want to ask about high availability in Palo Alto VM-Series. We are going to buy two VM-200 (1 for Internal, 1 for External) and will install it on ESXi. I want ask for your advice.1.Should I buy another two VM-200 for the redudancy?2.or let the vSphere (HA or FT, I don't know which one shoul...

Palo Alto 10.0 firewall in HA in Azure

Hi, We are trying to test VM series firewall in HA without load-balancer and following the documentation listed on PA website, can someone confirm if the document is well tested and we are seeing issues in connectivity and Template for secondary firewall is not clearly identified. Please let me know if there is any working template for HA. Also...

Panorama network and device templates not syncing to firewall

Hello, We are trying to set up a new deployment in AWS consisting of two firewalls managed by a Panorama server. For starters, we deployed one firewall and one Panorama instance. They are in the same VPC, different subnets. Security groups currently allow all TCP to/from the Panorama server and the firewall. Both Panorama and the firewall have ...

PA-VM8.1.0 Initial Password Not Working

Hello, I installed PA-VM8.1.0-KVM-8.1.0.qcow2 in my GNS3 lab and the username/password admin/admin is not working. Is there another username/password I can try? I also loaded PA-VM8.1.0-KVM-8.0.0.qcow2 and PA-VM7.1.0-KVM-8.1.0.qcow2 and the username/password admin/admin does not work for those either.

mwaldrep by L0 Member
  • 4905 Views
  • 1 replies
  • 0 Likes
  • 526 Posts
  • 107 Subscriptions
Labels