VM-Series in the Public Cloud
The VM-Series is the virtualized form factor of the next-generation firewall. Use this discussion as a resource to discuss VM-Series deployments across public clouds like AWS, Microsoft Azure, Google Cloud Platform, Oracle Cloud, and Alibaba.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
VM-Series in the Public Cloud
The VM-Series is the virtualized form factor of the next-generation firewall. Use this discussion as a resource to discuss VM-Series deployments across public clouds like AWS, Microsoft Azure, Google Cloud Platform, Oracle Cloud, and Alibaba.
About VM-Series in the Public Cloud

Welcome to the VM-Series in the Public Cloud discussion forum! This community exists as a resource for you to discuss VM-Series deployments on AWS, Microsoft Azure, Google Cloud Platform, Oracle Cloud and Alibaba. We encourage you to engage in this rapidly growing community to share ideas, pose questions, and propose real-world solutions to any challenges that may arise.

Disclaimer:
This forum is provided for Live Community members to discuss and share information pertaining to the VM-Series deployments on AWS, Microsoft Azure, Google Cloud Platform Oracle Cloud and Alibaba. Please use the information from this forum at your own risk and make sure to test and verify proposed solutions presented here. For information on contacting Palo Alto Networks support, click here.

Discussions

Welcome to the VM-Series in the Public Cloud Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 3652 Views
  • 0 replies
  • 0 Likes

real client IP in VM series firewall in GCP cloud

Hi Members, I have a setup in GCP cloud wherein I have to deploy set of vm series palo firewalls between load balancer and real servers.The problem is I need to know the exact IP address of the client whereas if you see in firewall logs, you will get to see only the IP address subnet of external load balancer.can anyone help me on this ?? thanks...

VMs cannot access the Internet

Hello, Hope I get some direction/solution here. VM (10.9.8.4) can ping trusted interface (10.8.130.4) of PA but with packet loss!!! However, tracert 8.8.8.8 does not show the trusted interface as next hop....request timed out. Cannot go to the Internet. All NSG set to allowed. PA has the most basic config at this stage with Allow All Policy. Tr...

AWS VM-series - untrust interface - eating packets

Hi Guys, I am working on inbound (from the internet) flow on the VM-series untrust interface directly. Set up -VM-series FW - 3 interface -- Mgmt , Untrust , Trust Client -> Internet GW -> EIP -> Firewall untrust interface - eth1/1 - > (SNAT - eth1/2 ; DNAT - Server private IP ) -> Server In the monitor log, I can see the SNAT &a...

Resolved! No traffic between VMs and PA in Azure

Hi there, We have deployed PA-VM in Azure and there are other 4 VMs within the same vnet. There are NSGs on each interface of PA (mgmt, trusted, untrusted) and also on the VMs. There is allowed-all rule in the PA with intrazone default rule logging enabled. Ping is also enabled. There is no switch or other device between the VMs and PA. Routing ...

Request for Refund

Hi, I selected the wrong bundle of Palo Alto Firewall by mistake and subscribed it for an year. I later on cancelled the subscription but still got charged for it. I didn't not initialize any machine so I don't have a CPU id to sign up for a support account. How should I submit a refund request? Any help will be highly appreciated. Thanks.

Not able to apply evaluation license to PA-VM in eve-ng running GCC

Hello EveryoneI have couple of PA-VM 50 evaluation licenses and I was successfully able to apply them in the PA-VMs in EVE-NG running on my VMware workstation. But due to hardware limitation I decided to build my eve-ng in Google Cloud Console (GCC) and so far the experience was great, I was able to run all my servers, routers, switches and even...

PAVM-GCC-1.jpg
PAVM-GCC-2.jpg
PAVM-GCC-3.jpg
PAVM-GCC-4.jpg

Failed plugin validation - Panorama 10.1.0

hello I am using the following versionsPanorama 10.1.0Azure plugin: 3.1.0VM series plugin: 1.0.11 I am configuring Panorama for VM series orchestration as per the document and video below:https://docs.paloaltonetworks.com/vm-series/10-1/vm-series-deployment/set-up-the-vm-series-firewall-on-azure/panorama-orchestrated-deployments-in-azure/orches...

ISP get slow speed

One of my Clients getting Low speed through the firewall when they Connect to Laptop They get the speed.They have a dual isp one is 20 mbps. and the second is 10 mbps.If there is an article please share the KB of palo altoPA-VM VM-50

Azure Public Load Balancer Public IP

Hello Everyone, I am pretty new to this Palo cloud transit VNet idea. So please excuse me if this is a dumb question 🙂 I have been reading the design guides from Palo and that leads to this question. As per the docs, we use a public load balancer to accept traffic from the internet and the firewall will destination NAT it to inside VMs. So the ...

Transit VNet.JPG
a-techie by L1 Bithead
  • 3469 Views
  • 1 replies
  • 0 Likes

Resolved! Autoscaling in AWS version 3 (Gateway load balancer integration) - Firewalls never register in Panorama

Hi all, This is a really helpful group and I hope you can help with this challenge. 1. We deployed the ASG using Template 3.0 - all successful.2. Firewalls bootstrapped successfully.3. The lambda had a problem enabling the VM-Series element for cloudwatch (stated error 13 in use but) managed to make the change manually4. Everything else error fr...

Resolved! Using the ASG Cloudformation template. The licensing API doesn't work to allow lambda to connect.

After a lot of challenges using the template we have one problem left (hopefully) We downloaded the licensing api and successfully applied to panorama. When our lambda tries to connect using the following type string: https://[Panorama IP]/api/?type=op&key=[API Key[&cmd=%3Cshow%3E%3Csystem%3E%3Cinfo/%3E%3C/system%3E%3C/show%3E We receive...

Resolved! GCP VM-100 deployment issue

I am trying to programmatically create a compute instance running the VM series Next-Gen bundle 2 PAYG image. Can anyone tell me how this can be done? I understand that I need to load the image into cloud Storage which I use in my code so that the compute vm knows where to get the PAN-OS image. However, Iit is not clear to me how I can get the P...

Autoscaling in AWS version 3 (Gateway load balancer integration) - Decouple the Lambda scripts for autoscaling when not using the template

Hi everyone, We are looking to deploy the virtual firewalls in AWS in an autoscaling group and plan to build the AWS infrastructure (GLB, subnets, routing tables etc using terraform). The lambda scripts with the Cloud formation template are extensive (3500 lines of code) to monitor for firewalls being added/removed as part of a scaling event and...

Terminal Services Agent (TSAgent) for Azure Windows Virtual Desktop?

Has anyone tried, or knows the compatibility / support status of TSAgent on Microsoft's Windows 10 WVD capability in Azure? We're using it at the moment and are also looking to add user-id to the Palo Alto setup but wanted to check the status of support for the TSAgent into it as it is Microsoft-Azure-only Windows 10 multi-user setup (as oppos...

  • 526 Posts
  • 107 Subscriptions
Labels