VM-Series in the Public Cloud
The VM-Series is the virtualized form factor of the next-generation firewall. Use this discussion as a resource to discuss VM-Series deployments across public clouds like AWS, Microsoft Azure, Google Cloud Platform, Oracle Cloud, and Alibaba.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
VM-Series in the Public Cloud
The VM-Series is the virtualized form factor of the next-generation firewall. Use this discussion as a resource to discuss VM-Series deployments across public clouds like AWS, Microsoft Azure, Google Cloud Platform, Oracle Cloud, and Alibaba.
About VM-Series in the Public Cloud

Welcome to the VM-Series in the Public Cloud discussion forum! This community exists as a resource for you to discuss VM-Series deployments on AWS, Microsoft Azure, Google Cloud Platform, Oracle Cloud and Alibaba. We encourage you to engage in this rapidly growing community to share ideas, pose questions, and propose real-world solutions to any challenges that may arise.

Disclaimer:
This forum is provided for Live Community members to discuss and share information pertaining to the VM-Series deployments on AWS, Microsoft Azure, Google Cloud Platform Oracle Cloud and Alibaba. Please use the information from this forum at your own risk and make sure to test and verify proposed solutions presented here. For information on contacting Palo Alto Networks support, click here.

Discussions

AWS interface limits

Is the AWS VM limited to only 3 interfaces or can we add 3 more?  I was reading there may be limitations associated with machine type but wanted to be sure before we went down the path of changing that.

FIPS mode in Azure Government

Has anyone been successful in converting their VM-series appliances running in Azure Government to FIPS-CC mode? The SSH keys I created and allowed for FW management prior to the conversion were wiped out and resetting the keys via the Azure portal d

...

cl625410 by L0 Member
  • 2907 Views
  • 1 replies
  • 0 Likes

Resolved! NGFW HA on AWS with different AZ

Hi All,

 

I want to configure Active/Passive HA on AWS, but both the PA-Instance should be in different AZ. How can we achieve this?

I have referred below article: https://docs.paloaltonetworks.com/vm-series/9-1/vm-series-deployment/set-up-the-vm-series

...

Azure Network Watcher

Hello,

 

i want to do a packet capture on a VM interface using Network Watcher for some traffic on our VM-300 series NGFW but our CSP advises this is not possible.  The extensions section in Azure seems to confirm this.

 

 

can anyone advise if this featu

...

RyanJohnstone1144_0-1633536096660.png

Public IPs with NAT in IPSEC

I've got a rather bizarre setup that I'm trying to integrate with a new customer using a vm-series 300 in AWS. I have setup and established an IPSEC tunnel  (that even comes up when we attempt to send traffic over the tunnel). Where it gets complicat

...

NAT plan - Copy of Page 1.png

Azure LB Static Route and IPSEC failover

 

I am having the attached topology. I have two ipsec tunnel from two vm series paloalto to same peer ip which is in prisma cloud. 

on trust side I have an Azure load balancer which would send traffic to 2 firewalls and having a health probe as ssh to

...

ASingh106_0-1635861715552.png
  • 655 Posts
  • 91 Subscriptions
Labels