VM-Series in the Public Cloud
The VM-Series is the virtualized form factor of the next-generation firewall. Use this discussion as a resource to discuss VM-Series deployments across public clouds like AWS, Microsoft Azure, Google Cloud Platform, Oracle Cloud, and Alibaba.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
VM-Series in the Public Cloud
The VM-Series is the virtualized form factor of the next-generation firewall. Use this discussion as a resource to discuss VM-Series deployments across public clouds like AWS, Microsoft Azure, Google Cloud Platform, Oracle Cloud, and Alibaba.
About VM-Series in the Public Cloud

Welcome to the VM-Series in the Public Cloud discussion forum! This community exists as a resource for you to discuss VM-Series deployments on AWS, Microsoft Azure, Google Cloud Platform, Oracle Cloud and Alibaba. We encourage you to engage in this rapidly growing community to share ideas, pose questions, and propose real-world solutions to any challenges that may arise.

Disclaimer:
This forum is provided for Live Community members to discuss and share information pertaining to the VM-Series deployments on AWS, Microsoft Azure, Google Cloud Platform Oracle Cloud and Alibaba. Please use the information from this forum at your own risk and make sure to test and verify proposed solutions presented here. For information on contacting Palo Alto Networks support, click here.

Discussions

Welcome to the VM-Series in the Public Cloud Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 3657 Views
  • 0 replies
  • 0 Likes

Terminal Services Agent (TSAgent) for Azure Windows Virtual Desktop?

Has anyone tried, or knows the compatibility / support status of TSAgent on Microsoft's Windows 10 WVD capability in Azure? We're using it at the moment and are also looking to add user-id to the Palo Alto setup but wanted to check the status of support for the TSAgent into it as it is Microsoft-Azure-only Windows 10 multi-user setup (as oppos...

Firewall forwarding log to Private IP of Panorama --- failing - (AWS - VM series)

I have an Panorama managing Firewalls (in different region , subscription) -- latched via Public IP. The firewalls are set to forward logs to Panorama. Unfortunately , the Firewalls are forwarding logs to Private IP address (which is failing cause of no connectivity).How can I force log forwarding to use Panorama's public IP address ? I have alr...

Resolved! Connectivity issue during failover test

We have three VPC and Transit Gateway along with Gateway Load Balancer deployed. Two VM series deployed in two AZs and We have test VPC that spans in three AZs Gateway Both FW registered in Target Group of Load Balancer using IP address. When FW are deployed interface swap is not used. Routes are configured as network diagram. I can ping from t...

Palo-post-image.JPG

Panorama (on EC2) config export to S3 (AWS)

I am design an config backup architecture for all the devices managed by Panorama (in AWS Cloud EC2) , dumping the devices configurations to S3 bucket . Is there anything natively present on this VM-series to utilize for this ? ++@jmeurer , @BPry , @Warby -- Any pointers .

Resolved! How to use Serial Console / EC2 connect in AWS

Hi All , Workstation(Dynamic Public IP) - > Used to access Panorama mgmt Interface (mgmt interface is allowing only that workstation IP) The management interface of my Panorama is configured to allow only one particular IP . Now since that workstation has got new IP , we cannot connect to the Panorama VM in AWS any more. Is there a possibilit...

Resolved! accessing a new Palo Alto firewall in the AWS.

Team, it has been some days that we got our virtual Palo Alto in the AWS and were able to change password using the initial access and the ppk file. However, due to some issues we had to get another firewall provisioned and I am unable to recreate the steps we had done earlier. After the instance is provisioned we downloaded the .pem file, cover...

nson2139 by L3 Networker
  • 9620 Views
  • 5 replies
  • 0 Likes

Can we advertise an IP of /32 from Palo Alto firewall to TG (Transit gateway) of AWS via BGP route advertisement

Loopback is configured on router in at a HUB site and we want to ping the IP of an instance in VPC-1.We are advertising the loopback IP (/32) from HUB site as shown in the above diagram. Loopback will be advertised from Hub site to TG (Transit gateway in AWS) via BGP , then this will be advertised from TG to Palo Alto firewall. Again from P...

KhurshidAnjum_0-1620318033696.png

Azure VNET peering

We are going with hub and spoke model, PA being the hub. When we peer a spoke VNET with the hub does the subnets in peered spoke also go through intrazone rules. Spoke-vnet - (subnet1, subnet2). Would subnet1 <> subnet2 communication pass through intrazone rules or does the whole spoke-net is seen as one large routed subnet.

raji_toor by L4 Transporter
  • 3595 Views
  • 1 replies
  • 0 Likes

SSL Decryption Inbound Inspection

On AWS we have deployed Application Load balancer after firewall. Can we configure ssl inbound inspection in this case?Will it work properly, whic certificate we have to import on firewall, server certificate or ALB certificate?

Source and destination both NAT required for inbound connection on Azure...

Hi Team, On public cloud Azure, why we need to translate source address also for Destination NAT?When i am translating source with trust interface IP it is working fine but when i am keeping the address as original it is not working. Kindly let me know is there any limitation on Public cloud for that we require source translation as well? Regard...

Website is slow when put behind vm-series 300

We have deployed vm-series 300 in AWS recently and put our production site behind it, but we are seeing a performance degradation, the website is taking around 2-3 mins to load for the first time which normally it didnt take, we have not put any url filtering profiles yet but yes we do have some security and nat profiles in place(which normal I ...

Screenshot 2021-04-12 at 11.29.58 PM.png
Tariq87 by L1 Bithead
  • 12213 Views
  • 14 replies
  • 0 Likes

Cloud VM Series disconnecting from Panorama after commit & push

Hello,I had 2 VM-series firewalls running 10.0.3 in AWS which I had connected to my on-prem Panorama also running 10.0.3.All looked fine until I made a change to the security policy and executed a commit & push to the VM's.After this the Panorama commit status seemed to hand and then eventually came back with an error "job failed because of ...

  • 527 Posts
  • 107 Subscriptions
Labels