VM-Series in the Public Cloud
The VM-Series is the virtualized form factor of the next-generation firewall. Use this discussion as a resource to discuss VM-Series deployments across public clouds like AWS, Microsoft Azure, Google Cloud Platform, Oracle Cloud, and Alibaba.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
VM-Series in the Public Cloud
The VM-Series is the virtualized form factor of the next-generation firewall. Use this discussion as a resource to discuss VM-Series deployments across public clouds like AWS, Microsoft Azure, Google Cloud Platform, Oracle Cloud, and Alibaba.
About VM-Series in the Public Cloud

Welcome to the VM-Series in the Public Cloud discussion forum! This community exists as a resource for you to discuss VM-Series deployments on AWS, Microsoft Azure, Google Cloud Platform, Oracle Cloud and Alibaba. We encourage you to engage in this rapidly growing community to share ideas, pose questions, and propose real-world solutions to any challenges that may arise.

Disclaimer:
This forum is provided for Live Community members to discuss and share information pertaining to the VM-Series deployments on AWS, Microsoft Azure, Google Cloud Platform Oracle Cloud and Alibaba. Please use the information from this forum at your own risk and make sure to test and verify proposed solutions presented here. For information on contacting Palo Alto Networks support, click here.

Discussions

Welcome to the VM-Series in the Public Cloud Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 3657 Views
  • 0 replies
  • 0 Likes

Resolved! GWLB and Palo Alto Zones

I am building some PA VM's behind GWLB. i would like to do traffic between VPC's to flow through this GWLB and TGW which appears to be possible however i can not find any documentation on how to seperate these into different Zones within the palo. I would like the Traffic from VPC A and VPC B to be mapped to different Palo Alto Zones. I was told...

PA-VM-01 can't ping to PA-AM-02 via External Interface.

Hi all, I am a new Palo Alto firewalls learner, I start the lab which has 2 PA-VMs direct connected (in the purpose of testing VPN site to site) but it can't ping to each other it showing destination unreachable. I had tried to configure Interface management by allowed ping on both PAs but it's still not working, please help!! Thanks,

Chheang by L0 Member
  • 2669 Views
  • 1 replies
  • 0 Likes

Issue With adding Secondary IPs to Azure VM

Recently, we've been having an issue with assigning secondary IPs to our Azure PA VMs where if we add a new IP, it doesn't seem to apply until we add a second IP. After the 2nd IP is added, the first starts working but the 2nd doesn't work. The Palo interfaces are set to DHCP and IPs are assigned to the Azure NIC. Same issue on 3 firewalls in di...

Ash2k by L2 Linker
  • 3641 Views
  • 1 replies
  • 0 Likes

Azure VM Backup

Hello, we are trying to take an Azure back up of the Palo Alto VM but our CSP is reporting an issue with the backup agents on the Palo VM. The backup Pre checks are failing with a warning that it "cannot communicate with the vm agent for snapshot status vm sub task timed out" Can anyone guide on where i should look for where this issue may be,...

Source / Destination NAT question

Have a case where i want to re-write the source-IP and destination-port on traffic heading to the internet. So coming in from the private network as 10.1.1.1 -> 2.2.2.2:4000 and changing as it leaves to the internet to 3.3.3.3 -> 2.2.2.2:443. The part i'm struggling with is preserving the original destination IP. For the NAT policy rule, ...

Resolved! Azure - no traffic to untrust public ip

I've followed the instructions here and can't get traffic to my untrust public IP: https://www.paloaltonetworks.com/documentation/71/virtualization/virtualization/set-up-the-vm-series-firewall-in-azure/deploy-the-vm-series-firewall-in-azure-solution-template I'm using the Azure BYOL template (version 8.1) and can see my PA interfaces getting the...

dmarlow by L1 Bithead
  • 26535 Views
  • 17 replies
  • 0 Likes

AWS with EIP public ip address setup

Hi All, pretty dumb question here. I've setup the VM-series in AWS and attached three interfaces to the box. The intention here is to setup NAT (due to overlapping IP space) over a site-to-site VPN. * management, I can get to this just fine and use the web console etc (call this 10.0.0.2/24)* "inside" attached to eth1/1, is connected to our pri...

HA VM-series PALO ALTO On cloud Azure

Hi All,I have followed a procedure HA sounds good : everything is green.BUT (there is a but) : the floating IP is not moving when I am doing a failover from HA1 to HA2.I am on PAN OS 9.0.1. The troubleshooting feature said it is ok.The Azure Active Directory Service Principal seems good.Any hint ?Thanks ! smart-linksyssmartwifilinksyssmartwif...

Resolved! Certificates not showing up GUI

Has anybody ran into an issue where the certificates are in the cert store are NOT showing up in gui, but they are in the CLI? On a vm-300 that exported device state and now I can't see them via the gui. I did this on two other FW's, different regions, and no issues. Thanks!

East west traffic in transit gateway with vpn attachment with firewall...

Hi Team, i am deploying two vm firewall in different AZ of same VPCI will configure VPN attachment with firewall for east west and outbound traffic to be scanned by firewall. My concern is for the return traffic of east west from the vm firewall.The outbound traffic will pass with vpn attachment but how the return traffic will flow?

Resolved! PA-VM series limitation without trial license.

Hi, I'm new to Palo Alto Networks. I'm using VM for study purpose. Can I have the information of limitations using the VM without trial license installed? The deployments are still in light environment. We will see the plan for next subject if the licenses are required. Somewhat on several features case, the PA-VM doesn't provide them and can ma...

Furqon by L0 Member
  • 9938 Views
  • 2 replies
  • 0 Likes

Supported SR-IOV for Palo Alto in WS

Hello everybody,I see that we have SR-IOV and DPDK modes supported for Palo Alto in AWS and understand that DPDK is proffered mode which provides fast processing. 192168101.comso are there any specific situation where SR-IOV mode is preferred over DPDK?are you know? 19216811.dev

  • 527 Posts
  • 107 Subscriptions
Labels