VM-Series in the Public Cloud
The VM-Series is the virtualized form factor of the next-generation firewall. Use this discussion as a resource to discuss VM-Series deployments across public clouds like AWS, Microsoft Azure, Google Cloud Platform, Oracle Cloud, and Alibaba.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
VM-Series in the Public Cloud
The VM-Series is the virtualized form factor of the next-generation firewall. Use this discussion as a resource to discuss VM-Series deployments across public clouds like AWS, Microsoft Azure, Google Cloud Platform, Oracle Cloud, and Alibaba.
About VM-Series in the Public Cloud

Welcome to the VM-Series in the Public Cloud discussion forum! This community exists as a resource for you to discuss VM-Series deployments on AWS, Microsoft Azure, Google Cloud Platform, Oracle Cloud and Alibaba. We encourage you to engage in this rapidly growing community to share ideas, pose questions, and propose real-world solutions to any challenges that may arise.

Disclaimer:
This forum is provided for Live Community members to discuss and share information pertaining to the VM-Series deployments on AWS, Microsoft Azure, Google Cloud Platform Oracle Cloud and Alibaba. Please use the information from this forum at your own risk and make sure to test and verify proposed solutions presented here. For information on contacting Palo Alto Networks support, click here.

Discussions

Welcome to the VM-Series in the Public Cloud Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 3672 Views
  • 0 replies
  • 0 Likes

AWS Transit VPC CloudFormation

Can anyone assist with this CF Template? https://github.com/PaloAltoNetworks/aws-transit-vpcIt is outdated, and I can't figure out why it's getting hung up. First the AMI was old, so I updated that to 9.1, now it's created one PA in the transit VPC, but I can't login (password is wrong) so I'm guessing the bootstrap config (which I am just using...

PA firewall traffic to AWS API gateway

Planning to secure AWS infra using a VM firewall Palo Alto. Main AWS components are API Gateway & Lambda.Traffic from external network (public) comes to API gateway and to lambda. Is it possible to route incoming traffic via PA firewall to API gateway.

GlobalProtect --- Use machine certificate or a user certificate (without specifying Username Field)

Hi, I'm busy setting up GlobalProtect for a client, and already have LDAP authentication working. However the client requires a second factor for the authentication and went with certificates because they have an internal PKI. I've been trying to configure this to use machine certificates, so that only corporate machines would have access. I've ...

Want to use on-prem AD server to authenticate users on VM Series in Azure

I have a VM series firewall deployed in Azure with a VPN connection to my on-prem PA firewall. I have GP working on the VM firewall via local user database but I am unable to get the VM firewall to utilize my on-prem AD server to authenticate users. I have tried adjusting the service route but this does not work for dynamic-DHCP interfaces. H...

Express Route connection Palo Alto VM Firewall in Azure

Hello All Our Company has opted to deploy Palo Alto Firewall (VM 500 Series) in our Azure environment. One of my requirements is to establish connection between this Palo Alto Firewall and the Express Route Gateway in Azure. I would like to know if anyone here is able to setup this? if so, can you please tell me how to do so?

Azure NGFW active-active HA and Panorama requirements

Hi, we're currently evaluating the use of NGFW's for a new Azure deployment. Ideally, we need to deploy NGFW in an active-active HA pattern behind an Azure internal load balancer. The documentation appears to state that Panorama is required to support this configuration. Is this a hard requirement? Is it possible to enable active-active with Con...

Monitoring interface traffic with SNMP

Using physical PA boxes, this works fine. However, with the VM version (at least in Azure) it does not. Only the mgmt interface shows any traffic when reading interface statistics through SNMP. Is this a known issue? ethernet1/1 is the untrusted interface and I'd like to chart utilization of it, but it just stays 0. IF-MIB::ifInOctets.1 = Cou...

Site to Site VPN between AWS transit GW and PA FW in AWS

Hello First time posting and looking for help on solution ............i have a PA fw in AWS and i am attempting to setup a VPN to AWS transit GW.FW set up with ÖUTSIDE int using DHCP and and EIP attached ... AWS TGW (VPN) -------------------------------------------------AWS(single FW with DHCP)52.x.x.x ------------------------------------------...

how to assign same floating ip to multiple network interfaces on Azure?

Hi,I spun 2 PA VM-Series on Azure cloud. Both firewalls are up and running with HA but when I try to assign floating ip on public and private interfaces of firewall VMs as a secondary ip, I can do it on primary VM only. When I try to assign the same floating ip on secondary VM it gives me an error that ip already exists on primary VM. How do I a...

ZuberP by L0 Member
  • 4469 Views
  • 2 replies
  • 0 Likes

Resolved! PA cannot get update and cannot get internet access

HI,I deployed PA firewall in AWS. NAT is running in PA firewall and I am not using AWS NAT . Now the problem is all my hosts behind the PA firewall can access to internet by using PA NAT and pass through the PA firewall.But My firewall unreachable to internet. PA cannot ping 8.8.8.8 .My PA unreachable to paloalto site to get update.So I cannot g...

crypto by L2 Linker
  • 8082 Views
  • 3 replies
  • 0 Likes
  • 530 Posts
  • 107 Subscriptions
Labels