VM-Series in the Public Cloud
The VM-Series is the virtualized form factor of the next-generation firewall. Use this discussion as a resource to discuss VM-Series deployments across public clouds like AWS, Microsoft Azure, Google Cloud Platform, Oracle Cloud, and Alibaba.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
VM-Series in the Public Cloud
The VM-Series is the virtualized form factor of the next-generation firewall. Use this discussion as a resource to discuss VM-Series deployments across public clouds like AWS, Microsoft Azure, Google Cloud Platform, Oracle Cloud, and Alibaba.
About VM-Series in the Public Cloud

Welcome to the VM-Series in the Public Cloud discussion forum! This community exists as a resource for you to discuss VM-Series deployments on AWS, Microsoft Azure, Google Cloud Platform, Oracle Cloud and Alibaba. We encourage you to engage in this rapidly growing community to share ideas, pose questions, and propose real-world solutions to any challenges that may arise.

Disclaimer:
This forum is provided for Live Community members to discuss and share information pertaining to the VM-Series deployments on AWS, Microsoft Azure, Google Cloud Platform Oracle Cloud and Alibaba. Please use the information from this forum at your own risk and make sure to test and verify proposed solutions presented here. For information on contacting Palo Alto Networks support, click here.

Discussions

Welcome to the VM-Series in the Public Cloud Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 3650 Views
  • 0 replies
  • 0 Likes

Azure deployment. NAT rule assistance.

Howdy Group. I have a newbie question and wanted to ask the group. Maybe I am thinking too hard about it.Customer wanted a FW load balancer on both sides… and this was the screen capture of the solution. I have a nice easy question about incoming traffic and how it gets to its proper destination. My question is surrounding NAT and the need to ...

SteveCantwell_0-1591356510602.jpeg
SteveCantwell_1-1591356510609.png

HA on AWS

Hi,I would like to ask about PA FW HA on AWS.I am confused AWS said if we use loadbalancer or ELB ,we can not do PA HA.That mean even though I put PA is in front of ELB,we cannot do HA?vgw---->PA--->ELB--->ServersIf I want to do PA HA with ELB what should I do?if we deploy different availability zone,can we do PA HA ?

crypto by L2 Linker
  • 9528 Views
  • 8 replies
  • 0 Likes

Resolved! Azure natting and routing of internet inbound via Palo?

My Azure subscription will be hosting public websites. Azure handles the translation between the assigned public and private IP addresses for each website. My question concerns routing. Say i have a VM 10.1.1.10/24. The 10.1.1.0/24 subnet has a UDR which will send internet-bound traffic out through my Palo. But where can i assign a UDR for in...

Resolved! Azure No Arp

Hey All, I'm coming across a weird issue here. We have two subents in Azure. Let's call them Subnet1 and Subnet2 Subnet1 has a UDR to point traffic to the internal interface of the firewall. This works, we see the traffic come into the firewall. We don't see any return traffic from the server in subnet 2. There is a static route pointing to the ...

Issues Deploying PA VM in Azure with ARM Template

I need to deploy a PA VM in Azure, and cannot use the market place since I'm deploying in an existing Resource Group. When I try to deploy using the ARM template from github, it fails saying the subnet names are not valid in my vnet. I've tried creating the subnets with the exact names prior to deploying the template, and just creating brand new...

roll back mgmt-interface-swap=enable

add this to the user data on my vm instance after it was already configured.Not the brightest choice..The PA VM has become unreachable as a result and I'm trying to figure out how to roll this back. Is that possible?Can't find any documentation on rolling back this. Triedremoved the user-data and mgmt-interface-swap=disable. Unsuccessfully..Reco...

Unable to communicate eth1/2 interface

Hi Guys I have come here with lot of hope , I am doing my masters project and for that purpose my topology .My goal here is to show how paloalto can block the threats with its inbuilt IDS IPS ,url filtering , block traffic etc but right now I am facing a issue setting up a network I configured ping management on the firewall also I configured th...

PA Azure no public traffic ingressing

Hi Team, I've set up a public load balancer, with its respective backend pool pointing to the firewalls untrust interfaces and a test load balancing rule, but no matter what, nothing is ingressing on our public interface! The weird thing is, the untrust interface the firewall has, also has a public IP attached to it, and I'm not seeing any gener...

Azure ExpressRoute QinQ

We are moving to a new data center and i need to set up an Expressroute to Azure. The data center provides an L2 transit. This means i need an outer VLAN and and inner VLAN to setup the BGP connection. has anyone connected to Azure through a data center provider that only has L2? i can find Cisco docs for connections like this but nothing fr...

mcouch by L1 Bithead
  • 6719 Views
  • 1 replies
  • 2 Likes

Public Inbound Traffic not hitting the firewall

Hi Team, I have set-up a Palo Alto appliance in Azure and i am trying to allow public access (RDP) to a server in Azure via the firewall. Here's what I have done:Attached a public IP to the Untrust interface of the Firewall (NSG attached to allow all traffic)Defined this Public IP in Untrust ethernet in the firewallDefined a NAT and security pol...

How to secure DMZ and Internal traffic inside AWS Concept

Hi all, First, I 'm pretty with AWS...VPC is configured in the range 10.0.0.0/16.I have a firewall (PA VM) deployed with 3 interfaces (Untrust, DMZ, Trust).Untrust: 10.0.0.0/24, Internal : 10.0.1.0/24 (FW.1) , DMZ : 10.0.99.0/24 (FW.1).I created 3 Routing tables for each zone and assign each subnet into the RT.I changed the default route for rou...

Palo Alto Azure - second trust interface routing issue?

I am doing a lab in Azure with a VM-300. I have the three interfaces - trust, management, and untrust. I have this model working to protect 2 additional subnets that have VMs, I achieved east-west and north south protection, including microsegmentation. However, I was wondering if I can add a new interface to control security policies by zones ...

Samebeef by L0 Member
  • 3142 Views
  • 1 replies
  • 0 Likes
  • 526 Posts
  • 107 Subscriptions
Labels