VM-Series in the Public Cloud
The VM-Series is the virtualized form factor of the next-generation firewall. Use this discussion as a resource to discuss VM-Series deployments across public clouds like AWS, Microsoft Azure, Google Cloud Platform, Oracle Cloud, and Alibaba.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
VM-Series in the Public Cloud
The VM-Series is the virtualized form factor of the next-generation firewall. Use this discussion as a resource to discuss VM-Series deployments across public clouds like AWS, Microsoft Azure, Google Cloud Platform, Oracle Cloud, and Alibaba.
About VM-Series in the Public Cloud

Welcome to the VM-Series in the Public Cloud discussion forum! This community exists as a resource for you to discuss VM-Series deployments on AWS, Microsoft Azure, Google Cloud Platform, Oracle Cloud and Alibaba. We encourage you to engage in this rapidly growing community to share ideas, pose questions, and propose real-world solutions to any challenges that may arise.

Disclaimer:
This forum is provided for Live Community members to discuss and share information pertaining to the VM-Series deployments on AWS, Microsoft Azure, Google Cloud Platform Oracle Cloud and Alibaba. Please use the information from this forum at your own risk and make sure to test and verify proposed solutions presented here. For information on contacting Palo Alto Networks support, click here.

Discussions

Welcome to the VM-Series in the Public Cloud Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 3653 Views
  • 0 replies
  • 0 Likes

Resolved! VM information sources Missing random Data?

I have successfully turned up our vm information sources monitor on the firewall, but it appears to be missing random data, information, vlans, and networking mostly. I'm wondering if this is in relation to a timeout that is occurring because our VM's are so numerous. How would one confirm this? Almost all of the vm's I can get info on, it...

Sec101 by L4 Transporter
  • 5650 Views
  • 4 replies
  • 0 Likes

How can i Create more than 4 security zones on VM-100 on Azure??

We have deplyed a VM-100 FW on Azure on A D3_v2 VM. The VM support maxium of 4 vNICs to be attached to the firewall and i used them as (mgmt, trust, untrust, dmz). now i need to create more 2 DMZz with a diffewrent Subnets and Security zone, which is not supported ? Do you have any ideas on how to solve this Case ??? i must have two other isolat...

Autoscaling in AWS version 2.1 -Getting error with Application Template

Getting the below error while launching the application Template. Not sure what could be the reason behind it. Embedded stack arn:aws:cloudformation:us-east-1:632512868473:stack/application-exp-13-DeployNLBLambda-4AMN36HWPBE7/d2898ee0-8c89-11ea-a806-12301089d57f was not successfully created: The following resource(s) failed to create: [LambdaCu...

Configuring S2S VPN for Paloalto Deployed in Active/passive azure by using External LB IP

I have deployed Paloalto in HA A/P in Azure i need to establish S2S VPN to Onprem but i dont want to use floating IP because the failover time is very long in production environment ,can I use External Load Blanacer PIP and Create Load Balancing Rule (UDP 500 , 4500) to establish this VPN instead of floating IP .

Resolved! Second Public IP for VM-300 hosted in Azure

Hi everyone, our PAN NIC in Azure looks like this Primary IP: 192.168.1.4/1.1.1.1 Secondary IP: 192.168.1.8/1.1.1.2. On the Vm-300 interface eth1/1 (outside) recieves 192.168.1.4 via DHCP which is working fine. But how do I map the secondary IP? In this KB https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClDBCA0 it says...

AWS Transit Gateway

Hello, Is there planned AWS Transit Gateway integration? There is mention but no detail in this video: https://www.youtube.com/watch?v=6fhwoAwYrug Other than operational ease, the Transit Gateway advantages appear limited. Traffic between VPCs is not encrypted. VPC segmentation is via routing and does not traverse a firewall.

fwmike by L2 Linker
  • 17342 Views
  • 9 replies
  • 1 Likes

Resolved! Palo Alto Azure - second trust interface routing issue

Hello to all, I am doing a lab in Azure with a VM-300. I have the three interfaces - trust, management, and untrust. I have this model working to protect 2 additional subnets that have VMs, I achieved east-west and north south protection, including microsegmentation. However, I was wondering if I can add a new interface to control security poli...

route FW trust interface.png
LAN routes.png
LAN2 routes comm with LAN3.png
trust 2 route.png
Edwardo by L2 Linker
  • 17089 Views
  • 5 replies
  • 1 Likes

Resolved! VM interfaces vmxnet3

Hello,I'm using PA-VM with PAN-OS 9.0.4 on GNS3 2.2.5. I've configured four VMnets (0 - management, 1 - LAN_IT, 2 - LAN_USERS and 3 - SERVERS). I've access to management on IP address 10.0.64.3 on Eth0 port. I can't configure traffic ports e.g. e1/1, e1/2 because i can't see this interfaces. Any solutions? Configuration VMnets, GNS3 and PA on sc...

1.PNG
3.PNG
4.PNG
5.PNG
Werpet by L1 Bithead
  • 4559 Views
  • 1 replies
  • 0 Likes

More info on HA in Azure?

The documentation seems a bit light on detail. I have created a Service Principle in Azure and entered the data into my two firewalls as per these documents:https://docs.paloaltonetworks.com/vm-series/9-1/vm-series-deployment/set-up-the-vm-series-firewall-on-azure/configure-activepassive-ha-for-vm-series-firewall-on-azurehttps://docs.microsoft.c...

Resolved! Default route is not distributed to subscriber VPC - Bgp/Dynamic routing

Hello, currently doing a POC for Transit VPC setup in AWS with VM-Series firewalls and noticed that default route is not propagated on subscriber VPC routing tables. All the other subnets are propagating. Followed https://www.paloaltonetworks.com/resources/guides/aws-transit-vpc-model-deployment-guide as is but I'm using PAN-OS 9.1 and in the g...

Resolved! Azure bootstrap - indirect internet access

Hello, We are in the process of bootstrapping our ELA-licensed VM-series firewalls for use in Azure. The firewalls will not have internet access once spun up, so I am not able to simply load the auth code in the license folder. We will be leveraging Panorama to speak with the licensing server in order to load the licensed features on the firewal...

DMZ setup on Transit VPC (AWS)

I'm just wondering if anyone setup a DMZ on Transit firewalls in Transit VPC on AWS? Basically we need to have outbound to inbound NAT rule with a elastic ip address. Came across this link but not sure if this is the proper way of doing it. We would like achieve this through a dedicated VSYS but open for different options.

  • 526 Posts
  • 107 Subscriptions
Labels