VM-Series in the Public Cloud
The VM-Series is the virtualized form factor of the next-generation firewall. Use this discussion as a resource to discuss VM-Series deployments across public clouds like AWS, Microsoft Azure, Google Cloud Platform, Oracle Cloud, and Alibaba.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
VM-Series in the Public Cloud
The VM-Series is the virtualized form factor of the next-generation firewall. Use this discussion as a resource to discuss VM-Series deployments across public clouds like AWS, Microsoft Azure, Google Cloud Platform, Oracle Cloud, and Alibaba.
About VM-Series in the Public Cloud

Welcome to the VM-Series in the Public Cloud discussion forum! This community exists as a resource for you to discuss VM-Series deployments on AWS, Microsoft Azure, Google Cloud Platform, Oracle Cloud and Alibaba. We encourage you to engage in this rapidly growing community to share ideas, pose questions, and propose real-world solutions to any challenges that may arise.

Disclaimer:
This forum is provided for Live Community members to discuss and share information pertaining to the VM-Series deployments on AWS, Microsoft Azure, Google Cloud Platform Oracle Cloud and Alibaba. Please use the information from this forum at your own risk and make sure to test and verify proposed solutions presented here. For information on contacting Palo Alto Networks support, click here.

Discussions

Welcome to the VM-Series in the Public Cloud Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 3502 Views
  • 0 replies
  • 0 Likes

Source and destination both NAT required for inbound connection on Azure...

Hi Team, On public cloud Azure, why we need to translate source address also for Destination NAT?When i am translating source with trust interface IP it is working fine but when i am keeping the address as original it is not working. Kindly let me know is there any limitation on Public cloud for that we require source translation as well? Regard...

Strange issue- VM-Series Ext interface with Elastic IP in AWS not reachable. (outside test PC reachable)

I am trying to POC a scenario for my customer in AWS with dual Palo Alto in HA within same availability zone. (We need to build a site to Site VPN tunnel from on-Premises to AWS Palo behind IGW) I am facing a strange issue. I an not able to reach the outside Elastic IP address of Palo.(I am able to reach the public IP on Management interface). T...

Palo_Lab.PNG

Website is slow when put behind vm-series 300

We have deployed vm-series 300 in AWS recently and put our production site behind it, but we are seeing a performance degradation, the website is taking around 2-3 mins to load for the first time which normally it didnt take, we have not put any url filtering profiles yet but yes we do have some security and nat profiles in place(which normal I ...

Screenshot 2021-04-12 at 11.29.58 PM.png
Tariq87 by L1 Bithead
  • 11564 Views
  • 14 replies
  • 0 Likes

Cloud VM Series disconnecting from Panorama after commit & push

Hello,I had 2 VM-series firewalls running 10.0.3 in AWS which I had connected to my on-prem Panorama also running 10.0.3.All looked fine until I made a change to the security policy and executed a commit & push to the VM's.After this the Panorama commit status seemed to hand and then eventually came back with an error "job failed because of ...

IPSEC Tunnel to Azure - Odd pattern

We received a report of some connectivity issues with an IPSEC tunnel between a Palo 5220 (9.1.8) and Azure VNG Looking at this deeper, we see an odd rekey pattern happening with the IPSEC Rekey. Every 4th rekey is a non-rekey and occurs short. Can anyone help us understand what could possibly be causing this? Its happening only on Azure VPN ...

Resolved! GWLB and Palo Alto Zones

I am building some PA VM's behind GWLB. i would like to do traffic between VPC's to flow through this GWLB and TGW which appears to be possible however i can not find any documentation on how to seperate these into different Zones within the palo. I would like the Traffic from VPC A and VPC B to be mapped to different Palo Alto Zones. I was told...

PA-VM-01 can't ping to PA-AM-02 via External Interface.

Hi all, I am a new Palo Alto firewalls learner, I start the lab which has 2 PA-VMs direct connected (in the purpose of testing VPN site to site) but it can't ping to each other it showing destination unreachable. I had tried to configure Interface management by allowed ping on both PAs but it's still not working, please help!! Thanks,

Chheang by L0 Member
  • 2548 Views
  • 1 replies
  • 0 Likes

Issue With adding Secondary IPs to Azure VM

Recently, we've been having an issue with assigning secondary IPs to our Azure PA VMs where if we add a new IP, it doesn't seem to apply until we add a second IP. After the 2nd IP is added, the first starts working but the 2nd doesn't work. The Palo interfaces are set to DHCP and IPs are assigned to the Azure NIC. Same issue on 3 firewalls in di...

Ash2k by L2 Linker
  • 3541 Views
  • 1 replies
  • 0 Likes

Azure VM Backup

Hello, we are trying to take an Azure back up of the Palo Alto VM but our CSP is reporting an issue with the backup agents on the Palo VM. The backup Pre checks are failing with a warning that it "cannot communicate with the vm agent for snapshot status vm sub task timed out" Can anyone guide on where i should look for where this issue may be,...

Source / Destination NAT question

Have a case where i want to re-write the source-IP and destination-port on traffic heading to the internet. So coming in from the private network as 10.1.1.1 -> 2.2.2.2:4000 and changing as it leaves to the internet to 3.3.3.3 -> 2.2.2.2:443. The part i'm struggling with is preserving the original destination IP. For the NAT policy rule, ...

AWS Transit Gateway Deployment Multi-Security-VPC-Outbound

Hi Expert , First of all, I newbie for deployment on a public cloud such as AWS by the way I guess and would like to know on deployment guide of Palo alto about securing application on was about multi-security vpc for outbound traffic the VPN attachment that means it attaches on tgw between AWS to On-Primes or between firewall cross AZ or both ...

  • 704 Posts
  • 107 Subscriptions
Top Liked Authors
Labels