VM-Series in the Public Cloud
The VM-Series is the virtualized form factor of the next-generation firewall. Use this discussion as a resource to discuss VM-Series deployments across public clouds like AWS, Microsoft Azure, Google Cloud Platform, Oracle Cloud, and Alibaba.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
VM-Series in the Public Cloud
The VM-Series is the virtualized form factor of the next-generation firewall. Use this discussion as a resource to discuss VM-Series deployments across public clouds like AWS, Microsoft Azure, Google Cloud Platform, Oracle Cloud, and Alibaba.
About VM-Series in the Public Cloud

Welcome to the VM-Series in the Public Cloud discussion forum! This community exists as a resource for you to discuss VM-Series deployments on AWS, Microsoft Azure, Google Cloud Platform, Oracle Cloud and Alibaba. We encourage you to engage in this rapidly growing community to share ideas, pose questions, and propose real-world solutions to any challenges that may arise.

Disclaimer:
This forum is provided for Live Community members to discuss and share information pertaining to the VM-Series deployments on AWS, Microsoft Azure, Google Cloud Platform Oracle Cloud and Alibaba. Please use the information from this forum at your own risk and make sure to test and verify proposed solutions presented here. For information on contacting Palo Alto Networks support, click here.

Discussions

Welcome to the VM-Series in the Public Cloud Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 3642 Views
  • 0 replies
  • 0 Likes

IPSec Tunnel is up but not passing traffic (On-Prem to Azure Palo Alto VM)

Hi guys. GOAL:I have an office in India with several users. They need to access a server in Azure that sits behind Virtual PA using Global Protect. I have successfully setup an IPSec Tunnel between my On-prem PA and an Azure PA, however, I am not passing any traffic in either direction.I suspect I might be over simplifying this deployment. I cho...

CMoore927039_1-1743429050105.png

Resolved! PaloAlto Firewall Firmware Upgrade (Not using Panorama)

Hi Guys,I have a query regarding VM Series Palo alto Firmware Upgrade.If I want to upgrade from 11.0.4 series to 11.1.6 series, Do I need to download and install 11.1 major release or I just have to download the 11.1 Major Update and then directly download and install 11.1.x version.NEED YOUR EXPERT ADVISE.

KishorTP by L1 Bithead
  • 3032 Views
  • 4 replies
  • 0 Likes

Resolved! Azure deployment: why SNAT is not needed for E/W traffic?

I've been checking the official Azure deployment guide, section Deploying Outbound and East-West Security. https://www.paloaltonetworks.com/resources/guides/azure-transit-vnet-deployment-guide What I don't understand why SNAT is not required for E/W traffic while it is required for inbound traffic. What makes LB use the same FW for return tr...

santonic by L6 Presenter
  • 2247 Views
  • 1 replies
  • 0 Likes

Resolved! AWS VM-Series Virtual Bundle1 Health Check issue with Gateway Load Balancer

I am following the video https://www.youtube.com/watch?v=c28ZwlhCIWE to implement a Centralized design using Bundle1. However, I am getting health check issue for the GWLB. I capture packets on the firewall and can see packet from the GWLB (10.100.0.94) to the FW (10.100.0.89). but no response. Target group always time out to get a response. I...

KimSiah_0-1685934698777.png
KimSiah_1-1685935127996.png
KimSiah by L1 Bithead
  • 4831 Views
  • 2 replies
  • 0 Likes

SSL Forward Proxy - Exclude certain IPs from decryption

Hi there, I'm running PA-VM (VM-300) version 9.1.16-h3 in Azure. I have configured response pages which work as expected. However, I cannot seem to stop decryption of SSL traffic for specific source IPs Out of frustration I have configured an any/any do not decrypt run and I can still cleary see SSL traffic being decrypted rather than just the c...

j.rowe by L0 Member
  • 1732 Views
  • 3 replies
  • 0 Likes

Resolved! Commit issue

Hi Team, I am using the VM-series FWs in Azure cloud, while commit I am receiving the following error. I am trying to change the DNS servers for the VM-series FW, as its not resolving the "updates.paloaltonetworks.com" After changing the DNS server & commit error received, Error while on GUI "Commit job was not queued since auto-comm...

PAN-OS Downgrade Resulted in Maintenance Mode with No Error Reason

Hello All, A bit of a weird one here: downgrading PAN-OS on a VM series NGFW from 11.2.0 to 11.1.4-h7. The device continually enters maintenance mode after it reboots to finish the installation process to 11.1.4-h7. The curious part is the maintenance entry reason: "No error entry reason detected". Please see the attached photo for clarity. ...

nohash4u by L3 Networker
  • 2481 Views
  • 4 replies
  • 0 Likes

Palo Alto VM Series Routing Problem in AWS

I am working on a greenfield proof of concept and I am running into some challenges. I am trying to get VPC A in Account A to route internet traffic through VPC B in Account B using VPC peering. The Palo Alto VM Series resides in VPC B. Is this configuration possible, or am I forced to use a Transit Gateway or IPSEC VPN? Account A / VPC A CIDR 1...

Not able to set the PANG admin account password after enabling FIPS-CC mode

Hello, When I set up my AWS PANG to FIPS-CC mode I am not able to set the admin account password. I tested the paloaltonetworks.panos.panos_admpwd module before enabling FIPS-CC and it works utilizing the priv key (RSA 4096). I successfully set up one firewall on FIPS-CC and set up the admin account password. My VM Mode Amazon AWSPANG Software V...

Welcome to the VM-Series in the Public Cloud Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 3642 Views
  • 0 replies
  • 0 Likes

DHCP client Interface on OCI PA VM

Hi wondering if come one can help me and I am new to PA I have deployed an OCI PA instance and configured all interfaces as Layer 3 > attached a V-Router and a Zone to interface and selected DHCP client. Still the Ethernet 1/1 is not showing an IP through PA-CLI. Same steps as below URL https://docs.paloaltonetworks.com/pan-os/10-2/pan-o...

Palo Alto Firewall in Azure backup

Got some PA-VM-FLEX in GCP and Azure. I could create a backup routine for the GCP ones, but, I can't complete a backup for the Azure one. Found some old topics saying it is not possible to backup VM PA in Azure with Azure backup. Is that true? So, if Azure Backup routine doesn't work, what's the way to backup the VM to restore in case needed?

isobrado by L0 Member
  • 4795 Views
  • 2 replies
  • 0 Likes

Can VM-FW in Azure provide IPv6?

Hello, I would like use VM-FW on Azure for IPv6?I looked at the following document. https://docs.paloaltonetworks.com/vm-series/11-1/vm-series-deployment/about-the-vm-series-firewall/ipv6-support-on-public-cloud It seems to provide IPv6 only on AWS. Is it right?

Cloud PKI and Global Protect user authentication

Hi, We are trying to deploy the user authentication for Global Protect using Cloud pki Azure certificate. Anyone has deployed this successfully. A certificate has been generated in Cloud pki and imported to Palo alto VM-100. Also we have pushed the certificate via intune to client devices for testing. it didnt worked. any idea?

  • 526 Posts
  • 107 Subscriptions
Top Liked Authors
Labels