VM-Series in the Public Cloud
The VM-Series is the virtualized form factor of the next-generation firewall. Use this discussion as a resource to discuss VM-Series deployments across public clouds like AWS, Microsoft Azure, Google Cloud Platform, Oracle Cloud, and Alibaba.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
VM-Series in the Public Cloud
The VM-Series is the virtualized form factor of the next-generation firewall. Use this discussion as a resource to discuss VM-Series deployments across public clouds like AWS, Microsoft Azure, Google Cloud Platform, Oracle Cloud, and Alibaba.
About VM-Series in the Public Cloud

Welcome to the VM-Series in the Public Cloud discussion forum! This community exists as a resource for you to discuss VM-Series deployments on AWS, Microsoft Azure, Google Cloud Platform, Oracle Cloud and Alibaba. We encourage you to engage in this rapidly growing community to share ideas, pose questions, and propose real-world solutions to any challenges that may arise.

Disclaimer:
This forum is provided for Live Community members to discuss and share information pertaining to the VM-Series deployments on AWS, Microsoft Azure, Google Cloud Platform Oracle Cloud and Alibaba. Please use the information from this forum at your own risk and make sure to test and verify proposed solutions presented here. For information on contacting Palo Alto Networks support, click here.

Discussions

Welcome to the VM-Series in the Public Cloud Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 3657 Views
  • 0 replies
  • 0 Likes

Resolved! PA-VM in Azure - multiple Zones? (e.g. DMZ,Trust,Unstrust,etc)

(sorry for the repost but the other forums/topic areas just don't ever seem to get a response when I post there and are much less active) In the deployment guides and conversations I've had it seems that the PA-VM firewall in Azure is typically designed around only four interfaces: trust, untrust, mgmt, HA. Two zones only: Trust/Untrust. Subn...

VM-Series on - Sizing, Internet traffic, Scalability Considerations

Dear Members, Hope you are doing well. We need your support for VM-series FW setup on Azure and considerations. We are planning to use 2 VM series in internet facing traffic and 2 VM series for internal traffic management. When deploying these VMs what points we need to keep in mind so that we can expand these in the future based on the tr...

N-Open by L1 Bithead
  • 1357 Views
  • 1 replies
  • 0 Likes

How to take VM series BYOL trial License?

Hello experts! I want to take a trial license for BYOL for the VM series next-generation firewall in Azure. Can you please let me know if we can have a trial license from Support? My second question is, can you provide me the link from where I can contact support for BYOL license purchasing? Thanks! Nidhi

Issues with Overlay Routing and AWS Gateway Load Balancer

Hey Folks, I am having difficulties to get Overlay routing working with AWS GWLB and I was wondering is it something that I am doing wrong or missing some configuration element... Any of you using AWS GWLB with overlay routing enabled? In my test setup when overlay routing is enabled the test VM is able to reach internet over the PAN FW - ...

SSL Forward Proxy Configuration Question

Trying to get SSL Forward Proxy configured for one of my sites and had a quick question around the configuration. For the certificate I need to put the IP address for the trust side of open flame-grilled. The problem is I am not sure which Interface IP address to use validation code... MYBKExperience All of my internal subnets and VLANs have int...

Rekey causes VPN tunnel to stop sending network traffic

Hello everybody, I'm having a weird issue with VPNs between a Palo Alto Cloud Firewall (PanOS9.1.3h) and Cisco Meraki Z3.All VPN Tunnels are established propely, but after a random period of time during the rekey step, a tunnel stays online, but network traffic can't be send anymore. We are currently having 5 of these connections with the same i...

PA VM-Series syslog ingest log to Azure log analytic workspace

Hi all, May i know if anyone had experience setting up VM Series FW to ingest the syslog to Azure log analytic? Is it the only is to setup a new intermediate syslog server install with Azure AMA, the VM series will send syslog to the new syslog server and AMA will ingest the log to log analytic ? Thanks for the help 🙂 Thank you, Meng Kiat

Resolved! AWS NAT not coming back

Hello,I tried to setup the nat, I can see my NAT and Security rule are being hit, but traffic is not flowing Bundle 1Interface Swap (tested this with no swap too, and it didn;t work)All of the 3 interfaces disabled src destinationall of them same sg, 0.0.0.0./0eth0 and eth1 are on the same subnet (public) with a route 0.0.0.0/0 to igweth0 and et...

Screen Shot 2019-11-13 at 10.03.52 PM.png
Screen Shot 2019-11-13 at 10.13.30 PM.png
Screen Shot 2019-11-13 at 10.23.49 PM.png
nronica by L1 Bithead
  • 11487 Views
  • 7 replies
  • 0 Likes

SSL Forward Proxy for custom url with host and path

SSL decrytion works if i set custom url with host only like www.example.local, but failed to decrypt if i set it as 'www.example.local/image/' i found article below, it should support custom url with host+path, but now i suspect will pan really support host+path decrption https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g0000...

Site-to-Site IPSEC between AWS and Azure (VM-Series)

I am trying to setup an IPSEC Site-to-Site VPN between our azure and aws environment, both of which have VM-300 series fw's running. I am able to get the tunnel up and see traffic coming across the link, but when i try and reach a resource on either end via PING/TRACE etc.. there is no response. I see the requests for the traffic in the PA going...

sscarola by L0 Member
  • 1939 Views
  • 1 replies
  • 0 Likes

Resolved! Equivalent of VLAN within Azure..

Probably one of the most simple questions going, but coming from a large on prem environment, I'm trying to understand how its meant to look from an AzurePOV.Typically, when we have a new server in say a /29 , i create a new sub interface for that vlan on the firewall, add a zone to it etc and crack on.Am i right in thinking that the "azure" way...

Same subnet VM not able to communicate to internet whereas other is working fine

I have PA-VA in Azure cloud, there is strange behavior for newly build VM 10.1.134.7 where logs are showing allow but machine not able to communicate to internet whereas existing VM 10.1.134.4 working fine. I just added new VM 10.1.134.7 in the same policy which is already there for existing VM 10.1.134.4.

No inbound traffic to external firewall interfaces in Azure and change to default NSG behaviour

Just wanted to share my experience with recent project and make you aware of the change in Azure default behaviour, which can save you some troubleshooting. As you may now, earlier this year Azure introduced Standard SKU for Load Balancers and Public IP addresses. The standard SKU has better functionality and the recommendations is to use it in ...

BatD by L4 Transporter
  • 8822 Views
  • 2 replies
  • 3 Likes

Risks of the AWS PA-VM license deactivation and reactivation

Can we get anyone explained the potential issues or risks when deactivating the PA-VM in AWS and reactivating them with different auth code? Here is the use case: We had a few PA-VM firewalls deployed in the different segments of our AWS environment. In the past, the licensing process and onboarding with Panorama are all manual processes and t...

Rockey by L0 Member
  • 4474 Views
  • 1 replies
  • 0 Likes
  • 527 Posts
  • 107 Subscriptions
Labels