VM-Series in the Public Cloud
The VM-Series is the virtualized form factor of the next-generation firewall. Use this discussion as a resource to discuss VM-Series deployments across public clouds like AWS, Microsoft Azure, Google Cloud Platform, Oracle Cloud, and Alibaba.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
VM-Series in the Public Cloud
The VM-Series is the virtualized form factor of the next-generation firewall. Use this discussion as a resource to discuss VM-Series deployments across public clouds like AWS, Microsoft Azure, Google Cloud Platform, Oracle Cloud, and Alibaba.
About VM-Series in the Public Cloud

Welcome to the VM-Series in the Public Cloud discussion forum! This community exists as a resource for you to discuss VM-Series deployments on AWS, Microsoft Azure, Google Cloud Platform, Oracle Cloud and Alibaba. We encourage you to engage in this rapidly growing community to share ideas, pose questions, and propose real-world solutions to any challenges that may arise.

Disclaimer:
This forum is provided for Live Community members to discuss and share information pertaining to the VM-Series deployments on AWS, Microsoft Azure, Google Cloud Platform Oracle Cloud and Alibaba. Please use the information from this forum at your own risk and make sure to test and verify proposed solutions presented here. For information on contacting Palo Alto Networks support, click here.

Discussions

Welcome to the VM-Series in the Public Cloud Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 3684 Views
  • 0 replies
  • 0 Likes

Certificates on Palo alto - Types to be installed

Dear memebers, We are going to use palo alto vm series firewall on Azure and like to take your advice on the type of certificates to be installed. The firewalls will be public facing front end by Azure application gateway. The FW will be protecting a web site running on the background. If my understanding is correct, I need 2 types of certi...

N-Open by L1 Bithead
  • 1373 Views
  • 1 replies
  • 0 Likes

Palo alto - VM series - vCPU Count

Dear memebers, I need your advice on the vCPU count of the Palo alto. Our old employee has left the company and we have received below configuration from palo alto based on the requirements, Below is the spec. Install 6 VM NGFWs with 8 vCPUs, Each virtual firewall will havethe following licenses: Advanced Threat Prevention, AdvancedURL Filteri...

N-Open by L1 Bithead
  • 2113 Views
  • 1 replies
  • 0 Likes

Resolved! VM Series FW - Traffic from Cloudflare

Dear Members, Hope you are doing well. We are looking to protect our 2 internet facing VM series firewall by using cloudflare. The plan is use the magic transit tunnel from cloudflare and pass the traffic to internet facing vm series. Once i create the magic transit tunnel at cloud flare side, what should be the end of the tunnel connected...

N-Open by L1 Bithead
  • 7014 Views
  • 5 replies
  • 0 Likes

Resolved! PA-VM in Azure - multiple Zones? (e.g. DMZ,Trust,Unstrust,etc)

(sorry for the repost but the other forums/topic areas just don't ever seem to get a response when I post there and are much less active) In the deployment guides and conversations I've had it seems that the PA-VM firewall in Azure is typically designed around only four interfaces: trust, untrust, mgmt, HA. Two zones only: Trust/Untrust. Subn...

VM-Series on - Sizing, Internet traffic, Scalability Considerations

Dear Members, Hope you are doing well. We need your support for VM-series FW setup on Azure and considerations. We are planning to use 2 VM series in internet facing traffic and 2 VM series for internal traffic management. When deploying these VMs what points we need to keep in mind so that we can expand these in the future based on the tr...

N-Open by L1 Bithead
  • 1368 Views
  • 1 replies
  • 0 Likes

How to take VM series BYOL trial License?

Hello experts! I want to take a trial license for BYOL for the VM series next-generation firewall in Azure. Can you please let me know if we can have a trial license from Support? My second question is, can you provide me the link from where I can contact support for BYOL license purchasing? Thanks! Nidhi

Issues with Overlay Routing and AWS Gateway Load Balancer

Hey Folks, I am having difficulties to get Overlay routing working with AWS GWLB and I was wondering is it something that I am doing wrong or missing some configuration element... Any of you using AWS GWLB with overlay routing enabled? In my test setup when overlay routing is enabled the test VM is able to reach internet over the PAN FW - ...

SSL Forward Proxy Configuration Question

Trying to get SSL Forward Proxy configured for one of my sites and had a quick question around the configuration. For the certificate I need to put the IP address for the trust side of open flame-grilled. The problem is I am not sure which Interface IP address to use validation code... MYBKExperience All of my internal subnets and VLANs have int...

Rekey causes VPN tunnel to stop sending network traffic

Hello everybody, I'm having a weird issue with VPNs between a Palo Alto Cloud Firewall (PanOS9.1.3h) and Cisco Meraki Z3.All VPN Tunnels are established propely, but after a random period of time during the rekey step, a tunnel stays online, but network traffic can't be send anymore. We are currently having 5 of these connections with the same i...

PA VM-Series syslog ingest log to Azure log analytic workspace

Hi all, May i know if anyone had experience setting up VM Series FW to ingest the syslog to Azure log analytic? Is it the only is to setup a new intermediate syslog server install with Azure AMA, the VM series will send syslog to the new syslog server and AMA will ingest the log to log analytic ? Thanks for the help 🙂 Thank you, Meng Kiat

Resolved! AWS NAT not coming back

Hello,I tried to setup the nat, I can see my NAT and Security rule are being hit, but traffic is not flowing Bundle 1Interface Swap (tested this with no swap too, and it didn;t work)All of the 3 interfaces disabled src destinationall of them same sg, 0.0.0.0./0eth0 and eth1 are on the same subnet (public) with a route 0.0.0.0/0 to igweth0 and et...

Screen Shot 2019-11-13 at 10.03.52 PM.png
Screen Shot 2019-11-13 at 10.13.30 PM.png
Screen Shot 2019-11-13 at 10.23.49 PM.png
nronica by L1 Bithead
  • 11557 Views
  • 7 replies
  • 0 Likes

SSL Forward Proxy for custom url with host and path

SSL decrytion works if i set custom url with host only like www.example.local, but failed to decrypt if i set it as 'www.example.local/image/' i found article below, it should support custom url with host+path, but now i suspect will pan really support host+path decrption https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g0000...

Site-to-Site IPSEC between AWS and Azure (VM-Series)

I am trying to setup an IPSEC Site-to-Site VPN between our azure and aws environment, both of which have VM-300 series fw's running. I am able to get the tunnel up and see traffic coming across the link, but when i try and reach a resource on either end via PING/TRACE etc.. there is no response. I see the requests for the traffic in the PA going...

sscarola by L0 Member
  • 1960 Views
  • 1 replies
  • 0 Likes

Resolved! Equivalent of VLAN within Azure..

Probably one of the most simple questions going, but coming from a large on prem environment, I'm trying to understand how its meant to look from an AzurePOV.Typically, when we have a new server in say a /29 , i create a new sub interface for that vlan on the firewall, add a zone to it etc and crack on.Am i right in thinking that the "azure" way...

  • 530 Posts
  • 107 Subscriptions
Labels