Understand PA HA deployment supported since PAN-OS 9.0, so firewall pair can be deployed in the availability set so they are in different hardware cluster in Azure. But may I know anyone tried to form the HA in different availability zone in the same Azure region? Support or not?
We recommend deploying firewalls in separate AZs or at least put them into an Availability Set in Azure. HA mode is supported as well but not typically recommended. The load balancer method is recommended. You can see both setups in our reference architecture guide. https://www.paloaltonetworks.com/resources/guides/azure-architecture-guide
The Azure Marketplace offering has limited features and you can't deploy two firewalls over the marketplace in a single Ressource Group.
That why we are using Terraform templates or ARM templates. Below are the link to the ARM Templates with the examples how to use it.
ARM Templates: https://github.com/wwce/azure-arm
How to setup HA in Azure: https://docs.paloaltonetworks.com/vm-series/10-0/vm-series-deployment/set-up-the-vm-series-firewall-...
i hope i could help you.
@tostern Thanks. But PA needs to better their documentation regarding Azure deployments. While the Github mentions 3 models (Shared, Scaled and Dedicated). There is little explanation for each them and also there is no mention of them in the design guide. I understand and have tested implementation of both options with HA/without HA(load balancer) options. From what I understand the template I will use is shared model here and Transit VNet model (Common Firewall Option).
And I had got it working in HA without ARM template for those who are not comfortable using it. Install in dedicated resource group and then move the resources to another resource group where you want both firewalls to be.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!