Enhanced Security Measures in Place:   To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.

Deploying ARM template for Azure

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Deploying ARM template for Azure

L1 Bithead

Hi All,

Anyone encountered issue while deploying arm template from this link: "https://github.com/PaloAltoNetworks/Azure-interface-options"? i cannot seems to add it to my existing resource group using all the options. The error i have is as below.

 

error.png

 

1 accepted solution

Accepted Solutions

The subnets are prerequisits.  The template does not create them.   Each of the templates notes in the initial section what needs to already exist such as the Resource Group, VNET - with subnets, Storage Account for the VHDs, Load Balancer and AVailability Set.  

View solution in original post

11 REPLIES 11

L4 Transporter

Watch for a type-o in either your VNET name or the subnet named "Mgmt" especially a trailing space in the template which I have seen often when copying and pasting from the portal.  That error is indicating that the VNIC cannot be added to subnet Mgmt.  The templates assume the subnets designated already exist, they will not create them in the RG.

L1 Bithead

Its a fresh new deployment of firewall to existing RG without any existing firewall. I suspect there is issue with the Github template.

Which of the templates did you use?

L1 Bithead

Which one specifically? There are multiple ARM templates in those directories.

L1 Bithead

I tried both existing environment with and without New AVSET. Same result.

Could you please post a picture of your subnets under Settings in the VNET.  The Mgmt, Trust and Untrust subnet names in the template are the default example and need to be changed to match the subnets you have previously created in the VNET.  Same will apply to the subnet prefix and Start Address.

L1 Bithead

There are no Mgmt, Untrust and Trust subnets in my existing RG. There is only web subnet in the vnet.

The subnets are prerequisits.  The template does not create them.   Each of the templates notes in the initial section what needs to already exist such as the Resource Group, VNET - with subnets, Storage Account for the VHDs, Load Balancer and AVailability Set.  

L1 Bithead

Noted. I wasn't aware that the pre-requsite subnets expect me to create the firewall subnets beforehand. Thanks for tinkle!

I wish I could read your comment before deploying the Github template. I would have 
saved the one day.;) Thanks.


@jmeurer wrote:

The subnets are prerequisits.  The template does not create them.   Each of the templates notes in the initial section what needs to already exist such as the Resource Group, VNET - with subnets, Storage Account for the VHDs, Load Balancer and AVailability Set.  


 



  • 1 accepted solution
  • 6966 Views
  • 11 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!