- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
05-21-2026 03:43 AM
Treat your untrusted interface the same way you would a physical firewall and set up an outbound source NAT rule (even though your external IP is a private one on the interface)
05-21-2026 01:52 PM
I am just getting started with a PaloAlto on Azure, but I have found the only way to do this is to throw out the external load balancer (if you have one) and put the public IP directly on your PaloAlto Untrust (actually, the private NAT of the public IP as @reaper says). Azure blocks ICMP inbound/outbound by default. Also make sure your app vNet is routing internet traffic to the PaloAlto and not sending it out the Azure default route out Bastion.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!

