Palo Alto - Azure Interface DHCP

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Palo Alto - Azure Interface DHCP

L3 Networker

Hi,

 

Are you guys using DHCP client on the interfaces or are you staticly assign IPs  on PAN side?

 

Thanks

9 REPLIES 9

L4 Transporter

DHCP is the way to go.  It eases automated deployments and prevents any possible misconfiguration.  If you statically assign and it does not match what was assigned on Azure side, the traffic will not flow.

What about when you assign multiple IPs to a interface for NAT purposes 

You still assign them on the Azure side.  You then need to specify them direcdtly as either objects or directly in the security or NAT policy.  

There are 2 options here when you want to service multiple ips on a load balancer:

 

1) add additional ips to the firewall interface from within the azure portal AND you will have to switch to static on the firewall and manually add the first + additional ips that you want to service (they'll match the ips on the azure portal). dhcp only picks up the first address from the azure side in my experience (this may have changed so please double check).

 

#1 isn't the best option for ease of management

 

2) on the load balancer, enable floating ip on the rule and you will see the ip requested by the user come through to the firewall (even when having multiple front-side ips on the load balancer). you can then create corresponding nat and security rules based on that. using this method you can stay with dhcp on the firewall and do not need to add additional virtual ips from the azure portal side, nor on the firewall itself.

 

#2 is the better way to go.

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!