PAN-OS 9.0 Azure Deployment

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

PAN-OS 9.0 Azure Deployment

L2 Linker

Has anyone upgraded to PAN-OS 9.0 in their Azure environment?  I have 2 sets of Azure firewalls sitting behind multiple load balancers.  I saw where HA is now supported in Azure with Pan-OS 9.  I am debating if I want to be an early adopter and migrate, or wait 6 months for bugs to be addressed.

3 REPLIES 3

Cyber Elite
Cyber Elite

Hello,

Unless this is a dev environment, I would honeslty wait. I always wait till at least the 3rd or 4th update before considering the newest version. Check out the release notes and see if there is something you absolutly need.

 

Regards,

L1 Bithead

I have setup Ha in Azure. 

I'd like to wait but I have an issue forcing me to go down this route.

 

I know pre 9.0 methodology is to use two firewalls and Panaorama but I haev an API service provider charging us per VPN so the HA will save us a bomb, 

 

 

Anyway I have it working.  Problem is failover is 3 minutes plus . Also secondary device stops workign after 20 minutes, 

 

Shows a lot of promise once these bugs are sorted. 

 

 

L0 Member

I've deployed a few Azure HA PANOS 9.0.1 pairs. 

 

They work as expected, I've done many rounds of testing.  It is true, the Azure portion of the failover can take 2 - 3 minutes for the floating IPs to move; however, the design is much more straight forward than the LB sandwich in Azure.  Also, I've tested VPN/IPSec tunnels failover smoothly with the HA deployment, can't say that's even an option with the Azure LB sandwich without Azure Function/Automation updating a UDR after the pri fails.  

 

I'm curious about the previous poster's passive node not working after 20 minutes... was that issue resolved?  

  • 3978 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!