Strange issue- VM-Series Ext interface with Elastic IP in AWS not reachable. (outside test PC reachable)

Showing results for 
Show  only  | Search instead for 
Did you mean: 
Please sign in to see details of an important advisory in our Customer Advisories area.

Strange issue- VM-Series Ext interface with Elastic IP in AWS not reachable. (outside test PC reachable)

L1 Bithead

I am trying to POC a scenario for my customer in AWS with dual Palo Alto in HA within same availability zone. (We need to build a site to Site VPN tunnel from on-Premises to AWS Palo behind IGW)


I am facing a strange issue. I an not able to reach the outside Elastic IP address of Palo.(I am able to reach the public IP on Management interface). The ENI's are moving to the secondary on failover. 

  • I have deployed Palo Alto Primary FW and Secondary FW. 
  • All Security Groups are configured to permit all traffic. No NALC’s configured. 
  • Main VPC is
  • There are 4 Subnets: Public, Management, Private and HA
  • There are 2 route tables - Public and Private
  • 3  subnets (Public, Management and HA) are associated with Public Route Table and Private subnet is associated with Private RT.
  • Internet Gateway is attached to VPC. Default route is configured in Public RT pointing to IGW. Communication from Public RT is up as the Test PC and Palo Management interface is able to reach internet. 
  • Palo Alto is configured with Static IP and static default route pointing to the first IP of Public subnet (
  • Palo Configured with Security policy to permit all traffic.
  • Palo management profile permits ping, ssh, https
  • Elastic Public IP is attached to the Public and Management ENI’s. Palo Primary have 4 ENI's - Management (elastic IP), Public (elastic IP), HA and Private.
  • Source/destination check is disabled on all ENI's
  • HA configured and is syncing the configs with peer. Data plane Interface is moving to the Secondary Palo on failover. 
  • Management IP is reachable, test PC in public subnet is reachable, but Palo’s public IP is not. I re-created this lab at least 10 times now. The interesting thing is that, I was able to reach the external public IP of Palo yesterday but is not working after another rebuild. 

Am I missing something here? Can any one help me resolve this issue?. 






  • 0 replies
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!