- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
Have you wanted the ability to auto-scale your Palo Alto Networks VM-Series Virtual Next-Generation Firewall, but also have session resiliency in the case of failover? With the release of Cosmos PAN-OS 11.1, your firewalls can now auto-scale and have session resilience in case of failover.
Most customers deploy VM-Series virtual firewalls in the “hub” of a hub and spoke architecture, customers can automatically ensure inspection of traffic ingressing and egressing into a GCP environment, while also guaranteeing that inter-VPC traffic routes through the VM-Series. By deploying VM-Series behind a load balancer (or a load balancer sandwich in the below image), businesses can also spin-up and spin-down VM-Series firewalls as their network traffic fluctuates, scaling network security as their infrastructure grows. In other words, security never becomes the bottleneck for application development.
However, auto-scaling VM-Series firewalls did not sync sessions, meaning that a session would be lost if a firewall were to fail. Organizations could deploy VM-Series in High Availability (HA) Active-Passive to solve for this issue, but doing so would force them to resize (and reboot) their firewalls in the case that they needed to (manually) increase their network security throughput inspection, since HA only supports 2 firewalls.
Software Firewall Clustering works by syncing VM-Series sessions with a Redis Database. Architecturally, VM-Series would be deployed in the same load-balancing sandwich as auto-scaling. However, in the case that a VM-Series firewall were to fail, the load balancer would forward the session to another (healthy) firewall in the cluster. That new firewall would retrieve the session information from the Redis Database, continuing the policy in seconds without any interruption to the traffic.
Currently, Software Clustering is supported only in AWS and GCP, since only their load balancers will forward traffic to a different firewall in the case of session failure.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Subject | Likes |
---|---|
3 Likes | |
1 Like | |
1 Like | |
1 Like | |
1 Like |