Azure: Deploying Palo Alto Networks VM-series Part-2
This is a continuation of Part-1.
Configure Security Zones
Configure Interfaces
Configure Virtual Router (VR)
It is best practice to have two separate VRs in Azure; one for routing traffic to the internet, one for routing traffic to the trust (inside) zone.
Likewise, the placeholder VR is now the new VR to route traffic inside.
The configuration is the exact opposite. Where the default route next-hop is the other VR. The inside (trust vNIC) next hop is Azure default gateway for that subnet.
领英推荐
In the end, there should be two VRs with two static routes:
Outbound security rules configuration remain unchanged compared to non-cloud based infrastructure.
NAT rules:
Source NAT
Destination NAT
See part 3 for destination NAT.
Now, you can have two-traffic (Tx and Rx) routing through the firewall.
That's it, the firewall is deployed.