paloaltonetworks:vmseries:azure
Differences
This shows you the differences between two versions of the page.
| Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
| paloaltonetworks:vmseries:azure [2021/09/06 13:19] – bstafford | paloaltonetworks:vmseries:azure [2022/12/02 11:54] (current) – bstafford | ||
|---|---|---|---|
| Line 12: | Line 12: | ||
| You can deploy Panorama on 4CPU/8GB RAM but it will be limited to Management Mode only. For Panorama mode, you need at least 8 CPU and 16 GB of RAM. | You can deploy Panorama on 4CPU/8GB RAM but it will be limited to Management Mode only. For Panorama mode, you need at least 8 CPU and 16 GB of RAM. | ||
| + | In Azure for just managing 6 VM's, standard_D3_v2 should be sufficient if there is no logging happening. If you need Panorama in mixed mode, you must apply proper resource to the VM. | ||
| - | Just managing 6 VM's, standard_D3_v2 should be sufficient | + | HOWEVER, recent PAN-OS versions will complain every single time you log in to Panorama |
| + | |||
| + | Use '' | ||
| + | |||
| + | In June 2022, the reference archtiecture says to use Standard_D16s_v3. | ||
| + | |||
| + | As of Sep 2022: | ||
| + | * D16_v3 is 16 CPU and 64 GB RAM and is about $675 per month to run (not including ' | ||
| + | * D5_v2 is 16CPU and 56 GB RAM and is about $1,025 per month to run (not including ' | ||
| ===== Pay-As-You-Go ===== | ===== Pay-As-You-Go ===== | ||
| As of 28th Feb 2018 | As of 28th Feb 2018 | ||
| Line 56: | Line 65: | ||
| ===== Load Balancer Health Probe ===== | ===== Load Balancer Health Probe ===== | ||
| - | The Azure LB health probe does not complete a 3 way handshake - just the SYN and the SYNACK. On tcp-80 this is identified as " | + | Azure Health Probes target the firewall interface IP. |
| + | |||
| + | The Azure LB health probe does not complete a 3 way handshake - just the SYN and the SYNACK. On tcp-80 this is identified as " | ||
| + | |||
| + | ===== Deployment Notes ===== | ||
| + | For public load balancers, enable " | ||
| + | REMEMBER. When adding a secondary IP to the front end load balancer, you must enable " | ||
| - | ===== Deploymnet Notes ===== | ||
| - | For load balancers, " | ||
| Configure the firewall to update its domain based on the DHCP allocation. | Configure the firewall to update its domain based on the DHCP allocation. | ||
paloaltonetworks/vmseries/azure.1630934342.txt.gz · Last modified: (external edit)
