Palo Alto VM series NGFW and Azure Redhat openshift

N-Open 160 Reputation points
2023-11-10T16:47:30.29+00:00

Hello,

I have a palo alto VM series FW in hub network and ARO in spoke network distributed in 3 Azure Availability Zone.

How to allow traffic to come from internet to reach through palo alto FW to reach to POD running in the ARO. PODs of same application are distributed across three Availability Zone.

plz advice.

What forwarding to be done where? What is best approach for return traffic.

Azure Red Hat OpenShift
Azure Red Hat OpenShift
An Azure service that provides a flexible, self-service deployment of fully managed OpenShift clusters.
71 questions
Azure Virtual Network
Azure Virtual Network
An Azure networking service that is used to provision private networks and optionally to connect to on-premises datacenters.
2,159 questions
0 comments No comments
{count} votes

Accepted answer
  1. ChaitanyaNaykodi-MSFT 23,031 Reputation points Microsoft Employee
    2023-11-15T02:06:21.08+00:00

    @N-Open

    Thank you for reaching out and apologies for the delayed engagement here.

    I understand that you have a palo alto VM series FW in hub network and ARO in spoke network distributed in 3 Azure Availability Zone.

    Each subnet in Azure can be linked to a route table used to define how traffic initiated in that subnet is routed. You can define User Defined routes to direct traffic from the ARO cluster deployed in the spoke network to NVA deployed in your Hub Network. You can define a route with 0.0.0.0/0 as the address prefix and a next hop type of virtual appliance. This configuration allows the appliance to inspect the traffic and determine whether to forward or drop the traffic. If you intend to create a user-defined route that contains the 0.0.0.0/0 address prefix, read 0.0.0.0/0 address prefix first..

    You can go through this tutorial to understand how to Route network traffic with a route table.

    Regarding high availability, of the NVA you can refer to this documentation here which explains the most common options to deploy a set of Network Virtual Appliances (NVAs) for high availability in Azure.

    Please refer to this documentation if you are using Azure WAN solution.

    Hope this helps! Please let me know if you have any additional questions. Thank you!


    ​​Please "Accept the answer" if the information helped you. This will help us and others in the community as well.

    1 person found this answer helpful.

1 additional answer

Sort by: Most helpful
  1. Deleted

    This answer has been deleted due to a violation of our Code of Conduct. The answer was manually reported or identified through automated detection before action was taken. Please refer to our Code of Conduct for more information.


    Comments have been turned off. Learn more