Thank you for reaching out.
As documented here Generic Routing Encapsulation (GRE) packets are blocked in virtual networks. If I understand correctly, you will be deploying the Palo Alto firewall in an Azure VM and the GRE traffic will be blocked.
Additional reference:
This feature is already requested by other customers, which is under review by Microsoft PG teams, but we don't have any ETA as of yet. You can upvote the feature in the below feedback forum:
https://feedback.azure.com/d365community/idea/874be986-8426-ec11-b6e6-000d3a4f0789
Hope this helps! Please let me know if you have any additional questions. Thank you!
Please "Accept the answer" if the information helped you. This will help us and others in the community as well.