Home
EN
Location
Documentation Home
Palo Alto Networks
Support
Live Community
Knowledge Base
Clear
CN-Series Deployment Guide
:
High Availability for CN-Series Firewall on AWS EKS
Updated on
Fri Sep 01 23:19:15 UTC 2023
Focus
Download PDF
Updated on
Fri Sep 01 23:19:15 UTC 2023
Focus
Home
CN-Series
CN-Series Deployment Guide
Secure Kubernetes Workloads with CN-Series
Deploy the CN-Series Firewalls
High Availability for CN-Series Firewall on AWS EKS
Download PDF
CN-Series Deployment Guide
High Availability for CN-Series Firewall on AWS EKS
Table of Contents
Filter
Version
10.2
11.0
10.2
Expand all
|
Collapse all
CN-Series Firewall for Kubernetes
CN-Series Key Concepts
CN-Series Core Building Blocks
Components Required to Secure Kubernetes Clusters with CN-Series Firewall
CN-Series Deployment—Supported Environments
CN-Series System Requirements
CN-Series Performance and Scaling
Additional CN-Series Resources
License the CN-Series Firewall
Activate Credits
Create a CN-Series Deployment Profile
Manage Deployment Profiles
Secure Kubernetes Workloads with CN-Series
CN-Series Deployment Checklist
CN-Series Prerequisites
Install a Device Certificate on the CN-Series Firewall
Create Service Accounts for Cluster Authentication
Install the Kubernetes Plugin and Set up Panorama for CN-Series
Get the Images and Files for the CN-Series Deployment
Editable Parameters in CN-Series Deployment YAML Files
Deploy the CN-Series Firewalls
Deploy the CN-Series Firewall with Rancher Orchestration
Rancher Cluster Deployment
Set up Master and Worker Node on Rancher Cluster
Modify the Rancher Cluster Options YAML File
Deploy the CN-Series Firewall on GKE
Deploy the CN-Series Firewall as a Kubernetes Service on GKE
Deploy the CN-Series Firewall as a DaemonSet on GKE
Deploy the CN-Series Firewall on EKS
Deploy the CN-Series Firewall as a Kubernetes Service on AWS EKS
Deploy the CN-Series Firewall as a Daemonset on AWS EKS
Deploy the CN-Series from the AWS Marketplace
Deploy the CN-Series Firewall on OKE
Deploy the CN-Series Firewall as a Kubernetes Service on OKE
Deploy the CN-Series Firewall as a DaemonSet on OKE
Deploy the CN-Series Firewall as a Kubernetes Service
Deploy the CN-Series Firewall as a DaemonSet
Deploy the CN-Series Firewall as a Kubernetes CNF
Deploy the Kubernetes CNF L3 in Standalone Mode
High Availability Support for CN-Series Firewall as a Kubernetes CNF
High Availability for CN-Series Firewall on AWS EKS
Overview of HA on AWS EKS
IAM Roles for HA
HA Links
Heartbeat Polling and Hello Messages
Device Priority and Preemption
HA Timers
Configure Active/Passive HA on AWS EKS Using a Secondary IP
Configure DPDK on CN-Series Firewall
Set up DPDK on On-Premises Worker Nodes
Set up DPDK on AWS EKS
Deploy the CN-Series on OpenShift
Deploy CN-Series Firewalls with a Template
Deploy CN-Series Firewall with Terraform Templates
Prepare to Use the Terraform Templates
Deploy a GKE Cluster
Deploy an EKS Cluster
Deploy an AKS Cluster
Deploy a Sample Application
Deploy a CN-Series Firewall Using Terraform
Configure the Kubernetes Plugin for Panorama
Deploy CN-Series Firewalls with Helm Charts and Templates
Deploy CN-Series Firewalls With (Recommended) and Without the Helm Repository
Enable Horizontal Pod Autoscaling on the CN-Series
Configure Panorama to Secure a Kubernetes Deployment
IP-Address-to-Tag Mapping of Kubernetes Attributes
Secure 5G With the CN-Series Firewall
Enable Inspection of Tagged VLAN Traffic
Enable IPVLAN
Uninstall the Kubernetes Plugin on Panorama
Features Not Supported on the CN-Series
Upgrade the CN-Series Firewall
Migrate the CN-Series Firewall to PAN-OS 10.2
Upgrade the CN-Series Firewall—Rolling Update
Upgrade the CN-Series Firewall—Redeploy
High Availability for CN-Series Firewall on AWS EKS
You can now deploy the CN-Series-as-a-Kubernetes-CNF in HA. This mode of deployment supports only active/passive HA with session and configuration synchronization.
This section covers the following:
Overview of HA on AWS EKS
IAM Roles for HA
HA Links
Heartbeat Polling and Hello Messages
Device Priority and Preemption
HA Timers
Configure Active/Passive HA on AWS EKS Using a Secondary IP
Previous
High Availability Support for CN-Series Firewall as a Kubernetes CNF
Next
Overview of HA on AWS EKS
Recommended For You