Panorama Post-Deployment Configuration for VM Workloads and Kubernetes Clusters
Focus
Focus
Prisma AIRS

Panorama Post-Deployment Configuration for VM Workloads and Kubernetes Clusters

Table of Contents

Panorama Post-Deployment Configuration for VM Workloads and Kubernetes Clusters

Panorama configurations to secure your VM workloads/vNets and Kubernetes clusters after you deploy Panorama managed Prisma AIRS AI Runtime Firewall.
Where Can I Use This?What Do I Need?
  • Secure VMs and Kubernetes Clusters
This page covers the configurations you need to secure your VM workloads/vNets and Kubernetes clusters, and route traffic after you apply the Panorama-managed deployment Terraform template in your cloud environment.
On this page, you will:
  • Configure the following in Panorama:
    • Interfaces
    • Zones
    • NAT Policy
    • Routers
    • Security Policies
  • Secure VM workloads only for public clouds
  • Secure Kubernetes clusters in public and private clouds
  • Install a Kubernetes application with Helm
    • (Optional) Configure labels in your cloud environment for manual deployments.
      The deployment Terraform you generate from Strata Cloud Manager, automatically adds the required labels to organize your Prisma AIRS AI Runtime Firewall. For manual deployments, ensure you have the following labels (key-value pairs) in your Terraform template.
      • Add the following labels (key-value pairs) under Tags in the Terraform template file under your downloaded path `<azure|aws-deployment-terraform-path>/architecture/security_project/terraform.tfvars`. The value of these keys must be unique.
      • For GCP: `paloaltonetworks_com-trust` and `paloaltonetworks_com-occupied`.
      • For Azure and AWS: `paloaltonetworks.com-trust` and `paloaltonetworks.com-occupied`.
      • Ensure the network interface name in the security_project Terraform is suffixed by `-trust-vpc`.
Prisma AIRS AI Runtime Firewall is only supported for public clusters on GCP, Azure, and AWS cloud platforms and a few private clouds such as OpenShift, ESXi, and KVM.
Before proceeding, complete the following steps: