Secure your inbound traffic using the Azure gateway load balancer (GWLB).
| Where Can I Use This? | What Do I Need? |
- Microsoft Azure
- Microsoft Azure Stack
- Azure® Marketplace
- Azure China Marketplace
- Azure Government Marketplace
|
- VM-Series License (PAYG or BYOL)
- VM-Series plugin
- Panorama
- Panorama plugin for Azure
|
You can now deploy the VM-Series firewall for Azure in integration
with the Azure gateway load balancer (GWLB). Securing inbound traffic requires
complete visibility of the traffic source’s identity as it travels to its
destination in the cloud. When you deploy VM-Series firewalls behind
a public standard load balancer, the source IP addresses of inbound traffic are
replaced with the IP address of the load balancer. As a result, application source
identity is obfuscated. By deploying the VM-Series firewalls behind
the Azure GWLB, traffic packet headers and payload are kept intact, which provides
complete visibility of the source’s identity as it travels to its destination. When
Azure GWLB integration is enabled, the VM-Series uses VXLAN packets
to inspect the inner packet of traffic and apply policy to that packet.
When deployed behind the Azure GWLB, VM-Series firewalls can enforce a
zone-based security policy. You can segment VNet-bound and internet-bound traffic by
assigning a trust zone to the VNet-bound traffic and untrust-zone for the
internet-bound traffic.
With this integration, you can deploy the VM-Series firewall as a backend to the
Azure GWLB in all supported regions.
VM-Series firewall integration with the Azure GWLB requires PAN-OS
10.1.4 or later and VM-Series plugin 2.1.4 or later.
Follow best practices to not overlap the CIDRs used by
different VNets.