Deploy the VM-Series Firewall on Azure Stack HCI
| Where Can I Use This? | What Do I Need? |
- Microsoft Azure
- Microsoft Azure Stack
- Azure® Marketplace
- Azure China Marketplace
- Azure Government Marketplace
|
- VM-Series License (PAYG or BYOL)
- VM-Series plugin
- Panorama
- Panorama plugin for Azure
|
You can deploy the VM-Series firewall on Azure Stack HCI within Software Defined
Networking (SDN) architecture. Azure Stack HCI is a hyperconverged infrastructure (HCI)
cluster solution that hosts virtualized Windows and Linux workloads and their storage in
a hybrid environment that combines on-premises infrastructure with Azure cloud services.
For more information, see
Azure Stack HCI solution overview.
You can deploy the VM-Series firewall on Azure Stack HCI and protect the
inbound traffic, outbound traffic, and east-west traffic between various vNETs. The VM-Series firewall traffic is pinned to an active interface with an
out-of-band management interface, where the internal applications and inbound traffic
are routed through route tables to force traffic through the firewall load balancer for
east-west and north-south traffic to provide internal microsegmentation and a security
perimeter. The SDN Gateway then allows traffic to pass in and out of the internal SDN
via the hub vNet.
Perform the following steps to deploy the VM-Series firewall on Azure Stack HCI SDN:
- To get started, you will need the following:
Create an Azure Stack HCI cluster using any one of the below given
methods:
- Register Azure Stack HCI cluster with
Azure for monitoring, support, billing, and hybrid services.
Deploy the SDN infrastructure using any one of the following methods:
This document considers the Windows Admin
Center option for deploying the VM-Series firewall.
After successfully deploying the SDN infrastructure, go to the SDN
Infrastructure dashboard on your Windows Admin Center and ensure that all server
nodes are healthy.
- Deploy the VM-Series firewall.
Download the VHDX file. Register your
VM-Series firewall and obtain the VHDX file.
- Filter by PAN-OS for VM-Series Base Images and download the VHDX
file. For example, PA-VM-HPV-7.1.0.vhdx.
- Install the VM-Series firewall.
Perform the following steps to install
the VM-Series firewall on Azure Stack HCI:
Add a virtual
machine.
Go to Windows Admin Center > Cluster Manager and
select the Cluster.
- Go to Virtual Machines > Add> New.
Configure the following settings in the New Virtual Machine
Wizard:
Enter the Name for the VM-Series
firewall.
Select Generation 1. This is the default option and the only
version supported.
- Select the Host and Path for the VM-Series firewall. Browse
the VHD/VHDX FW image file.
Note: You must store the
VHD/VHDX in location C:/ClusterStorage/Volumes.
- To configure networking, from the Virtual Network dropdown menu,
select vNet.
A converged virtual switch
(vSwitch) gets created while bringing up the Azure Stack HCI
cluster.
Select Virtual Switch > Isolation Mode >
Virtual Network > Virtual Subnet.
Click Add IP Address and enter the IP address
for the management interface.
Select Network Security Group (optional).
- To connect the Virtual Hard Disk, select Use an existing virtual hard
disk and browse to the VHDX file you downloaded earlier in Step
6.
- Click Create.
After successfully installing the VM-Series firewall on the cluster,
you can add more Network Adapters for data traffic. Perform the following
to add a Network Adapter:
- (Optional) Enable MAC address spoofing if you're not using Layer 3 with MAC
address.
Double-click the dataplane virtual network adapter and click
Advanced Settings.
Click the Enable MAC address spoofing check box and
click Apply.
- Bootstrap the VM-Series Firewall.
- Power on the firewall.