Beginning with PAN-OS 7.1, you can configure the firewall to receive dataplane traffic on the primary interface in scenarios where the VM-Series firewall is behind the Amazon ELB. Before PAN-OS 7.1, the VM-Series firewall could not integrate with ELB because ELB could forward traffic only to the primary (eth0) elastic network interface (ENI) of an EC2 instance. You now have the ability to enable the primary interface on the VM-Series firewall to function as a dataplane interface, instead of functioning as the management interface, so that ELB can forward traffic to the firewall.