AWS Transit Gateway CloudBlade Integration
Focus
Focus
Prisma SD-WAN

AWS Transit Gateway CloudBlade Integration

Table of Contents

AWS Transit Gateway CloudBlade Integration

Learn about the AWS Transit Gateway CloudBlade integartion release notes.
Prisma SD-WAN CloudBlades™ platform enables the secure delivery of best-of-breed branch infrastructure from the cloud. The Prisma SD-WAN AWS Transit Gateway Integration CloudBlade optimizes branch to AWS connectivity by securely and seamlessly integrating your enterprise WAN with AWS.

AWS Transit Gateway CloudBlade Version 2.1.0

This section contains important updates and upgrade considerations of the AWS Transit Gateway CloudBlade Version 2.1.0.

New/Updated Features

  • From version 2.1.0 of the AWS Transit Gateway CloudBlade, the marketplace subscription listing has migrated to Palo Alto Networks marketplace from CloudGenix. There is no other change in features or functionality compared to the 2.0.0 version of the CloudBlade.
    The new marketplace subscription is mandatory for the 2.1.0 version of the CloudBlade, else the CloudBlade will fail.
To upgrade the AWS Transit Gateway CloudBlade version from version 2.0.0 to version 2.1.0.
  1. Go to Strata Cloud ManagerManagePrisma SD-WANCloudBlades.
  2. Locate the AWS Transit Gateway CloudBlade and click Configure.
  3. Ensure that the Admin State of the CloudBlade remains unchanged, during and after the upgrade process.
  4. Select the version you want to upgrade to from the Version drop-down.
  5. Re-enter the ACCESS KEY ID SECRET in the designated field during the upgrade. Retrieve this information from the AWS portal customer account.
  6. Click Save.
  7. To verify the successful upgrade of the CloudBlade, go to the Prisma SD-WAN CloudBlades web interface and check the Installed Version number in the AWS Transit Gateway CloudBlade tile.

Changes to Default Behavior

  • In an upgrade scenario from version 2.0.0 to version 2.1.0 of the AWS Transit Gateway CloudBlade, existing deployments will not be impacted; however, any new deployments require subscribing to the new marketplace.
  • The upgrade process should not impact the existing vION setup. It's expected to be non-disruptive.
  • No configuration change is expected on the vION which is already deployed.
  • Cloud Blades upgrade has no dependency on the vION upgrade and both can be done independently of each other. However, it is recommended not to do both upgrades together.
  • New vION deployments after the CloudBlade upgrade will use the m5.large instance type instead of m4.large instance type.
  • The upgraded CloudBlade version will support region-based CIDR deployments.

AWS Transit Gateway CloudBlade Version 2.0.0

This topic contains important features and caveats of the AWS Transit Gateway CloudBlade Version 2.0.0. The default virtual ION version for this CloudBlade is 5.5.3 b-2.

New/Updated Features

  1. From version 2.0.0 onwards, particular region(s) can be directly removed from the CloudBlade configuration screen. This was earlier possible only by disabling the CloudBlade.
  2. The Monitor tab now shows if a deployment fails or if any exceptions occur during deployment and points to the cause of the disruption.
  3. During roll back, when the CloudBlade is disabled, it removes / deletes all resources created in the AWS environment and the Prisma SD-WAN environment.
  4. You can now replace the TGW ID in a region and the connection gets established with the new TGW ID.

Changes to Default Behavior

  • If you are currently using version 1.0.0 of the AWS Transit Gateway CloudBlade, go to the CloudBlade configuration page and select version 2.0.0 for a seamless upgrade.
  • When you roll back the AWS Transit Gateway CloudBlade from version 2.0.0 to version 1.0.0, you must disable version 1.0.0 and re-deploy the CloudBlade.

AWS Transit Gateway CloudBlade Version 1.0.0

This topic contains important features and caveats of the AWS Transit Gateway CloudBlade Version 1.0.0. The default virtual ION version for this CloudBlade is 5.5.1b-7.

New Feature

The AWS Transit Gateway CloudBlade automatically deploys a Prisma SD-WAN Datacenter in the cloud and establishes BGP peering with AWS Transit Gateway over AWS Connect attachment. This allows remote sites to securely reach the Application VPCs in AWS over the Zero touch Prisma SD-WAN App-Fabric and the AWS Transit Gateway connect attachment allows enterprises to enjoy the benefits of higher throughput and dynamic routing.

Caveats/Limitations

The following caveats are observed with the AWS Transit Gateway Integration CloudBlade version 1.0.0:
  • Changes made to the Transit Gateway ID or the region are not reflected.
  • When multiple Transit Gateways are created and if one of the TGW IDs is removed from the CloudBlade configuration, the resources created by the CloudBlade are not deleted.