Home
EN
Location
Documentation Home
Palo Alto Networks
Support
Live Community
Knowledge Base
MENU
Home
VM-Series
VM-Series Deployment Guide
Set Up the VM-Series Firewall on AWS
Use Case: VM-Series Firewalls as GlobalProtect Gateways on AWS
Deploy GlobalProtect Gateways on AWS
Document:
VM-Series Deployment Guide
Deploy GlobalProtect Gateways on AWS
Download PDF
Last Updated:
Mon Mar 14 13:06:30 PDT 2022
Current Version:
8.1 (EoL)
Version 10.2
Version 10.1
Version 10.0
Version 9.1
Version 9.0 (EoL)
Version 8.1 (EoL)
Version 8.0 (EoL)
End-of-Life (EoL)
Previous
Next
Deploy GlobalProtect Gateways on AWS
To secure mobile users, in addition to deploying and configuring the GlobalProtect gateways on AWS, you need to set up the other components required for this integrated solution. The following table includes the recommended workflow:
Deploy the VM-Series firewall(s) on AWS.
See
Deploy the VM-Series Firewall on AWS
.
Configure the firewall at the corporate headquarters.
In this use case, the firewall is configured as the GlobalProtect portal and the LSVPN gateway.
Configure the GlobalProtectportal
.
Configure the GlobalProtectportal for LSVPN
.
Configure the portal to authenticateLSVPN satellites
.
Configure the GlobalProtectgateway for LSVPN
.
Set up a template on Panorama for configuring the VM-Series firewalls on AWS as GlobalProtect gateways and LSVPN satellites.
To easily manage this distributed deployment, use Panorama to configure the firewalls on AWS.
Create template(s) on Panorama
.
Then use the following links to define the configuration in the templates.
Configure the firewall asa GlobalProtect gateway
.
Prepare the satellite tojoin the LSVPN
.
Create device groups on Panorama to define the network access policies and internet access rules and apply them to the firewalls on AWS.
See
Create device groups
.
Apply the templates and the device groups to the VM-Series firewalls on AWS, and verify that the firewalls are configured properly.
Deploy the GlobalProtect client software.
Every end-user system requires the GlobalProtect agent or app to connect to the GlobalProtect gateway.
See
Deploy the GlobalProtectclient software
.
Previous
Next
Recommended For You
Recommended Videos
Recommended videos not found.