Enable two-zone policy to inspect traffic using overlay routing by integrating the VM-Series firewall AWS GWLB.
| Where Can I Use This? | What Do I Need? |
|
|
- AWS account
- Amazon Machine Image (AMI) ID
- VM-Series License (PAYG or BYOL)
- VM-Series plugin
- Panorama
- Panorama plugin for AWS
|
Overly routing requires PAN-OS 10.0.5
or later.
Using overlay routing in your VM-Series firewall
integration the AWS GWLB allows you to use two-zone policy to inspect
traffic leaving (egressing) your AWS environment. This allows packets
to leave the VM-Series firewall through a different interface than that
which they entered through.
When overlay routing is configured,
the firewall is able to perform a Layer 3 route lookup a packet’s
inner header. If the destination is the same as the ingress interface, the
packet will be directed as normal. All future packets in the session
are treated as vwire; as if overlay routing was not enabled. If
the packet is going to an outbound destination, the firewall decapsulates
the packet and forwards the packet to the IGW or NAT gateway. When
the packet returns, the firewall reapplies the encapsulation.
Use
the following procedure to enable overlay routing.