{"id":2419,"date":"2022-09-21T11:04:35","date_gmt":"2022-09-21T08:04:35","guid":{"rendered":"https:\/\/artem.services\/?p=2327"},"modified":"2022-10-03T17:49:58","modified_gmt":"2022-10-03T14:49:58","slug":"2419","status":"publish","type":"post","link":"https:\/\/artem.services\/?p=2419&lang=en","title":{"rendered":"Palo Alto VM-Series Firewall: AWS HA Multi AZ for GlobalProtect &#8212; Part 1"},"content":{"rendered":"<p><img loading=\"lazy\" class=\"alignnone size-large wp-image-2328\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/palo-alto-logo-1024x186.png\" alt=\"\" width=\"954\" height=\"173\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/palo-alto-logo-1024x186.png 1024w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/palo-alto-logo-300x54.png 300w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/palo-alto-logo-768x140.png 768w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/palo-alto-logo-1536x279.png 1536w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/palo-alto-logo-2048x372.png 2048w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/palo-alto-logo-954x173.png 954w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/palo-alto-logo-1354x246.png 1354w\" sizes=\"(max-width: 954px) 100vw, 954px\" \/><\/p>\n<p>&nbsp;<\/p>\n<p>The Palo Alto VM-Series Firewall uses an active\/passive configuration for high availability. In which the active firewall constantly synchronizes its configuration and information about active sessions with a similarly configured passive firewall. There are <a href=\"https:\/\/docs.paloaltonetworks.com\/vm-series\/10-2\/vm-series-deployment\/set-up-the-vm-series-firewall-on-aws\/high-availability-for-vm-series-firewall-on-aws\/overview-of-ha-on-aws\" target=\"_blank\" rel=\"noopener\">two options<\/a> for achieving HA on AWS: &quot;<strong>Secondary IP Move<\/strong>&quot; and &quot;<strong>Dataplane Interface Move<\/strong>&quot;.<\/p>\n<h2>Secondary IP Move<\/h2>\n<p>If the active firewall is unavailable, the passive one becomes active. It also makes API requests to transfer secondary IP addresses from an inaccessible host to itself and updates the routing tables so that traffic is sent to the new active firewall. Switching firewall roles in this method is faster than in &quot;<strong>Dataplane Interface Move<\/strong>&quot;.<\/p>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-2333\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-06-at-20.52.36.png\" alt=\"\" width=\"1252\" height=\"686\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-06-at-20.52.36.png 1252w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-06-at-20.52.36-300x164.png 300w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-06-at-20.52.36-1024x561.png 1024w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-06-at-20.52.36-768x421.png 768w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-06-at-20.52.36-954x523.png 954w\" sizes=\"(max-width: 1252px) 100vw, 1252px\" \/><\/p>\n<h2><span class=\"VIiyi\" lang=\"ru\"><span class=\"JLqJ4b\" data-language-for-alternatives=\"ru\" data-language-to-translate-into=\"en\" data-phrase-index=\"0\" data-number-of-phrases=\"1\"><span class=\"Q4iAWc\">Dataplane Interface Move<\/span><\/span><\/span><\/h2>\n<p><span class=\"VIiyi\" lang=\"ru\"><span class=\"JLqJ4b\" data-language-for-alternatives=\"ru\" data-language-to-translate-into=\"en\" data-phrase-index=\"0\" data-number-of-phrases=\"1\"><span class=\"Q4iAWc\">As in the case of &quot;<strong>Secondary IP Move<\/strong>&quot;, if the passive firewall detects that the active one is no longer available, then it becomes active, but instead of transferring IP addresses, it transfers ENI from the inaccessible firewall to itself.<\/span><\/span><\/span><\/p>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-2334\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-06-at-21.20.18.png\" alt=\"\" width=\"2114\" height=\"1036\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-06-at-21.20.18.png 2114w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-06-at-21.20.18-300x147.png 300w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-06-at-21.20.18-1024x502.png 1024w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-06-at-21.20.18-768x376.png 768w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-06-at-21.20.18-1536x753.png 1536w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-06-at-21.20.18-2048x1004.png 2048w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-06-at-21.20.18-954x468.png 954w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-06-at-21.20.18-1354x664.png 1354w\" sizes=\"(max-width: 2114px) 100vw, 2114px\" \/><\/p>\n<p><!--more-->Since it is planned to use VM Firewall as <strong>GlobalProtect<\/strong> to access local resources from outside, and firewalls must be in different AZs, only the &quot;<strong>Secondary IP Move<\/strong>&quot; option is suitable, but in this case, it will be the EIP that is associated with the main private IP address.<\/p>\n<p>HA requires at least 4 interfaces on each firewall:<\/p>\n<ul>\n<li>ENI0: <strong>MGMT<\/strong> &#8212; for management and configuration via console or web interface. Also, this interface will be used as HA1 link<\/li>\n<li>ENI1: <strong>HA2<\/strong> &#8212; to check firewall status<\/li>\n<li>ENI2: <strong>Untrust<\/strong> &#8212; interface for connecting to GlobalProtect. On an active firewall, EIP will be associated with this interface<\/li>\n<li>ENI3: <strong>Trust<\/strong> &#8212; interface through which local resources will be available<\/li>\n<\/ul>\n<blockquote><p>Keep in mind that there is a limit on the maximum number of ENIs attached to an instance, depending on its type and size. Limits can be found <a href=\"https:\/\/docs.aws.amazon.com\/AWSEC2\/latest\/UserGuide\/using-eni.html#AvailableIpPerENI\" target=\"_blank\" rel=\"noopener\">here<\/a>. In this case, instances will be used &#8212; <strong>m5.xlarge<\/strong><\/p><\/blockquote>\n<p>For clarity, the ranges of networks will be formed as follows:<\/p>\n<blockquote><p>10.0.&quot;firewall_number&quot;+&quot;interface_number&quot;.0\/24<\/p><\/blockquote>\n<p>Total we have:<\/p>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-2340\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-06-at-22.19.58.png\" alt=\"\" width=\"1196\" height=\"348\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-06-at-22.19.58.png 1196w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-06-at-22.19.58-300x87.png 300w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-06-at-22.19.58-1024x298.png 1024w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-06-at-22.19.58-768x223.png 768w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-06-at-22.19.58-954x278.png 954w\" sizes=\"(max-width: 1196px) 100vw, 1196px\" \/><\/p>\n<p>By type, these will be public subnets and isolated\/private (for GlobalProtect they do not need Internet access)<\/p>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-2342\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-06-at-22.22.28.png\" alt=\"\" width=\"1194\" height=\"444\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-06-at-22.22.28.png 1194w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-06-at-22.22.28-300x112.png 300w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-06-at-22.22.28-1024x381.png 1024w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-06-at-22.22.28-768x286.png 768w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-06-at-22.22.28-954x355.png 954w\" sizes=\"(max-width: 1194px) 100vw, 1194px\" \/><\/p>\n<p>As a result, we have the following scheme:<\/p>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-2330\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/pa-globalprotect-hld.png\" alt=\"\" width=\"2341\" height=\"1320\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/pa-globalprotect-hld.png 2341w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/pa-globalprotect-hld-300x169.png 300w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/pa-globalprotect-hld-1024x577.png 1024w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/pa-globalprotect-hld-768x433.png 768w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/pa-globalprotect-hld-1536x866.png 1536w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/pa-globalprotect-hld-2048x1155.png 2048w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/pa-globalprotect-hld-954x538.png 954w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/pa-globalprotect-hld-1354x763.png 1354w\" sizes=\"(max-width: 2341px) 100vw, 2341px\" \/><\/p>\n<h2>AWS Infrastructure<\/h2>\n<h4>VPC<\/h4>\n<p>Let&#8217;s go to the &quot;<strong>VPC<\/strong>&quot; section and select &quot;<strong>Create VPC<\/strong>&quot;. We will not use the wizard, we will create the necessary resources ourselves. Specify the name and CIDR, the rest will be left by default.<\/p>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-2348\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-07-at-14.23.05.png\" alt=\"\" width=\"1636\" height=\"1036\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-07-at-14.23.05.png 1636w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-07-at-14.23.05-300x190.png 300w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-07-at-14.23.05-1024x648.png 1024w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-07-at-14.23.05-768x486.png 768w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-07-at-14.23.05-1536x973.png 1536w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-07-at-14.23.05-954x604.png 954w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-07-at-14.23.05-1354x857.png 1354w\" sizes=\"(max-width: 1636px) 100vw, 1636px\" \/><\/p>\n<p>In the &quot;<strong>VPC<\/strong>&quot; tab, find &quot;<strong>Internet gateways<\/strong>&quot; and select &quot;<strong>Create internet gateway<\/strong>&quot;<\/p>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-2347\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-07-at-14.20.40.png\" alt=\"\" width=\"1642\" height=\"652\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-07-at-14.20.40.png 1642w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-07-at-14.20.40-300x119.png 300w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-07-at-14.20.40-1024x407.png 1024w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-07-at-14.20.40-768x305.png 768w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-07-at-14.20.40-1536x610.png 1536w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-07-at-14.20.40-954x379.png 954w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-07-at-14.20.40-1354x538.png 1354w\" sizes=\"(max-width: 1642px) 100vw, 1642px\" \/><\/p>\n<p>Let&#8217;s attach the created <strong>IGW<\/strong> to our <strong>VPC<\/strong><\/p>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-2349\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-07-at-14.24.45.png\" alt=\"\" width=\"2198\" height=\"550\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-07-at-14.24.45.png 2198w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-07-at-14.24.45-300x75.png 300w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-07-at-14.24.45-1024x256.png 1024w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-07-at-14.24.45-768x192.png 768w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-07-at-14.24.45-1536x384.png 1536w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-07-at-14.24.45-2048x512.png 2048w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-07-at-14.24.45-954x239.png 954w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-07-at-14.24.45-1354x339.png 1354w\" sizes=\"(max-width: 2198px) 100vw, 2198px\" \/><\/p>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-2350\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-07-at-14.27.24.png\" alt=\"\" width=\"1628\" height=\"766\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-07-at-14.27.24.png 1628w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-07-at-14.27.24-300x141.png 300w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-07-at-14.27.24-1024x482.png 1024w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-07-at-14.27.24-768x361.png 768w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-07-at-14.27.24-1536x723.png 1536w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-07-at-14.27.24-954x449.png 954w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-07-at-14.27.24-1354x637.png 1354w\" sizes=\"(max-width: 1628px) 100vw, 1628px\" \/><\/p>\n<h4>Subnets<\/h4>\n<p>Let&#8217;s create the necessary subnets, for this we go to &quot;<strong>VPC<\/strong>&quot; -&gt; &quot;<strong>Subnets<\/strong>&quot; and select &quot;<strong>Create subnet<\/strong>&quot;. It is necessary to create 4 subnets in 2 AZs according to the table above<\/p>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-2364\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-07-at-18.11.55.png\" alt=\"\" width=\"1420\" height=\"1202\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-07-at-18.11.55.png 1420w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-07-at-18.11.55-300x254.png 300w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-07-at-18.11.55-1024x867.png 1024w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-07-at-18.11.55-768x650.png 768w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-07-at-18.11.55-954x808.png 954w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-07-at-18.11.55-1354x1146.png 1354w\" sizes=\"(max-width: 1420px) 100vw, 1420px\" \/><\/p>\n<p>Check the created subnets, their CIDR, and Availability zones<\/p>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-2365\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-07-at-18.15.59.png\" alt=\"\" width=\"2156\" height=\"560\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-07-at-18.15.59.png 2156w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-07-at-18.15.59-300x78.png 300w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-07-at-18.15.59-1024x266.png 1024w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-07-at-18.15.59-768x199.png 768w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-07-at-18.15.59-1536x399.png 1536w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-07-at-18.15.59-2048x532.png 2048w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-07-at-18.15.59-954x248.png 954w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-07-at-18.15.59-1354x352.png 1354w\" sizes=\"(max-width: 2156px) 100vw, 2156px\" \/><\/p>\n<h4>Route tables<\/h4>\n<p>Let&#8217;s create 3 routing tables:<\/p>\n<ul>\n<li>PA-LAB-NETWORK-DEFAULT-RT<\/li>\n<li>PA-LAB-NETWORK-PUBLIC-RT<\/li>\n<li>PA-LAB-NETWORK-GP-TRUST-RT<\/li>\n<\/ul>\n<p>To do this, go to &quot;<strong>VPC<\/strong>&quot; -&gt; &quot;<strong>Route tables<\/strong>&quot; and select &quot;<strong>Create route table<\/strong>&quot;<\/p>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-2360\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-07-at-16.29.38.png\" alt=\"\" width=\"1642\" height=\"732\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-07-at-16.29.38.png 1642w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-07-at-16.29.38-300x134.png 300w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-07-at-16.29.38-1024x456.png 1024w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-07-at-16.29.38-768x342.png 768w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-07-at-16.29.38-1536x685.png 1536w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-07-at-16.29.38-954x425.png 954w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-07-at-16.29.38-1354x604.png 1354w\" sizes=\"(max-width: 1642px) 100vw, 1642px\" \/><\/p>\n<blockquote><p>For the &quot;<strong>TRUST<\/strong>&quot; zone, we create a separate table, since we will add routes to it on the <strong>Transit Gateway<\/strong>.<\/p><\/blockquote>\n<p>Select the routing table &quot;<strong>PA-LAB-NETWORK-PUBLIC-RT<\/strong>&quot; go to the &quot;<strong>Routes<\/strong>&quot; tab and select &quot;<strong>Edit routes<\/strong>&quot; and add a default route on <strong>IGW<\/strong><\/p>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-2362\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-07-at-16.47.31.png\" alt=\"\" width=\"2768\" height=\"816\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-07-at-16.47.31.png 2768w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-07-at-16.47.31-300x88.png 300w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-07-at-16.47.31-1024x302.png 1024w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-07-at-16.47.31-768x226.png 768w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-07-at-16.47.31-1536x453.png 1536w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-07-at-16.47.31-2048x604.png 2048w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-07-at-16.47.31-954x281.png 954w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-07-at-16.47.31-1354x399.png 1354w\" sizes=\"(max-width: 2768px) 100vw, 2768px\" \/><\/p>\n<p>We also associate the routing table with public subnets:<\/p>\n<ul>\n<li>MGMT-A<\/li>\n<li>MGMT-B<\/li>\n<li>UNTRUST-A<\/li>\n<li>UNTRUST-B<\/li>\n<\/ul>\n<p>Go to the &quot;<strong>Subnet associations<\/strong>&quot; tab and select &quot;<strong>Edit subnet associations<\/strong>&quot;<\/p>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-2395\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-16.21.32.png\" alt=\"\" width=\"2752\" height=\"944\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-16.21.32.png 2752w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-16.21.32-300x103.png 300w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-16.21.32-1024x351.png 1024w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-16.21.32-768x263.png 768w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-16.21.32-1536x527.png 1536w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-16.21.32-2048x703.png 2048w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-16.21.32-954x327.png 954w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-16.21.32-1354x464.png 1354w\" sizes=\"(max-width: 2752px) 100vw, 2752px\" \/><\/p>\n<p>We also associate the table &quot;<strong>TRUST-RT<\/strong>&quot; with the networks &quot;<strong>TRUST-A<\/strong>&quot; and &quot;<strong>TRUST-B<\/strong>&quot;<\/p>\n<p>Now select the &quot;<strong>DEFAULT-RT<\/strong>&quot; table and set it as the main table.<\/p>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-2396\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-16.30.19.png\" alt=\"\" width=\"734\" height=\"724\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-16.30.19.png 734w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-16.30.19-300x296.png 300w\" sizes=\"(max-width: 734px) 100vw, 734px\" \/><\/p>\n<h4>Security Group<\/h4>\n<p>Next, we need to create 4 security groups:<\/p>\n<ul>\n<li>PA-LAB-NETWORK-GP-MGMT-SG<\/li>\n<li>PA-LAB-NETWORK-GP-HA-SG<\/li>\n<li>PA-LAB-NETWORK-GP-UNTRUST-SG<\/li>\n<li>PA-LAB-NETWORK-GP-TRUST-SG<\/li>\n<\/ul>\n<blockquote><p>For HA, you can leave only the necessary ports, but we will simply allow traffic within the security group.<\/p><\/blockquote>\n<p>To do this, go to &quot;<strong>VPC<\/strong>&quot; -&gt; &quot;<strong>Security<\/strong>&quot; and select &quot;<strong>Create security group<\/strong>&quot;. Let&#8217;s create 4 security groups with the following rules:<\/p>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-2368\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-08-at-19.49.12.png\" alt=\"\" width=\"1132\" height=\"446\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-08-at-19.49.12.png 1132w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-08-at-19.49.12-300x118.png 300w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-08-at-19.49.12-1024x403.png 1024w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-08-at-19.49.12-768x303.png 768w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-08-at-19.49.12-954x376.png 954w\" sizes=\"(max-width: 1132px) 100vw, 1132px\" \/><\/p>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-2371\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-08-at-19.45.30.png\" alt=\"\" width=\"2042\" height=\"934\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-08-at-19.45.30.png 2042w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-08-at-19.45.30-300x137.png 300w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-08-at-19.45.30-1024x468.png 1024w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-08-at-19.45.30-768x351.png 768w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-08-at-19.45.30-1536x703.png 1536w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-08-at-19.45.30-954x436.png 954w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-08-at-19.45.30-1354x619.png 1354w\" sizes=\"(max-width: 2042px) 100vw, 2042px\" \/><\/p>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-2393\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-15.48.46.png\" alt=\"\" width=\"2680\" height=\"1112\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-15.48.46.png 2680w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-15.48.46-300x124.png 300w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-15.48.46-1024x425.png 1024w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-15.48.46-768x319.png 768w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-15.48.46-1536x637.png 1536w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-15.48.46-2048x850.png 2048w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-15.48.46-954x396.png 954w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-15.48.46-1354x562.png 1354w\" sizes=\"(max-width: 2680px) 100vw, 2680px\" \/><\/p>\n<p>Check the security groups that they belong to the correct VPC and their rules<\/p>\n<h4><img loading=\"lazy\" class=\"alignnone size-full wp-image-2379\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-08-at-20.46.48.png\" alt=\"\" width=\"2288\" height=\"284\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-08-at-20.46.48.png 2288w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-08-at-20.46.48-300x37.png 300w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-08-at-20.46.48-1024x127.png 1024w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-08-at-20.46.48-768x95.png 768w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-08-at-20.46.48-1536x191.png 1536w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-08-at-20.46.48-2048x254.png 2048w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-08-at-20.46.48-954x118.png 954w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-08-at-20.46.48-1354x168.png 1354w\" sizes=\"(max-width: 2288px) 100vw, 2288px\" \/><\/h4>\n<h4>ENI<\/h4>\n<p>Let&#8217;s create 8 ENIs according to the names of our SGs, associate them with the appropriate security groups, and add a description and a &quot;<strong>Name<\/strong>&quot; tag.<\/p>\n<p>Go to &quot;<strong>EC2<\/strong>&quot; -&gt; &quot;<strong>Network &amp; Security<\/strong>&quot; -&gt; &quot;<strong>Network Interfaces<\/strong>&quot; and select &quot;<strong>Create network interface<\/strong>&quot;<\/p>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-2377\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-08-at-20.32.36.png\" alt=\"\" width=\"1650\" height=\"1258\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-08-at-20.32.36.png 1650w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-08-at-20.32.36-300x229.png 300w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-08-at-20.32.36-1024x781.png 1024w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-08-at-20.32.36-768x586.png 768w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-08-at-20.32.36-1536x1171.png 1536w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-08-at-20.32.36-954x727.png 954w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-08-at-20.32.36-1354x1032.png 1354w\" sizes=\"(max-width: 1650px) 100vw, 1650px\" \/><\/p>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-2378\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-08-at-20.32.52.png\" alt=\"\" width=\"1626\" height=\"1208\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-08-at-20.32.52.png 1626w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-08-at-20.32.52-300x223.png 300w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-08-at-20.32.52-1024x761.png 1024w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-08-at-20.32.52-768x571.png 768w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-08-at-20.32.52-1536x1141.png 1536w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-08-at-20.32.52-954x709.png 954w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-08-at-20.32.52-1354x1006.png 1354w\" sizes=\"(max-width: 1626px) 100vw, 1626px\" \/><\/p>\n<p>Check the created interfaces that they belong to the correct VPC, AZ, and subnets<\/p>\n<h4><img loading=\"lazy\" class=\"alignnone size-full wp-image-2380\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-08-at-20.52.12.png\" alt=\"\" width=\"2346\" height=\"568\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-08-at-20.52.12.png 2346w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-08-at-20.52.12-300x73.png 300w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-08-at-20.52.12-1024x248.png 1024w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-08-at-20.52.12-768x186.png 768w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-08-at-20.52.12-1536x372.png 1536w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-08-at-20.52.12-2048x496.png 2048w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-08-at-20.52.12-954x231.png 954w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-08-at-20.52.12-1354x328.png 1354w\" sizes=\"(max-width: 2346px) 100vw, 2346px\" \/><\/h4>\n<h4>EIP<\/h4>\n<p>Now we need to create 3 EIPs:<\/p>\n<ul>\n<li>GP-MGMT-A<\/li>\n<li>GP-MGMT-B<\/li>\n<li>GP-PORTAL<\/li>\n<\/ul>\n<p>To do this, go to &quot;<strong>VPC<\/strong>&quot; -&gt; &quot;<strong>Virtual private cloud<\/strong>&quot; -&gt; &quot;<strong>Elastic IPs<\/strong>&quot; and select &quot;<strong>Allocate Elastic IP address<\/strong>&quot;. And add the &quot;<strong>Name<\/strong>&quot; tag<\/p>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-2374\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-08-at-20.18.42.png\" alt=\"\" width=\"1436\" height=\"1250\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-08-at-20.18.42.png 1436w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-08-at-20.18.42-300x261.png 300w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-08-at-20.18.42-1024x891.png 1024w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-08-at-20.18.42-768x669.png 768w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-08-at-20.18.42-954x830.png 954w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-08-at-20.18.42-1354x1179.png 1354w\" sizes=\"(max-width: 1436px) 100vw, 1436px\" \/><\/p>\n<p>Check the generated EIPs<\/p>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-2376\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-08-at-20.30.49.png\" alt=\"\" width=\"1930\" height=\"176\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-08-at-20.30.49.png 1930w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-08-at-20.30.49-300x27.png 300w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-08-at-20.30.49-1024x93.png 1024w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-08-at-20.30.49-768x70.png 768w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-08-at-20.30.49-1536x140.png 1536w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-08-at-20.30.49-954x87.png 954w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-08-at-20.30.49-1354x123.png 1354w\" sizes=\"(max-width: 1930px) 100vw, 1930px\" \/><\/p>\n<p>IP addresses &quot;<strong>MGMT-A-EIP<\/strong>&quot; and &quot;<strong>MGMT-B-EIP<\/strong>&quot; we need to associate with the corresponding interfaces, &quot;<strong>GP-PORTAL-IP<\/strong>&quot; &#8212; with the interface &quot;<strong>GP-UNTRUST-A<\/strong>&quot;, it is the instance in AZ A that will be initially active.<\/p>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-2389\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-13.53.27.png\" alt=\"\" width=\"1492\" height=\"1248\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-13.53.27.png 1492w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-13.53.27-300x251.png 300w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-13.53.27-1024x857.png 1024w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-13.53.27-768x642.png 768w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-13.53.27-954x798.png 954w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-13.53.27-1354x1133.png 1354w\" sizes=\"(max-width: 1492px) 100vw, 1492px\" \/><\/p>\n<h4>IAM<\/h4>\n<p>For HA mode, you need to create an <strong>IAM Policy<\/strong> with the following content:<\/p>\n<pre class=\"brush: java; title: ; notranslate\" title=\"\">\r\n{\r\n    &quot;Version&quot;: &quot;2012-10-17&quot;,\r\n    &quot;Statement&quot;: [\r\n        {\r\n            &quot;Action&quot;: [\r\n                &quot;ec2:AttachNetworkInterface&quot;,\r\n                &quot;ec2:DetachNetworkInterface&quot;,\r\n                &quot;ec2:DescribeInstances&quot;,\r\n                &quot;ec2:DescribeNetworkInterfaces&quot;,\r\n                &quot;ec2:AssignPrivateIpAddresses&quot;,\r\n                &quot;ec2:AssociateAddress&quot;,\r\n                &quot;ec2:DescribeRouteTables&quot;\r\n            ],\r\n            &quot;Resource&quot;: [\r\n                &quot;*&quot;\r\n            ],\r\n            &quot;Effect&quot;: &quot;Allow&quot;\r\n        },\r\n        {\r\n            &quot;Action&quot;: [\r\n                &quot;ec2:ReplaceRoute&quot;\r\n            ],\r\n            &quot;Resource&quot;: [\r\n                &quot;arn:aws:ec2:*:*:route-table\/*&quot;\r\n            ],\r\n            &quot;Effect&quot;: &quot;Allow&quot;\r\n        }\r\n    ]\r\n}\r\n<\/pre>\n<p>More information about the required rights can be found <a href=\"https:\/\/docs.paloaltonetworks.com\/vm-series\/10-2\/vm-series-deployment\/set-up-the-vm-series-firewall-on-aws\/high-availability-for-vm-series-firewall-on-aws\/iam-roles-for-ha\" target=\"_blank\" rel=\"noopener\">here<\/a>.<\/p>\n<p>To do this, go to the &quot;<strong>IAM<\/strong>&quot; -&gt; &quot;<strong>Access management<\/strong>&quot; -&gt; &quot;<strong>Policies<\/strong>&quot; section and select &quot;<strong>Create policy<\/strong>&quot;, switch from the visual editor to the &quot;<strong>JSON<\/strong>&quot; tab, and paste our policy.<\/p>\n<p>We will also create an IAM Role, go to the &quot;<strong>IAM<\/strong>&quot; -&gt; &quot;<strong>Access management<\/strong>&quot; -&gt; &quot;<strong>Roles<\/strong>&quot; section and select &quot;<strong>Create role<\/strong>&quot;<\/p>\n<ul>\n<li>Trusted entity type: &quot;AWS service&quot;<\/li>\n<li>Use case: &quot;EC2&quot;<\/li>\n<\/ul>\n<p>And associate the previously created policy.<\/p>\n<h4>MarketPlace<\/h4>\n<p>We will be using the &quot;<strong>VM-Series Next-Generation Firewall (BYOL and ELA)<\/strong>&quot; AMI, but before that, you need to subscribe to it in <a href=\"https:\/\/aws.amazon.com\/marketplace\/pp\/prodview-ccntnbzdod74k?sr=0-1&amp;ref_=beagle&amp;applicationId=AWS-Marketplace-Console\" target=\"_blank\" rel=\"noopener\">AWS MarketPlace<\/a><\/p>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-2385\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-13.45.50.png\" alt=\"\" width=\"2132\" height=\"192\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-13.45.50.png 2132w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-13.45.50-300x27.png 300w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-13.45.50-1024x92.png 1024w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-13.45.50-768x69.png 768w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-13.45.50-1536x138.png 1536w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-13.45.50-2048x184.png 2048w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-13.45.50-954x86.png 954w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-13.45.50-1354x122.png 1354w\" sizes=\"(max-width: 2132px) 100vw, 2132px\" \/><\/p>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-2386\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-13.46.13.png\" alt=\"\" width=\"2224\" height=\"1200\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-13.46.13.png 2224w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-13.46.13-300x162.png 300w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-13.46.13-1024x553.png 1024w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-13.46.13-768x414.png 768w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-13.46.13-1536x829.png 1536w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-13.46.13-2048x1105.png 2048w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-13.46.13-954x515.png 954w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-13.46.13-1354x731.png 1354w\" sizes=\"(max-width: 2224px) 100vw, 2224px\" \/><\/p>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-2387\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-13.48.23.png\" alt=\"\" width=\"2276\" height=\"272\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-13.48.23.png 2276w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-13.48.23-300x36.png 300w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-13.48.23-1024x122.png 1024w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-13.48.23-768x92.png 768w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-13.48.23-1536x184.png 1536w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-13.48.23-2048x245.png 2048w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-13.48.23-954x114.png 954w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-13.48.23-1354x162.png 1354w\" sizes=\"(max-width: 2276px) 100vw, 2276px\" \/><\/p>\n<p>After you have subscribed to AMI, if you go to the configuration you can find the AMI ID for your region<\/p>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-2388\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-13.50.38.png\" alt=\"\" width=\"1272\" height=\"858\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-13.50.38.png 1272w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-13.50.38-300x202.png 300w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-13.50.38-1024x691.png 1024w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-13.50.38-768x518.png 768w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-13.50.38-954x644.png 954w\" sizes=\"(max-width: 1272px) 100vw, 1272px\" \/><\/p>\n<h4>EC2 Instance<\/h4>\n<p>Let&#8217;s create the first instance for <strong>AZ A<\/strong>, specify the AMI ID from the previous step, instance type: <strong>m5.xlarge<\/strong>. Be sure to specify the SSH key, if you don&#8217;t have one, first create or export it.<\/p>\n<p><strong>Network settings<\/strong><\/p>\n<p>Let&#8217;s select our VPC, select any <strong>subnet from<\/strong> <strong>AZ A<\/strong>, as we will connect network interfaces manually (WebUI bug, you will be shown for manual adding only interfaces that are created in the same zone as the subnet, even though we will not use it directly) and be sure to indicate that we will use the existing security group and leave this field empty.<\/p>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-2390\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-15.24.01.png\" alt=\"\" width=\"1516\" height=\"1060\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-15.24.01.png 1516w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-15.24.01-300x210.png 300w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-15.24.01-1024x716.png 1024w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-15.24.01-768x537.png 768w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-15.24.01-954x667.png 954w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-15.24.01-1354x947.png 1354w\" sizes=\"(max-width: 1516px) 100vw, 1516px\" \/><\/p>\n<p>Next, in the tab &quot;<strong>Advanced network configuration<\/strong>&quot; as &quot;<strong>Network interface 1<\/strong>&quot; select the &quot;<strong>MGMT<\/strong>&quot; interface, do not touch all other settings.<\/p>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-2391\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-15.31.33.png\" alt=\"\" width=\"1512\" height=\"790\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-15.31.33.png 1512w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-15.31.33-300x157.png 300w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-15.31.33-1024x535.png 1024w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-15.31.33-768x401.png 768w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-15.31.33-954x498.png 954w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-20-at-15.31.33-1354x707.png 1354w\" sizes=\"(max-width: 1512px) 100vw, 1512px\" \/><\/p>\n<p>We add 3 more additional interfaces in the following order:<\/p>\n<ul>\n<li>HA<\/li>\n<li>UNTRUSTED<\/li>\n<li>TRUSTED<\/li>\n<\/ul>\n<p>In the tab &quot;<strong>Advanced details<\/strong>&quot; we find the item &quot;<strong>IAM instance profile<\/strong>&quot; and select the created IAM Role.<\/p>\n<p>In the same way, we create an <strong>instance for AZ B<\/strong>.<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>&nbsp; The Palo Alto VM-Series Firewall uses an active\/passive configuration for high availability. In which the active firewall constantly synchronizes its configuration and information about active sessions with a similarly configured passive firewall. There are two options for achieving HA on AWS: &quot;Secondary IP Move&quot; and &quot;Dataplane Interface Move&quot;. Secondary IP Move If the active &hellip; <a href=\"https:\/\/artem.services\/?p=2419&#038;lang=en\" class=\"more-link\">\u041f\u0440\u043e\u0434\u043e\u043b\u0436\u0438\u0442\u044c \u0447\u0438\u0442\u0430\u0442\u044c<span class=\"screen-reader-text\"> &quot;Palo Alto VM-Series Firewall: AWS HA Multi AZ for GlobalProtect &#8212; Part 1&quot;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[599,1335],"tags":[543,1899,1901,1903,1905],"_links":{"self":[{"href":"https:\/\/artem.services\/index.php?rest_route=\/wp\/v2\/posts\/2419"}],"collection":[{"href":"https:\/\/artem.services\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/artem.services\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/artem.services\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/artem.services\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2419"}],"version-history":[{"count":6,"href":"https:\/\/artem.services\/index.php?rest_route=\/wp\/v2\/posts\/2419\/revisions"}],"predecessor-version":[{"id":2462,"href":"https:\/\/artem.services\/index.php?rest_route=\/wp\/v2\/posts\/2419\/revisions\/2462"}],"wp:attachment":[{"href":"https:\/\/artem.services\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2419"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/artem.services\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2419"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/artem.services\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2419"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}