In this scenario, you’ll transfer your BYOIP addresses from your AWS account to
avoid incurring hourly EIP management costs.
To use BYOIPs, you must create a
IP Address Management (IPAM) pool in
your AWS account and share it in your Cloud NGFW for AWS deployment account.
IPAM helps manage your IP addressing schema to meet security requirements. See
Bring your own IP addresses on the AWS
site for more information. Egress NAT is supported for rulestack and Panorama
policy management only.
When creating an IPAM pool in AWS you must whitelist the Palo Alto
Networks AWS Account ID for Cloud NGFW to share IP addresses between the
Cloud NGFW dataplane and AWS. During the IPAM pool creation process, you
select the option to Allow Amazon VPC IP Address
Manager (a mandatory step to create the IPAM pool);
specify the AWS Data Plane Account ID for your Cloud NGFW resource:
010510656586.
It may take approximately 10 minutes to create an IPAM pool.
IPv6 Protocol Compatibility and NAT Limitations
Source-Based NAT (SNAT/NAT66): Source-based address
translation, also known as NAT66 is not supported for IPv6
traffic. All IPv6-to-IPv6 communication uses native routing without
address translation.
When EgressNAT is enabled on an IPv6-enabled firewall, source
address translation (NAT) is only applied to IPv4 traffic.
Outbound IPv6 traffic uses native, legacy IPv6 routing without
address translation.
Egress NAT translates a private IP address to a public routable address
by altering the source address of packets passing through the Cloud NGFW,
allowing connections to be initiated only for outgoing network connections.
For Cloud NGFW instances deployed in IPv6 environments, Egress
NAT is supported for IPv4 traffic only. IPv6-to-IPv6
communication utilizes native routing without address translation.
Create an IPAM Pool
To create an IPAM pool: