| Where Can I Use This? | What Do I Need? |
|
|
- CN-Series 10.2.x or above Container Images
- Panorama running PAN-OS 10.2.x or above version
- Helm 3.6 or above version client for CN-Series deployment with helm chart
|
You can now deploy the CN-Series as a Container
Network Function (CNF) in your Kubernetes environment.
CN-Series as a daemonset and CN-Series as a kubernetes-service deployment mode provide an
automated security deployment and leverage the auto-scaling capabilities of Kubernetes. However,
these deployment modes have limited insertion options and don’t support I/O acceleration. In
addition, they limit the achievable throughput for the application pods that require inspection
and use multiple network interfaces.
Deploying the CN-series as a kubernetes-CNF resolves these challenges for traffic that uses
Service Function Chaining (SFC) through external entities such as cloud provider's native
routing, vRouters, and Top of Rack (TOR) switches. The CN-series as a kubernetes-CNF mode of
deployment does not impact the application pods.
Complete the following procedure to deploy the CN-series as a kubernetes-CNF .
Before
you begin, ensure the CN-Series YAML file version is compatible
with the PAN-OS version:
PAN-OS 10.2.0 or later requires YAML
3.0.0