Secure your inbound traffic using the Azure gateway load balancer (GWLB).
| Where Can I Use This? | What Do I Need? |
- Microsoft Azure
- Microsoft Azure Stack
- Azure® Marketplace
- Azure China Marketplace
- Azure Government Marketplace
|
- VM-Series License (PAYG or BYOL)
- VM-Series plugin
- Panorama
- Panorama plugin for Azure
|
You can now deploy the VM-Series firewall for Azure in integration with the Azure
gateway load balancer (GWLB). Securing inbound traffic requires complete visibility
of the traffic source’s identity as it travels to its destination in the cloud. When
you deploy the VM-Series firewalls behind a public standard load balancer, the
source IP addresses of inbound traffic are replaced with the IP address of the load
balancer. As a result, application source identity is obfuscated. By deploying the
VM-Series firewalls behind the Azure GWLB, traffic packet headers and payload are
kept intact, which provides complete visibility of the source’s identity as it
travels to its destination. When Azure GWLB integration is enabled, the VM-Series
uses VXLAN packets to inspect the inner packet of traffic and apply policy to that
packet.
When deployed behind the Azure GWLB, VM-Series firewalls can enforce a
zone-based security policy. You can segment VNet-bound and internet-bound traffic by
assigning a trust zone to the VNet-bound traffic and untrust-zone for the
internet-bound traffic.
With this integration, you can deploy the VM-Series firewall as a backend to the
Azure GWLB in all supported regions.
VM-Series firewall integration with the Azure GWLB requires PAN-OS 10.1.4
or later and VM-Series plugin 2.1.4 or later.
VM-Series firewall integration with the Azure GWLB is supports IPv4 only.
IPv6 only is not supported on the Azure GWLB.
Follow best practices to not overlap the CIDRs used by
different VNets.