Пікірлер
@yuding1833
@yuding1833 22 күн бұрын
Great Video !
@mohammadchavoshi5568
@mohammadchavoshi5568 Ай бұрын
🙏🏽🙏🏽🙏🏽🙏🏽🙏🏽
@djangosmissingfingers
@djangosmissingfingers 2 ай бұрын
This is awesome. I would love to see an explanation of how this changes with Overlay routing and app-vpc to subint matching as well.
@abelcarvajalgil6705
@abelcarvajalgil6705 3 ай бұрын
Thank you for your job. Excellent explication traffic North-South East-West
@alinaqvi385
@alinaqvi385 6 ай бұрын
Excellent and thank you, Mr. Carter.
@ralphcarter769
@ralphcarter769 3 ай бұрын
You are very welcome
@jayf9553
@jayf9553 8 ай бұрын
ON the data port of the Palo's do we set up zones? I feel like you lose the ability to apply zones if you're routing all traffic though that data port without applying multiple zones. How do you apply multiple zones to one interface?
@maxcavalera917
@maxcavalera917 3 ай бұрын
You can use sub-interfaces(this will over complicate the design) or you can just control traffic based on src/dst instead of zones (you will need to deny all intra-zone traffic that is allow by default)
@tdelnatte
@tdelnatte 8 ай бұрын
Great job, very grateful. Jusk ask, is it possible to create a gateway loadbalancer endpoint cross account environnement typically for inbound from internet?
@user-sf1cv5np6o
@user-sf1cv5np6o 9 ай бұрын
Awesome video
@arunabhbiswas3210
@arunabhbiswas3210 10 ай бұрын
Very few videos available on KZbin that talks about this architecture, but yours one is unique and best of all. Quick question about the outbound traffic (north-south) that is flowing from PROD vpc to the internet via security vpc transit attachment, that has only routes to security vpc, prod vpc and dev vpc, but i dont see any entry that tells it to redirect this outbound traffic to security vpc. Then how come it will reach to security vpc transit eni? can you please explain this?
@sunilgavaskark7423
@sunilgavaskark7423 11 ай бұрын
Very easy and nice Explanation. Thank you.
@sunilgavaskark7423
@sunilgavaskark7423 11 ай бұрын
Thanks for the Excellent Video !
@AdityaM35
@AdityaM35 11 ай бұрын
Can we have inbound update?
@slogoheinzy8695
@slogoheinzy8695 3 ай бұрын
can we Ralph ?
@yourrakesh123
@yourrakesh123 Жыл бұрын
This is an awesome tutorial that I was searching on youtube. Excellent explanation on setting up GWLB and firewall in multi-account environment through TGW. :)
@BreathingBadminton
@BreathingBadminton Жыл бұрын
Thank you for the detailed diagram and explanation. Keep up the Good Job.
@EE-eg2bp
@EE-eg2bp Жыл бұрын
Thanks so much for this! It helped me figure out the missing piece in my deployment that I was struggling with. I simply forgot to point the default route on the Palos to the service BD's gateway.
@danieloctavianus2295
@danieloctavianus2295 Жыл бұрын
Question : Why you have to configure the BD ip address on subnet section? that is for route leak, right?
@hakinen4000
@hakinen4000 Жыл бұрын
Hi Ralph, thank you for posting this, truly helped this newbie understand how AWS GW can be used. I do have a question, what if this is trying to be deployed in an environment that already has PA's setup across multiple sites and these sites connect to the Core (via IPSEC), where most of our on-prem apps reside? Thanks again for the great and easy to understand video
@David-bc2oj
@David-bc2oj Жыл бұрын
What would the architecture look like if I needed to put a WAF in front of the http/https ports? The WAF would be working together with the Palo Alto NGFW to handle non-http/https traffic
@ADV-IT
@ADV-IT Жыл бұрын
Great detailed explanation, thanks!
@roysegev6172
@roysegev6172 Жыл бұрын
What is the service bridge domain?
@chrisholman7468
@chrisholman7468 Жыл бұрын
I found this very insightful (well earned kudos to you Ralph), but when trying to implement it, I can't make it support a load balanced application. The Prod IGW routing table only routes to AZ 1a, therefore the app is not load balanced. I've been trying to figure out how to make this possible, but no luck so far. Any hints welcome.
@MrGlaska
@MrGlaska Жыл бұрын
What if you are using active/standby FW? Do you need select L3 VIP then?
@daschboot
@daschboot Жыл бұрын
thanks for the explanation Ralph, it is clear and understandable.
@bx1803
@bx1803 Жыл бұрын
Is there a template for this available?
@cciecollabv2666
@cciecollabv2666 Жыл бұрын
Guys Why he didnt use L3OUT with INET Routers ? do u think he were was going with a poor Design , at least not a CVD !!!! Pls Advise Thanks
@srinivasanandababu2701
@srinivasanandababu2701 Жыл бұрын
Can we use VPCe instead of traversing via Transit GW?
@mehulpruthi
@mehulpruthi Жыл бұрын
Thank a ton Ralph, request you to teach us about Azure GWLB with PAN Firewalls for Inbound, Outbound and East-West Security
@shamstabrez2986
@shamstabrez2986 2 жыл бұрын
plz make video on cloud wan with complete details n hands on lab
@yahiaccnp1310
@yahiaccnp1310 2 жыл бұрын
can we connect firewall as a per metal server and put gateway on it and all communication from Fabric went through it.
@vainilk78
@vainilk78 2 жыл бұрын
Ralph, that was a great session. I want to know what charting tool you used ? I want to learn more about it to map my AWS drawing design better.
@abdimohamed1554
@abdimohamed1554 2 жыл бұрын
Great info. Where is part 2?
@edgarssimanis9381
@edgarssimanis9381 2 жыл бұрын
Thanks, awesome explanation
@arindamsaha9052
@arindamsaha9052 2 жыл бұрын
That was an awesome explanation.
@johnjiang2470
@johnjiang2470 2 жыл бұрын
Ralph, great presentation!
@randicalib
@randicalib 2 жыл бұрын
hi, where can i watch the configuration video?
@nash.p9781
@nash.p9781 2 жыл бұрын
Great video Ralph, super presentation.
@VirtualizeStuff
@VirtualizeStuff 2 жыл бұрын
Excellent job Ralph explaining the GWLB and the awesome packet walk! Learned a ton!
@intellectMind2024
@intellectMind2024 2 жыл бұрын
Great Ralph, any new videos if you could post .. That would be really helpful my friend 🥰
@trandat7274
@trandat7274 2 жыл бұрын
Many thanks Ralph, your video is very very great.... Thanks a lot !!!!
@zubairqureshi9063
@zubairqureshi9063 2 жыл бұрын
Awesome presentation and explanation 👍🏻
@CreateWithDre
@CreateWithDre 2 жыл бұрын
Love it Ralph. Got this one working manually and traffic is flowing inbound/outbound as intended. Only issue is with Global Protect, my VPN users can't seem to connect to internal resources. Is that because the return path is coming back across the GWLB, but the forwarding to a server (is going across the TGW)? Any suggestions/articles that you know of addressing this concern? Thanks so much and keep up the great work.
@SudhaGanapareddy
@SudhaGanapareddy 2 жыл бұрын
Great, This helps me to understand the outline of ACI.
@dougclendening5896
@dougclendening5896 2 жыл бұрын
What if you don't want inline and just want to mirror the TGW traffic off to a security vpc to be analyzed?
@teibidh
@teibidh 2 жыл бұрын
You want VPC Traffic Mirroring for this, I believe.
@user-xs6hr1ol7d
@user-xs6hr1ol7d 2 жыл бұрын
Quite Impressive !
@nonatercesa2865
@nonatercesa2865 2 жыл бұрын
Very nice video; well explained. Thanks Ralph. I have a few questions though. Is there a reason why you did not allow the Palo Alto (PA) firewalls to act as the NAT gateway? I have a new AWS deployment with PA firewalls in active-passive mode but one of the infrastructure requirement is to allow the PA to act as the NAT gateway, and as the VPN Gateway because the intention is to create a site-to-site (S2S) IPSec tunnel between the PA in AWS and another PA that is on-premise. I like to know if I will still need a GWLB in a case where the PAs are in active-passive and not in active-active. Awaiting your reply. Thanks again.
@matheusbertimansano9693
@matheusbertimansano9693 2 жыл бұрын
i m curious as well to know if is required
@vennempify
@vennempify 2 жыл бұрын
@@matheusbertimansano9693 Apparently this is supported with a slightly different architecture - I'm playing with this now and have the above architecture working as expected. I believe if you wanted to NAT out thru PAT it would rrequire another feature called Overlay Routing which released in 10.0.3 or 10.0.4.
@abdallahezat8604
@abdallahezat8604 2 жыл бұрын
great effort !
@Shanayathukral
@Shanayathukral 2 жыл бұрын
Hi Raplh, great video! U mentioned about part 2 on how to ? May i know when u are doing that video?
@looqmern
@looqmern 2 жыл бұрын
Hi, how does one configure the palo alto to use one interface for inbound and outbound traffic and what does the security policy look like? Thanks
@Shanayathukral
@Shanayathukral 2 жыл бұрын
I think it will be same zone to same zone policy, but your source destination subnet will be used as a differentiator.
@dmohan16
@dmohan16 2 жыл бұрын
Excellent explanation..!! well articulated with the traffic flows.
@s_dee_13
@s_dee_13 2 жыл бұрын
Does this support ipv6?