没有合适的资源?快使用搜索试试~ 我知道了~
vm-series-deployment.pdf
需积分: 5 0 下载量 150 浏览量
2023-10-27
01:20:48
上传
评论
收藏 44.84MB PDF 举报
温馨提示
试读
1102页
vm-series-deployment.pdf
资源推荐
资源详情
资源评论
VM-Series Deployment Guide
Version 10.2
docs.paloaltonetworks.com
Contact Information
Corporate Headquarters:
Palo Alto Networks
3000 Tannery Way
Santa Clara, CA 95054
www.paloaltonetworks.com/company/contact-support
About the Documentation
• For the most recent version of this guide or for access to related documentation, visit the Technical
Documentation portal docs.paloaltonetworks.com.
• To search for a specific topic, go to our search page docs.paloaltonetworks.com/search.html.
• Have feedback or questions for us? Leave a comment on any page in the portal, or write to us at
documentation@paloaltonetworks.com.
Copyright
Palo Alto Networks, Inc.
www.paloaltonetworks.com
©
2021-2022 Palo Alto Networks, Inc. Palo Alto Networks is a registered trademark of Palo
Alto Networks. A list of our trademarks can be found at www.paloaltonetworks.com/company/
trademarks.html. All other marks mentioned herein may be trademarks of their respective companies.
Last Revised
February 26, 2022
VM-Series Deployment Guide Version 10.2 2
©
2023 Palo Alto Networks, Inc.
Table of Contents
About the VM-Series Firewall...................................................................... 15
VM-Series Deployments..........................................................................................................16
VM-Series in High Availability............................................................................................... 17
Upgrade the VM-Series Firewall........................................................................................... 19
Upgrade the PAN-OS Software Version (Standalone Version)...........................19
Upgrade the PAN-OS Software Version (HA Pair)................................................21
Upgrade the PAN-OS Software Version Using Panorama...................................25
Upgrade the PAN-OS Software Version (VM-Series for NSX)........................... 28
Upgrade the VM-Series Model.................................................................................. 34
Upgrade the VM-Series Model in an HA Pair........................................................ 36
Downgrade a VM-Series Firewall to a Previous Release..................................... 37
VM-Series Plugin....................................................................................................................... 38
Configure the VM-Series Plugin on the Firewall................................................... 38
Upgrade the VM-Series Plugin...................................................................................39
Enable Jumbo Frames on the VM-Series Firewall............................................................ 42
Hypervisor Assigned MAC Addresses................................................................................. 44
Custom PAN-OS Metrics Published for Monitoring.........................................................46
Interface Used for Accessing External Services on the VM-Series Firewall................48
PacketMMAP and DPDK Driver Support........................................................................... 49
Enable NUMA Performance Optimization on the VM-Series........................................ 51
Enable ZRAM on the VM-Series Firewall........................................................................... 53
License the VM-Series Firewall....................................................................55
VM-Series Firewall Licensing................................................................................................. 56
License Types..................................................................................................................56
Flexible vCPUs and Fixed Model Licensing.............................................................57
Flexible vCPUs and Fixed Model Deployment.......................................................59
Create a Support Account...................................................................................................... 61
Serial Number and CPU ID Format for the VM-Series Firewall.................................... 62
Use Panorama-Based Software Firewall License Management.....................................63
Software NGFW Credits......................................................................................................... 69
Maximum Limits Based on Tier and Memory.........................................................72
Activate Credits..............................................................................................................81
Create a Deployment Profile...................................................................................... 82
Manage a Deployment Profile....................................................................................84
Register the VM-Series Firewall (Software NGFW Credits)................................86
Provision Panorama.......................................................................................................89
Migrate Panorama to a Software NGFW License................................................. 90
VM-Series Deployment Guide Version 10.2 3
©
2023 Palo Alto Networks, Inc.
Table of Contents
Transfer Credits..............................................................................................................94
Renew Your Software NGFW Credits......................................................................96
Amend and Extend a Credit Pool.............................................................................. 97
Deactivate License (Software NGFW Credits)....................................................... 98
Delicense Ungracefully Terminated Firewalls...................................................... 100
Set the Number of Licensed vCPUs.......................................................................101
Customize Dataplane Cores..................................................................................... 102
Migrate a Firewall to a Flexible VM-Series License............................................103
Software NGFW Licensing API................................................................................107
VM-Series Models.................................................................................................................. 119
VM-Series System Requirements............................................................................120
CPU Oversubscription................................................................................................122
VM-50 Lite Mode....................................................................................................... 123
VM-Series Model License Types............................................................................. 124
Activate VM-Series Model Licenses.......................................................................135
Register the VM-Series Firewall..............................................................................141
Install a Device Certificate on the VM-Series Firewall...................................... 144
Switch Between the BYOL and the PAYG Licenses...........................................149
Switch Between VM-Series Model Licenses........................................................ 150
Deactivate License(s)..................................................................................................153
Renew VM-Series Firewall License Bundles.........................................................158
Install a License API Key........................................................................................... 160
Licensing API................................................................................................................ 161
What Happens When Licenses Expire?............................................................................ 167
Licenses for Cloud Security Service Providers (CSSPs)................................................. 170
Get the Auth Codes for CSSP License Packages.................................................170
Register the VM-Series Firewall with a CSSP Auth Code................................. 171
Add End-Customer Information for a Registered VM-Series Firewall............172
Set Up a VM-Series Firewall on an ESXi Server.................................... 177
Supported Deployments on VMware vSphere Hypervisor (ESXi).............................. 178
VM-Series on ESXi System Requirements and Limitations.......................................... 179
VM-Series on ESXi System Requirements............................................................ 179
VM-Series on ESXi System Limitations................................................................. 180
Install a VM-Series firewall on VMware vSphere Hypervisor (ESXi).......................... 181
Plan the Interfaces for the VM-Series for ESXi................................................... 181
Provision the VM-Series Firewall on an ESXi Server..........................................182
Perform Initial Configuration on the VM-Series on ESXi.................................. 185
Add Additional Disk Space to the VM-Series Firewall.......................................186
Use VMware Tools on the VM-Series Firewall on ESXi and vCloud Air........ 188
Use vMotion to Move the VM-Series Firewall Between Hosts.......................189
VM-Series Deployment Guide Version 10.2 4
©
2023 Palo Alto Networks, Inc.
Table of Contents
Use the VM-Series CLI to Swap the Management Interface on ESXi.............190
VM Monitoring on vCenter..................................................................................................191
About VM Monitoring on VMware vCenter........................................................ 191
Install the Panorama Plugin for VMware vCenter.............................................. 192
Configure the Panorama Plugin for VMware vCenter....................................... 193
Troubleshoot ESXi Deployments........................................................................................196
Basic Troubleshooting................................................................................................196
Installation Issues........................................................................................................ 196
Licensing Issues............................................................................................................198
Connectivity Issues..................................................................................................... 199
Performance Tuning of the VM-Series for ESXi............................................................. 201
Install the NIC Driver on ESXi................................................................................. 201
Enable DPDK on ESXi................................................................................................202
Enable SR-IOV on ESXi..............................................................................................203
Enable ESXi VLAN Access Mode with SR-IOV....................................................203
Enable Multi-Queue Support for NICs on ESXi...................................................204
VNF Tuning for Performance...................................................................................205
Set Up the VM-Series Firewall on vCloud Air........................................219
About the VM-Series Firewall on vCloud Air.................................................................. 220
Deployments Supported on vCloud Air............................................................................ 221
Deploy the VM-Series Firewall on vCloud Air................................................................ 222
Set Up the VM-Series Firewall on VMware NSX-T.............................. 231
Set Up the VM-Series Firewall on VMware NSX-T (North-South).............................232
Supported Deployments of the VM-Series Firewall on VMware NSX-T (North-
South)..............................................................................................................................232
Components of the VM-Series Firewall on NSX-T (North-South)...................233
Deploy the VM-Series Firewall on NSX-T (North-South)..................................234
Extend Security Policy from NSX-V to NSX-T.....................................................248
Set Up the VM-Series Firewall on NSX-T (East-West)..................................................250
Components of the VM-Series Firewall on NSX-T (East-West).......................250
VM-Series Firewall on NSX-T (East-West) Integration...................................... 251
Supported Deployments of the VM-Series Firewall on VMware NSX-T (East-
West).............................................................................................................................. 253
Deploy the VM-Series Using the Operations-Centric Workflow.................... 255
Deploy the VM-Series Using the Security-Centric Workflow..........................273
Delete a Service Definition from Panorama.........................................................303
Migrate from VM-Series on NSX-T Operation to Security Centric
Deployment...................................................................................................................304
Extend Security Policy from NSX-V to NSX-T.....................................................310
Use In-Place Migration to Move Your VM-Series from NSX-V to NSX-T..... 311
VM-Series Deployment Guide Version 10.2 5
©
2023 Palo Alto Networks, Inc.
剩余1101页未读,继续阅读
资源评论
mr.card
- 粉丝: 0
- 资源: 33
上传资源 快速赚钱
- 我的内容管理 展开
- 我的资源 快来上传第一个资源
- 我的收益 登录查看自己的收益
- 我的积分 登录查看自己的积分
- 我的C币 登录后查看C币余额
- 我的收藏
- 我的下载
- 下载帮助
安全验证
文档复制为VIP权益,开通VIP直接复制
信息提交成功