Traffic to and from Palo Alto Networks firewall will stop working after Azure SKU upgrade from Basic to Standard

Traffic to and from Palo Alto Networks firewall will stop working after Azure SKU upgrade from Basic to Standard

4908
Created On 05/23/22 21:50 PM - Last Modified 12/04/24 23:07 PM


Symptom


Traffic to and from Palo Alto Networks firewall will stop working after upgrade the SKU (Stock Keeping Unit)from Basic to Standard.



Environment


  • Palo Alto VM Firewalls
  • Supported PAN-OS
  • Microsoft Azure


Cause


  • The issue is caused when Network Security Groups is not associated with the Palo Alto Networks VM Firewall's interfaces and upgrade of SKU is completed as per Azure recommendation

image.png

    image.png



    Resolution


    1. Create Network Security Groups and associate to each Network Interface that needs Public IP addresses.
    2. For details Refer to the following link: Network security groups.


      Additional Information


      Upgrade a public IP address using the Azure portal



      Actions
      • Print
      • Copy Link

        https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000CphBCAS&lang=en_US&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

      Choose Language