SlideShare a Scribd company logo
Ed Caswell
Consulting Engineer
Palo Alto Networks
Securing the Public Cloud
AWS Deployment Scenarios
in
ELB Interoperability
4 | ©2014, Palo Alto Networks. Confidential and Proprietary.
Region 1
Web farm Web farm
Internal
ELB
AZ1 AZ2
External ELB
CloudFormation Template: Automates full
use case deployments
S3: AWS service where bootstrapping files
are stored
CloudWatch: Consumes metrics and makes
intelligent scale in/out decisions
Lambda: Code as a service pushes custom
metrics to CloudWatch via XML API
Auto Scale Groups (ASG): The firewalls are
members of an ASG that scales in/out based
on custom metrics
PAN-OS Bootstrapping: Automates
creation of fully configured firewall
PAN-OS API: enables delivery of custom
metric to CloudWacth
Panorama: Optional but highly
recommended to simplify VM-Series
management
Native AWS and PAN-OS/VM-Series Services Used
5 | © 2015, Palo Alto Networks. Confidential and Proprietary.
AWS Services PAN-OS/VM-Series Services
Region 1
AZ1
External ELB
AZ2
Internal ELB
Web ASG
1
CFT deploys
base topology
ASG1
2 Initial firewalls are
bootstrapped from S3
ASG2
Bootstrapping adds
VM-Series firewalls to
Panorama
Auto Scaling the VM-Series on AWS
6 | © 2016, Palo Alto Networks. Confidential and Proprietary.
Region 1
AZ1
External ELB
AZ2
Internal ELB
Web ASG
ASG1
3
Standard metrics
sent to CloudWatch
4
Alarm triggers
ASG scale out
ASG2
Auto Scaling the VM-Series on AWS
7 | © 2016, Palo Alto Networks. Confidential and Proprietary.
Region 1
AZ1
External ELB
AZ2
Internal ELB
Web ASG
ASG1
5 l function collects
PAN-OS metrics via API
Custom metrics
sent to
CloudWatch
6
7
Alarm triggers FW
ASG scale events
ASG2
Bootstrapping
continues to add
FWs to Panorama
l Function
removes FWs
from Panorama
Auto Scaling the VM-Series on AWS
8 | © 2016, Palo Alto Networks. Confidential and Proprietary.
Region 1
AZ1
IELB VIP 1 IELB VIP 2
AZ2
Web ASG
ASG1 ASG2
8
l function monitors
for ELB VIP changes IELB VIP 3
9 l function deploys new
ASG with NAT rule for new VIP
ASG3
IELB VIP 4
ASG4
External ELB
Internal ELB
Auto Scaling the VM-Series on AWS
9 | © 2016, Palo Alto Networks. Confidential and Proprietary.
InterVPC
Securing one VPC
IPSec VPN
DC-FW1
DC-FW2
AZ1b
Web1-01
Web1-02
AZ1c
Securing one VPC
AZ1b
IPSec VPN
DC-FW1
DC-FW2
Web1-01
Web1-02
Web2-01
Web2-02
IPSec VPNs
Securing lots of VPCs
DC-FW1
DC-FW2
Marketing App
HR App
QA Environment
Dev Environment
Region
Services VPC
Subnet 1
Availability Zone 2
Availability Zone 1
Subnet 2
Region
Subscribing VPC
Subnet 1
Availability Zone 2
Availability Zone 1
Subnet 2
Region
Services VPC
Subnet 1
Availability Zone 2
Availability Zone 1
Subnet 2
DC-FW1
DC-FW2
Services VPC + Hybrid + Internet Gateway
DC-FW1
DC-FW2
Routing
Default route learned via DHCP from IGW on E1/1
Static route defined for enterprise network
Redistribution profile shares static routes with BGP peers
BGP routes propagated into local route table
SNAT on gateway firewall ensure symmetric return
DC-FW1
DC-FW2
More scale
DC-FW1
DC-FW2
LOTS more scale
Direct Connect
Location
Service Provider Links

More Related Content

PPTX
stackArmor - Security MicroSummit - McAfee
PPTX
stackArmor Security MicroSummit - AWS Security with Splunk
PPTX
Strengthening Operations with Splunk and AWS CloudTrail
PPTX
The Serverless Tidal Wave - SwampUP 2018 Keynote
PPTX
Splunk Cloud
PPTX
Running Splunk on AWS
PPTX
How Autodesk Leverages Splunk as an Assurance Platform on AWS
PPTX
Using the Force.com Integration APIs
stackArmor - Security MicroSummit - McAfee
stackArmor Security MicroSummit - AWS Security with Splunk
Strengthening Operations with Splunk and AWS CloudTrail
The Serverless Tidal Wave - SwampUP 2018 Keynote
Splunk Cloud
Running Splunk on AWS
How Autodesk Leverages Splunk as an Assurance Platform on AWS
Using the Force.com Integration APIs

Similar to stackArmor Security MicroSummit - Next Generation Firewalls for AWS (20)

PPTX
AWS Introduction
PPTX
AWS Introduction
PDF
AWS VPC, ELB, Route53 and CloudFront
PDF
Aws Architecture Fundamentals
PPTX
AWS Security Architecture - Overview
PDF
Overview of AWS Building Blocks
PDF
[Jun AWS 201] Technical Workshop
PPTX
AcademyCloudFoundations_Module_10 (2).pptx
PPTX
Enterprise grade firewall and ssl termination to ac by will stevens
PDF
saa3_wk5.pdf
DOC
PDF
Trusted Application Delivery: Achieving Ultimate Security
PPTX
Don't think about the difficulty Let's try to connect easy to IPv6 network w...
PDF
AWS BaseCamp: AWS Architecture Fundamentals
PPTX
Modernizing DevOps
PDF
DEF CON 24 - Rich Mogull - pragmatic cloud security
PDF
게임을 위한 Cloud Native on AWS (김일호 솔루션즈 아키텍트, AWS) :: Gaming on AWS 2018
PPTX
Understanding Virtual Networking in the Cloud - RightScale Compute 2013
PPTX
AWS Accelerated Program - Session 2 - Storage Services.pptx
PDF
Aws Architecture Fundamentals | Dallas
AWS Introduction
AWS Introduction
AWS VPC, ELB, Route53 and CloudFront
Aws Architecture Fundamentals
AWS Security Architecture - Overview
Overview of AWS Building Blocks
[Jun AWS 201] Technical Workshop
AcademyCloudFoundations_Module_10 (2).pptx
Enterprise grade firewall and ssl termination to ac by will stevens
saa3_wk5.pdf
Trusted Application Delivery: Achieving Ultimate Security
Don't think about the difficulty Let's try to connect easy to IPv6 network w...
AWS BaseCamp: AWS Architecture Fundamentals
Modernizing DevOps
DEF CON 24 - Rich Mogull - pragmatic cloud security
게임을 위한 Cloud Native on AWS (김일호 솔루션즈 아키텍트, AWS) :: Gaming on AWS 2018
Understanding Virtual Networking in the Cloud - RightScale Compute 2013
AWS Accelerated Program - Session 2 - Storage Services.pptx
Aws Architecture Fundamentals | Dallas
Ad

More from Gaurav "GP" Pal (17)

PPTX
stackArmor - FedRAMP and 800-171 compliant cloud solutions
PPTX
stackArmor - FedRAMP and 800-171 compliant cloud solutions
PDF
stackArmor MicroSummit - Niksun Network Monitoring - DPI
PDF
Magento Hosting on AWS
PDF
Rapid deployment of Sitecore on AWS
PDF
Secured Hosting of PCI DSS Compliant Web Applications on AWS
PDF
Implementing Secure DevOps on Public Cloud Platforms
PDF
FGMC - Managed Data Platform - CloudDC Meetup
PPTX
stackArmor presentation for DevOpsDC ver 4
PDF
AWS Frederick Meetup 07192016
PPTX
DevOps for ETL processing at scale with MongoDB, Solr, AWS and Chef
PPTX
Hosting Tableau on AWS
PDF
AWS Security Best Practices, SaaS and Compliance
PDF
Big Data - Accountability Solutions for Public Sector Programs
PDF
2013 11-06 adopting aws at scale - lessons from the trenches
PDF
DevOps in the Amazon Cloud – Learn from the pioneersNetflix suro
PPTX
Enterprise transformation with cloud computing Jan 2014
stackArmor - FedRAMP and 800-171 compliant cloud solutions
stackArmor - FedRAMP and 800-171 compliant cloud solutions
stackArmor MicroSummit - Niksun Network Monitoring - DPI
Magento Hosting on AWS
Rapid deployment of Sitecore on AWS
Secured Hosting of PCI DSS Compliant Web Applications on AWS
Implementing Secure DevOps on Public Cloud Platforms
FGMC - Managed Data Platform - CloudDC Meetup
stackArmor presentation for DevOpsDC ver 4
AWS Frederick Meetup 07192016
DevOps for ETL processing at scale with MongoDB, Solr, AWS and Chef
Hosting Tableau on AWS
AWS Security Best Practices, SaaS and Compliance
Big Data - Accountability Solutions for Public Sector Programs
2013 11-06 adopting aws at scale - lessons from the trenches
DevOps in the Amazon Cloud – Learn from the pioneersNetflix suro
Enterprise transformation with cloud computing Jan 2014
Ad

Recently uploaded (20)

PDF
NewMind AI Weekly Chronicles - August'25 Week I
PDF
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
PDF
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
PDF
NewMind AI Monthly Chronicles - July 2025
PDF
Dropbox Q2 2025 Financial Results & Investor Presentation
PDF
How UI/UX Design Impacts User Retention in Mobile Apps.pdf
PPT
“AI and Expert System Decision Support & Business Intelligence Systems”
PDF
Electronic commerce courselecture one. Pdf
PPT
Teaching material agriculture food technology
PDF
cuic standard and advanced reporting.pdf
PDF
Modernizing your data center with Dell and AMD
DOCX
The AUB Centre for AI in Media Proposal.docx
PPTX
Cloud computing and distributed systems.
PDF
Mobile App Security Testing_ A Comprehensive Guide.pdf
PDF
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
PDF
The Rise and Fall of 3GPP – Time for a Sabbatical?
PDF
KodekX | Application Modernization Development
PDF
Approach and Philosophy of On baking technology
PDF
Agricultural_Statistics_at_a_Glance_2022_0.pdf
PDF
Building Integrated photovoltaic BIPV_UPV.pdf
NewMind AI Weekly Chronicles - August'25 Week I
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
NewMind AI Monthly Chronicles - July 2025
Dropbox Q2 2025 Financial Results & Investor Presentation
How UI/UX Design Impacts User Retention in Mobile Apps.pdf
“AI and Expert System Decision Support & Business Intelligence Systems”
Electronic commerce courselecture one. Pdf
Teaching material agriculture food technology
cuic standard and advanced reporting.pdf
Modernizing your data center with Dell and AMD
The AUB Centre for AI in Media Proposal.docx
Cloud computing and distributed systems.
Mobile App Security Testing_ A Comprehensive Guide.pdf
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
The Rise and Fall of 3GPP – Time for a Sabbatical?
KodekX | Application Modernization Development
Approach and Philosophy of On baking technology
Agricultural_Statistics_at_a_Glance_2022_0.pdf
Building Integrated photovoltaic BIPV_UPV.pdf

stackArmor Security MicroSummit - Next Generation Firewalls for AWS

  • 1. Ed Caswell Consulting Engineer Palo Alto Networks Securing the Public Cloud AWS Deployment Scenarios
  • 2. in
  • 4. 4 | ©2014, Palo Alto Networks. Confidential and Proprietary. Region 1 Web farm Web farm Internal ELB AZ1 AZ2 External ELB
  • 5. CloudFormation Template: Automates full use case deployments S3: AWS service where bootstrapping files are stored CloudWatch: Consumes metrics and makes intelligent scale in/out decisions Lambda: Code as a service pushes custom metrics to CloudWatch via XML API Auto Scale Groups (ASG): The firewalls are members of an ASG that scales in/out based on custom metrics PAN-OS Bootstrapping: Automates creation of fully configured firewall PAN-OS API: enables delivery of custom metric to CloudWacth Panorama: Optional but highly recommended to simplify VM-Series management Native AWS and PAN-OS/VM-Series Services Used 5 | © 2015, Palo Alto Networks. Confidential and Proprietary. AWS Services PAN-OS/VM-Series Services
  • 6. Region 1 AZ1 External ELB AZ2 Internal ELB Web ASG 1 CFT deploys base topology ASG1 2 Initial firewalls are bootstrapped from S3 ASG2 Bootstrapping adds VM-Series firewalls to Panorama Auto Scaling the VM-Series on AWS 6 | © 2016, Palo Alto Networks. Confidential and Proprietary.
  • 7. Region 1 AZ1 External ELB AZ2 Internal ELB Web ASG ASG1 3 Standard metrics sent to CloudWatch 4 Alarm triggers ASG scale out ASG2 Auto Scaling the VM-Series on AWS 7 | © 2016, Palo Alto Networks. Confidential and Proprietary.
  • 8. Region 1 AZ1 External ELB AZ2 Internal ELB Web ASG ASG1 5 l function collects PAN-OS metrics via API Custom metrics sent to CloudWatch 6 7 Alarm triggers FW ASG scale events ASG2 Bootstrapping continues to add FWs to Panorama l Function removes FWs from Panorama Auto Scaling the VM-Series on AWS 8 | © 2016, Palo Alto Networks. Confidential and Proprietary.
  • 9. Region 1 AZ1 IELB VIP 1 IELB VIP 2 AZ2 Web ASG ASG1 ASG2 8 l function monitors for ELB VIP changes IELB VIP 3 9 l function deploys new ASG with NAT rule for new VIP ASG3 IELB VIP 4 ASG4 External ELB Internal ELB Auto Scaling the VM-Series on AWS 9 | © 2016, Palo Alto Networks. Confidential and Proprietary.
  • 11. Securing one VPC IPSec VPN DC-FW1 DC-FW2 AZ1b Web1-01 Web1-02
  • 12. AZ1c Securing one VPC AZ1b IPSec VPN DC-FW1 DC-FW2 Web1-01 Web1-02 Web2-01 Web2-02 IPSec VPNs
  • 13. Securing lots of VPCs DC-FW1 DC-FW2 Marketing App HR App QA Environment Dev Environment
  • 14. Region Services VPC Subnet 1 Availability Zone 2 Availability Zone 1 Subnet 2 Region Subscribing VPC Subnet 1 Availability Zone 2 Availability Zone 1 Subnet 2
  • 15. Region Services VPC Subnet 1 Availability Zone 2 Availability Zone 1 Subnet 2
  • 16. DC-FW1 DC-FW2 Services VPC + Hybrid + Internet Gateway
  • 17. DC-FW1 DC-FW2 Routing Default route learned via DHCP from IGW on E1/1 Static route defined for enterprise network Redistribution profile shares static routes with BGP peers BGP routes propagated into local route table SNAT on gateway firewall ensure symmetric return
  • 19. DC-FW1 DC-FW2 LOTS more scale Direct Connect Location Service Provider Links

Editor's Notes

  • #14: Too many firewalls to purchase, manage, monitor Too many enforcements points Who’s job to add the FWs to the VPCs?
  • #15: Routing: VM-Series learns default route via DHCP VM-Series redistributes default route into BGP VM-Series shares default route with each VGW via BGP peering Each VGW propagates the default route it learned via BGP into the local route table EC2 instances require no special configuration for routing – just the default GW they learned via DHCP