Palo Alto Series - Specifications
Overview
This page documents the customer-facing specifications for the Palo Alto Series VM‑Series virtual firewall. The VNF supports single and dual deployment modes; choose deployment mode during creation. Use the Create page to provide deployment inputs and this Specifications page to review images, flavors, interfaces and service parameters.
Flavors
Choose a VM flavor that matches your expected load and whether you need DPDK support. The available sizes are rendered below.
| Standard | DPDK | |
|---|---|---|
| Small | 2 vCPU 8 GB Mem 64 GB Disk | 2 vCPU 4 GB Mem 64 GB Disk |
| Medium | 4 vCPU 16 GB Mem 64 GB Disk | 4 vCPU 16 GB Mem 64 GB Disk |
| Large | 8 vCPU 32 GB Mem 64 GB Disk | 8 vCPU 32 GB Mem 64 GB Disk |
Interfaces
The diagram above shows the main customer-facing topology: the VM and its three interfaces. Individual VLAN sub-interfaces (101–148) are grouped for readability; their per-VLAN parameters are documented below.
Common interface behavior:
- Public IP addresses for Internet-facing interfaces are platform-generated outputs shown after deployment.
- Interface numbering is preserved as #1, #2, #3; optional interfaces are indicated in their sections.
#1 - Internet Interface - management
Role: out-of-band management / Internet management interface.
- No customer configuration is required for this interface during creation. The platform will allocate and display a Public IP address (management) as a deployment output.
- This interface is informational in the provisioning flow; the public IP is a platform-generated output.
#2 - Internet Interface
Role: Internet access for customer traffic.
- The platform provides a primary public IP for this interface as a deployment output.
- To request additional public IPv4 addresses, use the Added IP address number parameter. This is optional and updatable and accepts an integer from 1 to 8.
- Additional public IPs, when allocated, are shown in deployment outputs alongside the primary public IP.
#3 - MPLS‑VPN interface
Role: connects the VM to Orange MPLS‑VPN using VLAN sub-interfaces.
- Configure VLAN sub-interfaces (101–148) to map MPLS VPN entries to the device.
- Each VLAN sub-interface accepts a VPN list (one or more VPN entries). For each VPN entry you provide a VPN Name and optionally a VPN role (options: any-to-any, client, server).
- BGP can be enabled per VLAN sub-interface using the Enable BGP boolean (default: false). When enabled, BGP-specific fields become relevant for that VLAN/sub-interface.
- AS prepend is an optional integer used per VLAN BGP settings; valid values are 1..6 and should be provided only when instructed by your network operator.
For large numbers of VLANs, configure a representative VLAN entry and repeat as needed in the provisioning UI; the platform accepts per-VLAN entries for the listed range.
Software device versions
Available Palo Alto VM‑Series images are rendered below. Choose an image variant that matches your flavor (DPDK variants pair with DPDK-capable flavors).
- 10.2.10-h9
Virtual device parameters
Provide these VM-level values during creation.
- VM name — required. Hostname used as the VM identifier. Must be a short hostname matching pattern [a-zA-Z0-9-]* and maximum length 22 characters.
- VM image — required. Select one of the supported VM‑Series images provided by the platform. DPDK variants are available for use with DPDK flavors.
- VM flavor — required. Choose a flavor matching your performance and DPDK requirements. DPDK-capable flavors should be used with DPDK images.
- VM AS number — optional. Provide an autonomous system number if you plan to use BGP on the VM. Accepts 2- or 4-byte AS values (range 1 .. 4294967295).
Service-specific parameters
Service-specific parameters are requested at service level (not per-VM or per-interface). They are required by the provisioning workflow and are distinct from platform-generated outputs.
-
Hashed password (mandatory, secret): Provide the administrative password already hashed using the vendor-approved method. The platform expects the hashed form; do not submit plaintext. This value is hidden in the UI and is not updatable after provisioning.
-
IPv4 address of the primary Panorama server (optional): If you use Panorama for centralized management, provide the IPv4 address of your primary Panorama server so the VM can be preconfigured to contact it. Must be a valid IPv4 address; this field is not updatable.
-
IPv4 address of the secondary Panorama server (optional): Secondary Panorama IPv4 address for fallback management. Provide a valid IPv4 address if applicable.
-
Authentication key (optional, secret): Opaque key used for vendor provisioning or auto-registration. Provide only if required by your onboarding process; the value is hidden and not displayed after input.
-
Template name (optional): Vendor template identifier to apply on the VM during initialization. Provide the exact template name if you want automated template application.
-
Devicegroup name (optional): Vendor device group identifier used for centralized management grouping (Panorama). Provide if you require preassigned group membership.
-
PIN ID and PIN Value (optional, PIN Value is secret): Used only for vendor PIN-based auto-registration flows. Provide these only if your provisioning process requires them; treat PIN Value as sensitive and hidden.
Platform-generated outputs
The platform returns key outputs after provisioning. Notably:
- Public IP address (management) — the IPv4 address allocated for the management interface (#1). This is a platform-generated output and is shown in deployment results.
- Public IP address (access) — the primary IPv4 address allocated for the Internet access interface (#2). Any additional public IPs requested via Added IP address number are also returned in outputs when allocated.
Licence
Only Bring Your Own Licence (BYOL) type is supported for Fortinet SDWAN. You need to purchase your software licence with Fortinet sales.
Security group
No default security group configured for Fortinet VNE model.