Palo Alto Prisma Virtual ION - Specifications
About this VNF
Palo Alto Prisma Virtual ION is an SD‑WAN gateway virtual device deployable from the Evolution Platform. The blueprint supports single and dual deployment modes; choosing dual mode results in two deployed virtual devices. The specification does not describe automatic high‑availability or failover behavior.
Flavors and images
| Standard | DPDK | |
|---|---|---|
| Small | 2 vCPU 8 GB Mem 64 GB Disk | - |
| Large | 8 vCPU 32 GB Mem 64 GB Disk | 8 vCPU 32 GB Mem 64 GB Disk |
In the create flow you choose an image and a flavor for each virtual device. Supported images include the Prisma Virtual ION builds listed in the software JSON.
Software device versions
- 6.2.1-b3
Interfaces
The diagram above shows the simplified topology: two Internet-facing interfaces (#1 and #2), each associated with a platform-provided public IP, and an optional MPLS-VPN trunk (#3) that uses VLAN sub-interfaces. All interfaces attach to the Palo Alto Prisma Virtual ION VM. VLAN sub-interfaces are aggregated in the diagram for readability.
#1 - Internet Interface - management
- Role: management / out-of-band access.
- Public IP address is allocated by the platform and presented as a provisioning output; no customer IP input is required.
- No additional configuration is normally required during the create flow for this interface.
#2 - Internet Interface - access
- Role: Internet access for SD‑WAN traffic and external access.
- Public IP address is allocated by the platform. To request extra public IPs, use Added IP address number and enter an integer between 1 and 8. The platform will allocate the requested addresses and present them as provisioning outputs.
- The number of extra IPs is updatable via the platform where supported.
#3 - MPLS-VPN interface (optional)
- Role: trunk interface hosting VLAN sub-interfaces (IDs in the 101–148 range) to connect to MPLS‑VPNs.
- For each VLAN sub-interface you can:
- Add one or more VPN entries.
- Provide a VPN Name (pattern: alphanumeric, dash or underscore) and select a VPN role (any-to-any, client, server).
- Optionally enable BGP for the VLAN and set AS prepend when applicable.
- VLANs and VPN entries are configured only when the customer uses MPLS‑VPN connectivity.
Routing and BGP
- Enable BGP is an optional, per‑VLAN setting. When not enabled, no BGP-specific configuration is applied through this setting.
- AS prepend is an optional integer (range 1–6) that can be set per VLAN; the blueprint indicates its use for backup VM scenarios in certain designs. Provide AS prepend only if required by your service design.
- The specification does not define detailed peering policies; coordinate peering and route details with Orange when enabling BGP.
Virtual device parameters
Key VM-level parameters available in the create flow:
- VM name — hostname for the VM. Provide a string conforming to the platform hostname rules and maximum length shown in the create form.
- VM image — select one of the supported Prisma Virtual ION image identifiers.
- VM flavor — select the VM size (flavor) appropriate for expected throughput. Flavors are shown in the Flavors table.
- Disk size — optional boot volume size in GB; change within allowed limits in the create flow.
- VM AS number — provide this AS number when you plan to enable BGP (supports 2‑ or 4‑byte AS values).
Service specific parameters
Service-specific parameters are service-level values required during provisioning. They are not VM passwords or platform outputs and are used by cloud-init to configure the device at first boot.
-
Prisma SDWAN key — a vendor-provided connection key used by the Prisma SD‑WAN orchestrator. For this VNF, the platform uses the key in cloud-init to register the VM with the Prisma orchestration service. This field is required and not updatable after provisioning; enter the key in the service parameters section during create.
-
Prisma SDWAN secret — a vendor-provided secret paired with the key for authentication to the Prisma orchestrator. This field is required, hidden in the UI, and not updatable after provisioning; enter the secret during create.
Both credentials are provided by the customer and must be valid for the Prisma orchestrator to allow device registration.
Platform-generated outputs
- Public IP address (Interface 1) — the platform allocates and displays the management public IPv4 address after provisioning.
- Public IP address (Interface 2) — the platform allocates and displays the access public IPv4 address(es) after provisioning, including any extra addresses requested via Added IP address number.
These addresses are platform outputs and are shown in the provisioning summary and VM details.
Service parameters and validation
The create flow validates common constraints such as image selection, flavor selection, VM name format and length, disk size limits, presence of the required Prisma SDWAN key and secret, and the Added IP address number range (1–8) when provided.
Licence
Only Bring Your Own Licence (BYOL) type is supported for Fortinet SD-WAN. You need to purchase your software licence with Fortinet sales.
Security group
No default security group configured for Fortinet VNE model.