Aller au contenu principal

Palo Alto Series - Specifications

Palo Alto Series (VM-Series) — SDWAN Gateway

This page describes the Palo Alto Series (VM-Series) when deployed as an SDWAN Gateway. It summarises supported deployment modes, interfaces, VM-level parameters, service-specific inputs and platform-generated outputs needed during provisioning.

Flavors

Choose a flavor to size the virtual device. Supported flavor families include standard and DPDK variants; the full flavor table is rendered below.

Flavors for Palo Alto Series (VM-Series)
StandardDPDK
Small
2 vCPU
8 GB Mem
64 GB Disk
2 vCPU
4 GB Mem
64 GB Disk
Medium
4 vCPU
16 GB Mem
64 GB Disk
4 vCPU
16 GB Mem
64 GB Disk
Large
8 vCPU
32 GB Mem
64 GB Disk
8 vCPU
32 GB Mem
64 GB Disk

Common flavor families:

  • Standard: std1.c2m, std1.c4m, std1.c8m
  • DPDK (packet-acceleration): dpdk1.c2, dpdk1.c4m, dpdk1.c8m

In dual deployment mode select a flavor for each virtual device instance.

Interfaces

Diagram legend: Internet connects to two platform-allocated public IPs. Public IP (management) attaches to the #1 - Internet Interface - management; Public IP (access) attaches to the #2 - Internet Interface - access. #3 - MPLS-VPN interface is a trunk that may expose VLAN sub-interfaces (VLAN 101..108) to map customer MPLS VPNs to the VM. The VM node represents the Palo Alto VM-Series virtual device hosting all listed interfaces. "(optional)" marks interfaces flagged optional in the specification.

Common interface behaviour

  • Public IP addresses for the Internet-facing interfaces are allocated by the platform and presented as informational platform outputs; customers do not provide those public IPs during provisioning.
  • VLAN sub-interfaces under the MPLS trunk are optional and can be enabled per deployment. When enabled, each VLAN sub-interface accepts VPN mapping and optional BGP settings.

#1 - Internet Interface - management

Role: Out-of-band management and Internet connectivity for management tasks.

  • The management public IP is a platform-generated output (informational). No customer-provided IP is required for this interface in the provisioning form.

#2 - Internet Interface - access

Role: Internet access for service traffic.

  • The access public IP is a platform-generated output (informational). The platform allocates and reports this address after provisioning.

#3 - MPLS-VPN interface (optional)

Role: Trunk to the MPLS-VPN via VLAN sub-interfaces.

  • VLAN sub-interfaces available: VLAN 101, VLAN 102, VLAN 103, VLAN 104, VLAN 105, VLAN 106, VLAN 107, VLAN 108 (each marked optional).
  • For each enabled VLAN sub-interface customers can provide:
    • VPN Name — identifier (pattern: alphanumeric, hyphen or underscore). This maps a VLAN sub-interface to an MPLS VPN.
    • VPN role — one of any-to-any, client, server.
    • Enable BGP — optional boolean; when enabled the platform exposes BGP configuration fields for that sub-interface.
    • AS prepend — optional integer 1..6. The AS prepend value indicates how many times the VM AS is prepended to the AS path; the specification notes this is used for backup VM scenarios only.

Routing and BGP

  • BGP is an optional capability on VLAN sub-interfaces. The Enable BGP toggle controls whether BGP-related fields are applicable for the selected sub-interface (default: disabled).
  • VM AS number is a virtual-device scope parameter used when BGP is configured. Provide a valid AS number in the range 1..4294967295 when required by your peering design.
  • AS prepend (1..6) is an advanced option and applies only when BGP is enabled on a sub-interface.

Virtual device parameters

These parameters apply to the VM instance(s):

  • VM name — hostname used to identify the virtual device. Provide a hostname matching the allowed pattern and length constraints.
  • VM image — select one of the supported PA-VM images (see Software images section). This field is required and not updatable after provisioning.
  • Flavor — select a supported flavor (see Flavors above). Flavor selection is required at provisioning time and defines the VM sizing.
  • VM AS number — optional AS number to use for BGP sessions when BGP is configured.

Required VM-level inputs include VM name, VM image and Flavor.

Service-specific parameters

Service-specific parameters are service-level values requested during provisioning (they are not VM-level network addresses). They let the platform initialise vendor integration or set initial credentials.

  • Hashed password — A pre-hashed administrative password string. The platform uses this value to set the firewall admin credential during provisioning. This parameter is mandatory and not updatable; provide a hashed value (do not submit plain text).

  • IPv4 address of the primary Panorama server — Provide the primary Panorama server IPv4 if you manage the device through Panorama. This parameter is optional and not updatable; supply a valid IPv4 address when required.

  • IPv4 address of the secondary Panorama server — Optional secondary Panorama IPv4 address for vendor management integration; not updatable.

  • Authentication key — Optional authentication token used by the VM for vendor workflows; not updatable when provided.

  • Template name — Optional vendor template identifier to assign on the device during provisioning; not updatable.

  • Devicegroup name — Optional device-group identifier for vendor management; not updatable.

  • PIN ID and PIN Value — Optional identifier and secret used for auto-registration workflows with vendor services; both are not updatable when provided and are treated as hidden/credential values.

For all service-specific parameters: indicate the value exactly as required by your vendor or management procedures. The Hashed password is mandatory; other parameters are optional and only required when you use the corresponding vendor management features (Panorama, templates, auto-registration).

Platform-generated outputs

The platform provides informational outputs after provisioning. Key platform outputs for this VNF include:

  • Public IP address (management) — IPv4 allocated by the platform for the management interface.
  • Public IP address (access) — IPv4 allocated by the platform for the access interface.

These are platform-assigned values shown in the deployment output and are not customer-provided inputs.

Software images

Supported images (exact names):

  • PA-VM-KVM-10.2.6
  • PA-VM-KVM-10.2.10-h9
  • PA-VM-KVM-10.2.10-h9_DPDK
  • 10.2.10-h9

Licence

Only Bring Your Own Licence (BYOL) type is supported for Fortinet SD-WAN. You need to purchase your software licence with Fortinet sales.

Security group

No default security group configured for Fortinet VNE model.