Solution Requirements and Design

The virtual machine will load, start, and function. The first port configured to the VM is assigned to the Palo Alto management interface. Subsequent ports attach sequentially from Ethernet 1/1. Sub-interfaces do work with this VM, so it is easily possible to deploy the firewall with a single Integrated Application Hosting (IAH) forwarding plane port, and break out ports using VLANs on the switch. The serial terminal function of ExtremeXOS works with no extra configuration required.

Table 1. Services Offered by the IAH Compute Environment on ExtremeXOS
Switch Models Number of CPUs Available RAM Available Storage Dedicated Management Port Management Port BW Number of Sideband Ports Sideband BW Supported
X465i-48W 2 6GB 120GB Yes 1G 2 10G
X465-24MU 2 6GB 120GB Yes 1G 2 10G
X465-24MU-24W 2 6GB 120GB Yes 1G 2 10G
X465-24XE 2 6GB 120GB Yes 1G 2 10G
X695-48Y-8C 6 14GB 128GB Yes 1G 1 10G
Table 2. Extreme Integration Elements
Minimum ExtremeXOS Version Switch Model Resources Required from IAH to Support Solution License Requirement
30.7 X465-24MU-24W

2 CPU cores

5,730 KB of RAM

Core license
30.7 X695-48Y-8C

2 CPU cores

8,192 KB of RAM

Core license
Table 3. Palo Alto Integration Elements
AP OS Application Resources Required from IAH to Support Solution License Requirement
9.1.2 PAN VM-100 (PA-KVM-9.1.2.qcow2)

2 CPU cores

5,730 KB of RAM

Standard Subscription
9.1.2 PAN VM-100 (PA-KVM-9.1.2.qcow2)

2 CPU cores

8,192 KB of RAM

Standard Subscription
Note

Note

Virtual Interface mapping is not visible to the Palo Alto Firewall virtual machine. If all mapped interfaces are virtual, the VM will panic and go into maintenance mode.