Install Palo Alto as VM

In this post; I will walk you through the steps for installing and configuring the VM Palo Alto firewall on VMware workstation.

I will walk you through the steps for configuring the firewall interfaces, defining zones, Create Virtual Router, creating Interface Management profil

New let’s start to install PA firewall and build the infrastructure, then  configure interfaces, Management profile, defining zones, create Role and Account, Create Virtual Router,NAT, Static and OSPF Routing and more.

I hope this guide is useful to some people that would like to use the Palo Firewall

In my next post; I will walk you through the steps for PA implementation in real environment with devices from different vendors.

I will cover in this post:

1- Create Virtual Network on VMware Workstation
2- Import Palo Alto Firewall Image
3- Add additional 2 Interface and modify MAC address
4- Verify the Palo Alto interfaces
5- Login to CL and Web interface

Created Virtual Networks

Created the following Virtual Networks on your workstation:

VMnet0 host-only interface on the subnet as the Management network
VMnet1 host-only interface on the subnet as internal network
VMnet2 host-only interface on the subnet as external network
VMnet3 host-only interface on the subnet as DMZ network

Note: I will use (VMnet1, VMnet3, VMnet4, and VMnet5) network, because network mentioned above occupied on my VMware enviroment.

PA_I00  PA_I01

 Import Palo Alto

You will need to import the PA image

File –> Open

PA_I02  PA_I03

after importt the PA VM will only have 2 interfaces – You need to add 2 more interfaces


Before you start the VM Firewall you need to edit the .VMX

Edit .vmx file and change for all Ethernet ethernet”X”.virtualDev = “e1000” to “vmxnet3”


Modify MAC address

PAN VM uses hard-coded MAC addresses, map these in your lab VMware virtual machine network interfaces settings, until you license the product.

Select the interface –> Advance and type the MAC address


Mac address should assign as below:

VMnet0  –> 00:0C:29:9F:6A:93

VMnet1 –> BA:DB:EE:FB:AD:10

VMnet2 –> BA:DB:EE:FB:AD:11

VMnet3 –> BA:DB:EE:FB:AD:12

Verify the Palo Alto interface

Boot up the Palo Alto VM, once it has loaded successfully you will see the console login



Login using admin/admin to get to the CLI


1_ Verify the management interface is indeed defaulted to

“Show interface management”



2_Verify the data interface

Execute the “show interface hardware command to list the interfaces with their hardware attributes:






Use the computer that connected to management network; then use the web browser to navigate (Remember the “s” on https://)

Login using admin/admin

PA_I15  PA_I16


By default the management interface is configured to, use command below to change to whatever my example the subnet:

set deviceconfig system ip-address

show interface management

PA VM’s management interface  now set to and you should be able to to navigate in-order to manage PA firewall



  1. Hello,

    I would like to install 2 Palo Alto vm to implement the HA but as the mac-addresses are the same on each vm, it’s not possible to make them being able to communicate with each other.
    To this end, is there a way to modify the mac-addresses of the vm for each interface ?


Leave a Reply

Fill in your details below or click an icon to log in: Logo

You are commenting using your account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Google+ photo

You are commenting using your Google+ account. Log Out / Change )

Connecting to %s