Alicloud Deploy 1 FW into an Existing VPC from a Marketplace Image

This template deploys a VM-Series NGFW into an existing VPC in Alicloud using the 10.0.3 marketplace image.


  • Terraform v0.13
  • Alicloud key-pair
  • An existing VPC
  • 3 vSwicthes - for Management, Trust, and Untrust interfaces
  • Security group for Management interface
  • Security group for data (Trust and Untrust) interfaces
  • Auth_code (if you want to license the VM-Series via bootstrap)


  1. Update the "terraform.tfvars" file with the necessary information.

  2. Run "terraform init"

  3. Run "terraform apply"

  4. VM-Series will be deployed. It takes about 10 minutes for it to be fully ready.

  5. The VM-Series Management IP will be shown in the terraform outputs.

Removing The Demo Environment

  1. Run "terraform destroy"
  2. De-license the VM-Series (if you have licensed it)

Support Policy

The code and templates in the repo are released under an as-is, best effort, support policy. These scripts should be seen as community supported and Palo Alto Networks will contribute our expertise as and when possible. We do not provide technical support or help in using or troubleshooting the components of the project through our normal support options such as Palo Alto Networks support teams, or ASC (Authorized Support Centers) partners and backline support options. The underlying product used (the VM-Series firewall) by the scripts or templates are still supported, but the support is only for the product functionality and not for help in deploying or using the template or script itself. Unless explicitly tagged, all projects or work posted in our GitHub repository (at or sites other than our official Downloads page on are provided under the best effort policy.

Developer Sites


Copyright © 2023 Palo Alto Networks, Inc. All rights reserved.