Deploy Managed AIRS for AWS in Strata Cloud Manager
You can use the Strata Cloud Manager console to deploy Managed AIRS for AWS resources
and configure security policies in free-trial mode without subscribing from the AWS
Marketplace or incurring Pay-As-You-Go (PAYG) charges.
| Where Can I Use This? | What Do I Need? |
|
|
- Access to Strata Cloud Manager (SCM)
|
Prerequisites
Before attempting to attach AI security templates or enforce model safety
profiles on an AWS-hosted firewall asset, verify that the deployment meets these
requirements:
Strata Cloud Manager: You have access to Palo Alto Networks
Strata Cloud Manager (SCM). If you do not have a Strata Cloud Manager, you
can
activate a new Strata Cloud Manager
Essentials (steps 1-8) to use with Managed AIRS for AWS. In
either case, the integration automatically enables Strata Cloud Manager Pro
features for Managed AIRS for AWS.
Apps & Services: Select either All Apps &
Services or Prisma Access & NGFW
Configuration.
Role: Select at least one of the following roles:
Superuser, Network Administrator, or Security
Administrator.
The firewall must be managed via Strata Cloud Manager and associated with a
valid Tenant Support Group (TSG).
AWS Account: You have an AWS account with the necessary
permissions to subscribe to AWS Marketplace services and create VPCs,
security groups, and IAM roles.
Deploy Managed AIRS for AWS resource in Strata Cloud Manager Console
Use the following steps to deploy your Managed AIRS for AWS, integrate them with your
AWS network routing, and activate your marketplace billing subscription:
Log in to your Strata Cloud Manager console.
Go to the left-hand navigation menu and select
Configuration.
Click Cloud NGFW & Managed AIRS.
In the main workspace dashboard, click Create Firewall.
On the Choose Firewall Type screen, select the Managed AI
Runtime Security (Preview) as the firewall type.
Under
Enter General Info, fill out the configuration
parameters:
Firewall Name: Input a unique, identifiable name for
your firewall resource.
Region: Select the target AWS Region hosting your AI
infrastructure.
Availability Zone IDs: Check one or more
Availability Zones hosting the target AI workloads that require
real-time security.
Under Choose Firewall Tier, select either Standard or
Premium based on your resource requirements.
(Optional) Under Configure Endpoints, enter any
additional authorized AWS Account IDs (separated by commas) where you want
to deploy firewall endpoints.
Review your inputs and click
Create.
The notification screen will display “Creating Firewall... “
and take up to 10 minutes to provision instances across your selected
Availability Zones.