Deploy Managed AIRS for AWS in Strata Cloud Manager
Focus
Focus
Prisma AIRS

Deploy Managed AIRS for AWS in Strata Cloud Manager

Table of Contents

Deploy Managed AIRS for AWS in Strata Cloud Manager

You can use the Strata Cloud Manager console to deploy Managed AIRS for AWS resources and configure security policies in free-trial mode without subscribing from the AWS Marketplace or incurring Pay-As-You-Go (PAYG) charges.
Where Can I Use This?What Do I Need?
  • Managed AIRS for AWS
  • Access to Strata Cloud Manager (SCM)

Prerequisites

Before attempting to attach AI security templates or enforce model safety profiles on an AWS-hosted firewall asset, verify that the deployment meets these requirements:
  • Strata Cloud Manager: You have access to Palo Alto Networks Strata Cloud Manager (SCM). If you do not have a Strata Cloud Manager, you can activate a new Strata Cloud Manager Essentials (steps 1-8) to use with Managed AIRS for AWS. In either case, the integration automatically enables Strata Cloud Manager Pro features for Managed AIRS for AWS.
  • Strata Cloud Manager Roles: You have the following two options in your Strata Cloud Manager user role:
    • Apps & Services: Select either All Apps & Services or Prisma Access & NGFW Configuration.
    • Role: Select at least one of the following roles: Superuser, Network Administrator, or Security Administrator.
  • The firewall must be managed via Strata Cloud Manager and associated with a valid Tenant Support Group (TSG).
  • AWS Account: You have an AWS account with the necessary permissions to subscribe to AWS Marketplace services and create VPCs, security groups, and IAM roles.

Deploy Managed AIRS for AWS resource in Strata Cloud Manager Console

Use the following steps to deploy your Managed AIRS for AWS, integrate them with your AWS network routing, and activate your marketplace billing subscription:
  1. Log in to your Strata Cloud Manager console.
  2. Go to the left-hand navigation menu and select Configuration.
  3. Click Cloud NGFW & Managed AIRS.
  4. In the main workspace dashboard, click Create Firewall.
  5. On the Choose Firewall Type screen, select the Managed AI Runtime Security (Preview) as the firewall type.
  6. Under Enter General Info, fill out the configuration parameters:
    • Firewall Name: Input a unique, identifiable name for your firewall resource.
    • Region: Select the target AWS Region hosting your AI infrastructure.
    • Availability Zone IDs: Check one or more Availability Zones hosting the target AI workloads that require real-time security.
  7. Under Choose Firewall Tier, select either Standard or Premium based on your resource requirements.
  8. (Optional) Under Configure Endpoints, enter any additional authorized AWS Account IDs (separated by commas) where you want to deploy firewall endpoints.
  9. Review your inputs and click Create.
    The notification screen will display “Creating Firewall... “ and take up to 10 minutes to provision instances across your selected Availability Zones.