Managed AIRS for AWS Limits and Quotas
Focus
Focus
Prisma AIRS

Managed AIRS for AWS Limits and Quotas

Table of Contents

Managed AIRS for AWS Limits and Quotas

Learn the limits and quotas of the Managed AIRS for AWS.
Where Can I Use This?What Do I Need?
  • Managed AIRS for AWS
  • Access to Strata Cloud Manager (SCM)
The following tables list the limits for your Managed AIRS for AWS. Unless indicated otherwise, you can request an increase for these limits.
Use the Managed AIRS for AWS pricing estimator to help you determine AWS limits and quotas for your Managed AIRS for AWS subscription.
Managed AIRS for AWS offers different SKUs to accommodate varying deployment size requirements.
  • Standard: Recommended for cloud-native environments requiring increased compute power. It supports 16 GB of memory and can scale out to secure 45 Gbps of traffic.
  • Premium: Ideal for high-demand, mission-critical applications requiring maximum performance at a higher hourly price. A Premium resource can scale out to secure 100 Gbps of traffic.
SKU Selection Quick Recommendations
  • Standard SKU (Recommended Default)
    • Best for most standard deployments. A Standard resource can scale out to secure 45 Gbps of traffic.
    • Cost: No additional cost over Base.
  • Premium SKU
    • Best for large configurations or policy sets that exceed Standard limits, or Managed AIRS for AWS deployments using Egress NAT to minimize Egress IP allocation.
    • Cost: Incurs additional tier-based pricing.
To deploy a Managed AIRS for AWS resource with these advanced capacity capabilities, Create a Managed AIRS for AWS Resource. To upgrade an existing active resource, change or upgrade Managed AIRS for AWS resource tiers.

Managed AIRS for AWS Management

Name
Default Limits per Managed AIRS for AWS Tenant
Adjustable
Managed AIRS for AWS endpoints for each NGFW resource
300
No
To change any of the adjustable limits listed above, contact Palo Alto Networks Customer Support.

Strata Cloud Manager Policy Management

Attribute
Standard SKU Maximum Limit per Managed AIRS for AWS Resource*
Premium SKU Maximum Limit per Managed AIRS for AWS Resource*
Policy
Security rules
10,000
20,000
Decryption rules
1,000
2,000
Objects
Address objects
20,000
40,000
Address groups
2,500
4,000
Members per address group
2,500
2,500
FQDN address groups
2,000
2,000
Service objects
2,000
2,500
Service groups
250
250
Members per service group
500
500
EDL
Max number of DNS per domain system
2,000,000
2,000,000
Max number of IPs per system
50,000
50,000
Max number of URLs per system
100,000
100,000
Max number of custom lists
30
30
URL Filtering
Total entities for allow list, block list and custom categories
25,000
25,000
Max custom categories
500
1,000
Max v-Router limits
20
125
* The limits on policy and objects specified are unidimensional maximum. Palo Alto Networks recommends additional testing within your environment to ensure you meet your policy authoring objectives.