Focus
Cloud NGFW for AWS

Cloud NGFW for AWS is Palo Alto Networks ML-powered Next-Generation Firewall (NGFW) capabilities delivered as a fully managed cloud-native service by Palo Alto Networks on the Amazon Web Services (AWS) platform. This deployment model combines the power of the Palo Alto NGFW with the ease of use. The Cloud NGFW service provides advanced application visibility and access control using Palo Alto Networks’ App-ID and URL filtering technologies. It provides threat prevention and detection through cloud-delivered security services and threat prevention signatures.

What's New

November 2025

Try & Buy Cloud NGFW in Strata Cloud Manager- You can now Try & Buy Cloud NGFW for AWS natively in Strata Cloud Manager (SCM). Before this, you were required to first subscribe to the service from the AWS Marketplace, acquire AWS admin credentials, establish cross-account IAM permissions, create new user identities, and then navigate across multiple consoles to create firewalls, endpoints, and policies. This new feature drastically simplifies how you get started, deploy, operate, and manage billing for Cloud NGFW for AWS—all within a single SCM console. For more information, see the Getting Started from Strata Cloud Manager.

Panorama and Strata Logging Service linking Improvements- You no longer need to procure Strata Logging Service separately for your Panorama-managed Cloud NGFW resources. You just associate your Panorama with an existing Strata Tenant (TSG), which you had previously activated based on your Strata Cloud Manager Pro/Essential licenses. If you do not have a Strata Cloud Manager, you can activate a new Strata Cloud Manager Essentials (steps 1-9) and associate your Panorama with it. In either case, when you link the Cloud NGFW to a Panorama previously associated with the Strata tenant, the integration automatically enables Strata Logging Service and SCM Pro features for Cloud NGFW.

To ensure successful integration, the linking process now validates whether your Panorama is associated with a Strata tenant and automatically enables the SLS configurations. For more information, see the Panorama Policy Management.

August 2025 Simplified Onboarding - Cloud NGFW for AWS enhances the onboarding experience by eliminating the need to onboard the AWS account to the Cloud NGFW tenant before creating resources and enabling endpoints in any of its VPCs. You no longer need to onboard the AWS account to create endpoints; You simply allowlist the AWS account when creating or updating Cloud NGFW resources. For more information, see Getting started from an AWS Member account.

Introducing Cloud NGFW for AWS

Rethink network security for public cloud using Cloud NGFW for AWS.

Deploying Cloud NGFW

Part 1: Subscribing to Cloud NGFW

Deploying Cloud NGFW

Part 2: Define Security Policies