Home
EN
Location
Documentation Home
Palo Alto Networks
Support
Live Community
Knowledge Base
Clear
Cloud NGFW for AWS
:
Cloud NGFW for AWS Distributed Deployments
Updated on
Sep 11, 2023
Focus
Download PDF
Updated on
Sep 11, 2023
Focus
Home
AWS
Cloud NGFW for AWS
Cloud NGFW Resource and NGFW Endpoints
Direct Traffic to Cloud NGFW for AWS
Cloud NGFW for AWS Distributed Deployments
Download PDF
Cloud NGFW for AWS
Cloud NGFW for AWS Distributed Deployments
Table of Contents
Filter
Expand all
|
Collapse all
Getting Started with Cloud NGFW for AWS
About Cloud NGFW for AWS
Getting Started from the AWS Marketplace
Working with Cloud NGFW for AWS
NGFW Management and Deployment
Security Features
Cloud NGFW for AWS Supported Regions and Zones
Supported Cloud NGFW for AWS Deployments
Cloud NGFW for AWS Pricing
Cloud NGFW for AWS Free Trial
Cloud NGFW for AWS Limits and Quotas
Subscribe to Cloud NGFW for AWS
Cross-Account Role CFT Permissions for Cloud NGFW
Invite Users to Cloud NGFW for AWS
Manage Cloud NGFW for AWS Users
Deploy Cloud NGFW for AWS with the AWS Firewall Manager
Enable Programmatic Access
Terraform Support for Cloud NGFW AWS
Provision Cloud NGFW Resources to your AWS CFT
Usage Explorer
Cloud NGFW for AWS Rulestacks and Rules
About Rulestacks and Rules on Cloud NGFW for AWS
X-Forwarded-For on Cloud NGFW for AWS
Create a Rulestack on Cloud NGFW for AWS
Cloud NGFW for AWS Security Rule Objects
Create a Prefix List on Cloud NGFW for AWS
Create an FQDN List for Cloud NGFW on AWS
Create a Custom URL Category for Cloud NGFW on AWS
Configure an Intelligent Feed on Cloud NGFW for AWS
Add a Certificate to Cloud NGFW for AWS
Create Security Rules on Cloud NGFW for AWS
Cloud NGFW for AWS Security Profiles
Predefined URL Categories for Cloud NGFW for AWS
Set Up Site Access for URLs on Cloud NGFW for AWS
Set Up File Blocking on Cloud NGFW for AWS
Set Up Outbound Decryption on Cloud NGFW for AWS
Set Up Inbound Decryption on Cloud NGFW for AWS
Cloud NGFW Resource and NGFW Endpoints
Create an NGFW Resource on AWS
Create and View NGFW Endpoints
Direct Traffic to Cloud NGFW for AWS
Cloud NGFW for AWS Centralized Deployments
Cloud NGFW for AWS Distributed Deployments
Configure Logging for Cloud NGFW on AWS
Cloud NGFW for AWS Traffic Log Fields
Cloud NGFW for AWS Threat Log Fields
Cloud NGFW for AWS Decryption Log Fields
Enable Audit Logging on Cloud NGFW for AWS
Delete a Cloud NGFW Resource
Cloud NGFW for AWS Security Features
Configure DNS Security
Private DNS Server
Route 53 DNS Service
Private Hosted Zone DNS
Configure WildFire for Cloud NGFW on AWS
Panorama Policy Management
Integrating Panorama
Prepare for Panorama Integration
Link the Cloud NGFW to Palo Alto Networks Management
Unlink the Cloud NGFW from Palo Alto Networks Management
Use Panorama for Cloud NGFW Policy Management
View Cloud NGFW Logs and Activity in Panorama
View Cloud NGFW Logs in Cortex Data Lake
Tag Based Policies
Cloud NGFW for AWS Release Updates
What’s New
Cloud NGFW for AWS Known Issues
Cloud NGFW for AWS Addressed Issues
Cloud NGFW for AWS Distributed Deployments
In a distributed deployment, each VPC that requires protection has its own NGFW. This deployment method is less complicated and, therefore, reduces the chance of misconfiguration.
For additional examples of distributed deployments, see
Cloud NGFW for AWS Deployment Architectures
.
Distributed East-West (intra-VPC)
Traffic from the source instance is routed to the NGFW endpoint and on to the NGFW for inspection.
If the traffic is allowed, the NGFW endpoint sends the traffic on to the destination.
Distributed Outbound
Traffic from the source instance is routed to the NGFW endpoint and on to the NGFW for inspection.
If the traffic is allowed, the NGFW endpoint sends the inspected traffic to the NAT gateway.
The NAT gateway sends the traffic to the internet gateway.
The traffic continues to the internet and the destination.
Distributed Inbound
Traffic from the source arrives at the internet gateway.
The internet gateway routes the traffic to the NGFW endpoint and then to the NGFW for inspection.
If the traffic is allowed, the NGFW endpoint routes the traffic to the application load balancer.
The application load balancer forwards the traffic to the destination.
Previous
Cloud NGFW for AWS Centralized Deployments
Next
Configure Logging for Cloud NGFW on AWS
Recommended For You