Change or Upgrade Cloud NGFW Resource Tiers
Focus
Focus
Cloud NGFW for AWS

Change or Upgrade Cloud NGFW Resource Tiers

Table of Contents

Change or Upgrade Cloud NGFW Resource Tiers

Upgrade an active Cloud NGFW for AWS resource to a higher capacity tier to meet increased performance or rule capacity demands.
Where Can I Use This?What Do I Need?
  • Cloud NGFW for AWS
  • Cloud NGFW subscription
  • Palo Alto Networks Customer Support Account (CSP)
  • AWS Marketplace account
  • User role (either tenant or administrator)
  • Active Cloud NGFW resource in CREATE_COMPLETE or UPDATE_COMPLETE state
Cloud NGFW for AWS supports three capacity tiers—Base, Standard, and Premium—that determine the memory, throughput, and rule capacity available to your firewall. You can upgrade an existing firewall to a higher tier at any time when the firewall is in a stable state to accommodate increased workload demands without reprovisioning. For a full comparison of per-tier limits, see Cloud NGFW for AWS Limits and Quotas.
Operational Rules for Tier Changes:
  • You can upgrade from Base to Standard, Base to Premium, or Standard to Premium.
  • Downgrading tiers is not supported. Once you upgrade a firewall to a higher tier, you cannot revert to a lower tier.
  • You can only initiate a tier change when the firewall status displays CREATE_COMPLETE or UPDATE_COMPLETE. Tier changes are not available while the firewall is in a transitional state.
  • A tier upgrade triggers a firewall update cycle. During this cycle, the firewall status transitions to UPDATE_IN_PROGRESS and returns to UPDATE_COMPLETE when finished.
Upgrading a firewall tier causes a brief traffic disruption as the firewall restarts to apply the new capacity configuration. Plan tier changes during a scheduled maintenance window to minimize impact to production traffic.
  1. Log into your Cloud NGFW console and select NGFWs from the navigation menu.
  2. Select the name of the active firewall you want to upgrade.
  3. On the firewall details page, verify that the firewall Status is CREATE_COMPLETE or UPDATE_COMPLETE before proceeding.
  4. Select Edit.
  5. In the Tiers section, select the target capacity tier.
    • Standard SKU (Recommended Default): Designed for scaling cloud-native workloads up to 40 Gbps, supporting 2 Gbps fat sessions and advanced feature sets.
    • Premium SKU: Tailored for mission-critical applications requiring maximum performance, supporting up to 4 Gbps fat sessions. For per-tier rule and resource limits, see Cloud NGFW for AWS Limits and Quotas.
    You can only select a tier equal to or higher than the current tier. Downgrading to a lower tier is not supported.
  6. Select Save and review the acknowledgment dialog.
  7. Confirm the tier change by selecting Confirm in the acknowledgment dialog.
    The firewall status changes to UPDATE_IN_PROGRESS.
    When the upgrade completes, the status returns to UPDATE_COMPLETE.
    The dashboard will instantly generate a prominent banner at the top of the interface stating:
    Firewall updating tier takes roughly 15-20 minutes to reflect the changes. Please click the refresh button on the top right to see updated status.
    You can safely navigate away from the page. Once the underlying automated infrastructure rollover completes, the Tier parameter column on your main dashboard will update to display your new active performance tier.