Upgrade an active Cloud NGFW for AWS resource to a higher capacity tier to meet
increased performance or rule capacity demands.
| Where Can I Use This? | What Do I Need? |
|
|
- Cloud NGFW subscription
- Palo Alto Networks Customer Support Account (CSP)
- AWS Marketplace account
- User role (either tenant or administrator)
- Active Cloud NGFW resource in
CREATE_COMPLETE or
UPDATE_COMPLETE
state
|
Cloud NGFW for AWS supports three capacity tiers—Base, Standard, and Premium—that
determine the memory, throughput, and rule capacity available to your firewall. You
can upgrade an existing firewall to a higher tier at any time when the firewall is
in a stable state to accommodate increased workload demands without reprovisioning.
For a full comparison of per-tier limits, see
Cloud NGFW for AWS Limits and Quotas.
Operational Rules for Tier Changes:
- You can upgrade from Base to Standard, Base to Premium, or Standard to
Premium.
- Downgrading tiers is not supported. Once you upgrade a firewall to a higher
tier, you cannot revert to a lower tier.
- You can only initiate a tier change when the firewall status displays
CREATE_COMPLETE or
UPDATE_COMPLETE. Tier changes are not
available while the firewall is in a transitional state.
- A tier upgrade triggers a firewall update cycle. During this cycle, the
firewall status transitions to UPDATE_IN_PROGRESS
and returns to UPDATE_COMPLETE when finished.
Upgrading a firewall tier causes a brief traffic disruption as the firewall
restarts to apply the new capacity configuration. Plan tier changes during a
scheduled maintenance window to minimize impact to production traffic.