Update route tables to direct traffic to the Cloud NGFW for AWS.
Where Can I Use This?
What Do I Need?
Cloud NGFW for AWS
Cloud NGFW subscription
Palo Alto Networks Customer Support Account (CSP)
AWS Marketplace account
User role (either tenant or administrator)
After your have deployed your Cloud NGFW and created endpoints, you must update your
route tables to send traffic to your firewall. Which route tables you update and how
they are updated depends on your specific deployment.
In the AWS console, NGFW endpoints are displayed as Gateway Load Balancer endpoints. You
can identify the NGFW endpoints in the AWS console by their endpoint ID. You can find
the endpoint IDs for a specific firewall in the Cloud NGFW console under NGFWsfirewall-nameEndpoints.
The following are examples of packet flows in different deployment modes and include
examples of updated routes for those packet flows.