Cloud NGFW for AWS V1 to V2 Migration
Learn how the Cloud NGFW for AWS migration to V2 infrastructure affects your existing
firewalls, Terraform deployments, and log configuration.
| Where Can I Use This? | What Do I Need? |
|
|
- Cloud NGFW subscription
- Palo Alto Networks Customer Support Account (CSP)
- AWS Marketplace account
|
Palo Alto Networks® is migrating all existing Cloud NGFW for AWS V1 tenants to
V2 infrastructure to provide a more scalable and feature-rich experience through
Simplified Onboarding.
The migration is designed as a rolling update to ensure continuous logging and zero
impact on active data plane traffic. During the transition, firewalls will display an
Updating status in the console, and management actions will be temporarily
disabled to prevent configuration drift. To access the updated V2 Management Console
once the migration is complete, simply log out and back into your session.
Benefits of Migrating from V1 to V2
Migrating to V2 provides the following advantages:
- You can add accounts to an allow list without requiring full permissions for
creating endpoints, instead of onboarding the AWS accounts.
- The following features are available exclusively on V2:
- Premium SKUs (upcoming)
- User-ID with Panorama® (upcoming)
- Egress NAT using Cloud NGFW with Strata Cloud Manager (upcoming)
Impacts of Cloud NGFW for AWS from V1 to V2 Migration
Before migration — When you log into your CNGFW for AWS tenant, you will see
that your tenant is running version V1.
During migration —
UI Status: Firewall Status displays an
Updating status in the Cloud NGFW for AWS V1
console.
Console Restrictions: Access links to edit or modify firewalls
will be grayed out to prevent configuration changes during the
migration.
Firewall Operations: Create, Update, and Delete Firewall resources
may fail during this time window. Additionally, Policy configuration
commits via Panorama, Strata Cloud Manager or Local Rulestack may fail
during the specified maintenance window. You will be able to resume
these operations in a few hours after the maintenance window.
User Action (Programmatic): It is recommended that
during the migration window no Terraform or API config changes are
performed.