Focus
Cloud NGFW for Azure

Cloud Next-Generation Firewall by Palo Alto Networks - an Azure Native ISV Service - is Palo Alto Networks Next-Generation Firewall (NGFW) delivered as a cloud-native service on Azure. You can discover Cloud NGFW in the Azure Marketplace and consume it in your Azure Virtual Networks (VNet) and in Azure Virtual WAN (vWAN). With Cloud NGFW, you can access the core NGFW capabilities such as App-ID and URL filtering based technologies. It provides threat prevention and detection through cloud-delivered security services and threat prevention signatures.

What's New

June 2026

Premium Instance Support for Cloud NGFW for Azure
Cloud NGFW for Azure now supports Premium instances, offering higher performance and increased capacity for enterprise-scale workloads. You can now select between Standard and Premium SKUs during firewall creation or upgrade existing Standard firewalls to Premium in a self-service manner.

Standard Instance- The foundational tier recommended for cloud-native environments requiring standard policy sets. Includes standard autoscaling to manage peak traffic up to 100 Gbps.

Premium Instance- Ideal for securing highly sensitive applications. Supports much larger policy sets and a faster ramp-up to seamlessly handle massive peak traffic up to 200 Gbps at a higher price. The Premium tier functions as an add-on dimension, incurring an extra 60% hourly charge of firewall based and add-ons (CDSS and Central management).

For more information, see CNGFW for Azure Pricing and CNGFW for Azure Limits and Quotas.


May 2026

Enterprise DLP Support for Cloud NGFW for Azure
Cloud NGFW now integrates with Enterprise Data Loss Prevention (E-DLP) to safeguard your sensitive information against unauthorized access and exfiltration. With this integration, customers can centrally manage DLP patterns and profiles across their cloud infrastructure using Panorama, maintaining a consistent security posture.

Onboarding is streamlined through automated association: if you already have a Cloud NGFW resource registered with Panorama, simply adding it to a Strata Tenant (Tenant Service Group or TSG) activates E-DLP if not already present in the TSG and automatically links your Cloud NGFW resources to the E-DLP cloud service.

Cloud NGFW for Azure exclusively supports E-DLP. Consequently, all data-filtering profiles configured in Panorama are treated as E-DLP usage and will be billed at the E-DLP add-on price (40% of the base firewall credits).

To learn more about this capability, see Enterprise DLP for Azure CNGFW.


March 2026 DNAT Port Range Support

You can now specify port ranges in DNAT rules. This enhancement simplifies configuration for applications using multiple ports and improves rule scalability by allowing a single entry for an entire range. For more information, see Configure a Source and Destination NAT Rule.

December 2025

You can now deploy Cloud NGFW for Azure in New Zealand North region.

For more information, see Cloud NGFW for Azure Supported Regions .


October 2025

Billing Change for Cloud NGFW on Azure

Effective October 2025, Palo Alto Networks is implementing a previously announced change to how Cloud NGFW on Azure costs are billed. When you deploy Cloud NGFW in a Hub vNET, you alse established peering between the your spoke vNETs and the hub VNet and redirected traffic to Cloud NGFW. Until now, Palo Alto Networks temporarily absorbed the cost associated with this peering. This $0.01 per GB charge, which reflects Microsoft Azure's standard peering rate, will now be billed directly to your Marketplace billing account as a Pay-As-You-Go (PAYG) charge, even if you are on a credit consumption plan. For more information, see Cloud NGFW Azure pricing.

September 2025


Azure Monitor Metrics

Cloud NGFW now publishes additional metrics in Azure Monitor to help you monitor your Cloud NGFW's health, performance, and usage patterns.

Key metrics available include:

  • Throughput

  • Sessions

  • SNAT Port Utilization

  • Latency

  • Packet counts

For more information, see View Cloud NGFW Metrics in Azure Monitor and Enable and View Cloud NGFW for Azure Monitoring Metrics.


Support for Multi-Dimensional Scaling

Cloud NGFW for Azure can now automatically scale based on additional metrics such as Source NAT port utilization, session throughput and session count, ensuring greater reliability and performance for diverse workloads. For more information, see Cloud NGFW for Azure Resiliency and Scalability and View Cloud NGFW for Azure Metrics natively in Azure .


Strata Logging Service Support for Panorama Managed Cloud NGFW resources

You can now enable SLS for existing Panorama-managed Cloud NGFW for Azure resources by simply generating a new registration string from the Panorama plugin and updating it in the Azure portal. For more information, see Enable Strata Logging Service (SLS) for existing Panorama-managed firewalls and View Traffic and Threat Logs in Strata Logging Service.


July  2025

Additional Azure Regions

You can now deploy Cloud NGFW for Azure in the following regions:

  • Spain Central
  • Mexico Central
  • India South

For more information, see Cloud NGFW for Azure Supported Regions.

SNAT Port Enhancement

More SNAT ports are now allocated for each firewall instance. SNAT port allocation will scale based on the front-end IPs configured.


Premium Instance Support for Cloud NGFW for Azure

Premium Instance Support for Cloud NGFW for Azure

Getting Started with Cloud NGFW for Azure

Learn how to get started with Cloud NGFW for Azure.

Cloud NGFW Credits

Learn about Cloud NGFW credits.

Cloud NGFW for Azure SNAT and DNAT

Learn about SNAT and DNAT deployments.