Focus
Cloud NGFW for AWS

Cloud NGFW for AWS is Palo Alto Networks ML-powered Next-Generation Firewall (NGFW) capabilities delivered as a fully managed cloud-native service by Palo Alto Networks on the Amazon Web Services (AWS) platform. This deployment model combines the power of the Palo Alto NGFW with the ease of use. The Cloud NGFW service provides advanced application visibility and access control using Palo Alto Networks’ App-ID and URL filtering technologies. It provides threat prevention and detection through cloud-delivered security services and threat prevention signatures.

What's New

July 2026

Unified Software NGFW Credits for Cloud NGFW for AWS
Cloud NGFW for AWS now supports Palo Alto Networks Software NGFW Credits. Instead of procuring separate credit buckets, you can now purchase a single, flexible credit pool to fund your Cloud NGFW for AWS.

The Software NGFW Credit pool automatically aggregates unallocated credits from your main pool to absorb workload spikes before incurring Azure Marketplace PAYG overage fees. The system automatically draws unallocated credits from your main pool to cover tenant usage spikes. You can easily manage high-level credit allocation via Parent Deployment Profiles in the Customer Support Portal (CSP) and assign tenant-level credit allowances via Child Deployment Profiles in the CMS Hub App. You can also monitor real-time baseline consumption, SmartCredit buffer usage, and marketplace overflow through interactive Chart and Table views in the CMS Hub App.

For more information, see CNGFW for AWS Pricing and Software NGFW Credit and Redistribution.


Cloud NGFW for AWS Standard and Premium SKU
Palo Alto Networks introduces the Standard and Premium capacity SKU for Cloud NGFW for AWS. These new SKU types offer enhanced performance and cost-optimized infrastructure scaling, allowing you to tailor your firewall capabilities to your organizational traffic demands.

The Standard SKU is available at no additional base cost over the foundational type, providing an entry-level cloud-native scaling path that handles up to 2 Gbps fat sessions and scales out to secure up to 45 Gbps of traffic. 

For mission-critical applications with massive data requirements, the Premium SKU expands its capabilities to support up to 4 Gbps fat sessions and a scale-out capacity of up to 100 Gbps of traffic.

The modifications in SKU type are unidirectional and standalone operations. The downgrade is not supported, and concurrent configuration changes cannot be processed simultaneously alongside an active SKU upgrade. For more information, see CNGFW for AWS Pricing and CNGFW for AWS Limits and Quotas.


Advanced WildFire and Advanced DNS Security Support Cloud NGFW for AWS
Cloud NGFW for AWS now supports Advanced WildFire (AWF) and Advanced DNS Security (ADNS) on PAN-OS 11.2 or later, delivering Precision AI-powered protection against zero-day malware and evasive shadow domains.

Key Timelines:

  • New Deployments: Effective September 1, 2026, legacy standard DNS and WildFire subscriptions are End-of-Sale (EOS) and no longer available.

  • Existing Tenants: For now, you can temporarily maintain legacy subscriptions at standard rates.

When enabled, these modules are seamlessly integrated into your usage metrics and billed at a rate of 30% of the base firewall credits. For more information, see CNGFW for AWS Pricing.


June 2026

Cloud NGFW (CNGFW) Data Source Integration for Cortex XSIAM
You can now stream traffic and application logs directly from Cloud NGFW to Cortex XSIAM with full support for cross-region and cross-account connections. A new distinct connector is introduced to handle unique cloud-native identifiers, ensuring seamless log ingestion and analysis. For more information, see Cortex XSIAM.

Migration of Cloud NGFW for AWS from V1 to V2 Tenants
Palo Alto Networks® is migrating existing Cloud NGFW (AWS) V1 tenants to V2 infrastructure to provide a more scalable and feature-rich experience through simplified onboarding.

The migration is designed as a rolling update to ensure continuous logging and zero impact on active data plane traffic. During the transition, firewalls will display an Updating status in the console, and management actions will be temporarily disabled to prevent configuration drift. To access the updated V2 Management Console once the migration is complete, simply log out and back into your session.

While your existing V1 Terraform deployments remain fully supported for managing current resources, all new firewalls created after the migration must utilize the V2 provider schema. For more information on upgrading to the latest version of the cloudngfwaws Terraform provider, see Cloud NGFW firewall management using Terraform and Cloud NGFW for AWS V1 to V2 Migration.


March 2026


Cloud NGFW for AWS now supports IPv6 dual-stack (IPv4 + IPv6) traffic inspection. With this feature, you can enable AWS Network Firewall endpoints to filter both IPv4 and IPv6 traffic in dual-stack subnets/VPCs. For more information, see Configure Egress NAT and Create a Cloud NGFW for AWS Resource.


December 2025 Effective December 2025, Palo Alto Networks is implementing a previously announced Cloud NGFW on AWS Egress NAT pricing. When you configure Egress NAT on Cloud NGFW, Cloud NGFW will inspect and perform source NAT on all Internet Egress traffic. In this case, you no longer incur AWS NAT gateway costs but would pay Palo Alto Networks for the egress traffic data transfer and Palo Alto Networks-managed AWS Elastic IPs if you choose not to transfer your BYOIPs to Palo Alto Networks. For more information, see Cloud NGFW for AWS Pricing.
November 2025

Try & Buy Cloud NGFW in Strata Cloud Manager- You can now Try & Buy Cloud NGFW for AWS natively in Strata Cloud Manager (SCM). Before this, you were required to first subscribe to the service from the AWS Marketplace, acquire AWS admin credentials, establish cross-account IAM permissions, create new user identities, and then navigate across multiple consoles to create firewalls, endpoints, and policies. This new feature drastically simplifies how you get started, deploy, operate, and manage billing for Cloud NGFW for AWS—all within a single SCM console. For more information, see the Getting Started from Strata Cloud Manager.

Panorama and Strata Logging Service linking Improvements- You no longer need to procure Strata Logging Service separately for your Panorama-managed Cloud NGFW resources. You just associate your Panorama with an existing Strata Tenant (TSG), which you had previously activated based on your Strata Cloud Manager Pro/Essential licenses. If you do not have a Strata Cloud Manager, you can activate a new Strata Cloud Manager Essentials (steps 1-9) and associate your Panorama with it. In either case, when you link the Cloud NGFW to a Panorama previously associated with the Strata tenant, the integration automatically enables Strata Logging Service and SCM Pro features for Cloud NGFW.

To ensure successful integration, the linking process now validates whether your Panorama is associated with a Strata tenant and automatically enables the SLS configurations. For more information, see the Panorama Policy Management.

August 2025 Simplified Onboarding - Cloud NGFW for AWS enhances the onboarding experience by eliminating the need to onboard the AWS account to the Cloud NGFW tenant before creating resources and enabling endpoints in any of its VPCs. You no longer need to onboard the AWS account to create endpoints; You simply allowlist the AWS account when creating or updating Cloud NGFW resources. For more information, see Getting started from an AWS Member account.

Introducing Cloud NGFW for AWS

Rethink network security for public cloud using Cloud NGFW for AWS.

Deploying Cloud NGFW

Part 1: Subscribing to Cloud NGFW

Deploying Cloud NGFW

Part 2: Define Security Policies