AIRS Managed SaaS Firewall
Learn about the AIRS Managed SaaS Firewall, a managed cloud firewall on AWS, Azure, and GCP that secures AI workloads without managing infrastructure.
| Where Can I Use This? | What Do I Need? |
- Prisma AIRS — AI Runtime Security (Network Intercept)
|
- Prisma AIRS AI Runtime Security license
- AWS, Azure, or GCP account
|
When you run AI workloads on managed cloud services — such as Amazon Bedrock Agents or
similar serverless AI platforms — the Prisma® AIRS™ Managed SaaS Firewall provides
network-level AI security without requiring you to deploy or operate firewall
infrastructure. Palo Alto Networks delivers the firewall as a cloud-native managed
service in your public cloud environment, so you get inline AI threat inspection at scale
without the operational overhead of managing VM-Series instances yourself.
The AIRS Managed SaaS Firewall uses a dual-data plane architecture that combines Layer
4–7 network inspection with deep inline semantic inspection. This architecture
specifically resolves certificate pinning failures that occur in managed and serverless AI
platforms — a common obstacle when applying TLS inspection to traffic generated by Amazon
Bedrock Agents and similar services. It delivers AI threat protection, Model Context
Protocol (MCP) tool call guarding, and enterprise data loss prevention (DLP) across AI
pipelines running on AWS, Azure, and GCP.
The Managed SaaS Firewall is purpose-built for high-throughput, low-latency AI
environments including distributed training clusters, containerized Kubernetes pods, and
LLM inference pipelines. It uses AI-powered security inspection to detect and block
sophisticated threats, malicious prompts, and compliance anomalies targeting model
traffic, and provides deep packet inspection tailored for containerized East-West traffic
traversing internal machine learning cluster blocks.
Deployment is automated through Strata Cloud Manager using Terraform-based templates.
Auto-Execute deployment reduces manual onboarding steps for new firewalls across AWS and
Azure. For air-gapped or compliance-constrained environments, the
manual bootstrap deployment supports private cloud environments where
automated provisioning isn't available.