AIRS VM Firewall
Learn about the AIRS VM Firewall, a VM-Series software firewall that enforces network-level AI security without changing application code.
| Where Can I Use This? | What Do I Need? |
- Prisma AIRS — AI Runtime Security (Network Intercept)
- VM-Series
|
- Prisma AIRS AI Runtime Security license
- PAN-OS 11.2.11, 12.1.5, or later
|
When you need AI security without modifying application code, the AIRS VM Firewall
deploys as a Prisma® AIRS™ software firewall that inspects AI traffic inline at the
network layer. You change the network, not the application — and security policies apply
consistently across all AI traffic regardless of the applications or models generating
it. Strata Cloud Manager or Panorama provides centralized policy management across your
entire deployment.
The AIRS VM Firewall runs on the same universal image as VM-Series, with the license
determining the operational mode at runtime. The Prisma AIRS form factor includes all
VM-Series capabilities plus Container Network Security, Microperimeter, AI threat
protection, and Hyperscale Security Fabric — eliminating the need for separate products
across different security domains. You can deploy on AWS, Azure, GCP, or private cloud
environments and manage the full firewall lifecycle including configuration, policy, and
upgrades.
Prisma AIRS network intercept delivers Cloud-Delivered Security Services (CDSS) that
include best-in-class Layer 7 AI threat protection, cloud network security, and
container network security. It protects against prompt injection in 30+ attack
variations, detects malicious URLs across 74 categories, and achieves 99.58% malware
detection accuracy — all without touching application source code. It also provides
native support for
Model Context Protocol (MCP) threat detection across AI agent
traffic.
Deployment options scale from single-instance cloud firewalls to enterprise-scale
distributed architectures:
- Strata Cloud Manager — deploy and manage VM-Series and Prisma AIRS firewalls
across AWS, Azure, and GCP from a single centralized platform
- Panorama — integrate Prisma AIRS with existing Panorama-managed
infrastructure for organizations already standardized on Panorama policy
management
- Hyperscale Security Fabric (HSF) — deploy high-throughput clusters for
large-scale distributed environments requiring horizontal scaling across many
firewall nodes
- Microperimeter — enforce container-native security at the Kubernetes pod
level, securing East-West traffic without requiring network topology changes