Deploy Prisma AIRS on NVIDIA BlueField-3
Focus
Focus
Prisma AIRS

Deploy Prisma AIRS on NVIDIA BlueField-3

Table of Contents

Deploy Prisma AIRS on NVIDIA BlueField-3

Deploy a containerized Prisma® AIRS™ firewall on each NVIDIA BlueField-3 DPU in your AI factory cluster using a Helm chart, then configure traffic steering rules to selectively inspect north-south host traffic.
Where Can I Use This?What Do I Need?
  • NGFW (Prisma AIRS only)
  • Prisma AIRS license with ATP, Advanced WildFire, Advanced URL Filtering, and AI-Protection subscriptions
  • VMARM 12.2.3 or later
  • NVIDIA BlueField-3 B3220 SuperNIC per host server
  • DOCA 3.x installed on each BlueField-3
  • Kubernetes cluster with NVIDIA DPF — all BlueField-3 DPUs onboarded as cluster nodes before starting this procedure
  • VM-Series plugin installed in Strata Cloud Manager or Panorama
  • Helm CLI installed on your management workstation
  • Access to the Palo Alto Networks Customer Support Portal or GCP container repository
Deploy Prisma AIRS on your NVIDIA BlueField-3 DPUs to embed firewall inspection directly into your AI factory infrastructure at the host boundary. This protects north-south traffic without consuming host application resources. The Helm chart automates the deployment of the Prisma AIRS container, the OVS switch, and the connectivity between them across all DPU nodes in your Kubernetes cluster simultaneously.
Prerequisite:
Before you begin, confirm that your NVIDIA BlueField-3 DPUs are already onboarded as nodes in a Kubernetes cluster using the NVIDIA DPF deployment model. Prisma AIRS must be the only third-party networking service running on each BlueField-3.
Use the tabs below to configure DPU steering from your preferred management interface:

Panorama

Configure DPU traffic steering rules for your NVIDIA BlueField-3 embedded Prisma AIRS firewalls using the VM-Series plugin in Panorama.
  1. Access the VM-Series Plugin to configure DPU steering.
    1. From the Panorama web interface, select PanoramaPlugins.
    2. Locate the VM-Series Plugin and ensure it is installed and enabled.
  2. Define a new traffic steering rule.
    This rule instructs the DPU's OVS-DOCA to direct traffic matching the defined 5-tuple criteria to the Prisma AIRS firewall for inspection.
    1. Select DeviceTemplateVM-Series PluginNvidia.
    2. On the DPU Steering page, select Add Rule.
    3. For Standalone firewall Select VM-Series Plugin > Nvidia.
    4. On the DPU Steering page, select Add Rule.
    5. Enter a descriptive Name, such as Inspect_AI_Traffic.
    6. Set the Priority.
    7. For Action, select Inspect.
    8. Specify the traffic criteria:
      • For Protocol, select tcp.
      • For Source Subnet, enter 10.1.1.0/24.
      • For Destination Subnet, enter 10.2.0.0/24.
      • For Destination Port, enter 443.
    9. Select OK to save the rule.
      You can configure up to 1,000 rules.
  3. Commit the changes to the DPU-embedded firewalls.
    Committing the configuration applies the defined steering rules and failure mode settings from Panorama to your managed DPU-embedded firewalls.
    1. Select Commit at the top right of the Panorama interface.
    2. Review the changes and select Commit again in the confirmation dialog.

CLI

Configure DPU traffic steering rules for your NVIDIA BlueField-3 embedded Prisma AIRS firewalls using PAN-OS CLI commands.
  1. Enter configuration mode on the firewall to define steering flow rules using the following syntax:
    set deviceconfig plugins vm_series steering-flow <rule-name> action <inspect|allow|drop> in-port <port-name> priority <2-65535> match [ source-subnet <CIDR> ] [ destination-subnet <CIDR> ] [ protocol <any|tcp|udp|icmp> ] [ source-port <0-65535> ] [ destination-port <0-65535> ]
  2. Configure steering rules for your traffic types. Use the following examples as a reference:
    Inspect HTTPS traffic from a host subnet:
    set deviceconfig plugins vm_series steering-flow test1 action inspect in-port p0 priority 100 match source-subnet 10.1.1.0/24 destination-subnet 10.2.0.0/24 protocol tcp destination-port 443 commit
    Inspect all TCP traffic from a specific host IP:
    set deviceconfig plugins vm_series steering-flow inspect-tcp-10-4-50-89 action inspect in-port p0 priority 50 match source-subnet 10.4.50.89/32 protocol tcp commit
  3. Verify the active steering flow rules:
    admin@PA-VMARM> show plugins vm_series steering-flow
    The output lists all configured steering rules with their name, enabled state, in-port, priority, action, protocol, source subnet, destination subnet, and port values. Example output:
    Steering Flow Rules (501 configured): Name Enable In-Port Priority Action Protocol Source Subnet Dest Subnet SPort DPort --------------------------------------------------------------------------------------------------------- SteeringRule-CPT yes p0 100 inspect any 174.1.0.0/24 174.2.0.0/24 0 0 SteeringRule1 yes p0 101 inspect any 1.1.1.5 2.2.2.0/24 0 0 SteeringRule2 yes p0 102 inspect any 1.1.1.6 2.2.2.0/24 0 0 SteeringRule3 yes p0 103 inspect any 1.1.1.7 2.2.2.0/24 0 0
  4. Verify traffic statistics and packet counts:
    admin@PA-VMARM> show plugins vm_series steering-flow-stats