Deploy a containerized Prisma® AIRS™ firewall on each NVIDIA BlueField-3 DPU in
your AI factory cluster using a Helm chart, then configure traffic steering rules to
selectively inspect north-south host traffic.
| Where Can I Use This? | What Do I Need? |
|
|
- Prisma AIRS license with ATP, Advanced WildFire, Advanced
URL Filtering, and AI-Protection subscriptions
- VMARM 12.2.3 or later
- NVIDIA BlueField-3 B3220 SuperNIC per host server
- DOCA 3.x installed on each BlueField-3
- Kubernetes cluster with NVIDIA DPF — all BlueField-3 DPUs
onboarded as cluster nodes before starting this
procedure
- VM-Series plugin installed in Strata Cloud Manager or
Panorama
- Helm CLI installed on your management workstation
- Access to the Palo Alto Networks Customer Support Portal or
GCP container repository
|
Deploy Prisma AIRS on your NVIDIA BlueField-3 DPUs to embed firewall inspection
directly into your AI factory infrastructure at the host boundary. This protects
north-south traffic without consuming host application resources. The Helm chart
automates the deployment of the Prisma AIRS container, the OVS switch, and the
connectivity between them across all DPU nodes in your Kubernetes cluster
simultaneously.
Prerequisite:
Before you begin, confirm that your NVIDIA
BlueField-3 DPUs are already onboarded as nodes in a Kubernetes cluster using the
NVIDIA DPF deployment model. Prisma AIRS must be the only third-party networking
service running on each BlueField-3.
Use the tabs below to configure DPU steering from your preferred management
interface:
Panorama
Configure DPU traffic steering rules for your NVIDIA BlueField-3 embedded Prisma
AIRS firewalls using the VM-Series plugin in Panorama.
Access the VM-Series Plugin to configure DPU steering.
From the Panorama web interface, select .
Locate the
VM-Series Plugin and ensure it is
installed and enabled.
Define a new traffic steering rule.
This rule instructs the DPU's OVS-DOCA to direct traffic matching the
defined 5-tuple criteria to the Prisma AIRS firewall for inspection.
Select .
On the
DPU Steering page, select
Add
Rule.
For Standalone firewall Select
VM-Series Plugin > Nvidia.
On the DPU Steering page, select
Add Rule.
Enter a descriptive
Name, such as
Inspect_AI_Traffic.
Set the
Priority.
For
Action, select
Inspect.
Specify the traffic criteria:
- For Protocol, select
tcp.
- For Source Subnet, enter
10.1.1.0/24.
- For Destination Subnet, enter
10.2.0.0/24.
- For Destination Port, enter
443.
Select
OK to save the rule.
You can configure up to 1,000 rules.
Commit the changes to the DPU-embedded firewalls.
Committing the configuration applies the defined steering rules and failure
mode settings from Panorama to your managed DPU-embedded firewalls.
Select
Commit at the top right of the Panorama
interface.
Review the changes and select Commit again in
the confirmation dialog.
CLI
Configure DPU traffic steering rules for your NVIDIA BlueField-3 embedded Prisma
AIRS firewalls using PAN-OS CLI commands.
Enter configuration mode on the firewall to define steering flow rules using
the following syntax:
set deviceconfig plugins vm_series steering-flow <rule-name> action
<inspect|allow|drop> in-port <port-name> priority <2-65535> match [
source-subnet <CIDR> ] [ destination-subnet <CIDR> ] [ protocol
<any|tcp|udp|icmp> ] [ source-port <0-65535> ] [ destination-port
<0-65535> ]
Configure steering rules for your traffic types. Use the following examples as
a reference:
Inspect HTTPS traffic from a host subnet:
set deviceconfig plugins vm_series steering-flow test1 action
inspect in-port p0 priority 100 match source-subnet 10.1.1.0/24
destination-subnet 10.2.0.0/24 protocol tcp destination-port 443
commit
Inspect all TCP traffic from a specific host IP:
set deviceconfig plugins vm_series steering-flow
inspect-tcp-10-4-50-89 action inspect in-port p0 priority 50
match source-subnet 10.4.50.89/32 protocol tcp
commit
Verify the active steering flow rules:
admin@PA-VMARM> show plugins vm_series steering-flow
The output lists all configured steering rules with their name, enabled
state, in-port, priority, action, protocol, source subnet, destination
subnet, and port values. Example output:
Steering Flow Rules (501 configured):
Name Enable In-Port Priority Action Protocol Source Subnet Dest Subnet SPort DPort
---------------------------------------------------------------------------------------------------------
SteeringRule-CPT yes p0 100 inspect any 174.1.0.0/24 174.2.0.0/24 0 0
SteeringRule1 yes p0 101 inspect any 1.1.1.5 2.2.2.0/24 0 0
SteeringRule2 yes p0 102 inspect any 1.1.1.6 2.2.2.0/24 0 0
SteeringRule3 yes p0 103 inspect any 1.1.1.7 2.2.2.0/24 0 0
Verify traffic statistics and packet counts:
admin@PA-VMARM> show plugins vm_series steering-flow-stats