AIRS VM Firewall
Focus
Focus
Prisma AIRS

AIRS VM Firewall

Table of Contents

AIRS VM Firewall

Learn about the AIRS VM Firewall, a VM-Series software firewall that enforces network-level AI security without changing application code.
Where Can I Use This?What Do I Need?
  • Prisma AIRS — AI Runtime Security (Network Intercept)
  • VM-Series
  • Prisma AIRS AI Runtime Security license
  • PAN-OS 11.2.11, 12.1.5, or later
When you need AI security without modifying application code, the AIRS VM Firewall deploys as a Prisma® AIRS™ software firewall that inspects AI traffic inline at the network layer. You change the network, not the application — and security policies apply consistently across all AI traffic regardless of the applications or models generating it. Strata Cloud Manager or Panorama provides centralized policy management across your entire deployment.
The AIRS VM Firewall runs on the same universal image as VM-Series, with the license determining the operational mode at runtime. The Prisma AIRS form factor includes all VM-Series capabilities plus Container Network Security, Microperimeter, AI threat protection, and Hyperscale Security Fabric — eliminating the need for separate products across different security domains. You can deploy on AWS, Azure, GCP, or private cloud environments and manage the full firewall lifecycle including configuration, policy, and upgrades.
Prisma AIRS network intercept delivers Cloud-Delivered Security Services (CDSS) that include best-in-class Layer 7 AI threat protection, cloud network security, and container network security. It protects against prompt injection in 30+ attack variations, detects malicious URLs across 74 categories, and achieves 99.58% malware detection accuracy — all without touching application source code. It also provides native support for Model Context Protocol (MCP) threat detection across AI agent traffic.
Deployment options scale from single-instance cloud firewalls to enterprise-scale distributed architectures:
  • Strata Cloud Manager — deploy and manage VM-Series and Prisma AIRS firewalls across AWS, Azure, and GCP from a single centralized platform
  • Panorama — integrate Prisma AIRS with existing Panorama-managed infrastructure for organizations already standardized on Panorama policy management
  • Hyperscale Security Fabric (HSF) — deploy high-throughput clusters for large-scale distributed environments requiring horizontal scaling across many firewall nodes
  • Microperimeter — enforce container-native security at the Kubernetes pod level, securing East-West traffic without requiring network topology changes