NVIDIA BlueField-3 to Secure AI Factories
Focus
Focus
Prisma AIRS

NVIDIA BlueField-3 to Secure AI Factories

Table of Contents

NVIDIA BlueField-3 to Secure AI Factories

Learn how Prisma® AIRS™ deploys as a containerized firewall directly on the NVIDIA BlueField-3 data processing unit to inspect north-south traffic at the AI factory host boundary without consuming host application compute resources.
Where Can I Use This?What Do I Need?
  • NGFW (Prisma AIRS only)
  • Prisma AIRS license with ATP, Advanced WildFire, Advanced URL Filtering, and AI-Protection subscriptions
  • VMARM 12.2.3 or later
  • NVIDIA BlueField-3 B3220 SuperNIC (16 cores, 32 GB memory, 120 GB hard disk)
  • DOCA 3.x
  • VM-Series plugin (for traffic steering rule configuration)
  • Kubernetes cluster with NVIDIA DPF (Data Plane Framework) deployment — NVIDIA BlueField-3 DPUs onboarded as cluster nodes
  • Strata Cloud Manager or Panorama for centralized management
As you build AI factory infrastructure to support AI agents, applications, data pipelines, and models, you need security embedded directly into the infrastructure without compromising the compute resources your AI workloads depend on. Traditionally, you deploy next-generation firewalls directly on the host server. This wastes CPU and memory that AI applications need, and creates awkward inspection points that don't align with natural traffic boundaries.
Prisma AIRS now runs as a containerized firewall directly on the NVIDIA BlueField-3 data processing unit (DPU), a SmartNIC embedded in each AI factory server. Because the DPU sits at the physical boundary between the network and the host, it is a natural and non-intrusive inspection point for all north-south traffic entering and exiting the host. The DPU provides its own ARM cores, memory, and storage — Prisma AIRS runs without touching any host application resources.
Prisma AIRS on BlueField-3 uses NVIDIA DOCA (Data Center Infrastructure on a Chip Architecture) for traffic steering through an Open vSwitch (OVS). By default, all traffic bypasses the firewall. You define steering rules based on 5-tuple matching that includes source IP, destination IP, protocol, source port, and destination port. The steering rules tell the OVS whether to:
  • Allow (bypass) traffic — traffic passes through OVS without firewall inspection
  • Block traffic — traffic is dropped at OVS before reaching the firewall
  • Inspect traffic — traffic is forwarded to the Prisma AIRS firewall for full next-generation inspection
You configure these steering rules through the VM-Series plugin in Strata Cloud Manager or Panorama. You can define up to 1,000 steering rules per firewall. Wildcards are supported in 5-tuple rules.
The firewall operates in virtual wire (v-wire) mode, with one interface toward the network and one interface toward the host. A dedicated management interface is also provided.

Deployment Architecture

You deploy Prisma AIRS on BlueField-3 using a Helm chart. The Helm chart brings up three components on each DPU node in your Kubernetes cluster:
  • The OVS switch
  • The Prisma AIRS firewall container
  • The connectivity and integration between OVS and Prisma AIRS
The Helm chart uses a values.yaml file as a central location to configure bootstrap parameters, environment variables, and deployment settings. The containerized Prisma AIRS image is available from the Palo Alto Networks Customer Support Portal or the Palo Alto Networks GCP container repository, and the Helm chart points to the GCP repository by default.

Resource Allocation on the BlueField-3 DPU

The BlueField-3 B3220 SuperNIC provides 16 ARM cores, 32 GB of memory, and 120 GB of storage. Prisma AIRS uses 4–12 of those ARM cores, 16 GB of memory, and up to 95 GB of storage, leaving the remaining DPU resources for DOCA services. Prisma AIRS must be the only third-party networking service running on the BlueField-3.

Supported Traffic and Throughput

This deployment is designed for north-south inspection at the host boundary, targeting AI inference traffic and operational technology (OT) traffic profiles up to approximately 1–5 Gbps. Traffic beyond that threshold or east-west inspection between pods within the same host should be handled by a centralized standalone Prisma AIRS or a hardware form-factor firewall, using standard L3 routing or PAN-CNI chaining for redirection.

Images

The containerized Docker and Prisma AIRS image for PAN-OS ARM 12.2.3 and later is accessible on the Palo Alto Networks Customer Support Portal (CSP) or via the GCP container registry at panos_vmc:12.2.3.
root@localhost:~# docker pull gcr.io/pan-cn-series/airs/panos_vmc:12.2.3 12.2.3: Pulling from pan-cn-series/airs/panos_vmc 7757623e21ac: Extracting [================================================> ] 3.768GB/3.908GB 7757623e21ac: Extracting [=================================================> ] 3.877GB/3.908GB 7757623e21ac: Pull complete Digest: sha256:45b24a8f93f34c52707f665aea57ba1db929e996e100f62ecdb73dace40cff61 Status: Downloaded newer image for gcr.io/pan-cn-series/airs/panos_vmc:12.2.3 gcr.io/pan-cn-series/airs/panos_vmc:12.2.3 root@localhost:~# root@localhost:~# root@localhost:~# docker images REPOSITORY TAG IMAGE ID CREATED SIZE gcr.io/pan-cn-series/airs/panos_vmc 12.2.3 99973cfc875a 4 weeks ago 7.76GB
Download the package from the Software Updates section by selecting PAN-OS for AI Runtime Security NVidia BlueField from the dropdown menu. This option appears dynamically for accounts provisioned with an active Prisma AIRS license.
root@localhost:~/BF3_images# docker load -i PanOS_bf3-12.2.3.tgz e91dfa115e2a: Loading layer [==================================================>] 7.933GB/7.933GB Loaded image: paloaltonetworks/panos_bf3_mpdp-arm:12.2.3 root@localhost:~/BF3_images# root@localhost:~/BF3_images# root@localhost:~/BF3_images# docker images REPOSITORY TAG IMAGE ID CREATED SIZE paloaltonetworks/panos_bf3_mpdp-arm 12.2.3 4d2f154857f9 23 hours ago 7.76GB

Upgrade Behavior

When you upgrade Prisma AIRS, replace the container by redeploying with the new PAN-OS version. During upgrade, the firewall automatically enters bypass mode (handled through DOCA steering rules) and traffic continues to flow. Bypass mode events are logged for your visibility. Persistent volumes preserve the serial number, configuration, and logs across upgrades. If a DOCA or BlueField-3 firmware upgrade removes the firewall container, you must redeploy it through the Helm chart.

Limitations

  • High availability (active/passive failover across two BlueField-3 cards) is not supported in this release.
  • East-west inspection of pods or services within the same host is not supported.
  • Deploying multiple Prisma AIRS instances on a single BlueField-3 is not supported.
  • Multiple physical interfaces per firewall are not supported (multiple sub-interfaces are supported).
  • FIPS mode is not supported.
  • VM-Series firewall form-factor is not supported on BlueField-3; only Prisma AIRS is supported.
  • IPv6 steering rules are not supported in this release.