NVIDIA BlueField-3 to Secure AI Factories
Learn how Prisma® AIRS™ deploys as a containerized firewall directly on the
NVIDIA BlueField-3 data processing unit to inspect north-south traffic at the AI factory
host boundary without consuming host application compute resources.
| Where Can I Use This? | What Do I Need? |
|
|
- Prisma AIRS license with ATP, Advanced WildFire, Advanced URL
Filtering, and AI-Protection subscriptions
- VMARM 12.2.3 or later
- NVIDIA BlueField-3 B3220 SuperNIC (16 cores, 32 GB memory, 120
GB hard disk)
- DOCA 3.x
- VM-Series plugin (for traffic steering rule
configuration)
- Kubernetes cluster with NVIDIA DPF (Data Plane Framework)
deployment — NVIDIA BlueField-3 DPUs onboarded as cluster
nodes
- Strata Cloud Manager or Panorama for centralized
management
|
As you build AI factory infrastructure to support AI agents, applications, data
pipelines, and models, you need security embedded directly into the infrastructure
without compromising the compute resources your AI workloads depend on. Traditionally,
you deploy next-generation firewalls directly on the host server. This wastes CPU and
memory that AI applications need, and creates awkward inspection points that don't align
with natural traffic boundaries.
Prisma AIRS now runs as a containerized firewall directly on the NVIDIA BlueField-3
data processing unit (DPU), a SmartNIC embedded in each AI factory server. Because the
DPU sits at the physical boundary between the network and the host, it is a natural and
non-intrusive inspection point for all north-south traffic entering and exiting the
host. The DPU provides its own ARM cores, memory, and storage — Prisma AIRS runs
without touching any host application resources.
Prisma AIRS on BlueField-3 uses NVIDIA DOCA (Data Center Infrastructure on a Chip
Architecture) for traffic steering through an Open vSwitch (OVS). By default, all
traffic bypasses the firewall. You define steering rules based on 5-tuple matching that
includes source IP, destination IP, protocol, source port, and destination port. The
steering rules tell the OVS whether to:
- Allow (bypass) traffic — traffic passes through OVS without firewall
inspection
- Block traffic — traffic is dropped at OVS before reaching the
firewall
- Inspect traffic — traffic is forwarded to the Prisma AIRS firewall for full
next-generation inspection
You configure these steering rules through the VM-Series plugin in Strata Cloud Manager
or Panorama. You can define up to 1,000 steering rules per firewall. Wildcards are
supported in 5-tuple rules.
The firewall operates in virtual wire (v-wire) mode, with one interface toward the
network and one interface toward the host. A dedicated management interface is also
provided.
Deployment Architecture
You deploy Prisma AIRS on BlueField-3 using a Helm chart. The Helm chart brings up
three components on each DPU node in your Kubernetes cluster:
- The OVS switch
- The Prisma AIRS firewall container
- The connectivity and integration between OVS and Prisma AIRS
The Helm chart uses a values.yaml file as a central location to
configure bootstrap parameters, environment variables, and deployment settings. The
containerized Prisma AIRS image is available from the Palo Alto Networks Customer
Support Portal or the Palo Alto Networks GCP container repository, and the Helm
chart points to the GCP repository by default.
Resource Allocation on the BlueField-3 DPU
The BlueField-3 B3220 SuperNIC provides 16 ARM cores, 32 GB of memory, and 120 GB
of storage. Prisma AIRS uses 4–12 of those ARM cores, 16 GB of memory, and up to
95 GB of storage, leaving the remaining DPU resources for DOCA services. Prisma
AIRS must be the only third-party networking service running on the BlueField-3.
Supported Traffic and Throughput
This deployment is designed for north-south inspection at the host boundary,
targeting AI inference traffic and operational technology (OT) traffic profiles up
to approximately 1–5 Gbps. Traffic beyond that threshold or east-west inspection
between pods within the same host should be handled by a centralized standalone
Prisma AIRS or a hardware form-factor firewall, using standard L3 routing or
PAN-CNI chaining for redirection.
Images
The containerized Docker and Prisma AIRS image for PAN-OS ARM 12.2.3 and later is
accessible on the Palo Alto Networks Customer Support Portal (CSP) or via the GCP
container registry at
panos_vmc:12.2.3.
root@localhost:~# docker pull gcr.io/pan-cn-series/airs/panos_vmc:12.2.3
12.2.3: Pulling from pan-cn-series/airs/panos_vmc
7757623e21ac: Extracting [================================================> ] 3.768GB/3.908GB
7757623e21ac: Extracting [=================================================> ] 3.877GB/3.908GB
7757623e21ac: Pull complete
Digest: sha256:45b24a8f93f34c52707f665aea57ba1db929e996e100f62ecdb73dace40cff61
Status: Downloaded newer image for gcr.io/pan-cn-series/airs/panos_vmc:12.2.3
gcr.io/pan-cn-series/airs/panos_vmc:12.2.3
root@localhost:~#
root@localhost:~#
root@localhost:~# docker images
REPOSITORY TAG IMAGE ID CREATED SIZE
gcr.io/pan-cn-series/airs/panos_vmc 12.2.3 99973cfc875a 4 weeks ago 7.76GB
Download the package from the Software Updates section by selecting PAN-OS for AI
Runtime Security NVidia BlueField from the dropdown menu. This option appears
dynamically for accounts provisioned with an active Prisma AIRS license.
root@localhost:~/BF3_images# docker load -i PanOS_bf3-12.2.3.tgz
e91dfa115e2a: Loading layer [==================================================>] 7.933GB/7.933GB
Loaded image: paloaltonetworks/panos_bf3_mpdp-arm:12.2.3
root@localhost:~/BF3_images#
root@localhost:~/BF3_images#
root@localhost:~/BF3_images# docker images
REPOSITORY TAG IMAGE ID CREATED SIZE
paloaltonetworks/panos_bf3_mpdp-arm 12.2.3 4d2f154857f9 23 hours ago 7.76GB
Upgrade Behavior
When you upgrade Prisma AIRS, replace the container by redeploying with the new
PAN-OS version. During upgrade, the firewall automatically enters bypass mode
(handled through DOCA steering rules) and traffic continues to flow. Bypass mode
events are logged for your visibility. Persistent volumes preserve the serial
number, configuration, and logs across upgrades. If a DOCA or BlueField-3 firmware
upgrade removes the firewall container, you must redeploy it through the Helm
chart.
Limitations
- High availability (active/passive failover across two BlueField-3 cards) is not
supported in this release.
- East-west inspection of pods or services within the same host is not
supported.
- Deploying multiple Prisma AIRS instances on a single BlueField-3 is not
supported.
- Multiple physical interfaces per firewall are not supported (multiple
sub-interfaces are supported).
- FIPS mode is not supported.
- VM-Series firewall form-factor is not supported on BlueField-3; only Prisma
AIRS is supported.
- IPv6 steering rules are not supported in this release.