Managed AIRS for AWS Subscription and Billing
Focus
Focus
Prisma AIRS

Managed AIRS for AWS Subscription and Billing

Table of Contents


Managed AIRS for AWS Subscription and Billing

Learn about AWS Marketplace billing for Managed AIRS for AWS, including generating billing codes and linking AWS accounts to Strata Cloud Manager.
Where Can I Use This?What Do I Need?
  • Managed AIRS for AWS
  • Managed AIRS for AWS subscription
  • Palo Alto Networks Customer Support Account (CSP)
  • AWS Marketplace account
  • User role (either tenant or administrator)

Managed AIRS for AWS Tenant

When you create the first Managed AIRS for AWS resource in the Strata Cloud Manager, the platform automatically creates a Managed AIRS for AWS tenant and links it with Strata Cloud Manager. This Managed AIRS for AWS tenant remains dedicated to the Strata Cloud Manager.

AWS Marketplace Billing Association

You can generate a billing code in the Strata Cloud Manager console for an AWS account and then use it when you subscribe from the same account in AWS Marketplace. This action establishes the PAYG billing link, enabling metering records to be sent from Managed AIRS for AWS to the AWS Marketplace Metering Service. Your Managed AIRS for AWS resources remain intact during this transition.

Generate Billing Code and Subscribe using AWS Marketplace

  1. Add a Pay-As-You-Go (PAYG) Subscription
    1. In the Strata Cloud Manager UI, go to the Subscriptions page.
    2. Click Add New Subscription.
    3. Enter the AWS Account ID that will be used for billing.
    4. Click Generate Billing Subscription Code. The platform will generate a billing association code, and an email will be sent to the admin user who created the Strata Cloud Manager tenant.
    5. Click Complete the Subscription on AWS Marketplace.
    6. Go to the Palo Alto Networks Managed AIRS for AWS page on the AWS Marketplace and click View purchase options or Subscribe. This will open the AWS Marketplace in a new browser tab.
  2. Complete Subscription on AWS Marketplace.
    If you are subscribing to Managed AIRS for AWS with this AWS account for the first time, you will be redirected to Palo Alto Networks Managed AIRS for AWS page in AWS Marketplace. Perform the following steps:
    1. Click Subscribe.
    2. Review the offer details and click Subscribe again on the confirmation page if prompted.
    3. After subscribing, click Set up your account. You will be redirected to the AWS Quick Launch page to link your Strata Cloud Manager tenant.
      If you have previously subscribed to Managed AIRS for AWS from this account, the subscribe button will be greyed out. Click Set up your Account to go to the Quick Launch page as described in Step 2 in Generate Billing Code and Subscribe using AWS Marketplace. For more information, see AWS Marketplace Billing Aggregation.
  3. Click Enable Integration and ensure that you have all required AWS permissions.
  4. Click Login or create an account.
  5. Link your Managed AIRS for AWS Account by applying Billing Code generated in Step 1.
    1. Select the option I have a Strata Cloud Manager Billing Subscription Code and enter the code you generated in Strata Cloud Manager to link the Strata Cloud Manager.
    2. Enter your Email.
    3. Click Save.
      Upon successful subscription, you will be redirected back to the Strata Cloud Manager UI.
    4. Click Continue with Strata Cloud Manager. You are now redirected to the Strata Cloud Manager portal. In the Subscription tab, you can see the Pay-as-you-go subscription or free-trial subscription details.
      If you want to add a second Strata Cloud Manager tenant using the same AWS account, click Add New Subscription. You will be redirected to generate new Strata Cloud Manager Billing Subscription Code. Complete the steps described in Step 2. This will change the billing account to a different AWS Account.

Replace AWS Marketplace Billing Association

If you would like to subscribe using a different account for billing purposes, you can repeat the above process and generate a billing code for another AWS account and then use it when you subscribe from the corresponding AWS account in the AWS Marketplace. When you subscribe from a second AWS account to the same Strata Cloud Manager, the platform replaces the currently established billing link with this newly subscribed account. It dynamically selects the new subscribed account for sending metering and overage records. You can then go ahead and unsubscribe from the original AWS account. Your Managed AIRS for AWS resources remain intact during this transition.
If you unsubscribe from the currently subscribed PAYG account used for billing and have not added Managed AIRS for AWS credits to your Managed AIRS for AWS tenant, the platform will delete all your Managed AIRS for AWS resources.

AWS Marketplace Billing Aggregation

You may use multiple Strata Cloud Managers in your environment to meet your governance model or regional presence. When this is the case, it becomes necessary to create Managed AIRS for AWS resources independently for each Strata Cloud Manager.
This distributed approach necessitates a repetition of certain critical steps for each Strata Cloud Manager. Specifically, you will need to:
  1. Generate a Billing Code within each Strata Cloud Manager Console: This involves navigating to the administrative interface of each Strata Cloud Manager and following the procedure to generate a unique billing subscription code. This code is essential for linking Strata Cloud Manager to AWS Marketplace for billing purposes.
  2. Establish a Billing Link to AWS Marketplace: After generating the billing code, you establish a billing link for each Strata Cloud Manager using your AWS Marketplace account:
    1. Click Set up your Account to go to the Quick Launch page.
    2. You are redirected to Quick launch page of your relevant product listing in AWS Marketplace.
    3. Click Link a different account.
    4. Select the option I have a Strata Cloud Manager Billing Subscription Code.
    5. Accurately enter the unique billing code previously generated in the respective Strata Cloud Manager and click Continue.
Following these steps initiates the linking process using the previously established AWS Marketplace subscription. Upon successful completion of the billing link, the workflow will automatically redirect you back to the Strata Cloud Manager console, confirming the integration. This process ensures that billing for Cloud NGFW resources deployed through each specific Strata Cloud Manager is correctly associated with the appropriate AWS Marketplace account.
In this case, if you unsubscribe from the currently subscribed account used for establishing billing links with multiple Strata Cloud Managers and have not added Managed AIRS for AWS credits to your Managed AIRS for AWS tenant, the platform will delete all your Managed AIRS for AWS resources in all the associated Strata Cloud Managers.

Credit Management

Optionally, you can purchase and activate Managed AIRS for AWS Credits, then associate them with each Strata Cloud Manager/Managed AIRS for AWS tenant. From then on, the platform continuously validates usage against your credit allocation on each Strata Cloud Manager. If consumption exceeds your allocated credits, the platform calculates overages and sends PAYG metering records to AWS Marketplace. If your credits expire, the Cloud NGFW platform automatically and seamlessly switches to your active AWS Marketplace subscription for Pay-As-You-Go billing. Your Managed AIRS for AWS resources remain intact during these transitions.