Listing Thumbnail

    Cloud Next-Generation Firewall as a Service (30-Day Free Trial to PAYG)

     Info
    Deployed on AWS
    Free Trial
    Vendor Insights
    Quick Launch
    Fully managed, cloud-native firewall service with threat prevention, app control and advanced URL filtering that integrates with AWS Firewall Manager, CloudWatch and more.

    Overview

    Play video

    Product Overview

    Cloud Next-Generation Firewall (CNGFW) for AWS delivers best-in-class network security powered by artificial intelligence and machine learning, stopping zero-day exploits faster than traditional platforms. This fully managed turnkey cloud-native firewall service with 99.99% availability removes the complexity of managing firewall infrastructure in AWS. It lets you immediately turn on the next-generation firewall features and scale your security, ensuring seamless protection for your applications in the AWS environment.

    Cloud NGFW extends your threat prevention capabilities across AWS environments and seamlessly integrates with key AWS services like AWS Firewall Manager, CloudWatch, Kinesis Firehose, and more. It provides real-time insights, automated security workflows, and granular traffic control for robust network protection. Recent enhancements include Strata Cloud Manager integration for centralized visibility and firewall-as-code enhancements.

    Benefits

    • Effortless Deployment and Zero-Operational Burden: Palo Alto Networks Cloud NGFW takes care of the complex operational tasks, allowing for seamless firewall deployment and management in AWS. It streamlines processes such as certificate management, software upgrades, patch management and multi-dimensional scaling to ensure 99.99% availability. By eliminating the challenges of managing and scaling firewalls yourself, you can deploy robust cloud protection in just a few clicks, without worrying about infrastructure management.

    • Advanced Threat Prevention. Secure your AWS VPC traffic from zero-day attacks and unknown command-and-control traffic using Cloud-Delivered Security Services (CDSS) powered by Precision AI as well as Unit 42 Threat Research, enabling detection and mitigation 180x faster than traditional platforms.

    • Real-Time Threat Detection. Protect your applications with advanced AI and ML-powered threat prevention, leveraging intelligence derived from 70,000+ global customers to stop zero-day exploits, DNS threats, and web-based threats before they impact your network. This extensive threat intelligence network continuously learns and adapts, providing unparalleled protection that evolves with the latest attack vectors.

    • Granular Traffic Control. Gain visibility and precise control over your network traffic based on workloads, users, and applications with patented Layer 7 classification. Reduce attack surfaces and safeguard your AWS environment from malicious traffic.

    • Centralized Visibility. Simplify security operations with centralized management using Strata Cloud Manager or Panorama. Gain comprehensive visibility into applications, users, and threats for more efficient security management, faster threat resolution, and optimized policy creation.

    • Improved Metrics & Monitoring. Leverage AWS CloudWatch to monitor NGFW health, performance, and usage patterns in real-time, ensuring your security operations run at peak efficiency.

    • Firewall-as-Code Enhancements. Automate your firewall deployment, policy enforcement and account management workflows with the support of APls, CloudFormation and Terraform. Eliminate manual interventions and streamline your security operations.

    • Cloud NGFW is the Firewall-as-a-Service. Choose either AWS Firewall Manager or Palo Alto Networks Panorama for consistent policy management across multiple AWS accounts, enabling flexible control and seamless security across your cloud environments.

    Activate your 30-Day free trial and create up to two next-generation firewall resources on your existing AWS VPCs, securing up to 100GB of traffic. After the free trial, you'll transition to a pay-as-you-go model, and you can check your subscription status on the Subscription Management page.

    Highlights

    • Deploy your next-generation firewall with one-click, automated provisioning that auto-scales to match your network traffic. Leverage Palo Alto Networks Panorama or Strata Cloud Manager for unified security management, ensuring you maintain control and visibility across your cloud infrastructure without the complexity of managing infrastructure.
    • Integrate seamlessly with AWS-native services like CloudWatch, Kinesis Firehose, and AWS Firewall Manager, providing real-time insights, granular traffic control, and enhanced security capabilities. Backed by Palo Alto Networks Unit 42 Threat Research, the service delivers cutting-edge threat prevention and faster mitigation of zero-day exploits.
    • Cloud NGFW supports automated onboarding of AWS environments and workflow automation through APIs, CloudFormation, and Terraform, enabling quick deployment and consistent operations. Gain comprehensive visibility and management across multiple AWS accounts with centralized security operations using Strata Cloud Manager or Panorama.

    Details

    Delivery method

    Deployed on AWS

    Features and programs

    Vendor Insights

     Info
    Skip the manual risk assessment. Get verified and regularly updated security info on this product with Vendor Insights.
    Security credentials achieved
    (2)

    Buyer guide

    Gain valuable insights from real users who purchased this product, powered by PeerSpot.
    Buyer guide

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Quick Launch

    Leverage AWS CloudFormation templates to reduce the time and resources required to configure, deploy, and launch your software.

    Pricing

    Free trial

    Try this product free according to the free trial terms set by the vendor.

    Cloud Next-Generation Firewall as a Service (30-Day Free Trial to PAYG)

     Info
    Pricing is based on actual usage, with charges varying according to how much you consume. Subscriptions have no end date and may be canceled any time.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    Usage costs (5)

     Info
    Dimension
    Cost/unit
    Base NGFW - incl. 3 AZs (1unit=1 usage hour), addt'l AZ 0.33 unit/hr
    $1.50
    Traffic Secured - First 15 TB / month (1 unit = 1 GB)
    $0.065
    Traffic Secured - Next 15 TB / month (1 unit = 1 GB)
    $0.045
    Traffic Secured - Above 30 TB / month (1 unit = 1 GB)
    $0.03
    Add-Ons (1 unit = 1 Cloud NGFW Credit) (refer to page bit.ly/cngfwaws)
    $0.012

    Vendor refund policy

    We do not currently support refunds, but you can cancel at any time.

    Custom pricing options

    Request a private offer to receive a custom quote.

    How can we make this page better?

    We'd like to hear your feedback and ideas on how to improve this page.
    We'd like to hear your feedback and ideas on how to improve this page.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Resources

    Vendor resources

    Support

    Vendor support

    "Premium support is now included with the product: https://www.paloaltonetworks.com/resources/datasheets/premium-support . To help you get started with your deployment such as how-to videos, deployment guides and reference architectures, please visit: https://live.paloaltonetworks.com/t5/cloud-ngfw-help-center/ct-p/Cloud_NGFW . For post-sales support, you can use the following options: 1) Open a case by following the steps here: https://www.paloaltonetworks.com/services/support/customer-support-plan . 2) Call us at 1 (866) 898-9087"

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Product comparison

     Info
    Updated weekly

    Accolades

     Info
    Top
    10
    In Network Infrastructure, Security
    Top
    25
    In Data Governance

    Customer reviews

     Info
    AI generated sentiment from actual customer reviews on AWS and G2
    Reviews
    Functionality
    Ease of use
    Customer service
    Cost effectiveness
    15 reviews
    Insufficient data
    21 reviews
    Insufficient data
    Positive reviews
    Mixed reviews
    Negative reviews

    Overview

     Info
    AI generated from product descriptions
    Threat Prevention
    Advanced AI and machine learning-powered threat detection leveraging intelligence from global customer network to stop zero-day exploits and unknown command-and-control traffic
    Network Traffic Classification
    Patented Layer 7 classification for granular traffic control based on workloads, users, and applications with precise network traffic visibility
    Cloud Service Integration
    Native integration with AWS services including Firewall Manager, CloudWatch, Kinesis Firehose for comprehensive security management and monitoring
    Infrastructure Automation
    Support for infrastructure-as-code deployment using APIs, CloudFormation, and Terraform for automated firewall provisioning and policy enforcement
    Security Intelligence
    Cloud-delivered security services powered by Precision AI and Unit 42 Threat Research for real-time threat detection and mitigation
    Network Security Capabilities
    Next-generation firewall with intrusion prevention, application control, content filtering powered by AI-driven FortiGuard Labs technology
    Cloud Integration
    Seamless integration with AWS services including AWS Gateway Load Balancer and AWS Firewall Manager
    Scalability Architecture
    Single instance capable of protecting up to 1000 subnets across multiple VPCs, subnets, and availability zones in an AWS region
    Security Policy Management
    Comprehensive console with purpose-built wizards for associating AWS accounts, creating firewall instances, defining protected objects, and managing security policies
    Multi-Platform Policy Synchronization
    Supports policy definition and synchronization across AWS Firewall Manager and FortiManager platforms
    Cloud Infrastructure Monitoring
    Continually monitor public cloud infrastructure across AWS, Azure, and GCP environments to provide comprehensive visibility of resources and potential threats
    Vulnerability Detection
    Identify infrastructure vulnerabilities impacting security and compliance best practice standards with risk profiling and contextual alerts
    Multi-Cloud Asset Management
    Achieve a complete picture of cloud assets across multi-cloud environments, monitoring configurations, deployments, and access anomalies
    Security Configuration Analysis
    Detect insecure configurations, over-privileged IAM roles, and compliance failures from development through live service stages
    API Integration Capabilities
    Provide programmatic access to security features via REST API for seamless integration with third-party SIEM and DevOps tools

    Security credentials

     Info
    Validated by AWS Marketplace
    FedRAMP
    GDPR
    HIPAA
    ISO/IEC 27001
    PCI DSS
    SOC 2 Type 2
    -
    -
    -
    -
    -
    No security profile
    No security profile

    Contract

     Info
    Standard contract
    No
    No
    No

    Customer reviews

    Ratings and reviews

     Info
    0 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    0%
    0%
    0%
    0%
    0%
    0 AWS reviews
    |
    104 external reviews
    External reviews are sourced from G2  and are not included in the star rating for this product.
    Yaswanth V.

    Digital Transformation project and having Palo Alto as the External Firewall

    Reviewed on May 26, 2025
    Review provided by G2
    What do you like best about the product?
    Their high end security and can be Used with third party integration
    The support team was very helpful and the suppliers too
    Easy to login frequent updates
    Implementation was very easy to integrate with other firewalls
    we are using it for managing our sd wan Across globe with our head office
    What do you dislike about the product?
    complex to use than others and bit on the high-cost variants and bit of an overkill for smaller environments and certification and training cost way more than others.
    What problems is the product solving and how is that benefiting you?
    It acts as a central management tool for our head office and remote offices, and we are using it for VPN and SD WAN Management we intergrated it with PRISMA
    Navjeet S.

    I had a wonderful experience working with palo alto network cloud

    Reviewed on May 23, 2025
    Review provided by G2
    What do you like best about the product?
    I like using Palo Alto Networks Cloud NGFW everyday. It is my go to for getting strong security for my website. Jt integrates perfectly with the other interfaces.
    Would recommend it to everyone who values sustainability and efficiency of security systems.
    What do you dislike about the product?
    The complexity of finding the website ans navigate around jt can be reduced.
    It took me some time to get familiar to the environment. It is great for AWS, but support on other cloud platforms feels limited.
    What problems is the product solving and how is that benefiting you?
    It provides strong security for cloud environments, works well with AWS, and is easy to scale as needed. It also makes managing network security more streamlined and efficient.
    Sai Kaushik S.

    Review of G2

    Reviewed on May 22, 2025
    Review provided by G2
    What do you like best about the product?
    Protecting organizations from cyberattacks starts with a network security platform as the cornerstone of an effective network security strategy. Security tools such as next-generation firewalls, cloud-delivered SASE, threat prevention, URL filtering, DNS security, artificial intelligence for operations and IoT security are essential to protect organizations from evasive threats and malware.
    What do you dislike about the product?
    Nothing as you guys are helping to build firewalls to protect us from cyber attacks, so i feel there is nothing i can say, i feel thhis is helpful for people
    What problems is the product solving and how is that benefiting you?
    Cloud NGFW acts as a security measure for cloud operations. It protects cloud applications by preventing unauthorized access and ensures smooth operation, reducing team workload. Cloud NGFW stops threats, provides clear visibility, and reduces the time needed for security management. It offers a smart, automated security system for all cloud operations.
    Telecommunications

    Robust features that meets many use cases and catch scenarios, however slightly laggy load times.

    Reviewed on May 21, 2025
    Review provided by G2
    What do you like best about the product?
    I like the detailed policy/ rule creation that fits the companies hardware stack. There is no missing features so to say everything is well thought of.
    What do you dislike about the product?
    The thing I do not like about Palo Alto Networks Cloud NGFW is that there is a steep learning curve and the GUI is complicated, I hope for ease of use.
    What problems is the product solving and how is that benefiting you?
    It helps the company manage their firewall rules and policy accordingly based on the work that needs to be done or installing new hardware and using it to mitigate threats and it works well with our Elastic Stack. A common daily use case is giving exceptions to people traveling to different countries we give them a rule to allow traffic from there using the work companies laptop after they get approval while certain countries traffic is automatically blocked due to adversarial risks according to government policy that goes down toward regular IT companies and their infrastructure.
    Internet

    Comprehensive Security software for Enterprise needs

    Reviewed on May 06, 2025
    Review provided by G2
    What do you like best about the product?
    PANW's NGFW(PAN-VM Series) especially powered by Prisma Access is quite a novel solution for securing workloads and connectivity needs across Branch offices, DC, CSPs and Internet endpoints. It ensures your enterprise security needs are met at scale for large user-base(your employees/your customers) through varied deployments of your app stack in todays world as business continues to evolve with their needs/deployments.
    What do you dislike about the product?
    Deployment of the appliance-software in a cloud deployment is fairly complex especially with Availability in mind given appliances are stateful in nature when compared to a managed CSP offering. Also, the costs can run pretty high based on the package selection.
    What problems is the product solving and how is that benefiting you?
    PANWs Threat detection/malware protection/IPS-IDS solution are the main feature sets customers I work with care for. This are critical feature sets for application deployment especially when they are internet exposed.
    View all reviews