Listing Thumbnail

    Cloud Next-Generation Firewall as a Service (30-Day Free Trial to PAYG)

     Info
    Free Trial
    Vendor Insights
    Quick Launch
    Fully managed, cloud-native firewall service with threat prevention, app control and advanced URL filtering that integrates with AWS Firewall Manager, CloudWatch and more.
    Listing Thumbnail

    Cloud Next-Generation Firewall as a Service (30-Day Free Trial to PAYG)

     Info

    Overview

    Play video

    Product Overview

    Cloud Next-Generation Firewall (CNGFW) for AWS delivers best-in-class network security powered by artificial intelligence and machine learning, stopping zero-day exploits faster than traditional platforms. This fully managed turnkey cloud-native firewall service with 99.99% availability removes the complexity of managing firewall infrastructure in AWS. It lets you immediately turn on the next-generation firewall features and scale your security, ensuring seamless protection for your applications in the AWS environment.

    Cloud NGFW extends your threat prevention capabilities across AWS environments and seamlessly integrates with key AWS services like AWS Firewall Manager, CloudWatch, Kinesis Firehose, and more. It provides real-time insights, automated security workflows, and granular traffic control for robust network protection. Recent enhancements include Strata Cloud Manager integration for centralized visibility and firewall-as-code enhancements.

    Benefits

    • Effortless Deployment and Zero-Operational Burden: Palo Alto Networks Cloud NGFW takes care of the complex operational tasks, allowing for seamless firewall deployment and management in AWS. It streamlines processes such as certificate management, software upgrades, patch management and multi-dimensional scaling to ensure 99.99% availability. By eliminating the challenges of managing and scaling firewalls yourself, you can deploy robust cloud protection in just a few clicks, without worrying about infrastructure management.

    • Advanced Threat Prevention. Secure your AWS VPC traffic from zero-day attacks and unknown command-and-control traffic using Cloud-Delivered Security Services (CDSS) powered by Precision AI as well as Unit 42 Threat Research, enabling detection and mitigation 180x faster than traditional platforms.

    • Real-Time Threat Detection. Protect your applications with advanced AI and ML-powered threat prevention, leveraging intelligence derived from 70,000+ global customers to stop zero-day exploits, DNS threats, and web-based threats before they impact your network. This extensive threat intelligence network continuously learns and adapts, providing unparalleled protection that evolves with the latest attack vectors.

    • Granular Traffic Control. Gain visibility and precise control over your network traffic based on workloads, users, and applications with patented Layer 7 classification. Reduce attack surfaces and safeguard your AWS environment from malicious traffic.

    • Centralized Visibility. Simplify security operations with centralized management using Strata Cloud Manager or Panorama. Gain comprehensive visibility into applications, users, and threats for more efficient security management, faster threat resolution, and optimized policy creation.

    • Improved Metrics & Monitoring. Leverage AWS CloudWatch to monitor NGFW health, performance, and usage patterns in real-time, ensuring your security operations run at peak efficiency.

    • Firewall-as-Code Enhancements. Automate your firewall deployment, policy enforcement and account management workflows with the support of APls, CloudFormation and Terraform. Eliminate manual interventions and streamline your security operations.

    • Cloud NGFW is the Firewall-as-a-Service. Choose either AWS Firewall Manager or Palo Alto Networks Panorama for consistent policy management across multiple AWS accounts, enabling flexible control and seamless security across your cloud environments.

    Activate your 30-Day free trial and create up to two next-generation firewall resources on your existing AWS VPCs, securing up to 100GB of traffic. After the free trial, you'll transition to a pay-as-you-go model, and you can check your subscription status on the Subscription Management page.

    Highlights

    • Deploy your next-generation firewall with one-click, automated provisioning that auto-scales to match your network traffic. Leverage Palo Alto Networks Panorama or Strata Cloud Manager for unified security management, ensuring you maintain control and visibility across your cloud infrastructure without the complexity of managing infrastructure.
    • Integrate seamlessly with AWS-native services like CloudWatch, Kinesis Firehose, and AWS Firewall Manager, providing real-time insights, granular traffic control, and enhanced security capabilities. Backed by Palo Alto Networks Unit 42 Threat Research, the service delivers cutting-edge threat prevention and faster mitigation of zero-day exploits.
    • Cloud NGFW supports automated onboarding of AWS environments and workflow automation through APIs, CloudFormation, and Terraform, enabling quick deployment and consistent operations. Gain comprehensive visibility and management across multiple AWS accounts with centralized security operations using Strata Cloud Manager or Panorama.

    Details

    Delivery method

    Features and programs

    Vendor Insights

     Info
    Skip the manual risk assessment. Get verified and regularly updated security info on this product with Vendor Insights.
    Security credentials achieved
    (2)

    Buyer guide

    Gain valuable insights from real users who purchased this product, powered by PeerSpot.
    Buyer guide

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Quick Launch

    Leverage AWS CloudFormation templates to reduce the time and resources required to configure, deploy, and launch your software.

    Pricing

    Free trial

    Try this product free according to the free trial terms set by the vendor. Usage-based pricing is in effect for usage beyond the free trial terms. Your free trial gets automatically converted to a paid subscription when the trial ends, but may be canceled any time before that.

    Cloud Next-Generation Firewall as a Service (30-Day Free Trial to PAYG)

     Info
    Pricing is based on actual usage, with charges varying according to how much you consume. Subscriptions have no end date and may be canceled any time.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    Usage costs (5)

     Info
    Dimension
    Cost/unit
    Base NGFW - incl. 3 AZs (1unit=1 usage hour), addt'l AZ 0.33 unit/hr
    $1.50
    Traffic Secured - First 15 TB / month (1 unit = 1 GB)
    $0.065
    Traffic Secured - Next 15 TB / month (1 unit = 1 GB)
    $0.045
    Traffic Secured - Above 30 TB / month (1 unit = 1 GB)
    $0.03
    Add-Ons (1 unit = 1 Cloud NGFW Credit) (refer to page bit.ly/cngfwaws)
    $0.012

    Vendor refund policy

    We do not currently support refunds, but you can cancel at any time.

    Custom pricing options

    Request a private offer to receive a custom quote.

    How can we make this page better?

    We'd like to hear your feedback and ideas on how to improve this page.
    We'd like to hear your feedback and ideas on how to improve this page.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Resources

    Vendor resources

    Support

    Vendor support

    "Premium support is now included with the product: http://www.paloaltonetworks.com/resources/datasheets/premium-support . To help you get started with your deployment such as how-to videos, deployment guides and reference architectures, please visit: http://live.paloaltonetworks.com/t5/cloud-ngfw-help-center/ct-p/Cloud_NGFW . For post-sales support, you can use the following options: 1) Open a case by following the steps here: http://www.paloaltonetworks.com/services/support/customer-support-plan . 2) Call us at 1 (866) 898-9087"

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by HAQM Web Services.

    Product comparison

     Info
    Updated weekly

    Accolades

     Info
    Top
    10
    In Network Infrastructure, Security
    Top
    25
    In Data Governance

    Customer reviews

     Info
    AI generated sentiment from actual customer reviews on AWS and G2
    Reviews
    Functionality
    Ease of use
    Customer service
    Cost effectiveness
    15 reviews
    Insufficient data
    21 reviews
    Insufficient data
    Positive reviews
    Mixed reviews
    Negative reviews

    Overview

     Info
    AI generated from product descriptions
    Threat Prevention
    Advanced AI and machine learning-powered threat detection leveraging intelligence from global customer network to stop zero-day exploits and unknown command-and-control traffic
    Network Traffic Classification
    Patented Layer 7 classification for granular traffic control based on workloads, users, and applications with precise network traffic visibility
    Cloud Service Integration
    Native integration with AWS services including Firewall Manager, CloudWatch, Kinesis Firehose for comprehensive security management and monitoring
    Infrastructure Automation
    Support for infrastructure-as-code deployment using APIs, CloudFormation, and Terraform for automated firewall provisioning and policy enforcement
    Security Intelligence
    Cloud-delivered security services powered by Precision AI and Unit 42 Threat Research for real-time threat detection and mitigation
    Network Security Capabilities
    Next-generation firewall with intrusion prevention, application control, content filtering powered by AI-driven FortiGuard Labs technology
    Cloud Integration
    Seamless integration with AWS services including AWS Gateway Load Balancer and AWS Firewall Manager
    Scalability Architecture
    Single instance capable of protecting up to 1000 subnets across multiple VPCs, subnets, and availability zones in an AWS region
    Security Policy Management
    Comprehensive console with purpose-built wizards for associating AWS accounts, creating firewall instances, defining protected objects, and managing security policies
    Multi-Platform Policy Synchronization
    Supports policy definition and synchronization across AWS Firewall Manager and FortiManager platforms
    Cloud Infrastructure Monitoring
    Continually monitor public cloud infrastructure across AWS, Azure, and GCP environments to provide comprehensive visibility of resources and potential threats
    Vulnerability Detection
    Identify infrastructure vulnerabilities impacting security and compliance best practice standards with risk profiling and contextual alerts
    Multi-Cloud Asset Management
    Achieve a complete picture of cloud assets across multi-cloud environments, monitoring configurations, deployments, and access anomalies
    Security Configuration Analysis
    Detect insecure configurations, over-privileged IAM roles, and compliance failures from development through live service stages
    API Integration Capabilities
    Provide programmatic access to security features via REST API for seamless integration with third-party SIEM and DevOps tools

    Security credentials

     Info
    Validated by AWS Marketplace
    FedRAMP
    GDPR
    HIPAA
    ISO/IEC 27001
    PCI DSS
    SOC 2 Type 2
    -
    -
    -
    -
    -
    No security profile
    No security profile

    Contract

     Info
    Standard contract
    No
    No
    No

    Customer reviews

    Ratings and reviews

     Info
    0 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    0%
    0%
    0%
    0%
    0%
    0 AWS reviews
    |
    93 external reviews
    External reviews are sourced from G2  and are not included in the star rating for this product.
    Albert L.

    as network engineer

    Reviewed on Apr 19, 2025
    Review provided by G2
    What do you like best about the product?
    I love how easy Palo Alto’s Cloud NGFW is to set up and manage. It’s super reliable, offers strong security, and integrates perfectly with AWS. Total peace of mind
    What do you dislike about the product?
    It’s powerful, but the pricing can be high for smaller teams. Also, the learning curve is a bit steep if you're new to Palo Alto’s ecosystem. In general is the best.
    What problems is the product solving and how is that benefiting you?
    It blocks threats before they reach our cloud apps, gives deep visibility, and saves us tons of time on security management. Way fewer incidents and stress now.
    Computer & Network Security

    From an analysis perspective, pretty nice.

    Reviewed on Apr 15, 2025
    Review provided by G2
    What do you like best about the product?
    The logs are easily malleable and provide you with how little or how much info you need on an event.
    As far as implementation goes, it's pretty straightforward.
    What do you dislike about the product?
    Even though the setup is mostly straightforward, it can get a little tricky when you're working with more complex cloud environments or trying to line things up with existing on-prem policies.
    What problems is the product solving and how is that benefiting you?
    One major issue was maintaining consistent security policies across both our on-prem and cloud environments. With Cloud NGFW, we’re able to apply the same level of visibility and control in AWS (or Azure) as we have on-prem, which makes our hybrid architecture way more manageable and secure.
    Naveen sai M.

    Rock-solid cloud firewall with excellent visibility and control

    Reviewed on Apr 09, 2025
    Review provided by G2
    What do you like best about the product?
    The best part about using Palo Alto’s Cloud NGFW is the level of visibility and granular control it gives over network traffic — especially in cloud-native environments.
    What do you dislike about the product?
    Pricing can be a bit on the higher side, especially for smaller teams or early-stage projects.The initial ramp up is bit of learning curve. We need to get trained before we start using this.
    What problems is the product solving and how is that benefiting you?
    Palo Alto’s Cloud NGFW is helping us secure cloud workloads across different environments without needing to rely on multiple tools or complex custom configurations. It significantly reduced the time we spend managing firewall rules and security policies, especially in dynamic cloud setups
    Bharath V.

    Palo Alto NGFW

    Reviewed on Mar 07, 2025
    Review provided by G2
    What do you like best about the product?
    PA next gen cloud firewalls deep threat detection integration gives a great security backbone for any network infrastructure. Their AI threat detection is a game changer
    What do you dislike about the product?
    Palo alto being a huge company, it comes with alot of visibility in the market and constant vulnerabilities. Regular patching and sometimes more intrusive patching which could put production networks at risk
    What problems is the product solving and how is that benefiting you?
    As the world is moving towards as a service platforms cloud firewall as a service be Ill really important and needed for the current hybrid environments
    Retail

    Quite happy with the solution

    Reviewed on Mar 07, 2025
    Review provided by G2
    What do you like best about the product?
    It really helped my on my day to day work to make my threat hunting streameless. Real time visibility is a great asset! We were quite happy with Palo Alto compared with our previous solution.
    What do you dislike about the product?
    Getting used to the GUI might take some time and the documentation doesn't help much but once you get used to that, everything works quite fine. So that's not a big deal
    What problems is the product solving and how is that benefiting you?
    It helped us to detect and successfully stop lateral movement attacks and data exfiltration attempts.It saved a lot of time with the automated corelation of events.
    View all reviews