Overview
VM-Series, when combined with native AWS services, enable you to create "touchless" deployments and allow your developers to operate at the speed of the cloud. VM-Series protects your applications and data using whitelisting and segmentation policies that are dynamically updated based on AWS tags, allowing you to reduce the attack surface area and achieve compliance. Additionally, threat prevention policies can stop both known and unknown attacks.
VM-Series now supports DPDK on the C5, C5n, M5, and M5n instances, running on the AWS Nitro System, to efficiently process traffic and offer increased performance. In addition, Panorama (available separately in Marketplace) allows the VM-Series to be managed centrally alongside our firewall appliances to maintain security policies that are consistent with on-premises environments.
There are three PAYG bundles available. The licenses includes are as follows: Bundle 1: VM-Series+Threat Prevention+Advanced Threat Prevention+USG (US Government) Support Bundle 2: VM-Series+Threat Prevention+Advanced Threat Prevention+URL Filtering+Advanced URL filtering+DNS Security+Global Protect+WildFire+Advanced Wildfire+USG (US Government) Support. Link: https://aws.amazon.com/marketplace/pp/prodview-wsu46li6jw3je Bundle 3: VM-Series+Advanced Threat Prevention+Advanced URL Filtering+DNS Security+Global Protect+WildFire+USG (US Government) Support. Link: https://aws.amazon.com/marketplace/pp/prodview-gfbcyenj6z75uÂ
Highlights
- An AWS Network Competency and Security Competency approved solution that complements native AWS security with real-time threat and data theft prevention
- Dynamic and large scale deployments can be protected using AWS Auto Scaling/ELB integration with AWS Transit Gateway
Details
Unlock automation with AI agent solutions

Features and programs
Buyer guide

Financing for AWS Marketplace purchases
Pricing
Free trial
Dimension | Cost/hour |
|---|---|
m5.2xlarge Recommended | $2.05 |
m5.large | $1.15 |
c5n.xlarge | $1.53 |
m5n.large | $1.15 |
m5.4xlarge | $3.83 |
c5.xlarge | $1.53 |
c5.4xlarge | $3.83 |
c5.2xlarge | $2.05 |
c5n.4xlarge | $3.83 |
c5n.2xlarge | $2.05 |
Vendor refund policy
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
64-bit (x86) Amazon Machine Image (AMI)
Amazon Machine Image (AMI)
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Additional details
Usage instructions
https://docs.paloaltonetworks.com/vm-series/10-0/vm-series-deployment/about-the-vm-series-firewall/upgrade-the-vm-series-firewall.html See documentation for detailed steps to set admin password before using the web interface of VM-Series. Once the instance is running, connect to it using a SSH client with the private key file used to launch the instance. For example: ssh -i <privatekey.pem> admin@<EIP or private IP of eth0> Then use the PAN-OS CLI commands "configure", "set mgt-config users admin password" and "commit" commands to set the password.
Support
Vendor support
To help you get started with your deployment such as how-to videos, deployment guides and reference architectures, please visit: https://live.paloaltonetworks.com/awsÂ
For post-sales support, you can use the following options: Call us at 1 (866) 898-9087 Open a case by following the steps here:
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

Standard contract
Customer reviews
Has supported urgent deployments and enabled inline threat protection but pricing and features could be more flexible
What is our primary use case?
I am not working on a NAC solution. I am working on Palo Alto Networks VM-Series firewall, and I am mainly working with firewalls.
I am totally working with Palo Alto Networks VM-Series products. I am working with VMs, including 400 series, 1400 series, and 3400 series firewalls, which are next-generation firewalls and fourth-generation firewalls of Palo Alto Networks VM-Series.
I am also working with VMs for Palo Alto Networks VM-Series, and for POCs sometimes. Mostly, I provide solutions for some of our customers who need urgent solutions with Palo Alto Networks VM-Series. I provide them VMs and activate the licenses from Palo Alto as a partner. We are working as innovator partners with Palo Alto. Sometimes for POCs and for urgent solutions, if the customer or some organization needs it, we provide them Palo Alto Networks VM-Series and it works fine.
We are working with Dynamic Address Groups in Palo Alto Networks VM-Series. Mostly, we use them for securing our network and for blocking malicious traffic from specific sources around the globe. We block them through Dynamic Address Groups as a source and create another policy for that. We block any dynamic addresses coming with malicious traffic using specific policies. We use Dynamic Address Groups and after tagging those malicious IPs, when they come to our firewall from outside or from inside, including some of our local computers, if we detect something concerning such as bots or similar traffic, we block them using Dynamic Address Groups.
Advanced Threat Protection is working in Palo Alto Networks VM-Series. In Advanced Threat Protection, we use inline protection features, including anti-malware solutions and vulnerability protection. We mostly use Advanced Threat Protection because Palo Alto provides the core subscription and core security bundle, which is cheaper than the other bundle. We propose the same bundle to customers because it is cheaper and includes DNS security, SD-WAN, vulnerability protection, URL filtering, anti-spyware, and antivirus subscriptions bundled in the same core bundle. If I buy only threat protection separately, it is more expensive than this bundle. We create security profiles for spyware and antivirus and provide inline protection to customers.
What is most valuable?
App-IDs in Palo Alto Networks VM-Series are very important and working fine. We mostly use App-IDs due to which we are securing customers who are vulnerable and who need security solutions.
There are Dynamic Address Groups, EDLs, and integration with other solutions such as Forescout for Palo Alto Networks VM-Series, which we did two years ago. There are API integrations as well. We mostly automate the security structure for the organization using SIEMÂ solutions, integration with SIEMÂ solutions, and XDRÂ solutions. This is very interesting.
What needs improvement?
I am not using Palo Alto Networks VM-Series mostly, but based on my experience, there are some deficiencies in Palo Alto Networks VM-Series. Having those features missing, we are not proposing Palo Alto Networks VM-Series to all customers. However, for urgency and for some solutions that customers need for some of their other sites and subdivisions, we are providing the same.
For how long have I used the solution?
I have been working with Palo Alto Networks VM-Series since 2020, which is approximately six to seven years back.
What do I think about the stability of the solution?
Palo Alto Networks VM-Series is very stable.
What do I think about the scalability of the solution?
Scalability for Palo Alto Networks VM-Series is eight out of ten.
How are customer service and support?
Technical support for Palo Alto Networks VM-Series is provided through premium partner support. We are working with StarLink, and they are providing the best solution and best support. We have advanced partnership and advanced support for some of our customers. They are good with technical solutions.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
Palo Alto Networks VM-Series is better than Fortinet, mainly in its SP3 structure, flexibility, and reliability, and based on feedback from customers. Most of our customers have shifted from Fortinet to Palo Alto Networks VM-Series. Their feedback indicated concerns about slowness, subscription renewals, and other aspects they were not happy with.
Which other solutions did I evaluate?
Fortinet is the main competitor for Palo Alto Networks VM-Series on the market.
What other advice do I have?
Prices of Palo Alto Networks VM-Series are higher than other firewalls and other solutions. However, we are using its security features and proposing them, mostly winning tenders with this product. Palo Alto Networks VM-Series is a very best solution if you have subscription and extra support, and I would rate this solution seven to eight out of ten. I would give this review an overall rating of eight.