Fully managed, cloud-native firewall service with threat prevention, app control and advanced URL filtering that integrates with AWS Firewall Manager, CloudWatch and more.
Cloud Next-Generation Firewall (CNGFW) for AWS delivers best-in-class network security powered by artificial intelligence and machine learning, stopping zero-day exploits faster than traditional platforms. This fully managed turnkey cloud-native firewall service with 99.99% availability removes the complexity of managing firewall infrastructure in AWS. It lets you immediately turn on the next-generation firewall features and scale your security, ensuring seamless protection for your applications in the AWS environment.
Cloud NGFW extends your threat prevention capabilities across AWS environments and seamlessly integrates with key AWS services like AWS Firewall Manager, CloudWatch, Kinesis Firehose, and more. It provides real-time insights, automated security workflows, and granular traffic control for robust network protection. Recent enhancements include Strata Cloud Manager integration for centralized visibility and firewall-as-code enhancements.
Benefits
Effortless Deployment and Zero-Operational Burden: Palo Alto Networks Cloud NGFW takes care of the complex operational tasks, allowing for seamless firewall deployment and management in AWS. It streamlines processes such as certificate management, software upgrades, patch management and multi-dimensional scaling to ensure 99.99% availability. By eliminating the challenges of managing and scaling firewalls yourself, you can deploy robust cloud protection in just a few clicks, without worrying about infrastructure management.
Advanced Threat Prevention. Secure your AWS VPC traffic from zero-day attacks and unknown command-and-control traffic using Cloud-Delivered Security Services (CDSS) powered by Precision AI as well as Unit 42 Threat Research, enabling detection and mitigation 180x faster than traditional platforms.
Real-Time Threat Detection. Protect your applications with advanced AI and ML-powered threat prevention, leveraging intelligence derived from 70,000+ global customers to stop zero-day exploits, DNS threats, and web-based threats before they impact your network. This extensive threat intelligence network continuously learns and adapts, providing unparalleled protection that evolves with the latest attack vectors.
Granular Traffic Control. Gain visibility and precise control over your network traffic based on workloads, users, and applications with patented Layer 7 classification. Reduce attack surfaces and safeguard your AWS environment from malicious traffic.
Centralized Visibility. Simplify security operations with centralized management using Strata Cloud Manager or Panorama. Gain comprehensive visibility into applications, users, and threats for more efficient security management, faster threat resolution, and optimized policy creation.
Improved Metrics & Monitoring. Leverage AWS CloudWatch to monitor NGFW health, performance, and usage patterns in real-time, ensuring your security operations run at peak efficiency.
Firewall-as-Code Enhancements. Automate your firewall deployment, policy enforcement and account management workflows with the support of APls, CloudFormation and Terraform. Eliminate manual interventions and streamline your security operations.
Cloud NGFW is the Firewall-as-a-Service. Choose either AWS Firewall Manager or Palo Alto Networks Panorama for consistent policy management across multiple AWS accounts, enabling flexible control and seamless security across your cloud environments.
Activate your 30-Day free trial and create up to two next-generation firewall resources on your existing AWS VPCs, securing up to 100GB of traffic. After the free trial, you'll transition to a pay-as-you-go model, and you can check your subscription status on the Subscription Management page.
Highlights
Deploy your next-generation firewall with one-click, automated provisioning that auto-scales to match your network traffic. Leverage Palo Alto Networks Panorama or Strata Cloud Manager for unified security management, ensuring you maintain control and visibility across your cloud infrastructure without the complexity of managing infrastructure.
Integrate seamlessly with AWS-native services like CloudWatch, Kinesis Firehose, and AWS Firewall Manager, providing real-time insights, granular traffic control, and enhanced security capabilities. Backed by Palo Alto Networks Unit 42 Threat Research, the service delivers cutting-edge threat prevention and faster mitigation of zero-day exploits.
Cloud NGFW supports automated onboarding of AWS environments and workflow automation through APIs, CloudFormation, and Terraform, enabling quick deployment and consistent operations. Gain comprehensive visibility and management across multiple AWS accounts with centralized security operations using Strata Cloud Manager or Panorama.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
You pay only for what you use, with no upfront commitment. Your bill combines separate charges. A firewall charge is based on usage hours; the base covers three availability zones, and each extra zone adds a fraction of an hour per hour. A traffic charge applies per gigabyte inspected, tiered by monthly volume: the first 15 TB, the next 15 TB, and anything above 30 TB. Optional add-ons draw on Cloud NGFW Credits. The trial runs 30 days, then converts to this pay-as-you-go billing. Charges scale with your actual deployment size and traffic.
Top-of-mind questions for buyers
What does one firewall usage-hour cover, and how do extra availability zones change it?
One unit equals one hour of running the base firewall service across three availability zones. Each additional availability zone adds 0.33 unit per hour on top of the base. So a fourth zone raises your hourly rate proportionally. Charges accrue only while the firewall runs.
How is traffic billed once I cross a volume tier during a month?
Traffic is metered per gigabyte inspected and grouped into monthly tiers. The first 15 TB bills at one rate, the next 15 TB at another, and volume above 30 TB at a third. Only the gigabytes within each band bill at that band's rate, not your whole volume.
Which charge drives my bill — firewall hours or traffic inspected?
Both bill independently and add together on one invoice. Firewall hours scale with how many zones run and for how long. Traffic charges scale with gigabytes inspected each month. High-throughput deployments tend to see traffic charges dominate; low-traffic always-on setups lean toward the hourly firewall charge. Add-ons draw separately from Cloud NGFW Credits.
www.paloaltonetworks.com
Helpful?
Vendor refund policy
We do not currently support refunds, but you can cancel at any time.
Request a private offer to receive a custom quote.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Artificial intelligence and machine learning-powered threat prevention leveraging Precision AI and Unit 42 Threat Research to detect and mitigate zero-day exploits 180x faster than traditional platforms.
Layer 7 Application Classification and Control
Patented Layer 7 classification enabling granular traffic control based on workloads, users, and applications with precise visibility and malicious traffic filtering.
Cloud-Delivered Security Services Integration
Cloud-Delivered Security Services (CDSS) powered by threat intelligence from 70,000+ global customers providing real-time detection of zero-day exploits, DNS threats, and web-based threats.
Infrastructure as Code and Automation Support
Support for automated deployment and policy management through APIs, CloudFormation, and Terraform enabling firewall-as-code workflows and infrastructure automation.
AWS Native Service Integration
Seamless integration with AWS services including AWS Firewall Manager, CloudWatch, Kinesis Firehose, and Strata Cloud Manager for centralized management and real-time monitoring.
Intrusion Prevention System
Leading Intrusion Prevention System (IPS) integrated into unified security solution for threat detection and prevention
Advanced Evasion Technique Detection
Capability to identify and stop Advanced Evasion Techniques (AETs) with superior performance compared to other security devices
Application Layer Security
Advanced application control with application layer exfiltration security and dynamic security controls
Sandboxing and Malware Analysis
Sandboxing technology for identifying zero-day attacks and advanced malware threats
Centralized Management Console
Unified management console for streamlined security administration across data center, office, and branch firewalls
Advanced Threat Prevention Capabilities
Includes firewall, Data Loss Prevention (DLP), Intrusion Prevention System (IPS), application control, IPsec VPN, URL filtering, antivirus, and anti-bot features for multi-layered network security.
Traffic Inspection and Control
Inspects and controls encrypted data flows between on-premises networks and AWS VPCs, including North-South traffic entering and exiting private subnets and East-West traffic between VPCs.
Infrastructure-as-Code Integration
Integrates with infrastructure-as-code tools including Terraform and Ansible for policy automation, with dynamic security policy adaptation based on real-time cloud metadata.
Provides unified, centralized management through Check Point Security Management Server with consistent policy, logging, and reporting across AWS, hybrid, and on-premises environments.
I like the combination of enterprise-grade security and ease of management. Cloud NGFW provides strong threat prevention and application visibility while automatically scaling with cloud workloads, reducing the operational effort required to manage traditional firewall infrastructure.
What do you dislike about the product?
Nothing really I'm impressed with most of the services.
What problems is the product solving and how is that benefiting you?
It helps solve the complexity of securing cloud workloads while keeping security management simple. The improved visibility, threat prevention, segmentation, and automatic scalability help reduce operational workload and allow IT teams to focus more on supporting the business rather than managing firewall infrastructure.
Banking
Enterprise Security Without the Overhead, but Mind the Scale and Hidden Costs
Reviewed on Sep 07, 2026
Review provided by G2
What do you like best about the product?
Palo Alto Networks Cloud NGFW brings enterprise-grade Layer 7 inspection directly into public cloud environments (such as AWS and Azure) as a fully managed, cloud-native service. Zero Infrastructure Overhead: Unlike traditional VM-Series virtual appliances that require manual provisioning, HA pairing, routing tables, and lifecycle patching, Cloud NGFW operates as a managed service. Palo Alto Networks handles availability, autoscaling, and underlying OS maintenance. True Layer 7 Inspection via App-ID: Standard cloud-native firewalls primarily filter on basic L3/L4 tuples (IP addresses, ports, and protocols). Cloud NGFW applies Palo Alto's App-ID engine to identify applications regardless of port, evasion technique, or encryption. Cloud-Delivered Security Services (CDSS): It integrates the full threat prevention stack directly into traffic inspection pipelines—including Advanced Threat Prevention (IPS), Advanced URL Filtering, DNS Security, and WildFire for zero-day malware analysis. Native Cloud Integration: It connects seamlessly with cloud routing constructs (such as AWS Gateway Load Balancer and Azure Virtual WAN), allowing centralized routing and automated deployment via cloud orchestration templates (Terraform, CloudFormation). Unified Policy Management: Policies can be orchestrated either through native cloud consoles (like AWS Firewall Manager) or centralized via Panorama / Strata Cloud Manager, ensuring consistent rule enforcement across on-prem data centers and multi-cloud VPCs/VNets.
What do you dislike about the product?
While Cloud NGFW eliminates appliance lifecycle overhead, trading off the full PAN-OS appliance model for a managed service introduces several distinct operational and technical drawbacks: High and Unpredictable Cost at Scale: Pricing combines an hourly firewall consumption fee with per-gigabyte data processing charges. For high-throughput environments (e.g., heavy East-West inspection between VPCs or massive backup transfers), data transfer billing escalates rapidly compared to fixed, BYOL software licensing for VM-Series appliances. Feature Stripping Compared to Full PAN-OS: Cloud NGFW is purpose-built strictly for inline traffic filtering. It strips out core edge firewall features you get on VM-Series or hardware firewalls: No GlobalProtect / Remote Access VPN: You cannot use it as a termination point for client VPN connections. No Native Site-to-Site IPsec/BGP Routing: Advanced routing topologies, policy-based forwarding (PBF), and custom IPsec tunnel configurations must be offloaded to cloud-native gateways (e.g., AWS Transit Gateway, Azure VPN Gateway). Limited SSL/TLS Decryption Flexibility: Inbound and outbound TLS inspection can be significantly more rigid and cumbersome to configure compared to PAN-OS forward proxy implementations. Loss of Deep Granular Control & Troubleshooting: Because the underlying data plane is an abstracted, managed black box, you lose root-level visibility. There is no PAN-OS CLI access to run debug datapath, check session tables in real-time, tweak auto-scaling thresholds manually, or capture raw packet dumps on specific dataplane interfaces. Logging Latency and Cloud Fragmentation: Cloud NGFW does not stream directly to Panorama's local log collector with sub-second immediacy. Logs are pushed out via cloud-native logging (such as Amazon CloudWatch/S3 or Azure Log Analytics/Kusto). This introduces ingest latency (often several minutes) and requires distinct query languages (KQL, CloudWatch Insights) for real-time security troubleshooting. Ecosystem and Feature Parity Gaps: Updates, newly released App-IDs, and advanced policy parameters often roll out to PAN-OS first before finding full parity inside the Cloud NGFW service schema.
What problems is the product solving and how is that benefiting you?
Cloud NGFW addresses the core operational friction points created when trying to enforce enterprise-grade security inside public cloud environments. It bridges the gap between basic cloud-native firewalls (which lack deep security capabilities) and virtual appliances like VM-Series (which introduce heavy engineering overhead). Core Problems Solved The Virtual Appliance Maintenance Burden: Deploying VM-based firewalls requires managing OS patching, dynamic signature updates, high-availability (HA) health checks, and complex auto-scaling scripts across multiple Availability Zones. Cloud NGFW removes all underlying compute management by delivering firewall inspection as an elastic, cloud-managed service. Shallow Cloud-Native Security (L3/L4 Blind Spots): Native cloud security controls (such as standard AWS Network Firewall or Azure Firewall) often struggle with sophisticated Layer 7 evasion, non-standard application ports, and granular content inspection. Cloud NGFW solves this by embedding Palo Alto’s App-ID engine, Advanced Threat Prevention (IPS), WildFire, and DNS Security natively into cloud traffic flows. Policy Fragmentation Between Cloud and On-Premises: Securing hybrid estates often forces teams to manage separate rule sets in cloud consoles and on-prem hardware. Cloud NGFW integrates directly with Panorama and Strata Cloud Manager, allowing teams to enforce uniform security policies across physical data centers and cloud VPCs/VNets from one pane of glass. Complex Network Plumbing and Scaling: Building multi-AZ inspection topologies with Gateway Load Balancers (GWLB) or Virtual WAN routing can require complex custom automation. Cloud NGFW is purpose-built to attach natively to cloud routing constructs, auto-scaling up and down dynamically with traffic volume without manual capacity planning. How That Benefits You Operational Area Without Cloud NGFW With Cloud NGFW Day-2 Operations Hours spent patching PAN-OS versions, fixing HA split-brains, and testing update rollbacks. Near-zero maintenance: Palo Alto and the cloud provider handle the underlying infrastructure, lifecycle, and availability. Capacity Planning Over-provisioning VM sizes to handle traffic spikes, or writing custom auto-scaling orchestration. Elastic throughput: Scales seamlessly with workload demands via managed integrations (e.g., AWS GWLB, Azure vWAN). Rule Governance Translating compliance and security baselines into disparate cloud security group/firewall formats. Centralized control: Manage rules alongside existing Palo Alto firewalls via Panorama or directly through cloud-native APIs/Terraform. Threat Visibility IP/Port-only logs that require correlating external tools to identify actual malware or command-and-control (C2) activity. Deep application inspection: Immediate App-ID, malicious URL, and DNS-layer blocking inline before traffic leaves or traverses your subnets. If your team is already invested in the Palo Alto Networks ecosystem, Cloud NGFW provides a path to maintain identical security postures and compliance across the cloud without having to operate a virtual data center fleet of firewalls.
Mahmoud T.
Seamless Cloud-Native Security with Centralized Panorama Management
Reviewed on Sep 07, 2026
Review provided by G2
What do you like best about the product?
Palo Alto Networks Cloud NGFW is its seamless cloud-native integration combined with enterprise-grade security. It delivers Palo Alto’s best-in-class Layer 7 threat protection and App-ID capabilities without the operational complexity of managing firewall infrastructure. The ability to manage security policies centrally via Panorama ensures consistent policy enforcement across hybrid environments. Additionally, its automated scaling and zero-overhead maintenance allow us to secure cloud workloads efficiently while keeping management simple.
What do you dislike about the product?
The main drawbacks are the high cost structure—especially data processing charges—and higher complexity when integrating with Panorama for hybrid setups. It also offers slightly less granular customization compared to traditional PA-Series VM Firewalls, and multi-cloud support can still be somewhat limited depending on the provider.
What problems is the product solving and how is that benefiting you?
It solves the operational headache of manually deploying, patching, and scaling firewall VMs, while providing much deeper L7 security than basic cloud-native tools. Benefits: It saves significant operational time, allows unified policy management across hybrid networks via Panorama, and scales automatically with our traffic without requiring manual infrastructure work.
Information Technology and Services
Amazing UI and Seamless Integration with Powerful AI Features
Reviewed on Sep 03, 2026
Review provided by G2
What do you like best about the product?
the experience was amazing , UI and interface is very good and suitable , integration between components is very seamless , performance is significant , value for money is very good , support is very strong and AI features is very powerful
What do you dislike about the product?
over all experiences was very good , I cannot see bad things in the experience
What problems is the product solving and how is that benefiting you?
Ready to use:
> Palo Alto Networks Cloud NGFW has helped us address the challenge of securing fast-changing cloud workloads without the operational overhead of deploying, scaling, and maintaining traditional firewall appliances. It gives us consistent Layer 7 security and threat prevention for inbound, outbound, and east-west traffic, helping reduce exposure to malware, exploits, command-and-control traffic, and data exfiltration. > > The biggest benefit is operational simplicity. We can apply standardized policies across cloud accounts and VPCs, automate deployments through infrastructure-as-code workflows, and scale protection with demand. This has reduced manual firewall administration, accelerated secure application deployments, improved visibility, and helped us maintain a more consistent security posture across our cloud environment.
Bhushan B.
Strong Security and Easy Development Experience
Reviewed on Sep 03, 2026
Review provided by G2
What do you like best about the product?
Strong security and very easy development
What do you dislike about the product?
The initial configuration is somewhat complex and requires a steep learning curve
What problems is the product solving and how is that benefiting you?
It helps us maintain consistent security policies across our multi-cloud environment. As a result, it significantly reduces the time our team spends on manual configuration and lowers our overall risk of a breach.