Listing Thumbnail

    Cloud Next-Generation Firewall as a Service (30-Day Free Trial to PAYG)

     Info
    Deployed on AWS
    Quick Launch
    Fully managed, cloud-native firewall service with threat prevention, app control and advanced URL filtering that integrates with AWS Firewall Manager, CloudWatch and more.
    4.3

    Overview

    Play video

    Product Overview

    Cloud Next-Generation Firewall (CNGFW) for AWS delivers best-in-class network security powered by artificial intelligence and machine learning, stopping zero-day exploits faster than traditional platforms. This fully managed turnkey cloud-native firewall service with 99.99% availability removes the complexity of managing firewall infrastructure in AWS. It lets you immediately turn on the next-generation firewall features and scale your security, ensuring seamless protection for your applications in the AWS environment.

    Cloud NGFW extends your threat prevention capabilities across AWS environments and seamlessly integrates with key AWS services like AWS Firewall Manager, CloudWatch, Kinesis Firehose, and more. It provides real-time insights, automated security workflows, and granular traffic control for robust network protection. Recent enhancements include Strata Cloud Manager integration for centralized visibility and firewall-as-code enhancements.

    Benefits

    • Effortless Deployment and Zero-Operational Burden: Palo Alto Networks Cloud NGFW takes care of the complex operational tasks, allowing for seamless firewall deployment and management in AWS. It streamlines processes such as certificate management, software upgrades, patch management and multi-dimensional scaling to ensure 99.99% availability. By eliminating the challenges of managing and scaling firewalls yourself, you can deploy robust cloud protection in just a few clicks, without worrying about infrastructure management.

    • Advanced Threat Prevention. Secure your AWS VPC traffic from zero-day attacks and unknown command-and-control traffic using Cloud-Delivered Security Services (CDSS) powered by Precision AI as well as Unit 42 Threat Research, enabling detection and mitigation 180x faster than traditional platforms.

    • Real-Time Threat Detection. Protect your applications with advanced AI and ML-powered threat prevention, leveraging intelligence derived from 70,000+ global customers to stop zero-day exploits, DNS threats, and web-based threats before they impact your network. This extensive threat intelligence network continuously learns and adapts, providing unparalleled protection that evolves with the latest attack vectors.

    • Granular Traffic Control. Gain visibility and precise control over your network traffic based on workloads, users, and applications with patented Layer 7 classification. Reduce attack surfaces and safeguard your AWS environment from malicious traffic.

    • Centralized Visibility. Simplify security operations with centralized management using Strata Cloud Manager or Panorama. Gain comprehensive visibility into applications, users, and threats for more efficient security management, faster threat resolution, and optimized policy creation.

    • Improved Metrics & Monitoring. Leverage AWS CloudWatch to monitor NGFW health, performance, and usage patterns in real-time, ensuring your security operations run at peak efficiency.

    • Firewall-as-Code Enhancements. Automate your firewall deployment, policy enforcement and account management workflows with the support of APls, CloudFormation and Terraform. Eliminate manual interventions and streamline your security operations.

    • Cloud NGFW is the Firewall-as-a-Service. Choose either AWS Firewall Manager or Palo Alto Networks Panorama for consistent policy management across multiple AWS accounts, enabling flexible control and seamless security across your cloud environments.

    Activate your 30-Day free trial and create up to two next-generation firewall resources on your existing AWS VPCs, securing up to 100GB of traffic. After the free trial, you'll transition to a pay-as-you-go model, and you can check your subscription status on the Subscription Management page.

    Highlights

    • Deploy your next-generation firewall with one-click, automated provisioning that auto-scales to match your network traffic. Leverage Palo Alto Networks Panorama or Strata Cloud Manager for unified security management, ensuring you maintain control and visibility across your cloud infrastructure without the complexity of managing infrastructure.
    • Integrate seamlessly with AWS-native services like CloudWatch, Kinesis Firehose, and AWS Firewall Manager, providing real-time insights, granular traffic control, and enhanced security capabilities. Backed by Palo Alto Networks Unit 42 Threat Research, the service delivers cutting-edge threat prevention and faster mitigation of zero-day exploits.
    • Cloud NGFW supports automated onboarding of AWS environments and workflow automation through APIs, CloudFormation, and Terraform, enabling quick deployment and consistent operations. Gain comprehensive visibility and management across multiple AWS accounts with centralized security operations using Strata Cloud Manager or Panorama.

    Details

    Delivery method

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Buyer guide

    Gain valuable insights from real users who purchased this product, powered by PeerSpot.
    Buyer guide

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Quick Launch

    Leverage AWS CloudFormation templates to reduce the time and resources required to configure, deploy, and launch your software.

    Pricing

    Cloud Next-Generation Firewall as a Service (30-Day Free Trial to PAYG)

     Info
    Pricing is based on actual usage, with charges varying according to how much you consume. Subscriptions have no end date and may be canceled any time.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    Usage costs (5)

     Info
    Dimension
    Cost/unit
    Base NGFW - incl. 3 AZs (1unit=1 usage hour), addt'l AZ 0.33 unit/hr
    $1.50
    Traffic Secured - First 15 TB / month (1 unit = 1 GB)
    $0.065
    Traffic Secured - Next 15 TB / month (1 unit = 1 GB)
    $0.045
    Traffic Secured - Above 30 TB / month (1 unit = 1 GB)
    $0.03
    Add-Ons (1 unit = 1 Cloud NGFW Credit) (refer to page bit.ly/cngfwaws)
    $0.012

    AI Insights

     Info

    Dimensions summary

    You pay only for what you use, with no upfront commitment. Your bill combines separate charges. A firewall charge is based on usage hours; the base covers three availability zones, and each extra zone adds a fraction of an hour per hour. A traffic charge applies per gigabyte inspected, tiered by monthly volume: the first 15 TB, the next 15 TB, and anything above 30 TB. Optional add-ons draw on Cloud NGFW Credits. The trial runs 30 days, then converts to this pay-as-you-go billing. Charges scale with your actual deployment size and traffic.

    Top-of-mind questions for buyers

    One unit equals one hour of running the base firewall service across three availability zones. Each additional availability zone adds 0.33 unit per hour on top of the base. So a fourth zone raises your hourly rate proportionally. Charges accrue only while the firewall runs.
    Traffic is metered per gigabyte inspected and grouped into monthly tiers. The first 15 TB bills at one rate, the next 15 TB at another, and volume above 30 TB at a third. Only the gigabytes within each band bill at that band's rate, not your whole volume.
    Both bill independently and add together on one invoice. Firewall hours scale with how many zones run and for how long. Traffic charges scale with gigabytes inspected each month. High-throughput deployments tend to see traffic charges dominate; low-traffic always-on setups lean toward the hourly firewall charge. Add-ons draw separately from Cloud NGFW Credits.
    www.paloaltonetworks.com
    Helpful?

    Vendor refund policy

    We do not currently support refunds, but you can cancel at any time.

    Custom pricing options

    Request a private offer to receive a custom quote.

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Resources

    Vendor resources

    Support

    Vendor support

    "Premium support is now included with the product: https://www.paloaltonetworks.com/resources/datasheets/premium-support . To help you get started with your deployment such as how-to videos, deployment guides and reference architectures, please visit: https://live.paloaltonetworks.com/t5/cloud-ngfw-help-center/ct-p/Cloud_NGFW . For post-sales support, you can use the following options: 1) Open a case by following the steps here: https://www.paloaltonetworks.com/services/support/customer-support-plan . 2) Call us at 1 (866) 898-9087"

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Product comparison

     Info
    Updated weekly

    Accolades

     Info
    Top
    10
    In Network Infrastructure
    Top
    10
    In Log Analysis, Network Infrastructure

    Customer reviews

     Info
    Sentiment is AI generated from actual customer reviews on AWS and G2
    Reviews
    Functionality
    Ease of use
    Customer service
    Cost effectiveness
    Positive reviews
    Mixed reviews
    Negative reviews

    Overview

     Info
    AI generated from product descriptions
    AI and Machine Learning-Powered Threat Prevention
    Artificial intelligence and machine learning-powered threat prevention leveraging intelligence from 70,000+ global customers to detect and mitigate zero-day exploits, DNS threats, and web-based threats 180x faster than traditional platforms.
    Layer 7 Application Classification and Control
    Patented Layer 7 classification enabling granular traffic control and visibility based on workloads, users, and applications with precise network traffic management.
    Cloud-Delivered Security Services
    Cloud-Delivered Security Services (CDSS) powered by Precision AI and Unit 42 Threat Research for advanced threat prevention and detection of zero-day attacks and unknown command-and-control traffic.
    Infrastructure as Code and Automation
    Support for automated deployment, policy enforcement, and account management workflows through APIs, CloudFormation, and Terraform integration.
    AWS Native Service Integration
    Seamless integration with AWS services including AWS Firewall Manager, CloudWatch, Kinesis Firehose, and Strata Cloud Manager for centralized management and real-time monitoring.
    Intrusion Prevention System
    Leading Intrusion Prevention System (IPS) integrated into unified security solution for threat detection and prevention
    Advanced Evasion Technique Detection
    Capability to identify and stop Advanced Evasion Techniques (AETs) with superior performance compared to other security devices
    Application Layer Security
    Advanced application control with application layer exfiltration security and dynamic security controls
    Sandboxing and Malware Analysis
    Sandboxing technology for identifying zero-day attacks and advanced malware threats
    Centralized Management Console
    Unified management console for streamlined security administration across data center, office, and branch firewalls
    Advanced Threat Prevention Capabilities
    Includes firewall, Data Loss Prevention (DLP), Intrusion Prevention System (IPS), application control, IPsec VPN, URL filtering, antivirus, and anti-bot features for multi-layered network security.
    Traffic Inspection and Control
    Inspects and controls encrypted data flows between on-premises networks and AWS VPCs, including North-South traffic entering and exiting private subnets and East-West traffic between VPCs.
    Infrastructure-as-Code Integration
    Integrates with infrastructure-as-code tools including Terraform and Ansible for policy automation, with dynamic security policy adaptation based on real-time cloud metadata.
    AWS Service Integration
    Supports integration with Gateway Load Balancer, AWS Security Hub, VPC Ingress Routing, AWS Traffic Mirroring, AWS Transit Gateway, AWS Outposts, and Amazon Macie.
    Centralized Security Management
    Provides unified, centralized management through Check Point Security Management Server with consistent policy, logging, and reporting across AWS, hybrid, and on-premises environments.

    Contract

     Info
    Standard contract
    No
    No
    No

    Customer reviews

    Ratings and reviews

     Info
    4.3
    180 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    53%
    41%
    5%
    1%
    0%
    12 AWS reviews
    |
    168 external reviews
    External reviews are from G2  and PeerSpot .
    Computer Networking

    Effortless Cloud Integration and Massive Time Savings

    Reviewed on Aug 14, 2026
    Review provided by G2
    What do you like best about the product?
    effortlessly it integrates directly into our existing cloud setup. Instead of wasting time on complex network routing or custom workarounds, it plugs right into our cloud provider's native infrastructure and management tools. This seamless integration saves our team several hours each week when extending security across multiple accounts. An unexpected benefit was how easily our regular IT staff could manage and work with it without needing specialized firewall training
    What do you dislike about the product?
    premium credit based pricing structure and the initial learning curve required for policy setup Additionally, while standard cloud integrations are straightforward, navigating detailed threat logs and fine tuning advanced rules felt slightly overwhelming at first for general IT engineers without specialized Palo Alto training. The service could be improved by providing clearer usage forecasting calculators inside the console and offering pre-configured rule templates for standard cloud networking architectures
    What problems is the product solving and how is that benefiting you?
    Before using Cloud NGFW, we struggled with manually deploying and routing traffic through virtual firewall instances across multiple cloud accounts, which created significant maintenance overhead. Now, we can secure our cloud traffic using a fully managed service that plugs right into our cloud setup without complex workarounds This has cut our weekly networking maintenance workload by nearly 50% and reduced new cloud environment setup times from several days down to just a few hours
    Naveen V.

    Powerful Security with Advanced Configuration Challenges

    Reviewed on Aug 13, 2026
    Review provided by G2
    What do you like best about the product?
    I like Palo Alto Networks Cloud NGFW for the visibility and control it provides over network traffic and security. The security policies are flexible and allow us to control access based on our organization’s requirements. The monitoring and threat detection capabilities are really useful for troubleshooting connectivity issues and identifying potential security risks. I really enjoy the overall reliability and ease of managing security policies. The visibility into network activities makes it easier to identify unusual traffic and troubleshoot issues quickly. The combination of strong security controls, monitoring, and centralized management works especially well for supporting a secure IT environment. It's also easy to manage once the initial setup and advanced configurations are understood.
    What do you dislike about the product?
    I find the complexity of some of the configurations and security policy options challenging, especially for users who are not familiar with the software. Some advanced features can take time to understand and configure correctly. It would be helpful to have more straightforward guidance, simplified workflows, and clearer documentation for common support and troubleshooting scenarios to make the platform even easier to use. Simplifying the configuration interface and making security policy management more simple would improve the overall user experience. More practical examples and guided troubleshooting for common scenarios would also be helpful.
    What problems is the product solving and how is that benefiting you?
    I use Palo Alto Networks Cloud NGFW to secure and protect our cloud and network infrastructure, monitor network traffic, apply security policies, control access, and ease troubleshooting. It provides visibility and control over network traffic, preventing threats and helping enforce security policies effectively.
    Computer & Network Security

    NextGen Firewall Cloud Security with Centralized Network Protection

    Reviewed on Aug 13, 2026
    Review provided by G2
    What do you like best about the product?
    What I like most about Palo Alto Networks Cloud NGFW is the strong security capabilities combined with centralized management. Layer 7 application inspection, URL filtering, SSL/TLS decryption I liked the most.
    What do you dislike about the product?
    Sometimes it can be difficult to provision the infra and required setup for it rest are fine.
    What problems is the product solving and how is that benefiting you?
    It's a managed, cloud-native next-generation firewall service available on Amazon Web Services (AWS) and Microsoft Azure so it won't make you sweat on configurations and uptime as it's managed service that means rest are handled by the teamitself.
    Henok P.

    Effortless Workload Security with a Better UI

    Reviewed on Aug 12, 2026
    Review provided by G2
    What do you like best about the product?
    The best feature I can think of is, Palo Alto Networks Cloud can easily secures my workloads and traffic with out manually installing firewall virtual machines
    Also, it is has way better user Interface than most systems
    What do you dislike about the product?
    The Pricing is not effective, since it is a Pay as you go approach. It is easy to be mis-used
    What problems is the product solving and how is that benefiting you?
    We host a tier 1 ERP system, and security was a major concern for all stakeholders. With Palo Alto Networks, we’ve been able to use it smoothly while keeping our data protected.
    Habtemariam Z.

    Zero Trust with Deep Layer-7 Visibility and High-Throughput Protection

    Reviewed on Aug 12, 2026
    Review provided by G2
    What do you like best about the product?
    Zero trust architecture more advancing, Deep Layer 1 -7 visibility, accurately identifies applications and blocks advanced threats automatically, Consistent Policy Enforcement, High Throughput Performance.
    What do you dislike about the product?
    High Cumulative Cost for not affordable for new startup company. Cloud NGFW can take some time to adapting to managing policy
    What problems is the product solving and how is that benefiting you?
    Used for secured cloud network traffic without physical firewall , flexible central control , application visibility and best threat preventions and also help to me reducing complexity of managing secured across distributed environment , improving visibility in to traffic and makes it easier to scaling security in our infrastructure
    View all reviews