Fully managed, cloud-native firewall service with threat prevention, app control and advanced URL filtering that integrates with AWS Firewall Manager, CloudWatch and more.
Cloud Next-Generation Firewall (CNGFW) for AWS delivers best-in-class network security powered by artificial intelligence and machine learning, stopping zero-day exploits faster than traditional platforms. This fully managed turnkey cloud-native firewall service with 99.99% availability removes the complexity of managing firewall infrastructure in AWS. It lets you immediately turn on the next-generation firewall features and scale your security, ensuring seamless protection for your applications in the AWS environment.
Cloud NGFW extends your threat prevention capabilities across AWS environments and seamlessly integrates with key AWS services like AWS Firewall Manager, CloudWatch, Kinesis Firehose, and more. It provides real-time insights, automated security workflows, and granular traffic control for robust network protection. Recent enhancements include Strata Cloud Manager integration for centralized visibility and firewall-as-code enhancements.
Benefits
Effortless Deployment and Zero-Operational Burden: Palo Alto Networks Cloud NGFW takes care of the complex operational tasks, allowing for seamless firewall deployment and management in AWS. It streamlines processes such as certificate management, software upgrades, patch management and multi-dimensional scaling to ensure 99.99% availability. By eliminating the challenges of managing and scaling firewalls yourself, you can deploy robust cloud protection in just a few clicks, without worrying about infrastructure management.
Advanced Threat Prevention. Secure your AWS VPC traffic from zero-day attacks and unknown command-and-control traffic using Cloud-Delivered Security Services (CDSS) powered by Precision AI as well as Unit 42 Threat Research, enabling detection and mitigation 180x faster than traditional platforms.
Real-Time Threat Detection. Protect your applications with advanced AI and ML-powered threat prevention, leveraging intelligence derived from 70,000+ global customers to stop zero-day exploits, DNS threats, and web-based threats before they impact your network. This extensive threat intelligence network continuously learns and adapts, providing unparalleled protection that evolves with the latest attack vectors.
Granular Traffic Control. Gain visibility and precise control over your network traffic based on workloads, users, and applications with patented Layer 7 classification. Reduce attack surfaces and safeguard your AWS environment from malicious traffic.
Centralized Visibility. Simplify security operations with centralized management using Strata Cloud Manager or Panorama. Gain comprehensive visibility into applications, users, and threats for more efficient security management, faster threat resolution, and optimized policy creation.
Improved Metrics & Monitoring. Leverage AWS CloudWatch to monitor NGFW health, performance, and usage patterns in real-time, ensuring your security operations run at peak efficiency.
Firewall-as-Code Enhancements. Automate your firewall deployment, policy enforcement and account management workflows with the support of APls, CloudFormation and Terraform. Eliminate manual interventions and streamline your security operations.
Cloud NGFW is the Firewall-as-a-Service. Choose either AWS Firewall Manager or Palo Alto Networks Panorama for consistent policy management across multiple AWS accounts, enabling flexible control and seamless security across your cloud environments.
Activate your 30-Day free trial and create up to two next-generation firewall resources on your existing AWS VPCs, securing up to 100GB of traffic. After the free trial, you'll transition to a pay-as-you-go model, and you can check your subscription status on the Subscription Management page.
Highlights
Deploy your next-generation firewall with one-click, automated provisioning that auto-scales to match your network traffic. Leverage Palo Alto Networks Panorama or Strata Cloud Manager for unified security management, ensuring you maintain control and visibility across your cloud infrastructure without the complexity of managing infrastructure.
Integrate seamlessly with AWS-native services like CloudWatch, Kinesis Firehose, and AWS Firewall Manager, providing real-time insights, granular traffic control, and enhanced security capabilities. Backed by Palo Alto Networks Unit 42 Threat Research, the service delivers cutting-edge threat prevention and faster mitigation of zero-day exploits.
Cloud NGFW supports automated onboarding of AWS environments and workflow automation through APIs, CloudFormation, and Terraform, enabling quick deployment and consistent operations. Gain comprehensive visibility and management across multiple AWS accounts with centralized security operations using Strata Cloud Manager or Panorama.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
This service bills by usage, with no infrastructure to manage. Your cost comes from two main parts. First, you pay for firewall runtime by the hour. The Base NGFW rate covers three availability zones, and each extra zone adds a fraction of a unit per hour. Second, you pay for traffic inspected, measured in gigabytes. Traffic pricing runs in monthly tiers: the first 15 TB, the next 15 TB, and anything above 30 TB. Add-Ons draw on Cloud NGFW Credits, letting you enable extra capabilities as separate usage units.
Top-of-mind questions for buyers
What does the Base NGFW hourly unit cover, and how do additional availability zones affect my cost?
The Base NGFW hourly rate covers firewall runtime across three availability zones. Each unit equals one usage hour. If you deploy into a fourth zone or more, each extra zone adds 0.33 units per hour to your runtime charge. Charges accrue while the firewall runs.
How do the monthly traffic tiers apply as my inspected data grows?
Traffic is metered per gigabyte inspected each month. The first 15 TB bills at the first-tier rate. The next 15 TB bills at the second-tier rate. Anything above 30 TB bills at the third-tier rate. Each tier applies only to the gigabytes within its range, and the transition happens automatically.
Which charge usually drives the largest part of my bill — firewall runtime or traffic inspected?
Both charges apply at once on the same invoice. Runtime charges depend on hours running and the number of availability zones. Traffic charges depend on gigabytes inspected each month. For steady, high-volume workloads, traffic often dominates. Add-Ons draw separately from Cloud NGFW Credits.
www.paloaltonetworks.com
Helpful?
Vendor refund policy
We do not currently support refunds, but you can cancel at any time.
Request a private offer to receive a custom quote.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Artificial intelligence and machine learning-powered threat prevention leveraging intelligence from 70,000+ global customers to detect and mitigate zero-day exploits, DNS threats, and web-based threats 180x faster than traditional platforms.
Layer 7 Application Classification and Control
Patented Layer 7 classification enabling granular traffic control and visibility based on workloads, users, and applications with precise network traffic management.
Cloud-Delivered Security Services
Cloud-Delivered Security Services (CDSS) powered by Precision AI and Unit 42 Threat Research for advanced threat prevention and detection of zero-day attacks and unknown command-and-control traffic.
Infrastructure as Code and Automation
Support for automated deployment, policy enforcement, and account management workflows through APIs, CloudFormation, and Terraform integration.
AWS Native Service Integration
Seamless integration with AWS services including AWS Firewall Manager, CloudWatch, Kinesis Firehose, and Strata Cloud Manager for centralized management and real-time monitoring.
Intrusion Prevention System
Leading Intrusion Prevention System (IPS) integrated into unified security solution for threat detection and prevention
Advanced Evasion Technique Detection
Capability to identify and stop Advanced Evasion Techniques (AETs) with superior performance compared to other security devices
Application Layer Security
Advanced application control with application layer exfiltration security and dynamic security controls
Sandboxing and Malware Analysis
Sandboxing technology for identifying zero-day attacks and advanced malware threats
Centralized Management Console
Unified management console for streamlined security administration across data center, office, and branch firewalls
Advanced Threat Prevention Capabilities
Includes firewall, Data Loss Prevention (DLP), Intrusion Prevention System (IPS), application control, IPsec VPN, URL filtering, antivirus, and anti-bot features for multi-layered network security.
Traffic Inspection and Control
Inspects and controls encrypted data flows between on-premises networks and AWS VPCs, including North-South traffic entering and exiting private subnets and East-West traffic between VPCs.
Infrastructure-as-Code Integration
Integrates with infrastructure-as-code tools including Terraform and Ansible for policy automation, with dynamic security policy adaptation based on real-time cloud metadata.
Provides unified, centralized management through Check Point Security Management Server with consistent policy, logging, and reporting across AWS, hybrid, and on-premises environments.
Easy to Use and Compliance-Ready, but Cost Can Be a Hurdle
Reviewed on Jul 21, 2026
Review provided by G2
What do you like best about the product?
Easy to use, meets compliance needs, and supports remote administration.
What do you dislike about the product?
The cost was more than the company was willing to spend, and replacing out-of-date equipment was quite expensive as well.
What problems is the product solving and how is that benefiting you?
It helped solve our office location security issues and meet our compliance needs.
Austin E.
Secure and User-Friendly, Needs Documentation Improvement
Reviewed on Jul 20, 2026
Review provided by G2
What do you like best about the product?
I like the ease of use and security of Palo Alto Networks Next-Generation Firewalls.
What do you dislike about the product?
The documentation and features of Palo Alto Networks Next-Generation Firewalls could be improved. Specifically, I think clearer documents on first-time setup and use or conversion from other firewalls would be really helpful. The initial setup wasn't terrible, but it wasn't easy either.
What problems is the product solving and how is that benefiting you?
Palo Alto Networks Next-Generation Firewalls meets our security needs and ensures compliance. I like their ease of use and security features.
Anonymous
Comprehensive Security with Policy Management Complexity
Reviewed on Jul 20, 2026
Review provided by G2
What do you like best about the product?
I value the visibility, ease of policy enforcement, and comprehensive threat prevention capabilities of Palo Alto Networks Next-Generation Firewalls. The firewalls provide strong protection while giving security teams detailed insight into applications, users, and network activity. I appreciate its integration with our SIEM, EDR, vulnerability management, identity services, and cloud security tools to correlate security events, improve threat detection, and streamline incident response workflows. Once implemented, the platform offers strong visibility and security capabilities.
What do you dislike about the product?
The platform is powerful but policy management and troubleshooting can be complex at scale. Simplified administration, improved reporting and easier optimization of advanced security features would further enhance the overall experience.
What problems is the product solving and how is that benefiting you?
Palo Alto Networks Next-Generation Firewalls secure our network by preventing malware and cyber threats, controlling application access, blocking malicious websites, and providing visibility into user and device activity. They allow us to enforce security policies and detect both known and emerging threats.
Internet
Granular App-ID/User-ID Control with an Intuitive UI and Powerful API Integrations
Reviewed on Jul 20, 2026
Review provided by G2
What do you like best about the product?
The granular visibility and control provided by their App-ID and User-ID technologies stand out. Rather than relying on traditional ports and protocols, it enables the creation of precise, zero-trust security policies based on the actual applications in use and the users behind them. Also, The design is highly intuitive, making it easy to navigate through complex security policies and network settings without a steep learning curve. Furthermore, its robust REST API and seamless integration with third-party applications and orchestration tools make automating security workflows and extending capabilities incredibly straightforward.
What do you dislike about the product?
The high initial hardware costs, coupled with expensive recurring licensing fees for essential security subscriptions, can make it a significant investment that may not fit tighter IT budgets. Even though performance is superb, it comes at a cost.
What problems is the product solving and how is that benefiting you?
It solves the critical problem of network blind spots by providing deep, application-level visibility and control, rather than just restricting traditional IP ports. It effectively eliminates the need to manage disjointed security silos. This benefits me by drastically reducing our attack surface and simplifying policy administration. With a clear, unified view of exactly what traffic and threats are moving through the network, I can troubleshoot issues much faster and maintain a robust security posture without spending hours deciphering complex logs. It's AI/ML solutions also help a lot.
Theogene N.
Reliable Firewall with Strong Threat Protection
Reviewed on Jul 20, 2026
Review provided by G2
What do you like best about the product?
I like its strong application visibility, effective threat prevention, intuitive management, and reliable security controls across users, applications, and network traffic.
What do you dislike about the product?
The licensing can be expensive, and the initial setup and policy management may feel complex without experienced administrators.
What problems is the product solving and how is that benefiting you?
It helps prevent cyber threats, control application access, and improve network visibility. This reduces security risks and makes it easier to detect and respond to suspicious activity.