Sold by
Cloud Next-Generation Firewall as a Service (30-Day Free Trial to PAYG)
Fully managed, cloud-native firewall service with threat prevention, app control and advanced URL filtering that integrates with AWS Firewall Manager, CloudWatch and more.
Reviews (204)
Information Technology and Services
Powerful
Reviewed on Sep 12, 2026
Review provided by G2
What do you like best about the product?
Its UI for the dashboard where you can do anything
What do you dislike about the product?
Not that much of course there's a room for improvement
What problems is the product solving and how is that benefiting you?
Speed
rahul p.
User-Friendly Interface with Advanced Features
Reviewed on Sep 08, 2026
Review provided by G2
What do you like best about the product?
I find Palo Alto Networks Cloud NGFW easy to use thanks to its user-friendly interface and intuitive GUI. It is very beginner-friendly, making navigation straightforward. I particularly value the user identification feature, which integrates with directory services like Active Directory. It allows us to apply policies based on users rather than IP addresses, which I find practical. Additionally, the cloud-based setup is easier than other options, like Cisco, due to its graphical interface.
What do you dislike about the product?
The Palo Alto Networks Cloud NGFW is great, but it should be more cost-effective, especially the security add-ons like advanced threat prevention and advanced URL filtering.
What problems is the product solving and how is that benefiting you?
Palo Alto Networks Cloud NGFW simplifies our network management with its easy-to-use, beginner-friendly GUI and allows user-based policies through integration with directory services, enhancing security beyond IP-based rules.
Otshabeng P.
Great Cloud Security
Reviewed on Sep 07, 2026
Review provided by G2
What do you like best about the product?
I like the combination of enterprise-grade security and ease of management. Cloud NGFW provides strong threat prevention and application visibility while automatically scaling with cloud workloads, reducing the operational effort required to manage traditional firewall infrastructure.
What do you dislike about the product?
Nothing really I'm impressed with most of the services.
What problems is the product solving and how is that benefiting you?
It helps solve the complexity of securing cloud workloads while keeping security management simple. The improved visibility, threat prevention, segmentation, and automatic scalability help reduce operational workload and allow IT teams to focus more on supporting the business rather than managing firewall infrastructure.
Banking
Enterprise Security Without the Overhead, but Mind the Scale and Hidden Costs
Reviewed on Sep 07, 2026
Review provided by G2
What do you like best about the product?
Palo Alto Networks Cloud NGFW brings enterprise-grade Layer 7 inspection directly into public cloud environments (such as AWS and Azure) as a fully managed, cloud-native service. Zero Infrastructure Overhead: Unlike traditional VM-Series virtual appliances that require manual provisioning, HA pairing, routing tables, and lifecycle patching, Cloud NGFW operates as a managed service. Palo Alto Networks handles availability, autoscaling, and underlying OS maintenance. True Layer 7 Inspection via App-ID: Standard cloud-native firewalls primarily filter on basic L3/L4 tuples (IP addresses, ports, and protocols). Cloud NGFW applies Palo Alto's App-ID engine to identify applications regardless of port, evasion technique, or encryption. Cloud-Delivered Security Services (CDSS): It integrates the full threat prevention stack directly into traffic inspection pipelines—including Advanced Threat Prevention (IPS), Advanced URL Filtering, DNS Security, and WildFire for zero-day malware analysis. Native Cloud Integration: It connects seamlessly with cloud routing constructs (such as AWS Gateway Load Balancer and Azure Virtual WAN), allowing centralized routing and automated deployment via cloud orchestration templates (Terraform, CloudFormation). Unified Policy Management: Policies can be orchestrated either through native cloud consoles (like AWS Firewall Manager) or centralized via Panorama / Strata Cloud Manager, ensuring consistent rule enforcement across on-prem data centers and multi-cloud VPCs/VNets.
What do you dislike about the product?
While Cloud NGFW eliminates appliance lifecycle overhead, trading off the full PAN-OS appliance model for a managed service introduces several distinct operational and technical drawbacks: High and Unpredictable Cost at Scale: Pricing combines an hourly firewall consumption fee with per-gigabyte data processing charges. For high-throughput environments (e.g., heavy East-West inspection between VPCs or massive backup transfers), data transfer billing escalates rapidly compared to fixed, BYOL software licensing for VM-Series appliances. Feature Stripping Compared to Full PAN-OS: Cloud NGFW is purpose-built strictly for inline traffic filtering. It strips out core edge firewall features you get on VM-Series or hardware firewalls: No GlobalProtect / Remote Access VPN: You cannot use it as a termination point for client VPN connections. No Native Site-to-Site IPsec/BGP Routing: Advanced routing topologies, policy-based forwarding (PBF), and custom IPsec tunnel configurations must be offloaded to cloud-native gateways (e.g., AWS Transit Gateway, Azure VPN Gateway). Limited SSL/TLS Decryption Flexibility: Inbound and outbound TLS inspection can be significantly more rigid and cumbersome to configure compared to PAN-OS forward proxy implementations. Loss of Deep Granular Control & Troubleshooting: Because the underlying data plane is an abstracted, managed black box, you lose root-level visibility. There is no PAN-OS CLI access to run debug datapath, check session tables in real-time, tweak auto-scaling thresholds manually, or capture raw packet dumps on specific dataplane interfaces. Logging Latency and Cloud Fragmentation: Cloud NGFW does not stream directly to Panorama's local log collector with sub-second immediacy. Logs are pushed out via cloud-native logging (such as Amazon CloudWatch/S3 or Azure Log Analytics/Kusto). This introduces ingest latency (often several minutes) and requires distinct query languages (KQL, CloudWatch Insights) for real-time security troubleshooting. Ecosystem and Feature Parity Gaps: Updates, newly released App-IDs, and advanced policy parameters often roll out to PAN-OS first before finding full parity inside the Cloud NGFW service schema.
What problems is the product solving and how is that benefiting you?
Cloud NGFW addresses the core operational friction points created when trying to enforce enterprise-grade security inside public cloud environments. It bridges the gap between basic cloud-native firewalls (which lack deep security capabilities) and virtual appliances like VM-Series (which introduce heavy engineering overhead). Core Problems Solved The Virtual Appliance Maintenance Burden: Deploying VM-based firewalls requires managing OS patching, dynamic signature updates, high-availability (HA) health checks, and complex auto-scaling scripts across multiple Availability Zones. Cloud NGFW removes all underlying compute management by delivering firewall inspection as an elastic, cloud-managed service. Shallow Cloud-Native Security (L3/L4 Blind Spots): Native cloud security controls (such as standard AWS Network Firewall or Azure Firewall) often struggle with sophisticated Layer 7 evasion, non-standard application ports, and granular content inspection. Cloud NGFW solves this by embedding Palo Alto’s App-ID engine, Advanced Threat Prevention (IPS), WildFire, and DNS Security natively into cloud traffic flows. Policy Fragmentation Between Cloud and On-Premises: Securing hybrid estates often forces teams to manage separate rule sets in cloud consoles and on-prem hardware. Cloud NGFW integrates directly with Panorama and Strata Cloud Manager, allowing teams to enforce uniform security policies across physical data centers and cloud VPCs/VNets from one pane of glass. Complex Network Plumbing and Scaling: Building multi-AZ inspection topologies with Gateway Load Balancers (GWLB) or Virtual WAN routing can require complex custom automation. Cloud NGFW is purpose-built to attach natively to cloud routing constructs, auto-scaling up and down dynamically with traffic volume without manual capacity planning. How That Benefits You Operational Area Without Cloud NGFW With Cloud NGFW Day-2 Operations Hours spent patching PAN-OS versions, fixing HA split-brains, and testing update rollbacks. Near-zero maintenance: Palo Alto and the cloud provider handle the underlying infrastructure, lifecycle, and availability. Capacity Planning Over-provisioning VM sizes to handle traffic spikes, or writing custom auto-scaling orchestration. Elastic throughput: Scales seamlessly with workload demands via managed integrations (e.g., AWS GWLB, Azure vWAN). Rule Governance Translating compliance and security baselines into disparate cloud security group/firewall formats. Centralized control: Manage rules alongside existing Palo Alto firewalls via Panorama or directly through cloud-native APIs/Terraform. Threat Visibility IP/Port-only logs that require correlating external tools to identify actual malware or command-and-control (C2) activity. Deep application inspection: Immediate App-ID, malicious URL, and DNS-layer blocking inline before traffic leaves or traverses your subnets. If your team is already invested in the Palo Alto Networks ecosystem, Cloud NGFW provides a path to maintain identical security postures and compliance across the cloud without having to operate a virtual data center fleet of firewalls.
Mahmoud T.
Seamless Cloud-Native Security with Centralized Panorama Management
Reviewed on Sep 07, 2026
Review provided by G2
What do you like best about the product?
Palo Alto Networks Cloud NGFW is its seamless cloud-native integration combined with enterprise-grade security. It delivers Palo Alto’s best-in-class Layer 7 threat protection and App-ID capabilities without the operational complexity of managing firewall infrastructure. The ability to manage security policies centrally via Panorama ensures consistent policy enforcement across hybrid environments. Additionally, its automated scaling and zero-overhead maintenance allow us to secure cloud workloads efficiently while keeping management simple.
What do you dislike about the product?
The main drawbacks are the high cost structure—especially data processing charges—and higher complexity when integrating with Panorama for hybrid setups. It also offers slightly less granular customization compared to traditional PA-Series VM Firewalls, and multi-cloud support can still be somewhat limited depending on the provider.
What problems is the product solving and how is that benefiting you?
It solves the operational headache of manually deploying, patching, and scaling firewall VMs, while providing much deeper L7 security than basic cloud-native tools. Benefits: It saves significant operational time, allows unified policy management across hybrid networks via Panorama, and scales automatically with our traffic without requiring manual infrastructure work.
Information Technology and Services
Amazing UI and Seamless Integration with Powerful AI Features
Reviewed on Sep 03, 2026
Review provided by G2
What do you like best about the product?
the experience was amazing , UI and interface is very good and suitable , integration between components is very seamless , performance is significant , value for money is very good , support is very strong and AI features is very powerful
What do you dislike about the product?
over all experiences was very good , I cannot see bad things in the experience
What problems is the product solving and how is that benefiting you?
Ready to use:
> Palo Alto Networks Cloud NGFW has helped us address the challenge of securing fast-changing cloud workloads without the operational overhead of deploying, scaling, and maintaining traditional firewall appliances. It gives us consistent Layer 7 security and threat prevention for inbound, outbound, and east-west traffic, helping reduce exposure to malware, exploits, command-and-control traffic, and data exfiltration.
>
> The biggest benefit is operational simplicity. We can apply standardized policies across cloud accounts and VPCs, automate deployments through infrastructure-as-code workflows, and scale protection with demand. This has reduced manual firewall administration, accelerated secure application deployments, improved visibility, and helped us maintain a more consistent security posture across our cloud environment.
> Palo Alto Networks Cloud NGFW has helped us address the challenge of securing fast-changing cloud workloads without the operational overhead of deploying, scaling, and maintaining traditional firewall appliances. It gives us consistent Layer 7 security and threat prevention for inbound, outbound, and east-west traffic, helping reduce exposure to malware, exploits, command-and-control traffic, and data exfiltration.
>
> The biggest benefit is operational simplicity. We can apply standardized policies across cloud accounts and VPCs, automate deployments through infrastructure-as-code workflows, and scale protection with demand. This has reduced manual firewall administration, accelerated secure application deployments, improved visibility, and helped us maintain a more consistent security posture across our cloud environment.
Bhushan B.
Strong Security and Easy Development Experience
Reviewed on Sep 03, 2026
Review provided by G2
What do you like best about the product?
Strong security and very easy development
What do you dislike about the product?
The initial configuration is somewhat complex and requires a steep learning curve
What problems is the product solving and how is that benefiting you?
It helps us maintain consistent security policies across our multi-cloud environment. As a result, it significantly reduces the time our team spends on manual configuration and lowers our overall risk of a breach.
Computer & Network Security
Strong Security, Easy Cloud Deployment, and Scalable Centralized Management
Reviewed on Sep 02, 2026
Review provided by G2
What do you like best about the product?
I like the combination of strong security, easy cloud deployment, centralized management, and scalability. It’s also easy to configure.
What do you dislike about the product?
The pricing can also become expensive at higher traffic volumes, and getting the most value from its advanced security features requires some Palo Alto Networks expertise.
What problems is the product solving and how is that benefiting you?
One challenge is the limited availability of practical documentation and troubleshooting guidance, which can make configuration and issue resolution more difficult.
Financial Services
Strong Threat Prevention with Cloud-Native Simplicity
Reviewed on Sep 02, 2026
Review provided by G2
What do you like best about the product?
What I like best about Palo Alto Networks Cloud NGFW is its combination of strong threat prevention and cloud-native simplicity. It provides deep Layer 7 inspection and advanced threat prevention while reducing the need to manage firewall infrastructure. The value is good considering the level of security, visibility, threat prevention, and centralized management it provides. Although the cost and licensing can be relatively high, the reduced operational overhead and improved security capabilities make it a worthwhile investment for organizations with significant cloud security requirements.
What do you dislike about the product?
One area I dislike about Palo Alto Networks Cloud NGFW is the complexity of configuration and policy management, especially for teams that are new to the Palo Alto Networks ecosystem.
What problems is the product solving and how is that benefiting you?
It helps us address the complexity of securing cloud environments by offering centralized security policies, strong threat prevention, and clear visibility—without the overhead of managing firewall infrastructure ourselves. As a result, it reduces administrative effort, improves consistency across our security controls, and lets our team spend more time on day-to-day security operations and threat response.
prashant K.
Strong Security with Great Visibility
Reviewed on Sep 01, 2026
Review provided by G2
What do you like best about the product?
I like Palo Alto Networks Cloud NGFW for its strong security capabilities and the visibility it provides. It has the ability to inspect network traffic and apply security policies, allowing the definition of rules or policies for which applications are accessible or blocked. The initial setup was relatively straightforward.
What do you dislike about the product?
I think there could be more detailed configuration documentation and workflow for Palo Alto Networks Cloud NGFW.
What problems is the product solving and how is that benefiting you?
I use Palo Alto Networks Cloud NGFW to solve network security challenges, like protecting cloud workloads and controlling network traffic. It provides strong security capabilities and visibility, allowing us to inspect traffic and apply security policies effectively.