Create a Cloud NGFW for AWS resource.
| Where Can I Use This? | What Do I Need? |
|
|
- Cloud NGFW subscription
- Palo Alto Networks Customer Support Account (CSP)
- AWS Marketplace account
- User role (either tenant or administrator)
|
Now that you have created rulestacks and rules, you can create an NGFW resource and
associate a local rulestack with that NGFW. During the configuration of your NGFW,
you must choose how to create NGFW endpoints—automatically or manually. If you chose
to manually create NGFW endpoints, you
create NGFW endpoints in the
availability zones you specify.
Before enabling IPv6 support, you must complete the following
infrastructure setup in your AWS environment:
PAN-OS Version: Ensure that your firewall is running
PAN-OS version 11.2.8 or above.
AWS IPAM: You must have a pre-configured AWS IP
Address Manager (IPAM) in your region.
Private ULA Parent Pool: Create an IPv6 ULA (Unique
Local Address) pool in the private scope of your IPAM in the
fd80::/9 range.
VPC Capability: Your target VPC must be associated
with a /56 IPv6 CIDR allocated from your IPAM
pool.
Cloud NGFW for AWS offers different SKU capacity tiers to accommodate varying
performance and deployment size requirements. You can select a capacity tier during
initial provisioning to match your traffic scaling and rule capacity demands.
Prerequisites & Operational Rules Tier Selection Availability: - You can provision a new firewall directly into any of the three capacity
tiers (Base, Standard, or Premium).
- Once created, you can dynamically scale/upgrade your firewall tier at any
time via the console, provided that the firewall status displays a stable
CREATE_COMPLETE or UPDATE_COMPLETE state.
- You can only upgrade firewall tiers; downgrading tiers is not supported.
Complete the following steps to create an NGFW resource from the Cloud NGFW
console or the Strata Cloud Manager (SCM) console.
Complete the following steps to create an NGFW resource from the Cloud NGFW console
or the Strata Cloud Manager console.