Create a Cloud NGFW for AWS Resource
Focus
Focus
Cloud NGFW for AWS

Create a Cloud NGFW for AWS Resource

Table of Contents

Create a Cloud NGFW for AWS Resource

Create a Cloud NGFW for AWS resource.
Where Can I Use This?What Do I Need?
  • Cloud NGFW for AWS
  • Cloud NGFW subscription
  • Palo Alto Networks Customer Support Account (CSP)
  • AWS Marketplace account
  • User role (either tenant or administrator)
Now that you have created rulestacks and rules, you can create an NGFW resource and associate a local rulestack with that NGFW. During the configuration of your NGFW, you must choose how to create NGFW endpoints—automatically or manually. If you chose to manually create NGFW endpoints, you create NGFW endpoints in the availability zones you specify.
​​Before enabling IPv6 support, you must complete the following infrastructure setup in your AWS environment:
  • PAN-OS Version: Ensure that your firewall is running PAN-OS version 11.2.8 or above.
  • AWS IPAM: You must have a pre-configured AWS IP Address Manager (IPAM) in your region.
  • Private ULA Parent Pool: Create an IPv6 ULA (Unique Local Address) pool in the private scope of your IPAM in the fd80::/9 range.
  • VPC Capability: Your target VPC must be associated with a /56 IPv6 CIDR allocated from your IPAM pool.
Cloud NGFW for AWS offers different SKU capacity tiers to accommodate varying performance and deployment size requirements. You can select a capacity tier during initial provisioning to match your traffic scaling and rule capacity demands.
Prerequisites & Operational Rules Tier Selection Availability:
  • You can provision a new firewall directly into any of the three capacity tiers (Base, Standard, or Premium).
  • Once created, you can dynamically scale/upgrade your firewall tier at any time via the console, provided that the firewall status displays a stable CREATE_COMPLETE or UPDATE_COMPLETE state.
  • You can only upgrade firewall tiers; downgrading tiers is not supported. Complete the following steps to create an NGFW resource from the Cloud NGFW console or the Strata Cloud Manager (SCM) console.
Complete the following steps to create an NGFW resource from the Cloud NGFW console or the Strata Cloud Manager console.
  1. Log into your CNGFW console, select NGFWs from the navigation menu, and click Create Firewall.
  2. Enter a descriptive Name.
  3. (Optional) Enter a Description.
  4. Select an AWS Account from the drop-down to associate with this NGFW.
  5. Select a VPC from the drop-down.
    IPv6 Tenant Activation- To enable IPv6 for your Cloud NGFW, you must first request activation as the feature is not enabled by default and is managed on a per-tenant basis. Before proceeding with the infrastructure setup, open a Technical Assistance Center (TAC) case with Palo Alto Networks support explicitly stating, Please enable IPv6, and ensure you include your specific Tenant ID in the request.
  6. Configure the Capacity Tier (SKU Selection).
    Under the Tiers section, toggle your selection based on your workload needs.
    • Base SKU: Optimized for entry-level workloads, supporting up to 1 Gbps fat sessions.
    • Standard SKU (Recommended Default): Designed for scaling cloud-native workloads up to 40 Gbps, supporting 2 Gbps fat sessions and advanced feature sets.
    • Premium SKU: Tailored for mission-critical applications requiring maximum performance, supporting up to 4 Gbps fat sessions. For more information, see Cloud NGFW for AWS Limits and Quotas.
  7. In the Policy Management section, select a local rulestack from the drop-down.
  8. Specify AWS availability zones or subnets. Specify whether or not the Cloud NGFW tenant will (service-managed mode) or won't (customer-managed mode) deploy NGFW endpoints.
    • Yes (service-managed)—in service-managed mode, the Cloud NGFW tenant automatically creates NGFW endpoints in the VPC subnets you specify. Perform the endpoint management for service-managed mode through Cloud NGFW console only. The endpoint management for service-managed mode can only be done by associating or disassociating a subnet. Associating a subnet creates the endpoint and disassociating a subnet removes the endpoint.
    • No (customer-managed)—in customer-managed mode, you must manually create NGFW endpoints in each availability zone you specify.
    In the Endpoint Management section, you can enable your Cloud NGFW for securing traffic in multiple AWS availability zones. You pay for each AWS availability zone that your NGFW is provisioned to secure traffic. You can manage how the endpoints are created for your NGFW in these availability zones. You pay AWS for each VPC (gateway load balancer) endpoint that you create for your NGFW.
    The Availability Zone displays the Zone ID and the corresponding Availability Zone Name in your Palo Alto Networks account. Use this information when mapping your availability zones to your AWS accounts.
  9. Click Create.