Palo Alto NetworksNetwork Security

    Cloud NGFW

    Fully-managed next-generation firewall as a native cloud service.

    Palo Alto Networks Cloud NGFW is a fully-managed Next-Generation Firewall delivered as a native cloud service in AWS and Azure. It brings App-ID, inline machine-learning threat prevention, and Cloud-Delivered Security Services to cloud workloads without you managing firewall software or infrastructure — Palo Alto operates the firewall, you set the policy. Faltrox designs the policy and integrates it into your managed cloud defence.

    Overview

    What Cloud NGFW is

    Running the VM-Series gives full control but means managing firewall software, scaling, and availability yourself. For teams that want next-generation security in the cloud without that operational burden, Cloud NGFW is the answer: a fully-managed NGFW delivered as a native service in AWS and Azure, procured and integrated the cloud-native way.

    It delivers the same App-ID, inline machine-learning threat prevention, TLS decryption, and Cloud-Delivered Security Services as the rest of the platform, but Palo Alto Networks operates the underlying firewall — availability, scaling, and software — so you focus on policy. It integrates natively with cloud networking (AWS Firewall Manager, Azure) and is managed through Strata Cloud Manager or Panorama. Faltrox designs the policy, integrates it into your cloud architecture, and operates it as managed cloud defence.

    Coverage

    What it protects

    The platforms, threats, and surfaces this product is built to defend.

    01

    AWS & Azure

    Delivered as a native, fully-managed firewall service in AWS and Azure.

    02

    No Firewall Ops

    Palo Alto operates availability, scaling, and software — you set the policy.

    03

    Cloud Segmentation

    Segments and protects cloud workloads and traffic natively.

    04

    Inline ML Prevention

    Machine learning prevents known and unknown threats to cloud workloads.

    05

    Elastic Scale

    Scales natively with cloud traffic without capacity planning.

    06

    Cloud-Delivered Services

    Subscribes to the full Cloud-Delivered Security Services suite.

    How it works

    The mechanism

    How the product moves from signal to protected state, step by step.

    1. 01

      Procure

      Cloud NGFW is procured and deployed the cloud-native way through the AWS or Azure marketplace and integrations.

    2. 02

      Integrate

      It integrates natively with cloud networking so traffic is routed through the managed firewall service.

    3. 03

      Set Policy

      You define App-ID, User-ID, and threat policy — while Palo Alto operates the underlying firewall.

    4. 04

      Prevent & Scale

      Inline machine learning prevents threats and the service scales natively with cloud traffic.

    5. 05

      Operate

      Faltrox designs the policy, integrates it into the cloud architecture, and monitors it as managed cloud defence.

    Capabilities

    Key capabilities

    Fully-Managed Service

    Palo Alto Networks operates availability, scaling, and software so you only manage policy.

    Native AWS & Azure

    Delivered as a native cloud firewall service, procured and integrated the cloud-native way.

    App-ID

    Identifies applications regardless of port, protocol, or evasion, as the basis of policy.

    ML-Powered Prevention

    Inline machine learning prevents known and unknown threats to cloud workloads.

    Elastic Scaling

    Scales natively with cloud traffic without capacity planning or appliance sizing.

    Cloud-Delivered Security Services

    Subscribes to Advanced Threat Prevention, URL Filtering, WildFire, and DNS Security.

    TLS Decryption

    Decrypts and inspects encrypted cloud traffic so threats cannot hide in TLS.

    Unified Management

    Managed through Strata Cloud Manager or Panorama alongside the rest of the estate.

    Works with

    Part of the platform

    Palo Alto Networks products this pairs with, and the Faltrox services that operate it.

    Delivery

    You buy the outcome, not the console

    Managed by Faltrox

    Faltrox licenses, deploys, and tunes Palo Alto Networks Cloud NGFW for your environment, then runs it as part of a managed service, so you get the protection without staffing another security console.

    See the service

    FAQ

    Common questions

    01How is Cloud NGFW different from the VM-Series?

    The VM-Series is a virtual firewall you deploy and operate yourself; Cloud NGFW is a fully-managed native cloud service where Palo Alto Networks operates the firewall — availability, scaling, and software — and you only manage policy. Faltrox scopes which fits your operating model per cloud.

    02Which clouds does it support?

    It is delivered as a native, fully-managed firewall service in AWS and Azure, procured and integrated the cloud-native way through those platforms’ marketplaces and networking integrations.

    03Do we still control the security policy?

    Yes — you define the App-ID, User-ID, and threat policy; Palo Alto operates the underlying firewall infrastructure. It removes the operational burden without removing your control over security. Faltrox designs and manages that policy for you.

    04Does it scale automatically?

    Yes — as a native cloud service it scales elastically with cloud traffic, so there is no appliance sizing or capacity planning; security keeps pace with cloud auto-scaling.

    05How does Faltrox operate it?

    We design the security policy, integrate Cloud NGFW into your cloud network architecture, enable the Cloud-Delivered Security Services, and monitor it through Strata Cloud Manager — delivering managed cloud firewalling without you running firewall infrastructure.

    Start an engagement

    Secure what’s next.

    Speak with the engineering team to define scope, walk through the methodology, and decide whether Faltrox is the right team to test and run your environment.

    Contact us