Cloud NGFW
Fully-managed next-generation firewall as a native cloud service.
Palo Alto Networks Cloud NGFW is a fully-managed Next-Generation Firewall delivered as a native cloud service in AWS and Azure. It brings App-ID, inline machine-learning threat prevention, and Cloud-Delivered Security Services to cloud workloads without you managing firewall software or infrastructure — Palo Alto operates the firewall, you set the policy. Faltrox designs the policy and integrates it into your managed cloud defence.
Overview
What Cloud NGFW is
Running the VM-Series gives full control but means managing firewall software, scaling, and availability yourself. For teams that want next-generation security in the cloud without that operational burden, Cloud NGFW is the answer: a fully-managed NGFW delivered as a native service in AWS and Azure, procured and integrated the cloud-native way.
It delivers the same App-ID, inline machine-learning threat prevention, TLS decryption, and Cloud-Delivered Security Services as the rest of the platform, but Palo Alto Networks operates the underlying firewall — availability, scaling, and software — so you focus on policy. It integrates natively with cloud networking (AWS Firewall Manager, Azure) and is managed through Strata Cloud Manager or Panorama. Faltrox designs the policy, integrates it into your cloud architecture, and operates it as managed cloud defence.
Coverage
What it protects
The platforms, threats, and surfaces this product is built to defend.
AWS & Azure
Delivered as a native, fully-managed firewall service in AWS and Azure.
No Firewall Ops
Palo Alto operates availability, scaling, and software — you set the policy.
Cloud Segmentation
Segments and protects cloud workloads and traffic natively.
Inline ML Prevention
Machine learning prevents known and unknown threats to cloud workloads.
Elastic Scale
Scales natively with cloud traffic without capacity planning.
Cloud-Delivered Services
Subscribes to the full Cloud-Delivered Security Services suite.
How it works
The mechanism
How the product moves from signal to protected state, step by step.
- 01
Procure
Cloud NGFW is procured and deployed the cloud-native way through the AWS or Azure marketplace and integrations.
- 02
Integrate
It integrates natively with cloud networking so traffic is routed through the managed firewall service.
- 03
Set Policy
You define App-ID, User-ID, and threat policy — while Palo Alto operates the underlying firewall.
- 04
Prevent & Scale
Inline machine learning prevents threats and the service scales natively with cloud traffic.
- 05
Operate
Faltrox designs the policy, integrates it into the cloud architecture, and monitors it as managed cloud defence.
Capabilities
Key capabilities
Fully-Managed Service
Palo Alto Networks operates availability, scaling, and software so you only manage policy.
Native AWS & Azure
Delivered as a native cloud firewall service, procured and integrated the cloud-native way.
App-ID
Identifies applications regardless of port, protocol, or evasion, as the basis of policy.
ML-Powered Prevention
Inline machine learning prevents known and unknown threats to cloud workloads.
Elastic Scaling
Scales natively with cloud traffic without capacity planning or appliance sizing.
Cloud-Delivered Security Services
Subscribes to Advanced Threat Prevention, URL Filtering, WildFire, and DNS Security.
TLS Decryption
Decrypts and inspects encrypted cloud traffic so threats cannot hide in TLS.
Unified Management
Managed through Strata Cloud Manager or Panorama alongside the rest of the estate.
Works with
Part of the platform
Palo Alto Networks products this pairs with, and the Faltrox services that operate it.
Delivery
You buy the outcome, not the console
Managed by Faltrox
Faltrox licenses, deploys, and tunes Palo Alto Networks Cloud NGFW for your environment, then runs it as part of a managed service, so you get the protection without staffing another security console.
FAQ
Common questions
01How is Cloud NGFW different from the VM-Series?
The VM-Series is a virtual firewall you deploy and operate yourself; Cloud NGFW is a fully-managed native cloud service where Palo Alto Networks operates the firewall — availability, scaling, and software — and you only manage policy. Faltrox scopes which fits your operating model per cloud.
02Which clouds does it support?
It is delivered as a native, fully-managed firewall service in AWS and Azure, procured and integrated the cloud-native way through those platforms’ marketplaces and networking integrations.
03Do we still control the security policy?
Yes — you define the App-ID, User-ID, and threat policy; Palo Alto operates the underlying firewall infrastructure. It removes the operational burden without removing your control over security. Faltrox designs and manages that policy for you.
04Does it scale automatically?
Yes — as a native cloud service it scales elastically with cloud traffic, so there is no appliance sizing or capacity planning; security keeps pace with cloud auto-scaling.
05How does Faltrox operate it?
We design the security policy, integrate Cloud NGFW into your cloud network architecture, enable the Cloud-Delivered Security Services, and monitor it through Strata Cloud Manager — delivering managed cloud firewalling without you running firewall infrastructure.
Start an engagement
Secure what’s next.
Speak with the engineering team to define scope, walk through the methodology, and decide whether Faltrox is the right team to test and run your environment.
Contact us