VM-Series
The virtual ML-Powered NGFW for public clouds and virtualized data centres.
The Palo Alto Networks VM-Series is the virtualized form of the ML-Powered Next-Generation Firewall, protecting public clouds, on-premises virtualized data centres, and NFV environments with the same PAN-OS security as physical appliances. It brings App-ID, inline machine-learning threat prevention, and Cloud-Delivered Security Services to virtual and cloud workloads. Faltrox deploys, automates, and operates it as software-defined network defence.
Overview
What VM-Series is
As workloads move to public cloud and virtualized data centres, network security has to move with them — but a physical appliance cannot follow a workload into AWS, Azure, GCP, or a hypervisor. The VM-Series is the virtual NGFW that can: the full PAN-OS ML-Powered NGFW packaged as a virtual machine that deploys anywhere workloads run.
It delivers App-ID application control, User-ID-based access, inline machine-learning prevention of known and unknown threats, TLS decryption, and the full Cloud-Delivered Security Services — identical to the physical firewalls — so policy is consistent across physical and virtual estates. It integrates with cloud-native automation (Terraform, autoscaling) so security scales with the workloads it protects. Faltrox deploys it, automates its lifecycle, and operates it as part of unified physical-and-virtual defence.
Coverage
What it protects
The platforms, threats, and surfaces this product is built to defend.
Public Clouds
Protects workloads in AWS, Azure, Google Cloud, and other public clouds.
Virtualized Data Centres
Secures on-premises virtualized and private-cloud environments.
East-West Segmentation
Microsegments traffic between virtual workloads to contain lateral movement.
Inline ML Prevention
Machine learning prevents known and unknown threats to virtual workloads in real time.
NFV Environments
Runs as a network-functions-virtualization security function where needed.
Cloud Automation
Integrates with Terraform and autoscaling so security scales with workloads.
How it works
The mechanism
How the product moves from signal to protected state, step by step.
- 01
Deploy
The VM-Series is deployed as a virtual machine into public cloud, private cloud, or a hypervisor via cloud-native automation.
- 02
Identify
App-ID, User-ID, and Content-ID identify applications, users, and content in a single pass, identical to physical firewalls.
- 03
Prevent
Inline machine learning and Cloud-Delivered Security Services prevent known and unknown threats to virtual workloads.
- 04
Scale
It integrates with autoscaling so security capacity grows and shrinks with the workloads it protects.
- 05
Operate
Faltrox automates its lifecycle and operates it as part of unified physical-and-virtual defence.
Capabilities
Key capabilities
Virtual ML-Powered NGFW
The full PAN-OS NGFW as a virtual machine, identical in policy to physical appliances.
Multi-Cloud Coverage
Deploys in AWS, Azure, Google Cloud, and other public and private clouds.
App-ID
Identifies applications regardless of port, protocol, or evasion, as the basis of policy.
ML-Powered Prevention
Inline machine learning prevents known and unknown threats to virtual workloads.
Cloud-Delivered Security Services
Subscribes to Advanced Threat Prevention, URL Filtering, WildFire, and DNS Security.
Cloud Automation
Integrates with Terraform, autoscaling, and cloud-native tooling for elastic security.
Consistent Policy
Enforces the same policy across physical and virtual firewalls from Panorama or Strata Cloud Manager.
East-West Segmentation
Microsegments traffic between virtual workloads to contain lateral movement.
Works with
Part of the platform
Palo Alto Networks products this pairs with, and the Faltrox services that operate it.
Delivery
You buy the outcome, not the console
Managed by Faltrox
Faltrox licenses, deploys, and tunes Palo Alto Networks VM-Series for your environment, then runs it as part of a managed service, so you get the protection without staffing another security console.
FAQ
Common questions
01How is the VM-Series different from a physical firewall?
It is the same PAN-OS ML-Powered NGFW packaged as a virtual machine, so it enforces identical policy and threat prevention — but it deploys where physical hardware cannot: into public clouds, private clouds, and hypervisors, following workloads wherever they run.
02Does it scale with our cloud workloads?
Yes — it integrates with cloud-native automation (Terraform) and autoscaling, so security capacity grows and shrinks with the workloads it protects rather than being a fixed bottleneck. Faltrox automates that lifecycle.
03Can we manage it alongside our physical firewalls?
Yes — the same Panorama or Strata Cloud Manager manages physical and virtual firewalls together with consistent policy, so your physical and virtual estates are operated as one. Faltrox runs that unified management.
04How does it relate to Cloud NGFW and CN-Series?
The VM-Series is the customer-managed virtual firewall; Cloud NGFW is the fully-managed NGFW-as-a-service in AWS/Azure; CN-Series is the containerised firewall for Kubernetes. Faltrox scopes which form factor fits each part of your cloud estate.
05How does Faltrox operate it?
We deploy and automate the VM-Series in your clouds and virtual data centres, build the policy consistent with your physical estate, enable the Cloud-Delivered Security Services, and monitor it — delivering unified physical-and-virtual network defence.
Start an engagement
Secure what’s next.
Speak with the engineering team to define scope, walk through the methodology, and decide whether Faltrox is the right team to test and run your environment.
Contact us