Cloud Next-Generation Firewall as a Service (30-Day Free Trial to PAYG) logo

    Cloud Next-Generation Firewall as a Service (30-Day Free Trial to PAYG)

    Fully managed, cloud-native firewall service with threat prevention, app control and advanced URL filtering that integrates with AWS Firewall Manager, CloudWatch and more.

    Ratings and reviews

    4.3
    213 ratings
    53%
    41%
    5%
    1%
    0%
    12 AWS reviews
    |
    201 external reviews
    External reviews are from G2  and PeerSpot .

    Filters

    Review type

    AWS Marketplace reviews
    External reviews
    Reviews (213)
    Anonymous

    Comprehensive Security with Minor Operational Hurdles

    Reviewed on Sep 18, 2026
    Review provided by G2
    What do you like best about the product?
    I really appreciate the managed architecture and the centralized policy capabilities, which make implementing Security Policy/Rulestacks, Threat Prevention, and URL Filtering efficient and effective. The SSL/TLS inspection and centralized logging and monitoring features are also important for maintaining security across cloud environments. Endpoint protection, WAF, and the core Firewall functionalities are what I like most about using Palo Alto Networks Cloud NGFW. The integration and synergy with Wiz and Cortex tools further enhance the security and operational insights. The initial setup was easy, which was a pleasant surprise for such a comprehensive service.
    What do you dislike about the product?
    One area I would like to see improved is the operational simplicity and cost visibility when deploying Cloud NGFW at scale. I would also like more granular cost and usage visibility at the resource or application level. Cloud NGFW pricing can involve resource hours, traffic processing, and additional security-service or centralized-management add-ons, so forecasting costs for high-volume environments can require careful analysis. Another area is automation and deployment consistency. For large multi-account AWS environments, stronger out-of-the-box automation and IaC capabilities could simplify onboarding and policy changes. That said, these are more areas for improving operational efficiency rather than fundamental security limitations.
    What problems is the product solving and how is that benefiting you?
    Palo Alto Networks Cloud NGFW protects inbound, outbound, and VPC-to-VPC traffic, while the managed architecture and centralized policy capabilities ensure robust security. It offers threat prevention, URL filtering, and SSL/TLS inspection benefits, minimizing security management complexity in cloud environments.
    varun s.

    Strong Cloud Security and Straightforward Management with Palo Alto Networks Cloud NGFW

    Reviewed on Sep 18, 2026
    Review provided by G2
    What do you like best about the product?
    I like Palo Alto Networks Cloud NGFW because it offers strong security, is straightforward to manage, and helps protect cloud applications from cyber threats. Overall, it gives me confidence that our cloud environment is better protected.
    What do you dislike about the product?
    The setup can feel a bit complex for beginners, and the pricing may be on the high side for small businesses.
    What problems is the product solving and how is that benefiting you?
    Palo Alto Networks Cloud NGFW helps protect cloud applications from cyber threats while making security management easier. It saves time, strengthens overall security, and helps reduce the risk of attacks.
    Abhishek S.

    Simple, Scalable, Centralized Security Management That Streamlines Firewall Complexity

    Reviewed on Sep 18, 2026
    Review provided by G2
    What do you like best about the product?
    I like its simplicity, scalability, and centralized security management. It makes it easier to secure network traffic consistently while reducing the complexity of managing traditional firewalls.
    What do you dislike about the product?
    The initial setup and troubleshooting can sometimes be a bit complex, and the solution can become costly as the environment scales. I’d also like to see more flexibility and simplicity in some advanced configurations.
    What problems is the product solving and how is that benefiting you?
    It helps us simplify firewall management, secure cloud traffic, and apply consistent security policies across environments. This reduces manual effort, improves visibility, and helps us respond to security issues faster.
    Anonymous

    Straightforward Setup with Easy Learning Curve

    Reviewed on Sep 17, 2026
    Review provided by G2
    What do you like best about the product?
    I like that Palo Alto Networks Cloud NGFW makes it easier to understand and practice network security concepts such as traffic inspection, firewall rules, app control, and threat prevention without having to manage the underlying infrastructure. It's safe and saves me from dealing with infrastructure setup, maintenance, patching, and scaling. This allows me to spend more time experimenting with security policies and learning cloud network security concepts. The setup was relatively easy, thanks to its cloud-native approach.
    What do you dislike about the product?
    For personal training, the main area of improvement would be making the learning experience more beginner-friendly. More guided labs, example architectures, and clearer documentation would make it easier to understand the product and explore its capabilities. Also, some of the initial networking and configuration concepts took a little time to understand.
    What problems is the product solving and how is that benefiting you?
    It secures cloud network traffic, prevents unauthorized access, and gives better network visibility without managing firewall infrastructure, saving me setup and maintenance time to focus on learning security concepts.
    Rahul C.

    Robust Cloud Security with User-Friendly Setup

    Reviewed on Sep 17, 2026
    Review provided by G2
    What do you like best about the product?
    I like the security features of Palo Alto Networks Cloud NGFW. It offers a lot of features to protect our company security and is a great addition to our network infrastructure. I also find it very user-friendly with an easy setup process. The product quality stands out to me, making it a good tool with lots of features.
    What do you dislike about the product?
    The interface is feature-rich, but sometimes it feels like there are too many options in one place. It can take a little time to find the exact setting you need.
    What problems is the product solving and how is that benefiting you?
    The product secures all forms of internet and main connectivity, enhancing our network infrastructure with robust features to protect company security.
    abdou m.

    Comprehensive Security with Simplified Management

    Reviewed on Sep 14, 2026
    Review provided by G2
    What do you like best about the product?
    I really like that Palo Alto Networks Cloud NGFW offers the full security capabilities of a next-gen firewall without the headache of managing infrastructure. The ease of setup was a big plus for us; it was very easy and straightforward. I also appreciate the features like App-ID, advanced threat prevention, and URL filtering that we use regularly. It’s great that the service reduces operational overhead while giving us enterprise-grade security.
    What do you dislike about the product?
    The policy management complexity for new users can be a bit of a hurdle. As rule sets grow, it tends to become quite complex. I think better policy visualization, AI-driven rule optimization, and simpler troubleshooting tools could definitely make it easier and more efficient.
    What problems is the product solving and how is that benefiting you?
    Palo Alto Networks Cloud NGFW protects our cloud applications and workloads, enforces consistent security policies, secures traffic, and reduces operational complexity with its managed service.
    Information Technology and Services

    Powerful

    Reviewed on Sep 12, 2026
    Review provided by G2
    What do you like best about the product?
    Its UI for the dashboard where you can do anything
    What do you dislike about the product?
    Not that much of course there's a room for improvement
    What problems is the product solving and how is that benefiting you?
    Speed
    rahul p.

    User-Friendly Interface with Advanced Features

    Reviewed on Sep 08, 2026
    Review provided by G2
    What do you like best about the product?
    I find Palo Alto Networks Cloud NGFW easy to use thanks to its user-friendly interface and intuitive GUI. It is very beginner-friendly, making navigation straightforward. I particularly value the user identification feature, which integrates with directory services like Active Directory. It allows us to apply policies based on users rather than IP addresses, which I find practical. Additionally, the cloud-based setup is easier than other options, like Cisco, due to its graphical interface.
    What do you dislike about the product?
    The Palo Alto Networks Cloud NGFW is great, but it should be more cost-effective, especially the security add-ons like advanced threat prevention and advanced URL filtering.
    What problems is the product solving and how is that benefiting you?
    Palo Alto Networks Cloud NGFW simplifies our network management with its easy-to-use, beginner-friendly GUI and allows user-based policies through integration with directory services, enhancing security beyond IP-based rules.
    Otshabeng P.

    Great Cloud Security

    Reviewed on Sep 07, 2026
    Review provided by G2
    What do you like best about the product?
    I like the combination of enterprise-grade security and ease of management. Cloud NGFW provides strong threat prevention and application visibility while automatically scaling with cloud workloads, reducing the operational effort required to manage traditional firewall infrastructure.
    What do you dislike about the product?
    Nothing really I'm impressed with most of the services.
    What problems is the product solving and how is that benefiting you?
    It helps solve the complexity of securing cloud workloads while keeping security management simple. The improved visibility, threat prevention, segmentation, and automatic scalability help reduce operational workload and allow IT teams to focus more on supporting the business rather than managing firewall infrastructure.
    Banking

    Enterprise Security Without the Overhead, but Mind the Scale and Hidden Costs

    Reviewed on Sep 07, 2026
    Review provided by G2
    What do you like best about the product?
    Palo Alto Networks Cloud NGFW brings enterprise-grade Layer 7 inspection directly into public cloud environments (such as AWS and Azure) as a fully managed, cloud-native service. Zero Infrastructure Overhead: Unlike traditional VM-Series virtual appliances that require manual provisioning, HA pairing, routing tables, and lifecycle patching, Cloud NGFW operates as a managed service. Palo Alto Networks handles availability, autoscaling, and underlying OS maintenance. True Layer 7 Inspection via App-ID: Standard cloud-native firewalls primarily filter on basic L3/L4 tuples (IP addresses, ports, and protocols). Cloud NGFW applies Palo Alto's App-ID engine to identify applications regardless of port, evasion technique, or encryption. Cloud-Delivered Security Services (CDSS): It integrates the full threat prevention stack directly into traffic inspection pipelines—including Advanced Threat Prevention (IPS), Advanced URL Filtering, DNS Security, and WildFire for zero-day malware analysis. Native Cloud Integration: It connects seamlessly with cloud routing constructs (such as AWS Gateway Load Balancer and Azure Virtual WAN), allowing centralized routing and automated deployment via cloud orchestration templates (Terraform, CloudFormation). Unified Policy Management: Policies can be orchestrated either through native cloud consoles (like AWS Firewall Manager) or centralized via Panorama / Strata Cloud Manager, ensuring consistent rule enforcement across on-prem data centers and multi-cloud VPCs/VNets.
    What do you dislike about the product?
    While Cloud NGFW eliminates appliance lifecycle overhead, trading off the full PAN-OS appliance model for a managed service introduces several distinct operational and technical drawbacks: High and Unpredictable Cost at Scale: Pricing combines an hourly firewall consumption fee with per-gigabyte data processing charges. For high-throughput environments (e.g., heavy East-West inspection between VPCs or massive backup transfers), data transfer billing escalates rapidly compared to fixed, BYOL software licensing for VM-Series appliances. Feature Stripping Compared to Full PAN-OS: Cloud NGFW is purpose-built strictly for inline traffic filtering. It strips out core edge firewall features you get on VM-Series or hardware firewalls: No GlobalProtect / Remote Access VPN: You cannot use it as a termination point for client VPN connections. No Native Site-to-Site IPsec/BGP Routing: Advanced routing topologies, policy-based forwarding (PBF), and custom IPsec tunnel configurations must be offloaded to cloud-native gateways (e.g., AWS Transit Gateway, Azure VPN Gateway). Limited SSL/TLS Decryption Flexibility: Inbound and outbound TLS inspection can be significantly more rigid and cumbersome to configure compared to PAN-OS forward proxy implementations. Loss of Deep Granular Control & Troubleshooting: Because the underlying data plane is an abstracted, managed black box, you lose root-level visibility. There is no PAN-OS CLI access to run debug datapath, check session tables in real-time, tweak auto-scaling thresholds manually, or capture raw packet dumps on specific dataplane interfaces. Logging Latency and Cloud Fragmentation: Cloud NGFW does not stream directly to Panorama's local log collector with sub-second immediacy. Logs are pushed out via cloud-native logging (such as Amazon CloudWatch/S3 or Azure Log Analytics/Kusto). This introduces ingest latency (often several minutes) and requires distinct query languages (KQL, CloudWatch Insights) for real-time security troubleshooting. Ecosystem and Feature Parity Gaps: Updates, newly released App-IDs, and advanced policy parameters often roll out to PAN-OS first before finding full parity inside the Cloud NGFW service schema.
    What problems is the product solving and how is that benefiting you?
    Cloud NGFW addresses the core operational friction points created when trying to enforce enterprise-grade security inside public cloud environments. It bridges the gap between basic cloud-native firewalls (which lack deep security capabilities) and virtual appliances like VM-Series (which introduce heavy engineering overhead). Core Problems Solved The Virtual Appliance Maintenance Burden: Deploying VM-based firewalls requires managing OS patching, dynamic signature updates, high-availability (HA) health checks, and complex auto-scaling scripts across multiple Availability Zones. Cloud NGFW removes all underlying compute management by delivering firewall inspection as an elastic, cloud-managed service. Shallow Cloud-Native Security (L3/L4 Blind Spots): Native cloud security controls (such as standard AWS Network Firewall or Azure Firewall) often struggle with sophisticated Layer 7 evasion, non-standard application ports, and granular content inspection. Cloud NGFW solves this by embedding Palo Alto’s App-ID engine, Advanced Threat Prevention (IPS), WildFire, and DNS Security natively into cloud traffic flows. Policy Fragmentation Between Cloud and On-Premises: Securing hybrid estates often forces teams to manage separate rule sets in cloud consoles and on-prem hardware. Cloud NGFW integrates directly with Panorama and Strata Cloud Manager, allowing teams to enforce uniform security policies across physical data centers and cloud VPCs/VNets from one pane of glass. Complex Network Plumbing and Scaling: Building multi-AZ inspection topologies with Gateway Load Balancers (GWLB) or Virtual WAN routing can require complex custom automation. Cloud NGFW is purpose-built to attach natively to cloud routing constructs, auto-scaling up and down dynamically with traffic volume without manual capacity planning. How That Benefits You Operational Area Without Cloud NGFW With Cloud NGFW Day-2 Operations Hours spent patching PAN-OS versions, fixing HA split-brains, and testing update rollbacks. Near-zero maintenance: Palo Alto and the cloud provider handle the underlying infrastructure, lifecycle, and availability. Capacity Planning Over-provisioning VM sizes to handle traffic spikes, or writing custom auto-scaling orchestration. Elastic throughput: Scales seamlessly with workload demands via managed integrations (e.g., AWS GWLB, Azure vWAN). Rule Governance Translating compliance and security baselines into disparate cloud security group/firewall formats. Centralized control: Manage rules alongside existing Palo Alto firewalls via Panorama or directly through cloud-native APIs/Terraform. Threat Visibility IP/Port-only logs that require correlating external tools to identify actual malware or command-and-control (C2) activity. Deep application inspection: Immediate App-ID, malicious URL, and DNS-layer blocking inline before traffic leaves or traverses your subnets. If your team is already invested in the Palo Alto Networks ecosystem, Cloud NGFW provides a path to maintain identical security postures and compliance across the cloud without having to operate a virtual data center fleet of firewalls.