9.1 Cloud NGFW for AWS and Azure Architectures (GWLB and VWAN)

Key Takeaways

  • Cloud NGFW for AWS leverages AWS Gateway Load Balancer (GWLB) and VPC Endpoints to inspect traffic across enterprise VPCs without requiring manual routing overhead or complex overlay tunnels.
  • Cloud NGFW for Azure integrates natively into Azure Virtual WAN (VWAN) as a trusted security partner provider within the Secure Virtual Hub, providing automated routing intent inspection.
  • Cloud NGFW configurations are governed using Managed Rulestacks (Local Rulestacks managed via AWS/Azure consoles or Global Rulestacks centralized via Panorama).
  • Consumption models for Cloud NGFW support pay-as-you-go (PAYG) hourly/consumption billing via cloud marketplaces as well as Palo Alto Networks Software NGFW Credit (FLEX) allocations.
Last updated: July 2026

9.1 Cloud NGFW for AWS and Azure Architectures (GWLB and VWAN)

Cloud NGFW Architecture & Multicloud Security Overview

As enterprise workloads migrate to public cloud providers like Amazon Web Services (AWS) and Microsoft Azure, securing cloud traffic without introducing operational friction or bottlenecking cloud agility requires specialized deployment architectures. Cloud NGFW is Palo Alto Networks' fully managed, cloud-native Next-Generation Firewall service. Unlike self-managed VM-Series virtual appliances that require manual scaling group configurations, load balancer setups, software maintenance, and operating system updates, Cloud NGFW operates as a managed Software-as-a-Service (SaaS) offering where Palo Alto Networks maintains the underlying infrastructure, auto-scaling, fault tolerance, and PAN-OS updates while customers maintain full control over security policy definitions.

Cloud NGFW for AWS Architecture & Gateway Load Balancer Integration

In AWS environments, Cloud NGFW for AWS integrates seamlessly with AWS Gateway Load Balancer (GWLB) and VPC Endpoint Services (GWLBE). AWS GWLB operates at Layer 3 (IP network layer) and Layer 4, using GENEVE (Generic Network Virtualization Encapsulation) tunneling over UDP port 6081 to encapsulate original IP packets with metadata (such as source ENI and VPC IDs) and forward them across the AWS Hyperplane network fabric to Cloud NGFW inspection instances.

AWS Topology, Traffic Steering, and High Availability

  1. Spoke VPC to Internet (Egress Inspection): Traffic originating from instance subnets in a Spoke VPC is routed via VPC route tables to a local GWLB Endpoint (GWLBE) provisioned in a dedicated security subnet within each Availability Zone (AZ).
  2. GENEVE Encapsulation: The GWLBE forwards the packet to the central AWS GWLB, which encapsulates the packet in a 50-byte GENEVE header containing connection state and flow tracking metadata before delivering it to Cloud NGFW tenant inspection endpoints.
  3. App-ID & Threat Inspection: Cloud NGFW decrypts SSL/TLS traffic (if configured), inspects flows using Single-Pass Parallel Processing (SP3), applies App-ID, Threat Prevention, Advanced URL Filtering, DNS Security, and WildFire analysis, and strips the GENEVE header upon packet approval.
  4. Return Path & Multi-AZ Resilience: Approved packets are returned to the GWLB and forwarded to their Internet Gateway (IGW) or NAT Gateway destination. AWS GWLB performs continuous health checks on Cloud NGFW endpoints; if an inspection node fails, GWLB transparently reroutes active flows to healthy instances across Availability Zones without dropping existing TCP sessions.

Managed Rulestacks in AWS

Cloud NGFW policies are structured using Rulestacks:

  • Local Rulestacks: Administered directly through the AWS Management Console, Cloud NGFW API, or AWS CloudFormation/Terraform. Local Rulestacks are ideal for cloud-native teams requiring local policy scope tailored to specific AWS account boundaries.
  • Global Rulestacks: Administered centrally using Panorama. Panorama pushes security policy rulesets, device groups, and security profiles directly to Cloud NGFW instances, enabling consistent enterprise security governance across physical appliances, VM-Series, and Cloud NGFW.

Cloud NGFW for Azure Architecture & Virtual WAN Integration

In Microsoft Azure environments, Cloud NGFW for Azure integrates natively with Azure Virtual WAN (VWAN) and Azure Secure Virtual Hubs. Azure VWAN provides a managed hub-and-spoke connectivity network where Microsoft manages routing between Virtual Networks (VNets), branch offices, SD-WAN devices, and cloud services.

Secure Virtual Hub Integration and Routing Intent

Cloud NGFW for Azure is deployed directly inside the Azure Secure Virtual Hub as a native Network Virtual Appliance (NVA) provider:

  • Routing Intent & Routing Policies: Administrators configure Azure VWAN Routing Intent. This directs all Private Traffic (VNet-to-VNet, VNet-to-Branch, VNet-to-ExpressRoute) and Public Traffic (Internet Egress) traversing the Virtual Hub to automatically route through Cloud NGFW endpoints without needing custom User-Defined Routes (UDRs) on individual spoke VNet subnets.
  • High Availability & Auto-Scaling: Azure manages compute scaling and fault domains across Azure Availability Zones automatically. Cloud NGFW instances dynamically scale CPU and inspection bandwidth based on active traffic load without administrative intervention.
  • Azure Portal Integration: Management, billing, metrics, and log exporting (to Azure Monitor and Log Analytics) are native to the Azure Portal, offering single-pane billing and resource deployment.

Consumption Models: Pay-As-You-Go vs. SaaS Licensing

Deploying Cloud NGFW allows organizations to align firewall costs with actual cloud usage and procurement preferences:

  1. Pay-As-You-Go (PAYG): Billed directly through AWS Marketplace or Azure Marketplace. Charges consist of fixed hourly firewall instance consumption fees plus variable throughput data processing charges (per GB inspected). PAYG requires no upfront commitment and draws down against cloud provider enterprise discount commitments (e.g., AWS EDP or Azure MACC).
  2. Palo Alto Networks Credits (FLEX Licensing): Organizations purchase software credit pools from Palo Alto Networks or authorized partners. Credits are flexibly consumed across Cloud NGFW instances, VM-Series, and cloud security subscriptions based on actual hourly deployment metrics.

Platform Comparison Matrix

Architecture FeatureCloud NGFW for AWSCloud NGFW for AzureVM-Series (Self-Managed)
Primary Cloud FabricAWS GWLB + VPC Endpoints (GWLBE)Azure Virtual WAN (Secure Hub)AWS GWLB / Azure ALB / UDRs
Management PlaneCloud NGFW Console & PanoramaAzure Portal & PanoramaPanorama or Local Web Interface
Infrastructure ScalingFully Managed Auto-Scaling by Palo AltoFully Managed Auto-Scaling by Palo AltoUser-Configured Auto-Scaling Groups
Encapsulation ProtocolGENEVE (UDP 6081)Azure Software-Defined Network FabricGENEVE / VXLAN / IPsec
Routing MechanismVPC Route Tables pointing to GWLBEAzure VWAN Central Routing IntentSubnet User-Defined Routes (UDRs)
Billing MechanismAWS Marketplace PAYG / FLEX CreditsAzure Marketplace PAYG / FLEX CreditsBYOL / PAYG Hourly / FLEX
Security SubscriptionsThreat Prevention, URL Filtering, WildFire, DNS SecurityThreat Prevention, URL Filtering, WildFire, DNS SecurityComplete PAN-OS Subscription Suite
Loading diagram...
Cloud NGFW for AWS GWLB Architecture
Test Your Knowledge

When deploying Cloud NGFW for AWS with Gateway Load Balancer (GWLB), which network encapsulation protocol is used to transport packets between the GWLB endpoints and the firewall inspection instances?

A
B
C
D
Test Your Knowledge

How does Cloud NGFW for Azure simplify traffic steering across Virtual Networks in an Azure Virtual WAN (VWAN) architecture?

A
B
C
D
Test Your Knowledge

Which management option allows enterprise security teams to push centralized security policy rulesets across both physical PAN-OS appliances and Cloud NGFW instances?

A
B
C
D