
Overview
The Prisma® SD-WAN Instant-On Network (ION) models of hardware and software devices enable the integration of a diverse set of wide area network (WAN) connection types, improve application performance and visibility, enhance security and compliance, and reduce the overall cost and complexity of your WAN. Built with the intent to transform branch infrastructure, Prisma SASE powers the branch of the future with next generation SD-WAN.
Highlights
- Extend Prisma SD-WAN between remote offices, data centers, and AWS cloud
- End-to-end application performance for exceptional user experience
- Improved security outcomes with integrated security
Details
Unlock automation with AI agent solutions

Features and programs
Financing for AWS Marketplace purchases
Pricing
Vendor refund policy
Refunds provided in accordance with customer license and sales agreement
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
Prisma SD-WAN Greenfield Deployment
"""The Prisma SD-WAN greenfield CloudFormation template will deploy and configure the following:
- A new VPC
- 1 private and 1 public subnet
- An Internet Gateway
- Route tables associated with each subnet
- The public subnet has a default route to the new Internet Gateway
- A single elastic IP to be assigned to the Prisma SD-WAN instance interface in the public subnet
- 2 security groups, one for the Prisma SD-WAN interface in the public subnet and one for the Prisma SD-WAN interfaces in the private subnet
- A Prisma SD-WAN EC2 instance with the appropriate associations to the elastic IP, security groups, subnets, and user supplied meta-data to register the ION to the customer's portal"""
CloudFormation Template (CFT)
AWS CloudFormation templates are JSON or YAML-formatted text files that simplify provisioning and management on AWS. The templates describe the service or application architecture you want to deploy, and AWS CloudFormation uses those templates to provision and configure the required services (such as Amazon EC2 instances or Amazon RDS DB instances). The deployed application and associated resources are called a "stack."
Additional details
Usage instructions
To use the Prisma SD-WAN virtual ION v6.5.1 AWS:
- To procure a license please contact your Palo Alto Networks account manager directly, or request via https://www.paloaltonetworks.com/sase/sd-wan#connect
- Obtain a token/secret from https://stratacloudmanager.paloaltonetworks.com (Settings -> ION License Management)
- Launch the appropriate AWS CloudFormation Template for your use case
- Brownfield to insert the ION instance into an existing VPC
- Greenfield to create a new VPC with the ION instance deployed
- Greenfield HA to create a new VPC with the 2 ION instance deployed in seperate availability zones
- Once the image boots it will show up in your Prisma SD-WAN tenant in Strata Cloud Manager as online-unclaimed, claim the device and configure per your requirements
- Follow the getting started guide here for more details https://docs.paloaltonetworks.com/content/dam/techdocs/en_US/supporting/prisma-sd-wan/prisma-sd-wan-ion-aws-deployment.pdf
Resources
Vendor resources
Support
Vendor support
Email and telephone support provided in accordance with customer license and sales agreement
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Similar products



Customer reviews
Prisma world
- High WAN Costs and Complexity: It reduces reliance on expensive MPLS by intelligently utilizing cheaper broadband and LTE/5G connections, lowering operational costs and simplifying network setup.
- Poor Application Performance: It ensures critical applications (especially SaaS) always have the best path, dynamically routing traffic to minimize latency and packet loss, leading to a significantly improved user experience.
- Limited Network Visibility and Manual Management: It provides centralized, deep visibility into network and application performance, and automates many operational tasks through AI/ML (AIOps), reducing manual effort and speeding up troubleshooting.
- Inconsistent Branch Security: It integrates security natively, often as part of a SASE (Secure Access Service Edge) strategy, ensuring consistent security policies across all locations and for all users and devices.
For me, this translates to cost savings, better application performance for our users, and a vastly simplified network management experience. We spend less time troubleshooting and more time on strategic initiatives.
Disappointing Experience with Prisma SD-WAN
Lack of stability – We experienced instability in tunnels and failovers that weren’t always timely. In critical environments, this is a serious concern.
Limitations in complex scenarios – The product seems to perform better in standardized deployments. When dealing with advanced configurations or integration with existing systems, options are often rigid or require workarounds that feel like temporary fixes.
Support needs improvement – Response times are not always fast, and we frequently had to re-explain the same issue to multiple support engineers. Additionally, the available documentation is scattered and, in some cases, outdated.
In our usage is reducing the dependency from Service Provider MPLS networks
Evaluating Prisma SD-WAN
It constantly monitors the performance of all WAN links and dynamically steers traffic based on real-time conditions like latency, jitter, and packet loss — which has significantly improved application performance without me needing to manually intervene.
I also like the management over cloud which is easy to control.
Lastly, the UI — while functional — could be a bit more hard in some areas. For example, navigating between different policy layers or finding certain logs sometimes takes more clicks than it should.
That said, these are mostly usability issues, and once you're familiar with the platform, they’re manageable.
With Prisma SD-WAN, we now have dynamic path selection based on real-time network conditions, which means critical applications like VoIP and video conferencing always get the best possible link. That’s directly improved user experience and reduced complaints from remote offices.
Prisma SD-WAN Made Our Network Smoother — A Few Bumps, But Totally Worth It
Interesting solution for sd-wan
2. Steep learning curve – The interface and configuration options are powerful but may feel overwhelming at first.
3. Documentation gaps – Some users report that documentation is either too generic or lacks real-world deployment examples.
4. UI performance – The web interface can sometimes be slow or unintuitive, especially when navigating large configurations.
5. Licensing and cost – Pricing models may not be straightforward, and costs can grow with scale.
6. Integration quirks – Integration with legacy systems or third-party solutions may require manual workarounds.