Listing Thumbnail

    VM-Series Next-Gen Virtual Firewall w/Advanced Threat Prevention (PAYG)

     Info
    Deployed on AWS
    Free Trial
    Protect AWS workloads, VDIs, and user traffic with AI/ML-powered virtual firewall from Palo Alto Networks. This listing includes VM-Series virtual firewall, Palo Alto Networks flagship - Advanced Threat Prevention security service and 24x7 premium technical support

    Overview

    Play video

    This offering includes a free, 15-day trial. Go beyond base layer 3, 4 protection with industry leading firewall in the cloud-native form factor that seamlessly integrates and scales with your AWS environment.

    02/01/24 UPDATE - This listing now includes Palo Alto Networks Advanced Threat Prevention cloud-delivered Security Service. ATP increases firewalls efficacy against zero day and other resilient threats (requires PAN-OS versions 10.2.8, 11.0.4, 11.1.2 or later).

    Next-Gen Security - protect business critical data with VM-Series virtual firewalls that give you complete application layer-7 visibility and control of your traffic in your AWS environment.

    Easy deployment - get started with a few clicks and deploy additional firewalls through the familiar EC2 instance creation flow.

    Simplified policy management - means your policies adapt to changes in your AWS infrastructure while keeping your resources protected in a consistent manner without manual intervention by the FW admin.

    Threat coverage - keep your workloads safe from threats with industry-leading traffic inspection.

    This listing also includes Palo Alto Networks Advanced Threat Prevention service which safeguards your network from known and zero day threats, such as exploits, malware, spyware, and command and control attacks, with market-leading, researcher-grade signatures and ML inspection engine that do not compromise performance.

    Looking for higher levels of security? Try the following PAYG listing to provide higher level of security to your AWS infrastructure:

    VM-Series Next-Generation Virtual Firewall w/ Advanced Security Subs (PAYG). See link below:

    https://aws.amazon.com/marketplace/pp/prodview-3xtziatyes54i?sr=0-8&ref_=beagle&applicationId=AWSMPContessa 

    Highlights

    • Best-in-class public cloud network security solution powered by AI/ML and latest threat research protects your workloads against day zero and known threats with application layer 7 visibility
    • Integrations with Gateway Load Balancer, AWS Auto Scaling, and Transit VPC with AWS Transit Gateway allow you to protect traffic across many types of dynamic and large scale deployments
    • Policy definitions dynamically apply to your cloud assets based on AWS tags, Application IDs, User IDs, geographies or zones.

    Details

    Delivery method

    Delivery option
    64-bit (x86) Amazon Machine Image (AMI)

    Latest version

    Operating system
    OtherLinux PAN-OS 10.2.13-h16

    Deployed on AWS

    Unlock automation with AI agent solutions

    Fast-track AI initiatives with agents, tools, and solutions from AWS Partners.
    AI Agents

    Features and programs

    Buyer guide

    Gain valuable insights from real users who purchased this product, powered by PeerSpot.
    Buyer guide

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    Free trial

    Try this product free for 15 days according to the free trial terms set by the vendor. Usage-based pricing is in effect for usage beyond the free trial terms. Your free trial gets automatically converted to a paid subscription when the trial ends, but may be canceled any time before that.

    VM-Series Next-Gen Virtual Firewall w/Advanced Threat Prevention (PAYG)

     Info
    Pricing is based on actual usage, with charges varying according to how much you consume. Subscriptions have no end date and may be canceled any time. Alternatively, you can pay upfront for a contract, which typically covers your anticipated usage for the contract duration. Any usage beyond contract will incur additional usage-based costs.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    Usage costs (42)

     Info
    Dimension
    Cost/hour
    c5n.xlarge
    Recommended
    $1.17
    m5n.large
    $0.99
    m5.4xlarge
    $3.69
    m4.4xlarge
    $3.69
    c6a.4xlarge
    $3.69
    m6in.4xlarge
    $3.69
    c6a.2xlarge
    $1.80
    m5.large
    $0.99
    m6in.2xlarge
    $1.80
    m4.large
    $0.99

    How can we make this page better?

    We'd like to hear your feedback and ideas on how to improve this page.
    We'd like to hear your feedback and ideas on how to improve this page.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    64-bit (x86) Amazon Machine Image (AMI)

    Amazon Machine Image (AMI)

    An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.

    Additional details

    Usage instructions

    See documentation for detailed steps to set admin password before using the web interface of VM-Series. Once the instance is running, connect to it using a SSH client with the private key file used to launch the instance. For example: ssh -i <privatekey.pem> admin@<EIP or private IP of eth0> Then use the PAN-OS CLI commands "configure", "set mgt-config users admin password" and "commit" commands to set the password.

    Support

    Vendor support

    To help you get started with your deployment such as how-to videos, deployment guides and reference architectures, please visit:

    https://live.paloaltonetworks.com/aws 

    For post-sales support, you can use the following options: Call us at 1 (866) 898-9087 Open a case by following the steps here:

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Product comparison

     Info
    Updated weekly

    Accolades

     Info
    Top
    10
    In Network Infrastructure
    Top
    10
    In Log Analysis, Network Infrastructure

    Customer reviews

     Info
    Sentiment is AI generated from actual customer reviews on AWS and G2
    Reviews
    Functionality
    Ease of use
    Customer service
    Cost effectiveness
    Positive reviews
    Mixed reviews
    Negative reviews

    Overview

     Info
    AI generated from product descriptions
    Network Traffic Inspection
    Advanced layer-7 application visibility and control with comprehensive traffic inspection capabilities
    Threat Prevention Technology
    AI/ML-powered security engine with researcher-grade signatures for detecting known and zero-day threats
    Cloud Security Integration
    Native integration with AWS infrastructure components including Gateway Load Balancer, Auto Scaling, and Transit VPC
    Dynamic Policy Management
    Automated policy application using AWS tags, Application IDs, User IDs, geographies, and network zones
    Deployment Flexibility
    Seamless deployment through EC2 instance creation workflow with cloud-native form factor
    Network Virtualization
    Secure virtual private network (VPN) gateway for connecting remote sites and branch offices
    Advanced Threat Protection
    Dynamic security controls with application layer exfiltration security and advanced evasion techniques (AETs) identification
    Intrusion Prevention
    Integrated advanced Intrusion Prevention System (IPS) with capability to stop Advanced Evasion Techniques
    Security Policy Management
    Centralized policy configuration with global update capabilities across network infrastructure
    Malware Detection
    Sandboxing technology for identifying zero-day attacks and advanced malware
    Network Traffic Inspection
    Inspects traffic entering and exiting private subnets in VPC ("North-South") and between VPCs ("East-West")
    Advanced Threat Prevention
    Provides multi-layered security capabilities including firewall, IPS, threat emulation, and threat extraction with advanced catch rates
    Cloud Infrastructure Integration
    Supports infrastructure-as-code tools like Terraform and Ansible, dynamically adapts security policies based on cloud metadata
    Security Protocol Coverage
    Comprehensive security features including Data Loss Prevention, application control, IPsec VPN, URL filtering, antivirus, and anti-Bot protection
    Cloud Service Compatibility
    Integrates with AWS services including Gateway Load Balancer, AWS Security Hub, VPC Ingress Routing, AWS Traffic Mirroring, and AWS Transit Gateway

    Contract

     Info
    Standard contract
    No
    No
    No

    Customer reviews

    Ratings and reviews

     Info
    3.7
    5 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    20%
    60%
    0%
    0%
    20%
    5 AWS reviews
    |
    32 external reviews
    Star ratings include only reviews from verified AWS customers. External reviews can also include a star rating, but star ratings from external reviews are not averaged in with the AWS customer star ratings.
    Sanket Bhostekar

    Experience with integrated visibility and ongoing support fulfills requirements effectively

    Reviewed on Jul 31, 2025
    Review provided by PeerSpot

    What is our primary use case?

    We have a Firewall as well as a Synapse  solution, and we have EDR, XDR  as well. The Palo Alto Networks VM-Series  Firewall is what we are using.

    What is most valuable?

    From a Synapse  perspective, they have better visibility, better CV detection, better exposure detection, and it is in a single tool, so we are happy with it.

    The integration of Palo Alto Networks VM-Series  within my existing network infrastructure and security tools is good; they are resilient, and we can integrate with anything easily.

    What needs improvement?

    There is one thing regarding Palo Alto Networks VM-Series that they need to look into, which is ISPM, Identity Security Posture Management, and other than that, I could see there are multiple things which they have already been doing well.

    Technical support is good for Palo Alto Networks VM-Series, but sometimes for new feature requests, we are facing challenges. We are the conglomerate, so individual business has different requirements, which we are expecting some new requests for. Whenever any custom requirement exists in an existing tool, they are taking much time with the engineering team, which is the only thing I'm expecting them to improve. Other than that, this product is very good.

    I think overall security is something they need to make into a single pane of glass to help the customer who is using only the single Palo Alto Networks vendor, so they will get end-to-end visibility in a single console.

    For how long have I used the solution?

    I have been using them for around three years.

    What do I think about the scalability of the solution?

    My experience with the scalability of Palo Alto Networks VM-Series is good; whenever we are facing any issues, they are helping, and it is a scalable environment.

    How are customer service and support?

    Technical support is good for Palo Alto Networks VM-Series, but sometimes for new feature requests, we are facing challenges.

    How would you rate customer service and support?

    Positive

    What other advice do I have?

    We are generally satisfied with Palo Alto Networks VM-Series.

    I would rate Palo Alto Networks VM-Series technical support an eight out of ten.

    I would recommend Palo Alto Networks VM-Series to others.

    I am a customer of Palo Alto Networks.

    Actually, we are trying to migrate to Cortex Cloud; currently, we are using Prisma, so we are in the phase to migrate to Cortex Cloud, but have not yet migrated, so I am not experienced with it and cannot give feedback about it.

    We haven't used Prisma Access Browser .

    Overall rating: 10/10

    Oyvind Mattland

    Enhance security with robust DNS and threat prevention features

    Reviewed on Apr 30, 2025
    Review provided by PeerSpot

    What is our primary use case?

    The use case varies. I use it as a gateway, and others use it for microsegmentation in the cloud. Additionally, some deploy it on-premises to protect specific environments. Most of the use cases are in cloud environments.

    What is most valuable?

    The most valuable features are the DNS security and threat prevention capabilities. The DNS security significantly enhances security through visibility and detection, allowing control over crucial traffic like DNS, which is often exploited by ransomware. Additionally, threat prevention and URL security are crucial licenses I recommend to customers, raising the security level substantially.

    What needs improvement?

    There are continuous developments with many new features coming every year. Although I receive feature requests from customers, I don't have any particular areas for improvement in mind right now.

    For how long have I used the solution?

    I have been working with Palo Alto Networks VM-Series  for more than ten years.

    What was my experience with deployment of the solution?

    Setting up the VM-Series is usually very easy. The firewall can be deployed and set up within half an hour, though it depends on the complexity of the configuration.

    What do I think about the stability of the solution?

    In terms of stability, I would rate it eight out of ten. Perfection is unlikely as the dynamic nature of traffic and constant changes can result in occasional bugs despite regular updates. Perfection in stability remains challenging for any vendor.

    What do I think about the scalability of the solution?

    I rate the scalability of Palo Alto Networks VM-Series  ten out of ten. It is easy to use with an excellent graphical user interface and extensive documentation, which contributes to its high scalability.

    How are customer service and support?

    I conduct most of the support myself and rate the overall support a nine out of ten. However, sometimes cases take longer to resolve, and there's always room for improvement, especially in terms of response time from higher support levels.

    How would you rate customer service and support?

    Positive

    How was the initial setup?

    The initial setup is straightforward and easy. The process involves registering and configuring the software, and with flex mode, it is easy to scale by purchasing additional credits for more CPU and RAM without needing new hardware.

    What's my experience with pricing, setup cost, and licensing?

    The pricing is more on the expensive side, but it is justified due to its functionality, reliability, and throughput, even with all features enabled. In comparison to FortiGate , Check Point, and Cisco, the performance does not degrade significantly. Although I rate the cost six out of ten, the features justify the higher expense.

    What other advice do I have?

    Overall, I rate Palo Alto Networks VM-Series an eight out of ten. While no product is perfect, I am satisfied with its performance and value.

    Which deployment model are you using for this solution?

    Hybrid Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Aravind Vellingiri

    Enhance cybersecurity for large enterprises using advanced threat management

    Reviewed on Apr 25, 2025
    Review provided by PeerSpot

    What is our primary use case?

    Our primary use case involves working with TVS Group of companies in India, a large automobile manufacturer. We take care of their entire cybersecurity system. We implement Palo Alto Networks VM-Series  firewalls along with third-party vendors and support them remotely for their day-to-day issues. We use these solutions to enhance cybersecurity and provide protection against various security threats.

    What is most valuable?

    The VM-Series firewalls are described as useful for security posture, offering next-generation features such as Unified Threat Management, app-centric capabilities, and threat intelligence. The firewalls use sandboxing and behavioral analysis to allow or quarantine new traffic. They help in identifying legitimate domains and instruct admins if approval is needed. This set of features is very helpful in daily tasks.

    What needs improvement?

    An improvement could be the integration of security intelligence with Palo Alto cloud via APIs. This would allow IOCs, domains, and hash values to be automatically entered, reducing manual entry. Integration with CSIRT across all use levels would make it easier for administrators to stay updated on the blocked entities without manual intervention.

    For how long have I used the solution?

    I have been working with Palo Alto Networks VM-Series  firewalls for about four to five years.

    What do I think about the stability of the solution?

    Generally, the VM-Series firewalls are stable. I would rate the stability as eight out of ten.

    What do I think about the scalability of the solution?

    The solution is scalable and can easily handle an increase in the number of users.

    How are customer service and support?

    I have worked with Palo Alto technical support for over two years. They are responsive and provide high-quality assistance. Previously, I have raised tickets, and they were efficiently handled by the technical team. My experience has been positive overall.

    How would you rate customer service and support?

    Positive

    How was the initial setup?

    The initial setup of the VM-Series firewalls is quite easy compared to traditional firewalls. It is manageable with fewer administrators required. On a scale of one to ten, I would rate the setup as nine for its ease of implementation.

    What about the implementation team?

    I am directly involved in the implementation of these firewalls. It typically takes around two to three hours to deploy the firewalls in a single environment.

    What other advice do I have?

    The solution is user-friendly and easy to manage within an environment. As a VM, it requires no physical space and can be managed with one or two admins. It's also 99.9% secure, according to cloud security standards. Overall, I give Palo Alto Networks VM-Series a rating of nine out of ten.

    Which deployment model are you using for this solution?

    On-premises

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Other
    RonnieYazdani

    User-friendly CLI and efficient dashboard streamline operations with robust security features

    Reviewed on Apr 17, 2025
    Review provided by PeerSpot

    What is our primary use case?

    We usually recommend Palo Alto Networks VM-Series  for BFSI companies.

    What is most valuable?

    I find Palo Alto Networks VM-Series  easy to deploy, and none of my customers have had significant complaints. My customers have high certifications provided by Palo Alto Networks. The friendly dashboard and the ability to easily command and use the CLI make Palo Alto Networks VM-Series a better product. It offers robust solutions, making it valuable to my customers.

    What needs improvement?

    It may be beneficial if the firewall can monitor all internal elements like VMs pulling from HP servers. Consolidating these insights into a single dashboard would be advantageous.

    For how long have I used the solution?

    I have been familiar with Palo Alto Networks for four or five years.

    What do I think about the stability of the solution?

    The performance of VM instances has some limitations in terms of threshold and throughput compared to appliances.

    What do I think about the scalability of the solution?

    I would rate scalability as eight out of ten.

    How are customer service and support?

    Palo Alto Networks offers better technical support, maintaining SLA efficiently, and resolving issues promptly.

    How would you rate customer service and support?

    Positive

    Which solution did I use previously and why did I switch?

    In some cases, I have migrated from Cisco to Palo Alto Networks VM-Series smoothly.

    What's my experience with pricing, setup cost, and licensing?

    Pricing for Palo Alto Networks is higher than other OEMs, but considering the robustness and features, it gains customer trust. Technical configuration is a focus area due to its high commercial profile.

    Which other solutions did I evaluate?

    I consider Check Point alongside Palo Alto Networks, as well as Cisco for wireless solutions.

    What other advice do I have?

    When evaluating, consider the customer’s environment and pain points since both Check Point and Palo Alto Networks have their advantages. Overall, I rate Palo Alto Networks VM-Series eight out of ten.

    Frank Nguyen

    Secures remote work with advanced threat protection and efficient traffic management

    Reviewed on Apr 03, 2025
    Review from a verified AWS customer

    What is our primary use case?

    I am using Palo Alto Networks VM-Series  because almost all my application infrastructure is hosted on AWS . AWS  supports deploying Palo Alto Networks VM-Series  in their marketplace, and Palo Alto is a leader in security in the firewall market. I also use the GlobalProtect  VPN from Palo Alto Networks.

    What is most valuable?

    Palo Alto Networks VM-Series is very strong in security features like antivirus, anti-spyware, and machine learning capabilities that help scan for antivirus and anti-spam. This ensures high security for internal and external traffic. They frequently update antivirus patterns and application threats, which provides reliable protection. I also value GlobalProtect  VPN for supporting remote users as most of my employees work remotely. Additionally, Palo Alto Networks helps me visualize and manage network traffic effectively, blocking risky files and enhancing network security.

    What needs improvement?

    Currently, I do not have specific suggestions for Palo Alto Networks VM-Series improvements. I am happy with the rich features provided. As I have only used it for four months, I might need more time to explore and suggest enhancements.

    For how long have I used the solution?

    I have been using Palo Alto Networks VM-Series since December 2020, around four months.

    What was my experience with deployment of the solution?

    Deploying Palo Alto Networks VM-Series was a bit challenging. I rate it a six out of ten for ease, as it required going through extensive documentation to set it up. Deployment took nearly a week to complete.

    What do I think about the stability of the solution?

    I rate the stability of Palo Alto Networks VM-Series as seven out of ten. I have not experienced any major problems or downtime, but I haven't yet explored all its features.

    What do I think about the scalability of the solution?

    Currently, I do not have a clear answer about the scalability of Palo Alto Networks VM-Series as I have not scaled it yet.

    How are customer service and support?

    I have not directly used Palo Alto's technical support as I rely on vendor support. The vendor provides me with documentation when needed.

    How would you rate customer service and support?

    Which solution did I use previously and why did I switch?

    Before using Palo Alto Networks VM-Series, I used a physical box on-premises. The switch was due to moving all infrastructure to AWS, necessitating a virtual solution.

    How was the initial setup?

    The initial setup of Palo Alto Networks VM-Series was somewhat challenging, requiring extensive documentation review. I rate it a six out of ten for ease.

    What about the implementation team?

    I handled almost 100% of the deployment myself. However, for specific features, I consulted the vendor engineer, who provided online documentation for guidance.

    What's my experience with pricing, setup cost, and licensing?

    I rate the pricing of Palo Alto Networks VM-Series as six or seven out of ten. The cost involves purchasing through a vendor, which might mark up due to the supply chain. I've had no complaints about Palo Alto's pricing.

    Which other solutions did I evaluate?

    I did not evaluate other options before choosing Palo Alto Networks VM-Series, as it is a leader in the market.

    What other advice do I have?

    Overall, I rate Palo Alto Networks VM-Series an eight out of ten. I am happy with its performance and rich features.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Amazon Web Services (AWS)
    View all reviews