|
1 | 1 | ---
|
2 |
| -title: Create a Cloud Next Generation Firewall (NGFW) by Palo Alto Networks |
3 |
| -description: This article describes how to use the Azure portal to create a Cloud NGFW (Next-Generation Firewall) by Palo Alto Networks. |
| 2 | +title: Create a Cloud Next-Generation Firewall (NGFW) by Palo Alto Networks |
| 3 | +description: Learn how to use the Azure portal to create a Cloud NGFW (Next-Generation Firewall) by Palo Alto Networks. |
4 | 4 |
|
5 | 5 | ms.custom: references_regions
|
6 | 6 | ms.topic: quickstart
|
7 |
| -ms.date: 12/09/2024 |
| 7 | +ms.date: 06/27/2025 |
8 | 8 |
|
9 | 9 | ---
|
10 | 10 |
|
11 | 11 | # QuickStart: Get started with Cloud NGFW by Palo Alto Networks
|
12 | 12 |
|
13 | 13 | In this quickstart, you use Azure Marketplace to find and create an instance of **Cloud NGFW by Palo Alto Networks - an Azure Native ISV Service resource**.
|
14 | 14 |
|
15 |
| -## Create a new Cloud NGFW by Palo Alto Networks resource |
| 15 | +## Prerequisites |
16 | 16 |
|
17 |
| -In this section, you see how create a Palo Alto Networks resource. |
| 17 | +[!INCLUDE [create-prerequisites](../includes/create-prerequisites.md)] |
18 | 18 |
|
19 |
| -### Basics |
| 19 | +## Create a Cloud NGFW resource |
20 | 20 |
|
21 |
| -1. In the Azure portal, create a Cloud NGFW by Palo Alto Networks resource using the Marketplace. Use search to find _Cloud NGFW by Palo Alto Networks_. Then, select **Subscribe**. Then, select **Create**. |
| 21 | +[!INCLUDE [create-resource](../includes/create-resource.md)] |
22 | 22 |
|
23 |
| -1. Set the following values in the Basics tab. |
| 23 | +In this section, you'll create a Cloud NGFW by Palo Alto Networks resource. |
24 | 24 |
|
25 |
| - :::image type="content" source="media/palo-alto-create/palo-alto-basics.png" alt-text="Screenshot of Basics tab of the Palo Alto Networks create experience."::: |
| 25 | +### Basics tab |
26 | 26 |
|
27 |
| - | Property | Description | |
| 27 | +- Set the following values on the **Basics** tab. |
| 28 | + |
| 29 | + :::image type="content" source="media/palo-alto-create/palo-alto-basics.png" alt-text="Screenshot of the Basics tab of the Create Cloud NGFW page." lightbox="media/palo-alto-create/palo-alto-basics.png"::: |
| 30 | + |
| 31 | + | Setting | Description | |
28 | 32 | |---------|---------|
|
29 |
| - | **Subscription** | From the drop-down, select your Azure subscription where you have owner access. | |
30 |
| - | **Resource group** | Specify whether you want to create a new resource group or use an existing one. A resource group is a container that holds related resources for an Azure solution. For more information, see Azure Resource Group overview. | |
31 |
| - | **Name** | Put the name for the Palo Alto Networks account you want to create. | |
| 33 | + | **Subscription** | Select an Azure subscription for which you have owner access. | |
| 34 | + | **Resource group** | Specify whether you want to create a new resource group or use an existing one. A resource group is a container that holds related resources for an Azure solution. For more information, see [What is a resource group?](../../azure-resource-manager/management/manage-resource-groups-portal.md#what-is-a-resource-group). | |
| 35 | + | **Firewall name** | Enter a name for the firewall. | |
32 | 36 | | **Region** | Select an appropriate region. |
|
33 |
| - | **Pricing Plan** | Specified based on the selected Palo Alto Networks plan. | |
| 37 | + | **Marketplace Plan** | Select **Cloud NGFW by Palo Alto Networks - an Azure Native ISV Service (PAYG)**. | |
34 | 38 |
|
35 |
| -### Networking |
| 39 | +### Networking tab |
36 | 40 |
|
37 |
| -1. After completing the Basics tap, select the **Next: Networking** to see the **Networking** tab. 1. Select either **Virtual Network** or **Virtual Wan Hub**. |
| 41 | +1. After providing the required information on the **Basics** tab, select **Next** to go to the **Networking** tab. |
38 | 42 |
|
39 |
| -1. Use the dropdowns to set the **Virtual Network**, **Private Subnet**, and Public **Public Subnet** associated with the Palo Alto Networks deployment. |
| 43 | +1. Select either **Virtual Network** or **Virtual Wan Hub**. |
40 | 44 |
|
41 |
| -1. For **Public IP Address Configuration**, select either **Create New** or **Use Existing** and type in a name for **Public IP Address Name(s)**. |
| 45 | +1. Select the dropdown arrows to set the **Virtual Network**, **Private Subnet**, and **Public Subnet** that are associated with the Cloud NGFW deployment. |
42 | 46 |
|
43 |
| -1. Select the checkbox **Enable Source NAT** to indicate your preferred NAT settings. |
| 47 | +1. Under **Public IP Address Configuration**, select either **Create new** or **Use existing**. |
44 | 48 |
|
45 |
| -### Security Policy |
| 49 | +1. If you select **Create new**, accept the supplied public IP address name or enter a name. If you select **Use existing**, select a public IP address name. |
46 | 50 |
|
47 |
| -1. After setting the Domain Name System (DNS) values, select the **Next: Security Policy** to see the **Security Policies** tab. You can set the policies for the firewall using this tab. |
| 51 | +1. Under **Source NAT Settings**, indicate your preferred NAT settings. |
48 | 52 |
|
49 |
| - :::image type="content" source="media/palo-alto-create/palo-alto-rulestack.png" alt-text="Screenshot of the Rulestack in the Palo Alto Networks create experience."::: |
| 53 | +### Security Policies tab |
50 | 54 |
|
51 |
| -1. Select checkbox **Managed By** to indicate either **Azure Portal** or **Palo Alto Networks Panorama**. |
| 55 | +1. After setting the networking values, select **Next** to go to the **Security Policies** tab. You can set the policies for the firewall on this tab. |
52 | 56 |
|
53 |
| -1. For **Choose Local Rulestack**, select either **Create New** or **Use Existing** options. |
| 57 | + :::image type="content" source="media/palo-alto-create/palo-alto-rulestack.png" alt-text="Screenshot of the Security Policies tab of the Create Cloud NGFW page." lightbox="media/palo-alto-create/palo-alto-rulestack.png"::: |
54 | 58 |
|
55 |
| -1. Input an existing rulestack in the **Local Rulestack** option. |
| 59 | +1. Under **Managed by**, select **Azure Rulestack**, **Palo Alto Networks Panorama**, or **Palo Alto Networks Strata Cloud Manager**. |
56 | 60 |
|
57 |
| -1. Select the checkbox **Best practice rule** to indicate Firewall mode or IDS mode options. |
| 61 | +1. Your options depend on the choice you made in the previous step. Indicate your choices for the required settings. |
58 | 62 |
|
59 | 63 | ### DNS Proxy
|
60 | 64 |
|
61 |
| -1. After completing the **Security Policies** values, select the **Next: DNS Proxy** to see the **DNS Proxy** screen. |
62 |
| - |
63 |
| - :::image type="content" source="media/palo-alto-create/palo-alto-dns-proxy.png" alt-text="Screenshot of the DNS Proxy in the Palo Alto Networks create experience."::: |
64 |
| - |
65 |
| -1. Select the checkbox **DNS Proxy** to indicate **Disabled** or **Enabled**. |
66 |
| - |
67 |
| -### Tags |
68 |
| - |
69 |
| -You can specify custom tags for the new Palo Alto Networks resource in Azure by adding custom key-value pairs. |
70 |
| - |
71 |
| -1. Select Tags. |
72 |
| - |
73 |
| - :::image type="content" source="media/palo-alto-create/palo-alto-tags.png" alt-text="Screenshot showing the tags pane in the Palo Alto Networks create experience."::: |
74 |
| - |
75 |
| -1. Type in the **Name** and **Value** properties that you need. |
76 |
| - |
77 |
| - | Property | Description | |
78 |
| - |----------| -------------| |
79 |
| - |**Name** | Name of the tag corresponding to the Azure Palo Alto Networks resource. | |
80 |
| - | **Value** | Value of the tag corresponding to the Azure Palo Alto Networks resource. | |
| 65 | +1. After you configure the **Security Policies** values, select **Next** to go to the **DNS Proxy** tab. |
81 | 66 |
|
82 |
| -### Terms |
| 67 | + :::image type="content" source="media/palo-alto-create/palo-alto-dns-proxy.png" alt-text="Screenshot of the DNS Proxy tab of the Create Cloud NGFW page." lightbox="media/palo-alto-create/palo-alto-dns-proxy.png"::: |
83 | 68 |
|
84 |
| -Next, you must accept the Terms of Use for the new Palo Alto Networks resource. |
| 69 | +1. Under **DNS Proxy**, select either **Disabled** or **Enabled**. |
85 | 70 |
|
86 |
| -1. Select Terms. |
| 71 | +### Tags tab (optional) |
87 | 72 |
|
88 |
| - :::image type="content" source="media/palo-alto-create/palo-alto-terms.png" alt-text="Screenshot showing the terms pane in the Palo Alto create experience."::: |
| 73 | +You can optionally create tags for your resource. |
89 | 74 |
|
90 |
| -1. Select the checkbox **I Agree** to indicate approval. |
| 75 | +### Terms tab |
91 | 76 |
|
92 |
| -### Review and create |
| 77 | +Next, you must accept the terms of use for the new Cloud NGFW resource. |
93 | 78 |
|
94 |
| -1. Select the **Next: Review + Create** to navigate to the final step for resource creation. When you get to the **Review + Create** page, all validations are run. At this point, review all the selections made in the Basics, Networking, and optionally Tags panes. You can also review the Palo Alto and Azure Marketplace terms and conditions. |
| 79 | +1. Select the **Terms** tab. |
95 | 80 |
|
96 |
| -1. After reviewing all the information, select **Create**. Azure now deploys the Cloud NGFW by Palo Alto Networks. |
| 81 | + :::image type="content" source="media/palo-alto-create/palo-alto-terms.png" alt-text="Screenshot showing the Terms tab of the Create Cloud NGFW page." lightbox="media/palo-alto-create/palo-alto-terms.png"::: |
97 | 82 |
|
98 |
| -## Deployment completed |
| 83 | +1. Select the **I Agree** box to indicate your acceptance. |
| 84 | +1. Select **Next** to go to the final step of creating the resource. |
99 | 85 |
|
100 |
| -1. Once the create process is completed, select **Go to Resource** to navigate to the specific Cloud NGFW by Palo Alto Networks resource. |
| 86 | +### Review + create tab |
101 | 87 |
|
102 |
| -1. Select **Overview** in the service menu to see information on the deployed resources. |
| 88 | +[!INCLUDE [review-create](../includes/review-create.md)] |
103 | 89 |
|
104 | 90 | ## Next steps
|
105 | 91 |
|
106 |
| -- [Manage the Palo Alto Networks resource](manage.md) |
| 92 | +- [Manage the Cloud NGFW resource](manage.md) |
107 | 93 |
|
108 |
| -- Get Started with Cloud Next-Generation Firewall by Palo Alto Networks on |
| 94 | +- Get started with Cloud NGFW on: |
109 | 95 |
|
110 | 96 | > [!div class="nextstepaction"]
|
111 | 97 | > [Azure portal](https://portal.azure.com/#view/HubsExtension/BrowseResource/resourceType/PaloAltoNetworks.Cloudngfw%2Ffirewalls)
|
|
0 commit comments