What’s your mean time to secure?
Your team just found a workload that was pushed to the cloud without security review, and it’s collecting information from your customers.
You need to secure that application and shield the rest of your network from the application, and do it fast.
Start the clock
Fortunately, software firewalls from Palo Alto Networks can rapidly discover, protect and monitor cloud applications. You get uniform visibility and strong security, regardless of environment.
STEP 1: DISCOVER
Import applications and networks from the public cloud
First, the firewall SaaS management console collects and analyzes the application’s network, traffic, and DNS logs.
Discovery is fast, accurate, and safe because the console only needs read permissions to connect to the cloud API.
STEP 1: DISCOVER
Full visibility, automatically and persistently
Discovery gives you full network-level visibility. This includes applications, inbound user connections, and traffic between workloads and outbound to the Internet.
You’re relieved to see this app looks simple. The AI apps you've been securing recently rely on models and datasets. But this app has only made connections to its update server.
STEP 2: PROTECT
Add a firewall in just a few clicks
Software firewall deployment is simple. You click the “plus” icon to protect traffic flows between the application, the Internet, the users, and the other applications in your network.
The result is a custom Terraform module to install a software firewall in the right location based on your specifications.
STEP 2: PROTECT
Stop inbound attacks
For most firewalls, if you don’t know what software an app is running, it is tricky to build a policy.
For Palo Alto Networks software firewalls, it’s easy. Advanced Threat Protection (ATP) and Advanced Wildfire (AWF) anti-malware keep the app safe, regardless of what service, version or protocols it’s using.
STEP 2: PROTECT
Stop outbound exposure
For outbound protection, there’s no need to build time-consuming, traditional “allow lists.”
Advanced DNS Security (ADNS) and Advanced URL Filtering (AURL) prevent the app from connecting to malicious sites like command and control (C2) or compromised update repositories.

STEP 2: PROTECT
Stop east-west attacks inside the perimeter
It’s not enough to protect the workload. If an attacker is already inside, you need to protect the data and the rest of your network.
Palo Alto Networks software firewalls work inline to detect and block attacks, so you can deploy them between applications. This stops lateral spread, and lets east-west connections flow quickly and safely.
STEP 2: PROTECT
Smarter security, powered by Precision AI™
With Palo Alto Networks software firewalls, even Zero Day threats are blocked to keep applications and users safe.
AI-powered inline inspection and Zero Trust principles protect each app, and protect applications from each other.
STEP 3:
Monitor continuously and effortlessly
In an environment that changes as often as cloud, it's not enough just to protect each app. Palo Alto Networks software firewalls connect natively to each cloud to monitor the entire network for any new endpoints that might need protection.
Looking good so far
Now the application and sensitive customer information are protected. You have quickly:
- Discovered the app to identify its behavior and connections
- Protected the app and its data from attack
- Established continuous monitoring to track the app and network to avoid future surprises
STEP 4: GETTING AHEAD
Flexible credits enable flexible deployments
You can deploy firewalls when and where you need them because the licensing model is as agile as the firewall deployment.
New firewalls automatically pull from your credits pool, and return the credits when you decommission them. This lets you focus on the problem, not the procurement.
Congratulations!
In no time flat, you’ve secured an unknown app on your company’s cloud tenancy. Then you got ahead of any security surprises by finding other potential problems.
With what you’ve accomplished, you feel like you didn’t just beat the bad guys: you also beat the clock.
There’s only one thing left to do.
Any app.
Any network.
Any cloud.
Secured.
Rest easy knowing Palo Alto Networks software firewalls are there to secure your:
- AI, non-AI, cloud-native and lift-and-shift apps
- Containerized and VM workloads
- Public and private cloud environments
Your network is protected against both foundational network threats and novel AI attacks. It’s enough to make you feel like a sweepstakes winner.
GET STARTED