Call a Specialist Today! 844-294-0778
VM-Series
Secure AWS, Azure, and Google Cloud workloads with the same ML-powered NGFW protection used on-premises. One policy framework. One management console. Any cloud.
Request a quote Download datasheet
VM-Series virtual firewalls deliver the same PAN-OS capabilities as PA-Series hardware appliances in a software form factor. Organizations maintain one policy framework across on-premises and cloud environments instead of managing separate security systems.
App-ID, Content-ID, User-ID, and WildFire run identically in VM-Series, providing the same application visibility and threat prevention available on PA-Series hardware.
Software NGFW Credits allow elastic scaling from 2 to 64 vCPUs, with on-demand allocation of security services and management capabilities across deployments.
Panorama and Strata Cloud Manager provide unified policy management across VM-Series and hardware firewalls from a single console.
Capabilities
Native cloud security operates at Layer 4. VM-Series provides Layer 7 application inspection, advanced threat prevention, and consistent policy enforcement across every environment.
Get complete Layer 7 inspection. Stop lateral movement of threats. Enforce trust zones and secure allowed traffic between microsegments.
Replace the complexity of tool sprawl with a centralized command center and single, unified security fabric.
Secure at the speed of business. Automatically scale up and scale down to meet real-world traffic needs.
Hybrid Cloud Security
A consistent security architecture spanning on-premises and cloud eliminates the complexity of managing separate systems for each environment. Three components deliver a unified security posture.
PA-400 or PA-1400 Series secures headquarters, branch offices, and users with ML-powered threat prevention.
View PA-SeriesVM-Series secures applications and workloads in AWS, Azure, and Google Cloud with the same PAN-OS policy framework used on-premises.
View capabilitiesPanorama or Strata Cloud Manager provides single-console policy management, logging, and reporting across both environments.
View Strata Cloud ManagerCloud provider security controls address basic network filtering. VM-Series provides the application-level inspection and consistent policy enforcement required for enterprise security and compliance.
Cloud provider firewalls operate at Layer 4, filtering by port and protocol. VM-Series inspects at Layer 7, identifying applications regardless of port, protocol, or encryption.
Detect threats hidden within allowed application traffic that Layer 4 controls cannot see.
Separate policy frameworks for on-premises and cloud create operational overhead and security gaps. VM-Series uses the same PAN-OS rules and objects used on PA-Series hardware.
Replicate existing on-premises security policies to the cloud without rebuilding from scratch.
PCI DSS, HIPAA, and SOC 2 require documented, consistent security controls. VM-Series extends the same certified protection used on-premises into cloud environments.
Maintain a unified compliance posture across hybrid infrastructure.
VM-Series addresses common cloud security requirements across migration, remote access, and branch connectivity use cases.
Lift-and-shift workloads to AWS, Azure, or GCP while maintaining existing security policies. VM-Series provides the same protection in the cloud, eliminating the need to redesign security architecture during migration.
Discuss migrationSegment and inspect traffic in Azure Virtual Desktop and Citrix VDI environments. VM-Series prevents lateral movement between virtual desktops and enforces user-based access policies.
Discuss VDI securityDeploy VM-Series as a virtual hub in the cloud to connect branch offices, data centers, and SaaS applications securely. Hub-and-spoke or full mesh architectures are supported.
Discuss SD-WANVM-Series deploys across all major public clouds, hypervisors, and software-defined networking environments.
Technical datasheets, deployment guidance, and sizing tools for VM-Series virtual firewalls.
Calculate the number of Software NGFW Credits needed based on vCPU count, throughput requirements, and security services.
Request custom sizingTry VM-Series free for up to 30 days on AWS, Azure, VMware ESXi, or Linux KVM environments.
Start free trialRecommended products
Advanced Threat Prevention, WildFire, DNS Security, URL Filtering, and Enterprise DLP available as add-on subscriptions for VM-Series deployments.
View security servicesContainer-native firewall for Kubernetes environments, providing Layer 7 visibility and threat prevention across container traffic.
View CN-SeriesML-powered hardware appliances for branch offices, campuses, and data centers. Pair with VM-Series for consistent hybrid cloud security.
View PA-SeriesEvaluate VM-Series for specific cloud environments, discuss hybrid deployment architecture, or request custom credit sizing based on throughput and vCPU requirements.