In our organization, we use the product "PA 3220" for Security and NAT policy configuration to block unwanted traffic. We can create different zones in our network, such as trusted, untrusted, DMZ. advance threat protection, and anti-malware protection.
We can create site-to-site and remote site VPNs as per users' requests. With the help of the SP3 engine, we can allow traffic with a high level of performance. We are able to configure the high availability as Active-Active or Active-Passive to load balance the traffic on the firewall interface. A vulnerability assessment is also done.
All the applications are classified on the basis of their features and functions.
The Sp3 Engine has helped us. Whenever any packet comes to the Palo Alto then a parallel process and single-pass activity are there. A fast packet forwarding mechanism is used here.
Single-pass traffic processing enables very high throughput and low latency. Single-pass software and parallel processing hardware are completely unique in network security.
We take advantage of a user behavior monitor and threat protection.
The Sp3 Engine is helpful. Single Pass software and Parallel Processing hardware are completely unique in network security.
This significantly reduces the amount of processing overhead required to perform multiple functions in one security device.
SP3 engine is most suitable for Next-Generation Firewalls.
All the features are good here as compared to other Next-Generation firewalls, however, some steps of configuration are complex and require hiring experienced staff. The cost is still high and licensing is still complex.
The current version Pan OS v10.0 is a more stable version now - most of the bugs and issues are fixed.
There's no need to add any points from my side about this product. It's a very good Next-Generation Firewall in our current environment.
I've used the solution for around the last three years.