What is our primary use case?
Generally, the solution is used as a perimeter-based firewall with a secondary firewall covering the servers.
How has it helped my organization?
Benefit wise with the speed of deep packet inspection, we've found it will assist with a quicker resolution to a potential false-positive alert. You're able to drill down. It's a third to probably 75% faster than a lot of the other premier firewalls on inspections. Therefore, your root cause analysis will then come to a resolution quicker. It's all about speed.
What is most valuable?
The deep inspection functionality is great.
The solution scales well.
As long as the solution is kept updated, it's pretty stable.
The solution provides a lot of value to the client.
What needs improvement?
The licensing cost is a typical complaint with many clients. The solution is expensive.
In terms of automation, they could get better with it, especially with third-party integration. There are not too many products that will integrate with ease to the Palo Alto product set. They keep things locked down quite hard, which technically is also a benefit. That said, third-party integration definitely would be a benefit to us, as most of our implementations are two or even three different firewalls. Having third-party tools that integrate with all three or all two other products would be a benefit.
For how long have I used the solution?
I've used the solution since it came out, about seven years ago.
What do I think about the stability of the solution?
The stability of the product has to be put into a relative context. If people keep it upgraded and maintained, there are generally no issues. If they let it fall behind and we have to do a catch-up or leapfrog versions then there could be other complexities.
What do I think about the scalability of the solution?
The solution is scalable. If a company puts in at the right requirements and they double it by 50%, which you should always do, then there is lots of headroom until the next refresh cycle.
Any type of company can leverage the solution, from smaller organizations to very large enterprises. The main difference is if there's a higher security environment, the solution requires more attention. However, it has the capability to handle any size of setup.
How are customer service and support?
I've never directly spoken with technical support and therefore cannot speak to how helpful or responsive they are.
How was the initial setup?
The solution is complex due to the fact that the salespeople from Palo Alto, or even from my firm will say, oh, we can just use this import wizard. However, that works to about a 60% level, and it does not do a complete import of Fortinet to Palo Alto or Cisco to a Palo Alto or Check Point to a Palo Alto.
That's where the complexity comes in. The customer thinks it's going to be easy. The salespeople said it's going to be easy. However, it really is not.
The time it takes to implement the solution is a hundred percent dependent upon the requirements of the solution. I've had firewalls taking six months to implement in a large retail environment and I've had also firewalls where you walk in and they give you just outbound requirements, and boom, it's up and out in two hours. That's why it really depends upon the complexity of the requirements.
What's my experience with pricing, setup cost, and licensing?
The cost of the product is quite high.
I deal in list price. I don't get into discounting due to the fact that I do everything on a solution based on the list price. I have seen super heavy discounts from Palo Alto, however.
The licensing for Palo Alto is very straightforward. They include a lot in their base license. However, there may be features in there that are included and are buried in the base licensing cost that the customer will never use.
What other advice do I have?
We're partners with Palo Alto.
I'm dealing with all different versions of the solution and not necessarily just the most recent version. While most of what we work with is on-prem, many people are now moving to the cloud.
I would advise those considering the solution to ensure that they have a knowledgeable installer. That is critical. Most of ours that we take over are watched installs.
I rate the product at a nine out of ten. From a security/cost-benefit perspective, it's one of the best.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner