It is used for protection against attacks and it is very fast and reliable. We have a lot of use cases for it.
Technical Manager at PSR
Machine learning and sandboxing are what differentiate this product from competitors
Pros and Cons
- "The sandboxing is valuable and they are frequently updating their signature database. We get new updates every five minutes. That makes it easy to detect new and unknown attacks."
- "Palos Alto's firewalls have machine learning software and sandboxing, and everything is one step ahead of all the competitors."
- "The configuration part could be improved. It's very difficult to configure. It doesn't have a user-friendly interface. You have to know Palo Alto deeply to use it."
What is our primary use case?
How has it helped my organization?
We are an implementation partner for Palo Alto. One of the companies we implemented its Next-Generation Firewalls for was previously using Barracuda. A ransomware attack happened and they lost all their backup data, and their configuration. Once we implemented Palo Alto for them, there were similar attacks but they were blocked.
Along with Prisma, it helps in preventing a lot of attacks, especially Zero-day attacks.
What is most valuable?
The sandboxing is valuable and they are frequently updating their signature database. We get new updates every five minutes. That makes it easy to detect new and unknown attacks.
What needs improvement?
The configuration part could be improved. It's very difficult to configure. It doesn't have a user-friendly interface. You have to know Palo Alto deeply to use it.
Also, it doesn't support open-source protocols like EIGRP. We had to find another solution for that.
Buyer's Guide
Palo Alto Networks NG Firewalls
September 2026
Learn what your peers think about Palo Alto Networks NG Firewalls. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
914,351 professionals have used our research since 2012.
For how long have I used the solution?
I've been using Palo Alto Networks NG Firewalls for the last six years.
What do I think about the stability of the solution?
Palo Alto suggests version 9.1.7 for stability. When new features come out, things are not as stable.
What do I think about the scalability of the solution?
It's scalable. I recommend it for its scalability.
We generally deploy these firewalls into larger environments, but the PA-400 series is affordable.
How are customer service and support?
There are problems with the technical support. When we are facing an attack, it's very difficult to get a hold of people from the TAC. It's not like Cisco, especially in India. There are very few members of Palo Alto TAC in India. Sometimes we get support from people in other countries.
How was the initial setup?
The initial deployment of these firewalls is very complex. The registration is a very difficult task. You have to go to the partner portal to register and it's not user-friendly. All the other solutions are not like that. With Juniper, for example, it's very easy to handle their portal.
The deployment time depends on the customer environment but it normally takes around three weeks. Our implementation strategy is to first understand the network we are dealing with and how we can deploy Palo Alto.
What's my experience with pricing, setup cost, and licensing?
The pricing for Palo Alto is very high. The price difference with other vendors is huge because Palo Alto has been the market leader for the last five or six years, and they have a reliable product. Everybody knows Palo Alto, like Cisco routing and switching. It's likely that only enterprise-level customers can afford this kind of firewall.
Which other solutions did I evaluate?
Palos Alto's firewalls have machine learning software and sandboxing. Everything is one step ahead of all the competitors.
Still, almost all vendors provide the same things. They call their technologies by different names, but that's the only big difference in features.
What other advice do I have?
According to the industry reviews Palo Alto has been the market leader for the last five or six years. They have better technology and the hardware is also good. It's the pricing and user interface where there are issues. Apart from them, everything is fine.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Manager IT Security & Infrastructure at Currimjee Jeewanjee & Co. Ltd.
Gives us visibility and reporting that we didn't have, improving our ability to monitor and secure our network
Pros and Cons
- "You can easily integrate it with Active Directory, and you can use the GlobalProtect VPN for internal and external purposes. The URL Filtering is also clear and the application filtering is a plus. The application filtering is much better when you compare it to FortiGate or other firewall vendors."
- "We have complete visibility through the logs and the alerting."
- "There has been a recent change in the graphical interface. For the monitoring part, they could have a better UI."
What is our primary use case?
We have implemented our own private cloud where we host different services for a number of internal companies that are part of a group. We have financial companies, hospitality, and construction companies; a large variety. We use Palo Alto to provide security protection for all these companies.
How has it helped my organization?
Previously, with our old firewalls, we did not have any visibility. The application layer was zero. We didn't have any visibility there. And we also didn't have any reports. Now, we have good visibility and we are able to get reports and we can monitor the network much better. That's a big change for us and a big help.
What is most valuable?
There are a lot of helpful features
- monitoring
- reporting
- WiFi.
You can easily integrate it with Active Directory, and you can use the GlobalProtect VPN for internal and external purposes. The URL Filtering is also clear and the application filtering is a plus. The application filtering is much better when you compare it to FortiGate or other firewall vendors.
Also, the fact that Next-Gen Firewalls from Palo Alto embed machine learning in the core of the firewall to provide inline and real-time attack prevention is very important. Nowadays, all the modern attacks, hackers, and bad people are becoming more intelligent and automating attacks. Embedding AI is a good idea.
We have complete visibility through the logs and the alerting. It depends on how you configure the firewall. You can configure it to get alerts whenever there's an attack or whenever something is happening. That's how we can assess if the firewall is doing the job correctly or not. We are happy with the way the firewall does its job.
What needs improvement?
There has been a recent change in the graphical interface. For the monitoring part, they could have a better UI.
For how long have I used the solution?
We have been using Palo Alto Networks NG Firewalls since 2012.
What do I think about the stability of the solution?
The big firewalls, like the PA-300 and the PA-3020, are very good, stable, and performant. They are very reliable. The smaller models are reliable, but the performance on their management plane is a bit slow. Even the management plane of the PA-850 is a bit slow when you compare it to some of the bigger models.
What do I think about the scalability of the solution?
Scaling is easy. We currently have about 1,000 endpoints.
How are customer service and support?
We haven't worked with their technical support.
Which solution did I use previously and why did I switch?
We replaced a Cisco ASA Firewall with Palo Alto, and then we started replacing all our other firewalls with Palo Alto. Cisco ASA was not a next-generation firewall at that time. And no firewall could beat the traffic monitoring and the visibility that we had on Palo Alto.
We did a PoC before going to Palo Alto. We placed the Palo Alto in virtual wire mode, meaning a transparent mode. Without changing our existing network infrastructure, we were able to plug the Palo Alto into our network where we could see all the incoming and all the outgoing traffic. Without creating any policies or any blocking, we were able to see all the traffic and we were impressed with that part and we decided to switch to Palo Alto.
How was the initial setup?
The first deployment was very complex. I was not the one who implemented it, it was an integrator, but it was a headache due to some difficulties. After that, things became easy. We have implemented six or seven Palo Altos, and things are easy because of our familiarity with the whole deployment process. The first time we were using this firewall we were not at ease with the product. After that, we got used to it and it became easier.
Because of the issues with the first one, it took one week for the deployment, for the complete transition from Cisco ASA to Palo Alto. Since then, all the deployments have been done in one day.
What was our ROI?
We have seen ROI as a result of the visibility and reporting. These are two things we didn't have, and now that we have the visibility, we can ensure that our network is secure.
What's my experience with pricing, setup cost, and licensing?
If you compare Palo Alto with other firewalls, it's a bit expensive.
Which other solutions did I evaluate?
At that time, Palo Alto was the leader and I think it was the only next-gen firewall.
We have looked into other firewalls since then. In 2017 or 2018, we decided to replace one Palo Alto with a Forcepoint Next-Gen Firewall. We placed that in the network but, after six months, we replaced it with Palo Alto.
What other advice do I have?
If someone is looking for the cheapest and fastest firewall, I would say the fastest is good, but not cheapest. Palo Alto Firewalls are not cheap.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Palo Alto Networks NG Firewalls
September 2026
Learn what your peers think about Palo Alto Networks NG Firewalls. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
914,351 professionals have used our research since 2012.
Presales Specialist at a tech services company with 1-10 employees
Embedded machine learning reduces manual work of having to search for attacks in a SIEM
Pros and Cons
- "DNS Security is a good feature because, in the real world with web threats, you can block all web threats and bad sites. DNS Security helps to prevent those threats. It's also very helpful with Zero-day attacks because DNS Security blocks all DNS requests before any antivirus would know that such requests contain a virus or a threat to your PC or your network."
- "If you need really reliable hardware and software, and don't want headaches after the implementation, just buy Palo Alto."
- "The only area I can see for improvement is that Palo Alto should do more marketing."
What is our primary use case?
We have had a couple of big projects with government companies here in Ukraine. One of those projects involved three data centers with a lot of security and network requirements, and we implemented Palo Alto as part of this project.
The use case was to build the new data centers with a firewall that would not only work on the perimeter but also for internal traffic. We deployed eight PA-5200 Series firewalls and integrated them with VMware NSX, and they're working together.
How has it helped my organization?
One of the points that helped us win the tender is that Palo Alto NG Firewalls embed machine learning in the core of the firewall to provide inline, real-time attack prevention. The customer's security team was asking for this feature from the firewalls because machine learning makes things much easier than manually sitting there with some kind of SIEM and searching for all kinds of attacks and critical issues. The machine learning is really helpful because it's doing the work automatically.
What is most valuable?
We had a small project with the PA-800 Series appliance where we implemented DNS Security. DNS Security is a good feature because, in the real world with web threats, you can block all web threats and bad sites. DNS Security helps to prevent those threats. It's also very helpful with Zero-day attacks because DNS Security blocks all DNS requests before any antivirus would know that such requests contain a virus or a threat to your PC or your network.
In general, Palo Alto NG Firewalls are
- easy to manage
- good, reliable appliances
- easy to configure.
They also have a good balance between security and traffic. They have good hardware and, for management, they have their own data plane. If traffic is really overloading the data plane, you still have the ability to get into the management tools to see what's going on. You can reset or block some traffic. Not all firewalls have that feature.
They have really good clients, such as a VPN client. You can also enforce security standards on workers in the field. It's a really good product. And now, for endpoint security, they have Cortex XDR. You use the same client, but with additional licenses that enable more features.
What needs improvement?
The only area I can see for improvement is that Palo Alto should do more marketing.
For how long have I used the solution?
We work with customers, but we are not using the solution ourselves.
What do I think about the scalability of the solution?
The scalability is really good because they have a chassis version of appliances. They plan to build new chassis. But for the really big projects here in Ukraine, we can easily cover what we need with the PA-8000 Series with Palo Alto chassis appliances.
In our project with the three data centers, each data center was able to process 40 gigs.
How are customer service and support?
First-level support is provided by our distributor Bakotech. They are technical guys and they really know the product. Unlike some support providers who just send you manuals to ready, they're really helpful. You can call them at any time and they get back to you shortly and help.
How was the initial setup?
The initial setup is really easy. If you're working with Palo Alto Panorama, which is their management server, it's very easy to deploy a lot of appliances in a couple of days, because you're just sending out the configuration and templates on a blind device. In a couple of hours that device is working like the rest.
Which other solutions did I evaluate?
Another valuable aspect of Palo Alto NG Firewalls is that the appliances and software are really reliable in terms of stability and performance. Some firewall vendors don't write real information on their datasheets and, after implementing them, you see that the reality is not the way it was described. For example, when it comes to threat prevention and how much traffic appliances can handle, there was a project where we beat another vendor's firewall because Palo Alto has the real information on its datasheets.
I have some experience with Cisco, on a small project but there was a somewhat older software version, and there was a lot of lag. When changing something in the configuration, once you pushed "commit" you could go have a coffee or do other stuff for 20 minutes or more, because it took a really long time to push that configuration to the device.
What other advice do I have?
If a colleague at another company said to me, "We're just looking for the cheapest and fastest firewall," I would tell them that the cheapest is not the best. If you need really reliable hardware and software, and don't want headaches after the implementation, just buy Palo Alto.
The PA-400 is really strong and not only for SOHO or SMB companies. They have a really big throughput with Threat Prevention and DNS Security enabled. It's a really good appliance in a small size. But it's not only for small companies. The PA-460 can easily handle the traffic of a midsize company, one with 100 or 200 employees, and maybe even a little more. The PA-460 can handle about 5 gigs of traffic. With Threat Prevention, they can handle 2.5 gigabytes of traffic. For a regular office, that's good. It might be a little small for big companies.
Regarding DS tunneling, it is mostly peer-type attacks. With tunneling, it depends on what type of tunneling is used. You need to look at the specific case, at things like whether it was an internal DNS tunnel or one from the outside to the inside between branches. Most of the time, you can see that kind of traffic with a firewall if you have enabled full logging and you drop the logs into a good SIEM, like ArcSight or others. You will see the anomaly traffic via tunnels. You can also switch on decryption so you can decrypt a tunnel and see what is going on inside.
We have had no issues from our customers who are working with Palo Alto NG Firewalls. They fully cover all our customers' needs.
Disclosure: My company has a business relationship with this vendor other than being a customer. Integrator
Security Team Technical Manager at ECCOM Network System Co., Ltd.
Its unified platform effectively reduces the workload on networks and security tools
Pros and Cons
- "Palo Alto NGFW’s unified platform has helped our customers eliminate security holes. With a unified platform, customers can deploy the NG Firewall both in the data center edge, inside the data center, and in the product/public cloud environments. They have the same user interfaces and platform, so they can be maintained by a single unified platform called Panorama. Customers can use Palo Alto Network NG Firewalls in all the places where they need to protect their environments. This helps to decrease security holes."
- "Palo Alto NGFW provides a unified platform that natively integrates all security capabilities."
- "Over the past one or two years, Palo Alto Networks has added a lot of features into the NG Firewall products. I think this is becoming more complicated for our customers. Therefore, we could use some best practices, best practice tools, and implementation guides for some of the complicated features."
What is our primary use case?
The solution is more towards the front of the security stack.
We use both AWS and Alibaba Cloud.
How has it helped my organization?
The single pass architecture has helped a lot in the implementation and maintenance of Palo Alto Networks. It changed the customer's opinion on UTM platforms. In the past, when customers used UTM platforms, they feared the security features would impact the performance and slow down the network, causing some instability. However, with the single pass architecture, Palo Alto has demonstrated that you can use a lot of the security features without having an impact on the security and network performance. Therefore, most of our customers will dare to use most of Palo Alto Networks' security features.
What is most valuable?
- Application identification
- Antivirus
- Vulnerability protection
- URL filtering
- SSL VPN
- IPsec VPN
Palo Alto NGFW provides a unified platform that natively integrates all security capabilities. Most of our customers are busy. They cannot afford the time to learn very complicated user interfaces and configuration procedures. With Palo Alto Networks, they offered a unified user interface for all its NG Firewall products and Panorama. I think it reduces some of our customers' maintenance time.
Palo Alto NGFW’s unified platform has helped our customers eliminate security holes. With a unified platform, customers can deploy the NG Firewall both in the data center edge, inside the data center, and in the product/public cloud environments. They have the same user interfaces and platform, so they can be maintained by a single unified platform called Panorama. Customers can use Palo Alto Network NG Firewalls in all the places where they need to protect their environments. This helps to decrease security holes.
What needs improvement?
Over the past one or two years, Palo Alto Networks has added a lot of features into the NG Firewall products. I think this is becoming more complicated for our customers. Therefore, we could use some best practices, best practice tools, and implementation guides for some of the complicated features.
For how long have I used the solution?
I have been using it for eight years, though my company does not use it.
What do I think about the stability of the solution?
Compared to its competitors, the stability of NG Firewalls is very good. We have faced some strange problems with the hardware platform or operating system. Most of these customer cases come from complicated configs and bugs. However, stability is very good overall.
What do I think about the scalability of the solution?
Scalability is not that good. Palo Alto Networks NG Firewalls product is for middle-sized and small businesses. It has fixed parts and capacities for processing. Some of their higher-end products have the scalability to expand capacities, but only a few customers can afford their larger product.
How are customer service and technical support?
I would rate it as eight to nine out of 10. Most of the technical engineers, who provide support for our customers, are efficient. There are one or two Tier 1 tech support engineers who often don't have answers.
Which solution did I use previously and why did I switch?
Palo Alto NGFW’s unified platform has helped to eliminate multiple network security tools and the effort needed to get them to work together with each other. Before using Palo Alto Networks NG Firewalls, customers might need to implement Layer 4 firewalls, IPS and possibly an antivirus, gateways, and maybe web proxies for all their devices. With Palo Alto NGFW’s unified platform, if a customer can do all the config and security policies on one platform, then this will merge all their security things onto a single platform.
How was the initial setup?
The initial setup is not complex; it is straightforward. Our users only need a cable and some basic steps to configure the management interface. Then, it can set up the NG Firewall and ensure that the network and routing are working as expected in the environment. I think its steps are easier than most of its competitors. The initial setup takes one or two hours.
The full setup time depends on the features, then whether the environment or customer needs are complicated or not.
What about the implementation team?
For our implementation strategy, we talk to our customers and work out documents for all their configs, which includes basic information that we need to know for implementing the firewall. Then, we follow the documents and do the implementation. We also may modify some content of the documents as the project processes.
It needs one or two employees with enough skills to manage and maintain it. They may need to modify firewalls, firewalls security rules, and possibly inspect alerts that are generated from firewalls.
What was our ROI?
By having a customer operate on a unified platform, they can do the application control, traffic control, threat protection, and URL filtering on a single platform. This effectively reduces the workload on all their networks and security tools.
Cheap and faster are the opposite sides of security. Security inspections have some technical and money costs. If you just purchase some cheap, fast firewalls, then you will lose a lot of the security features and fraud protection capabilities.
Which other solutions did I evaluate?
My company uses Cisco Firepower NGFW Firewall, not Palo Alto Networks NG Firewalls. We started our cooperation with Cisco a lot longer than with Palo Alto Networks. We have been working with Cisco to expand their business in China for more than 20 years, which is why the leaders in our company might be choosing Cisco products.
Most of our customers have been using Palo Alto Networks for a long time and do not want to change to another vendor. The unified user interface is a big benefit for them.
Palo Alto NGFW’s DNS Security is an effective way to detect and block DNS tunneling attacks, because most competitors do not have these techniques to detect the DNS tunneling on a single device. They require maybe a SIM or some analysts. So, this is something quite creative for Palo Alto Networks.
What other advice do I have?
For our customers, I would tell them that Palo Alto Networks NG Firewalls is easy to use, but probably difficult to master. It has a very easy to use interface and configuration utility, but it has a lot of advanced features that need some deep knowledge of the product.
No product can guarantee 100% evasions being blocked, but I think Palo Alto is among the top of the threat inspection vendors. From the NSS Labs Test Report, we can see that Palo Alto Networks always has a top score.
Machine learning in a single firewall is not that accurate or important for our customers. Since it will only see some network traffic, it cannot connect everything together, like endpoints and servers. Therefore, our customers do not value the machine learning techniques on a single firewall very much.
We may review the alerts generated by machine learning modules, then we can see if the alerts are real alerts, not false positives. This may tell us how efficient machine learning is.
Very few customers in China have used the Palo Alto NGFW’s DNS Security module. It is a new feature that was introduced only two years ago. Customers already know what the product can provide in terms of protection. Its DNS Security provides something that is not really easy to understand. Also, it increases the cost of the firewall because it requires another license to be implemented, and the cost is not low.
DNS Security is very impressive, and I think it will be an efficient way to block the rapidly changing threat landscape and maybe Zero-day attack methods.
Biggest lesson learnt: If you want to protect something, you need to gain visibility of the entire network. NG Firewalls provides a deep visibility into network traffic.
I would rate Palo Alto Networks NG Firewalls as nine out of 10.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
Senior Network Engineer at a tech services company with 201-500 employees
Combines many tools in one appliance, giving us a single point of view for our firewall and all related security issues
Pros and Cons
- "The most valuable features include the different security zones and the ability to identify applications not only by port numbers but by the applications themselves... And with the single-pass architecture, it provides a good trade-off between security and network performance. It provides good security and good network throughput."
- "With Palo Alto NG Firewalls, we can pass all compliance requirements; we trust it and we are building the security of our environment based on it, and we feel that we are secure in our network."
- "The machine learning in Palo Alto NG Firewalls for securing networks against threats that are able to evolve and morph rapidly is good, in general. But there have been some cases where we get false positives and Palo Alto has denied traffic when there have been new updates and signature releases. Valid traffic gets blocked. We have had some bad experiences with this. If there were an ability, before it denies traffic, to get some kind of notification that some traffic is going to be blocked, that would be good."
What is our primary use case?
We use it to segregate traffic between different tenant instances and to manage secure access to environments, DMZ zones, and to communicate what the firewall is doing.
How has it helped my organization?
With Palo Alto NG Firewalls, we can pass all compliance requirements. We trust it and we are building the security of our environment based on it. We feel that we are secure in our network.
It also provides a unified platform that natively integrates all security capabilities. It's very important because it gives us one solution that covers all aspects of security. The unified platform helps to eliminate security holes by enabling detection. It helps us to manage edge access to our network from outside sources on the internet and we can do so per application. It also provides URL filtering. The unified platform has helped to eliminate multiple network security tools and the effort needed to get them to work together with each other. In one appliance it combines URL filtering, intrusion prevention and detection, general firewall rules, and reporting. It combines all of those tools in one appliance. As a result, our network operations are better because we have a single point of view for our firewall and all related security issues. It's definitely a benefit that we don't need different appliances, different interfaces, and different configurations. Everything is managed from one place.
What is most valuable?
The most valuable features include the different security zones and the ability to identify applications not only by port numbers but by the applications themselves.
The DNS Security with predictive analytics and machine learning for instantly blocking DNS-related attacks works fine. We are happy with it.
And with the single-pass architecture, it provides a good trade-off between security and network performance. It provides good security and good network throughput.
What needs improvement?
The machine learning in Palo Alto NG Firewalls for securing networks against threats that are able to evolve and morph rapidly is good, in general. But there have been some cases where we get false positives and Palo Alto has denied traffic when there have been new updates and signature releases. Valid traffic gets blocked. We have had some bad experiences with this. If there were an ability, before it denies traffic, to get some kind of notification that some traffic is going to be blocked, that would be good.
In addition, there is room for improvement with the troubleshooting tools and packet simulator. It would help to be able to see how packets traverse the firewall and, if it's denied, at what level it is denied. We would like to see this information if we simulate traffic so we can predict behavior of the traffic flow, and not just see that information on real traffic.
For how long have I used the solution?
I have been using Palo Alto Networks NG Firewalls for about three years.
What do I think about the stability of the solution?
The solution is pretty stable.
What do I think about the scalability of the solution?
The scalability is good.
In terms of the extensiveness of use, it depends on business needs. Every communication from the company is going through this solution, so it's highly used and we are highly dependent on the solution.
In terms of increasing our use of the solution, it all comes down to business needs. If the business needs it, and we get to the limit of the current appliance, we will consider updating it or adding more appliances. At this point, we're good.
Which solution did I use previously and why did I switch?
We previously used Cisco. The switch was a business decision and may have had to do with cost savings, but I'm not sure what the driver was.
How was the initial setup?
The initial setup was a little bit complex, but not terrible. The complexity was not related to the product. It was more to do with needing to prepare and plan things properly so that in the future the solution will be scalable. If there were some predefined templates for different use cases, that would help. Maybe it has that feature, but I'm not familiar with it.
The time needed for deployment depends on the requirements. We also continuously optimized it, so we didn't just deploy it and forget it.
Our implementation strategy was to start with allowing less access and then allowing more and more as needed. We made the first configuration more restrictive to collect data on denied traffic, and then we analyzed the traffic and allowed it as needed.
We have less than 10 users and their roles are security engineers and network engineers. We have three to four people for deployment and maintenance and for coordinating with the business, including things such as downtime and a cut-over. The network and security engineers work to confirm that the configuration of the solution is meeting our requirements.
What about the implementation team?
We did it ourselves.
What's my experience with pricing, setup cost, and licensing?
I'm not sure about pricing. I don't know if Palo Alto NG Firewalls are cheaper or not, but I would definitely recommend Palo Alto as an option.
If you need additional features, you need additional licenses, but I'm not aware of the cost details.
Which other solutions did I evaluate?
We evaluated Cisco, Sophos, Dell EMC SonicWall, and FortiGate. Cost and reputation were some of the key factors we looked at, as well as the flexibility of configuration. Another factor was how many users could comfortably work on the solution when publicly deployed.
What other advice do I have?
The fact that Palo Alto NG Firewalls embed machine learning in the core of the firewall to provide inline, real-time attack prevention is important, but I still don't completely trust it. I haven't really seen this feature. Maybe it's somewhere in the background, but I haven't gotten any notifications that something was found or prevented. At this point, we still use traditional approaches with human interaction.
Overall, what I have learned from using Palo Alto is that you need to be very detailed in your requirements.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Network Administrator at a real estate/law firm with 201-500 employees
Handles all of our network traffic without impacting performance
Pros and Cons
- "The machine learning in the core of the firewalls, for inline, real-time attack prevention, is very important to us. With the malware and ransomware threats that are out there, to keep abreast of and ahead of those types of attacks, it's important for our devices to be able to use AI to distinguish when there is malicious traffic or abnormal traffic within our environment, and then notify us."
- "The way that the new hardware handles URL filtering, threat protection, and GlobalProtect has been pretty solid."
- "The SD-WAN product is fairly new. They could probably improve that in terms of customizing it and making the configuration a little bit easier."
What is our primary use case?
We use them to do quite a bit of URL filtering, threat prevention, and we also use GlobalProtect. And application visibility is huge for us. Rather than having to do port-based firewalling, we're able to take it to an application level.
How has it helped my organization?
We have quite a number of security pieces that are implemented for our network, such as a DNS piece, although we're not using Palo Alto for that purpose. But with that, in line with our seam, we're able to better distinguish what normal traffic looks like versus what a potential threat would look like. That's how we're leveraging the NG Firewalls. Also, we have separated the network for our databases and we only allow specific users or specific applications to communicate with them. They're not using the traditional port base, they're using application-aware ports to make sure that the traffic that has come in is what it says it is.
Machine learning in Palo Alto's firewalls, for securing networks against threats that are able to evolve and morph rapidly, has helped us out significantly, in implementation with different security software and processes. The combination allows our security analysts to determine the type of traffic that is flowing through our network and to our devices. We're able to collect the logs that Palo Alto generates to determine if there's any type of intrusion in our network.
What is most valuable?
The machine learning in the core of the firewalls, for inline, real-time attack prevention, is very important to us. With the malware and ransomware threats that are out there, to keep abreast of and ahead of those types of attacks, it's important for our devices to be able to use AI to distinguish when there is malicious traffic or abnormal traffic within our environment, and then notify us.
The fact that in the NSS Labs Test Report from July 2019 about Palo Alto NG Firewalls, 100 percent of the evasions were blocked, is very important to us.
What needs improvement?
The SD-WAN product is fairly new. They could probably improve that in terms of customizing it and making the configuration a little bit easier.
For how long have I used the solution?
I've been using Palo Alto NG Firewalls for about five years.
What do I think about the stability of the solution?
The firewalls are very stable. We've had no issues with downtime.
What do I think about the scalability of the solution?
They're very scalable. Because we use Panorama, we're able to have global firewall rules for areas that we want to block, across the network, for security reasons. We just push those down to all the devices in one shot.
Our corporate site has about 500 users, and our 14 remote sites, because they're retail, usually have anywhere from five to 10 users each.
How are customer service and technical support?
Their support is generally very knowledgeable. Sometimes it depends though on who you get, but they've always addressed our issues in a timely manner.
Which solution did I use previously and why did I switch?
We were using older versions of Palo Alto's firewalls and we also had Cisco firewalls in our environment.
How was the initial setup?
For our remote stores we're able to use Panorama, along with Palo Alto's Zero Touch Provisioning hardware. Once a device is connected to the internet and can communicate back to our Panorama, it just pulls the configurations. That means it's very easy to deploy.
It took about two to three months to deploy about 14 sites. That wasn't because we were having issues, it was just the way we scheduled the deployment, because we had to bring down different entities and had to schedule them accordingly with a maintenance window. But if it wasn't for that scheduling, within a week we could have deployed all of the remote sites.
For our implementation strategy, at our corporate site we had both old and new firewalls sitting side by side on the network. As we went to a remote site we would take them from their legacy Cisco and cut them over to the new firewall. Once that was done, we moved all of the firewall rules that were on the old firewall over to the new one.
When it comes to maintenance and administration of the firewalls, my team of five people is responsible. We have a network architect, a network specialist, two senior network specialists, and a security manager.
What about the implementation team?
We did it by ourselves. We have a certified Palo Alto engineer on staff and he did all the installation.
What's my experience with pricing, setup cost, and licensing?
Definitely look into a multi-year license, as opposed to a single-year. That will definitely be more beneficial in terms of cost. We went with five-year licenses. After looking at the overall costs, we calculate that we're only paying for four years, because it works out such that the last year is negligible. If we were to be billed yearly, the last year's costs would be a lot more. With the five-year plan we're saving about a year's worth of licenses.
Based on the quantity of devices we purchased, we found that the hardware price was actually cheaper than most of the other vendors out there.
If a colleague at another company were to say, "We are just looking for the cheapest and fastest firewall," given my experience with Palo Alto's NG Firewalls, my answer would depend on the size of the company and how much traffic they're going to be generating. Palo Alto is definitely not the cheapest, but if you scale it the right way it will be very comparable to what's out there.
Which other solutions did I evaluate?
One of the things we like about Palo Alto is the fact that the hardware appliances we have are not impacted in terms of resources. The CPU and memory stay low, so we don't have a bottleneck where it's trying to process a whole bunch of traffic and things are slow. We were looking at various brands because we were going from older hardware to newer, and we wanted to evaluate what the other vendors were doing. After that evaluation, we were comfortable that Palo Alto would be able to handle all of our network traffic without impacting performance.
We looked at Fortinet and Cisco. Cisco is a bit pricey when compared to our Palo Altos. Fortinet was definitely cheaper, but we were skeptical about their performance when we bundled all of the features that we wanted. We didn't think it was going to be fast enough to handle the network traffic that we were generating across the board. We believe Cisco would have handled our traffic, but their next-gen platform, along with SD-WAN, required us to have two separate devices. It wasn't something that would have been on one platform. That's probably why we didn't go down that road.
Part of what we considered when we were looking around was how familiar we were with the technology. That was also a big area for us. Most of the guys on our team were pretty familiar with Cisco and Palo Alto devices. They weren't too familiar with Fortinet or Check Point. We narrowed it down based on if we had a security breach, how easy would it be for us to start gathering information, remediating and troubleshooting, and looking at the origin of the threat. We looked at that versus having to call support because we weren't too familiar with a particular product. That was huge for us when we were doing the evaluation of these products.
What other advice do I have?
Other than the SD-WAN, everything else has been functioning like our previous setup because it's a pretty similar license. The way that the new hardware handles URL filtering, threat protection, and GlobalProtect has been pretty solid. I don't have any issues with those.
Overall, I would rate Palo Alto NG Firewalls at nine out of 10. It's definitely not the cheapest product out there. Cost is the main reason I wouldn't put it at a 10.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Director of Information Technology at a hospitality company with 10,001+ employees
A stable next-generation firewall solution
Pros and Cons
- "I like that they are more stable than the previous ones, and they allow a lot of other features."
- "It would be better to have more tools to control Palo Alto Networks NG Firewalls. We don't have too many tools to access Palo Alto. For example, the IT team doesn't have access to it. We can see it physically and see if it's running or not. We need to contact a special team to receive that information. I would also like to see more reporting in the next release."
- "It would be better to have more tools to control Palo Alto Networks NG Firewalls. We don't have too many tools to access Palo Alto."
What is our primary use case?
We use Palo Alto Networks NG Firewalls to manage the villains. Basically, to protect the environment.
What is most valuable?
I like that they are more stable than the previous ones, and they allow a lot of other features.
What needs improvement?
It would be better to have more tools to control Palo Alto Networks NG Firewalls. We don't have too many tools to access Palo Alto. For example, the IT team doesn't have access to it. We can see it physically and see if it's running or not. We need to contact a special team to receive that information. I would also like to see more reporting in the next release.
For how long have I used the solution?
I have been using Palo Alto Networks NG Firewalls for two years.
What do I think about the stability of the solution?
Palo Alto Networks NG Firewalls is stable.
What do I think about the scalability of the solution?
Palo Alto Networks NG Firewalls is scalable. We have about 250 people using it at our hotel.
How are customer service and technical support?
We use Trustwave, a company that provides the devices. We have an agreement with them, and we're satisfied with the support.
Which solution did I use previously and why did I switch?
We used to use Juniper and Fortinet.
How was the initial setup?
The initial setup is pretty much straightforward. It takes us about two hours to set up and deploy this solution. It takes a team of two guys to deploy and maintain this solution.
What other advice do I have?
I would recommend this solution to new users.
On a scale from one to ten, I would give Palo Alto Networks NG Firewalls a nine.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Security team leader at a aerospace/defense firm with 10,001+ employees
All of the policies configured are related to the application and not to a port
Pros and Cons
- "The strengths of Palo Alto Networks NG Firewalls are application visibility and application awareness. Their strong point is identifying applications for traffic. So all of the policies that are configured are related to the application and not to a port."
- "This solution cannot be implemented on-premises; it's only a cloud solution. The price is high as well."
- "From a financial perspective, this solution is quite expensive."
What is our primary use case?
We deployed the Palo Alto Next Generation Firewall on the perimeter of the network, so all traffic that flows to the company from the internet and from the company to the internet scanned by the Palo Alto Networks Firewall. In addition, all of the internal traffic from LAN users to services that are on the DMZ zone traverse the Palo Alto Firewall.
What is most valuable?
The strengths of Palo Alto Networks NG Firewalls are application visibility and application awareness. Their strong point is identifying applications for traffic. So all of the policies that are configured are related to the application and not to a port.
For example, let's say you want to allow HTTP traffic and the server is not listening on the standard http port which port 80 but listens on port 25 which Is the standard port for SMTP, this is not an obstacle has the firewall is focusing on the application, it identify the HTTP application and allow the HTTP application and block any other application on port 25. So we don't care on which port the app traverses.
It is easy to install and is stable too.
What needs improvement?
There is another solution from Palo Alto for endpoints - XDR that integrates with the firewall thus providing protection at the network level and also at the end point but the XDR solution is only a cloud based solution. I would really like it if would be possible to implement this solution on-premises this is something that I would love to see with Palo Alto Networks NG Firewalls.
The price could be lower.
For how long have I used the solution?
I've worked with Palo Alto Networks NG Firewalls within the last 12 months.
What do I think about the stability of the solution?
So far, it's stable. I haven't had any problem with it. I'm always authorizing to have the minor version aligned with the latest version. There haven't been any published vulnerabilities with the product so far.
What do I think about the scalability of the solution?
I'm using the cluster, and that's a great long term solution. So I haven't needed to expand.
There are more than 10,000 employees in the company. We hope to migrate the other branches that have a different vendor to Palo Alto.
How was the initial setup?
The initial setup was straightforward from my point of view.
What's my experience with pricing, setup cost, and licensing?
From a financial perspective, this solution is quite expensive.
The licensing is on a yearly basis even though we close the deal for three years upfront.
What other advice do I have?
I would advise that those thinking about Palo Alto Networks NG Firewalls need to switch how they think about a policy on the firewall. They should not to look at it from the point of view of the service and what port that policy is related to. Instead, they should look at it from the application side. Don't pay too much attention to the port. Just look at the application. For example, the NGFW doesn't care if SMTP traverses on port 25 or 65. It just enforces the protocol.
From a technical point of view, I don't think that there's something that's missing from the Palo Alto Networks NG Firewalls. So, I would rate it at nine on a scale from one to ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Director IT Security at a healthcare company with 10,001+ employees
Good threat hunt capabilities, good support, and easy to deploy
Pros and Cons
- "Mechanically, all firewalls work in a similar fashion, but what makes Palo Alto different is that it also has some of the threat hunt capabilities. It is a little bit better than other vendors."
- "As things are evolving, we want to make sure that Palo Alto is able to keep up with what is going on outside. They should continue to do more intelligence-related enhancements and integrate with some of the other security tools. We want to have a more intelligent toolset down the road."
What is our primary use case?
Basically, it is for protection and security. We are using it to make sure that our network is as secure as possible. We are able to evaluate each stack in each pocket and take certain actions as needed when we look into some of the content of the payload.
We have on-prem deployments, and we also have SaaS-based services.
What is most valuable?
Mechanically, all firewalls work in a similar fashion, but what makes Palo Alto different is that it also has some of the threat hunt capabilities. It is a little bit better than other vendors.
What needs improvement?
As things are evolving, we want to make sure that Palo Alto is able to keep up with what is going on outside. They should continue to do more intelligence-related enhancements and integrate with some of the other security tools. We want to have a more intelligent toolset down the road.
For how long have I used the solution?
We implemented this solution last year.
What do I think about the scalability of the solution?
We currently have 25,000 users. Its usage won't increase a lot, but IT is changing very rapidly, and it would depend on the security model towards which we are moving.
How are customer service and technical support?
Palo Alto provides pretty good support.
How was the initial setup?
It is straightforward. The deployment duration varies because there are different modules and components, but it doesn't mean that we have to complete everything to make it work. For the core piece of it, it would probably take a couple of months to install, configure, and test.
What about the implementation team?
We have a vendor to help us. We have two or three people for its deployment.
What's my experience with pricing, setup cost, and licensing?
It has a yearly subscription.
What other advice do I have?
I would recommend this solution. I would rate Palo Alto Networks NG Firewalls an eight out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Server Administrator and Operation Manager at a computer software company with 501-1,000 employees
Good security with very good web content control and capable of scaling
Pros and Cons
- "The stability of the product has been good over the years."
- "The solution is very user-friendly and easy to manage and administrate."
- "The cost of the device is very high."
What is our primary use case?
We primarily use the product for web browsing and in order to protect some sites that we are publishing to the web internet.
What is most valuable?
The solution is very helpful in controlling spam.
The product offers very good web content control and various aspects of security.
The stability of the product has been good over the years.
The initial setup is very easy. Compared to Cisco or other solutions, Palo Alto is very easy to implement and administer. They are both very easy.
What needs improvement?
I can't recall a feature that was missing. It's a pretty complete solution.
The cost of the device is very high.
To buy license support is very slow. For renewing devices and products, it's slow in terms of contacting and activating upgraded devices.
For how long have I used the solution?
I've been using the solution for four years at this point. It's been a while. We've been using it over the last 12 months as well.
What do I think about the stability of the solution?
The stability is excellent. It's reliable. We don't deal with bugs or glitches. It doesn't crash or freeze. Overall, it's been very good in terms of performance.
What do I think about the scalability of the solution?
We have not proven the scalability yet. We're planning to extend our office within the next year or six months to eight months. We are buying some appliances for the process of extending our office.
Currently, around 1,000 people use this solution.
How are customer service and technical support?
We've never been in touch with technical support. Having never dealt with them, I wouldn't be able to speak to how they are in terms of services.
Which solution did I use previously and why did I switch?
We also use Barracuda and Cisco for certain aspects of security.
How was the initial setup?
The initial setup is pretty straightforward. It's quite easy to implement.
The deployment takes about one week, or maybe a bit less, depending on the requirements. That includes both implementing and training.
Currently, two people are required for deployment and maintenance of the product
What about the implementation team?
We implement the solution with our network team. We implement the solution ourselves. We don't need the help of integrators or consultants.
What's my experience with pricing, setup cost, and licensing?
The pricing is quite high on Palo Alto.
On the lower end, it's likely to cost $15,000 for renovation and support.
Which other solutions did I evaluate?
We evaluated Cisco, Juniper, and Dell among other solutions before ultimately choosing this solution. Cisco can be complex in terms of device management compared to other options, for example. Cisco can be cheaper than Palo Alto, but that is not always the case.
What other advice do I have?
I'm not sure which version of the solution we're using. We use a physical appliance.
We're using three different models, for the most part.
My company is an outsourcing company that deploys software and testing.
The solution is very user-friendly and easy to manage and administrate. For that reason, I would rate the product at a nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free Palo Alto Networks NG Firewalls Report and get advice and tips from experienced pros
sharing their opinions.
Updated: September 2026
Product Categories
FirewallsPopular Comparisons
Fortinet FortiGate
Cisco Secure Firewall
Netgate pfSense
Sophos Firewall
Check Point Cloud Firewall (formerly CloudGuard Network Security)
WatchGuard Firebox
Check Point Harmony SASE (formerly Perimeter 81)
Cisco Meraki MX
Check Point Quantum Force (NGFW)
Azure Firewall
Palo Alto Networks VM-Series
Cisco Secure Access
Fortinet FortiGate-VM
Juniper SRX Series Firewall
Buyer's Guide
Download our free Palo Alto Networks NG Firewalls Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Is Palo Alto the best firewall for an on-premise/cloud hybrid IT network?
- What are the main differences between Palo Alto and Cisco firewalls ?
- Expert Opinion on Palo-Alto Required.
- Which is the best IPS - Cisco Firepower or Palo Alto?
- Features comparison between Palo Alto and Fortinet firewalls
- Is Palo Alto Networks NG Firewalls better than Check Point NGFW?
- What are the main differences between Palo Alto firewalls and Cisco Secure Firepower?
- Which is better - Palo Alto Networks NG Firewalls or Sophos XG?
- What is a better choice, Azure Firewall or Palo Alto Networks NG Firewalls?
- Which Palo Alto Networks NG Firewalls model is recommended for 1200 users?












