No more typing reviews! Try our Samantha, our new voice AI agent.
Jorge Huaman - PeerSpot reviewer
Technology Manager at Italtel
Real User
Leaderboard
Dec 14, 2020
Easy for clients to connect to their information
Pros and Cons
  • "They have a good system operator in the firewalls and it provides many tools that they can use to protect their networks."
  • "Palo Alto has very good administration tools which is not the case with the others."
  • "Maybe they could add some tools and more competing services, like servers, but that would increase the cost of the solution."

What is our primary use case?

Our primary use case is for the perimeter connection of our clients in the network. Our client brings their services to their clients, and they have the option to connect to a webpage. With Palo Alto Networks NG Firewalls they can safely provide a username and password to their clients.

It is mainly on-premise, because the majority of the clients at this point want that kind of option. But many of them are already asking for the cloud option, like Prisma, for example.

How has it helped my organization?

It has improved our clients' organizations because previously the clients did not have the option to fully connect. In this solution, they have the opportunity to add services to their web page and book clients.

What is most valuable?

The feature that I have found most valuable is the connection. It's very easy for the clients to connect to their information. They use an SSL connection by BPM.

What needs improvement?

We work very closely with the vendors here and at this point they use external support.

Maybe they could add some tools and more competing services, like servers, but that would increase the cost of the solution.

Buyer's Guide
Palo Alto Networks NG Firewalls
July 2026
Learn what your peers think about Palo Alto Networks NG Firewalls. Get advice and tips from experienced pros sharing their opinions. Updated: July 2026.
909,153 professionals have used our research since 2012.

For how long have I used the solution?

My company has been using Palo Alto Networks NG Firewalls for almost one year. It is new for us. We have more experience with Cisco and Fortinet.

What do I think about the stability of the solution?

In my company, I am responsible for the development of the proposal that we give to the client. We develop the spectrum and the pricing. We make presentations to the customer to explain the solution and answer questions about it.

What do I think about the scalability of the solution?

The scalability is very strong. The vendor provides has high availability.

Our clients are medium sized businesses.

Palo Alto is not a cheap solution. It is expensive. But because of its technology it pays itself back. In each case we work with the vendor to obtain a major discount for their business. I give that discount to our customer, who benefit from the services that we can bring them.

How are customer service and support?

This is our first dealing with Palo Alto. With other vendors we have more experience, like with Cisco and Fortinet.

Palo Alto's documentation and manuals are very complete. It's very easy to obtain the information that way.

Which solution did I use previously and why did I switch?

The client still uses Cisco, Fortinet, and Checkpoint. Palo Alto has very good administration tools which is not the case with the others. You can't compare all vendors. Also, the granularity of the information that they can obtain from the firewalls is better.

How was the initial setup?

The initial setup depends. In the case of one client, for example, they have a very complex connection of networks, which is architectural. It is integrated and we need to pick it out and include all the rules that they have and to put in the firewalls which they want to buy in the next month. That kind of job is not easy for us, not just regarding Palo Alto but for other vendors, too.

What other advice do I have?

On a scale of one to ten, I would give Palo Alto Networks NG Firewalls a nine.

I would recommend this product to others.

In terms of what advice I would give to future customers looking into implementing Palo Alto Firewalls, I would tell them that they have a good system operator in the firewalls and that it provides many tools that they can use to protect their networks. You don't find that in the other vendors.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
Ragesh Alappurath - PeerSpot reviewer
Senior Network Engineer at Almoayyed Computers
Real User
Nov 9, 2020
Great GlobalProtect and App-ID features; easy implementation and good integration
Pros and Cons
  • "GlobalProtect and App-ID features are very good."
  • "Palo Alto is more expensive in comparison to Fortinet and other firewalls, but it's okay because they do provide quality."
  • "Lacks mobility between on-prem and cloud based."
  • "Managing can be difficult."

What is our primary use case?

We deploy and provide support for this solution to our customers. The use case depends on customer requirements because Palo Alto Next Generation Firewall can be used as a data center firewall, perimeter firewall or on the cloud for a perimeter firewall or used with communications. Some customers use it for global protect connectivity. I am a senior network engineer and we are partners with Palo Alto Networks. 

What is most valuable?

The best feature of this solution is the GlobalProtect, followed by the App-ID feature which is very good. I also like the VMS feature. 

What needs improvement?

They've improved a lot of things but we'd like to see more mobility between on-prem and cloud based. I'd also like to see security synchronization between the firewalls. Managing can be difficult. 

For how long have I used the solution?

I've been providing this solution for over two years. 

What do I think about the stability of the solution?

There are occasionally issues with reporting, otherwise stability is fine. 

What do I think about the scalability of the solution?

The scalability of this solution is fine. 

How are customer service and technical support?

Technical support is fine, although sometimes there have been delays. From a technical perspective, they are knowledgeable. 

How was the initial setup?

Now that I have some experience with it, the initial setup is simple. If it's being deployed on-prem, deployment takes a couple of days. But if it's a cloud deployment, we can complete deployment in a day. 

What's my experience with pricing, setup cost, and licensing?

Palo Alto is more expensive in comparison to Fortinet and other firewalls. It's okay because they do provide quality. 

What other advice do I have?

I would recommend this firewall still. Our system integrates well but it depends on customer requirements so we sometimes choose to go with an alternative firewall.

I would rate this solution an eight out of 10. 

Which deployment model are you using for this solution?

Hybrid Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
Buyer's Guide
Palo Alto Networks NG Firewalls
July 2026
Learn what your peers think about Palo Alto Networks NG Firewalls. Get advice and tips from experienced pros sharing their opinions. Updated: July 2026.
909,153 professionals have used our research since 2012.
Associate cloud system admin at Innocap
Real User
May 19, 2024
Is used to secure our Internet traffic and the application traffic
Pros and Cons
  • "The payload is a very valuable feature."
  • "The technical support needs improvement."

What is our primary use case?

We use the solution to secure our Internet traffic and the application traffic from the Internet. 

There is also no need to connect to a VPN most of the time.

What is most valuable?

The payload is a very valuable feature. 

What needs improvement?

The technical support needs improvement. 

For how long have I used the solution?

I have been using Palo Alto Networks NG Firewalls for six years. 

What do I think about the stability of the solution?

It is a stable solution. 

How was the initial setup?

The deployment takes five to ten minutes. 

What's my experience with pricing, setup cost, and licensing?

There are security licenses. 

What other advice do I have?

Overall, I rate the solution a nine out of ten. 

Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
reviewer2393664 - PeerSpot reviewer
IT Technical Lead at a tech services company with 1,001-5,000 employees
Real User
Apr 29, 2024
Has advanced threat prevention features but central management system is complicated
Pros and Cons
  • "We utilize advanced threat prevention features like web filtering and SSL decryption, which haven't caused any issues."
  • "The tool's central management system is complicated, making it challenging to manage multiple devices centrally. Individually, the firewalls are easy to use and manage. I'd like to see better central management features in the next release. They've introduced some, but I haven't tried them yet, so I can't say how effective they are. However, having a single management interface would be a big improvement."

What is most valuable?

We utilize advanced threat prevention features like web filtering and SSL decryption, which haven't caused any issues.

What needs improvement?

The tool's central management system is complicated, making it challenging to manage multiple devices centrally. Individually, the firewalls are easy to use and manage.

I'd like to see better central management features in the next release. They've introduced some, but I haven't tried them yet, so I can't say how effective they are. However, having a single management interface would be a big improvement.

For how long have I used the solution?

I have been working with the product for six years. 

What do I think about the stability of the solution?

The product is scalable. 

What do I think about the scalability of the solution?

The tool is stable. 

How are customer service and support?

The tool's technical support is good compared to other vendors. 

How would you rate customer service and support?

Positive

How was the initial setup?

Setting up the tool can be challenging, especially if configuring them individually. There's an option for zero-touch configuration, but it still involves managing Palo Alto Networks NG Firewalls, which adds complexity and doesn't always justify the cost. If you're experienced with the technology and starting from scratch, expect a steep learning curve.

What's my experience with pricing, setup cost, and licensing?

The tool is expensive, especially considering all the necessary licenses for centrally managing firewalls. For medium-sized companies like ours, it's often not feasible within our budget constraints.

We pay around €200k yearly for all our firewalls. Additionally, we received a quote of over 1 million per year for Prisma Access. There is a significant cost difference compared to other options, where it's around €200k per year.

We have to pay a license for support. 

What other advice do I have?

We started with on-premise infrastructure, including domain controllers. Still, as we moved to the cloud, there was a gap in group membership management until Palo Alto came up with a solution. We have multiple firewalls, about 50 of which are difficult to manage. However, the features offered by the firewalls themselves are really good.

In the future, we might consider switching from Palo Alto Networks NG Firewalls. We're currently evaluating a new solution. However, cost is a concern, as it seems more expensive than other products and SaaS solutions.

Integration with Palo Alto Networks NG Firewalls and other security tools or IT infrastructure is not entirely straightforward but manageable. It's easier compared to some other vendors but still requires effort. I have tried to integrate it with Cisco ISE. 

I recommend Palo Alto NG Firewalls for large enterprises. However, due to their high price, I wouldn't recommend them for small—to medium-sized companies, especially those with limited IT budgets.

We've found that Palo Alto NG Firewalls are particularly good at stopping zero-day attacks. Compared to other companies like Fortinet, we've had fewer security breaches with it.

I rate the overall solution a seven out of ten. 

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer2173293 - PeerSpot reviewer
Analyst at a non-tech company
Real User
May 2, 2023
Provide an additional level of network security and vigilance
Pros and Cons
  • "I like the firewall's vulnerability management features, which give you reminders to update your system and update your OS."
  • "The built-in machine learning features provide some automation, but I think there should be an option for manual review because nothing replaces the human eye."

What is our primary use case?

An NG firewall provides an additional level of network security and vigilance. It also helps us manage activities using privileges and a zero-trust approach. 

What is most valuable?

I like the firewall's vulnerability management features, which give you reminders to update your system and update your OS. Palo Alto Networks NG Firewalls provide a unified platform that integrates all security capabilities. It provides pretty good consistency across locations. 

What needs improvement?

The built-in machine learning features provide some automation, but I think there should be an option for manual review because nothing replaces the human eye. 

For how long have I used the solution?

We have used NG Firewalls for a little more than a year and a half. 

What do I think about the stability of the solution?

Palo Alto Networks NG Firewalls are pretty stable. 

What do I think about the scalability of the solution?

Palo Alto Networks NG Firewalls scale up enough for my workplace. Beyond that, I could not say. 

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer2063289 - PeerSpot reviewer
Senior information technology consultant at a tech services company with 11-50 employees
Consultant
Jan 17, 2023
An extremely strong security tool, with machine learning capabilities for advanced threat detection
Pros and Cons
  • "We have found the SSL decryption within this solution to be great; you can enable this feature and have the ability to see more of what is happening across your network."
  • "We would like to see improvement in the web interface for this solution, so that it can handle updates without manual intervention to put the data in order."

What is our primary use case?

Our main use of this solution is to create micro segmentations only in the public cloud, and use the data we receive to see threats passing through the Vnets.

How has it helped my organization?

We have found that this solution has improved not only the level of security that is in place, but also reduced the amount of operational time needed for us to handle cloud-based security.

What is most valuable?

We have found the SSL decryption within this solution to be great; you can enable this feature and have the ability to see more of what is happening across your network.

We also really like the Wi-Fi service feature of this solution.  It has a great base of information, and uses machine learning to improve recognition of issues and threats.

What needs improvement?

We would like to see improvement in the web interface for this solution, so that it can handle updates without manual intervention to put the data in order.

For how long have I used the solution?

We have been working with this solution for two years.

What do I think about the stability of the solution?

We have found this to be a stable solution during our time working with it.

What do I think about the scalability of the solution?

As it is cloud-based, the solution is easily scalable.

How are customer service and support?

We have found the technical support for this solution to be very good; we just open a support chat window and we have assistance when we need it.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

We previously used Fortinet, and changed to this solution because of the superior performance.

How was the initial setup?

The initial setup of this solution was very easy, and the deployment took just under two weeks to complete.

What about the implementation team?

We used a consultancy team from Add Valley Services for our implementation of this solution, and their service was great.

What's my experience with pricing, setup cost, and licensing?

We would advise that this solution has a higher price point than other comparable products, however, the license fee covers all the features that the solution can provide and there are not extra costs involved.

What other advice do I have?

We would recommend that organizations implementing this solution use a good consulting service and plan extensively up front, before implementation, in order to ensure a smooth deployment with no issues.

We would rate this solution as 10 out of 10.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Chong Kah Wooi - PeerSpot reviewer
Technical Manager at Ipenet Solutions
Reseller
Jun 3, 2022
Secure solution that makes it easy to understand your network visibility, control the network, and prevent attacks
Pros and Cons
  • "The solution is user-friendly. It's secure and easy to understand your network visibility, control the network, and prevent attacks."
  • "The pricing could be improved. They need to work on the setup over the firewall, VLAN, and PPPoE."

What is our primary use case?

I am a reseller of Palo Alto Networks.

What is most valuable?

The solution is user-friendly. It's secure and easy to understand your network visibility, control the network, and prevent attacks.

What needs improvement?

The pricing could be improved. They need to work on the setup over the firewall, VLAN, and PPPoE.

What do I think about the stability of the solution?

It's stable.

What do I think about the scalability of the solution?

It's scalable.

How are customer service and support?

I seldom call technical support because it's easy to understand and configure the solution.

What's my experience with pricing, setup cost, and licensing?

It could be less expensive.

What other advice do I have?

I would rate this solution 9 out of 10.

If you want to have a secure network, use Palo Alto. 

Disclosure: My company has a business relationship with this vendor other than being a customer.
PeerSpot user
PeerSpot user
Security Consultant at a tech services company with 501-1,000 employees
Reseller
Jan 30, 2022
Good application detection, strong antivirus capabilities and built-in machine learning
Pros and Cons
  • "From my experience, comparing it to other products, the granularity you can have in the application is very good, the application detection is excellent, and it's certainly one of the best."
  • "The solution would benefit from having a dashboard."
  • "From a normal IPS after attack, routine attack and threat detection attack, in other words, the standard IPS detection attack, I don't see Palo Alto as very good compared to others."

What is our primary use case?

We primarily use the solution as a datacenter firewall for 0 trust security model

What is most valuable?

From my experience, comparing it to other products, the granularity you can have in the application is very good. The application detection is excellent. It's certainly one of the best. 

The engine detector application is usually one of the best compared to any other firewall on the market, in my opinion.  With it, I can do a lot of rules based on the application. If you have multiple internet links, you can have an application export from one link, and an application wire from another link. You can have security on the application. The security, for example, can have different functionalities. Basically, the granularity of rules is amazing in Palo Alto.

They have a good reputation for their antivirus capabilities.

The solution offers a strong URL based system or detection for malicious URL or malicious files. 

They even have a machine learning algorithm. They do a lot of very advanced detection for files and URLs. 

Once you deploy the product, you can basically forget about it. It has high customer satisfaction because it's always just working.

What needs improvement?

The solution would benefit from having a dashboard.

From a normal IPS after attack, routine attack and threat detection attack, in other words, the standard IPS detection attack, I don't see Palo Alto as very good compared to others. The standard network IPS functionality could be better. It's there in solutions like McAfee or Tipping Point, however, I don't see it here in this solution.

For how long have I used the solution?

We've been working with Palo Alto for about six years now.

What do I think about the stability of the solution?

From my experience, it's the best hardware compared to other NG firewalls from the perspective of performance stability. While the other firewalls lose 50 or 60% of performance when enabling all policies, Palo Alto loses 10 to 20% maximum, even with enabled IPS and fire detection and all. From our experience performance-wise, it's one of the best hardware solutions for firewalls. 

We haven't lost performance really, so I would describe it as very stable. There are not any issues.

What do I think about the scalability of the solution?

Since the solution is hardware, there are some limitations in terms of scalability.

Usually, in hardware, you can't say it's scalable or not due to the fact that you have the limitations built-in related to the size of the box. The box has a maximum number that it can reach. You can add more hardware, however, the hardware itself is finite.

We usually do a POC first so we can get the figures for performance and we can put in a box that can support 20 or 30 people extra for future expansion.

How are customer service and support?

In general technical support is very good. That said, usually, when we face an issue, we try to solve it ourselves internally before going to level one support. 

In general, we never have had a big issue with support. I don't have much experience with the support team to tell you if they're really good or not. Usually 80% of the cases we open, we talk with the distributor and finish the operation case directly with Palo Alto. It's more like a backend request and therefore I don't have much input that would be objective.

Which solution did I use previously and why did I switch?

As resellers, we also work with Cisco and some Forcepoint solutions.

I like that in Cisco there's more security parts, like IPS, and a Demandware engine.

I like Cisco, in general, more than Palo Alto if I'm comparing the two. However, from an application perspective, our application's usability and detection and firewall control using an application, it's Palo Alto that's the best on the market. That's, of course, purely from a  firewall point of view. Even in terms of detection of the applications, it has the best system.

How was the initial setup?

The deployment depends on the client's environment as well as how they are using it. For example, an internet NG firewall on the internet, it takes, on average, a week between installation, integration, and tuning. Usually we don't do all the policies because we are system integrator. We do the main policies and we teach the customer and then do a handover to the user for tuning and all the installation extras.

If it's a data center project, it takes more time and effort. It takes a month sometimes due to the fact that we'll be dealing with a lot of traffic. The application and server are usually harder to control than internet applications like Facebook and other standard applications, and easier on the internet. Then there's also internal applications, custom applications, migrating applications, finance education applications, etc., which are not always direct from the customer or directly known.

In short, the implementation isn't always straightforward. There can be quite a bit of complexity, depending on the company.

What other advice do I have?

In general, I prefer hardware, and Palo Alto's is quite good. However, we have a couple of virtual deployments for cases as well.

I would definitely recommend the solution. It's one of the best firewalls on the market. I've worked with four different vendors in the past, and some of the most mature NG firewalls are Palo Alto's. It's their main business, so they are able to really focus on the tech. They spend a lot of time on R&D. They're always leading the way with new technologies. 

While Cisco has more main products, Palo Alto really does focus in on NG firewalls. That's why I always see them as a leader in the space.

I'd rate the solution nine out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
PeerSpot user
Amar-Patil - PeerSpot reviewer
Security Engineer at a tech services company with 1,001-5,000 employees
Real User
Top 5
Nov 24, 2021
Enables us to monitor VPN compliance and integrate with multiple vendors
Pros and Cons
  • "With App-ID, we can identify exact traffic. Even if someone tries to fool the firewall with a different port number, or with the correct port number, Palo Alto is able to identify what kind of traffic it is."
  • "In addition to our environment being secure, we can monitor compliance of VPN users."
  • "The solution has normal authentication, but does not have two-factor or multi-factor authentication. There is room for development there."

What is our primary use case?

These firewalls are only used for perimeter purposes, in gateway mode.

How has it helped my organization?

In addition to our environment being secure, we can monitor compliance of VPN users. Security and monitoring are the two big benefits.

It's also very critical for us that it provides a unified platform that natively integrates all security capabilities. We have multiple vendors and multiple solutions. Palo Alto has to work with them. For example, when it comes to authentication, we can integrate LDAP and RADIUS, among others. And in one of our customer's environments, we have integrated a new, passwordless authentication.

What is most valuable?

Apart from the security, Palo Alto NG Firewalls have nice features like App-ID and User-ID. These are the two most useful features.

With App-ID, we can identify exact traffic. Even if someone tries to fool the firewall with a different port number, or with the correct port number, Palo Alto is able to identify what kind of traffic it is.

With User-ID, we can configure single sign-on, which makes things easy for users. There is no need for additional authentication for a user. And for documentation and reporting purposes, we can fetch user-based details, based on User-ID, and can generate new reports.

Another good feature is the DNS Security. With the help of DNS security, we can block the initial level of an attack, and we can block malicious things from a DNS perspective.

The GlobalProtect VPN is also very useful.

What needs improvement?

The solution has normal authentication, but does not have two-factor or multi-factor authentication. There is room for development there.

For how long have I used the solution?

We have been using Palo Alto Networks NG Firewalls for two years. I've worked on the 800 Series and the 3000 Series.

What do I think about the stability of the solution?

It's quite stable. They are launching a new firmware version, but compared to other products, Palo Alto is quite stable.

How are customer service and support?

I have worked with Palo Alto's support many times and it is quite good. Whenever we create a support ticket, they are on time and they update us in a timely manner. In terms of technical expertise, they have good people who are experts in it. They are very supportive of customers.

How would you rate customer service and support?

Positive

How was the initial setup?

The initial deployment is straightforward; very simple. The primary access for these firewalls is quite simple. We can directly access them, after a few basic steps, and start the configuration. Even the hardware registration process and licensing are quite simple.

The time it takes to deploy a firewall depends upon hardware and upon the customer's environment. But a basic to intermediate deployment takes two to three months.

What was our ROI?

Our customers definitely see ROI with Palo Alto NG Firewalls, although I don't have metrics.

What's my experience with pricing, setup cost, and licensing?

I am not involved in the commercial side, but I believe that Palo Alto is quite expensive compared to others.

Which other solutions did I evaluate?

One of the pros of Palo Alto is the GlobalProtect, which is a VPN solution. GlobalProtect has broader compliance checks. I have worked on Check Point and FortiGate, but they don't have this kind of feature in their firewalls. Also, Check Point does not have DNS Security, which Palo Alto has.

What other advice do I have?

If you're going with Palo Alto, you have to use all its features, including the DNS Security, App-ID, and SSL decryption. Otherwise, there is no point in buying Palo Alto.

Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
reviewer1597335 - PeerSpot reviewer
System Engineer at a tech services company with 11-50 employees
Reseller
Jun 14, 2021
Effective traffic monitoring, functional GUI, and excellent technical support
Pros and Cons
  • "Some of the valuable features in this solution are traffic monitoring, GUI functionality, and it is very easy to troubleshoot if there is any problem that happens."
  • "The solution could be simplified."

What is our primary use case?

The customers primarily use this solution for a firewall.

What is most valuable?

Some of the valuable features in this solution are traffic monitoring, GUI functionality, and it very easy to troubleshoot if there is any problem that happens.

What needs improvement?

The solution could be simplified.

For how long have I used the solution?

I have been working with this solution for approximately three years.

What do I think about the stability of the solution?

I have not found any bugs, this solution is stable.

How are customer service and technical support?

The technical support I have been using has been through email communication. When I open a support case, shortly there is a response with a solution. They are responsive and have always found solutions for the issues I have been having.

How was the initial setup?

The installation is straightforward. Before I do a deployment for my customers I am able to do a simulation on my laptop.

What other advice do I have?

I rate Palo Alto Networks NG Firewalls an eight out of ten.

Which deployment model are you using for this solution?

Hybrid Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
PeerSpot user
Buyer's Guide
Download our free Palo Alto Networks NG Firewalls Report and get advice and tips from experienced pros sharing their opinions.
Updated: July 2026
Product Categories
Firewalls
Buyer's Guide
Download our free Palo Alto Networks NG Firewalls Report and get advice and tips from experienced pros sharing their opinions.