Try our new research platform with insights from 80,000+ expert users
reviewer1350975 - PeerSpot reviewer
Head of IT Infrastructure at a financial services firm with 1,001-5,000 employees
Real User
Provides a reliable central firewall
Pros and Cons
  • "Identifying applications is very easy with this solution."
  • "The reports it provides are not helpful."

What is our primary use case?

We use this solution as our central firewall, but not as a perimeter firewall. For our perimeter, we use another solution. 

Our organization consists of roughly 2,000 to 3,000 employees. 

What is most valuable?

Identifying applications is very easy with this solution.

What needs improvement?

I don't like the reporting. The reports it provides are not helpful. They should include more executive summaries and other important information — they're too technical.

For how long have I used the solution?

I have been using this solution for three years. 

Buyer's Guide
Palo Alto Networks NG Firewalls
May 2025
Learn what your peers think about Palo Alto Networks NG Firewalls. Get advice and tips from experienced pros sharing their opinions. Updated: May 2025.
851,823 professionals have used our research since 2012.

What do I think about the stability of the solution?

The stability is excellent. 

How are customer service and support?

The technical support is good, but not excellent. Their responses can be quite vague and unhelpful at times. 

Which solution did I use previously and why did I switch?

We used to use Checkpoint. We stopped using it because the price was too high. 

How was the initial setup?

Considering our limited amount of experience, the initial setup was easy. Deployment took one month. 

What about the implementation team?

A local reseller team of roughly three to five people implemented it for us — it was a great experience. 

Which other solutions did I evaluate?

We evaluated Palo Alto, Checkpoint, Fortinet, and Cisco Firepower. Overall, it came down to the price — that's why we went with Palo Alto Networks NG Firewalls.

What other advice do I have?

This solution is very particular; it's only suited to specific companies — it's a commercial opportunity. 

Overall, on a scale from one to ten, I would give this solution a rating of eight. 

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Marine Consultant/Captain/Senior DPO at Jan Arild Hammer
Consultant
The best firewall that is easy to set up and has good flexibility and stability
Pros and Cons
  • "Its flexibility is the most valuable."
  • "Its price can be better. They should also provide some more examples of configurations online."

What is our primary use case?

We use it to control what users may access internally and externally, which covers everything. We are using its latest version. The model that we are using is 3220.

What is most valuable?

Its flexibility is the most valuable.

What needs improvement?

Its price can be better. They should also provide some more examples of configurations online.

For how long have I used the solution?

I have been using this solution for one and a half years.

What do I think about the stability of the solution?

It is very stable.

What do I think about the scalability of the solution?

We haven't scaled it because if you want to scale it upwards, you have to change the firewall.

How are customer service and technical support?

I have sometimes used the local support here in Norway. That has been okay. There are no problems.

Which solution did I use previously and why did I switch?

I have tried Sophos, Cisco, and FortiGate. This is the best firewall.

How was the initial setup?

The initial setup is easy. There is good documentation for this.

What's my experience with pricing, setup cost, and licensing?

Its price can be better. Licensing is on a yearly basis.

What other advice do I have?

I would rate Palo Alto Networks NG Firewalls a ten out of ten. It is the best solution I have tried. I am happy with this solution.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Palo Alto Networks NG Firewalls
May 2025
Learn what your peers think about Palo Alto Networks NG Firewalls. Get advice and tips from experienced pros sharing their opinions. Updated: May 2025.
851,823 professionals have used our research since 2012.
Vice President & Head Technology Transition at a tech services company with 10,001+ employees
Real User
The solution is generally stable, and easily scalable
Pros and Cons
  • "The solution is scalable"
  • "The support could be improved."

What is our primary use case?

We have multiple IPS applications, and other multiple use cases.

What is most valuable?

We are using pretty much all of the features. This is deployed in our parameter and pretty much provides for different functionalities, for all incoming traffic and outgoing traffic.

What needs improvement?

The support could be improved.

The next release could use more configuration monitoring on this one, and additional features on auditing.

For how long have I used the solution?

I've been using the solution for three years.

What do I think about the stability of the solution?

The solution is generally stable. There are no issues. We have forty-thousand users.

What do I think about the scalability of the solution?

The solution is scalable, yes. We don't plan on increasing usage.

How are customer service and technical support?

We are being provided with decent support but some of the RCS, some of the issues can be resolved much faster.

Which solution did I use previously and why did I switch?

We were using Check Point. We switched because of certain features: entire equity, ideas, application visibility, single interfacing, etc.

How was the initial setup?

The initial setup was complex. We're in the process of replacing it in seventy or so locations, and setup is still ongoing, but going well. It was complex because of the multiple zones that we had to create. We had multiple interfaces so there are multiple complexities that we had to address. We don't require extra staff to maintain the solution.

What about the implementation team?

We implemented through a system integrator.

What was our ROI?

We have seen a return on investment. 

I don't have data points, but some of the use cases that we have already delivered to the organization have shown that a lot of threats have been identified and has been blocked. I don't know how you can quantify that. At the same time, the effort was significantly reduced on the deployment of new routes based on this.

What's my experience with pricing, setup cost, and licensing?

I think, if you compare, they're a little costly next to Cisco of Check Point, but they offer a lot of other additional features to look at. The licensing is annual, and there aren't any additional fees on top of that.

Which other solutions did I evaluate?

We actually did not but we were using two or three other products already, so we had a good idea of what to expect.

What other advice do I have?

I'd say the blueprint of the implementation needs to be ready before you start the implementation of the product. The product is generally stable and the team provides a good presence on it, but at the end, if you're putting it in the mission-critical data center, the planning needs to be extensive.

I would rate this solution an eight and a half out of ten.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
reviewer1498575 - PeerSpot reviewer
IT Architect at a computer software company with 501-1,000 employees
Real User
Advanced technology, reliable, and good customer service
Pros and Cons
  • "The technology's very good. We have had a lot of good experience with this solution."
  • "For an upcoming release, they could improve on the way to build security rules per user."

What is our primary use case?

In manufacture, we use this solution as a firewall and an internal gateway. Additionally, we use it for traffic control which keeps strategic traffic separate from production traffic.

What is most valuable?

The technology's very good. We have had a lot of good experience with this solution. We have done a lot of implementation for our clients and we have not had a lot of problems with this solution.

What needs improvement?

For an upcoming release, they could improve on the way to build security rules per user. Palo Alto has this functionality but in implementation, we had some problem. This functionality should be better in our opinion.

For how long have I used the solution?

I have been using the solution for more than seven years.

What do I think about the stability of the solution?

In my experience, the stability is very good. 

What do I think about the scalability of the solution?

We have more than 700 people using the solution in my company.

How are customer service and technical support?

We have had a good experience with technical support.

Which solution did I use previously and why did I switch?

We have used FortiGate in the past and we prefer this one.

How was the initial setup?

The setup was complex.

What about the implementation team?

Depending on the project, specific environment, and performance the deployment could take some time.

What's my experience with pricing, setup cost, and licensing?

With the licensing we pay for it annually, the price could be cheaper.

What other advice do I have?

If someone looking for stability and the leader in next-generation firewall technology, I would choose this solution.

I would recommend this solution to others.

I rate Palo Alto Networks NG Firewalls a ten out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Integrator
PeerSpot user
reviewer1001214 - PeerSpot reviewer
Sr. Engineer at a comms service provider with 51-200 employees
Real User
Reliable with a straightforward setup and good security features
Pros and Cons
  • "It's one of the best products I've worked with. It's typically a market leader on Gartner. It's a very respected brand."
  • "The pricing of the solution is quite high. It's one of the most expensive firewall solutions on the market."

What is our primary use case?

The solution is typically used for antivirus and antimalware purposes, to help protect an organization against attacks.

What is most valuable?

The solution offers many different capabilities.

It's one of the best products I've worked with. It's typically a market leader on Gartner. It's a very respected brand.

The solution offers very good security, especially in relation to antivirus activities.

The initial setup is pretty straightforward.

The product is extremely reliable.

What needs improvement?

The pricing of the solution is quite high. It's one of the most expensive firewall solutions on the market.

Clients are typically looking for a solution that's more aggressive in the market.

For example, with Fortinet, they have an SD-WAN that really has many capabilities. For example, it can inject a GSL SIM card along with the MPLS connection. It connects the system within one product. Palo Alto doesn't offer this. This is one area that will need to improve. In Indonesia, the market is growing strategically. Palo Alto has this one product, however, with the limitation of the GSM sim card they are getting left behind. 

For how long have I used the solution?

I started using the solution around 2012 or 2013. It may have been eight years or so. Sometimes I am doing a POC or implementing the solution, so it has been on and off.

What do I think about the stability of the solution?

While the solution itself is okay in terms of stability, there could be issues if the hardware is affected. We have hardware that gets affected by humidity, for example, which can end up affecting a wide range of infrastructure. If the environment is good, the solution will be okay. If we talking about Palo Alto's series starting from the 3,000 to 5,000 or 7,000, Palo Alto has a really stable product.

What do I think about the scalability of the solution?

We set up this solution for companies of all sizes, from small to large enterprises. One of our clients is a telecom, which is quite sizable. They have the most complex configuration. The solution, however, is able to work for any company, no matter what the size. In that sense, it's a scalable option.

That said, the NG firewall is not a typical product that we can scale up on a whim. If we want to scale up in this product, we need to buy a higher series. We have to replace it. If we want to scale out this product, we can do a roll out in another location. Therefore, you can expand it out, however, you do need to change the sizing, which means getting a size or two up.

How are customer service and technical support?

I haven't contacted technical support recently. The last time I spoke to the tech support team was five years ago or maybe as an Operation Engineer three or five years ago. Generally, I found that they were really good at understanding the product. In my experience, they were really helpful. I'd say I was satisfied with their support.

Which solution did I use previously and why did I switch?

I've also used Juniper, however, that may have been three or four years ago or so.

How was the initial setup?

In my case, I have a lot of experience with Palo Alto and the implementation process. Therefore, I don't find it too complex. It's rather straightforward for me. However, I have a long history with the solution. I find the hierarchy of the configuration fairly easy to understand, especially if you compare it to a solution such as Juniper. Juniper is a bit more complex to set up. Whereas, Palo Alto is a bit more straightforward.

How long deployment takes can vary. It really depends on the complexity of the configuration and the environment.

If a client only buys the implementation, they will have to handle the maintenance of the product. It's a good idea to have that type of person in-house.

What's my experience with pricing, setup cost, and licensing?

We find the cost of the solution to be very high. It's quite expensive, and one of the most expensive on the market.

The pricing is related to the complexity of the environment. The more complex the company's requirements, the more it will cost.

What other advice do I have?

We have a partnership with Palo Alto.

I am in pre-sales and often do POCs or do some aspect of evaluating the solution for clients to help them understand the usefulness.

Overall, I really do prefer Palo Alto to other options. I'm the most comfortable with it and I understand it the best out of other solutions such as Juniper or Fortinet.

I'd suggest organizations consider the solution. Yes, it is quite expensive. However, it is also very reliable and is always marked highly in Gartner due to its feature set and usability. It's easy to configure and it's very easy to add more features into your roadmap if you need to. It can easily integrate into a larger holistic security system to help keep a company safe.

In general, I would rate the solution at a nine out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
Assistant Manager at Net One Systems
Real User
Security is a lot easier than its competitors and it has well-integrated software
Pros and Cons
  • "I like that it has high security."
  • "The whole performance takes a long time. It takes a long time to configure."

What is our primary use case?

Our primary use case was to configure our PSAs for our customized configuration. 

What is most valuable?

I like that it has high security. 

What needs improvement?

The whole performance takes a long time. It takes a long time to configure. 

For how long have I used the solution?

I have been using Palo Alto for six years. 

How are customer service and technical support?

I contact Palo Alto by email or by phone. Their support is good. 

Which solution did I use previously and why did I switch?

I have previously worked with Cisco ASA. Palo Alto is a lot easier especially in regards to security. It is a well-integrated software.

How was the initial setup?

The difficulty of the deployment depends on our clients' environment and their requests.

We require a two-member team for support. 

In terms of how long it takes to deploy, again, it depends on the customers' environment. If the request is easy, it can take around two weeks.

What other advice do I have?

I would rate Palo Alto a nine out of ten. 

In the next release, they should simplify the deployment process. 

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Integrator
PeerSpot user
President at MT-Data
Real User
Awesome stability, great firewall capabilities, and a rather straightforward initial setup
Pros and Cons
  • "The solution allows us to set parameters on where our users can go. We can block certain sites or ads if we want to."
  • "We're working with the entry-level appliances, so I don't know what the higher-end ones are like, however, on the entry-level models I would say commit speeds need to be improved."

What is our primary use case?

We primarily use the solution for the firewalls. We're also using the next-gen features to shape what's going on. For example, to figure out what is allowed out and what isn't allowed out on a layer-7 application-aware firewall. We can block based on the application, as opposed to port access.

How has it helped my organization?

The solution helped us stop being policemen to our users. We don't have to run around telling people they can't do certain things. We can just not allow it and walk away from it. We're not out there seeing who is doing what, we just don't allow the what.

What is most valuable?

The solution allows us to set parameters on where our users can go. We can block certain sites or ads if we want to.

The firewall capabilities are very good.

What needs improvement?

We're working with the entry-level appliances, so I don't know what the higher-end ones are like, however, on the entry-level models I would say commit speeds need to be improved. 

The appliances I'm working on are relatively old now. We're talking five-year old hardware. That slow commit speed might be addressed with just the newer hardware. However, even though it is slow, the speed at which they do their job is very acceptable. The throughput even from a five-year-old appliance shocks me sometimes.

Currently, if I make changes on the firewall and I want to commit changes, that can take two or three minutes to commit those changes. It doesn't happen instantly.

The solution doesn't offer spam filtering. I don't know whether it's part of their plan to add something of that aspect in or not. I can always get spam filtering someplace else. It's not a deal-breaker for me. A lot of appliances do that, and there are just appliances that handle nothing but spam. 

For how long have I used the solution?

I've been using the solution for five years.

What do I think about the stability of the solution?

The stability is awesome. I haven't had any issues with the solution stability-wise. I've got the same firewalls that have been out there for five years and they work great.

What do I think about the scalability of the solution?

I don't work with enterprise-class products. I'm not in that environment. However, so as far as I know, Palo Alto has products that will go that large. Panorama may be able to scale quite well. You can manage all your appliances out of it. They are a very popular license.

Their GlobalProtect license is very much like Cisco's AnyConnect. It does the endpoint security checks. It makes sure they've got the latest patches on and the antivirus running and they've got the latest antivirus definitions and whatnot installed before they allow the VPN connection to happen. It's quite nice.

How are customer service and technical support?

Their support is very good. I've never had any issues with their support. I would say that we've been satisfied with their level of service. 

Occasionally there may be a bit of a language issue based on where their support is located.

How was the initial setup?

The initial setup is pretty typical. It's like any firewall. As long as you've worked with next-gen firewalls, it's just a matter of getting your head around the interface. It's the same sort of thing from one firewall to the other. It's just a matter of learning how Palo Alto does stuff. Palo Alto as a system, for me, makes a whole lot of sense in the way that they treat things. It makes sense and is easy to figure out. That's unlike, for example, the Cisco firewalls that seem to do everything backwards and in a complicated way to me. 

I haven't worked with enough Cisco due to the fact I don't really like the way they work. That isn't to say that Cisco firewalls are bad or anything. It's just that they don't operate the way I think. That might have changed since they acquired FireEye which they bought a couple of years back.

What's my experience with pricing, setup cost, and licensing?

I know the solution is not inexpensive. It depends on what you ultimately sign up for or whether you just want the warranty on the hardware. 

What other advice do I have?

I'm not really a customer. I'm like a consultant. I'm an introduction expert. If I think a client needs a certain technology I point them in the direction of whoever sells it. I do go in and configure it, so I do have experience actually using the product.

When I'm looking for something, I just find someone that sells Palo Alto and I redirect the client towards them. I'm not interested in being in a hardware vendor. There's no money in it. There's so much competition out there with people selling hardware. It doesn't matter where the client gets it from.

We tend to use the 200-series models of the solution.

I'd rate the solution eight out of ten. They do a very good job. The product works well.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
PeerSpot user
Vice President, Security Engineering at a financial services firm with 1,001-5,000 employees
Real User
Provides us with Zero Trust segmentation and an easy-to-use centralized control
Pros and Cons
  • "This solution not only provides better security than flat VLAN segments but allows easy movement through the lifecycle of the server."
  • "I wish that the Palos had better system logging for the hardware itself."

What is our primary use case?

We use this solution for Zero Trust Data Center Segmentation with layer 2 Palo Alto firewalls. Segmentation has allowed us to put servers into Zones based off VLAN tags applied at the Nutanix level and can change "personalities" with the change of a VLAN tag. Palo Alto calls the "Layer 2 rewrite". By default, all traffic runs through a pair of 5000 series PAs and nothing is trusted. All North and South, East and West traffic is untrusted. No traffic is passed unless it matched a rule in the firewalls. There is a lot of upfront work to get this solution to work but once implemented adds/moves/changes are easy.

How has it helped my organization?

This solution not only provides better security than flat VLAN segments but allows easy movement throughout the lifecycle of the server.

What is most valuable?

The most valuable feature is the ease of use of the central Panorama to control all firewalls as one unit for baseline rules and then treat each firewall separately when needed.

What needs improvement?

I wish that the Palos had better system logging for the hardware itself.

For how long have I used the solution?

We have been using this solution for four years.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Download our free Palo Alto Networks NG Firewalls Report and get advice and tips from experienced pros sharing their opinions.
Updated: May 2025
Product Categories
Firewalls
Buyer's Guide
Download our free Palo Alto Networks NG Firewalls Report and get advice and tips from experienced pros sharing their opinions.