Try our new research platform with insights from 80,000+ expert users
Director IT Infrastructure and Operations at a analyst firm with 51-200 employees
Real User
Top 20
Jan 7, 2025
Cost-effective with operational and maintenance ease
Pros and Cons
  • "It was valuable in inspecting packets and analyzing traffic patterns. It helped us understand where people were going and what kind of interactions they were doing. We could go to the level of controlling access and uploads/downloads."
  • "Palo Alto Networks NG Firewalls are the best in the field in terms of usability and coverage."
  • "Understanding the flow and application of securities can be complex, requiring navigation across different sections. Further integration into a unified system could improve usability."
  • "Understanding the flow and application of securities can be complex, requiring navigation across different sections."

What is our primary use case?

It was set up for VPN tunnels and inbound file access in my previous organization. We also had connections from our on-prem systems to any cloud systems, meaning Azure, AWS, or site-to-site VPNs.

How has it helped my organization?

We had a unified platform to look at and compare configurations between firewalls, the versions that we have, and what was available. We could do upgrades or updates to the firewalls using the interface.

Palo Alto Networks NG Firewalls are the best in the field in terms of usability and coverage.

Palo Alto Networks NG Firewalls did help reduce downtime. Because of the features that they had, we were able to push updates. We would do one site at a time. We had set up the cluster mode, so it saved the previous configuration, and then it went through the updates while the other one was running. It would apply the patch, recycle it, and make sure all the connections failover before going to the next one.

We rarely had any downtime. We were running 24/7. Most of the issues we had were with ISP. We did have multiple firewalls, and we were going through two different ISPs. Once one ISP was down, and then it was able to switch over to the other ISP automatically because of the way it was set up. If we had not set up the clustering or failover correctly with the Palo Alto Firewalls handling the two ISPs, it would have been almost a day's worth of downtime. When one ISP was down, if it had not automatically failed over, we would've had to go in and take care of this. This team was pretty much remote, so it would have easily taken us a day.

What is most valuable?

It was valuable in inspecting packets and analyzing traffic patterns. It helped us understand where people were going and what kind of interactions they were doing. We could go to the level of controlling access and uploads/downloads. We could control what they could do, what ports could be opened, and what ports were blocked. We could handle all that.

What needs improvement?

Understanding the flow and application of securities can be complex, requiring navigation across different sections. Further integration into a unified system could improve usability.

It is a bit complex to understand the flows and how the securities are applied to each of those flows. It was a little bit challenging because we had to go to two different sections to figure that out. It would be helpful if it is all unified so that we can see the way the firewall connections and security are set up and the applications that are using those connections. It could be structured differently so that it is more understandable. It has been a while, but it was a bit of a complex way. We had to hop from one area to the other and go back and forth to figure out how a specific connection and application was set up.

Buyer's Guide
Palo Alto Networks NG Firewalls
January 2026
Learn what your peers think about Palo Alto Networks NG Firewalls. Get advice and tips from experienced pros sharing their opinions. Updated: January 2026.
881,114 professionals have used our research since 2012.

For how long have I used the solution?

I have used the solution for two years and was hands-on for one year.

How are customer service and support?

Customer service and support have been very helpful and enabled the successful setup of site-to-site VPNs.

I have interacted with them on multiple occasions, and they have been good. We had some challenges in terms of setting up these site-to-site VPNs, and they were very helpful. They enabled us to be successful in setting up new infrastructure.

We had three different sites. I handled two specific sites. One was an existing site, and the other one required setting up brand-new infrastructure. In both cases, we reached out to Palo Alto for support, and they were very helpful.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

I previously used Cisco firewalls, which are more network-oriented and complex. Palo Alto Networks firewalls are easier to manage and maintain. Palo Alto is more application-oriented than Cisco. Cisco is more network-oriented. The interface of Cisco firewalls is very complex. With Palo Alto firewalls, there is an opportunity to improve, but it is still good.

With Cisco firewalls, no-downtime upgrades are very difficult or complex to do. Palo Alto firewalls are easier in terms of upgrading and minimizing downtime.

The pricing of Palo Alto firewalls is better than Cisco firewalls. Cisco firewalls are not cheap.

Cisco ASA firewalls are very good but require a pretty knowledgeable engineer to manage and maintain. Palo Alto firewalls are great. I am not implying that they are simple, but it is easy to manage and maintain a complex infrastructure with them.

How was the initial setup?

It was deployed on-prem. The whole building management system, such as door access security or cameras had to connect to the SaaS for video processing or tracking and recording. All those interfaces went through the firewall.

The biggest challenge we had was the download. The initial configuration was challenging, especially setting up site-to-site VPNs. Going through our Internet Service Provider took a while because those were all brand new. Setting up the firewall to talk and open it on the backend was a little bit of a challenge. We were also using a software-defined network, and there were some challenges in setting those connections up. There were also other data centers we had to talk to on a different protocol specifically for exchanging files. I believe it was a serial connection between systems. We had a few unique things in terms of setup.

What about the implementation team?

The implementation was handled internally with some support from Palo Alto Networks when needed.

What was our ROI?

The solution helped reduce downtime, which is crucial in time-sensitive industries like manufacturing. This reduction in downtime was significant and contributed to overall operational efficiency.

If you are in the manufacturing site, you do not want employees waiting for the infrastructure to be restored and get networks going. Especially in drug manufacturing, things are time-sensitive and under heavy regulation. You could lose the resources or the raw materials needed for producing your final product. From that aspect, it was very critical. There were a lot of savings there.

What's my experience with pricing, setup cost, and licensing?

Palo Alto Networks offers more cost efficiency compared to Cisco, with better operational and maintenance ease. 

What other advice do I have?

Its initial cost may be high, but the overall return on investment is superior due to reduced downtime and maintenance costs. When it comes to the cost, in addition to the initial investment, you have to look at the investment in the hardware, maintenance, and the time that you spend on it. Those all have to be added. Palo Alto provides the ease of operational maintenance.

I would rate Palo Alto Networks NG Firewalls a nine out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Adam-Brenner - PeerSpot reviewer
Solution Architect at a retailer with 201-500 employees
MSP
Top 10
Dec 27, 2024
Considered some of the most secure firewalls available, offering robust protection when configured with strict security rules
Pros and Cons
  • "The most valuable feature of Palo Alto Networks NG Firewalls is Cortex Data Lake."
  • "Customer service and support for Palo Alto Networks are excellent."
  • "Palo Alto Networks NG Firewalls offer best-in-breed security but could improve by reducing their pricing."
  • "Palo Alto Networks NG Firewalls offer best-in-breed security but could improve by reducing their pricing."

What is our primary use case?

Palo Alto Networks NG Firewalls are primarily used for perimeter security, typically deployed in pairs at most locations. Smaller sales offices often have just one, while larger facilities prioritize security with more firewalls due to their broader operational scope. These firewalls are also highly valuable in mixed environments where standardized security features are essential.

How has it helped my organization?

Palo Alto Networks NG Firewalls provides a unified platform that natively integrates all security capabilities. Panorama is our single console that allows us to do all things Palo Alto. We are a value-added reseller. Some customers specifically request Palo Alto firewalls, while others need guidance and comparisons. 

Palo Alto Networks NG Firewalls are considered some of the most secure firewalls available, offering robust protection when configured with strict security rules. Palo Alto firewalls maintain consistent security functionality across all models, with the primary difference being throughput capacity. While they previously faced criticism for their licensing model requiring separate purchases for features like URL filtering, their advanced malware detection, Wildfire and other integrated tools like IDS, IPS, and SIEM reporting provide comprehensive threat protection. Furthermore, their single-pass processing architecture mitigates the performance degradation typically associated with enabling multiple security features, ensuring consistent performance even with advanced threat protection enabled.

It can help reduce downtime caused by malicious insiders. If an employee intends to steal data on behalf of a competitor, these firewalls can help prevent data exfiltration and maintain network availability.

What is most valuable?

The most valuable feature of Palo Alto Networks NG Firewalls is Cortex Data Lake. This AI tool leverages data from 70,000 Palo Alto customers, correlating breaches and intrusion attempts into a back-end engine to analyze zero-day and incoming threats rapidly. This means if someone was attacked two days ago, I am protected from that same attack because the information is already in the system. My subscription to the Cortex Data Lake AI platform applies to my latest Palo Alto firewall, regardless of the specific model.

What needs improvement?

Palo Alto Networks NG Firewalls offer best-in-breed security but could improve by reducing their pricing. Their current premium pricing strategy limits accessibility for many customers. A more competitive pricing model would enable a wider range of organizations to benefit from their advanced security features.

For how long have I used the solution?

I have been using Palo Alto Networks NG Firewalls for 12 years.

What do I think about the stability of the solution?

Palo Alto Networks NG Firewalls are considered highly secure in the industry. Their main vulnerability stems from administrators configuring overly permissive rules. However, with appropriately configured policies, these firewalls can provide robust network security. 

What do I think about the scalability of the solution?

Palo Alto firewalls offer scalability across their various models, with throughput capacity being the primary differentiator. All models share a consistent set of security features, ensuring functionality remains the same regardless of the firewall's size. This simplifies adjustments as needs change.

How are customer service and support?

Customer service and support for Palo Alto Networks are excellent. They provide fast response and rapid remediation of problems.

How would you rate customer service and support?

Positive

How was the initial setup?

The initial setup is straightforward, especially with Palo Alto's zero-touch configuration concept. Plugging the firewall into the network and applying a predefined template allows quick and efficient deployment. With thorough network planning and pre-built configuration templates, firewall deployment can take less than an hour and be done by one person.

What was our ROI?

Increased data security and reduced cyber insurance premiums deliver a clear return on investment.

What's my experience with pricing, setup cost, and licensing?

Palo Alto Networks NG Firewalls have a higher price tag, costing roughly twice as much as competing products. However, this investment translates into substantial security advantages and has the potential to reduce cybersecurity insurance costs.

What other advice do I have?

I rate Palo Alto Networks NG Firewalls nine out of ten.

When choosing a firewall, consider the implications of prioritizing cost over security. Your vulnerability, attack surface, and the sensitivity of your data should factor into your decision. Industries like retail, aerospace, and engineering often handle sensitive data, making them attractive targets. Cyber insurance costs decrease as security measures increase. Opting for the cheapest firewall might lead to a significant increase in insurance premiums, potentially exceeding the price of a more robust firewall.

While no firewall is perfect, Palo Alto Networks NG Firewalls offer comprehensive security and reliable performance. However, choosing a firewall involves balancing cost with the sensitivity of your data and your risk tolerance. I recommend Palo Alto Networks NG Firewalls.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
Buyer's Guide
Palo Alto Networks NG Firewalls
January 2026
Learn what your peers think about Palo Alto Networks NG Firewalls. Get advice and tips from experienced pros sharing their opinions. Updated: January 2026.
881,114 professionals have used our research since 2012.
Jeelani Qadir - PeerSpot reviewer
Technical Lead at a consultancy with 10,001+ employees
Real User
Top 5
Nov 7, 2024
Highly valued for their performance and parallel processing architecture
Pros and Cons
  • "Palo Alto Networks NG Firewalls are highly valued for their performance and parallel processing architecture."
  • "The return on investment from Palo Alto Networks NG Firewalls is excellent."
  • "Palo Alto recently introduced a security analyzer in version ten, but this feature could be enhanced, and the URL filtering improved."
  • "Palo Alto recently introduced a security analyzer in version ten, but this feature could be enhanced, and the URL filtering improved."

What is our primary use case?

We use Palo Alto Networks Next-Generation Firewalls in our data center to manage security for both east-west and north-south traffic. These firewalls provide comprehensive protection for various traffic types, ensuring secure communication within the data center and between the data center and external networks.

How has it helped my organization?

Palo Alto Networks Next-Generation Firewalls provide a unified threat management solution with various security features, including threat prevention, URL filtering, security policies, and zone protection. These features are crucial for internet-level protection, enabling URL filtering, threat prevention, security policies, user identification, and a comprehensive VPN solution for site-to-site and remote access connections.

Palo Alto Networks Next-Generation Firewalls include WildFire, which uses machine learning for inline, real-time threat prevention.

It effectively secures our data centers with their application-based approach. Unlike traditional firewalls that solely rely on port numbers and IP addresses, these firewalls identify applications to determine whether to allow or block traffic. This enhanced inspection ensures only legitimate applications access the network, providing robust security.

It has also helped us reduce downtime because the failover is very swift and the performance is good. This offers us good throughput and parallel processing.

What is most valuable?

Palo Alto Networks NG Firewalls are highly valued for their performance and parallel processing architecture. Unlike traditional firewalls that operate based on ports, these next-generation firewalls are application-centric, identifying specific applications to provide enhanced security against a wider range of attacks.

What needs improvement?

Palo Alto recently introduced a security analyzer in version ten, but this feature could be enhanced, and the URL filtering improved.

For how long have I used the solution?

I have been using Palo Alto Networks NG Firewalls for almost eight years.

What do I think about the stability of the solution?

Palo Alto Networks NG Firewalls are stable and reliable when deployed and configured correctly.

What do I think about the scalability of the solution?

Palo Alto Networks Next-Generation Firewalls offer scalability both in the cloud and on-premises, but the methods differ. Cloud deployments benefit from auto-scaling, allowing for automatic adjustments to firewall capacity based on demand. On-premises solutions require manual provisioning of new hardware and subscriptions to achieve scalability.

How are customer service and support?

Palo Alto offers multiple tiers of support, including basic, premium, and premium plus. Overall, the technical support is good.

How would you rate customer service and support?

Neutral

Which solution did I use previously and why did I switch?

I have experience with both Check Point and Palo Alto firewalls. In a previous role, I worked with Check Point firewalls, while my current client utilizes Palo Alto firewalls.

How was the initial setup?

The initial deployment, while challenging, successfully validated Palo Alto's claims regarding throughput, session count, and parallel processing capabilities. Their assertion that enabling all engines does not cause packet rebuffering proved accurate, resulting in impressive performance. With a strong design and skilled architects, the deployment process ultimately proved efficient and successful.

What about the implementation team?

The migration tool assists in transferring configurations from systems like Cisco or Check Point, eliminating the need for manual migration.

What was our ROI?

The return on investment from Palo Alto Networks NG Firewalls is excellent. Their user-friendly interface and Panorama central management, which provides a comprehensive overview, make them an ideal investment.

What's my experience with pricing, setup cost, and licensing?

While Palo Alto Networks Next-Generation Firewalls may be considered expensive, their quality justifies the cost. They offer various support levels, including basic, premium, and premium plus, to cater to different needs.

I would recommend Cisco firewalls for those seeking the cheapest firewall.

Which other solutions did I evaluate?


What other advice do I have?

I would rate Palo Alto Networks NG Firewalls eight out of ten.

Palo Alto Networks NG Firewalls require maintenance due to the ongoing creation of new rules and policies, configuration changes, and necessary upgrades. For example, the operating system version is frequently updated, necessitating regular maintenance to ensure optimal performance and security.

The staffing needs for maintaining Palo Alto Networks NG Firewalls vary based on several factors, including the size and complexity of the organization. Key considerations include the number of data centers, hosted applications, users, and remote locations. Essentially, larger organizations with more users, devices, and network activity will require more personnel to effectively manage and maintain their firewall infrastructure.

Admins should be knowledgeable and should take proper training. It's essential to follow the correct configurations to avoid inconsistencies that may require significant maintenance.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
Director at a tech services company with 501-1,000 employees
Real User
Top 5
Dec 22, 2024
Leverage machine learning for real-time attack prevention but the configuration framework could be improved
Pros and Cons
  • "The most valuable features include the usual firewall functionalities, such as IPS and antivirus, which are effective."
  • "The effectiveness of this technology improves with each release, bolstering confidence in the product's ability to provide robust security."
  • "The configuration framework for Palo Alto Networks Next-Generation firewalls should be simplified, particularly for applications like ASG authentication."
  • "The configuration framework for Palo Alto Networks Next-Generation firewalls should be simplified, particularly for applications like ASG authentication. Technical support needs improvement, as issue resolution takes a significant amount of time."

What is our primary use case?

The primary use case is enterprise-level security. Our organization utilizes Palo Alto Networks Next-Generation Firewalls for internal security measures, including SD-WAN and SSL authentication configurations to establish secure network connections through the firewall.

How has it helped my organization?

Palo Alto Networks NG Firewalls provides a unified platform that natively integrates all security capabilities. The integration of machine learning in the core of the firewall that provides inline real-time attack prevention is crucial.

Palo Alto Networks NG firewalls embed machine learning in their core, which aids in preventing real-time attacks. The effectiveness of this technology improves with each release, bolstering confidence in the product's ability to provide robust security.

When we identify a vulnerability, we use Palo Alto Networks Next-Generation Firewalls to mitigate the threat.

We experienced no downtime in the past two and a half years while using Palo Alto Networks Next-Generation firewalls.

What is most valuable?

The most valuable features include the usual firewall functionalities, such as IPS and antivirus, which are effective. 

What needs improvement?

The configuration framework for Palo Alto Networks Next-Generation firewalls should be simplified, particularly for applications like ASG authentication. Technical support needs improvement, as issue resolution takes a significant amount of time. Furthermore, vulnerabilities in Palo Alto releases require prompt attention.

For how long have I used the solution?

I have worked with Palo Alto Networks NG Firewalls for more than ten years, and our company has used them for three years.

What do I think about the stability of the solution?

The overall stability of Palo Alto Networks NG firewall is good. I would rate it nine out of ten.

What do I think about the scalability of the solution?

The scalability of Palo Alto Networks NG Firewalls is good. I can comfortably rate it as an eight out of ten.

How are customer service and support?

Palo Alto Networks' technical support is generally good. However, some non-popular issues take longer to address.

How would you rate customer service and support?

Neutral

Which solution did I use previously and why did I switch?

Our organization initially utilized FortiGate firewalls. However, as we grew, we transitioned to Palo Alto Networks NG Firewalls due to their better performance in enterprise-level evaluations.

How was the initial setup?

Standard security configurations were straightforward to set up initially. However, adding portal security and application customizations posed challenges.

The deployment was small and required two to three people.

What about the implementation team?

Our experience with the integrator was mixed. While they provided some assistance, our team faced challenges configuring certain features, requiring additional support from Palo Alto and their partners.

What's my experience with pricing, setup cost, and licensing?

The pricing, setup cost, and licensing depend on the model. Overall, it is commercially competitive compared to Cisco and Fortinet. We paid less than $18,000.

Colleagues looking for the cheapest and fastest firewall can still use Palo Alto Networks NG Firewalls because they are affordable.

Which other solutions did I evaluate?

We evaluated several top products, including Fortinet, SonicWall, Sophos, and Cisco, before choosing Palo Alto Networks NG Firewalls.

What other advice do I have?

I rate Palo Alto Networks NG Firewalls a seven out of ten. While the features are satisfactory, improving the configuration framework and enhancing technical support would improve the product.

Palo Alto Networks NG Firewalls do not require maintenance.

We have 500 users in our organization.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Hrushikesh Pandit - PeerSpot reviewer
Senior Network Engineer L4 at a tech services company with 10,001+ employees
Real User
Top 20
Nov 24, 2024
Efficient threat management and automation drive reliability
Pros and Cons
  • "The most valuable features of Palo Alto Networks NG Firewalls are Threat Vault and AutoFocus."
  • "For colleagues seeking a cost-effective firewall, I recommend Palo Alto Networks NG Firewalls."
  • "Palo Alto Firewalls could improve by introducing more features, particularly in load balancing."
  • "Palo Alto Firewalls could improve by introducing more features, particularly in load balancing."

What is our primary use case?

The primary use case for Palo Alto is to address traffic-related issues and manage configurations pushed from Panorama to Palo Alto Firewalls. Additionally, it handles GPU-related challenges, global protect, and IP internal problems.

Both FortiGate and Cisco firewalls process network traffic sequentially, meaning each packet passes through security engines, e.g., security profiles and URL filtering, one by one, which can be time-consuming. In contrast, Palo Alto Networks NG Firewalls utilize single-pass parallel processing. When a packet arrives on an interface, the firewall creates multiple copies and sends them to all relevant security engines simultaneously. This parallel approach significantly reduces processing time and increases overall efficiency.

How has it helped my organization?

Palo Alto Networks Next-Generation Firewalls offer a comprehensive platform that seamlessly integrates all essential security functions, eliminating the need for multiple platforms. With integrated routing, switching, threat prevention, SASE, and Prisma capabilities, Palo Alto provides a centralized solution. A notable feature is the active-passive router configuration, enabling one firewall to be active while another remains on standby. Additionally, these firewalls incorporate SD-WAN, IPsec, and VPNs for enhanced network security and connectivity.

Palo Alto Networks NG Firewalls effectively utilize embedded machine learning to provide real-time attack prevention. Upon receiving a packet, the firewall performs an initial ingress phase analysis before passing it to the fast path for routing, switching, and connection establishment. Simultaneously, the security policy is checked. If a threat is detected, the initial packet is allowed through for analysis, while subsequent traffic is automatically blocked without the need for manual security policy configuration.

Our organization benefited from the comprehensive feature set of Palo Alto Networks NG Firewalls, eliminating the need for separate purchases of web-based firewalls, load balancers, routers, switches, Prisma devices, and SD-WAN devices. This saves our organizational costs.

Palo Alto provides strong security in our data centers and across all our workplaces.

Palo Alto Networks NG Firewalls reduce downtime and enhance network reliability and security through active-passive setups, where a secondary firewall automatically takes over if the primary one fails, ensuring continuous operation. These firewalls provide a seamless and efficient environment by automatically capturing logs and managing known threats. Advanced features like App-ID and Content-ID inspection enable deep packet inspection, identifying and mitigating threats even within encrypted files or those disguised as legitimate data, such as a virus bound to an MPG file. This comprehensive approach ensures robust security and minimizes the impact of malicious activities, regardless of the attacker's techniques.

What is most valuable?

The most valuable features of Palo Alto Networks NG Firewalls are Threat Vault and AutoFocus. Threat Vault allows us access to a comprehensive threat database, enabling us to get detailed information on threats and how to mitigate them. AutoFocus provides sandboxing capabilities, automatically addressing global threats.

What needs improvement?

Palo Alto Firewalls could improve by introducing more features, particularly in load balancing. Enhancing this capability would be beneficial.

For how long have I used the solution?

I have been working with Palo Alto NG Firewalls for six and a half years.

What do I think about the stability of the solution?

I would rate the stability of Palo Alto Networks NG Firewalls at eight and a half out of ten.

What do I think about the scalability of the solution?

Palo Alto Networks NG Firewalls are scalable and reliable. I have not faced any limitations with its scalability, and it is suitable for environments ranging from small offices to large data centers.

How are customer service and support?

Palo Alto provides good support.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

I previously worked with Cisco and FortiGate devices. I switched to Palo Alto Firewalls because of the comprehensive features offered by Palo Alto, including better hardware, software, and support.

How was the initial setup?

The initial setup was straightforward, taking about 20 to 30 minutes for one Palo Alto Network NG Firewall.

What about the implementation team?

The level two team was responsible for the configuration and setup process for Palo Alto Network NG Firewalls.

What's my experience with pricing, setup cost, and licensing?

I am not sure about the specific licensing costs of Palo Alto Networks NG Firewalls, but FortiGate and Palo Alto are generally cheaper than some high-end Cisco devices.

What other advice do I have?

I would rate Palo Alto Networks NG Firewalls eight out of ten.

For colleagues seeking a cost-effective firewall, I recommend Palo Alto Networks NG Firewalls. Despite not being the absolute cheapest, their robust hardware and software, combined with excellent support and comprehensive features, make them a more efficient and reliable long-term investment.

Palo Alto Networks NG Firewalls require maintenance.

I recommend considering Palo Alto for small or medium-sized environments due to its cost-efficiency, reliability, ease of use, and extensive features.

Which deployment model are you using for this solution?

Hybrid Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
reviewer2533908 - PeerSpot reviewer
Senior Network and Security Engineer at a computer software company with 501-1,000 employees
Real User
Top 20
Aug 25, 2024
It's a complete solution that's reliable, consistent, easy to manage, and full of rich security features
Pros and Cons
  • "Palo Alto solutions are scalable and highly capable. NG firewalls offer a complete solution that's reliable, consistent, easy to manage, and full of rich security features. They're easier than other firewalls and certainly more effective."
  • "Palo Alto could improve its machine-learning capabilities. That's all new. They integrate the telemetry data and analytics up to the cloud, where they can analyze for security policies and best practices like DNS Security. It uses AI tools to sort through all the massive logs and highlight where you can take action or be aware of what's happening. If you don't have many tools in your organization, it's nice to have one tool that does an excellent job across the board."

What is our primary use case?

We use Palo Alto firewalls to secure the enterprise network and connect our branch offices with our data centers.

How has it helped my organization?

A lot of Palo Alto's attack mitigation is automatic. It's nice that you can define security policies and profiles, and the firewall can automatically take action to mitigate attacks as they occur.

We can avoid downtime because Palo Alto supports high-availability firewalls, which usually enable us to do maintenance without interruption to the enterprise. We also have redundancy in our wide area, so we are not dependent on one internet provider. If it fails, we can route across an alternate provider through our VPN tunnels. 

What is most valuable?

Palo Alto solutions are scalable and highly capable. NG firewalls offer a complete solution that's reliable, consistent, easy to manage, and full of rich security features. They're easier than other firewalls and certainly more effective.

NG Firewalls provide a unified platform that natively integrates all security capabilities. It's critical to have a cohesive system that works across the entire organization. Palo Alto embeds machine learning into the firewall's core, which is necessary to keep up with the threat landscape. 

What needs improvement?

Palo Alto could improve its machine-learning capabilities. That's all new. They integrate the telemetry data and analytics up to the cloud, where they can analyze security policies and best practices like DNS Security. It uses AI tools to sort through all the massive logs and highlight where you can take action or be aware of what's happening. If you don't have many tools in your organization, it's nice to have one tool that does an excellent job across the board. 

For how long have I used the solution?

I have used Palo Alto NG Firewalls for five and a half years. 

What do I think about the scalability of the solution?

Palo Alto firewalls have excellent scalability. The same techniques and configuration scale from a small branch office to larger data centers. They're consistent in terms of configuration. You have centralized administration through Panorama to manage all of them easily and have global visibility with both configuration and logging.

How are customer service and support?

I rate Palo Alto support seven out of 10. Palo Alto has some excellent engineers, but recently, I've had difficulty finding a technician who can solve the problem quickly.  They're easy to reach, but it's sometimes harder to communicate with the support engineers. Some are more effective, but other engineers take a couple of days to analyze the issue. The support is not as good as it used to be.

How would you rate customer service and support?

Neutral

Which solution did I use previously and why did I switch?

I've used other brands of firewalls in another company, and this company has used some older firewalls. I have used Juniper SRX and NetScreen firewalls. I've also worked with Cisco ASA and SonicWall firewalls.

Palo Alto firewalls provide better visibility into the data and excellent logging that enables you to track all threats and activity. They seem to be more resilient to attacks. Other brands get overwhelmed by DDOS attacks, whereas Palo Alto has multiple levels of security that can head off some of those floods. They act almost like an intrusion detection system and some form of DDoS protection. They do a good job if you can't afford a separate product.

How was the initial setup?

I rate Palo Alto NG firewalls nine out of 10 for ease of setup. They're easier to set up than Juniper SRX or NetScreen. When I arrived, they had already installed a few firewalls, but they weren't working well. The failover and high availability were not set up properly. 

They were new to Palo Alto. They started deploying a few in their branch offices and configuring them with Panorama, so they're all registered and centrally administered. There are consistent policies and shared objects across your organization for filtering geographic regions and things like that. 

The IT VP administered some of the network after their other engineer left. They had previously used Fortinet and only recently purchased Palo Altos, but they were trying to get them deployed. As a senior network engineer, I deployed it with the IT VP, and the IT manager made some operational changes. I and a member of my team maintain the firewalls. 

What was our ROI?

Palo Alto enables you to support an extensive, busy network with fewer people. You can centrally administer the solution and apply automated content updates for virus and threat prevention. Once you get these things set up, they do a lot of it independently. You only need to keep a close watch on them. 

What's my experience with pricing, setup cost, and licensing?

Palo Alto can be priced higher than some less capable firewalls. However, they are exceptional when you consider the completeness of the solution and its ability to handle threats. Palo Alto is better than other solutions, which justifies a slightly higher price point. You have other tools that are easier to deploy, reducing your total cost of ownership. The newer models are faster, making the pricing more attractive.

A cheaper solution might be better if you have a small or home business that doesn't have many security requirements. Palo Alto scales down to small offices and larger data centers and enterprises. Their product scales to a wide range of use cases. 

What other advice do I have?

I rate Palo Alto NG Firewalls 10 out of 10. I recommend spending time with Palo Alto and other support partners planning and understanding your network before you deploy. You can simplify many capabilities into common rules that you can apply consistently across the organization to save time. Planning can help you build consistency in naming address objects, VLANs, and network resources.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer1260276 - PeerSpot reviewer
Technical Engineer - Technical Security at a tech services company with 1,001-5,000 employees
Real User
Top 10
Nov 27, 2024
It incorporates machine learning into the firewall and reduces downtime, but enabling multiple features can lead to performance degradation
Pros and Cons
  • "The most valuable features of Palo Alto Networks NG Firewalls are DNS sync calls, enabled security features, and Wildfire."
  • "Palo Alto Networks NG Firewalls helped reduce our downtime."
  • "The machine learning component on the firewall level requires more computing power to perform at the full production level."
  • "The machine learning component on the firewall level requires more computing power to perform at the full production level. Therefore, the ML is currently providing partial real-time attack prevention."

What is our primary use case?

Palo Alto Networks NG Firewalls are our perimeter firewalls that protect the network from external attackers. They provide visibility into network activity, from layer four to layer seven, including application visibility, user awareness, and content awareness. These features are crucial for any network and organization, regardless of size, whether it's 20 users or two million users – they all need a firewall.

How has it helped my organization?

It's crucial that the entire cybersecurity landscape shifts from traditional methods to artificial intelligence and machine learning. When vendors stay current with emerging and future technologies, they're better positioned for success. This proactive approach ensures they remain relevant and effective in the ever-evolving cybersecurity space.

Palo Alto Networks NG Firewalls helped reduce our downtime.

What is most valuable?

The most valuable features of Palo Alto Networks NG Firewalls are DNS sync calls, enabled security features, and Wildfire.

What needs improvement?

The machine learning component on the firewall level requires more computing power to perform at the full production level. Therefore, the ML is currently providing partial real-time attack prevention.

In large data centers, enabling multiple features, such as SSL decryption, can lead to performance degradation. This is especially noticeable in Palo Alto firewalls when SSL inspection is enabled. Ideally, this shouldn't happen. To address this, enterprises are often forced to upgrade to higher-end models, which is unnecessary. Palo Alto needs to address this issue. When performance degrades due to full packet inspection, the solution should be to increase the computing power within the same firewall, not to recommend upgrading to a larger, more expensive model. Performance issues during full inspection need to be resolved without requiring hardware upgrades.

The technical support has room for improvement.

For how long have I used the solution?

I have been using Palo Alto Networks NG Firewalls for five years.

What do I think about the stability of the solution?

I would rate the stability of Palo Alto Networks NG Firewalls six out of ten. After the upgrade, we are experiencing performance issues. Occasionally, we need to reboot the firewalls to refresh and recreate sessions. Gradually, performance returns to normal. Immediately following the upgrades, performance and utilization spike significantly.

What do I think about the scalability of the solution?

I would rate the scalability of Palo Alto Networks NG Firewalls eight out of ten.

Which solution did I use previously and why did I switch?

We previously used Checkpoint firewalls, but the performance was subpar and lacked an available interface. In contrast, Palo Alto Networks NG Firewalls offered more interfaces.

How was the initial setup?

The initial deployment was not complex but we did face some issues with respect to dynamic routing configurations.

What about the implementation team?

We used a third-party for the deployment.

What was our ROI?

We have observed an average return on investment from Palo Alto Networks NG Firewalls.

What's my experience with pricing, setup cost, and licensing?

Palo Alto Networks NG Firewalls are expensive. The total cost of ownership is high.

What other advice do I have?

I would rate Palo Alto Networks NG Firewalls six out of ten.

For those looking for the cheapest NG firewall, I would recommend Fortinet.

We deployed a total of four Palo Alto Networks NG Firewalls, two in the data center and two in the data recovery center. We have a total of 1,800 endpoints in our organization.

Frequent updates necessitate regular maintenance, which requires a team of four people.

Before purchasing, conduct a proof of concept to verify functionality, alignment with use cases and organizational requirements. Validate hardware compatibility and ensure correct sizing. Opt for direct Palo Alto OEM support instead of partner-enabled support.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
PeerSpot user
IP / Operations Support System Engineer; Pre-Sales Engineer at a tech services company with 1-10 employees
Real User
Top 20
Nov 24, 2024
Good features, high reliability, and fast support
Pros and Cons
  • "The most valuable feature is threat prevention."
  • "The solution is very stable and reliable."
  • "It is a good product, but they can add some functions for port scanning and network scanning."
  • "It is a good product, but they can add some functions for port scanning and network scanning."

What is our primary use case?

In our country, there are multiple use cases. Usually, it is for virtual cases or virtual environments and source areas.

What is most valuable?

The most valuable feature is threat prevention. SSL VPN is also very valuable. These are essential for our clients, especially for access to local infrastructure while preventing Internet threats.

Our clients can have a unified cybersecurity system if they subscribe to it. This firewall is an important part of access to any data center or branch office. They have site-to-site connectivity.

What needs improvement?

It is a good product, but they can add some functions for port scanning and network scanning. More network functionality would be beneficial.

For how long have I used the solution?

I have been working with the new generation firewall from Palo Alto Networks for two years.

What do I think about the stability of the solution?

The solution is very stable and reliable. I have not experienced any outages or issues. I would rate it a ten out of ten for stability.

What do I think about the scalability of the solution?

The solution is scalable if the right model is purchased. It is important to assess the infrastructure size before choosing a model.

How are customer service and support?

The technical support is very good. They offer fast and competent assistance. I would rate them a ten out of ten.

How would you rate customer service and support?

Positive

How was the initial setup?

Its deployment is easy. It takes two to three days.

The initial setup process involves basic and network configuration, security and policy configuration, and then getting the device to the client.

It does not require much maintenance. One person is enough for it.

What's my experience with pricing, setup cost, and licensing?

Its price is quite high but is justified for the features and capabilities provided, although I would prefer a lower price.

What other advice do I have?

If you have the budget, I would recommend using Palo Alto Networks NG Firewalls instead of other brands because they offer the greatest functionality.

I would rate Palo Alto Networks NG Firewalls a ten out of ten.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
Buyer's Guide
Download our free Palo Alto Networks NG Firewalls Report and get advice and tips from experienced pros sharing their opinions.
Updated: January 2026
Product Categories
Firewalls
Buyer's Guide
Download our free Palo Alto Networks NG Firewalls Report and get advice and tips from experienced pros sharing their opinions.