No more typing reviews! Try our Samantha, our new voice AI agent.
NimeshaBalasuriya - PeerSpot reviewer
Security Engineer at Sri Lanka Telecom Ltd
Real User
Feb 1, 2023
A unified platform that natively integrates all security capabilities
Pros and Cons
  • "Most of the features in Palo Alto are very valuable."
  • "Most other VPN clients include mobile VPNs but Palo Alto does not."

What is our primary use case?

Palo Alto is used as our organization's perimeter firewall. In fact, it is our data center. We use it to protect our perimeter level. The model that we use is the PA-5020, which is a bare metal device.

I currently work in ISP operations, where we host DNS servers for customers and also have a few AAA servers for broadband authentication. In Sri Lanka, there are ADSL customers and broadband customers, who authenticate against our AAA service. Additionally, we also protect our internal members using Palo Alto firewalls.

How has it helped my organization?

In the event that Palo Alto Networks NG Firewalls detect evolving and rapidly moving threats, we get help from the Palo Alto teams to resolve the issues. We do the level one troubleshooting and then open a tactic attempt to pass that to tech managers for resolution.

Previously, there were a couple of limited features available from GlobalProtect. However, after introducing these new features, the solution has been very helpful for us. This is very important.

We are a telecommunication service provider and we offer many IT services to our customers. The recent attack has made it very important for us to take precautions. Having a unified platform for our organization is an integral part of being able to identify and address attacks quickly.

What is most valuable?

Most of the features in Palo Alto are very valuable. Recently, in the COVID pandemic situation, we used SSL VPN through GlobalProtect from Palo Alto, which was very helpful for us to do work at home. We use general category-based filtering. Palo Alto is a very sophisticated firewall.

Palo Alto Networks NG Firewalls machine learning in the core of the firewall to prevent attacks is very important. Previously, our country was not targeted by attackers, but recently, we have identified that there are a couple of situations happening in our country. Recently, there has been an unstable political situation in our country, and during that time period, many attackers have been trying to infiltrate our networks. We definitely have to go to the next-generation features such as the Next-Generation Firewalls.

Having a unified platform that natively integrates all security capabilities is a great feature. We previously used a single management platform, Panorama from Palo Alto, across all of our Palo Alto products. However, Panorama is no longer being supported, due to its end-of-life status.

Having a unified platform helped to eliminate security holes. Between the UTM platforms, and Palo Alto, all features are available in one firewall, so we don't need to buy different products or separate IPS devices and separate antivirus devices. In Palo Alto UTM firewalls, most of the features are available such as antivirus with filtering, which is very important.

The solution is user-friendly.

What needs improvement?

The pricing of the solution is high and can be improved.

Most other VPN clients include mobile VPNs but Palo Alto does not. We are required to purchase the mobile VPN clients separately. During our RFPs we have noticed that most features by vendors are similar but the price for those features is higher with Palo Alto.

Buyer's Guide
Palo Alto Networks NG Firewalls
September 2026
Learn what your peers think about Palo Alto Networks NG Firewalls. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
914,351 professionals have used our research since 2012.

For how long have I used the solution?

I have been using the solution for seven years.

What do I think about the stability of the solution?

The solution is very stable.

What do I think about the scalability of the solution?

I'm not seeing scalability problems in my scenario, but overall Palo Alto is doing well in terms of scalability. I'm using ten licenses for V systems and the port density is good.

There are five firewall administrators, two engineers, and three technical staff. In my department, there are thirty users and during the work-from-home scenario, all of them are connecting through the SSL VPN. Thirty plus users in our organization and the request for the service that is in our country, in our broadband customer segment are 1,500 thousand.

The solution is at the end of the life cycle and we are in the process of upgrading.

How are customer service and support?

The support from the tech team is good, and their response is fine.

Which solution did I use previously and why did I switch?

There is a tendering process in my organization, so products that are technically qualified go through a two-stage process: the first stage is the technical qualification stage and the second stage is the financial qualification stage. However, in the end, everything comes down to finances, and that's why Palo Alto was awarded the tender and we switched from Check Point.

The first thing we did was install a client to manage the Check Point firewall. However, I think the new versions which operate at this time don't need the client. Previously, it definitely required a client, so that was a headache. Palo Alto is not like that, it's a dual-based configuration. Also, when we apply the rules, it's also very easy in Palo Alto. Another important aspect is that Palo Alto uses its own based firewall, and Check Point does not. We have to put the configuration to interfaces and likewise. This is very helpful because in my network, in some cases, we have to have a couple of interfaces that are met with the source, and we have to easily apply rules by selecting the source.

How was the initial setup?

The initial setup is straightforward. I was in the deployment stage when this firewall came to my organization. Palo Alto includes a quick reference guide in the box. For an initial setup, everything is available in that quick reference guide. 

We had the Check Point firewall previously and after the tender process, Palo Alto was selected as the new replacement. We took three to four weeks to migrate all the Check Point rules. We migrated around 100 to 150 rules from Check Point to Palo Alto which was very easy.

There is a team in my organization made up of engineers and technical officers. Working under the engineers the technical officers are responsible for the physical implementation of everything. I am an engineer in my organization, and engineers are responsible for installing programs and configurations. We have a timeline to meet for every new implementation, which is a project for us.

In the deployment stage, we had six or seven members on the deployment team. After deployment, we now have two engineers and three technical staff, for a total of five people who perform maintenance.

What about the implementation team?

The implementation was completed in-house.

What was our ROI?

My firewall is used to protect my internet servers. This means that the servers provide services to our broadband customers. After taking the revenue from broadband customers, Palo Alto is almost covered. However, there is no direct ROI for Palo Alto in my setup.

What's my experience with pricing, setup cost, and licensing?

We are purchasing an annual subscription for signatures, and categories. Our box has ten perpetual licenses for V Systems.

We don't have licenses for SSL VPNs because it is included in the box. For VPNs, we don't need a license. However, if we use the Power VPN client on our mobile devices, we need to purchase the client software.

Which other solutions did I evaluate?

Before choosing Palo Alto, we evaluated Check Point and FortiGate.

What other advice do I have?

I give the solution a nine out of ten.

We are currently in the process of procuring a new parallel processing solution. Our current parallel processing solution is reaching the end of its life in 2023, so we need to find a new solution by March 2023. Ideally, we would like to find a new solution from Palo Alto, but the selection process is still in progress so I can't say for sure which model will be chosen.

In the past seven years I have been using the solution, I have only had to open ten tickets for support.

The zero delay signature feature is not implemented because our license is not enabled in our firewall. We use layer seven filtering for our data center.

Palo Alto Networks NG Firewalls are protecting our data center. Almost all our country's broadband users request access through this firewall.

I can recommend the Palo Alto firewall for other companies as a perimeter firewall, as a data center, and as a work-from-home scenario for SSL VPN, but I don't have experience with it as a managed service.

To any potential new users, definitely go for Palo Alto, don't worry about its sophistication. With all my experience using Palo Alto, I have had very minor issues. I recommend Palo Alto as a company network solution.

The configuration of the solution is nice. During the time period that I have used Palo Alto, I have had only a few tickets raised and the tech support is helpful. Palo Alto firewalls cover most security threats.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Sachin Vinay - PeerSpot reviewer
Assistant Manager-Networks at a university with 1,001-5,000 employees
Real User
Top 5Leaderboard
Nov 3, 2022
Supports single-pass architecture, provides comprehensive security, and is cost-effective
Pros and Cons
  • "It has a unique approach to packet processing. It has single-pass architecture. We can easily perform policy lookups, application decoding, and integration or merging. This can be all done with a single pass. It effectively reduces the amount of processing required to perform multiple actions. This is the main advantage of using Palo Alto."
  • "With this Palo Alto firewall, we are able to manage DNS security in a single device because it has single-pass architecture."
  • "It is a complete product, but the SSL inspection feature requires some improvements. We need to deploy certificates at each end point to completely work out the UTM solutions. If you enable SSL encryption, it is a tedious process. It takes a lot of time to deploy the certificates to all endpoints. Without SSL inspection, UTM features will not work properly. So, we are forced to enable this SSL inspection feature."
  • "It is a complete product, but the SSL inspection feature requires some improvements."

What is our primary use case?

We are using PA-820. This Palo Alto series is being used in our separate branch office. We are managing surveillance and internet activities with this Next-Generation security firewall. We are using the UTM features and running best security practices through this firewall. Moreover, VPNs and other remote access security features are being implemented in our environment with this firewall.

How has it helped my organization?

It has a very good security database for attack prevention. There are many security breaches, and most of the 2022 security breaches use automation. It has a really good automation engine that clearly prevents new types of attacks. We recently avoided an attack with Palo Alto.

DNS security is super good in this. Its DNS attack coverage is 40% more, and it can disrupt 80% of attacks that use DNS. Without requiring any change in your infrastructure, you can avoid the attacks. With this Palo Alto firewall, we are able to manage DNS security in a single device because it has single-pass architecture.

It provides a unified platform that natively integrates all security capabilities. It has a VPN. We don't need to go for additional security features or devices in our environment. It is an all-in-one solution. With other firewalls, such as FortiGate, you require separate licenses. For example, for high availability, you would require an additional license, which is not the case with Palo Alto. In this way, Palo Alto is completely in line with our budget requirements. We are also planning to go with the higher version of Palo Alto firewalls in our environments.

It has helped to eliminate security holes. It creates a usage pattern with its machine learning and artificial intelligence features. It uses a good amount of artificial intelligence to create a pattern. If there are any changes in the usage pattern, it notifies us, and we are able to take action.

In our environment, we are running a lot of production servers. So, we cannot compromise on security. We give more priority to security than performance in our architecture. We put 70% focus on security and 30% on performance. Palo Alto completely suits our requirements. They have three-tier security. We can see the application layer traffic, network layer traffic, and session layer traffic.

It integrates perfectly. It integrates with SIEM solutions such as Darktrace. For log analysis, we are able to completely retrieve the logs.

What is most valuable?

The most important feature is advanced threat prevention. It stops most malware. It provides 96% or 97% prevention against malware. It has a leading intrusion prevention system in the industry. It is really good at malware prevention. It ensures that files are saved in a good and secure environment. It automatically detects and prevents unknown malware with its powerful malware prevention engine. 

It has a unique approach to packet processing. It has single-pass architecture. We can easily perform policy lookups, application decoding, and integration or merging. This can be all done with a single pass. It effectively reduces the amount of processing required to perform multiple actions. This is the main advantage of using Palo Alto.

What needs improvement?

It is a complete product, but the SSL inspection feature requires some improvements. We need to deploy certificates at each end point to completely work out the UTM solutions. If you enable SSL encryption, it is a tedious process. It takes a lot of time to deploy the certificates to all endpoints. Without SSL inspection, UTM features will not work properly. So, we are forced to enable this SSL inspection feature. 

For how long have I used the solution?

It has been three years.

What do I think about the stability of the solution?

It is extremely stable.

What do I think about the scalability of the solution?

It is scalable. There is a VM solution also, so it is completely scalable. 

We have about 3,000 users in our branch office. In terms of our plans to increase its usage, we are also planning to go for Palo Alto as our main firewall. We are planning to go with the higher-end version.

How are customer service and support?

I would rate them an eight out of ten.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

In our branch office, before the Palo Alto firewall implementation, we have been using FortiGate. We switched because of the budgetary requirements. With FortiGate, for the high availability feature, we required two devices. We had to buy two licenses, whereas Palo Alto required only one license. It was completely in tune with our budget. So, we had to go with Palo Alto.

FortiGate did not have single-pass architecture. It took a huge amount of resources for each action. For policy lookups, it took a considerable amount of system resources, such as CPU, RAM, etc. The waiting time was too high for policy lookup, application decoding, and signature matching. All this is carried out in a single pass in Palo Alto. So, it is considerably fast and also secure. There is no compromise in terms of security. It is completely secure, and we are able to do more functions in a single pass with the Palo Alto firewall. So, we save a lot of resources. With FortiGate, security was around 50%. After the implementation of PA 820, it has increased to 80%. We have achieved about a 30% increase in security. Even though PA 820 is not a higher-end series, performance-wise, it matches the higher-end series of FortiGate. So, there is a considerable amount of cost savings. We are able to save 20% to 30% extra.

In our organization, we have multiple vendors. We have FortiGate, Cisco ASA, and other security implementations. We have already purchased many other products. So, we cannot simply suggest Palo Alto across the organization. We have to consider the older purchases.

Palo Alto is a good competitor to FortiGate. Cisco, FortiGate, and Palo Alto are the three main competitors. When we compare these products, they have similarities, but I would suggest going with Palo Alto for higher security. If you are giving more priority to security and less priority to performance, definitely consider this. Cisco ASA and FortiGate are more performance-oriented. So, if you are planning to give more priority to security, I would definitely suggest Palo Alto.

How was the initial setup?

Its initial setup was complex. It was not straightforward. It required a considerable amount of time and effort. Migration was a little bit complex because we had a different vendor product. Migrating to this product required a considerable amount of time and planning because we didn't want to disrupt the networking in our existing environment. It took a good amount of planning and decision-making to migrate to Palo Alto.

Its deployment took about a week. In terms of the implementation strategy, we were deploying it at the branch office. We already had a solution there. So, we had to completely migrate the policies and everything else. We also had to identify the interfaces with the utmost urgency. We first migrated important interfaces and made sure that they all are working fine and all the security features are working fine. After that, we enabled all the policies and other features. In this way, we were able to completely migrate in seven days.

What about the implementation team?

It required three network administrators. They are responsible for actively managing the firewall configurations, taking backups, etc.

What was our ROI?

With this highly secure environment, we are able to maintain our production-level servers on-premises. We were planning to move them to the cloud for security, but with the implementation of Palo Alto, we were able to maintain them on-premises. We could create a considerable amount of production service, and thereby, we had a great return on investment through this.

What's my experience with pricing, setup cost, and licensing?

It is not that expensive. I would rate it an eight out of ten in terms of pricing. Other than the licensing, there are no additional costs.

Which other solutions did I evaluate?

We didn't evaluate anything other than FortiGate and Palo Alto.

What other advice do I have?

I would recommend this solution if security is more important to you. If the performance of the users is more important, I would not suggest Palo Alto. It gives more priority and weight to security. It has a complete security mechanism with AI, log-based analysis, etc. I would recommend it for higher cybersecurity and IT-related environments.

I would rate it a nine out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Palo Alto Networks NG Firewalls
September 2026
Learn what your peers think about Palo Alto Networks NG Firewalls. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
914,351 professionals have used our research since 2012.
Berry Wilson - PeerSpot reviewer
DevOps Security at a tech vendor with 10,001+ employees
MSP
Sep 3, 2024
Secures data centers consistently across all workplaces
Pros and Cons
  • "The ease of updating the platform was valuable. We could easily update the OS and different modules within the platform. It was a fairly user-friendly and easy-to-use platform."
  • "It is probably as good as it can be in terms of being highly sophisticated but having a very small leap to learn the platform and deploy it. I do not have many complaints about the platform."

What is our primary use case?

I have used it in a couple of different ways. One way was to use it as a perimeter device and to act like a traditional firewall for controlling the traffic in and out of the network and doing intrusion detection. It was more of a filtering-type device for remote access and VPNs. 

At another job, we used it as a site-to-site VPN. We scanned customer applications and code over a site-to-site VPN. These were the two main use cases that I have done over the last eight years with Palo Alto.

How has it helped my organization?

It integrates very well with AWS Cloud. We use the VM-Series of Palo Alto firewalls. It is good.

It is very important that Palo Alto Networks NG Firewalls provide a unified platform that natively integrates all security capabilities. That is because it is a very sophisticated environment when you start talking about the cloud and software-defined networking. When you think about that level of complexity, to have somebody like Palo Alto and AWS work together to make the deployment of those devices seamless is an incredible benefit to users.

There are different types of modules to provide defense for customers. It is pretty amazing.

It can secure data centers consistently across all workplaces. It is no secret that Palo Alto has made a large footprint in the industry when it comes to those types of security services. When you talk about the data centers and things like that, Palo Alto scales well. They are doing a great job.

In terms of downtime reduction, downtime is relative. There are many different types of elements that can cause downtime. It could be some type of attack or just a configuration change. However, things like Panorama and high availability embedded in the platform allow for high availability.

What is most valuable?

The ease of updating the platform was valuable. We could easily update the OS and different modules within the platform. It was a fairly user-friendly and easy-to-use platform. 

We found it to be fairly stable as well. It was largely stable.

What needs improvement?

Overall, when you consider how sophisticated the appliance or the platform is, they have done a remarkable job. It is probably as good as it can be in terms of being highly sophisticated but having a very small leap to learn the platform and deploy it. I do not have many complaints about the platform.

For how long have I used the solution?

I have worked with this solution for about eight years.

How are customer service and support?

Palo Alto has a great support ecosystem. I only had one issue with somebody, but we got that addressed. It was just like any industry or business. You are going to have some people who do not want to act right, but overall, they have high-quality support.

I would rate them an eight out of ten. I am a customer, and I am involved in high-pressure situations. I am always going to say that I want a quicker response, but when I am being flat-out honest and reasonable, they are as good as they could possibly be without overstepping.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

We have used Check Point. I did not like Check Point at all. It is very cumbersome, so I definitely would not recommend it. 

I found the Cisco ASA line to be overly complicated for what it needs to be, but that is the history of Cisco. They have very capable devices, but they are definitely not as friendly, in my opinion. I would give a nod to Palo Alto. Palo Alto GUI seems to be a little bit easier to navigate. Cisco devices have always been very capable, but they have a steeper learning curve.

How was the initial setup?

It is fairly simple. It is as simple as it can be to get started.

The number of people required depends on the environment and the type of project that you are doing. If you are designated to deploy it as a perimeter device, you do not need that many people. If you have a situation where it is in the cloud and you have to do a lot of other things to get traffic to the device, configure the interfaces in the cloud, and later create policies and bring everything into Palo Alto, it is a more sophisticated process. You need somebody very knowledgeable about that, or you need multiple people to work that out.

What about the implementation team?

We have had some complex scenarios, but I was fairly knowledgeable about AWS and the firewalls, so I was able to put everything together myself. I did not require any third-party help.

What was our ROI?

It is a pretty significant return on investment if a device does what it says it will do, and it has a small learning curve and good stability.

What's my experience with pricing, setup cost, and licensing?

I do not have much opinion on that because I have not been involved in the procurement process of the Palo Alto devices with the exception of pay-as-you-go through AWS, but all of this stuff is very expensive, in my opinion.

What other advice do I have?

I will be a little bit pessimistic and rate it a nine out of ten, but I feel that it is a ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Manager at a tech services company with 51-200 employees
Real User
Dec 29, 2022
Helps eliminate the need for multiple network security tools, removes security gaps, and is stable
Pros and Cons
  • "The solution does a great job of identifying malicious items and vulnerabilities with URL filtering."
  • "The user interface can be significantly simplified."

What is our primary use case?

We use the solution to filter out the traffic from our internal networks, not a public-facing network.

How has it helped my organization?

The predictive analytics and machine learning for blocking DNS-related attacks keep track of IP addresses and DNS names from other countries requesting access to our resources. The solution helps us identify any malicious activity and maintain our network safety. We first check the DNS issue and put it into the blacklist. If we get a similar DNS issue from another country in the future, we block the IP range altogether.

Apart from traditional technologies, we have been relying on signature-based identities. For example, we have been following up on what is in the data system and the firewall. These systems can only detect what has already been returned by the data system. If any security vendor does not update its databases or firewalls, or if its upgrades or firmware are not up to date, then malicious attacks can occur. The advantage of Palo Alto is its real-time analysis, as opposed to traditional methods that use signatures. Palo Alto Network NG Firewall has come up with some great behavioral analytics and the Wildfire feature, which helps organizations stay safe from false positive notifications or alerts.

The unified platform helps eliminate security gaps. We had certain servers that we hosted with open ports and we needed to ensure that these ports were closed. When we first set up the solution in the production environment for testing purposes, we detected traffic coming from ports on the server that had not been identified by our previous firewall. Palo Alto Network NG Firewalls uses all of its resources to detect security threats. The solution helps our organization close security vulnerabilities, Palo Alto Network NG Firewalls provide us with the instruments we need to complete our job. 

The unified platform helped eliminate multiple network security tools and the effort needed to get them to work together. We need to be able to detect the type of traffic being generated from which applications are on which systems and by which users. This will help us identify which IPs are making the requests. Previously we had to rely on multiple tools to collect this information. Palo Alto Network NG Firewalls also provide one graphical interface to display all the information. The solution simplified the process by dropping two to three tools and giving us a clear view of some first-hand data, especially data that has been preliminarily investigated in the case of cybercrime, which is essential.

Security is our primary concern which we build our networking concept around and networking is secondary. We have a single sign-on agent and a dedicated service to run the firewalls. Our architecture is set up in a way that, if a DDoS attack occurs, all the traffic would go down and we have to be prepared. When we consider both the network and security features, we are more inclined toward the security side. Our clients are usually understanding if the downtime is only two to ten minutes and we can recover quickly. 

There are no actual delays happening on the side of setting the solution up because we have all the resources documented on YouTube and on the website itself. We haven't experienced any delays in identifying and collecting the documents or installing the server. However, once we began the onboarding process, some technical issues arose. We forgot to include a customer's request for support from Palo Alto and as a result, the customer executed support themselves either through our website or a call, but a customer service agent acknowledged and resolved the request quickly. Because of that issue, we have been able to allocate adequate resources for implementation. We feel as if we are receiving premium service.

What is most valuable?

The most valuable features of Palo Alto Network NG Firewalls are policy editing and rule assigning for firewalls, as well as Wildfire. The solution does a great job of identifying malicious items and vulnerabilities with URL filtering. When combined with Fortinet, we have instant results.

Palo Alto Network NG Firewalls is doing impressive work with its AI technology, which is important to our organization. I have forwarded the papers to the director board in a recommendation to make the solution public-facing. We are considering using Palo Alto as an internet-facing firewall for our next project because the solution is an excellent firewall appliance with impressive features and a great UI.

What needs improvement?

The user interface can be significantly simplified. The dashboard and other features can be more thoughtfully designed. We get all the data in a single dashboard, which gives us additional insights. However, it takes time to sort it all out so it's easily accessible. If the data can be presented in a more graphical and structured way, it would be more helpful.

For how long have I used the solution?

I have been using the solution for eight months.

What do I think about the stability of the solution?

We have had a very minimal number of false positives with the solution and it has been very stable. There have been no issues with the firewall itself. In the previous case, we had a lot of tension between the firmware update and the customer service department. This was due to the system working itself up. We had absolutely zero capability issues.

What do I think about the scalability of the solution?

The solution is scalable with the Azure environment. I believe it is scalable because we have many data connectors. We were able to speed up the process within the hybrid environment.

How are customer service and support?

We had some technical support from Palo Alto at the time of installation.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

We have been using the FortiGate firewall for almost 20 years in our environment, but we recognized the Wildfire feature and some of the AIM firewall systems. FortiGate is not a next-gen firewall. Other applications such as Gartner insight offer better connections and recommend a firewall, similar to Palo Alto Networking NG Firewalls, for better application performance. We procured the solution and we have been testing it. We don't like to put all our eggs in one basket. We need multiple firewall solutions to connect with our environment. If one fails for any reason, we can have the second one take over the job. We have servers hosted in the cloud environment and each server has a different firewall installed. If we lose our connection due to a firewall issue, a firmware issue, or if Fortinet couldn't detect malware or a zero-day attack, we would be out of luck without Palo Alto Networks NG Firewalls. We are considering utilizing both solutions to best suit our needs. 

How was the initial setup?

The initial setup is straightforward. Depending on the resources and skill set of the network engineers the deployment should take between 15 and 20 minutes.

What's my experience with pricing, setup cost, and licensing?

The solution provides good protection and is worth the price.

The only additional cost to our organization comes from having to train our engineers on the proper use of the solution.

What other advice do I have?

I give the solution an eight out of ten.

We have two network administrators, which have been working on the design end, three analysts working on the system itself who are continuously monitoring the firewall status, three cybersecurity engineers, and two network engineers to deal with the networking concepts and any delays with the networking protocols. We also have three cybersecurity engineers to follow up with the monitoring, checking the security incidents, and responding. In total there are five users administrating this firewall on eight servers. The firewall acts as a router, filtering the packages between five servers on the other side. This provides an eight versus five network filtering job. The firewall is not public-facing. We are utilizing it to filter up the data, and packets of files, which are moving between the load balances.

We have an environment for production and for development. The development environment is for scaling our application. The production environment goes to the public, and we have a staging environment for testing our application. We have a joint venture with our clients, which we call UIT. This joint venture helps to reduce costs and create an environment that is beneficial for both our clients and us. We only use our staging environment occasionally, whenever we need to push something new to our service for testing purposes. It will be used around two to three days a week, or twelve to fifteen days a month. We are underutilizing the solution currently because we have only completed five percent of the development. We have analyzed the cost and are trying to procure the solution in our live environment.

The cost of security can be expensive when we analyze new technology and the need for new technologies to cover emerging vulnerabilities and malicious acts. I recommend Palo Alto Networks NG Firewalls because most of the colleagues in our environment, such as Cognizant, Deloitte, and many other IT companies use Palo Alto Networks NG Firewalls. 10 to 12 years ago, Fortinet was the leading security solution that most people were using followed by Cisco Firewall. Presently Palo Alto Networks NG Firewalls provide the most value from a security solution, such as the detection of vulnerabilities and malware, in a cost-effective way. 

Apart from the standard features of any firewall system, Palo Alto Networks offers some additional benefits that make it worth the price. These features include URL filtering and deep packet inspection, with the best feature being Wildfire. I recommend the solution.

Which deployment model are you using for this solution?

Hybrid Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Microsoft Azure
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Simon Webster - PeerSpot reviewer
Security Architect at University Corporation for Atmospheric Research
Real User
Aug 21, 2022
We get reports back from WildFire on a minute-by-minute basis
Pros and Cons
  • "The WildFire reporting and Cortex XDR platform have huge infrastructures in the cloud that secures the network against threats. So, we have the potential on the system, specifically for users, where we take care of this since the user is the most dangerous. We get reports back from WildFire on a minute-by-minute basis, rather than a daily or weekly update like I used to with different AV vendors. These features can detect viruses and malware more quickly, which is super important."
  • "Palo Alto can decide if traffic is of a certain kind, regardless of what port and protocol it is using, then it can figure that out and I can write my rules based on that, which is a huge functionality and super important to me."
  • "The biggest thing that needs to be improved with them is their training. I took a training class for the 8.0 build, then I took it again for the 9.0 and 10 builds. They add new features every time that they do a new major release, but the training doesn't keep up. It is the same basic training that probably was with the 3.0 build, and they just change the screenshots. I would love to see them do some more work since they have all these bells and whistles, but we don't know how to use those features on a large scale."
  • "The biggest thing that needs to be improved with them is their training."

What is our primary use case?

On certain levels, it protects our information. Luckily, I had switched to Palo Alto as our VPN solution for our users. We finished that in December of 2019, just in time for COVID to hit. We had a system that was able to support 650 to 700 users remoting into our campus through the VPN. This was a huge use case for us, as it was not intended to be the solution for COVID, but it turned out to be the solution for COVID. So, it was a great use case. Obviously, we want to protect our servers, virtual servers in the cloud, and on-prem. 

We have the eighth fastest supercomputer in the world. Unfortunately, we don't get to protect that because it has so much data going through it, i.e., petabytes a day. There isn't a firewall that can keep up with it. We just created a science DMZ for that kind of stuff as well as large data movers since we do weather data for the world. We research the ocean, sky, and solar weather. We have 104 universities who work with us around the world. Therefore, we need to have data available for all of them. We need to be protected as much as we can.

We started with Palo Alto 5060, then the 3060 came in, which was the next form. We have now switched to an HA system and have four firewalls as our base: a pair of 5220s and a pair of 5250s. We have been running the different OSs from PAN-OS 8.0, 8.1, 9.0, 9.1, and then 10.1. We are about to move to 10.2. We are in the process of doing that over the next week. We like to stay on the cutting edge because they are always adding more features and security.

We have it deployed in a number of different ways. We have our four main firewalls, which have two high availability pairs. One is set primarily for users and outward-facing functions. Therefore, our DMZ servers, staff, and guest networks are on one pair of firewalls. Back behind the scenes, labs and our HR department are on a separate set of firewalls. We call them: untrust and trust. Then, we have another set of firewalls, both in our Wyoming supercomputing center and in our Boulder main campus, which runs a specific program that has a DOD contract that requires more security, so they have their own set of firewalls. We also have firewalls in Azure Cloud for our tests and production environments. I am in the process of purchasing another VM firewall to put on the AWS Cloud. The last set that we have is at our Mauna Loa Solar Observatory, where we have an HA pair of just 800s because we only have a one gig radio link down the side of the volcano to the University of Hawaii.

We have between 1,200 and 1400 staff at any given time. Essentially all of them use the solution one way or another, either to access systems or through the VPN. We also have remote users who aren't employees but instead collaborators, and they can be anywhere in the world and remote into our systems. We then have people who are doing PhD programs at universities around the world who need to get into our systems to download data sets as part of their PhD or Master's program. Thus, the solution is not limited to our employees.

How has it helped my organization?

We have been around since the late 50s to early 60s. We were one of the original people who helped set up the ARPANET, which was a precursor to the Internet. Historically, our science has been open science. We want everyone to have it. The mindset has been that our network is flat and open to everything, and we have slowly reeled that in. Now, more of our stuff is behind firewalls. We are now going through a project where we are doing some more segmentation within the protected part. Each lab is protected from each other, or at least can be. They still talk to each other all the time, so we have rules for that. If we need to, we can shut access down right away because of the firewalls.

What is most valuable?

One of the best features is that Palo Alto NGFW can embed machine learning in the core of the firewall to provide inline, real-time attack prevention. We aren't using the AWS-offered firewalls in the cloud or Azure. When I read over the specs on it, it is more like a traditional firewall where a port is open to an IP address, and that is all you know. Palo Alto can decide if traffic is of a certain kind, regardless of what port and protocol it is using. Then, it can figure that out and I can write my rules based on that. That is a huge functionality and super important to me. The machine learning as well as being able to send stuff to WildFire is pretty important too. We like to get those types of reports and know that we have more protection from zero days than most traditional companies would.

The WildFire reporting and Cortex XDR platform have huge infrastructures in the cloud that secures the network against threats. So, we have the potential on the system, specifically for users, where we take care of this since the user is the most dangerous. We get reports back from WildFire on a minute-by-minute basis, rather than a daily or weekly update like I used to with different AV vendors. These features can detect viruses and malware more quickly, which is super important.

We have some large data movers that we can't put behind the firewalls. We don't have the largest firewalls, we have the 5200 Series firewalls. Their throughput is about 20 gigs a second, and it is protecting networks that have 100 gig connections. So, we have to be kind of choosy as to what we put behind the firewalls, but for the stuff that we put behind it, the latency really isn't problematic at all. Even though the firewall location is just one aspect, we have three different areas that talk to each other over multiple 240 gig links or 200 gig lengths. The firewall is not hindering that at all.

What needs improvement?

The biggest thing that needs to be improved with them is their training. I took a training class for the 8.0 build, then I took it again for the 9.0 and 10 builds. They add new features every time that they do a new major release, but the training doesn't keep up. It is the same basic training that probably was with the 3.0 build, and they just change the screenshots. I would love to see them do some more work since they have all these bells and whistles, but we don't know how to use those features on a large scale.

I know this little section here about the firewall, but I know there is a huge amount that still could be done with it. I am not touching enough of it because I just don't know how. It seems like the more I learn about it, the more I learn that there is to learn

For how long have I used the solution?

We have been using Palo Alto Firewalls for the past six years. We started with a single firewall, then built up from that.

What do I think about the stability of the solution?

It is very stable. A lot of times, it depends on what our network tweaks are, e.g., we monitor the link between the firewall and the router. If it misses some heartbeats on that, then it will switch over. That is part of how the HA process works. If it says I am not getting network connectivity, then it tells the other one to take over. We actually have an exciting way to do that because we have one data center at the top of the hill at the front-end of Boulder (or on the south-end.) We have another one in the HA link about 13 miles away at the north-end of Boulder. We actually do an HA pair across there using a 200-gig link with dark fiber between them. Most people, with their HA pairs, will be right next to each other, but ours are only that way on a globe.

How are customer service and support?

The firewall tech support team has been very good and responsive. Sometimes, they are too responsive. They call when I am in a different meeting, then I have to figure out with whom I am going to talk. The sales engineering team is also really good because they will monitor some of that, then call me about it separately to see if I need additional support.

Which solution did I use previously and why did I switch?

For the VPN only, we used Cisco's old ASA firewalls. That was set up before my time. We moved away from that when we went to GlobalProtect in December 2019.

Primarily, I wanted a single platform. We had Palo Alto Firewalls doing firewalling things and Cisco firewalls doing the AnyConnect VPN solution. Paying maintenance of both sets didn't make a whole lot of sense to me. Also, ASAs didn't seem to be able to support as many users concurrently as the Palo Alto solution looked like it could support. So, I just got rid of the Ciscos and went to the Palo Alto NG Firewalls and GlobalProtect.

How was the initial setup?

I have actually done a lot of initial setups. They are fairly straightforward at this point. The hardest part was where I had to just send them out to Mauna Loa, and I wasn't allowed to go to Hawaii for that. I had to set them up in Boulder, then I would think how they should be used and ship them over. That was a little difficult, since once they were on the ground in Hawaii, the final steps were slightly difficult to handle. As soon as they unplugged from the switch that was currently handling traffic and plugged into the switch where the firewall was connected, the person at the other end's laptop no longer had a connection for all the stuff that had been having traffic. We had to do everything by the old phone method. It was challenging, but we got through it.

Usually, I can get the initial deployment done in a few hours. However, going through and working with people to get what they need set up, as far as the rules and different areas behind the firewall, that takes a few weeks to a couple of months. A lot of that is based on people's time.

The first thing is get the basic things working: the networking, any routing that we need to do, and build communication to our RADIUS servers and Active Directory so we can log in and use our multi-factor authentication to manage the firewall. After that, I work with different groups who will be behind the firewall to find out what IP ranges they need supported, what kind of routing, who they want to talk to, and with whom they want talking to them. I have to know all that stuff. A lot of times, it is kind of teasing out information as far as what protocols they will be talking on or will they be using SSL or SNMP.

A lot of times that is a do-it on-the-fly kind of thing. You sort of stand stuff up, and say, "Check it now," and then they say, "Well, this one is not working now." Or, we just added a new service and this needs to be turned on. So, there is a lot of movement back and forth.

What about the implementation team?

I have done all of it by myself, except for the very first installation of the firewall that was done in conjunction with a reseller. That was before my time.

There are two of us on the firewall team. There are another three or four guys from the networking side team who also help out.

What was our ROI?

We had an external pen test a couple of years ago. They found a number of findings for the areas of our network that hadn't yet moved behind the firewall and no findings at all for the ones that had. This was just because of the way that we wrote the rules and because of the firewalls, which prevented an external source from being able to view and enumerate our systems. If something wasn't behind the firewall, they were able to get a response back in many cases, even when they weren't supposed to be outward-facing.

I have information that Palo Alto NGFW has blocked malicious activity. We use the Palo Alto High Confidence block lists. 

What's my experience with pricing, setup cost, and licensing?

There is an advantage to going with the high availability pair licensing model versus the standalone. It gives you a high availability pair, but the pricing is only a slight increase over a single system. It makes sense to take a look at your add-on functionality, like the Applications and Threats subscription and URL protection subscription. On the user side, I might want everything. However, on the server side, I might not need very much. I might want the Applications and Threats subscription and not much else. So, you don't have to buy all the bells and whistles for every firewall. Depending on what the function is, there are ways around it.

There are a lot of other subscriptions available, such as DNS Security and URL protection. I have heard there is an advanced URL protection going to be released soon. Also, there are a few others, like SD-WAN and GlobalProtect, which is one that we have because we have users who use Macs, Linux Boxes, and Windows systems. So, we need to support all of that.

Which other solutions did I evaluate?

Someone else made the decision to buy the initial Palo Alto gear. When they left, I had to learn the Palo Alto gear. At that point, I said, "I know Palo Alto. I like it. Why would I change away from it?" So, I have looked at different solutions throughout the years, but Palo Alto is one of the best out there.

We use Cisco Umbrella for DNS. We have done this for 15 years since it was open DNS as part of an MSF stipulation.

What other advice do I have?

All data goes through the firewall,since our HR and finance departments are behind the firewall. A lot of our labs are behind the firewall. We have some plans to expand, as I am about to put a virtual firewall in AWS Cloud for a project. We have a C-130 hub that has been flying into hurricanes and tornadoes for years. I want to put a firewall on that to protect the instrumentation from outside sources.

If you are just looking for the cheapest, fastest firewall out there, that is a foolish attitude. The point of a firewall is to increase your security, not to increase your throughput. You don't want it to degrade your throughput, but the cheapest solution and the solution that makes sense aren't necessarily the same thing.

The main advice would be to plan on starting small, then build up. Don't try to do everything at once. Also, make sure you do the available training prior to use or at the same time, at least the basic one, because that is important. 

Make sure you have a good networking background or a good network engineer standing next to you because talking to the routers is key.

I would rate it at about eight and a half to nine out of 10. There is no perfect answer, but this is a pretty good one.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Andres Briceño - PeerSpot reviewer
Cybersecurity Coordinator at Pronaca
Real User
Top 5
Sep 11, 2024
Offers robust integration, comprehensive log visibility, and effective threat prevention
Pros and Cons
  • "The Palo Alto Networks NG Firewalls excel in their integration capabilities."
  • "The integration with AI needs improvement."

What is our primary use case?

We have implemented peripheral firewalls and micro-segmentation within our LAN network. To further segment our data center, we have deployed firewalls in the middle of the network. Additionally, we utilize Palo Alto Networks NG Firewalls in our GCP environment for various use cases, including URL filtering, URP, file blocking, and threat prevention.

How has it helped my organization?

Palo Alto Networks NG Firewalls natively integrate all security capabilities, making it crucial for our XDR integration. To address the challenges of our small cybersecurity team, we have implemented significant optimizations. This streamlined approach allows us to efficiently monitor and analyze all logs, ultimately providing a comprehensive view of our security posture.

Palo Alto Networks NG Firewalls embed machine learning at their core to provide crucial, real-time inline attack prevention. In today's world of relentless cyber threats, detecting and blocking malware, viruses, and hacker intrusions is paramount. These attacks pose a constant threat to our data security, making firewalls essential tools for safeguarding our digital assets.

It provided immediate benefits to our organization through their seamless integration, automation capabilities, enhanced visibility, and robust traceability features.

Palo Alto Networks NG Firewalls are consistent in securing data centers across all our workplaces.

What is most valuable?

The Palo Alto Networks NG Firewalls excel in their integration capabilities. By combining them with XDR, Prisma Access, or other Palo Alto Networks SaaS products, organizations can achieve enhanced visibility, trust, and threat prevention. The integration with Cortex XDR enables automated threat prevention through the use of playbooks. This comprehensive solution is ideal for advanced threat detection, log correlation, and other security-related tasks.

What needs improvement?

The integration with AI needs improvement.

For how long have I used the solution?

I have been using Palo Alto Networks NG Firewalls for seven years.

How are customer service and support?

We provide the initial level of support for our customers' firewalls. If a customer requires direct assistance from Palo Alto support, we can open a case and facilitate their connection.

How would you rate customer service and support?

Positive

How was the initial setup?

The initial deployment is straightforward. I would rate the ease of deployment a nine out of ten.

Which other solutions did I evaluate?

When comparing Cisco, Check Point, and Palo Alto firewalls, I found Palo Alto to be the most effective. Its configuration interface is more intuitive, making it easier to set up policies and manage the firewall. In contrast, I encountered significant challenges with Cisco and Check Point firewalls. To date, I have not experienced any issues with Palo Alto.

What other advice do I have?

I would rate Palo Alto Networks NG Firewalls ten out of ten.

Palo Alto Networks NG Firewalls offer a robust security solution. However, when integrated with a comprehensive platform like Cortex XDR and XSOAR, their value proposition significantly increases for businesses. By leveraging indicators of compromise, NG Firewalls can generate Extended Detection and Response alerts, streamlining the identification and mitigation of threats. This automation eliminates the need for manual intervention by technicians and cybersecurity analysts, resulting in improved efficiency and overall security posture.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
HenryHo - PeerSpot reviewer
System Support Assistant at CITIC TELECOM CPC
Real User
Sep 2, 2024
It provides a unified platform, is stable, and reduces downtime
Pros and Cons
  • "Palo Alto Networks NG Firewalls' single-path architecture offers a valuable feature, ensuring stable performance for our customers."
  • "I would like Palo Alto Networks to provide a free virtual firewall."

What is our primary use case?

As a reseller, our primary customers utilizing Palo Alto Networks NG Firewalls are in the financial services, government, and manufacturing sectors. They select Palo Alto Networks NG Firewalls due to their superior performance and security capabilities compared to alternative firewall solutions.

How has it helped my organization?

Palo Alto Networks NG Firewalls provides a unified platform that natively integrates all security capabilities for our customers.

Palo Alto Firewalls integrate machine learning into their core functionality to offer real-time, inline attack prevention that our customers rely on.

Palo Alto Networks NG Firewalls offer a variety of models designed to protect data centers in all work environments. These models share standard features.

Palo Alto Networks NG Firewalls can significantly reduce downtime, and replacing a firewall typically takes only one to two minutes.

What is most valuable?

Palo Alto Networks NG Firewalls' single-path architecture offers a valuable feature, ensuring stable performance for our customers.

What needs improvement?

Palo Alto Networks NG Firewalls pricing has room for improvement.

I would like Palo Alto Networks to provide a free virtual firewall.

For how long have I used the solution?

I have been using Palo Alto Networks NG Firewalls for three years.

What do I think about the stability of the solution?

I have not encountered any stability issues using Palo Alto Networks NG Firewalls.

What do I think about the scalability of the solution?

The scalability of Palo Alto Networks NG Firewalls is limited because of the lack of a virtual firewall.

How are customer service and support?

The local support is better than the corporate support.

How would you rate customer service and support?

Neutral

What's my experience with pricing, setup cost, and licensing?

Palo Alto Networks NG Firewalls are expensive compared to other solutions.

I would rate the price eight out of ten, with ten being the most costly.

What other advice do I have?

I would rate Palo Alto Networks NG Firewalls eight out of ten.

Although Palo Alto Networks NG Firewalls are more expensive than other firewalls, they provide better protection and are a better value for your money.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. reseller
PeerSpot user
AjayKumar17 - PeerSpot reviewer
Technical Superintendent at Indian Institute Of Technology, Patna
Real User
Top 5
Aug 25, 2024
Has AI and ML capabilities, which work well for real-time attack prevention
Pros and Cons
  • "The unified platform provided is very important to us as it allows us to manage all traffic and ensure security without using separate tools. It has AI and ML capabilities, which work well for real-time attack prevention."
  • "One area for improvement with Palo Alto Networks NG Firewall would be customer support. Currently, in regions like India, customer support is handled by third-party partners. Unfortunately, the support provided by these partners has not been satisfactory. It would be beneficial if the tool handled customer support directly, similar to how Cisco maintains high-quality customer care. This would ensure that customers receive the level of support they expect."

What is most valuable?

The unified platform provided is very important to us as it allows us to manage all traffic and ensure security without using separate tools. It has AI and ML capabilities, which work well for real-time attack prevention.

Since implementing Palo Alto, we've seen an 80-90 percent reduction in issues. It handles ISP links, ensuring minimal downtime. Recently, we upgraded our secondary ISP to 3 Gbps, and when the primary link goes down, it automatically switches to the secondary. As a result, end users do not experience bandwidth shortages or interruptions in internet access.

What needs improvement?

One area for improvement with Palo Alto Networks NG Firewall would be customer support. Currently, in regions like India, customer support is handled by third-party partners. Unfortunately, the support provided by these partners has not been satisfactory. It would be beneficial if the tool handled customer support directly, similar to how Cisco maintains high-quality customer care. This would ensure that customers receive the level of support they expect.

Getting reliable service is important when you're a customer, especially with critical devices like firewalls. Firewalls are key parts of a network; if they fail, the whole network can become unstable. So, the support you get needs to be just as reliable as the device itself.

For how long have I used the solution?

I have been working with the product for a year. 

What do I think about the stability of the solution?

I haven't experienced any downtime. 

Which solution did I use previously and why did I switch?

We used Cisco ASA before. At that time, Cisco didn’t have a unified next-generation (NG) firewall, and I’m unsure if they offer one now. The main reason we decided to switch was that we needed a unified NG firewall. Besides the unified features that NG firewalls provide, there were other differences between Cisco and Palo Alto Networks NG Firewalls, particularly in terms of features and price. However, the features are mostly similar across different firewalls; it depends on how they’re implemented, how effective they are for end users, and how well they handle security. This varies from company to company and firewall to firewall because each has its architecture, data plan, processing, control, and so on. So, it depends on the original equipment manufacturer.

How was the initial setup?

The tool's deployment is complex and takes seven to eight days to complete. 

What's my experience with pricing, setup cost, and licensing?

The tool's pricing is similar to that of Cisco. It's a security appliance; the cost depends on your network topology and specific requirements. The suitability of NG firewalls should be chosen based on your network and what you need. If a colleague from a different company asked for the cheapest and fastest firewall, I suggest they consider options like Sophos. Sophos took over Cyberoam, which was previously a leader in NG firewalls

What other advice do I have?

I work with the product, and we purchased our box after a demo. We also have IoT security, but I don't personally handle that. I rate the overall product a nine out of ten. 

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Muhammad-Nadeem - PeerSpot reviewer
Lead Network Security Engineer at PTA
Real User
May 2, 2023
Help fill security leaks by enhancing confidentiality, integrity, and availability
Pros and Cons
  • "The application IDs, application controls, URL filtering, visibility, monitoring, and reporting are the most valuable features."
  • "The cost has room for improvement."

What is our primary use case?

We are a consulting group that specializes in deploying Palo Alto Networks NG Firewalls for a telecom-related partner in Pakistan. Additionally, we implemented global protection for remote users. Furthermore, we configured different policies for internal users based on their job designations and privileges, such as URL filtering and application controls.

How has it helped my organization?

Palo Alto Networks NG Firewalls' advanced machine learning capabilities offer real-time attack prevention and are crucial in our security setup. We implemented a multi-layered security approach and are currently working towards a zero-trust model, including defense for development. According to the Gartner report, Palo Alto ranks second after Check Point, highlighting the significance of security in our environment.

We access all the firewalls via Panorama. We configured certain global user profiles to allow access to our site for remote or work-from-home situations, which we then access through GlobalProtect.

Before we started to use Palo Alto Networks NG Firewalls, we had a different FortiGate firewall that presented several issues such as deep security URL filtering and throughput issues. However, with Palo Alto, we were able to address these problems, particularly with the use of parallel processing. We have successfully deployed inbound and outbound SSL inspection, as well as different URL filtering, making Palo Alto a more resilient option compared to other products.

It is important the solution provides a unified platform that natively integrates all security capabilities. Compared to other products, Palo Alto Networks NG Firewalls' unified platform is a ten out of ten and suitable for all environments. 

Palo Alto Networks NG Firewalls help fill security leaks by enhancing confidentiality, integrity, and availability.

Palo Alto Networks NG Firewalls help automate multiple security tools and unify them.

The solution assisted us with managing our network operations and reducing related costs. We use various Network Management Systems to monitor our network, including Palo Alto which we monitor from its dashboard. Additionally, we use various Security Operations Center solutions, as well as SolarWinds. We also utilize different monitoring platforms to track network traffic.

The WildFire feature offers protection against Zero-Day attacks, and we find that Palo Alto is a valuable tool for mitigating such attacks using WildFire.

Palo Alto's single architecture provides parallel processing and reliability as well as superior visibility compared to other products. The reporting feature is excellent and can impress management during presentations or when accessing logs.

What is most valuable?

The application IDs, application controls, URL filtering, visibility, monitoring, and reporting are the most valuable features.

What needs improvement?

I would like to have an on-prem sandbox solution included in a future update.

The cost has room for improvement.

For how long have I used the solution?

I have been using the solution for five years.

What do I think about the stability of the solution?

I give the stability a nine out of ten.

What do I think about the scalability of the solution?

I give the scalability a ten out of ten.

How are customer service and support?

The technical team is good.

How would you rate customer service and support?

Positive

How was the initial setup?

The initial setup is straightforward. I give the setup a ten out of ten. The deployment took three months to complete. We require five to six people for deployment.

What about the implementation team?

The implementation is completed in-house.

What's my experience with pricing, setup cost, and licensing?

The cost of Palo Alto Network NG Firewalls is significantly higher compared to Huawei. For instance, while we can buy a Huawei box for 100 rupees, a Palo Alto box costs 100,000 rupees.

What other advice do I have?

I give the solution a nine out of ten.

Palo Alto Networks NG Firewalls is an impressive product.

The solution is used for our enterprise clients.

Although Palo Alto is not the most inexpensive firewall solution, it is worth the cost to ensure proper protection for our networks.

Palo Alto PA-400 series cost and performance for small offices are good.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
ImranKhan3 - PeerSpot reviewer
Senior Technical Consultant at Ericsson
Real User
Dec 6, 2022
A feature-rich solution including Wi-Fi analysis and zero-day threat protection, with excellent customer support
Pros and Cons
  • "The solution's most valuable feature is the robust firewall, which we can also use as a UTM device."
  • "The price could be more friendly, which would be good for Palo Alto and us. If the price were a little lower, then it would be a viable option for mid-level businesses, who may not be able to deploy at the current price point."

What is our primary use case?

Our primary use for the solution is as a perimeter device and firewall. 

How has it helped my organization?

Suppose a packet enters our organization with a new, unknown signature. In that case, the firewall can upload it to the primary database and generate user alerts to inform users of the malicious signature, blocking it if necessary.

What is most valuable?

The solution's most valuable feature is the robust firewall, which we can also use as a UTM device. 

The Wi-Fi analysis and zero-day threat prevention are very good features. 

The product defends our production, blocks files, and prevents data leakage. It's a complete package for advanced security, which is excellent for a firewall.

It's beneficial and vital to us that Palo Alto NGFW embeds machine learning in the firewall's core to provide inline, real-time attack prevention. Suppose it observes any abnormalities in our traffic. In that case, the product can detect that through machine learning and generate a lock so we can mitigate an attack or a vulnerability in the system.   

Palo Alto NGFW's machine learning works well to secure our network against threats that can evolve and morph rapidly. A particular strategy we encounter on our system is when a packet comes in and behaves abnormally. Palo Alto detects the abnormality, generates an alert, and responds based on our policies by blocking or discarding the package.   

We use the firewall's DNS security, and it's excellent for blocking DNS attacks thanks to the continuously updating Palo Alto threat database. For example, the product blocks users from accessing sites with a known malicious DNS.

What needs improvement?

The price could be more friendly, which would be good for Palo Alto and us. If the price were a little lower, then it would be a viable option for mid-level businesses, who may not be able to deploy at the current price point.

For how long have I used the solution?

We've been using the solution for one and a half years. 

What do I think about the stability of the solution?

The solution is very stable and robust. 

What do I think about the scalability of the solution?

The product is scalable and very easy to configure; we enjoy the configuration and operation of the firewall. 

How are customer service and support?

We contacted Palo Alto technical support on several occasions, and they're excellent; they always try to resolve our issues as soon as possible. 

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

We previously used Cisco ASA and Check Point NGFW and switched to the Palo Alto solution because it offers more robust and complete protection and features.

How was the initial setup?

The initial setup is straightforward, and it depends on the network configuration. If we want to make few network changes, we can deploy the firewall in Virtual Wire mode, and we don't have to mess with IP addresses and so on. If we want to deploy with a new configuration, we can do that in Layer 3 mode.

If we upload a pre-planned configuration to our network firewall, the deployment can take as little as 10-15 minutes. We have a team of nine engineers responsible for daily policies, troubleshooting, etc.

What about the implementation team?

We deployed via an in-house team; we have a big team, so we deploy ourselves whenever possible.

What was our ROI?

The solution is worth the money for organizations operating in critical environments with lots of sensitive data and information. Data leaks can lead to broken trust with clients and a suffering reputation in the business community, including brand damage.

What's my experience with pricing, setup cost, and licensing?

Palo Alto NGFW is relatively expensive compared to the competition.

What other advice do I have?

I rate the solution 10 out of 10.

Palo Alto NGFW provides a unified platform that natively integrates all security capabilities, which is an important feature. It provides a robust kind of security counter at the perimeter level.  

The solution's unified platform helps eliminate security holes. For example, the firewall can easily block attempted SQL injections with the help of App-ID. 

Palo Alto NGFW's unified helped to eliminate multiple network security tools and the effort needed to get them to work with each other. The solution provides vulnerability assessment and protection, antivirus prevention, data leak prevention, file blocking, site blocking, and application blocking, all in one product. It's an excellent firewall device and very useful for our network. 

We have the zero-delay signatures feature implemented with our firewall, and it's essential because attack signatures are updated immediately. Attackers are trying to find new ways to harm our network daily, and the zero-delay feature makes it so that the network is updated in seconds, and the first user to see a new threat is the only one to experience first exposure. This functionality improved our security.   

To a colleague at another company who says they are looking for the cheapest and fastest firewall, it depends on their environment. I recommend Palo Alto or Check Point if they are a financial institution. If they are a mid-level non-financial institution, I recommend Cisco Secure Firewall because it's also a good firewall.

To someone looking to use Palo Alto NGFW for the first time, analyze the packet flow of your organization and understand which types of packets you're getting and which type of services you are providing in your data center or enterprise. Multiple data centers require a high security level, so I recommend activating the Layer 7 feature.

The biggest lesson I learned from using the solution is the importance of following all the steps in the operation manual when upgrading or updating. 

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Download our free Palo Alto Networks NG Firewalls Report and get advice and tips from experienced pros sharing their opinions.
Updated: September 2026
Product Categories
Firewalls
Buyer's Guide
Download our free Palo Alto Networks NG Firewalls Report and get advice and tips from experienced pros sharing their opinions.