Cloudflare Access vs Prisma SD-WAN comparison

Sponsored
 

Comparison Buyer's Guide

Executive Summary
 

Categories and Ranking

Lookout
Sponsored
Ranking in Secure Access Service Edge (SASE)
18th
Average Rating
7.2
Number of Reviews
5
Ranking in other categories
Secure Web Gateways (SWG) (24th), Mobile Data Protection (7th), Cloud Access Security Brokers (CASB) (12th), Threat Intelligence Platforms (18th), Endpoint Detection and Response (EDR) (43rd), Mobile Threat Defense (2nd), ZTNA as a Service (13th), ZTNA (10th)
Cloudflare Access
Ranking in Secure Access Service Edge (SASE)
11th
Average Rating
8.6
Number of Reviews
6
Ranking in other categories
Access Management (10th), ZTNA as a Service (10th)
Prisma SD-WAN
Ranking in Secure Access Service Edge (SASE)
7th
Average Rating
8.6
Number of Reviews
13
Ranking in other categories
Software Defined WAN (SD-WAN) Solutions (6th), WAN Edge (6th)
 

Mindshare comparison

As of June 2024, in the Secure Access Service Edge (SASE) category, the mindshare of Lookout is 0.1%, down from 0.4% compared to the previous year. The mindshare of Cloudflare Access is 8.2%, up from 6.0% compared to the previous year. The mindshare of Prisma SD-WAN is 3.5%, down from 5.9% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Secure Access Service Edge (SASE)
Unique Categories:
Secure Web Gateways (SWG)
0.4%
Mobile Data Protection
7.1%
Access Management
4.2%
ZTNA as a Service
12.9%
Software Defined WAN (SD-WAN) Solutions
5.2%
WAN Edge
5.1%
 

Featured Reviews

AP
May 23, 2023
User-focused design makes it easy to understand, and operations running in background provide peace of mind
In any of the discussions that we've had with their technical teams, they have been very knowledgeable and helpful in certain aspects. They have a lot of partnerships, from what we can tell, and that does start to make the waters a little bit murky. They have third parties that provide functionality and there is a concern that we're going to be bounced around between five different groups to get help for a problem. If you describe it incorrectly, all of a sudden you're with a group that can't help you and they have to forward you to another group. They have been very responsive and super helpful when it comes to any of the issues we've identified. Still, that concern about being bounced around between multiple partners detracts from the overall experience.
FS
May 24, 2024
Protects and regulates access to internal applications based on policies
Cloudflare Access has strong integration with Microsoft, among other platforms. However, when it comes to Kaspersky, we have clients who typically encounter challenges. The usual setup involves configuring a forward proxy, an IDP, and a CASB. Orchestrating these solutions can be challenging if the client already uses a VPN client such as Check Point or Mobile VPN. Clients typically do not replace their VPNs all at once; instead, they gradually phase out the old solution. The interaction between Cloudflare Access and the legacy VPN solution can be complex, particularly ensuring seamless access without introducing new restrictions. This complexity arises not from the product itself but from the nature of migrating to a new system. Migrating ten thousand employees daily is impractical, so a step-by-step approach throughout about a year is often necessary to facilitate a smoother transition.
LC
Jan 18, 2023
When we switched to this solution, we saw an immediate improvement in our network visibility
Prisma's analytics provide a lot of valuable data. I like the internet health chart that shows latency, dropped packets, MOS for data quality, etc. It also runs a continuous speed test in the background. I've used it multiple times to troubleshoot internet connections when the service provider has attempted to claim nothing is wrong with the circuit. It gives me data to send them showing we're not getting the speed we should, or there is constant packet loss. I wouldn't say the Layer 7 intelligence provides deep application visibility, but it does provide some visibility. We rely on our next-gen firewalls, which are also Palo Alto. They work with this product to give a deeper view of Layer 7. It has some machine-learning features. For example, it collects data in the background. You can look at the data flows to see that internet connectivity was poor at a given time, which correlates with a point on the data flow where the customer complained about a problem with the application. We can set various policies regarding which traffic goes where using a zone-based firewall. You can also set a policy based on events. We might implement a QoS mechanism where an application might have a higher priority. For example, it might dedicate more bandwidth toward video calls under a given condition based on the policy. We can custom-build applications to ensure they're impacted the least according to the policy we have set. With the policy in place, we don't need to interact with it as much. It does it for us, so we don't have to tweak too many settings, and it allows us to get pretty granular with it. The solution formerly known as CloudGenix is now Prisma SD-WAN, so it can do zone-based firewalls. However, they do not put heavy encryption on the device. That's mostly going to be handled by the firewall service you use. It doesn't have to be Palo. It could be Zscaler or Check Point. Even though it's a Palo Prisma device, it works well with various vendors and allows you to do that aspect.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"On the outside, the main differentiation is because Lookout ingest. They have ingested basically all of the apps for the last ten years and all the versions of all the apps, and we have that in a corporate database that allows us to do very large-scale machine learning and analysis on that data set. That's not something that any of the competitors really have the capability to do because they don't have access to the data set. A lot of the apps you can no longer get them because that version of the app is five or six years old, and it just doesn't exist anywhere anymore, except within our infrastructure. So, the ability to have that very rich dataset and learn from that dataset is a real differentiator."
"The solution is stable."
"The most valuable features are the antivirus as a whole, the anti-malware, and all of the protection features that scan our enterprise devices."
"The protection offered by the product is the most valuable feature. It detects vulnerabilities or traps on our users' phones and then prompts them to clean up their devices. Tools we used previously would only discover, which required us to gather information on the backend, so Lookout is a welcome upgrade."
"It's the endpoint exposition. We don't need to expose our VPN server to the internet and need a zero-test solution. I can apply some conditional access to the endpoint that's connecting to our network to check their security policies or the security condition of their workstation. Once the workstation is trying to connect to my internal network, then I would like to check the discrete condition of these endpoints that are trying to access my internal network. We created some conditional access. We have CrowdStrike, to check if the CrowdStrike is installed, to check if it's updated, and to check for Windows updates. We created some conditional policies to check it."
"Cloudflare Access is part of the Zero Trust philosophy."
"Enables me to work from two locations."
"Cloudflare, in my opinion, was easy to implement."
"The tool also offers good scalability, and the dashboard, along with real-time analytics, is very good."
"For Cloudflare Access, I am using the free plan...The most valuable feature is their protection."
"I like the link monitoring and analytics. These are the features that set Prisma apart from other products. Prisma works well with large, complex networks. One of my clients is a top bank in the United States, and Prisma has performed well for that customer."
"The gateway is available on the cloud which allows you access from anywhere and still connects to your home gateway."
"When it comes to supporting large, complex, network architectures, it's a very simple architecture. The main component is the fabric. It's very easy to troubleshoot if there is an issue happening in the underlying network."
"Prisma supports all of the applications we're currently using."
"Prisma's analytics provide a lot of valuable data. I like the internet health chart that shows latency, dropped packets, MOS for data quality, etc. It also runs a continuous speed test in the background. I've used it multiple times to troubleshoot internet connections when the service provider has attempted to claim nothing is wrong with the circuit. It gives me data to send them showing we're not getting the speed we should, or there is constant packet loss."
"If the MPLS goes down, there is a really smooth transition for a branch site to take traffic over the Internet. It will advertise the routes of that site in a jiffy."
"It is flexible to use the internet connection via local breakouts without going to data centers."
"The product provides efficient stability, security, and reliability features."
 

Cons

"The stability depends on the service from where you access it. Because sometimes, the place you are in, you have Gateway. You don't have Gateway. The gateway is overutilized. At the end, you need to go through their gateways. And this is the key point here. You have a tracking point. If it's not well orchestrated, and it scales up as you add more to the existing team, you will suffer"
"Lookout was moving into the SSE space. And so their work on SecureWeb Gateway and SD-WAN is still sort of evolving."
"From the analysis that we've done, they do seem to be maybe a step behind in trying to enter the market with a new solution. But when they do pick up, they do come out with some good products."
"We just submitted an enhancement request reflecting the main area we want to see improvement in; the APIs. Currently, we're able to build dashboards, but it's somewhat backward because we use our MDM API to create them. Lookout should provide API to customers so we can query our data and use it in our cloud, and this is the only outstanding area for improvement with the product right now."
"The pricing is an area that can be improved. Pricing, as far as I recall, was the source of our problems."
"For the topic of improvement, providing some training material is one of my suggestions."
"They don't have a person to provide support for customers using the solution under their free plan."
"When there are any dynamic changes in complex applications, the tool takes a lot of time, making its analytics-related area a major matter of concern where improvements are needed."
"Event correlation and analysis capabilities do not help minimize the number of alarms from a single event. That is the problem. We are getting a lot of incidents, and there is some issue with the correlation. That is still a drawback."
"There are two parallel things that we want Palo Alto to work on. First, customers want a unified appliance that does the work of all firewalls in addition to SD-WAN. Second, the cloud presence should be completely automated. If I purchase the SASE architecture, I shouldn't worry about deployments in Prisma Access or on Prisma SD-WAN. It should be deployed in one go."
"Prisma SD-WAN's technical support should be improved."
"Customer support is our biggest pain point. The quality of support has gone down a little since we initially deployed this product. I don't know if this is due to turnover at Palo Alto or a lack of training. It is now taking one or two days to get an initial response that says, "Hey, we've looked into this, can you pull this data for us?" In the past, we'd immediately get a response."
"Prisma SD-WAN should provide more flexibility and scalability on the hardware."
"I would also like to see improvement in the product training for customers. Palo Alto has not initiated very much training but they have to do so because this is a new product. If you have experience in a legacy environment, and you are moving to Prisma SD-WAN, you don't have a training framework. That is one of the disadvantages."
"The tool needs to work on price and complexity."
"They could add more advanced security features to the product."
 

Pricing and Cost Advice

"The pricing is fair; it's comparable to our previous solution, and we carried out multiple POCs and POVs (proof of value). The product is worth the money we pay for it."
"The licensing costs are good. Prisma has much more options and support for security, but it has a higher cost. For example, Lookout costs 2/3rd of Prisma's licensing price."
"In terms of feature performance versus cost, they're a good value."
"Lookout is definitely on the lower end when it comes to price point and that seems to be the only differentiator. The technology is in place in this space and it's really about who is coming in at the better price point now."
"My company has to make yearly payments towards the licensing costs attached to the solution. There are no hidden charges apart from the licensing costs of the solution."
"The pricing is somewhere in the middle. I would rate the pricing a seven out of ten."
"The prices are slightly expensive."
"If you're already invested in a Palo Alto product, it would be logical to use this solution. If not, there might be some other solutions that are more viable in terms of pricing."
"On a scale from one to ten, where one is cheap and ten is expensive, I rate the solution's pricing an eight out of ten."
"This solution stood out because it cost considerably less than the other SD-WAN solutions out there from Cisco."
report
Use our free recommendation engine to learn which Secure Access Service Edge (SASE) solutions are best for your needs.
787,779 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
19%
Manufacturing Company
10%
Financial Services Firm
10%
Government
6%
Computer Software Company
14%
Financial Services Firm
11%
Government
8%
Manufacturing Company
7%
Educational Organization
24%
Computer Software Company
12%
Manufacturing Company
8%
Financial Services Firm
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
No data available
 

Questions from the Community

What is your experience regarding pricing and costs for Lookout?
The licensing costs are good. Prisma has much more options and support for security, but it has a higher cost. For ex...
What needs improvement with Lookout?
The solution could improve identity integration as well. Zero trust, it's a good start as a zero-trust solution. More...
What do you like most about Cloudflare Access?
The tool also offers good scalability, and the dashboard, along with real-time analytics, is very good.
What is your experience regarding pricing and costs for Cloudflare Access?
The price of Cloudflare Access is the same as compared to Akamai, but I get better performance from Cloudflare. My co...
What needs improvement with Cloudflare Access?
My company has many complex applications. When there are any dynamic changes in complex applications, the tool takes ...
What do you like most about Prisma SD-WAN?
The product's initial setup phase is straightforward.
What is your experience regarding pricing and costs for Prisma SD-WAN?
On a scale from one to ten, where one is cheap and ten is expensive, I rate the solution's pricing an eight out of ten.
What needs improvement with Prisma SD-WAN?
Prisma SD-WAN should provide more flexibility and scalability on the hardware. The solution's conversions and failove...
 

Also Known As

CipherCloud
No data available
CloudGenix
 

Overview

 

Sample Customers

23andMe
Open Networking User Group, Columbia Sportswear Company, Coca Cola
Find out what your peers are saying about Cloudflare Access vs. Prisma SD-WAN and other solutions. Updated: May 2024.
787,779 professionals have used our research since 2012.