Palo Alto Networks WildFire is being used as an effective zero-day threat prevention solution. When a file comes in from a user innocently clicking on a website, then downloading the file, for example, if your Palo Alto is set up in a way that detects what is happening in that traffic going through, whether the file is an audio file, a DLL, an executable file, etc., if it thinks that file is unsafe, it will ask for a second opinion from Palo Alto Networks WildFire.
If you'll imagine how a network would work: You've got your computer, then your antivirus on the computer, then you have your internet gateway. That suspicious file will stop at the gateway, rather than stopping at the computer. Think about hurdles, where you've got these people running over hurdles, and to win the race, you have to jump over every single hurdle. If you get one of those hurdles wrong, that's it. You're done. That's why we're doing this check almost at the perimeter, or at the edge of the network, instead of on the device, because once you're on the device, it means you're on the network.
What I found most valuable in Palo Alto Networks WildFire is that it's intuitive. I also love the App-ID feature, especially because it works out of the box. I can also instantly see all the traffic going out, e.g. I can just plug a firewall in, then connect one network socket to a switch, etc. There's no configuration I need to do to see it. It just tells me that you're sending BitTorrent traffic, or SLL traffic, or you're going into 365, etc. It just does that out of the box, and it's the best thing that this solution can do. Straight away you can see all the traffic going through your network.
Palo Alto Networks WildFire, because it's from Palo Alto Networks, has better visibility on everything, so they can see what's happening in the world. They recently released the Palo Alto Networks WildFire machine learning feature on the firewall, so it's them saying: "This thing's happening on your firewall, so you should do this," and it just does it for you. Rather than relying on a human to interpret these problems, it will just do it for you, and that's pretty cool. I've not played with the machine learning feature myself, but that's something I'm very keen to have a look at.
We do a lot with charities, and I'd love Palo Alto Networks WildFire to have more discounts, e.g. charity discounts, so we can protect healthcare and schools, then other than aiming at the universities and the big hospitals where it's a lot of money, we can go for the smaller schools, too. They make quite a killing there.
Again, it's just charity pricing, but because we are a partner with them, we can do that ourselves, e.g. we can buy it and then reduce our margins on it to get them over. We feel that it's better to sell the device that's very good at a lower cost, then, we lock in with their services at the end, so work management, etc. Rather than saying, "It's going to cost you this much money, and it's too expensive to even begin with."
I've been a reseller of Palo Alto Networks WildFire for four years now.
Palo Alto Networks WildFire is a stable solution.
Palo Alto Networks WildFire is scalable, particularly if you pick the right firewall, and that's it: you can do what you need to with it.
With five being the highest and one being the lowest, I'm scoring the technical support for Palo Alto Networks WildFire a four. They're very, very good, but there is still room for improvement when some issues become more complex. If you understand the system, then you'll also understand why it is like it is.
Setting up Palo Alto Networks WildFire is easy out of the box, because you just plug in the cables you need, but the way it works is you need to have an understanding of networking, otherwise, setting it up will be difficult. If you are the right type of person, then you'll have no problems with the setup.
Palo Alto Networks WildFire is quite expensive, and this is what puts people off.
The way Palo Alto Networks WildFire works is that it's essentially a service that you get from Palo Alto as part of your subscription. You can subscribe to it at an additional cost, and the idea is it can communicate with all the Palo Alto devices in the world about a file, e.g. whether a file is suspicious or harmless.
For example, a machine in Australia downloads a file, and it doesn't know if it's a file that can be trusted or not. The Palo Alto Networks WildFire process is that it takes that file, and then moves it to the WildFire service in the cloud, so there's a transaction from the firewall doing that.
Let's say it's a Word file or something that looks suspicious, Palo Alto Networks WildFire then detonates the file, e.g. it takes that file and runs checks against it, before and after, and then it sees the difference and says, "Well, this actual file contains a payload." The way that it works then, is that there are attackers or people who are trying to subvert systems, and they will say, "Oh, if this file is running on a virtual machine, like in a sandbox environment, don't do the thing that you're going to do, only when it's a physical thing, like actual hardware.
The Palo Alto Networks WildFire process is a process that goes through all these other checks, e.g. it runs on physical, on virtual, on different types of Linux, MacOS, etc. This file is checked against all these different environments to see if it's okay or not, so this is done off the box, off the firewall.
This is the service that you pay for as part of that subscription, so when it's done, essentially that file is marked as safe, that's cool. If it's marked as bad, then that file, the hash is taken from it, so it's easily identified, then through the Palo Alto Networks WildFire subscription, all the firewalls in the world then get that information within just one minute, if you set it to that. It will say something similar to: "Look out for this file if you ever see it", and then all the machines now knows that the file is dodgy or suspicious. That's what Palo Alto Networks WildFire does.
Palo Alto Networks is very well rounded. They're building an ecosystem: the Palo Alto ecosystem. You've got global protect VPNs and they are the armor that works on the whole ecosystem. They also have integrations, e.g. there are other applications from HP that plug into the device, because it's got the APIs there.
For the deployment and maintenance of Palo Alto Networks WildFire, one person can do it, but it's a special tool, so a network staff that just looks after a server would probably struggle with it, just because of some of the concepts that you need to use. There are specific trainings you'd need to do to get the best out of it, but one specialist could do it, e.g. it's not unheard of.
My advice to others looking into implementing this solution is for them not to be put off by the cost. It's similar to looking at cars, e.g. there's a reason people like Jaguar cars over the Fords. I've always got this mantra that if you have a network, if you have a data network, and if it's going to cost you, e.g. if you look at the fines associated with various industries, and if you're a school that gets a data breach, it'll cost you this much money. The question is: "Can you afford that much money as a company?" If your answer is "No", then you have to look at mitigating it. I would suggest looking at Palo Alto Networks WildFire and saying, "Well, we do these types of things to protect your network."
If you still don't want to pay that money, then chances are, you don't particularly care about security. If you want to pay for that kind of thing to stave off the bigger fine that results from getting a data breach, or getting hacked, etc., then that's how we think about it. Don't be off put by the cost when you're looking at it. Palo Alto Networks WildFire is a very comprehensive device. They are the best firewalls in the world.
There are also other solutions like UTMs and XGs, e.g. if you like Fortigate, but everyone I've shown the Palo Alto to instantly said: "This big screen here: I can see all the traffic going through", and you just filter it at the top, and it just makes more sense to people. It's very intuitive.
My rating for Palo Alto Networks WildFire is eight out of ten. It's not a perfect score because of its cost.