No more typing reviews! Try our Samantha, our new voice AI agent.

IBM NS1 Connect vs Palo Alto Networks DNS Security comparison

Why PeerSpot?
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

IBM NS1 Connect
Ranking in Domain Name System (DNS) Security
8th
Average Rating
9.2
Reviews Sentiment
7.5
Number of Reviews
17
Ranking in other categories
Managed DNS (7th)
Palo Alto Networks DNS Secu...
Ranking in Domain Name System (DNS) Security
3rd
Average Rating
8.6
Reviews Sentiment
6.1
Number of Reviews
16
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of October 2026, in the Domain Name System (DNS) Security category, the mindshare of IBM NS1 Connect is 2.1%, up from 1.9% compared to the previous year. The mindshare of Palo Alto Networks DNS Security is 10.7%, up from 8.7% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Domain Name System (DNS) Security Mindshare Distribution
ProductMindshare (%)
Palo Alto Networks DNS Security10.7%
IBM NS1 Connect2.1%
Other87.2%
Domain Name System (DNS) Security
 

Featured Reviews

Sanchit Makkar - PeerSpot reviewer
Dns architect at a outsourcing company with 5,001-10,000 employees
Intelligent global traffic steering has improved reliability and reduced latency for users
IBM NS1 Connect has a very steep learning curve in terms of learning the custom filter chains and the complex multi-region setup, which requires a specialized DNS expert and can be difficult for beginners. One has to get trained on IBM NS1 before starting to use it. The documentation and the interface could be improved, as a step-by-step video configuration guide would be helpful in new implementations. Daily change audit features and easier rollback options should also be provided in the GUI itself. The dashboard and the GUI have gray areas for advanced tasks, which require API interaction and can be overwhelming for beginners.
Partha Dash - PeerSpot reviewer
Global Network Tech Lead at a tech vendor with 10,001+ employees
Protects against threats by quickly identifying insider risks and compromised devices
Palo Alto should explore agentless approaches to integrate DNS Security more easily and efficiently. The existing system sometimes presents challenges with backbone routing, impacting productivity. An agentless approach could be more lightweight and user-friendly. Additionally, there is a need for improvement in the pricing model for support and license renewals.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The Filter Chain is one of the most valuable features, for geo-load balancing and geo-fencing. The Filter Chain is the most useful because it allows us to do several things. With geo-fencing we can redirect a particular user to a particular answer. That's very valuable for us. Filter Chains with monitoring is our strategy to provide redundancy."
"IBM NS1 Connect has a positive impact on my organization, as I believe it improves security, availability, and DDoS attack mitigation because it detects failures and automatically redirects users to healthy resources."
"The fact that it's an API-first platform for DNS and application traffic management is one of the reasons we looked into NS1. We use it for a lot of automation and metrics gathering and it's been great."
"Going with NS1 has also improved the user experience for our users."
"The best benefits of using IBM NS1 Connect are the performance and availability of the product towards the cloud, and when comparing the performance with other products, I believe it is above par, as it is really helpful and gives me at least a 20 to 30% improvement in functionality."
"NS1 gives us a nice flat line, because it's always performant and fast and that's what we want to see."
"Their Pulsar filters allow us to collect RUM metrics from our users so that we can determine the best paths for our users to take. That has been very useful in providing the best user experience, and for responding to and recovering from downtime of our multiple CDNs."
"The solution's stability is absolutely perfect."
"DNS sinkhole is a valuable feature."
"The most valuable feature is DNS filtering."
"We now have insight into our DNS requests and we can actively see how many thousands of malicious requests have gotten knocked down in the last day or week that we didn't have before. There's more insight for both security and more insight."
"The most valuable features of the solution are DNSSEC and the domain generation algorithm."
"I would rate the scalability a nine out of ten."
"When comparing other cloud-based DNS security solutions to this one I have found the main beneficial feature in this solution to be we do not need to change our architecture."
"Palo Alto Networks DNS Security is a stable solution."
"So, in general, it's very stable because the process to deliver new features and new releases in not so long...I rate the scalability a nine out of ten."
 

Cons

"The technical support is slow. You raise a PR, and then it takes several weeks for them to respond."
"There could maybe be additional ways to manage traffic. There are no major improvements we're looking for. It's a very complete solution."
"When we first deployed, we flipped the switch, and it didn't work as well as we expected. It wasn't a complete outage, but we had issues in some places with some customers. The NS1 team went out of their way to resolve it on Thanksgiving. We have a post about it on our blog. We called it "Black Thursday.""
"I would love to see improvement in the testing capabilities they provide. They have a simulate-filter feature so that you can simulate how your traffic would flow, based on their Filter Chains. I believe that was shut off for quite some time. Having that as a way to test our load-balanced CDN structure would be fantastic."
"I would like to see the UI updated to allow me to do finer searches."
"We care about monitoring and telemetry work, and NS1 provides a pretty good system for monitoring. We can monitor our endpoints and points of presence around the world. If there are any issues, we can easily remove them from our network, but this area needs some improvement because it is not always reliable in NS1. In the past, we had a number of false-positive cases when the monitoring system told us about some problems in our infrastructure that were not true. NS1 is improving the system, and we are constantly talking about this with them. I know that they are releasing a new version of their monitoring system, which is really important for us, but this is a different area where we would expect them to improve."
"I believe IBM NS1 Connect can be improved in several ways. The main concern I identified is the cost, which is higher than other solutions despite its uses."
"When we first deployed, we flipped the switch, and it didn't work as well as we expected."
"The solution can capture more market if made more cost-competitive than Infoblox or Cisco Umbrella."
"Palo Alto should explore agentless approaches to integrate DNS Security more easily and efficiently."
"The number of hotfixes indicates that there are many bugs in the new releases. Comparing a few years earlier, a release contained much fewer hotfixes."
"I'm not really sure what needs improvement. The only hiccup I've really seen is a couple of the DNS requests get flagged as the Sophos traffic instead of DNS traffic, but that's more of their app detection in the DNS Security. I haven't really seen any issues with the DNS security."
"The pricing of the Palo Alto Networks DNS Security is very high."
"Sometimes, it blocks legitimate traffic for custom applications, requiring manual intervention."
"The solution’s scalability could be improved."
"The product should provide email protection."
 

Pricing and Cost Advice

"We pay about $30,000 a month. We used to pay about $20,000 with Dyn every month, for lower volume than we're doing right now, but it had none of the features that we have available with NS1, so it was worth it for us. It seems competitive for us, given that we're doing 4.5 billion requests."
"The cost of this product is one of the reasons that we chose it."
"NS1's pricing is much more aggressive than its competitors in the market and you get more value out of what you pay for it."
"From a cost standpoint, it's certainly not the most expensive out there, and it's also not the cheapest, but it does well to balance the cost and the functionality/reliability."
"Everything can always be cheaper, but as it is today the pricing is fair."
"There aren't many vendors offering DNS security solutions, but generally, Palo Alto subscriptions tend to be more expensive than other security vendors."
"The solution's pricing is equal to Cisco AMP or Cisco Umbrella."
"If one is very cheap and ten is very expensive, I rate the tool's price as two."
"It is not an expensive solution."
"Palo Alto Networks DNS Security is an expensive product. I rate the product's pricing an eight on a scale of one to ten, where one is cheap, and ten points are expensive."
"There is an annual license for the solution and I am satisfied with the pricing."
"The product is expensive compared to Fortinet."
"The product is expensive. My company makes payments on a quarterly basis towards the solution's costs."
report
Use our free recommendation engine to learn which Domain Name System (DNS) Security solutions are best for your needs.
915,341 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Comms Service Provider
13%
Financial Services Firm
9%
Computer Software Company
9%
Healthcare Company
6%
Financial Services Firm
14%
Manufacturing Company
10%
Computer Software Company
9%
Performing Arts
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business2
Midsize Enterprise4
Large Enterprise14
By reviewers
Company SizeCount
Small Business6
Large Enterprise10
 

Questions from the Community

What needs improvement with NS1 Managed DNS?
I believe IBM NS1 Connect can be improved in several ways. The main concern I identified is the cost, which is higher than other solutions despite its uses. Additionally, they could improve their h...
What is your primary use case for NS1 Managed DNS?
My main use case for IBM NS1 Connect is handling DNS traffic and routing traffic. A specific example of how I use IBM NS1 Connect to route traffic is routing the API, the websites' API, and the app...
What advice do you have for others considering NS1 Managed DNS?
Regarding IBM NS1 Connect's AI capabilities, the accuracy and reliability of output involve least privileged API keys, API key rotation, secret management, and monitoring and alerting, with alerts ...
What needs improvement with Palo Alto Networks DNS Security?
DNS Security protects us against threats, malware, and malicious domains or malicious navigation to the internet, which is where it can be improved the best. Palo Alto helps us with support, so I d...
What is your primary use case for Palo Alto Networks DNS Security?
I can describe my use cases for Palo Alto Networks DNS Security, which is used for protecting our network. I use this product, Palo Alto Networks DNS Security, with Palo Alto firewalls.
What advice do you have for others considering Palo Alto Networks DNS Security?
I don't have experience with Palo Alto Networks AutoFocus. Regarding the DNS Security, I have firewalls with the DNS Security module in the firewall. DNS Security is something we configure in our f...
 

Also Known As

NS1 Managed DNS, NS1
No data available
 

Overview

 

Sample Customers

Avast Software, Bloomberg L.P., BBC, Carfax, CNBC LLC, Deloitte Consulting LLP, Disney Streaming, Dropbox, EBAY Inc, Gannett Media Corp, Salesforce, Wayfair, Workday
Information Not Available
Find out what your peers are saying about IBM NS1 Connect vs. Palo Alto Networks DNS Security and other solutions. Updated: September 2026.
915,341 professionals have used our research since 2012.