We have deployed Palo Alto Networks NG Firewalls and every web filter security available. So, we came to know each website user who got blocked and the "not required" categories. These categories are permanently blocked, and if any changes are required in these categories, we will first get approval from management.
Deputy General Manager IT at ARAI
A next generation firewall solution with a useful sandbox feature, but performance could be better
Pros and Cons
- "I like the sandbox feature, and it's very good. It kills each malware deployment in the sense of signatures within five minutes. So, we can secure our network and infrastructure very well within the stipulated time. The WildFire functionality is very good because a few files are also getting blocked. It's critical as malware attacks are also getting ignored, and the logging is very well maintained in this firewall. The most valuable solutions in this field are application-based firewalls. That is the main criteria of the firewall and functionality. We can get all the logs related to this and each and every packet. I like that the firewall is working as an application. The application-based entity we have deployed is well maintained and working very well. We were able to find lots of vulnerabilities when we deployed it, but we could not disclose all. But there were vulnerabilities we could block by updating the firewall and taking actions on clientside machines. So, we got to know that we have lots of vulnerabilities inside the organization too, and we took lots of steps and resolved the number of vulnerabilities. Palo Alto Networks NG Firewalls is an all-in-one solution. It provides every entity log, which is a very good functionality of this firewall. It gives every packet and aspect that the firewall is performing through its logs, and it does it very well. This firewall's unified platform helped eliminate multiple network security tools. If anyone uses P2P sites, cryptocurrency websites, or any illegal sites, we can block it easily. It gives us a proper alert for these kinds of sites, and it properly secures our network. Monitoring is the best thing we are doing here, and we can block this kind of vulnerability as soon as it comes to us."
- "Palo Alto Networks NG Firewalls is an all-in-one solution; it provides every entity log, which is a very good functionality of this firewall, giving every packet and aspect that the firewall is performing through its logs, and it does it very well."
- "We are not happy with Palo Alto at all. It would be better if they provided more support for the firewall. We have a few pending issues with the configuration for each application. We cannot deploy them yet due to some support-related problems in the firewall. We have deployed a few policies for DNS spoofing and DNS attacks, but we could only block a few IP addresses through the policy. That's DNS security, and we have configured a few policies for DNS spoofing and more. URL categorization and URL filtering are not yet adequately maintained. For example, if you created a few rules in the rule-based configuration and made some rules downstairs, you will lose some of them if you give access upstairs. It's not giving us a proper solution for which route it is using. We need to apply the application-based policies and URL filtering-based policies. It creates more issues because we are not getting good support from the team."
- "We are not happy with Palo Alto at all."
What is our primary use case?
What is most valuable?
I like the sandbox feature, and it's very good. It kills each malware deployment in the sense of signatures within five minutes. So, we can secure our network and infrastructure very well within the stipulated time.
The WildFire functionality is very good because a few files are also getting blocked. It's critical as malware attacks are also getting ignored, and the logging is very well maintained in this firewall.
The most valuable solutions in this field are application-based firewalls. That is the main criteria of the firewall and functionality. We can get all the logs related to this and each and every packet. I like that the firewall is working as an application. The application-based entity we have deployed is well maintained and working very well.
We were able to find lots of vulnerabilities when we deployed it, but we could not disclose all. But there were vulnerabilities we could block by updating the firewall and taking actions on clientside machines. So, we got to know that we have lots of vulnerabilities inside the organization too, and we took lots of steps and resolved the number of vulnerabilities.
Palo Alto Networks NG Firewalls is an all-in-one solution. It provides every entity log, which is a very good functionality of this firewall. It gives every packet and aspect that the firewall is performing through its logs, and it does it very well.
This firewall's unified platform helped eliminate multiple network security tools. If anyone uses P2P sites, cryptocurrency websites, or any illegal sites, we can block it easily. It gives us a proper alert for these kinds of sites, and it properly secures our network. Monitoring is the best thing we are doing here, and we can block this kind of vulnerability as soon as it comes to us.
What needs improvement?
We are not happy with Palo Alto at all. It would be better if they provided more support for the firewall. We have a few pending issues with the configuration for each application. We cannot deploy them yet due to some support-related problems in the firewall.
We have deployed a few policies for DNS spoofing and DNS attacks, but we could only block a few IP addresses through the policy. That's DNS security, and we have configured a few policies for DNS spoofing and more.
URL categorization and URL filtering are not yet adequately maintained. For example, if you created a few rules in the rule-based configuration and made some rules downstairs, you will lose some of them if you give access upstairs. It's not giving us a proper solution for which route it is using. We need to apply the application-based policies and URL filtering-based policies. It creates more issues because we are not getting good support from the team.
For how long have I used the solution?
I have been using Palo Alto Networks NG Firewalls for the last three or four years.
Buyer's Guide
Palo Alto Networks NG Firewalls
September 2026
Learn what your peers think about Palo Alto Networks NG Firewalls. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
914,351 professionals have used our research since 2012.
What do I think about the stability of the solution?
Stability in the sense of security and alerts, this solution is very good, and we have not had had any issues. However, web filtering and application-based approach are very poor.
What do I think about the scalability of the solution?
Palo Alto Networks NG Firewalls is a scalable solution.
How are customer service and support?
Palo Alto Networks support could be better. We bought this solution for security purposes, and we asked the support team to convert each and every entity. They have not been able to convert this New Generation Firewall to date.
Their name suggests that the product will use every application and work as a New-Generation Firewall. Yet, it's not configured, and we can only configure 30% to 40% of the applications. That is also giving us some problems sometimes.
On a scale from one to ten, I would give Palo Alto Networks support a three.
Which solution did I use previously and why did I switch?
We have a policy in our organization to change the firewall every five years. So, I have experience working on FortiGate, SonicWall, and WatchGuard over the last 20 years.
WatchGuard is very good at web filtering. FortiGate is also very good, and they have their own application to manage the firewall, and SonicWall is also very good.
Palo Alto is a web-based firewall, and there are no applications to deploy and support. I mean, I take all the logs and all things from the client-side. As it's web-based, it's extremely slow.
When you click on a particular log, it will take a lot of time because it generates lots of logs. That is a good thing, but performance is a little slow. Both WatchGuard and FortiGate are very good for this kind of thing. Also, WatchGuard is application-based, and I didn't have to deploy it. I came to know about Palo Alto from my friends who said it was very good for application-based security.
How was the initial setup?
The initial setup and deployment are straightforward. We did not have any issues at all. It took us about 15 to 20 days to implement this solution.
What about the implementation team?
The policies we have with Atelier and WatchGuard were exported, and we tried to deploy these policies on the new firewall. The reseller helped us configure it but without our concession or permission and could not deploy the firewall. We later had more problems, and the reseller helped us with that as well.
Video Import Solutions is our local reseller in Pune, India. In our experience, not every engineer knew the firewall concept. I mean, not at all. If we wanted something new or had to deal with this application-related issue, they always told us they would log a case and resolve it. But they did not support us at all and did not give us any reason why they could not do it.
What was our ROI?
I am a technical guy, and I would say that you will not get a return on your investment. Even FortiGate and WatchGuard will offer next-generation solutions that perform better than Palo Alto Networks.
What's my experience with pricing, setup cost, and licensing?
The price could be better. Pricing is very different compared to WatchGuard, which costs around 60 lakhs, and FortiGate, which costs approximately 40 lakhs. Palo Alto Networks costs about a crore which is very high pricing.
We bought this firewall, and our organization did not want to pay so much. We spent around one crore rupees which is not within our budget at all, and we are unhappy with them.
What other advice do I have?
This firewall provides a unified platform that natively integrates all security
capabilities. It will queue all functionalities like firewall protection and alerts and track all DDoS attacks. It shares all the information with us, and we can monitor and take immediate action on the other alerts we receive.
I would advise potential users to only go for this solution if they have the budget and don't require any support. Only buy this firewall if you can install, configure, and solve potential problems on your own. If not, FortiGate and WatchGuard are much better options.
On a scale from one to ten, I would give Palo Alto Networks NG Firewalls a five.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Network Analyst at a recreational facilities/services company with 1,001-5,000 employees
Its single pane of glass makes monitoring and troubleshooting more homogeneous
Pros and Cons
- "With its single pane of glass, it makes monitoring and troubleshooting a bit more homogeneous. We are not looking at multiple platforms and monitoring management tools. It is more efficient from that perspective. It is more of a common monitoring and control system for multiple aspects of what used to be different systems. It provides efficiency and time savings."
- "As far as a firewall solution, it is one of the best ones that I have seen."
- "Once in a while, they have new features being released that can be buggy. My criticism is more general to all sorts of network or security devices. In general, everybody is releasing less-tested software. Then, it usually ends up that the first few customers who get a new release need to end up troubleshooting it."
- "Once in a while, they have new features being released that can be buggy."
What is our primary use case?
It is our main Internet firewall. It is used a lot for remote access users. We also use the site-to-site VPN instance of it, i.e., LSVPN. It is pretty much running everything. We have WildFire in the cloud, content filtering, and antivirus. It has pretty much all the features enabled.
We have a couple of virtual instances running in Azure to firewall our data center. Predominantly, it is all physical hardware.
I am part of the network team who does some work on Palo Alto Networks. There is actually a cybersecurity team who kind of controls the reins of it and does all the security configuration. I am not the administrator/manager in charge of the group that has the appliance.
How has it helped my organization?
With its single pane of glass, it makes monitoring and troubleshooting a bit more homogeneous. We are not looking at multiple platforms and monitoring management tools. It is more efficient from that perspective. It is more of a common monitoring and control system for multiple aspects of what used to be different systems. It provides efficiency and time savings.
What is most valuable?
It is fairly intuitive.
The central management of Panorama actually works. It is what FortiManager aspires to be, but Panorama is usable. You can push config down, do backups, and use templates from other sites, copying them over. The reliability and throughput, plus Panorama's control features, are its main selling features.
It is a combined platform that has different features, like Internet security and the site-to-site VPN. Previously, there were different components that did this. If it was a remote access VPN client, then you would have to go onto one platform and troubleshoot. If it was a site-to-site, it was on a different platform so you would have to go onto that one. It would be different command sets and troubleshooting steps. From that perspective, having that combined and all visible through Panorama's centralized management is probably one of the better benefits.
We had a presentation on Palo Alto Networks NG Firewalls a few years ago. I know the number of CPU cores that they have inside the firewall is crazy, but it is because they have to pack all the performance and analysis in real-time. It is fast. I am always amazed at the small PA-220s and how much performance they have with their full antivirus on it. They can pass 300-megabits per second, and they are just about the size of a paperback book. As far as how that single-pass processing impacts it, I am always amazed at how fast and how much throughput it has.
What needs improvement?
Once in a while, they have new features being released that can be buggy. My criticism is more general to all sorts of network or security devices. In general, everybody is releasing less-tested software. Then, it usually ends up that the first few customers who get a new release need to end up troubleshooting it. That is one of my criticisms because we have been hit by this a few times. I shouldn't single Palo Alto out as any better or worse than anybody else because they are all doing it now.
It is not like we are getting singled out. In some cases, we are looking for a new feature that we want to use. So, we upgrade and use it, and others are too, but the first release will tend to be a little bit buggy. Some of the stuff works great, but it is the newer features that you are usually integrating into your Windows clients where weird stuff happens.
For how long have I used the solution?
I use it every other day.
What do I think about the stability of the solution?
It is pretty reliable. All the services pretty much work. It is not too buggy. With any hardware/software manager these days, when you get new features, they tend to not be too thoroughly tested and can be buggy. We have been noticing this. For example, they had zero-touch deployment and the first few iterations just didn't work. While we have encountered a few bugs, I don't think they are any worse than anything else we get. The underlying hardware seems to be pretty reliable. You can do configuration changes, reboot and reload them, and they just keep coming back and work.
Our cybersecurity guys tend to do the patching and upgrades when they come around. When one of these things had a hard disk failure, they got that restored or replaced. For day-to-day maintenance, other than typical operational changes and troubleshooting, I don't think there is that much maintenance to be done. Every few weeks, there is probably somebody who goes for a few hours and checks the various patch levels and possibly does upgrades.
The upgrades are fairly easy to do. You just download the software, the central management system, and tick off the devices that you want to deploy it to. It will automatically download it. Then, you just sort of schedule a reboot. I don't know how many hours per week or month people put into it, but it is pretty reasonable.
What do I think about the scalability of the solution?
We have about half a dozen core firewalls and 30 to 40 remote firewalls. We haven't hit any scaling limitations yet. What we have is functioning well. At some point, our main firewall in our data center might be overwhelmed, but it has pretty high throughput numbers on it. So far, we haven't hit any sort of limitations. So far, so good.
The physical appliances are sort of tiered. You have your entry-level, which is good for 300-megabits of threat detection. The next ones have 800-megabits of threat detection. So, if you have a site with around 50 people, you can get the entry-level. However, there is always a point that if you have too many users doing too many things then the physical appliance just can't handle it. Then, you need to upgrade to a higher-level appliance. This is expected. When that happens, we will just sort of get the higher-level model or plan for two years of growth to get the right size. Therefore, as far as scalability, it just comes down to planning.
As far as the management platform, that would be more of a case of just adding CPU cores into your virtual machine as well as more memory. So far, we haven't had any scalability limitations. It is possible that we will see it at some point, but we haven't so far.
How are customer service and support?
This is not Palo Alto-specific. It seems to be across all the different vendors that there is a little bit of a hit-and-miss on whether you get a tech person who knows what they are doing and are interested in your problem. When you call frontline support, you can get somebody who doesn't know what they are doing and puts you off. Or the next time you call, you can get a tech who is on the ball and super helpful. This is sort of a smaller problem. It is a bit of a crapshoot on how good the support will be. I would rate the frontline technical support as five or six out of 10.
If it tends to be more of a critical problem, and you involve the sales team, then you are forwarded onto somebody who really knows what they are doing. However, the frontline support can be hit-and-miss. Their second-tier support is really good.
The top-tier support is 10 out of 10. We did have some more serious problems, then they put one of their engineers on it who has been amazing.
Overall, I would rate the technical support as eight out of 10.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I did work with Cisco ASA, prior to FireEye, where they purchased and integrated it as sort of the next generation part of their ASA.
One of our remote access solutions for remote access clients was Cisco ASA. That was just getting to its end-of-life. It actually worked quite well. It was pretty hands-off and reliable, but the hardware was getting to end-of-life. Because we had the Palo Alto capable of doing similar functions, we just migrated it over.
It was similar for our site-to-site VPN, which was Cisco DMVPN that we are still using, but we are migrating off it since its hardware is reaching end-of-life. By combining it into the Palo Alto umbrella, it makes the configuration and troubleshooting a bit easier and more homogenous.
Before, it was just different platforms doing sort of similar but different functions. Now, we are using similar platforms and devices rather than having three different solutions. This solution is sort of homogenized; it is sort of all in one place. I suspect that makes security a bit more thorough. Whereas, we had three different platforms before. Some of the delineation isn't clear, as they sort of overlap in some respects to what they do, but having it in one location and system makes gaps or overlaps or inconsistencies easier to spot.
How was the initial setup?
I was gone for a few years when they brought this in.
Adding additional appliances is very straightforward.
What was our ROI?
Having one manager/system with a common interface and commands, rather than three or four, is more efficient.
What's my experience with pricing, setup cost, and licensing?
It is expensive compared to some of the other stuff. However, the value you get out of it is sort of the central control and the ability to reuse templates.
It is a good product, but you pay for it. I think it is one of the more expensive products. So, if you are looking for a cheaper product, there are probably other options available. However, if you are looking for high performance, reliable devices, then it has kind of everything. Basically, you get what you pay for. You can get other firewalls for cheaper and some of the performance would probably be just as good, but some of the application awareness and different threat detections are probably superior on the Palo Alto Networks.
What other advice do I have?
As far as a firewall solution, it is one of the best ones that I have seen. It is fairly expensive compared to some of the other ones, but if you have the money and are looking for a solid, reliable system, then Palo Alto is the way to go.
For what we use it for, the solution is good.
I am part of the network team. There is a cybersecurity team who has control of its reins and does all the security configuration. I am not the administrator of it or a manager in charge of the group with this appliance.
I find the whole machine learning and AI capabilities a bit overhyped. Everybody throws it in there, but I'm actually a little bit suspicious of what it is actually doing.
I don't follow or monitor some of the day-to-day or zero-day threat prevention protection abilities that it has.
I would rate the solution as nine out of 10, as I am always hesitant to give perfect scores.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Palo Alto Networks NG Firewalls
September 2026
Learn what your peers think about Palo Alto Networks NG Firewalls. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
914,351 professionals have used our research since 2012.
Network Solutions Architect at a financial services firm with 10,001+ employees
Gives you a lot of information when you are monitoring traffic
Pros and Cons
- "It is critical that Palo Alto Networks NG Firewalls embeds machine learning in the core of the firewall to provide inline, real-time attack prevention. In my environments, we have an integration with a third-party vendor. As soon as there is new information about new threats and the destination that they are trying to reach on any of our network devices, that traffic will be stopped."
- "Palo Alto Networks NG Firewalls is a very good firewall; it is one of the best firewalls that I have used."
- "There is a bit of limitation with its next-generation capabilities. They could be better. In terms of logs, I feel like I am a bit limited as an administrator. While I see a lot of logs, and that is good, it could be better."
- "Palo Alto Networks NG Firewalls technical support is very poor."
What is our primary use case?
We use it as an Internet-facing parameter firewall. In my environment, it has security and routing. It is on a critical path in terms of routing, where it does a deep inspection, etc.
How has it helped my organization?
There have been a lot of improvements from security to service.
It is critical that Palo Alto Networks NG Firewalls embeds machine learning in the core of the firewall to provide inline, real-time attack prevention. In my environments, we have an integration with a third-party vendor. As soon as there is new information about new threats and the destination that they are trying to reach on any of our network devices, that traffic will be stopped.
What is most valuable?
Setting up a VPN is quite easy.
It gives you a lot of information when you are monitoring traffic.
In terms of user experience, Palo Alto has very good user administration.
Machine learning is important. Although we have not exhausted the full capabilities of the firewall using machine learning, the few things that we are able to do are already very good because we have an integration with a third-party. We are leveraging that third-party to get threat intelligence for some destinations that are dangerous, as an example. Any traffic that tries to go to those destinations is blocked automatically. There is a script that was written, then embedded, that we worked on with the third-party. So, machine learning is actually critical for our business.
What needs improvement?
There is a bit of limitation with its next-generation capabilities. They could be better. In terms of logs, I feel like I am a bit limited as an administrator. While I see a lot of logs, and that is good, it could be better.
I wanted Palo Alto Networks engineering to look at the traffic log, because I see traffic being dropped that happens to be legitimate. It would be interesting for me to just right click on the traffic, select that traffic, and then create a rule to allow it. For example, you sometimes see there is legitimate traffic being dropped, which is critical for a service. That's when actually you have to write it down, copy, a rule, etc. Why not just right click on it and select that link since that log will have the source destination report number? I would like to just right click, then have it pop up with a page where I can type the name of the rule to allow the traffic.
For how long have I used the solution?
I started using Palo Alto in 2015.
What do I think about the stability of the solution?
It is very stable. We had two outages this year that were not good. They were related to OSPF bugs. Those bugs affected our service availability.
What do I think about the scalability of the solution?
It is quite scalable. I have been able to create a lot of zones to subinterfaces for a number of environments. I don't really have any issues regarding scalability. It meets my expectations.
How are customer service and support?
Palo Alto Networks NG Firewalls technical support is very poor. Three or four months ago, I had a bug where the database of the firewall was locked. You cannot do anything with it. We looked for documentation, giving us a procedure to follow, but the procedure didn't work. We logged a complaint with Palo Alto Networks, and they gave us an engineer. The engineer relied on documentation that doesn't work, and we had already tested. In the end, the engineer gave us an excuse, "No, we need this account to be able to unlock it." This happened twice. The way out of it was just to restart the firewall. You can restart the firewall and everything goes back to normal. Therefore, I think the support that we got was very poor.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
I have used Check Point and Cisco ASA.
Initially, when I started with Palo Alto, we had Cisco ASA, but Palo Alto Networks beat ASA hands down.
We have a multi-vendor environment with different providers. Our standard is that we can't have the same firewall for each parameter, so there is some kind of diversity.
We had ASA looking at one side of the network and Palo Alto Networks looking at the other side of the network. We also had Juniper looking at another side of the network. At the end of the day, ASA was very good, I don't dispute that. However, in terms of functionality and user experience, Palo Alto Networks was better.
Palo Alto Networks beat ASA because it was a next-generation firewall (NGFW), while ASA was not.
How was the initial setup?
When we bought Palo Alto, we had Juniper devices in our environment. We were told that it was a bit like Juniper, so we were happy. However, some people were a bit skeptical and scared of Juniper firewalls. Because of that, it took us a very long time to put them on the network. However, as soon as we did the implementation, we realized that we were just thinking too much. It was not that difficult.
We deployed Palo Alto Networks as part of a project for data center implementation. The implementation of the firewall didn't take long.
What about the implementation team?
We buy through a third-party. Our account is managed by IBM.
What was our ROI?
We have seen ROI. There is more visibility in the environment in terms of security. There was a time when we suspected a security breach, and this firewall was able to give us all the logs that we expected.
What's my experience with pricing, setup cost, and licensing?
Palo Alto is like Mercedes-Benz. It is quite expensive, but the price is definitely justified.
Which other solutions did I evaluate?
One thing is system administration. In our opinion, Palo Alto administration is easier compared to other vendors. I know other vendors who have Check Point. You have to manage Check Point, and it is a bit cumbersome. It is a very nice, powerful firewall, but you need more knowledge to be able to manage Check Point compared to Palo Alto. Palo Alto is very straightforward and nice to use.
In our environment, troubleshooting has been easy. Anybody can leverage the Palo Alto traffic monitoring. In Cisco ASA and Check Point, you also have these capabilities, but capturing the traffic to see is one thing, while doing the interpretation is another thing. Palo Alto is more user-friendly and gives us a clearer interpretation of what is happening.
One thing that I don't like with Palo Alto is the command line. There isn't a lot of documentation for things like the command line. Most documents have a graphic user interface. Cisco has a lot of documents regarding command lines and how to maneuver their command line, as there are some things that we like to do with the command line instead of doing them with the graphic interface. Some things are easy to do on a graphic interface, but not in the command line. I should have the option to choose what I want to do and where, whether it is in the command line or a graphic interface. I think Palo Alto should try to make an effort in that aspect, as their documentation is quite poor.
We would rather use Cisco Umbrella for DNS security.
I compared the price of Palo Alto Networks with Juniper Networks firewall. The Juniper firewall is quite cheap. Also, Palo Alto Networks is a bit expensive compared to Cisco Firepower. Palo Alto Networks is in the same class of Check Point NGFW. Those two firewalls are a bit expensive.
It gives us visibility. In my opinion, the first firewall that I would put on our network is Palo Alto Network and the second would be Check Point.
What other advice do I have?
Palo Alto Networks NG Firewalls is a very good firewall. It is one of the best firewalls that I have used.
I would rate Palo Alto Networks as nine out of 10.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Director Of Technology at La Jolla Country Day School
Protects our network from various malicious activities by filtering and inspecting traffic
Pros and Cons
- "It is pretty important to have embedded machine learning in the core of the firewall to provide inline, real-time attack prevention, because all these different attacks and threats are constantly evolving. So, you want to have something beyond just hard pass rules. You want it to learn as it is going along. Its machine learning seems pretty good. It seems like it is catching quite a few things."
- "Its machine learning seems pretty good, and it seems like it is catching quite a few things."
- "There is a web-based GUI to do management, but you need to know how the machine or firewall operates. There are hundreds of different menus and options. I have used other firewalls before. Just implementing or designing a policy with Palo Alto, if you want a certain port to be open to different IP addresses, then that could take 20 to 25 clicks. That is just testing it out. It is quite complex to do. Whereas, with other places, you tell it, "Okay, I want this specific port open and this IP address to have access to it." That was it. However, not with Palo Alto, which is definitely more complex."
- "There is a web-based GUI to do management, but you need to know how the machine or firewall operates. There are hundreds of different menus and options."
What is our primary use case?
We basically use it to protect our network from various malicious activities out there. We have two subscriptions. We have the WildFire subscription, which is similar to DNS filtering. We also have Threat Protection, which allows the firewall to inspect traffic up to Layer 7. It inspects applications as well as unknown applications, quarantining and stopping things. So, you are not always chasing, "What applications should I be running on this device?" It does a good job of all of that. The management of it is a little tricky, but that is how it goes.
We are running the PA-3250s. We have two of them. They operate in Active/Passive mode. Therefore, if one fails, then the other one takes over.
What is most valuable?
It is pretty important to have embedded machine learning in the core of the firewall to provide inline, real-time attack prevention, because all these different attacks and threats are constantly evolving. So, you want to have something beyond just hard pass rules. You want it to learn as it is going along. Its machine learning seems pretty good. It seems like it is catching quite a few things.
What needs improvement?
There is a web-based GUI to do management, but you need to know how the machine or firewall operates. There are hundreds of different menus and options. I have used other firewalls before. Just implementing or designing a policy with Palo Alto, if you want a certain port to be open to different IP addresses, then that could take 20 to 25 clicks. That is just testing it out. It is quite complex to do. Whereas, with other places, you tell it, "Okay, I want this specific port open and this IP address to have access to it." That was it. However, not with Palo Alto, which is definitely more complex.
The VPN is only available for Windows and Mac iOS environments. We have a variety of iPads, iPhones, and Android stuff that wouldn't be able to utilize the built-in VPN services.
I would like easier management and logging. They can set up some profiles instead of having you create these reports yourself. However, you should be able to set it up to give you alerts on important things faster.
For how long have I used the solution?
We have had this in place for four years. I have been at the school for almost a year and a half. So, this is my second year here at the school, so my experience with it has probably been a year and change. I use other firewall solutions, but I have gotten pretty comfortable with the Palo Alto solution.
What do I think about the stability of the solution?
It is very stable. We have never had any issues with any failures on it.
I haven't felt any performance lags on it. It has been handling everything just fine.
What do I think about the scalability of the solution?
We purchased it a few years ago. Since then, we have had a lot more clients on our network, and it has handled all that fine. You go into it and just have to scale it higher. Palo Alto doesn't give you too many choices. There is not a medium; it is either very small or very big. So, you don't have a choice in that.
How are customer service and support?
We have never had to call Palo Alto. Secure Works does all our support maintenance on it.
Which solution did I use previously and why did I switch?
I have been here for a year and a half. Before, the firewall that they were using (Barracuda) was barely adequate for what we were doing. We got new ones simply, not because we had a software/hardware-type attack, but because we had a social engineering attack where one of the folks who used to work for us went on to do some crazy things. As a result, the reaction was like, "Oh, let's get a new firewall. That should stop these things in the future."
How was the initial setup?
The initial setup was pretty complex because they did not do it themselves. They actually hired some folks who put it in.
What about the implementation team?
We use Secureworks, which is a big security company. They actually send an alert when there are problems with the firewall or if there are security issues. They handled the deployment.
We also use another company called Logically to monitor the firewall in addition to all our other devices.
What's my experience with pricing, setup cost, and licensing?
Active/Passive mode is very redundant, but they require you to buy all the associated licensing for both firewalls, which is kind of a waste of money because you are really only using the services on one firewall at a time.
I would suggest looking at your needs, because this solution's pricing is very closely tied to that. If you decide that you are going to need support for 1,000 connections, then make sure you have the budget for it. Plan for it, because everything will cost you.
If another school would call and ask me, I would say, "It's not the cheapest. It's very fast, but it's not the cheapest firewall out there."
Which other solutions did I evaluate?
I have been looking at different firewalls because our service and maintenance contracts are up on it. We have two different outsourced folks who look at the firewall and help us do any configurations. My staff and I lack the knowledge to operate it. For any change that we need to make, we have to call these other folks, and that is just not sustainable.
We are moving away from this solution because of the pricing and costs. Everything costs a lot. We are moving to Meraki MS250s because of their simplicity. They match the industry better. I have called the bigger companies, and Meraki matches the size, then the type of institution that we are.
If someone was looking for the cheapest and fastest firewall product, I would suggest looking at the Meraki products in the educational space. I think that is a better fit.
What other advice do I have?
Its predictive analytics and machine learning for instantly blocking DNS-related attacks is doing a good job. I can't be certain because we also have a content filter on a separate device. Together, they kind of work out how they do DNS filtering. I know that we haven't had any problems with ransomware or software getting installed by forging DNS.
DNS Security for protection against sneakier attack techniques, like DNS tunneling, is good. I haven't had a chance to read the logs on those, but it does pretty well. It speaks to the complexity of the firewall. It is hard to assess information on it because there is just a lot of data. You need to be really good at keeping up with the logs and turning on all the alerts. Then, you need to have the time to dig through those because it could be blocking something, which it will tell you.
I haven't read the NSS Labs Test Report from July 2019 about Palo Alto NGFW, but it sounds interesting. Though it is a little bit of snake oil, because the worst attacks that we had last year were purely done through social engineering and email. I feel like this is an attack vector that the firewall can't totally block. So, before you put something in, like Palo Alto Firewalls, you need to have your security policy in place first.
I would rate this solution as eight out of 10. Technically, it is a good solution, but for usability and practicality, I would take points off for that.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Chief Information Security Officer at a tech vendor with 1-10 employees
Great firewall with excellent features and helpful configuration capabilities
Pros and Cons
- "Technical support is proactive in letting us know when there are updates that need to be made to the system."
- "We haven't had any issues so far."
What is our primary use case?
The solution is to provide protection for our cloud-based server resources.
How has it helped my organization?
We don't have to spend as much time monitoring or configuring the solution. We just feed the alerts into our stock and we don't have to manage it regularly.
What is most valuable?
The configuration and stability are great. The solution offers many good features. Palo Alto has by far the best firewall in the world.
Palo Alto NG Firewalls embed machine learning into the core of the firewall to provide real-time attack prevention. Of course, that's just expected these days. Anyone worth considering is doing this. Low-end firewall devices out there do not provide that. However, they're not enterprise-ready.
The machine learning in Palo Alto's Next-Generation Firewalls is excellent for securing our networks against threats that are able to evolve and morph rapidly. It's a ten out of ten.
The product provides a unified platform that natively integrates all the security capabilities. That's very important to us.
The product has zero-day signature features implemented.
There are no trade-offs between security and network performance with Palo Alto.
What needs improvement?
We haven't had any issues so far.
For how long have I used the solution?
I've used the solution for the last three years, although the company has used it for longer.
How are customer service and support?
Technical support is proactive in letting us know when there are updates that need to be made to the system. We've not had any issues with any of the maintenance activities.
How would you rate customer service and support?
Positive
What other advice do I have?
We are customers of Palo Alto.
I'd rate the solution ten out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Senior Manager Network Design at MEEZA, Managed IT Services Provider
Provides ease of deployment and helps us maintain a secure network environment
Pros and Cons
- "The product's most valuable features are the ease of deployment, regularly updated security information, and robust hardware."
- "Palo Alto's various products need better integration to ensure they work harmoniously."
What is our primary use case?
We use this firewall to segment our network into two parts and control traffic between them, providing a secure and efficient way to manage our network.
What is most valuable?
The product's most valuable features are the ease of deployment, regularly updated security information, and robust hardware.
What needs improvement?
Palo Alto's various products need better integration to ensure they work harmoniously.
For how long have I used the solution?
We have been using Palo Alto Networks NG Firewalls for the past six years.
What do I think about the stability of the solution?
The firewall is very stable; I rate it ten out of ten in terms of stability.
What do I think about the scalability of the solution?
The solution is highly scalable, accommodating around 5,000 users at our site. We plan to increase usage, which is a matter of purchasing new licenses without affecting current operations.
How are customer service and support?
While I have not used technical support service, my team has, and they have found it to be very good.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We switched from AWS to Oracle Advanced Analytics because while AWS was easy to use, it was more expensive.
How was the initial setup?
The setup is easy but requires careful planning and expert design to ensure optimal deployment. The process involves planning, reviewing requirements, designing, implementing, and operating the firewall.
What other advice do I have?
Palo Alto NG Firewall effectively prevents threats and helps maintain a secure network environment.
I rate it a nine out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Stable product with valuable technical support services
Pros and Cons
- "The initial setup process is quite easy."
- "Palo Alto Networks NG Firewalls work slowly for vulnerability management. Its performance could be faster."
What is most valuable?
The product’s most valuable feature is security.
What needs improvement?
Palo Alto Networks NG Firewalls work slowly for vulnerability management. Its performance could be faster.
For how long have I used the solution?
We have been using Palo Alto Networks NG Firewalls for five years.
What do I think about the stability of the solution?
The product is stable. I rate its stability a ten out of ten.
What do I think about the scalability of the solution?
I rate the product’s scalability a nine out of ten.
How are customer service and support?
The technical support services are good. They respond immediately.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We used FortiGate earlier. We plan to switch again to FortiGate as per our vendor’s preference.
How was the initial setup?
The initial setup process is quite easy. It took less than a month to complete.
What's my experience with pricing, setup cost, and licensing?
I rate the product’s pricing an eight out of ten.
Which other solutions did I evaluate?
We evaluated Check Point. We decided to go to Palo Alto for better pricing.
What other advice do I have?
I rate Palo Alto Networks NG Firewalls a nine out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Senior Presales Consultant at a tech services company with 11-50 employees
Features excellent packet inspection in a unified platform
Pros and Cons
- "The best feature is the packet inspection; compared to solutions like Cisco and FortiGate, Palo Alto's packet inspection is much less CPU intensive, allowing it to detect threats embedded within packages more quickly and efficiently."
- "The solution doesn't support routing in virtual firewall creation, and we want that to be enabled."
What is our primary use case?
Our primary use case is to provide our clients with an internet gateway.
What is most valuable?
The best feature is the packet inspection; compared to solutions like Cisco and FortiGate, Palo Alto's packet inspection is much less CPU intensive, allowing it to detect threats embedded within packages more quickly and efficiently.
Palo Alto Networks NGFW provides a unified platform that natively integrates all security capabilities; it's easy to integrate with other platforms, and we never faced any issues doing so.
Using Palo Alto Networks NGFW's unified platform, our clients have eliminated multiple network security tools and the effort needed to get them to work together.
What needs improvement?
The solution doesn't support routing in virtual firewall creation, and we want that to be enabled.
For how long have I used the solution?
We've been involved with Palo Alto Networks since 2008 and are a reseller, so we implement the solutions for our clients.
What do I think about the stability of the solution?
The solution is very stable; we don't have any problems with the stability.
What do I think about the scalability of the solution?
The product is very scalable. Most of our customers are enterprise-sized financial institutions with over 3,000 branches.
How are customer service and support?
Palo Alto Networks doesn't directly support Pakistan but rather through distributors. Out tickets go to the distributors, which are then forwarded to Palo Alto.
How would you rate customer service and support?
Neutral
How was the initial setup?
The initial setup is very straightforward; we can complete it three to four hours after activating the licenses.
What's my experience with pricing, setup cost, and licensing?
The product is expensive. With one being the cheapest and ten being the most expensive, I give it an eight.
What other advice do I have?
I rate the solution nine out of ten.
Palo Alto Networks NGFW is an excellent solution; 90% of the financial institutions in Pakistan use it as their ultimate gateway.
People are just starting to get into machine learning in Pakistan, so we're not 100% sure of its capabilities and potential. I believe machine learning becomes more efficient in a cloud environment than a hybrid one, though I have yet to research this thoroughly.
To a colleague at another company who says they want the cheapest and fastest firewall, Palo Alto Networks provides an expensive solution, but you can't compromise on security. You can buy the most inexpensive firewall, but you'll have to purchase add-ons and subscriptions to enable a complete security infrastructure in your organization. One solution for every situation that doesn't require any additional services is a better choice.
I advise those considering the solution to understand where they want to deploy it in the organization, as a broad installation is best for internet gateways. Next, the sensitivity of the data is important; for a financial institution like a bank, I recommend Palo Alto NGFWs because of the quality of the security and machine learning.
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
System Engineer at DLP
Has good ID management and the configuration is easy
Pros and Cons
- "The user experience is good and the configuration is very easy."
- "Technical support can be faster at responding."
What is our primary use case?
We use Palo Alto Networks NG Firewalls for our gateway security.
How has it helped my organization?
Embedded machine learning is important.
The user experience is good and the configuration is very easy.
Palo Alto Networks NG Firewalls provide a unified platform that natively integrates security capabilities.
What is most valuable?
IDM is the most valuable feature.
What needs improvement?
The process of applying updates to Palo Alto Networks NG Firewalls has room for improvement.
The price also has room for improvement and the technical support could respond faster.
For how long have I used the solution?
I have been using Palo Alto Networks NG Firewalls for one year.
What do I think about the stability of the solution?
The solution is extremely stable.
What do I think about the scalability of the solution?
The solution is scalable. We have 60 people that use the solution in our organization.
How are customer service and support?
The technical support is good but can sometimes be slow.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I previously used WatchGuard XTM firewalls, but I switched to Palo Alto Networks NG Firewalls because of their superior performance and features.
What was our ROI?
We have seen a good return on investment.
What's my experience with pricing, setup cost, and licensing?
Palo Alto Networks NG Firewalls are expensive compared to WatchGuard XTM firewalls.
What other advice do I have?
I give Palo Alto Networks NG Firewalls a ten out of ten.
We have to perform regular updates for the solution.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
Deputy Project Leader for CVE at a tech services company with 1-10 employees
Saves our company time and resources, which equals money saved
Pros and Cons
- "Palo Alto Networks NG Firewalls saves us time."
- "I would like more reporting and metrics in the solution."
What is our primary use case?
We use Palo Alto Networks NG Firewalls mostly for firewalls.
How has it helped my organization?
Palo Alto Networks NG Firewalls saves our company time and resources, which equals money.
What is most valuable?
Palo Alto Networks NG Firewalls saves us time. The solution's firewalls have secured our company, and we don't have to worry about anything.
What needs improvement?
I would like more reporting and metrics in the solution.
For how long have I used the solution?
We have been using Palo Alto Networks NG Firewalls for two years.
What do I think about the stability of the solution?
It is a stable solution.
What do I think about the scalability of the solution?
It is a very scalable solution.
What was our ROI?
We have seen an ROI with Palo Alto Networks NG Firewalls because it saves us time. We haven't worried about any security issues and feel very protected with Palo Alto Networks NG Firewalls.
What's my experience with pricing, setup cost, and licensing?
It is expensive but is worth the price.
Which other solutions did I evaluate?
Before choosing Palo Alto Networks NG Firewalls, we did evaluate other options.
What other advice do I have?
We're fine with the firewall and not shopping around for a firewall.
The fact that it embeds machine learning in the core of the firewall to provide inline, real-time attack prevention is invaluable to me.
Palo Alto NGFW provides a unified platform that natively integrates all security capabilities, which is invaluable to me.
It does a great job of securing data centers consistently across all workplaces, i.e., from the smallest office to the largest data centers, and we have zero complaints.
Palo Alto Networks NG Firewalls have helped us reduce about twenty extra hours a week of downtime in our organization.
I rate the value we receive from attending an RSA Conference a ten out of ten.
Attending RSAC will surely have an impact on our organization's cybersecurity purchases made throughout the year afterward.
Overall, I rate the solution a ten out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free Palo Alto Networks NG Firewalls Report and get advice and tips from experienced pros
sharing their opinions.
Updated: September 2026
Product Categories
FirewallsPopular Comparisons
Fortinet FortiGate
Cisco Secure Firewall
Netgate pfSense
Sophos Firewall
Check Point Cloud Firewall (formerly CloudGuard Network Security)
WatchGuard Firebox
Check Point Harmony SASE (formerly Perimeter 81)
Cisco Meraki MX
Check Point Quantum Force (NGFW)
Azure Firewall
Palo Alto Networks VM-Series
Cisco Secure Access
Fortinet FortiGate-VM
Juniper SRX Series Firewall
Buyer's Guide
Download our free Palo Alto Networks NG Firewalls Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Is Palo Alto the best firewall for an on-premise/cloud hybrid IT network?
- What are the main differences between Palo Alto and Cisco firewalls ?
- Expert Opinion on Palo-Alto Required.
- Which is the best IPS - Cisco Firepower or Palo Alto?
- Features comparison between Palo Alto and Fortinet firewalls
- Is Palo Alto Networks NG Firewalls better than Check Point NGFW?
- What are the main differences between Palo Alto firewalls and Cisco Secure Firepower?
- Which is better - Palo Alto Networks NG Firewalls or Sophos XG?
- What is a better choice, Azure Firewall or Palo Alto Networks NG Firewalls?
- Which Palo Alto Networks NG Firewalls model is recommended for 1200 users?














