Try our new research platform with insights from 80,000+ expert users
Technical Manager at PSR
Real User
Top 5
Machine learning and sandboxing are what differentiate this product from competitors
Pros and Cons
  • "The sandboxing is valuable and they are frequently updating their signature database. We get new updates every five minutes. That makes it easy to detect new and unknown attacks."
  • "The configuration part could be improved. It's very difficult to configure. It doesn't have a user-friendly interface. You have to know Palo Alto deeply to use it."

What is our primary use case?

It is used for protection against attacks and it is very fast and reliable. We have a lot of use cases for it.

How has it helped my organization?

We are an implementation partner for Palo Alto. One of the companies we implemented its Next-Generation Firewalls for was previously using Barracuda. A ransomware attack happened and they lost all their backup data, and their configuration. Once we implemented Palo Alto for them, there were similar attacks but they were blocked.

Along with Prisma, it helps in preventing a lot of attacks, especially Zero-day attacks.

What is most valuable?

The sandboxing is valuable and they are frequently updating their signature database. We get new updates every five minutes. That makes it easy to detect new and unknown attacks.

What needs improvement?

The configuration part could be improved. It's very difficult to configure. It doesn't have a user-friendly interface. You have to know Palo Alto deeply to use it.

Also, it doesn't support open-source protocols like EIGRP. We had to find another solution for that.

Buyer's Guide
Palo Alto Networks NG Firewalls
August 2025
Learn what your peers think about Palo Alto Networks NG Firewalls. Get advice and tips from experienced pros sharing their opinions. Updated: August 2025.
865,295 professionals have used our research since 2012.

For how long have I used the solution?

I've been using Palo Alto Networks NG Firewalls for the last six years.

What do I think about the stability of the solution?

Palo Alto suggests version 9.1.7 for stability. When new features come out, things are not as stable.

What do I think about the scalability of the solution?

It's scalable. I recommend it for its scalability.

We generally deploy these firewalls into larger environments, but the PA-400 series is affordable.

How are customer service and support?

There are problems with the technical support. When we are facing an attack, it's very difficult to get a hold of people from the TAC. It's not like Cisco, especially in India. There are very few members of Palo Alto TAC in India. Sometimes we get support from people in other countries.

How would you rate customer service and support?

Neutral

How was the initial setup?

The initial deployment of these firewalls is very complex. The registration is a very difficult task. You have to go to the partner portal to register and it's not user-friendly. All the other solutions are not like that. With Juniper, for example, it's very easy to handle their portal.

The deployment time depends on the customer environment but it normally takes around three weeks. Our implementation strategy is to first understand the network we are dealing with and how we can deploy Palo Alto.

What's my experience with pricing, setup cost, and licensing?

The pricing for Palo Alto is very high. The price difference with other vendors is huge because Palo Alto has been the market leader for the last five or six years, and they have a reliable product. Everybody knows Palo Alto, like Cisco routing and switching. It's likely that only enterprise-level customers can afford this kind of firewall.

Which other solutions did I evaluate?

Palos Alto's firewalls have machine learning software and sandboxing. Everything is one step ahead of all the competitors.

Still, almost all vendors provide the same things. They call their technologies by different names, but that's the only big difference in features.

What other advice do I have?

According to the industry reviews Palo Alto has been the market leader for the last five or six years. They have better technology and the hardware is also good. It's the pricing and user interface where there are issues. Apart from them, everything is fine.

Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
Amar-Patil - PeerSpot reviewer
Security Engineer at a tech services company with 1,001-5,000 employees
Real User
Top 5
Enables us to monitor VPN compliance and integrate with multiple vendors
Pros and Cons
  • "With App-ID, we can identify exact traffic. Even if someone tries to fool the firewall with a different port number, or with the correct port number, Palo Alto is able to identify what kind of traffic it is."
  • "The solution has normal authentication, but does not have two-factor or multi-factor authentication. There is room for development there."

What is our primary use case?

These firewalls are only used for perimeter purposes, in gateway mode.

How has it helped my organization?

In addition to our environment being secure, we can monitor compliance of VPN users. Security and monitoring are the two big benefits.

It's also very critical for us that it provides a unified platform that natively integrates all security capabilities. We have multiple vendors and multiple solutions. Palo Alto has to work with them. For example, when it comes to authentication, we can integrate LDAP and RADIUS, among others. And in one of our customer's environments, we have integrated a new, passwordless authentication.

What is most valuable?

Apart from the security, Palo Alto NG Firewalls have nice features like App-ID and User-ID. These are the two most useful features.

With App-ID, we can identify exact traffic. Even if someone tries to fool the firewall with a different port number, or with the correct port number, Palo Alto is able to identify what kind of traffic it is.

With User-ID, we can configure single sign-on, which makes things easy for users. There is no need for additional authentication for a user. And for documentation and reporting purposes, we can fetch user-based details, based on User-ID, and can generate new reports.

Another good feature is the DNS Security. With the help of DNS security, we can block the initial level of an attack, and we can block malicious things from a DNS perspective.

The GlobalProtect VPN is also very useful.

What needs improvement?

The solution has normal authentication, but does not have two-factor or multi-factor authentication. There is room for development there.

For how long have I used the solution?

We have been using Palo Alto Networks NG Firewalls for two years. I've worked on the 800 Series and the 3000 Series.

What do I think about the stability of the solution?

It's quite stable. They are launching a new firmware version, but compared to other products, Palo Alto is quite stable.

How are customer service and support?

I have worked with Palo Alto's support many times and it is quite good. Whenever we create a support ticket, they are on time and they update us in a timely manner. In terms of technical expertise, they have good people who are experts in it. They are very supportive of customers.

How would you rate customer service and support?

Positive

How was the initial setup?

The initial deployment is straightforward; very simple. The primary access for these firewalls is quite simple. We can directly access them, after a few basic steps, and start the configuration. Even the hardware registration process and licensing are quite simple.

The time it takes to deploy a firewall depends upon hardware and upon the customer's environment. But a basic to intermediate deployment takes two to three months.

What was our ROI?

Our customers definitely see ROI with Palo Alto NG Firewalls, although I don't have metrics.

What's my experience with pricing, setup cost, and licensing?

I am not involved in the commercial side, but I believe that Palo Alto is quite expensive compared to others.

Which other solutions did I evaluate?

One of the pros of Palo Alto is the GlobalProtect, which is a VPN solution. GlobalProtect has broader compliance checks. I have worked on Check Point and FortiGate, but they don't have this kind of feature in their firewalls. Also, Check Point does not have DNS Security, which Palo Alto has.

What other advice do I have?

If you're going with Palo Alto, you have to use all its features, including the DNS Security, App-ID, and SSL decryption. Otherwise, there is no point in buying Palo Alto.

Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
Buyer's Guide
Palo Alto Networks NG Firewalls
August 2025
Learn what your peers think about Palo Alto Networks NG Firewalls. Get advice and tips from experienced pros sharing their opinions. Updated: August 2025.
865,295 professionals have used our research since 2012.
LuisSilva6 - PeerSpot reviewer
Director of Information Technology at a hospitality company with 10,001+ employees
Real User
Top 5
A stable next-generation firewall solution
Pros and Cons
  • "I like that they are more stable than the previous ones, and they allow a lot of other features."
  • "It would be better to have more tools to control Palo Alto Networks NG Firewalls. We don't have too many tools to access Palo Alto. For example, the IT team doesn't have access to it. We can see it physically and see if it's running or not. We need to contact a special team to receive that information. I would also like to see more reporting in the next release."

What is our primary use case?

We use Palo Alto Networks NG Firewalls to manage the villains. Basically, to protect the environment. 

What is most valuable?

I like that they are more stable than the previous ones, and they allow a lot of other features.

What needs improvement?

It would be better to have more tools to control Palo Alto Networks NG Firewalls. We don't have too many tools to access Palo Alto. For example, the IT team doesn't have access to it. We can see it physically and see if it's running or not. We need to contact a special team to receive that information. I would also like to see more reporting in the next release.

For how long have I used the solution?

I have been using Palo Alto Networks NG Firewalls for two years.

What do I think about the stability of the solution?

Palo Alto Networks NG Firewalls is stable.

What do I think about the scalability of the solution?

Palo Alto Networks NG Firewalls is scalable. We have about 250 people using it at our hotel.

How are customer service and technical support?

We use Trustwave, a company that provides the devices. We have an agreement with them, and we're satisfied with the support.

Which solution did I use previously and why did I switch?

We used to use Juniper and Fortinet.

How was the initial setup?

The initial setup is pretty much straightforward. It takes us about two hours to set up and deploy this solution. It takes a team of two guys to deploy and maintain this solution.

What other advice do I have?

I would recommend this solution to new users.

On a scale from one to ten, I would give Palo Alto Networks NG Firewalls a nine.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer1350975 - PeerSpot reviewer
Head of IT Infrastructure at a financial services firm with 1,001-5,000 employees
Real User
Provides a reliable central firewall
Pros and Cons
  • "Identifying applications is very easy with this solution."
  • "The reports it provides are not helpful."

What is our primary use case?

We use this solution as our central firewall, but not as a perimeter firewall. For our perimeter, we use another solution. 

Our organization consists of roughly 2,000 to 3,000 employees. 

What is most valuable?

Identifying applications is very easy with this solution.

What needs improvement?

I don't like the reporting. The reports it provides are not helpful. They should include more executive summaries and other important information — they're too technical.

For how long have I used the solution?

I have been using this solution for three years. 

What do I think about the stability of the solution?

The stability is excellent. 

How are customer service and technical support?

The technical support is good, but not excellent. Their responses can be quite vague and unhelpful at times. 

Which solution did I use previously and why did I switch?

We used to use Checkpoint. We stopped using it because the price was too high. 

How was the initial setup?

Considering our limited amount of experience, the initial setup was easy. Deployment took one month. 

What about the implementation team?

A local reseller team of roughly three to five people implemented it for us — it was a great experience. 

Which other solutions did I evaluate?

We evaluated Palo Alto, Checkpoint, Fortinet, and Cisco Firepower. Overall, it came down to the price — that's why we went with Palo Alto Networks NG Firewalls.

What other advice do I have?

This solution is very particular; it's only suited to specific companies — it's a commercial opportunity. 

Overall, on a scale from one to ten, I would give this solution a rating of eight. 

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer1529103 - PeerSpot reviewer
Director IT Security at a healthcare company with 501-1,000 employees
Real User
Good threat hunt capabilities, good support, and easy to deploy
Pros and Cons
  • "Mechanically, all firewalls work in a similar fashion, but what makes Palo Alto different is that it also has some of the threat hunt capabilities. It is a little bit better than other vendors."
  • "As things are evolving, we want to make sure that Palo Alto is able to keep up with what is going on outside. They should continue to do more intelligence-related enhancements and integrate with some of the other security tools. We want to have a more intelligent toolset down the road."

What is our primary use case?

Basically, it is for protection and security. We are using it to make sure that our network is as secure as possible. We are able to evaluate each stack in each pocket and take certain actions as needed when we look into some of the content of the payload. 

We have on-prem deployments, and we also have SaaS-based services.

What is most valuable?

Mechanically, all firewalls work in a similar fashion, but what makes Palo Alto different is that it also has some of the threat hunt capabilities. It is a little bit better than other vendors.

What needs improvement?

As things are evolving, we want to make sure that Palo Alto is able to keep up with what is going on outside. They should continue to do more intelligence-related enhancements and integrate with some of the other security tools. We want to have a more intelligent toolset down the road.

For how long have I used the solution?

We implemented this solution last year.

What do I think about the scalability of the solution?

We currently have 25,000 users. Its usage won't increase a lot, but IT is changing very rapidly, and it would depend on the security model towards which we are moving. 

How are customer service and technical support?

Palo Alto provides pretty good support.

How was the initial setup?

It is straightforward. The deployment duration varies because there are different modules and components, but it doesn't mean that we have to complete everything to make it work. For the core piece of it, it would probably take a couple of months to install, configure, and test.

What about the implementation team?

We have a vendor to help us. We have two or three people for its deployment.

What's my experience with pricing, setup cost, and licensing?

It has a yearly subscription.

What other advice do I have?

I would recommend this solution. I would rate Palo Alto Networks NG Firewalls an eight out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Quality engineer of the 1st category at Modern Expo
Real User
Great protection without requiring a special dedicated network team; saves us a lot of time
Pros and Cons
  • "Protection from a single packet and ease of making security rules."
  • "It's not so easy to scale out your security capabilities."

What is our primary use case?

We have two 3000 Series Firewalls placed in our primary location. We have two sites and the secondary site uses the primary site for internet access. All traffic to the secondary location goes through a VPN tunnel. I'm a network administrator. 

What is most valuable?

The value of this solution for me is the protection from a single packet and ease of making security rules. It also doesn't require a special dedicated network team, I'm able to do it myself. It's a time saver for me and now in this pandemic period, users have access from home.  

What needs improvement?

I'd like to see some changes to the licensing policies and, on the technical side, improvement in scalability. It's not so easy to scale out your security capabilities. With the situation in business today, everybody lacks money and if you have to increase your resources and to constantly pay more for that, it becomes a problem. 

For how long have I used the solution?

I've been using this solution for 10 years. 

What do I think about the stability of the solution?

It's been 10 years and I don't remember any outages because of a hardware failure or a logical error in configuration. We had problems with servers or switches initially but it works like a charm now. 

What do I think about the scalability of the solution?

Scalability is the main disadvantage of Palo Alto. They call themselves a firewall with router capabilities but it's not a router and it requires a good bandwidth in VPN which could become a problem because you have to scale to really big hardware. We can solve the issue with other solutions, but for me the idea is to have less devices in your environment.
It's all about the hardware.  

How are customer service and technical support?

The support is quite good. A couple of months ago, I sent an email with an issue and we got an answer in 15-20 minutes. In my experience, Palo Alto support is one of the best, maybe the best support available.

Which solution did I use previously and why did I switch?

We previously used Juniper which is currently called Net Screen. I also looked at Sonic Wall. We carried out a proof of concept five years ago and they had to decide whether to go with Palo Alto or another vendor. 

How was the initial setup?

For me, the initial setup is very easy. To get the device running with some capabilities but maybe not all security rules takes about an hour and it's the same for any upgrades. We have around 900 users and one admin person from our organization who deals with any issues. 

What's my experience with pricing, setup cost, and licensing?

Palo Alto is an expensive solution, we currently have a three year contract. I'm not sure what our terms are. People always want cheaper, nobody wants to pay more. In our region, I think if Palo Alto was cheaper, more companies would buy the solution. 

What other advice do I have?

I would absolutely recommend this product, it's expensive but I trust it. There is always room for improvement such as with scalability capabilities in Palo Alto. I know I'm not the only one who thinks this is an issue. It's possible that next time we will try virtualized firewalls, it may be a little cheaper for us. We would consider switching to something else but it would be a big move and quite complicated. Moving to a different vendor is a whole other story.

I rate this solution a nine out of 10. 

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer1523322 - PeerSpot reviewer
Senior Staff Security Engineer at a renewables & environment company with 1,001-5,000 employees
Real User
Stable and scalable, works well, and makes our environment more secure
Pros and Cons
  • "The App-ID feature is the coolest feature because you don't need to open a new port. Apps are directly linked to the port. It provides one of the best ways to lock down the additional port switch."
  • "Its software updates can be improved. It sometimes becomes very slow with the software updates for different features. It should have an External Dynamic List of data. The malicious IP is not frequently getting updated in Palo Alto, and this should be done."

What is our primary use case?

We are working on creating security policies on the firewall. We have just put GlobalProtect VPN in our company. We also have Prisma Access.

We have on-prem and hybrid cloud deployments.

How has it helped my organization?

It has strengthened our security policies and made our environment more secure. It has provided us more security features. Due to the rules that we have created on Palo Alto Firewall, all the malicious things have been stopped from coming into our environment.

What is most valuable?

The App-ID feature is the coolest feature because you don't need to open a new port. Apps are directly linked to the port. It provides one of the best ways to lock down the additional port switch.

What needs improvement?

Its software updates can be improved. It sometimes becomes very slow with the software updates for different features.

It should have an External Dynamic List of data. The malicious IP is not frequently getting updated in Palo Alto, and this should be done.

For how long have I used the solution?

I have been using this solution for six years.

What do I think about the stability of the solution?

Its stability is good.

What do I think about the scalability of the solution?

Its scalability is also good.

Which solution did I use previously and why did I switch?

We were using Cisco ASA previously. Palo Alto has strengthened our security policies. It has also made our environment more secure than Cisco ASA.

How was the initial setup?

Its initial setup is straightforward.

What other advice do I have?

I would rate Palo Alto Networks NG Firewall an eight out of ten. It has been working very well.

Which deployment model are you using for this solution?

Hybrid Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Amazon Web Services (AWS)
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer1517283 - PeerSpot reviewer
Network Security Head at a government with 51-200 employees
Real User
An innovative platform that secures our network
Pros and Cons
  • "It's quite nice. It's very user-friendly, powerful, and there are barely any bugs."
  • "The scalability of the firewalls could be improved."

What is our primary use case?

We plan to continue using this solution. Within our organization, there are roughly 1,000 employees using this solution.

What is most valuable?

We chose Palo Alto for its security features. It's quite nice. It's very user-friendly, powerful, and there are barely any bugs. 

For how long have I used the solution?

We have been using this solution for roughly two years.

What do I think about the stability of the solution?

This solution is very stable.

What do I think about the scalability of the solution?

The scalability of the firewalls could be improved. You can't scale the physical firewalls because Palo Alto doesn't support clustering. 

How are customer service and technical support?

The support could be improved. They could be faster.

They have a multi-layer model of support. If we're experiencing any issues, we have to go to our local partner. If our local partner can't help, then we have to go through a distribution layer that's certified from Palo Alto. If our issues can't be fixed, they will escalate them to the vendor. This can be quite annoying, to be honest.

With Cisco, for example, you can open a ticket directly with the vendors themselves, and they can escalate it internally, which is much faster.

Which solution did I use previously and why did I switch?

We used to use Juniper Firewalls.

How was the initial setup?

The initial setup is quite straightforward. 

What about the implementation team?

We deployed this solution with some help from our local partners. Overall, deployment took a couple of days. A team of three deployed this solution.

What's my experience with pricing, setup cost, and licensing?

This solution is quite expensive.

What other advice do I have?

I would absolutely recommend this solution to others. Overall, on a scale from one to ten, I would give this solution a rating of nine.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Download our free Palo Alto Networks NG Firewalls Report and get advice and tips from experienced pros sharing their opinions.
Updated: August 2025
Product Categories
Firewalls
Buyer's Guide
Download our free Palo Alto Networks NG Firewalls Report and get advice and tips from experienced pros sharing their opinions.