Try our new research platform with insights from 80,000+ expert users
IS&S Europe and Global Infrastructure Manager at a manufacturing company with 10,001+ employees
Real User
Jul 21, 2019
Great at threat prevention and has good policy-based routing features
Pros and Cons
  • "The most valuable features are the threat prevention and policy-based routing features."
  • "I think they need to have a proper hardware version for a smaller enterprise. We had to go to a very high-end version which is very expensive. If we chose the lower-end version, it would not meet our goals. A middle-end is missing in its portfolio."

What is our primary use case?

We use this solution as a firewall. We use it for VPN setup, threat protection, and for internet breakout also. We actually deploy several different versions. We have a TA200, a PA820, and a PA3200 series.

What is most valuable?

The most valuable features are the threat prevention and policy-based routing features. 

What needs improvement?

I think they need to have a proper hardware version for a smaller enterprise. We had to go to a very high-end version which is very expensive. If we chose the lower-end version, it would not meet our goals. A middle-end is missing in its portfolio.

For example, there's the PA820 and the PA220, but there's nothing between. So they are really missing some kind of small-size or medium-size usage. Right now, you have to choose either a big one or you have a very small one, which is not really good.

In the next release, it would be helpful if there was some kind of a visualized feature that showed the traffic flow, or something like that, to be able to simulate. When we define something if we could see a simulation of how the flow will be treated that would be great. Because today everything is done by experts by checking logs, but it's very time-consuming. If there's also a simulator to use when you apply some configuration, you can also apply on the simulator, to copy the configuration. So, you can see maybe to generate some traffic and to see how it will be treated. That will be very good.

For how long have I used the solution?

I have been using this solution for five years.
Buyer's Guide
Palo Alto Networks NG Firewalls
December 2025
Learn what your peers think about Palo Alto Networks NG Firewalls. Get advice and tips from experienced pros sharing their opinions. Updated: December 2025.
879,310 professionals have used our research since 2012.

What do I think about the stability of the solution?

The solution is pretty stable. Once you have it configured, normally it shouldn't have any issues. It does sometimes impact the metric flow, but that's natural because it filters everything going through, so it slows down the speed.

What do I think about the scalability of the solution?

I don't think that product is really scalable. You have to either replace it with a higher version or use what you have. I think that's the only way. You cannot add something to increase its capacity, so you have to replace the current equipment to a new version or a new, higher version.

How are customer service and support?

For technical support, we have a contract with some local suppliers. It depends on our partner, so it's probably different from location to location, but as long as they are certified with Palo Alto, normally they should have a one or two experts in their organization. So you just need to find a good person to work with.

Which solution did I use previously and why did I switch?

We did previously have a different kind of a firewall. We used Check Point before. We also used NetScreen and Cisco. But in the end, we defined our standard and now use Palo Alto.

How was the initial setup?

Firewalls are never easy. You have to have very good network expertise to set it up, so it's not about the product being easy to use or not. It's because of the nature of the firewall. You have to understand how it works, how it should be set up, and to understand your data flows and things like that. 

I'm not really the person who does the hands-on setup and integration. I'm the guy who monitors the global deployment. I'm in charge of defining the standard, to deploy the standard to the site, but there's an operational team to do the final installation, configuration, and those types of things.

On the one side, it will take maybe two or three days to enable the firewall, but if you are talking about the global deployment, that depends on the budget, and the resources that will take different time periods to deploy worldwide, so we are still not finished for all the locations. So we are still doing it.

Globally we have around 100 locations. We have two major network engineers who manage the firewall, but to deploy it you also need a local IT because they have to physically be on site. And the two experts remotely control the equipment, configuration, and upgrades, etc. So it's very hard to say how many people you need. It depends on your company size and where your locations are based. For us, we have two dedicated people, but we also have the local IT when we need them to physically help in the integration. 

What about the implementation team?

We do use external partners for the setup. We use also our internal teams as well.

What's my experience with pricing, setup cost, and licensing?

It's a bit pricey.

What other advice do I have?

Once you install it, you use it every day. You can't stop because it's a security feature and a precaution. Also, we are using it to do some local breakouts, so we use utilize the local internet to carry some business traffic, to ensure there's no interruption. You have to let it run 24/7.

I would suggest you be careful when choosing your model. Consider your bandwidth as well as how you want to run the local area network because the throughput of the firewall has to be well designed.

I would rate this solution a nine out of10.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Associate cloud system admin at a financial services firm with 11-50 employees
Real User
Top 20
May 19, 2024
Is used to secure our Internet traffic and the application traffic
Pros and Cons
  • "The payload is a very valuable feature."
  • "The technical support needs improvement."

What is our primary use case?

We use the solution to secure our Internet traffic and the application traffic from the Internet. 

There is also no need to connect to a VPN most of the time.

What is most valuable?

The payload is a very valuable feature. 

What needs improvement?

The technical support needs improvement. 

For how long have I used the solution?

I have been using Palo Alto Networks NG Firewalls for six years. 

What do I think about the stability of the solution?

It is a stable solution. 

How was the initial setup?

The deployment takes five to ten minutes. 

What's my experience with pricing, setup cost, and licensing?

There are security licenses. 

What other advice do I have?

Overall, I rate the solution a nine out of ten. 

Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
Buyer's Guide
Palo Alto Networks NG Firewalls
December 2025
Learn what your peers think about Palo Alto Networks NG Firewalls. Get advice and tips from experienced pros sharing their opinions. Updated: December 2025.
879,310 professionals have used our research since 2012.
reviewer2393664 - PeerSpot reviewer
IT Technical Lead at a tech services company with 1,001-5,000 employees
Real User
Top 20
Apr 29, 2024
Has advanced threat prevention features but central management system is complicated
Pros and Cons
  • "We utilize advanced threat prevention features like web filtering and SSL decryption, which haven't caused any issues."
  • "The tool's central management system is complicated, making it challenging to manage multiple devices centrally. Individually, the firewalls are easy to use and manage. I'd like to see better central management features in the next release. They've introduced some, but I haven't tried them yet, so I can't say how effective they are. However, having a single management interface would be a big improvement."

What is most valuable?

We utilize advanced threat prevention features like web filtering and SSL decryption, which haven't caused any issues.

What needs improvement?

The tool's central management system is complicated, making it challenging to manage multiple devices centrally. Individually, the firewalls are easy to use and manage.

I'd like to see better central management features in the next release. They've introduced some, but I haven't tried them yet, so I can't say how effective they are. However, having a single management interface would be a big improvement.

For how long have I used the solution?

I have been working with the product for six years. 

What do I think about the stability of the solution?

The product is scalable. 

What do I think about the scalability of the solution?

The tool is stable. 

How are customer service and support?

The tool's technical support is good compared to other vendors. 

How would you rate customer service and support?

Positive

How was the initial setup?

Setting up the tool can be challenging, especially if configuring them individually. There's an option for zero-touch configuration, but it still involves managing Palo Alto Networks NG Firewalls, which adds complexity and doesn't always justify the cost. If you're experienced with the technology and starting from scratch, expect a steep learning curve.

What's my experience with pricing, setup cost, and licensing?

The tool is expensive, especially considering all the necessary licenses for centrally managing firewalls. For medium-sized companies like ours, it's often not feasible within our budget constraints.

We pay around €200k yearly for all our firewalls. Additionally, we received a quote of over 1 million per year for Prisma Access. There is a significant cost difference compared to other options, where it's around €200k per year.

We have to pay a license for support. 

What other advice do I have?

We started with on-premise infrastructure, including domain controllers. Still, as we moved to the cloud, there was a gap in group membership management until Palo Alto came up with a solution. We have multiple firewalls, about 50 of which are difficult to manage. However, the features offered by the firewalls themselves are really good.

In the future, we might consider switching from Palo Alto Networks NG Firewalls. We're currently evaluating a new solution. However, cost is a concern, as it seems more expensive than other products and SaaS solutions.

Integration with Palo Alto Networks NG Firewalls and other security tools or IT infrastructure is not entirely straightforward but manageable. It's easier compared to some other vendors but still requires effort. I have tried to integrate it with Cisco ISE. 

I recommend Palo Alto NG Firewalls for large enterprises. However, due to their high price, I wouldn't recommend them for small—to medium-sized companies, especially those with limited IT budgets.

We've found that Palo Alto NG Firewalls are particularly good at stopping zero-day attacks. Compared to other companies like Fortinet, we've had fewer security breaches with it.

I rate the overall solution a seven out of ten. 

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer2173293 - PeerSpot reviewer
Analyst at a non-tech company
Real User
May 2, 2023
Provide an additional level of network security and vigilance
Pros and Cons
  • "I like the firewall's vulnerability management features, which give you reminders to update your system and update your OS."
  • "The built-in machine learning features provide some automation, but I think there should be an option for manual review because nothing replaces the human eye."

What is our primary use case?

An NG firewall provides an additional level of network security and vigilance. It also helps us manage activities using privileges and a zero-trust approach. 

What is most valuable?

I like the firewall's vulnerability management features, which give you reminders to update your system and update your OS. Palo Alto Networks NG Firewalls provide a unified platform that integrates all security capabilities. It provides pretty good consistency across locations. 

What needs improvement?

The built-in machine learning features provide some automation, but I think there should be an option for manual review because nothing replaces the human eye. 

For how long have I used the solution?

We have used NG Firewalls for a little more than a year and a half. 

What do I think about the stability of the solution?

Palo Alto Networks NG Firewalls are pretty stable. 

What do I think about the scalability of the solution?

Palo Alto Networks NG Firewalls scale up enough for my workplace. Beyond that, I could not say. 

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer2063289 - PeerSpot reviewer
Senior information technology consultant at a tech services company with 11-50 employees
Consultant
Jan 17, 2023
An extremely strong security tool, with machine learning capabilities for advanced threat detection
Pros and Cons
  • "We have found the SSL decryption within this solution to be great; you can enable this feature and have the ability to see more of what is happening across your network."
  • "We would like to see improvement in the web interface for this solution, so that it can handle updates without manual intervention to put the data in order."

What is our primary use case?

Our main use of this solution is to create micro segmentations only in the public cloud, and use the data we receive to see threats passing through the Vnets.

How has it helped my organization?

We have found that this solution has improved not only the level of security that is in place, but also reduced the amount of operational time needed for us to handle cloud-based security.

What is most valuable?

We have found the SSL decryption within this solution to be great; you can enable this feature and have the ability to see more of what is happening across your network.

We also really like the Wi-Fi service feature of this solution.  It has a great base of information, and uses machine learning to improve recognition of issues and threats.

What needs improvement?

We would like to see improvement in the web interface for this solution, so that it can handle updates without manual intervention to put the data in order.

For how long have I used the solution?

We have been working with this solution for two years.

What do I think about the stability of the solution?

We have found this to be a stable solution during our time working with it.

What do I think about the scalability of the solution?

As it is cloud-based, the solution is easily scalable.

How are customer service and support?

We have found the technical support for this solution to be very good; we just open a support chat window and we have assistance when we need it.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

We previously used Fortinet, and changed to this solution because of the superior performance.

How was the initial setup?

The initial setup of this solution was very easy, and the deployment took just under two weeks to complete.

What about the implementation team?

We used a consultancy team from Add Valley Services for our implementation of this solution, and their service was great.

What's my experience with pricing, setup cost, and licensing?

We would advise that this solution has a higher price point than other comparable products, however, the license fee covers all the features that the solution can provide and there are not extra costs involved.

What other advice do I have?

We would recommend that organizations implementing this solution use a good consulting service and plan extensively up front, before implementation, in order to ensure a smooth deployment with no issues.

We would rate this solution as 10 out of 10.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Chong Kah Wooi - PeerSpot reviewer
Technical Manager at a tech services company with 11-50 employees
Reseller
Jun 3, 2022
Secure solution that makes it easy to understand your network visibility, control the network, and prevent attacks
Pros and Cons
  • "The solution is user-friendly. It's secure and easy to understand your network visibility, control the network, and prevent attacks."
  • "The pricing could be improved. They need to work on the setup over the firewall, VLAN, and PPPoE."

What is our primary use case?

I am a reseller of Palo Alto Networks.

What is most valuable?

The solution is user-friendly. It's secure and easy to understand your network visibility, control the network, and prevent attacks.

What needs improvement?

The pricing could be improved. They need to work on the setup over the firewall, VLAN, and PPPoE.

What do I think about the stability of the solution?

It's stable.

What do I think about the scalability of the solution?

It's scalable.

How are customer service and support?

I seldom call technical support because it's easy to understand and configure the solution.

What's my experience with pricing, setup cost, and licensing?

It could be less expensive.

What other advice do I have?

I would rate this solution 9 out of 10.

If you want to have a secure network, use Palo Alto. 

Disclosure: My company has a business relationship with this vendor other than being a customer.
PeerSpot user
PeerSpot user
Security Consultant at a tech services company with 501-1,000 employees
Reseller
Jan 30, 2022
Good application detection, strong antivirus capabilities and built-in machine learning
Pros and Cons
  • "From my experience, comparing it to other products, the granularity you can have in the application is very good. The application detection is excellent. It's certainly one of the best."
  • "The solution would benefit from having a dashboard."

What is our primary use case?

We primarily use the solution as a datacenter firewall for 0 trust security model

What is most valuable?

From my experience, comparing it to other products, the granularity you can have in the application is very good. The application detection is excellent. It's certainly one of the best. 

The engine detector application is usually one of the best compared to any other firewall on the market, in my opinion.  With it, I can do a lot of rules based on the application. If you have multiple internet links, you can have an application export from one link, and an application wire from another link. You can have security on the application. The security, for example, can have different functionalities. Basically, the granularity of rules is amazing in Palo Alto.

They have a good reputation for their antivirus capabilities.

The solution offers a strong URL based system or detection for malicious URL or malicious files. 

They even have a machine learning algorithm. They do a lot of very advanced detection for files and URLs. 

Once you deploy the product, you can basically forget about it. It has high customer satisfaction because it's always just working.

What needs improvement?

The solution would benefit from having a dashboard.

From a normal IPS after attack, routine attack and threat detection attack, in other words, the standard IPS detection attack, I don't see Palo Alto as very good compared to others. The standard network IPS functionality could be better. It's there in solutions like McAfee or Tipping Point, however, I don't see it here in this solution.

For how long have I used the solution?

We've been working with Palo Alto for about six years now.

What do I think about the stability of the solution?

From my experience, it's the best hardware compared to other NG firewalls from the perspective of performance stability. While the other firewalls lose 50 or 60% of performance when enabling all policies, Palo Alto loses 10 to 20% maximum, even with enabled IPS and fire detection and all. From our experience performance-wise, it's one of the best hardware solutions for firewalls. 

We haven't lost performance really, so I would describe it as very stable. There are not any issues.

What do I think about the scalability of the solution?

Since the solution is hardware, there are some limitations in terms of scalability.

Usually, in hardware, you can't say it's scalable or not due to the fact that you have the limitations built-in related to the size of the box. The box has a maximum number that it can reach. You can add more hardware, however, the hardware itself is finite.

We usually do a POC first so we can get the figures for performance and we can put in a box that can support 20 or 30 people extra for future expansion.

How are customer service and support?

In general technical support is very good. That said, usually, when we face an issue, we try to solve it ourselves internally before going to level one support. 

In general, we never have had a big issue with support. I don't have much experience with the support team to tell you if they're really good or not. Usually 80% of the cases we open, we talk with the distributor and finish the operation case directly with Palo Alto. It's more like a backend request and therefore I don't have much input that would be objective.

Which solution did I use previously and why did I switch?

As resellers, we also work with Cisco and some Forcepoint solutions.

I like that in Cisco there's more security parts, like IPS, and a Demandware engine.

I like Cisco, in general, more than Palo Alto if I'm comparing the two. However, from an application perspective, our application's usability and detection and firewall control using an application, it's Palo Alto that's the best on the market. That's, of course, purely from a  firewall point of view. Even in terms of detection of the applications, it has the best system.

How was the initial setup?

The deployment depends on the client's environment as well as how they are using it. For example, an internet NG firewall on the internet, it takes, on average, a week between installation, integration, and tuning. Usually we don't do all the policies because we are system integrator. We do the main policies and we teach the customer and then do a handover to the user for tuning and all the installation extras.

If it's a data center project, it takes more time and effort. It takes a month sometimes due to the fact that we'll be dealing with a lot of traffic. The application and server are usually harder to control than internet applications like Facebook and other standard applications, and easier on the internet. Then there's also internal applications, custom applications, migrating applications, finance education applications, etc., which are not always direct from the customer or directly known.

In short, the implementation isn't always straightforward. There can be quite a bit of complexity, depending on the company.

What other advice do I have?

In general, I prefer hardware, and Palo Alto's is quite good. However, we have a couple of virtual deployments for cases as well.

I would definitely recommend the solution. It's one of the best firewalls on the market. I've worked with four different vendors in the past, and some of the most mature NG firewalls are Palo Alto's. It's their main business, so they are able to really focus on the tech. They spend a lot of time on R&D. They're always leading the way with new technologies. 

While Cisco has more main products, Palo Alto really does focus in on NG firewalls. That's why I always see them as a leader in the space.

I'd rate the solution nine out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
PeerSpot user
it_user1599615 - PeerSpot reviewer
Network Security Engineer
Real User
Jun 13, 2021
Useful web filtering, responsive technical support, but VPN needs improvement
Pros and Cons
  • "The best features of this solution are URL filtering and traffic visibility."
  • "The areas that need to improve are network protection and user identification."

What is our primary use case?

I am using the solution for protecting the network organization from threats.

What is most valuable?

The best features of this solution are URL filtering and traffic visibility.

What needs improvement?

The areas that need to improve are network protection and user identification.

In the next release of the solution the VPN could improve because it is not as good as competitors.

For how long have I used the solution?

I have been using this solution within the past 12 months.

What do I think about the stability of the solution?

This solution is stable and reliable.

What do I think about the scalability of the solution?

We have 10 employees using this solution in my organization. We are in the beginning phases of testing and will increase usage if the test phase results are favorable.

How are customer service and technical support?

The technical support is responsive.

How was the initial setup?

The initial setup was easy.

What's my experience with pricing, setup cost, and licensing?

We are on an annual license for this solution. I am happy with the price and when comparing it to other solutions it is priced competitively.

Which other solutions did I evaluate?

I have evaluated Sophos firewalls and I found Palo Alto solutions better because of the protection and web filters.

What other advice do I have?

I would recommend this solution to others.

I rate Palo Alto Networks NG Firewalls a seven out of ten.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
Buyer's Guide
Download our free Palo Alto Networks NG Firewalls Report and get advice and tips from experienced pros sharing their opinions.
Updated: December 2025
Product Categories
Firewalls
Buyer's Guide
Download our free Palo Alto Networks NG Firewalls Report and get advice and tips from experienced pros sharing their opinions.