We utilize advanced threat prevention features like web filtering and SSL decryption, which haven't caused any issues.
IT Technical Lead at a tech services company with 1,001-5,000 employees
Has advanced threat prevention features but central management system is complicated
Pros and Cons
- "We utilize advanced threat prevention features like web filtering and SSL decryption, which haven't caused any issues."
- "The tool's central management system is complicated, making it challenging to manage multiple devices centrally. Individually, the firewalls are easy to use and manage. I'd like to see better central management features in the next release. They've introduced some, but I haven't tried them yet, so I can't say how effective they are. However, having a single management interface would be a big improvement."
What is most valuable?
What needs improvement?
The tool's central management system is complicated, making it challenging to manage multiple devices centrally. Individually, the firewalls are easy to use and manage.
I'd like to see better central management features in the next release. They've introduced some, but I haven't tried them yet, so I can't say how effective they are. However, having a single management interface would be a big improvement.
For how long have I used the solution?
I have been working with the product for six years.
What do I think about the stability of the solution?
The product is scalable.
Buyer's Guide
Palo Alto Networks NG Firewalls
May 2025

Learn what your peers think about Palo Alto Networks NG Firewalls. Get advice and tips from experienced pros sharing their opinions. Updated: May 2025.
857,028 professionals have used our research since 2012.
What do I think about the scalability of the solution?
The tool is stable.
How are customer service and support?
The tool's technical support is good compared to other vendors.
How would you rate customer service and support?
Positive
How was the initial setup?
Setting up the tool can be challenging, especially if configuring them individually. There's an option for zero-touch configuration, but it still involves managing Palo Alto Networks NG Firewalls, which adds complexity and doesn't always justify the cost. If you're experienced with the technology and starting from scratch, expect a steep learning curve.
What's my experience with pricing, setup cost, and licensing?
The tool is expensive, especially considering all the necessary licenses for centrally managing firewalls. For medium-sized companies like ours, it's often not feasible within our budget constraints.
We pay around €200k yearly for all our firewalls. Additionally, we received a quote of over 1 million per year for Prisma Access. There is a significant cost difference compared to other options, where it's around €200k per year.
We have to pay a license for support.
What other advice do I have?
We started with on-premise infrastructure, including domain controllers. Still, as we moved to the cloud, there was a gap in group membership management until Palo Alto came up with a solution. We have multiple firewalls, about 50 of which are difficult to manage. However, the features offered by the firewalls themselves are really good.
In the future, we might consider switching from Palo Alto Networks NG Firewalls. We're currently evaluating a new solution. However, cost is a concern, as it seems more expensive than other products and SaaS solutions.
Integration with Palo Alto Networks NG Firewalls and other security tools or IT infrastructure is not entirely straightforward but manageable. It's easier compared to some other vendors but still requires effort. I have tried to integrate it with Cisco ISE.
I recommend Palo Alto NG Firewalls for large enterprises. However, due to their high price, I wouldn't recommend them for small—to medium-sized companies, especially those with limited IT budgets.
We've found that Palo Alto NG Firewalls are particularly good at stopping zero-day attacks. Compared to other companies like Fortinet, we've had fewer security breaches with it.
I rate the overall solution a seven out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.

Analyst at a non-tech company
Provide an additional level of network security and vigilance
Pros and Cons
- "I like the firewall's vulnerability management features, which give you reminders to update your system and update your OS."
- "The built-in machine learning features provide some automation, but I think there should be an option for manual review because nothing replaces the human eye."
What is our primary use case?
An NG firewall provides an additional level of network security and vigilance. It also helps us manage activities using privileges and a zero-trust approach.
What is most valuable?
I like the firewall's vulnerability management features, which give you reminders to update your system and update your OS. Palo Alto Networks NG Firewalls provide a unified platform that integrates all security capabilities. It provides pretty good consistency across locations.
What needs improvement?
The built-in machine learning features provide some automation, but I think there should be an option for manual review because nothing replaces the human eye.
For how long have I used the solution?
We have used NG Firewalls for a little more than a year and a half.
What do I think about the stability of the solution?
Palo Alto Networks NG Firewalls are pretty stable.
What do I think about the scalability of the solution?
Palo Alto Networks NG Firewalls scale up enough for my workplace. Beyond that, I could not say.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Palo Alto Networks NG Firewalls
May 2025

Learn what your peers think about Palo Alto Networks NG Firewalls. Get advice and tips from experienced pros sharing their opinions. Updated: May 2025.
857,028 professionals have used our research since 2012.
Senior information technology consultant at a tech services company with 11-50 employees
An extremely strong security tool, with machine learning capabilities for advanced threat detection
Pros and Cons
- "We have found the SSL decryption within this solution to be great; you can enable this feature and have the ability to see more of what is happening across your network."
- "We would like to see improvement in the web interface for this solution, so that it can handle updates without manual intervention to put the data in order."
What is our primary use case?
Our main use of this solution is to create micro segmentations only in the public cloud, and use the data we receive to see threats passing through the Vnets.
How has it helped my organization?
We have found that this solution has improved not only the level of security that is in place, but also reduced the amount of operational time needed for us to handle cloud-based security.
What is most valuable?
We have found the SSL decryption within this solution to be great; you can enable this feature and have the ability to see more of what is happening across your network.
We also really like the Wi-Fi service feature of this solution. It has a great base of information, and uses machine learning to improve recognition of issues and threats.
What needs improvement?
We would like to see improvement in the web interface for this solution, so that it can handle updates without manual intervention to put the data in order.
For how long have I used the solution?
We have been working with this solution for two years.
What do I think about the stability of the solution?
We have found this to be a stable solution during our time working with it.
What do I think about the scalability of the solution?
As it is cloud-based, the solution is easily scalable.
How are customer service and support?
We have found the technical support for this solution to be very good; we just open a support chat window and we have assistance when we need it.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We previously used Fortinet, and changed to this solution because of the superior performance.
How was the initial setup?
The initial setup of this solution was very easy, and the deployment took just under two weeks to complete.
What about the implementation team?
We used a consultancy team from Add Valley Services for our implementation of this solution, and their service was great.
What's my experience with pricing, setup cost, and licensing?
We would advise that this solution has a higher price point than other comparable products, however, the license fee covers all the features that the solution can provide and there are not extra costs involved.
What other advice do I have?
We would recommend that organizations implementing this solution use a good consulting service and plan extensively up front, before implementation, in order to ensure a smooth deployment with no issues.
We would rate this solution as 10 out of 10.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Technical Manager at Ipenet Solutions
Secure solution that makes it easy to understand your network visibility, control the network, and prevent attacks
Pros and Cons
- "The solution is user-friendly. It's secure and easy to understand your network visibility, control the network, and prevent attacks."
- "The pricing could be improved. They need to work on the setup over the firewall, VLAN, and PPPoE."
What is our primary use case?
I am a reseller of Palo Alto Networks.
What is most valuable?
The solution is user-friendly. It's secure and easy to understand your network visibility, control the network, and prevent attacks.
What needs improvement?
The pricing could be improved. They need to work on the setup over the firewall, VLAN, and PPPoE.
What do I think about the stability of the solution?
It's stable.
What do I think about the scalability of the solution?
It's scalable.
How are customer service and support?
I seldom call technical support because it's easy to understand and configure the solution.
What's my experience with pricing, setup cost, and licensing?
It could be less expensive.
What other advice do I have?
I would rate this solution 9 out of 10.
If you want to have a secure network, use Palo Alto.
Disclosure: My company has a business relationship with this vendor other than being a customer:
Security Engineer at a tech services company with 1,001-5,000 employees
Enables us to monitor VPN compliance and integrate with multiple vendors
Pros and Cons
- "With App-ID, we can identify exact traffic. Even if someone tries to fool the firewall with a different port number, or with the correct port number, Palo Alto is able to identify what kind of traffic it is."
- "The solution has normal authentication, but does not have two-factor or multi-factor authentication. There is room for development there."
What is our primary use case?
These firewalls are only used for perimeter purposes, in gateway mode.
How has it helped my organization?
In addition to our environment being secure, we can monitor compliance of VPN users. Security and monitoring are the two big benefits.
It's also very critical for us that it provides a unified platform that natively integrates all security capabilities. We have multiple vendors and multiple solutions. Palo Alto has to work with them. For example, when it comes to authentication, we can integrate LDAP and RADIUS, among others. And in one of our customer's environments, we have integrated a new, passwordless authentication.
What is most valuable?
Apart from the security, Palo Alto NG Firewalls have nice features like App-ID and User-ID. These are the two most useful features.
With App-ID, we can identify exact traffic. Even if someone tries to fool the firewall with a different port number, or with the correct port number, Palo Alto is able to identify what kind of traffic it is.
With User-ID, we can configure single sign-on, which makes things easy for users. There is no need for additional authentication for a user. And for documentation and reporting purposes, we can fetch user-based details, based on User-ID, and can generate new reports.
Another good feature is the DNS Security. With the help of DNS security, we can block the initial level of an attack, and we can block malicious things from a DNS perspective.
The GlobalProtect VPN is also very useful.
What needs improvement?
The solution has normal authentication, but does not have two-factor or multi-factor authentication. There is room for development there.
For how long have I used the solution?
We have been using Palo Alto Networks NG Firewalls for two years. I've worked on the 800 Series and the 3000 Series.
What do I think about the stability of the solution?
It's quite stable. They are launching a new firmware version, but compared to other products, Palo Alto is quite stable.
How are customer service and support?
I have worked with Palo Alto's support many times and it is quite good. Whenever we create a support ticket, they are on time and they update us in a timely manner. In terms of technical expertise, they have good people who are experts in it. They are very supportive of customers.
How would you rate customer service and support?
Positive
How was the initial setup?
The initial deployment is straightforward; very simple. The primary access for these firewalls is quite simple. We can directly access them, after a few basic steps, and start the configuration. Even the hardware registration process and licensing are quite simple.
The time it takes to deploy a firewall depends upon hardware and upon the customer's environment. But a basic to intermediate deployment takes two to three months.
What was our ROI?
Our customers definitely see ROI with Palo Alto NG Firewalls, although I don't have metrics.
What's my experience with pricing, setup cost, and licensing?
I am not involved in the commercial side, but I believe that Palo Alto is quite expensive compared to others.
Which other solutions did I evaluate?
One of the pros of Palo Alto is the GlobalProtect, which is a VPN solution. GlobalProtect has broader compliance checks. I have worked on Check Point and FortiGate, but they don't have this kind of feature in their firewalls. Also, Check Point does not have DNS Security, which Palo Alto has.
What other advice do I have?
If you're going with Palo Alto, you have to use all its features, including the DNS Security, App-ID, and SSL decryption. Otherwise, there is no point in buying Palo Alto.
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Network Security Engineer
Useful web filtering, responsive technical support, but VPN needs improvement
Pros and Cons
- "The best features of this solution are URL filtering and traffic visibility."
- "The areas that need to improve are network protection and user identification."
What is our primary use case?
I am using the solution for protecting the network organization from threats.
What is most valuable?
The best features of this solution are URL filtering and traffic visibility.
What needs improvement?
The areas that need to improve are network protection and user identification.
In the next release of the solution the VPN could improve because it is not as good as competitors.
For how long have I used the solution?
I have been using this solution within the past 12 months.
What do I think about the stability of the solution?
This solution is stable and reliable.
What do I think about the scalability of the solution?
We have 10 employees using this solution in my organization. We are in the beginning phases of testing and will increase usage if the test phase results are favorable.
How are customer service and technical support?
The technical support is responsive.
How was the initial setup?
The initial setup was easy.
What's my experience with pricing, setup cost, and licensing?
We are on an annual license for this solution. I am happy with the price and when comparing it to other solutions it is priced competitively.
Which other solutions did I evaluate?
I have evaluated Sophos firewalls and I found Palo Alto solutions better because of the protection and web filters.
What other advice do I have?
I would recommend this solution to others.
I rate Palo Alto Networks NG Firewalls a seven out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Team Leader at a tech services company with 501-1,000 employees
Plenty of useful features, reliable, but priced high
Pros and Cons
- "There are plenty of features available in this solution, such as attack blocker and spam blocker. Additionally, it is very robust and in-depth."
- "The solution is not straightforward."
What is our primary use case?
We use this solution to protect our network.
How has it helped my organization?
This solution has helped our organization by protecting the perimeter of our network from both internal and external threats.
What is most valuable?
There are plenty of features available in this solution, such as attack blocker and spam blocker. Additionally, it is very robust and in-depth.
What needs improvement?
The solution is not straightforward.
For how long have I used the solution?
I have been using this solution for approximately eight years.
What do I think about the stability of the solution?
The solution is very stable.
What do I think about the scalability of the solution?
The scalability is good. We have approximately 500 users using this solution in my company.
How was the initial setup?
The initial setup was complex. The full installation, including customize to meet our requirements, took approximately one month.
What about the implementation team?
We used the help from an integrator team for the implementation.
What was our ROI?
The technical support is satisfactory.
What's my experience with pricing, setup cost, and licensing?
The price of the solution is on the higher side compared to competitors.
Which other solutions did I evaluate?
We are currently looking for a better-priced solution.
What other advice do I have?
This is a very good solution but it is very expensive.
I rate Palo Alto Networks NG Firewalls a six out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
ITSM Engineer at a comms service provider with 11-50 employees
Reliable with good App-ID, Content-ID, User-ID, and encryption and decryption features
Pros and Cons
- "The App-ID, Content-ID, User-ID, and encryption and decryption are valuable features."
- "They can improve the handling and management of User-ID. They should also improve its price. Their technical support can also be improved."
What is our primary use case?
We are using it for data center protection, intrasystem security, endpoints protection, load balancing, and DHCP.
What is most valuable?
The App-ID, Content-ID, User-ID, and encryption and decryption are valuable features.
What needs improvement?
They can improve the handling and management of User-ID. They should also improve its price. Their technical support can also be improved.
For how long have I used the solution?
I have been using this solution for three years.
What do I think about the stability of the solution?
It is stable and reliable.
What do I think about the scalability of the solution?
We went from 4 devices to 16 devices, and it was not a big problem. Currently, we don't have any plans to increase its usage. Our network won't grow over the next two years. It will stay as it is.
How are customer service and technical support?
Their technical support is sometimes lousy, but sometimes, it is okay. Their technical support can be improved.
How was the initial setup?
Its initial setup is not too complex for an environment like this.
What's my experience with pricing, setup cost, and licensing?
Its price should be improved.
What other advice do I have?
I would recommend this solution. I would rate Palo Alto Networks NG Firewalls an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.

Buyer's Guide
Download our free Palo Alto Networks NG Firewalls Report and get advice and tips from experienced pros
sharing their opinions.
Updated: May 2025
Product Categories
FirewallsPopular Comparisons
Fortinet FortiGate
Netgate pfSense
Cisco Secure Firewall
Check Point NGFW
Azure Firewall
WatchGuard Firebox
SonicWall TZ
Juniper SRX Series Firewall
Fortinet FortiGate-VM
SonicWall NSa
Untangle NG Firewall
KerioControl
Buyer's Guide
Download our free Palo Alto Networks NG Firewalls Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Is Palo Alto the best firewall for an on-premise/cloud hybrid IT network?
- What are the main differences between Palo Alto and Cisco firewalls ?
- Expert Opinion on Palo-Alto Required.
- Which is the best IPS - Cisco Firepower or Palo Alto?
- Features comparison between Palo Alto and Fortinet firewalls
- Is Palo Alto Networks NG Firewalls better than Check Point NGFW?
- Which is better - Palo Alto Networks NG Firewalls or Sophos XG?
- What are the main differences between Palo Alto firewalls and Cisco Secure Firepower?
- What is a better choice, Azure Firewall or Palo Alto Networks NG Firewalls?
- Which Palo Alto Networks NG Firewalls model is recommended for 1200 users?