No more typing reviews! Try our Samantha, our new voice AI agent.
Technical Services Lead at Telenet Solutions
Reseller
Top 5Leaderboard
Sep 29, 2024
It provides a unified platform, helps secure our data centers, and reduces downtime
Pros and Cons
  • "Our clients find the most valuable features in Palo Alto Networks NG Firewalls to be the user-friendly interface, extensive capabilities, and highly granular rule creation process."
  • "The UI needs to be more user-friendly to attract novice users."

What is our primary use case?

We partner with vendors primarily to foster better understanding and relationships. Our core business is system integration, where we cater to diverse customer requirements. A customer might approach us with a specific need, and we deliver. A product like Palo Alto's XDR or EDR endpoint protection is popular due to its features, but ultimately, the choice depends on individual customer requirements, including extra services or integrations. We currently have around six customers using Palo Alto.

Aside from the usual content filtering and application filtering, the primary driving force for Palo Alto Networks NG Firewalls has been the SD-WAN. Additionally, ADR has also been a significant factor. All our clients also use Palo Alto as their firewall solution.

How has it helped my organization?

Palo Alto NG Firewalls offer a comprehensive platform that consolidates all security features, making them the preferred choice for our clients implementing SD-WAN and ADR solutions due to their integrated threat management capabilities.

Palo Alto NG Firewalls' embedding of machine learning into the firewall's core is crucial. They provide a cloud-based sandbox platform, enabling offloading of numerous tasks and offering AI-powered solutions to detect advanced or new threats. Palo Alto's methods for achieving this are impressive.

Some of the benefits our clients have seen using Palo Alto NG Firewalls include rapid deployment to their branches thanks to SD-WAN, improved control over branch networks, and enhanced overall environmental protection. It's important to remember that firewall security is product-dependent, and attackers often target widely deployed products for maximum impact. This explains the prevalence of attacks on popular firewalls like FortiGate and Checkpoint. Interestingly, Palo Alto is not as frequently targeted because attackers seek large-scale impact, making niche platforms like Palo Alto less appealing. Staying on a less common platform can offer a security advantage by attracting less unwanted attention from potential attackers.

Palo Alto NG Firewalls help secure our data centers across all workplaces. We also leverage a cloud platform for edge security.

Palo Alto NG Firewalls help reduce our clients' downtime. They are rarely attacked, and their uptime is over 99 percent.

What is most valuable?

Our clients find the most valuable features in Palo Alto Networks NG Firewalls to be the user-friendly interface, extensive capabilities, and highly granular rule creation process. This level of granularity allows for precise control and customization in network security policies.

What needs improvement?

Some of our clients find the price of the NG Firewalls to be expensive.

The UI needs to be more user-friendly to attract novice users.

Buyer's Guide
Palo Alto Networks NG Firewalls
September 2026
Learn what your peers think about Palo Alto Networks NG Firewalls. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
913,683 professionals have used our research since 2012.

For how long have I used the solution?

I have been using Palo Alto Networks NG Firewalls for four years.

What do I think about the stability of the solution?

I would rate the stability of Palo Alto Networks NG Firewalls nine out of ten.

What do I think about the scalability of the solution?

The entry-level Palo Alto Networks NG Firewalls lack scalability, but their higher-end counterparts offer this feature. Overall, I would rate their scalability a six out of ten.

How are customer service and support?

The Palo Alto support is excellent.

How was the initial setup?

The initial deployment is straightforward for technical people. The number of people required for deployment depends on the environment, but one or two people are usually sufficient. For example, in a branch scenario, one person might handle the headquarters while the other visits the branches. However, even at headquarters, there could be more than one person depending on the customer's services, enabling them to collaborate on creating rules, modifying requirements, or gathering information while someone else focuses on the deployments.

What was our ROI?

Usually, our clients see a return on investment after the first year of deployment.

What's my experience with pricing, setup cost, and licensing?

I find the pricing of Palo Alto Networks NG Firewalls to be reasonable. The price is based on that selected package, with the lowest starting at $3,000 annually.

What other advice do I have?

I would rate Palo Alto Networks NG Firewalls nine out of ten.

I would recommend Palo Alto Networks NG Firewalls, but it ultimately comes down to the organization's needs. Some organizations are almost entirely cloud-based, while others rely on the Internet for a few specific tasks and may have on-premises processing or branch offices. The ideal firewall solution varies depending on the specific environment and use cases; a firewall that performs well for one organization might not be the best fit for another.

The primary reason people opt for cloud or hybrid solutions is to manage workloads or services already operating in the cloud. This trend extends to Palo Alto Networks NG Firewalls, where the cloud versions are gaining popularity. However, many users prefer the on-premise version of the firewalls to safeguard their on-premise infrastructure. This may involve physical or virtual appliances as long as they remain on-premise and not in the cloud.

Other than updates, Palo Alto Networks NG Firewalls rarely require physical maintenance because most data centers are clean.

Palo Alto Networks NG Firewalls are excellent firewalls but require technical expertise and dedicated resources for deployment. However, with technical know-how, they are easy to configure and deploy and offer flexibility for adaptation to various environments. We highly recommend them for SD-WANs and VPNs due to their high compatibility.

Disclosure: My company has a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer2533908 - PeerSpot reviewer
Senior Network and Security Engineer at a computer software company with 501-1,000 employees
Real User
Aug 25, 2024
It's a complete solution that's reliable, consistent, easy to manage, and full of rich security features
Pros and Cons
  • "Palo Alto solutions are scalable and highly capable. NG firewalls offer a complete solution that's reliable, consistent, easy to manage, and full of rich security features. They're easier than other firewalls and certainly more effective."
  • "Palo Alto could improve its machine-learning capabilities. That's all new. They integrate the telemetry data and analytics up to the cloud, where they can analyze for security policies and best practices like DNS Security. It uses AI tools to sort through all the massive logs and highlight where you can take action or be aware of what's happening. If you don't have many tools in your organization, it's nice to have one tool that does an excellent job across the board."

What is our primary use case?

We use Palo Alto firewalls to secure the enterprise network and connect our branch offices with our data centers.

How has it helped my organization?

A lot of Palo Alto's attack mitigation is automatic. It's nice that you can define security policies and profiles, and the firewall can automatically take action to mitigate attacks as they occur.

We can avoid downtime because Palo Alto supports high-availability firewalls, which usually enable us to do maintenance without interruption to the enterprise. We also have redundancy in our wide area, so we are not dependent on one internet provider. If it fails, we can route across an alternate provider through our VPN tunnels. 

What is most valuable?

Palo Alto solutions are scalable and highly capable. NG firewalls offer a complete solution that's reliable, consistent, easy to manage, and full of rich security features. They're easier than other firewalls and certainly more effective.

NG Firewalls provide a unified platform that natively integrates all security capabilities. It's critical to have a cohesive system that works across the entire organization. Palo Alto embeds machine learning into the firewall's core, which is necessary to keep up with the threat landscape. 

What needs improvement?

Palo Alto could improve its machine-learning capabilities. That's all new. They integrate the telemetry data and analytics up to the cloud, where they can analyze security policies and best practices like DNS Security. It uses AI tools to sort through all the massive logs and highlight where you can take action or be aware of what's happening. If you don't have many tools in your organization, it's nice to have one tool that does an excellent job across the board. 

For how long have I used the solution?

I have used Palo Alto NG Firewalls for five and a half years. 

What do I think about the scalability of the solution?

Palo Alto firewalls have excellent scalability. The same techniques and configuration scale from a small branch office to larger data centers. They're consistent in terms of configuration. You have centralized administration through Panorama to manage all of them easily and have global visibility with both configuration and logging.

How are customer service and support?

I rate Palo Alto support seven out of 10. Palo Alto has some excellent engineers, but recently, I've had difficulty finding a technician who can solve the problem quickly.  They're easy to reach, but it's sometimes harder to communicate with the support engineers. Some are more effective, but other engineers take a couple of days to analyze the issue. The support is not as good as it used to be.

How would you rate customer service and support?

Neutral

Which solution did I use previously and why did I switch?

I've used other brands of firewalls in another company, and this company has used some older firewalls. I have used Juniper SRX and NetScreen firewalls. I've also worked with Cisco ASA and SonicWall firewalls.

Palo Alto firewalls provide better visibility into the data and excellent logging that enables you to track all threats and activity. They seem to be more resilient to attacks. Other brands get overwhelmed by DDOS attacks, whereas Palo Alto has multiple levels of security that can head off some of those floods. They act almost like an intrusion detection system and some form of DDoS protection. They do a good job if you can't afford a separate product.

How was the initial setup?

I rate Palo Alto NG firewalls nine out of 10 for ease of setup. They're easier to set up than Juniper SRX or NetScreen. When I arrived, they had already installed a few firewalls, but they weren't working well. The failover and high availability were not set up properly. 

They were new to Palo Alto. They started deploying a few in their branch offices and configuring them with Panorama, so they're all registered and centrally administered. There are consistent policies and shared objects across your organization for filtering geographic regions and things like that. 

The IT VP administered some of the network after their other engineer left. They had previously used Fortinet and only recently purchased Palo Altos, but they were trying to get them deployed. As a senior network engineer, I deployed it with the IT VP, and the IT manager made some operational changes. I and a member of my team maintain the firewalls. 

What was our ROI?

Palo Alto enables you to support an extensive, busy network with fewer people. You can centrally administer the solution and apply automated content updates for virus and threat prevention. Once you get these things set up, they do a lot of it independently. You only need to keep a close watch on them. 

What's my experience with pricing, setup cost, and licensing?

Palo Alto can be priced higher than some less capable firewalls. However, they are exceptional when you consider the completeness of the solution and its ability to handle threats. Palo Alto is better than other solutions, which justifies a slightly higher price point. You have other tools that are easier to deploy, reducing your total cost of ownership. The newer models are faster, making the pricing more attractive.

A cheaper solution might be better if you have a small or home business that doesn't have many security requirements. Palo Alto scales down to small offices and larger data centers and enterprises. Their product scales to a wide range of use cases. 

What other advice do I have?

I rate Palo Alto NG Firewalls 10 out of 10. I recommend spending time with Palo Alto and other support partners planning and understanding your network before you deploy. You can simplify many capabilities into common rules that you can apply consistently across the organization to save time. Planning can help you build consistency in naming address objects, VLANs, and network resources.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Palo Alto Networks NG Firewalls
September 2026
Learn what your peers think about Palo Alto Networks NG Firewalls. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
913,683 professionals have used our research since 2012.
Chan Lung - PeerSpot reviewer
Presale Consultant at a tech vendor with 1,001-5,000 employees
Real User
Top 5
Oct 30, 2024
Provides strong protection through network segmentation and XDR
Pros and Cons
  • "Palo Alto NG Firewalls offer an efficient interface that simplifies log checking, troubleshooting connection issues, and firewall policy configuration."
  • "Enhancing support teams' capability to handle cases without much delay would be beneficial."

What is our primary use case?

I primarily help users migrate from traditional firewalls to Palo Alto NG Firewalls. This involves troubleshooting, assisting with application control and backup configuration, and teaching users how to optimize the firewall for their needs. Additionally, I guide users through the process of redesigning their firewalls and migrating their servers, which often includes helping them understand and manage the vast number of applications they have. Sometimes, the firewall cannot identify specific applications, requiring customization to ensure accurate recognition and security. Currently, I am working on a management query language, which involves collaborating with other teams to assess the necessity of specific applications and connections between the firewall and various assets. This ensures optimal security and network efficiency.

How has it helped my organization?

Although Palo Alto Networks NG Firewalls now utilize machine learning, its significance wasn't initially apparent to me. My first experience with Palo Alto revealed the power of their machine learning through features like WildFire, which uses real-time analysis to understand and combat hacker attacks. While early versions had tools like Power Tool that hinted at machine learning capabilities, Palo Alto didn't explicitly promote this functionality until version 10, likely in response to increasing market competition and the growing prominence of machine learning in firewalls. The embedded machine learning is helpful.

Palo Alto NG Firewalls has improved our organization's security by providing strong protection through network segmentation and XDR. The firewall has proven effective in reducing security risks and monitoring endpoint activity. It offers excellent application recognition and thorough threat analysis, boosting overall network security.

Palo Alto NG Firewalls have reduced over 90 percent of our network downtime.

What is most valuable?

Palo Alto NG Firewalls offer an efficient interface that simplifies log checking, troubleshooting connection issues, and firewall policy configuration. The process is user-friendly, guiding users through network infrastructure setup, interface creation, settings application, and policy configuration in a clear and intuitive manner.

What needs improvement?

Palo Alto Firewalls can improve their support structure, especially concerning longer working hours for engineers. Enhancing support teams' capability to handle cases without much delay would be beneficial. Additionally, the high cost of the product could be re-evaluated.

For how long have I used the solution?

I have been using Palo Alto Next Generation Firewalls for over ten years.

What do I think about the stability of the solution?

Palo Alto NG Firewalls are stable. On a scale of one to ten, I would rate them around seven or eight for stability.

What do I think about the scalability of the solution?

I find Palo Alto NG Firewalls to be highly scalable, and would rate their scalability as eight out of ten.

How are customer service and support?

Customer support's effectiveness depends on the clarity and completeness of information provided by users.

How would you rate customer service and support?

Neutral

Which solution did I use previously and why did I switch?

I've used Check Point and Fortinet in addition to Palo Alto, but I prefer Palo Alto's interface and performance.

How was the initial setup?

The initial setup for Palo Alto NG Firewalls is clear and instructive, detailing network infrastructure setup before advancing to policy configuration.

A fresh deployment of Palo Alto NG Firewalls can be completed in three days, followed by a two-day handover session to train users. This totals five days for deployment and training. However, migrations for companies with over 10,000 users and 20 subnets can take up to a month, potentially involving additional user requests or a phased approach.

What about the implementation team?

I have vast experience deploying these firewalls on-premises within our team, making use of the intuitive interface provided by Palo Alto for implementation.

What's my experience with pricing, setup cost, and licensing?

Although Palo Alto is expensive, its superior security functions, application identification, and overall performance justify the cost and make it stand out from the competition.

What other advice do I have?

I would rate Palo Alto NG Firewalls nine out of ten. The Palo Alto NG Firewalls are great, but they are expensive.

I'm most interested in Palo Alto NG Firewalls, specifically how to improve their efficiency and application identification capabilities. Sometimes applications have unique requirements or behave differently, making accurate identification crucial. Palo Alto NG Firewalls excel at application-level security because they can block traffic, prevent attacks, and identify potentially compromised applications. Unlike traditional firewalls, Palo Alto NG Firewalls go beyond basic policy enforcement and traffic filtering by incorporating intrusion prevention systems and antivirus functionality. This allows them to analyze internal traffic for risks, similar to how antivirus software protects endpoints.

Future users need to appreciate the costs involved in using Palo Alto, and the manual configuration required is beneficial because it ensures clarity and control over what is being configured. To enhance your organization's security posture and management, I recommend implementing Palo Alto Networks NG Firewalls.

Three people in our organization are directly using the Palo Alto NG Firewalls.

Upgrading Palo Alto Next-Generation Firewalls requires some maintenance.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Mohamed Kishk - PeerSpot reviewer
Network and Information Security Manager at a pharma/biotech company with 1,001-5,000 employees
Real User
Top 5
Sep 29, 2024
Helps us secure our network against suspicious activity but the reporting needs improvement
Pros and Cons
  • "The most valuable feature of Palo Alto Networks NG Firewalls is its application visibility, which allows us to see all users and their accessed resources."
  • "The SD-WAN feature needs improvement."

What is our primary use case?

We primarily use Palo Alto Networks NG Firewalls for a DMZ firewall. Its primary function is to separate our network into four layers: a DMZ zone for all publishing services, an internal zone for internal user access to publishing services, a zone for terminating connections between VPN consultants and internal services, and a zone for Internet access.

We implemented Palo Alto Networks NG Firewalls to secure our network and control access using filtering and application control. We also use Palo Alto WildFire for vulnerability scanning.

We have Palo Alto Networks NG Firewalls deployed on the cloud and on-prem.

How has it helped my organization?

Palo Alto helps us secure our network against suspicious activity from both internal and external sources. Its integration with our SIEM aids our SOC team in blocking malicious activity.

Palo Alto Networks NG Firewalls do a good job securing our environment. To access any solution, the first step is to calculate the required throughput. Because we are working with a small network or environment, we need a specific amount of throughput from a Firewall model. I chose this particular model based on my throughput requirements. The second consideration is the level of security achievable by the solution. We are using additional methods, such as performing a gap analysis and assessing the solution, to determine this. This involves simulating attacks passing through the Firewalls to observe how the solution detects or blocks them.

What is most valuable?

The most valuable feature of Palo Alto Networks NG Firewalls is its application visibility, which allows us to see all users and their accessed resources. Additionally, its user-friendliness and customization options contribute to its overall value.

What needs improvement?

The reporting feature needs significant improvement. Generating reports in Palo Alto is challenging because it relies on specific attributes and source IDs. We want to create reports to view the number of users and consumption, but customization is difficult. The interface for generating reports is user-unfriendly, making it difficult to find information. Overall, the reporting capabilities are weak compared to other firewall solutions.

The SD-WAN feature needs improvement. It currently relies on the physical interface instead of the sub-interface, requiring Panorama rather than a local firewall. Furthermore, the configuration customization for SD-WAN application source and subnetting is significantly limited compared to other firewalls.

The technical support is slow and needs improvement.

For how long have I used the solution?

I have been using Palo Alto Networks NG Firewalls for five years.

What do I think about the stability of the solution?

I would rate the stability of Palo Alto Networks NG Firewalls ten out of ten.

What do I think about the scalability of the solution?

I would rate the scalability of Palo Alto Networks NG Firewalls ten out of ten.

How are customer service and support?

Palo Alto does not provide direct support to customers. Each region has support partners, so to get direct support from Palo Alto, you need to be a very large customer. This is why resolving issues with Palo Alto takes a long time. We go through our partner, and they take some time to investigate and try to solve the problem. If they can't, they escalate the case to Palo Alto, which takes additional time to investigate and try solutions. This is why our cases may take days or weeks to resolve.

How would you rate customer service and support?

Negative

Which solution did I use previously and why did I switch?

I work with numerous firewall solutions, including FortiGate, Cisco Firepower, Cisco Sourcefire, and Forcepoint Firewalls. I've found that each firewall excels in specific areas. For instance, I recommend Cisco Firepower for central firewall management. However, for DMZ and application control, I suggest Palo Alto. Finally, I recommend FortiGate for perimeter firewall deployment based on its extensive features and overall stability.

How was the initial setup?

The initial deployment is straightforward and can be completed in a few hours for small environments. However, larger environments with multiple policies will require additional deployment time.

What was our ROI?

We have seen a return on investment of 30 percent from Palo Alto Networks NG Firewalls. 

What's my experience with pricing, setup cost, and licensing?

Palo Alto is a more expensive firewall solution than others. However, it is the top choice for a DMZ and a valuable investment overall. We still need to invest in an additional firewall with more advanced features to enhance perimeter security.

What other advice do I have?

I would rate Palo Alto Networks NG Firewalls seven out of ten.

Those looking for the cheapest and fastest firewall won't find that combination. They must invest money to get a fast firewall suitable for their environment. Gather their requirements before choosing a firewall that fits their budget and features. They can opt for the quickest or cheapest option or select a device compatible with their needs.

We have Palo Alto Networks NG Firewalls deployed in multiple locations, serving both on-premises and cloud departments. There are three people in our organization that work with the NG Firewalls. Our clients are enterprises.

Palo Alto Networks NG Firewalls require maintenance for software upgrades, and after several years, the hardware will also need upgrades.

I recommend Palo Alto Networks NG Firewalls for their stability and high level of security. If the security of your infrastructure is critical, Palo Alto is a strong choice, though it comes with a higher price tag. If budget is a concern or security isn't a top priority, then Palo Alto may not be the best fit.

Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
Igor Lima - PeerSpot reviewer
Network administrator at a comms service provider with 201-500 employees
Real User
Top 5
Oct 30, 2024
The unified platform helps centralize management and reduce downtime
Pros and Cons
  • "Palo Alto Networks NG Firewalls offer a comprehensive suite of security features, with Intrusion Prevention System and certificate inspection being among the most valuable."
  • "The machine learning feature, with its continuous potential for improvement, directly enhances the security of Palo Alto Networks NG Firewalls."

What is our primary use case?

We provide localization services and use Palo Alto Networks NG Firewalls to protect our environment.

We have two on-premises Palo Alto Networks NG Firewalls that are managed in the cloud.

How has it helped my organization?

Palo Alto Networks NG Firewalls provide a unified platform for centralized management. This is one of the most critical features of the NG Firewalls.

Palo Alto Networks NG Firewalls utilize embedded machine learning to combat the evolving landscape of cyber threats. This is crucial because traditional security methods often fall short against modern malware and sophisticated attacks. By employing machine learning, these firewalls proactively identify and mitigate risks in a way that static rules-based systems cannot, effectively countering the advanced techniques increasingly used by malicious actors.

It helps reduce downtime in our organization by 98 percent.

What is most valuable?

Palo Alto Networks NG Firewalls offer a comprehensive suite of security features, with Intrusion Prevention System and certificate inspection being among the most valuable.

What needs improvement?

The machine learning feature, with its continuous potential for improvement, directly enhances the security of Palo Alto Networks NG Firewalls.

For how long have I used the solution?

I have been using Palo Alto Networks NG Firewalls for almost 12 years.

How are customer service and support?

The technical support is good, and Palo Alto has excellent documentation.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

We also use FortiGate Firewalls in addition to Palo Alto Networks NG Firewalls. Both offer similar features and prices and are considered top competitors in the market.

What was our ROI?

The return on investment from Palo Alto Networks Next-Generation Firewalls has been significant, as the enhanced security they provide to the enterprise effectively offsets their cost.

What's my experience with pricing, setup cost, and licensing?

Palo Alto Networks NG Firewalls are affordable, and we get what we pay for.

What other advice do I have?

I would rate Palo Alto Networks NG Firewalls ten out of ten.

We have over 10,000 end users.

When choosing a firewall, cost often reflects capability. While budget-friendly options exist, their security levels may not match those of higher-end providers like Palo Alto or Fortinet. Investing in a robust firewall often provides enhanced protection and advanced features, justifying the higher cost.

We have three employees and one consultant who are responsible for the maintenance of our NG Firewalls.

Which deployment model are you using for this solution?

Hybrid Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
John Sayer - PeerSpot reviewer
President at JTS Network Consulting, LLC
Real User
Dec 19, 2022
Phenomenal reporting and it's easy to find which threats have been detected and what traffic is going through the box
Pros and Cons
  • "One of the simple features I like about Palo Alto firewalls is that it's extremely easy to find out what's happening in the network. The reporting is phenomenal, and it's easy to find which threats have been detected and what traffic is going through the box. When a customer notices something is wrong, you can quickly check the amount of traffic going through the firewall around that time. If there is anything out of the ordinary, you can decide it needs to be investigated further."
  • "The reporting and visibility are phenomenal, but you don't get that information out of the box. They can email reports regularly, and the functionality is all there. However, a lot of it is based on an older model for email, where customers have in-house email servers. The small and medium-sized business customers I deal with are moving toward Office 365 or some other cloud-based mail and not maintaining their own internal mail servers."

What is our primary use case?

NG Firewalls form the edge between customers' networks and the internet. They often provide load balancing to multiple internet providers. In most cases, people use NG Firewalls for more than just a basic firewall function. 

The intrusion detection and prevention feature is usually the most significant piece that people want because it provides layers of protection against malware, ransomware, and things of that nature.

How has it helped my organization?

My colleague likes to tell our clients that none of his customers who installed a Palo Alto have ever had a ransomware attack. I'm always nervous when he says that because things change so fast. However, it gives people peace of mind that they're protected at the network's edge. 

The firewall is going to do everything possible to protect resources and data. We have customers with social security numbers, HIPAA data, and other sensitive customer information. Other products don't seem to provide the same level of protection and leave customers open to malware or ransomware attacks.

Palo Alto has many features to protect against data leakage and unauthorized downloads, so it can do quite a lot to protect a network against any attack. The leadership at our client companies feel reassured that they've done what they can with the best solution out there to protect themselves.

Smart people always do stupid things, like clicking on something they shouldn't. They often realize their mistake five minutes or five seconds after doing it. We've seen what these mistakes can quickly do to an organization. Palo Alto's features help you prevent those types of things from happening. You can immediately block suspicious file downloads and push those up to Palo Alto to investigate. You can get ahead of the problem and help other folks who might not have seen that attack.

NG Firewalls provide a unified platform that natively integrates all security capabilities. Having all those features in one platform at the edge is essential. That's a massive component of the customers' overall security structure. It isn't everything, but it protects the edge of the network. 

It does not prevent someone from getting their company laptop infected at home and infecting the network when they come to the office the next day. That's where other pieces come into play to make an overall security structure. The firewall is designed to protect everything at the edge and has everything you need to do that. It protects you at the edges and provides reports that give people information about what's happening on the network at a given time and date. 

NG Firewalls take care of any holes in the client's network and reduces the number of security tools needed. A decade ago, deploying these types of tools required multiple devices, whether that was Barracuda email, firewall, and an intrusion detection platform. Generally, people had antivirus and anti-spyware systems running in their enterprises. All of that is now integrated into the Palo Alto Firewall platform. 

The antivirus and anti-spyware features are as good as anything out there. It's updated constantly, so any novel threats are automatically detected. On top of all these features, it provides a solid edge platform that incorporates all of the security features necessary in that edge component.

What is most valuable?

One of the simple features I like about Palo Alto firewalls is that it's extremely easy to find out what's happening in the network. The reporting is phenomenal, and it's easy to find which threats have been detected and what traffic is going through the box. When a customer notices something is wrong, you can quickly check the amount of traffic going through the firewall around that time. If there is anything out of the ordinary, you can decide it needs to be investigated further.

I talk to customers a lot about simple aspects. Palo Alto firewalls have vast technical capabilities in the signature database, which is constantly updated. Palo Alto does a lot of work to find threats in the wild, which is rare among vendors. From a practical and operational standpoint, the ability to see what's happening at any time, live or historically, is a huge benefit compared to other firewalls that are out there.

Machine learning is a massive part of it. Threats are always evolving, and they can constantly update the signatures they're hunting and the raw data streams they're looking for outside of something that's been defined as a true signature type of attack.

Most of my customers use what Palo Alto refers to as the Wildfire functionality. Their online analysis team checks every 15 minutes to find anything new that has been detected in the wild anywhere in the world. Once their team finds something, they immediately disseminate that information down to the firewalls so they can start looking for something new. That includes anything that has evolved from one version of an attack to another. So far, we have not run into any issues with changing attacks creating problems for customers with a Palo Alto firewall in place.

It's rare for our customers to use the zero-day intelligence feature to upload information to Palo Alto. Still, receiving anything from Palo Alto that others have detected out in the wild is beneficial. Any zero-day signature people find in a data stream can be pushed down to the firewalls, and it's a huge benefit to know that the firewall can stay on top of the changes in the attack world.

The PA 400 series is excellent. It's the product that they were missing. Years ago, there was a Palo Alto 200 and a Palo Alto 500. The 500 was a relatively low-cost platform that focused more on team-sized businesses. It reached the end of its life, and they replaced it with an 800, a similar form factor but quite a bit more expensive. The 200 was replaced with a 220, which was at the low end cost-wise in the product family, but they never had anything in the middle. 

They didn't have something that offered high performance at a reasonable cost. The 400s provide that missing link inside their product family to cater to small and medium-sized businesses. Because more and more, even though companies are small, with 50 to 100 people in a company, internet bandwidth has gotten so cheap that they're typically running 1+ gigabit-per-second connections out to the internet.

While they may not be using that much bandwidth today, that will change as they do more and more online. We saw during the pandemic how that could change quickly. Suddenly, everybody's working from home, and internet connectivity is the company's lifeblood. The 400 series gives customers decent performance at a lower price point in a small form factor. It's a product they can deploy, knowing it will protect them and provide the performance they need for years.

What needs improvement?

The reporting and visibility are phenomenal, but you don't get that information out of the box. They can email reports regularly, and the functionality is all there. However, a lot of it is based on an older model for email, where customers have in-house email servers. The small and medium-sized business customers I deal with are moving toward Office 365 or some other cloud-based mail and not maintaining their own internal mail servers. 

Palo Alto is developing that, and I need to understand how they integrate with an Office 365-type mail environment. The next piece is figuring out how to get that information to the people who need it without somebody physically sitting in front of the screen or going to the firewall to have it delivered to them regularly. The capability is there, but it's primarily based on an older email architecture that customers rarely use anymore.

For how long have I used the solution?

I'm an integrator who has been doing professional services with Palo Alto installations for at least eight years.

What do I think about the stability of the solution?

Palo Alto firewalls are solid. I can recall that we haven't had platform failures or product issues with the Palo Alto Firewalls. Everything can have a power supply failure. We have seen that occasionally, but it's rare. In eight years, we've had to replace power supplies in two firewalls out of hundreds we've deployed. It's a physically stable platform, and the software is also solid. I typically avoid the most recent software versions until they reach what I consider mature and seasoned. 

We've seldom had issues with performance. I always tell people that internet bandwidth will be bigger and cheaper in the future, so firewalls need to keep pace from a performance standpoint. Palo Alto has done a decent job of bringing out new models with higher throughput levels while maintaining all the threat-driven functions. But we constantly need to evaluate where we are with internet bandwidth and where we expect to be in the future. 

We tell people that the physical hardware platform they choose will protect them today, no matter which one. However, the choice will determine how long that can stay in your network. It ultimately comes down to pure bandwidth. As we move towards the cloud, more and more internet bandwidth becomes critical. Multiple internet providers are now essential on most of our customers' networks. The raw bandwidth and performance through the box must keep up with that. Palo Alto's newer platforms have multiple-gigabit throughput, and I assume they'll continue with that as they evolve the product line further.

What do I think about the scalability of the solution?

Their product line includes sizeable chassis-based firewall systems that can do multiple virtual firewalls within a single platform. Even their middle-tier products have that capability. Some of our customers have numerous divisions that need separation between departments, so those scalable features come in handy. Most are organizations with one or two firewalls per site. Still, I've worked with large enterprises that had tens or hundreds of firewalls in their overall environment to maintain a separation between departments and to separate users from servers.

Palo Alto also has a product called Panorama that lets you centralize the configurations of vast numbers of firewalls. It acts as a central point for changing firewall settings, and you can push the changes out to a subset of firewalls in your environment or all of them. The bottom line is that Palo Alto can scale up NG firewalls to massive numbers of platforms.

How are customer service and support?

I rate Palo Alto support eight out of 10. 

How would you rate customer service and support?

Positive

How was the initial setup?

NG Firewalls are easy to set up. I've been doing it for a long time, so it's effortless for me to set them up. When registering a firewall with Palo Alto, you can download a Day 1 configuration into the box with many of the standard protection features activated. 

I don't use that, but I periodically check it to see if there is something else Palo Alto has determined should be enabled or a feature that should be tuned differently than I typically do. They provide the initial configuration with the critical features activated.

Deployment requires a small team. Sometimes, it's only a person from the customer side and me. Usually, it is me plus one other engineer working on deploying these where we've got changes on switches to support the firewall or adjustments to the DNS systems. A lot of different areas come into play when we change the edge. Frequently, our customers are transitioning from a rudimentary network design to a new design where we're implementing firewall and network segmentation within their environment. That's easy, but we use a team of two or three folks to finish the job as quickly as possible.

What was our ROI?

While all next-generation firewall platforms have some degree of these different components built into them, Palo Alto has rock-solid antivirus, anti-spyware, threat prevention, data leakage prevention, and file blocking, plus all of the typical functions that a firewall does. It does all of these functions exceptionally well in addition to regular firewall aspects like blocking DDoS attacks and generic types of attacks. It tends to be more expensive than most competing platforms, but the return on investment is huge. I'm almost to the point of saying that I won't support any other firewall platforms out there.

There are several new firewall models that have come along, but I tell people that Palo Alto will provide all the protection you could need. There's no reason to look at anything else out there because most other platforms don't provide the same level of protection. The value proposition to customers is the peace of knowing they've got the best protection at the edge they can buy.

What's my experience with pricing, setup cost, and licensing?

The licensing model is becoming more and more typical of vendors. There are several different licenses that we usually provide with the firewalls. DNS security is a newer one, and we're considering the types of customers who might benefit from that. 

The cost of the license is platform-dependent. It would be nice if they standardized that across the board to make the license a flat fee instead of based on scale and the platform you're using. Functionality shouldn't change based on the platform or the amount of data going through it. It's the same functionality on there. That's one aspect customers often raise. The platform's price is what it is, but the ongoing cost of the annual license is hard for some customers to wrap their heads around. 

Which other solutions did I evaluate?

Many people are just looking for the cheapest, fastest firewall, and my answer is always the same. It's a cliche to say you get what you pay for, but when you opt for the cheapest product, you have to understand that the costs of an attack are monumental. We had a customer who deployed SonicWall firewalls because they wanted something inexpensive that provides a basic level of functionality. They have spent three weeks trying to recover from a ransomware attack because the firewall didn't prevent them from downloading files into their environment, and it lacked some of the features a Palo Alto firewall has.

I tend to use examples like that. It's like switches. When everything's working great, you can go to the local store and buy yourself a cheap and expensive switch, and it'll be fine. But when there are problems, how do you recover? And what can you do with the firewall that will protect you against attacks you don't anticipate? That's where Palo Alto shines. You know you are protected when you deploy it.

Other products are less expensive because they don't provide the same level of functionality. They'll talk about threat prevention, anti-spyware, and malware functions, but they have not been updated automatically like Palo Alto and they lack zero-day functionality. Maybe they don't have some other components, like data leakage protection or file download protections to thwart a concerted attack against organizations.

I always ask people what it would cost to shut down their business for several days. This customer had a solid backup strategy for their servers at least, enabling them to start using cloud-based versions of all their servers within three days. They still were out of business for three days. Now that we've put Palo Alto firewalls in place, they feel confident that's not going to happen again.

I get nervous when people say it can't happen, but we haven't seen it happen with the Palo Alto firewall with the capabilities and features we enable on these boxes. When people say they don't want to spend that money, they need to consider it as something protecting their entire business. An internet connection isn't a nice-to-have; it's the lifeblood of their business, being protected by the firewalls.

What other advice do I have?

I rate Palo Alto NG Firewalls 10 out of 10. People who are only starting with these firewalls should rely on the technical notes and briefs Palo Alto provides on functionality. I started using Palo Alto firewalls years ago, and we deployed firewalls the way we knew how. Later, I worked with another integrator who had been doing it for about two or three years more than I had. He was configuring areas on the firewalls that I had never considered. That becomes the critical piece; turning a firewall up based on what another firewall vendor does is enough to get you the same level of functionality that the other vendors provide.

But with the additional capabilities that Palo Alto includes in the firewalls, it's imperative to have all the different pieces activated as much as the customer can accommodate in their environment. And that's a critical piece that Palo Alto provides a lot of online resources, and there are a lot of technical notes that are out there on what needs to be enabled in addition to that Day 1 configuration. That can give you a big headstart on all the different areas that need to be enabled within the firewall.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. partner
PeerSpot user
MartinFerguson - PeerSpot reviewer
Managing Director/Co-Founder at Azured
Real User
Nov 30, 2022
The solution simplifies operations, ties into existing services, and uses machine learning
Pros and Cons
  • "I can enable the features I want and configure the policies based on the user and not all users and network traffic, making firewall management much easier."
  • "The stability of this solution is unbelievable and the best on the market."
  • "We have not taken Palo Alto's firewall management solution because it's too expensive and we don't feel it delivers significant value."

What is our primary use case?

We use the solution for all the capabilities that the firewall offers, including proxy filtering, VPN connection, and Next-Gen firewall capability. We integrate the solution with clients that use ExpressRoute, which is a very common and popular service in Australia. We route all our client's local traffic, 10.x, and the client's Class B public address traffic all into Palo Alto Networks NG Firewalls. We use the solution to provide hub and spoke integration, web filtering, and for VPN. 

The solution is a fully managed centralized firewall service for both public and private traffic, including on-prem traffic and Azure traffic.

How has it helped my organization?

The solution ties into existing services. We offer network-based services and SD-WAN overlay. We use VeloCloud appliances and put the solution at the heart of that to provide Next-Gen security capability. The solution benefits our clients by reducing the number of firewalls required in their organization, which is hosted in Azure. The solution's aggregation gives us the ability to service our clients by reducing their firewall footprint. The solution also enables us to route all traffic, including internet outbound traffic from a client's side onto Palo Alto NG Firewalls across an ExpressRoute connection.

Palo Alto NG Firewalls provide a unified platform that natively integrates all security capabilities.

In combination with additional tools and services we offer, the solution makes a significant contribution to eliminating security holes.

The solution helps eliminate multiple network security tools and the effort required to have them work together. The solution simplified our operations. We only support and deliver Palo Alto NG firewalls as a service. We don't offer a firewall as a service on any other appliance. We chose Palo Alto because of its Next-Gen capabilities and being the market leader in terms of security appliances. 

What is most valuable?

I like the native integration into Azure AD and the solution is fantastic from the perspective of managing user access and using the VPN client. The TLS inspection is a fantastic service that's offered in Palo Alto NG Firewalls. In my opinion, the solution is best of breed, which is one of the reasons why we adopted it in the first place.

We have had a couple of DNS attacks and predictive analytics and machine learning for instantly blocking DNS attacks worked well. 

Depending on the license skew, we implement the zero delay signatures feature for some of our customers.

I can enable the features I want and configure the policies based on the user and network traffic, making firewall management much easier.

What needs improvement?

There are some features of Fortinet such as the virtual domain capability, that I would love to see in this solution, but they don't outweigh the technical capabilities of Palo Alto as the firewall.

We have not taken Palo Alto's firewall management solution because it's too expensive and we don't feel it delivers significant value. We have developed our own reporting. Sometimes there are limitations around the APIs and it would be great if the APIs could be enhanced.

For how long have I used the solution?

I have been using Palo Alto Networks for about 10 years, but not the Next-Generation version. Five years ago, we set up a Palo Alto firewall as a service with Palo Alto in the back end. We did this for Telstra in Australia, and we're the only company in the world that can support the default route over ExpressRoute, using the Palo Alto Networks NG Firewalls as a service that we offer.

What do I think about the stability of the solution?

The stability of this solution is unbelievable and the best on the market. We've never had an outage as a result of a technical problem on hundreds of firewalls that we run or thousands when we include the HA pairs and clusters that we've built.

What do I think about the scalability of the solution?

The solution is scalable and we have never reached the limits. We stuck with Palo Alto because of their Next-Gen capabilities, and we have about 500 clients using this solution as a service.

How are customer service and support?

The technical support is exceptionally good. They have more capabilities in Australia now and we've had no problems. The technical support has been so good, we haven't had to look for another vendor.

How would you rate customer service and support?

Positive

How was the initial setup?

The initial setup is straightforward. We have a multi-tenanted version and a single version. We have different flavors of the implementation and it's all scripted. We can build a fully operational firewall HA pair with follow-the-sun, 24-hour, seven-days-a-week support in about 30 minutes. We use DevOps to set everything up and it is effective because it is all scripted.

What about the implementation team?

The implementation was completed in-house.

What was our ROI?

Our service is incredibly profitable. We don't feel we can offer an alternative that will give us the same return on investment.

What's my experience with pricing, setup cost, and licensing?

The pricing is straightforward with no hidden costs. There is a cost for the licensing, the Virtual Network if the solution is run in Azure, and there is also a cost for the operational support.

I suggest sizing correctly when in the cloud because the skew can always be changed at a later time.

Which other solutions did I evaluate?

We've evaluated a couple of other products in the past to make sure that we still have the right solution in the market.

What other advice do I have?

I give the solution a nine out of ten.

The embedded machine learning included in the solution's firewall core used to provide inline real-time attack prevention is an important capability because it gives us the heuristics. The solution uses existing knowledge of the service and how we use the firewall, to determine if something nefarious is being undertaken. I don't believe that we are using the feature to its fullest capability.

We integrate Palo Alto NG Firewalls into Sentinel and we use additional data points to determine attacks.

We use the solution's DNS security for some of our clients.

We use a lot of data points from various systems and not only this solution to determine if a threat is live and active. We don't recommend publishing using the solution. We do local DNS resolution using the Palo Alto NG Firewalls. We're purely an Azure consultancy. We use Azure publishing services to publish. We integrate the solution into virtual networks from a DNS point of view, but we are always on the safe side, and we never use the solution for DNS publishing to the public internet. We are an ISB. We provide managed services, but we are primarily an integrator.

In terms of a trade-off between security and network performance, there will always be a performance lag when doing TLS inspections because the traffic has to be decrypted in real-time, however, the benefit outweighs the disadvantages from a network performance perspective. When the TLS inspections are sized properly, the performance lag is hardly noticeable.

We sometimes work with Palo Alto, for example, to support the default route over ExpressRoute.

The maintenance is all scripted and fully automated. We are always at the current stable release and we update as regularly as we get the updates from Palo Alto. There is no impact, no downtime, and no loss of service unless we've got a customer with a single firewall that requires a reboot, in which case we schedule the outage.

I have worked with many different appliances in Azure over the years, and I still do with some clients who already have incumbent NBAs, but for our firewall as a service, I have always used Palo Alto.

What we find is that clients want to utilize the features but don't know how to implement them or have the capability. We offer that support. Palo Alto is extremely good value for the money if we maximize its capabilities. If we want a cheap firewall, then Palo Alto isn't the answer. If we want a capable value-for-money firewall, when we are utilizing all of the services available, Palo Alto is the best on the market. If we want a cheap solution we can go to Fortinet which is not as technically sound but for someone who is price sensitive and doesn't want to use all the features and functions of Palo Alto NG Firewalls that is an option. We work with Palo Alto for our firewall as a service, and we work with Velo for our network as a service. The operational run cost for us is low with these vendors because those firewalls are extremely reliable and because we don't have problems with the firewalls, we don't need a big operational support team.

We did some work with the NHS Test and Trace program and they had a multi-client solution that we deployed hundreds of firewalls across Azure and AWS, using Palo Alto. The client did explore other vendors that were cheaper and after looking at the operational support capability, features, and how reliable the firewall was, the option was clear and not driven by price. 

I would automate the solution. I would use infrastructure as code deployment and manage my devices using IHC. If I was going for a larger state, I would use the solution's management tool.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Microsoft Azure
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
IT System Administrator at Bouri
Real User
Top 5Leaderboard
Oct 30, 2024
Enhanced backup and good security with room for simpler dashboard navigation
Pros and Cons
  • "The solution provides more security."
  • "The dashboard needs improvement as I find it more complicated compared to Sophos."

What is our primary use case?

We're using Palo Alto Networks NG Firewalls as a backup hardware solution. When the main firewalls have an issue, we're using the backup solution and hardware firewalls to avoid any network issues or prolonged downtime.

How has it helped my organization?

Palo Alto Networks Firewalls helped us reduce downtime. When we have another backup solution, the firewalls come down, we have backup hardware, and we have a Docker site that can work if we have an issue in our HQ data center.

What is most valuable?

Palo Alto provides more security. 

I have no issues if the subscription is renewed on time. 

What needs improvement?

Some configurations can take time.

The dashboard needs improvement as I find it more complicated compared to Sophos. It is not as user-friendly, especially when trying to easily check problems or generate reports which are easier with Sophos.

For how long have I used the solution?

I've used the solution for two years.

What do I think about the stability of the solution?

The solution is stable. It has a feature that allows load balancing across multiple lines. If one line drops, another line can maintain service until the issue is resolved and we return to the original line.

What do I think about the scalability of the solution?

The solution is scalable for large companies, however, it is expensive for medium and small companies.

How are customer service and support?

I would rate technical support from Palo Alto at an eight out of ten.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

We are still using a Sophos appliance as well. However, we are planning to consolidate to using just one solution soon.

How was the initial setup?

I was involved in the setup. I participated with the company that ran the implementation. They didn't provide me with most of the information necessary to help implement in other areas.

What about the implementation team?

The consultant company we're dealing with is the one handling the setup for this solution, not us. The consultant is a partner with Palo Alto.

What was our ROI?

As an investment, if you're going to use it for enterprise, it's good.

What's my experience with pricing, setup cost, and licensing?

The price of Palo Alto Firewalls is too expensive compared to Sophos licenses and appliance hardware.

What other advice do I have?

For medium companies, I would advise using Sophos. For larger enterprises, Palo Alto is more suitable.

I'd rate the solution seven out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Chuks Nkwoukwu - PeerSpot reviewer
Manager at Network International
Real User
Aug 17, 2024
It caters to all network sizes, provides a single-pane-of-glass, and helps reduce downtime
Pros and Cons
  • "The most valuable features are IPS and stateful inspection."
  • "Palo Alto Networks Next-Generation Firewalls are expensive and could become more competitive with reduced costs."

What is our primary use case?

We implemented Palo Alto Networks NG Firewalls as our intrusion prevention system to filter layer seven traffic and perform SSL inspection through deep packet inspection at the application layer.

We use Palo Alto Networks NG Firewalls for layer three packet filtering of east-west and north-south traffic and layer seven filtering through web filtering.

How has it helped my organization?

Palo Alto Networks NG Firewalls include Panorama, a unified platform providing a complete overview of our security features. This centralized management tool offers a single pane of glass for monitoring all security touchpoints through metrics, streamlining our network infrastructure protection. As a crucial component of our perimeter defence strategy, Panorama is integral to our overall network security priorities.

The machine learning feature embedded in Palo Alto Networks NG Firewalls for inline, real-time attack prevention is essential for proactive incident response and mitigation.

We realized their advantages within the first month of deploying Palo Alto Networks NG Firewalls. While those unfamiliar with the firewall's capabilities may not immediately recognize the benefits, those with a deeper understanding have seen positive results almost instantly.

Palo Alto Networks offers a diverse range of firewall models, catering to small offices, entry-level needs, and large data centres. This consistency in their product line allows them to effectively secure organizations of all sizes, from small to medium-sized businesses to extensive data centres. Considering their out-of-the-box protection across different work environments, I would give Palo Alto Networks a rating of nine out of ten for consistency.

Palo Alto Networks NG Firewalls have helped our organization reduce downtime by safeguarding against DDoS attacks, phishing attempts, and other malicious threats. These firewalls effectively prevent unauthorized access to our enterprise infrastructure.

What is most valuable?

The most valuable features are IPS and stateful inspection. Stateful inspection simplifies firewall management by automatically allowing return traffic for established connections, eliminating the need to create separate policies for inbound and outbound traffic within the same session.

What needs improvement?

Palo Alto Networks Next-Generation Firewalls are expensive and could become more competitive with reduced costs.

For how long have I used the solution?

I have been using Palo Alto Networks NG Firewalls for five years.

What do I think about the stability of the solution?

Palo Alto Networks NG Firewalls are highly stable.

What do I think about the scalability of the solution?

Since Palo Alto Networks NG Firewalls are physical hardware devices, they offer scalability but are limited by the hardware's capabilities.

How are customer service and support?

The technical support of Palo Alto is fantastic.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

I previously used Cisco ASA firewalls but switched to Palo Alto Networks NG Firewalls because Cisco ASA does not offer next-generation firewall capabilities like stateful.

How was the initial setup?

The deployment was straightforward, even though we received some assistance from Palo Alto engineers.

The deployment was completed in five days. Prior to execution, we planned the integration of the firewall into our infrastructure. This high-level plan involved identifying the network, provisioning the firewall, connecting network cables, configuring the firewall, and conducting tests.

What was our ROI?

Our logs indicate a significant number of attempted unauthorized access or attacks on our infrastructure, which the Palo Alto NG Firewalls have successfully blocked. Given this evidence of the firewall's effectiveness in protecting our systems, I believe it demonstrates a strong return on investment.

What's my experience with pricing, setup cost, and licensing?

Palo Alto Networks NG Firewalls are expensive.

What other advice do I have?

I would rate Palo Alto Networks NG Firewalls ten out of ten.

Even though Palo Alto might be more expensive, I would always recommend it because you typically get better equipment for your investment.

Occasionally, we need to upgrade the operating system, which is considered maintenance. Although we have a high availability setup with two firewalls, an active one and a backup, they typically run continuously without issues.

We have 1,000 users across multiple locations that utilize Palo Alto Networks NG Firewalls in our organization.

I recommend always having a proper plan and considering not only the cost but also the technical benefits in terms of the next-generation firewall features offered by Palo Alto.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Janardhan Reddy - PeerSpot reviewer
Manager-Information Technology at a computer software company with 51-200 employees
Real User
Jul 18, 2024
Has geofencing features and helps to prevent security holes by 70-80 percent
Pros and Cons
  • "The tool's most valuable features are its security features, which are highly valued based on market standards and Gartner reports. We conducted a POC before procuring it, and from that perspective, it is very good. The machine learning feature helps prevent more threats, but no device or firewall can be 100 percent secure because threats evolve daily."
  • "The setup was complex. We have perimeter firewalls and multiple voice devices handling calls. Directing traffic through gateway perimeter firewalls becomes quite complex in such a scenario. The implementation took around two months and required three to four people for deployment."

What is most valuable?

The tool's most valuable features are its security features, which are highly valued based on market standards and Gartner reports. We conducted a POC before procuring it, and from that perspective, it is very good. The machine learning feature helps prevent more threats, but no device or firewall can be 100 percent secure because threats evolve daily.

We use geofencing in our firewalls to prevent unknown attacks from other countries. The solution stops these attacks in the cloud so they don't reach my firewall. Only allowed countries can access it.

The solution provides a unified platform that natively integrates with other security platforms. It is a must as a compliance requirement and aligns with standard security best practices. The platform also helps to prevent security holes by 70-80 percent. 

We have implemented the Zero-Delay Signature feature. It is important to prevent unwanted network penetration and information theft, so having it in the firewall at the gateway level is mandatory. 

What needs improvement?

The setup was complex. We have perimeter firewalls and multiple voice devices handling calls. Directing traffic through gateway perimeter firewalls becomes quite complex in such a scenario. The implementation took around two months and required three to four people for deployment.

For how long have I used the solution?

I have been working with the product for four years. 

What do I think about the stability of the solution?

Palo Alto Networks NG Firewalls' stability is very good. 

What do I think about the scalability of the solution?

Based on our expected growth, we have some buffer and procured a model that offers an additional 10-20% capacity. Around 1,500 people in our company use it, and two to three administrators manage it around the clock. Currently, we have no plans to increase usage.

How are customer service and support?

The technical support is very good. We log a call and get a response within five to ten minutes. If there is any critical issue, they get on a call and resolve it. We opt for OEM direct support. It depends on whether an integrator will assist us or we must log in through the portal. 

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

I decided to switch from FortiGate to Palo Alto Network NG Firewalls because we found that it performs better regarding security standards. It's considered an industry standard.

What about the implementation team?

A system integrator helped us with the implementation. 

What's my experience with pricing, setup cost, and licensing?

Cost-wise, I don't see much difference in network-related costs, but this is a premium-grade firewall. There is a cost involved, and you must pay for that to get the most out of it. Its licensing costs are straightforward. There aren't any hidden costs. 

What other advice do I have?

I need to check DNS security with Palo Alto Firewalls. I set it up initially, but my team manages it daily. I approve any changes, but my team handles the hands-on work. I can't say all tools will be integrated, but other tools might also be needed based on our business and use cases. This alone might not suffice.

Network performance is okay but not great because multiple hops are involved. Each tool, like an endpoint with antivirus, scans the traffic before it moves to the firewall, which also scans it before sending it out. So, there will be some performance regulation. We cannot expect 100% performance in any network once you have any firewall with all the built-in security features implemented.

When I recommend the tool to others, I first check their business needs and understand what they're looking for. If they're focused on security posture and are ready to invest, I'd recommend Palo Alto Networks NG Firewalls. But if they want something cheap, I'd suggest options like FortiGate or SonicWall. Also, I'd check if they have the in-house skills to manage it day-to-day.

I'm familiar with the PA-400 series of Palo Alto Networks NG Firewalls. It's good for small offices, and we use the same series in one of our branch offices. 

I've learned that using this solution is a continuous learning process. Every day, I analyze and evaluate the differences between each product to see if it meets our business requirements and is cost-effective. I rate it a ten out of ten. 

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Download our free Palo Alto Networks NG Firewalls Report and get advice and tips from experienced pros sharing their opinions.
Updated: September 2026
Product Categories
Firewalls
Buyer's Guide
Download our free Palo Alto Networks NG Firewalls Report and get advice and tips from experienced pros sharing their opinions.