In my role as a tech, I provided support for various firewalls, including the PA, PM, and virtual series. It wasn't limited to a specific product like the PA-800 series, PA-1000 series, PA-9000 series, PA-7000 series, or PA-5000 series. We received training for all firewall types.
Associate Process Manager at a computer software company with 5,001-10,000 employees
Offers trained customer support, stability and ease of use
Pros and Cons
- "It is scalable. But that depends on what model you are using."
- "There are constant updates for the operating system. It is a nice thing also, but it has its own disadvantages. Continuous updates are there. The users face issues like, how often do I need to update that? Within a period of five months, I'm updating it two or three times. It gives them a feeling that they are not confident about their product and have to update it so frequently."
What is our primary use case?
How has it helped my organization?
Palo Alto gives proper training for the product, not cutting corners over that. They don't assume you have previous knowledge and experience and start working directly, which happens in most companies.
So, they provide product training very thoroughly. This helps the support system to have the necessary knowledge, not just before starting to work or troubleshoot.
In the 11 months, we were initially trained on various OS versions and given tools like vSphere because we didn't have access to the Palo Alto environment.
Later, when we got access, we were given a tool to design our own networks, study them, and, if needed, raise concerns about issues.
The engineers or senior engineers would then study and guide us. They trained us for new upgraded versions of the OS regularly. Even as a third party, we had complete access to the Palo Alto Networks domain, tools, database, knowledge base, and everything.
This gave us the opportunity to build our skills and understand what Palo Alto requires us to do. We could troubleshoot it properly with customers.
What is most valuable?
What needs improvement?
There are constant updates for the operating system. It is a nice thing also, but it has its own disadvantages. Continuous updates are there. The users face issues like, how often do I need to update that?
Within a period of five months, I'm updating it two or three times. It gives them a feeling that they are not confident about their product and have to update it so frequently.
Plus, there are certain bugs, like in the 10.1 version, it's had some bugs. Then, they are upgrading it to the 10.2 version. They are updating that for the bugs. But the time duration between the two is less than the others.
If we go for Cisco, they don't have their OS upgrades frequently as parallel to us. So that's the disadvantage.
Buyer's Guide
Palo Alto Networks PA-Series
June 2026
Learn what your peers think about Palo Alto Networks PA-Series. Get advice and tips from experienced pros sharing their opinions. Updated: June 2026.
902,456 professionals have used our research since 2012.
For how long have I used the solution?
I was working on a project outsourced from Palo Alto to a company. I was employed in that company for 11 months. During that time, I received guidance and training directly from Palo Alto Networks. I served as a tech engineer for the entire duration. It was quite recent, about three or four months ago.
What do I think about the stability of the solution?
It is stable. It's just the thing about the frequent updates. So that's the only issue there. So if they somehow reduce that frequency, all these will be easy.
What do I think about the scalability of the solution?
It is scalable. But that depends on what model you are using.
However, other PA-Series models, such as the device on the APAC, are highly scalable and support other vendors.
Moreover, within the network, the device is scalable.
How are customer service and support?
The customer service and support are really good. And they continuously ask the support team to go through some training updates. So, continuously, we have these updates on the KPIs on a knowledge basis. And the last time, we had this training on the latest version upgradation. So they continuously give the training.
Which solution did I use previously and why did I switch?
How was the initial setup?
I was physically present during the setup processes because many times, customers come saying, "I have purchased this new product, but I don't know how to install it."
There were two teams: the sales team was there, and they had their own engineers. They used to provide the customers.
But at times, we also had to get involved in case there were any technical glitches or issues because the sales engineers did not do troubleshooting.
So for that, some of our engineers got involved. At that time, we used to give the setup, whether it was a VM, a cloud, or a physical device.
At times, customers lack the knowledge of installing and deploying it into the system. So, we used the knowledge base to supply them with articles on the basic level. But even if the customer couldn't understand that, then we used to set it up ourselves directly.
The setup and everything was pretty much given in the KB articles in the knowledge base. So that was pretty much good. And if the customer is not able to understand, then I used to do that.
What about the implementation team?
I supported both the cloud version, which is a VM version and the physical device.
For the cloud deployment of this product, you don't need to buy physical hardware, a modular device from Palo Alto, which is cost-effective and cost-efficient. It can be deployed in AWS or Azure, any cloud provider.
However, the disadvantage or the downside, I can say, is that it is on another network and it is software-based. It is not 100% under your control because it is mostly connected to the AWS or Azure environments. Some controls are not 100% with the user.
If I deploy a VM on the Azure network, then I have to define something compatible with the Azure network. That is the con for cloud deployment. But if the user needs cost-effective solutions, they can go for the cloud.
With the physical device or hardware, it is under your control. You can manage it properly and get excellent tech support directly from Palo Alto, unlike the cloud, where support has to be from both ends.
Sometimes, this creates confusion or complexity, but not always, but it may create complex support. In the case of the physical device, it does not because it is provided by one single vendor.
The disadvantage is that Palo Alto devices are costlier than other devices in the market, like Fortinet or CheckPoint. However, Palo Alto has an advantage in continuously striving to provide better support and upgrading their software or operating system.
On average, the time taken to deploy the solution actually depends on what the environment is and what other vendors are connected to it. So, if it is a Cisco router, where is it connected with what else is in the environment? It actually depends on that.
And it also depends on how much the customer has, like network knowledge. So, if they need to have some policies to block or allow, IP addresses, and more, if they have all that handy, then it is like two hours or something, not more than that. So it's pretty well done. It is a faster thing. But if the customer is not that handy, then it makes it difficult for us.
Maitaince is not required unless there is some issue, like a manufacturing defect once or twice. It wasn't, of course, too many times.
But sometimes, it occurs because the device gets old or there is a manufacturing defect. It was a hardware replacement directly. So, it was pretty much good. That process was a piece of cake.
Palo Alto Networks has a program that allows customers to transfer their device licenses to another company. This means that if you have purchased a Palo Alto Networks firewall and you no longer need it, you can sell it to another company, and they will be able to transfer the license to their name. But for that, I need to go to Palo Alto and first discuss it with them. So they have this other team. So they check and verify everything.
This is something that I have never encountered with any other vendor.
What's my experience with pricing, setup cost, and licensing?
The pricing is a bit on the higher side but it is reasonable because they give that kind of level of support and everything else.
What other advice do I have?
Overall, I would rate the solution an eight out of ten. The one con is that it's a little more expensive than others. But the pros here are that it has good support.
Overall, it is a good product, and you can definitely have it with other vendors. So it doesn't have any issue. If you only have Palo Alto, you cannot have others in the environment. You can definitely have others connected there. There is no issue.
And the technical support team is also there to guide you. It's a very good team. So you can always go ahead and purchase Palo Alto. It's a little bit pricier than others. But it is worth it because you'll get other support and everything is very good.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Deputy senior network engineer at a manufacturing company with 201-500 employees
Provides excellent features and documentation and enables users to connect to the internet securely
Pros and Cons
- "The documentation is great."
- "The web interface is slow."
What is our primary use case?
We use the solution to connect to the internet. It is for a company that produces dog and cat food. We have enabled threat prevention.
What is most valuable?
The product makes me and my users feel safe. I like the URL filtering. I don't have to change or add something. I like the security analyzer a lot. I use it a lot to see if there are any configuration errors. It points me in the right direction. The documentation is great. We can find everything we want in the knowledge base. We can learn how to set things up. It is understandable. Even I know how to do it.
What needs improvement?
The web interface is slow. It is a pain. However, the rest of the device does what it's supposed to do. I rate the web interface a two or three out of ten. I rate the rest of the solution seven or eight out of ten. Integrating the tool into our security system was not quite easy. It has a steep learning curve. We have to think about things like security profiles. It would be nice if the vendor provided a penetration testing tool.
For how long have I used the solution?
I have been using the solution for a year and a half.
What do I think about the stability of the solution?
I rate the tool’s stability a nine out of ten.
What do I think about the scalability of the solution?
The box is a bit small for us. I think it is a purchasing error, though. We have 300 users.
How was the initial setup?
I rate the ease of setup a six out of ten.
What's my experience with pricing, setup cost, and licensing?
The licensing is great. We renew it, and it works. The pricing is fair. I rate the pricing a five out of ten.
Which other solutions did I evaluate?
We also use CrowdStrike for threat prevention. The Check Point products I worked with were very old. I have also used OPNSense and pfSense. OPNSense and pfSense are open-source solutions.
What other advice do I have?
We don't do much decryption of the encrypted traffic. I will recommend the tool to others. Overall, I rate the solution an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Palo Alto Networks PA-Series
June 2026
Learn what your peers think about Palo Alto Networks PA-Series. Get advice and tips from experienced pros sharing their opinions. Updated: June 2026.
902,456 professionals have used our research since 2012.
Team Lead, Infosec & Netsec Unit at Microgenesis Business Systems
Enabled us to monitor remote workers and take necessary actions, such as blocking problematic IP addresses
Pros and Cons
- "A valuable feature that we can consider is the deployment time, which is significantly reduced. It is almost 90% faster compared to other solutions."
- "As we migrate fully into the cloud, additional features like capacity upgrading and improvements to hardware resources will be necessary, especially since our equipment consists of older-generation switches and routers."
What is our primary use case?
There are various use cases, particularly for desktop scenarios. One of them involves exploring contacts. Virtual firewall use cases revolve around different scenarios, such as transitioning to the cloud. For instance, when Barclays uses Azure or AWS, there's a focus on meeting security obligations and implementing threat prevention to comply with regulations like GDPR or PPA. This includes creating segmentation to align with regulatory standards. As part of this process, security features available in cloud platforms like virtual firewalls and threat prevention are incorporated.
How has it helped my organization?
After the implementation here, especially since I work in the data center, I've noticed the significance of security. For example, Veeam, CDL, and other aspects became crucial, especially during the COVID period when users started working from home. This situation led to numerous blocks, and user profiles were getting blocked due to issues with IP addresses ending up on blocked lists. However, after implementing the 3M series virtual firewall, we were able to effectively manage security for our cloud applications, like those in AWS. This enabled us to monitor remote workers and take necessary actions, such as blocking problematic IP addresses. Consequently, we reduced the number of tickets raised with ISP providers.
What is most valuable?
A valuable feature that we can consider is the deployment time, which is significantly reduced. It is almost 90% faster compared to other solutions. This leads to quicker deployment and less downtime.
What needs improvement?
I have found that the tool works well for me, but there are areas where security testing and protection could be improved, especially in virtual or cloud environments. However, in this project, once we deployed it, we haven't encountered any issues.
The cost is currently manageable, but as we migrate fully into the cloud, additional features like capacity upgrading and improvements to hardware resources will be necessary, especially since our equipment consists of older-generation switches and routers. So, I'm looking for additional capabilities in these areas.
For how long have I used the solution?
I've been working on my current project for more than two years now.
What do I think about the stability of the solution?
I would rate the stability a nine out of ten.
What do I think about the scalability of the solution?
I would rate the scalability an eight and a half out of ten.
How was the initial setup?
The deployment is quite straightforward, and it's faster than it used to be. This means that there is less downtime involved.
What's my experience with pricing, setup cost, and licensing?
From my perspective, managing the price is important, especially because we're a small business. For larger organizations like Barclays, we provide our requirements to the client, and they place the order on BigFix. It's their responsibility to consider their budget and make decisions accordingly. We appreciate the features we get, but the cost-sharing still depends on the client.
Which other solutions did I evaluate?
The client needs to provide approval for the POCs used by our team; it's not within my control.
What other advice do I have?
When evaluating options, you should consider team members who are knowledgeable in supporting next-generation firewalls like NGFW. We also need to factor in the specific product offerings. For instance, if we have options like the PA-440, PA-850, and PA-8350, we should compare their prices and features. It's important to make decisions based on the situation and the needs of the organization.
Considering factors like availability and the specific situation, I would rate this an eight. It's important to explore other potential cases as well.
I would rate the solution a nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Integrator
IT Coordinator at CSA Makati
Customizable features enhance threat prevention capabilities
Pros and Cons
- "The most valuable feature of Palo Alto Networks PA-Series is that it is highly customizable."
- "The initial setup of Palo Alto Networks PA-Series is very complicated."
What is our primary use case?
The primary use case for Palo Alto Networks PA-Series is for the previous firewall.
What is most valuable?
The most valuable feature of Palo Alto Networks PA-Series is that it is highly customizable. So far, it works well in terms of threat prevention capabilities.
What needs improvement?
The interface of Palo Alto Networks PA-Series should be made much more user-friendly.
For how long have I used the solution?
I have used Palo Alto Networks PA-Series for five years.
What do I think about the stability of the solution?
I rate the stability of Palo Alto Networks PA-Series as nine.
What do I think about the scalability of the solution?
I rate the scalability of Palo Alto Networks PA-Series around seven.
How are customer service and support?
I rate the technical support from Palo Alto Networks as eight.
How would you rate customer service and support?
Positive
How was the initial setup?
The initial setup of Palo Alto Networks PA-Series is very complicated.
What was our ROI?
The same device has been used for nine years and could be cost-effective.
What's my experience with pricing, setup cost, and licensing?
The price of Palo Alto Networks PA-Series is expensive.
What other advice do I have?
Although I would recommend Palo Alto Networks PA-Series to others, it would depend on budget and familiarity with the system. If they have the budget and know-how, it might be suitable. However, for users not accustomed to using Palo Alto, I would not suggest it. Overall, I rate this solution as an eight.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
IT Manager at a computer software company with 51-200 employees
Offers web filtering and application filtering and good multi-site environment
Pros and Cons
- "The cloud-based aspect helps significantly. It integrates seamlessly with other Palo products like Prisma Cloud, offers robust VPN protection, and it's all in one convenient package."
- "The UI definitely needs work. In my opinion, the UI could be simpler and more user-friendly for the average user."
What is our primary use case?
It's our basic firewall, mainly web filtering and application filtering. We use it in a multi-site environment, especially with cloud-based firewalls.
What is most valuable?
Web filtering and application filtering are the most valuable features.
The cloud-based aspect helps significantly. It integrates seamlessly with other Palo products like Prisma Cloud, offers robust VPN protection, and it's all in one convenient package.
What needs improvement?
The UI definitely needs work. In my opinion, the UI could be simpler and more user-friendly for the average user.
For example, I encountered complexities with policy management. Policy management is one of the areas where the UI is not intuitive, and managing policies can be quite complex.
For how long have I used the solution?
I have been using this solution for one year. We work with all the technologies from Palo.
What do I think about the stability of the solution?
It is a stable product. I would rate the stability a nine out of ten.
What do I think about the scalability of the solution?
I would rate the scalability a ten out of ten because cloud deployment makes it incredibly easy to scale.
High-tech, multi-site, or multi-region companies, regardless of size, can benefit from Palo Alto.
How are customer service and support?
Faster response times would be more beneficial.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I have experience with Palo Alto's PA-Series and Fortinet FortiGate.
However, my preference depends on the setup. If I'm looking at a single site, a straightforward deployment, I'd go with FortiGate.
If I'm looking at multi-site, complex deployments and a cloud-based design, then Palo Alto.
How was the initial setup?
The initial setup is fairly complex. There's a definite learning curve involved in setting it up correctly.
What about the implementation team?
We require assistance from a third-party company for the setup.
What's my experience with pricing, setup cost, and licensing?
The prices are pretty high, definitely on the upper end. They're among the highest in the pricing tier Firewall category.
What other advice do I have?
In general, I'd rate this solution at least an eight out of ten. It has some room for improvement.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Technical Lead at Happiest Minds Technologies
An exceptionally stable tool that offers updates and fixes every two or three months
Pros and Cons
- "It is a stable solution. Stability-wise, I rate the solution a ten out of ten."
- "With Palo Alto Networks PA-Series, I find that the support team takes a long time to resolve the issues that a user may face during the use of the product."
What is our primary use case?
My company operates at multiple sites. My company has multiple work-related departments, and for each department, we have multiple servers along with multiple printers and other devices. My organization has to restrict certain accesses based on company policies. Generally, my company has to look after what accesses are to be allowed and which are not to be allowed, based on source and destination. If some business cases require some access, then our company allows access for those on the firewall.
What is most valuable?
Palo Alto Networks generally offers some very good features, like antivirus, DLP, URL filtering, and dynamic blocking. All the attributes offered by Palo Alto Networks are quite good and fall under the next-generation firewall features.
What needs improvement?
With Palo Alto Networks, every two or three months, there are some updates or bug fixes that happen. Everything is good with Palo Alto Networks.
With Palo Alto Networks PA-Series, I find that the support team takes a long time to resolve the issues that a user may face during the use of the product. You need to keep describing your issues to the support team since Palo Alto Networks usually provides you with a few engineers who then connect you with another set of engineers, making it a long process. When it comes to the support offered by Palo Alto Networks, our company has seen that we need to escalate an issue to senior management, which takes a lot of time. The support part of the product can improve a little bit.
For how long have I used the solution?
I have experience with Palo Alto Networks PA-Series. My company has a partnership with Palo Alto Networks. I use the solution's recent version, which is PAN-OS 10.0.
What do I think about the stability of the solution?
It is a stable solution. Stability-wise, I rate the solution a ten out of ten.
What do I think about the scalability of the solution?
Scalability-wise, I rate the solution an eight and a half out of ten.
More than 5,000 people in our company use Palo Alto Networks PA-Series.
How are customer service and support?
I rate the technical support an eight out of ten.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
Earlier, my company was involved with Cisco ASA Firewall and Check Point Software.
How was the initial setup?
The product's initial setup was easy.
The solution is deployed on an on-premises model.
If you are involved in the initial configuration part, then the deployment process related to the product may take around two or three hours.
What other advice do I have?
I rate the overall tool a nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer.
Cyber Security Solutions Technology Consultant at a tech services company with 51-200 employees
Easily adds new functions to existing hardware without any performance degradation and offers good network visibility and control
Pros and Cons
- "It offers application-based policy enforcement. Palo Alto Networks firewalls help us recognize protocol anomalies, contrasting with other vendors that may require policies based on port numbers. With Palo Alto Networks, the port number isn't a constraint because their devices handle protocol traffic at Layer 7, allowing for accurate identification of protocol usage and port numbers. They can identify which protocol actually uses which port."
- "In future releases, maybe Palo Alto can enhance and enlarge their portfolio with SIEM solutions. They already have an endpoint protection solution, SOAR solution, that's fine. But when it comes to standalone IDS/IPS solution or email security solution, for example, we don't have any product in that category for Palo Alto."
What is our primary use case?
We use Palo Alto Networks firewalls for our perimeter security defense.
How has it helped my organization?
We use it for threat prevention in our networks. Check permission, advanced URL filtering, and DNS security. There are different subscriptions, and we are actually using them all.
We are really satisfied with the firewall's throughput and its threat prevention performance regarding network traffic. We can easily decrypt our SSL traffic and thanks to the technology named App-ID, it recognizes network protocols without relying on port numbers.
It operates at Layer 7, and its ability to recognize protocols even if they use a default port for another protocol is impressive. It alerts you to such anomalies.
The single-pass architecture technology is particularly noteworthy because it allows for the addition of new functions to existing hardware without any performance degradation, even when all modules, like self-encrypted encryption, malware protection, threat protection, and industrial filtering, are enabled. This results in outstanding performance.
That's why we use Palo Alto Networks in our IT firm and recommend their devices to all our customers.
We also have functions related to network visibility and control. We use Panorama controllers, which operate in a geographically distributed architecture, allowing us to easily control, configure, and manage network devices.
With single-touch provisioning, you can effortlessly add new files to your Panorama VM. It offers extensive features that we currently use.
Panorama is a Palo Alto Networks product optimized for firewalls. As for integration, we can easily integrate the PA-Series with popular brands, switches, and routers like Cisco, Extreme Networks, or HP Aruba across your local area network's switches and routers, enhancing application-based policy enforcement.
What is most valuable?
It offers application-based policy enforcement. Palo Alto Networks firewalls help us recognize protocol anomalies, contrasting with other vendors that may require policies based on port numbers.
With Palo Alto Networks, the port number isn't a constraint because their devices handle protocol traffic at Layer 7, allowing for accurate identification of protocol usage and port numbers. They can identify which protocol actually uses which port. So, if there's an unplanned issue, like, for example, a hacker trying to create a DNS tunnel using a non-standard port (like 1536 instead of the usual 53), Palo Alto's Endpoint UI will easily detect it and allow you to take measures.
PA-Series includes built-in network packet brokers, a valuable feature as it allows SSL traffic to be decrypted just once. If you need to inspect this decrypted traffic further, there's no need for a third-party solution—Palo Alto Networks firewalls handle it themselves.
What needs improvement?
In future releases, maybe Palo Alto can enhance and enlarge their portfolio with SIEM solutions. They already have an endpoint protection solution, SOAR solution, that's fine.
But when it comes to standalone IDS/IPS solution or email security solution, for example, we don't have any product in that category for Palo Alto.
For how long have I used the solution?
I have been using it for two years.
What do I think about the stability of the solution?
It's very reliable. Even if you have only one firewall, failures are rare. Moreover, the high availability feature allows two firewalls to sync with each other for continuous operation, ensuring stability.
How are customer service and support?
The customer service and support are good. Both local and global support teams are readily accessible and they report back in a short period. I've never encountered any issues with their support.
How would you rate customer service and support?
Positive
How was the initial setup?
The setup's ease depends on your experience and the resources at hand, like Palo Alto Networks' documentation. With the right information, it's not a problem.
For me, the deployment took around 30 minutes.
What's my experience with pricing, setup cost, and licensing?
Many people think Palo Alto firewalls are expensive, but I don't feel that way. Let's compare it with Fortinet firewalls.
With Fortinet, every two or three years, the firewall generation changes, and they have limited support for older devices. But with Palo Alto, you still get support from the vendor for seven or eight years.
Also, many vendors prepare data sheets for their firewalls with most features disabled. For example, they might say their firewall has 20 gigabit throughput, but they don't mention if threat prevention or service encryption is on or off. With Palo Alto, even when you enable all the modules, it still provides the exact throughput they advertise.
If you're buying two firewalls, one from Fortinet and one from Palo Alto, both rated at 20 gigabit throughput, and you enable all the modules on the Fortinet one, it might downgrade to 10 or even 5 gigabit throughput. But with Palo Alto and all security modules enabled, you still get the full 20 gigabit throughput.
That's the key difference. That's why customers trust Palo Alto, and that's why it's a big player in network security.
What other advice do I have?
Overall, I would rate the solution a ten out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. reseller
Director of Sales at S4E Serbia
Efficient threat prevention and network protection with intuitive user interface, flexible licensing bundles and robust technical support
Pros and Cons
- "Comprehensive logging is essential for monitoring and analysis purposes. For remote users, the firewall can be configured as a VPN concentrator, with VPN policies defined within the firewall settings."
- "Utilizing these features as a unified solution can require additional setup, particularly when incorporating Panorama for centralized management, which may involve extra costs."
What is our primary use case?
Our clients primarily utilize the Palo Alto Networks PA-Series as a VPN concentrator and next-generation firewall, particularly at the internet perimeter in Serbia. This setup effectively shields them from online threats and grants control over end-user activities, including website access.
How has it helped my organization?
The PA-Series has significantly enhanced our company's cybersecurity stance by providing us with comprehensive control over users and applications. With advanced inspection capabilities, we effectively scrutinize all network traffic, allowing only known users and applications to pass through the firewall.
When discussing threat prevention, key features essential for effective protection include thorough threat inspection, including virus and malware detection, as well as functioning as an Intrusion Prevention System. With comprehensive threat inspection, all potential threats are thoroughly analyzed, ensuring maximum security. Integrating Palo Alto Networks' Cortex XDR on endpoints further enhances threat prevention capabilities. This combination enables centralized analysis of security events from both the firewall and endpoints, facilitating a more comprehensive threat analysis and response strategy.
The benefits we've observed in Secure Traffic Management using the PA-Series are significant. Palo Alto Networks revolutionized firewalls with the invention of next-generation firewalls. Unlike other vendors who added this functionality to existing firewalls, Palo Alto Networks built their user interface from scratch, resulting in an exceptionally intuitive interface. Administrating the PA-Series is straightforward and user-friendly, requiring minimal time for users to become accustomed to it. Additionally, having everything accessible from one console enhances efficiency and streamlines management processes.
What is most valuable?
Security features like threat prevention, URL filtering, and DNS traffic inspection are crucial components of our setup. We also implement LightFire sandboxing for analyzing unknown files. Encryption of traffic is enabled, with careful consideration given to which traffic should be decrypted for inspection.
Comprehensive logging is essential for monitoring and analysis purposes. For remote users, the firewall can be configured as a VPN concentrator, with VPN policies defined within the firewall settings.
What needs improvement?
C Palo Alto Networks firewalls can be somewhat complex due to the various options available. They offer different devices and subscription models, including standalone firewalls and bundled options. Utilizing these features as a unified solution can require additional setup, particularly when incorporating Panorama for centralized management, which may involve extra costs.
For how long have I used the solution?
I have been working with it for over ten years.
What do I think about the stability of the solution?
Stability is crucial when considering which version of the operating system to use for Palo Alto Networks devices. Recommendations provided on the Palo Alto webpage suggest opting for the most stable version available. Users often refrain from immediately adopting new releases due to potential instability. Instead, they wait until the release has proven its stability, a practice commonly observed with other vendors as well. Therefore, it is advised not to constantly pursue the latest release but to prioritize stability when making decisions.
What do I think about the scalability of the solution?
Scalability with hardware firewalls is limited, as increased user numbers or higher throughput may push the firewall close to its maximum capacity. In such cases, purchasing a new device becomes necessary, as there is no inherent scalability. However, with virtual firewalls, scalability is simpler as additional credits can be purchased without new hardware. For instance, our customers typically upgrade to newer models every four years.
How are customer service and support?
For technical support, I would rate it a solid ten. Our support team in Serbia is highly regarded and often considered one of the best in Europe. We provide exceptional support services, and even for the most challenging cases, Palo Alto Networks is deeply involved, ensuring that complex issues are addressed effectively. Our commitment to providing top-notch support ensures our customers receive the assistance they need, contributing to our reputation for excellent support services. For example, certain issues are not directly related to Palo Alto Networks' products. They often stem from users employing various solutions from different vendors, resulting in integration challenges and overall system malfunctions. In such cases, Palo Alto Networks' support assists in identifying whether the issue originates from their products or other vendors' solutions. The focus lies in troubleshooting the entire integrated setup to pinpoint the source of the problem accurately.
How would you rate customer service and support?
Positive
How was the initial setup?
The deployment process is generally straightforward, but its ease can vary depending on the complexity of the customer's network and specific requirements. While deployments for institutions like banks may be more intricate and time-consuming, deployments for typical companies are relatively simple. I would rate it nine out of ten.
What about the implementation team?
In our cloud network infrastructure, we maximize efficiency by deploying the PA-Series focusing on redundancy and advanced security measures. Typically, we set up two devices in a high-availability configuration to ensure uninterrupted operations. This setup synchronizes sessions between devices, eliminating single points of failure within the network. Some users with budget constraints opt to purchase a spare device without licenses. In the event of a failure in the primary device, they can quickly switch configurations to the backup device, although this process may take some time. On the network perimeter, we prioritize next-generation firewall features such as user identification, achieved through integration with Active Directory. This enables us to create policies based on user groups rather than IP addresses. Additionally, we utilize Palo Alto's application recognition capabilities to control application usage, allowing only approved applications while blocking others.
Maintenance is straightforward and can be handled adequately by a single individual.
What's my experience with pricing, setup cost, and licensing?
The PA-Series includes various subscriptions such as URL filtering, sandboxing, and DNS security. The Alto license is also bundled with the device, simplifying the purchasing process. Other optional licenses include GlobalProtect for remote VPN access and an IoT license for managing internet of things devices.
Licensing is now simplified with Palo Alto Networks offering bundles of licenses, available for purchase over the past few years. These bundles, typically priced around forty percent lower than individual licenses, include essential features such as threat prevention, URL filtering, DNS security, LightFire, and SD-WAN. Users can easily acquire the device, bundle subscriptions, and support package, comprising support and device warranty. Some users opt for additional licenses like GlobalProtect, which may not be included in the bundle. Licensing options range from one to three years, with easy renewal upon expiration. The cost varies depending on the device model, with entry-level firewalls priced around $1,300 to $1,500, while higher-end models can reach prices of several hundred thousand dollars. Ultimately, the cost is influenced by factors such as the number of users and specific requirements.
What other advice do I have?
Overall, I would rate it ten out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
Business Development Manager at ISTT
Easy to use and offers a good user interface
Pros and Cons
- "The product's initial setup process was simple."
- "The product's high prices are an area of concern where improvements are required."
What is our primary use case?
I use the solution in my company to protect our networks.
My company provides Palo Alto Networks PA-Series to our customers. My company takes care of the product's integration part for our customers.
What is most valuable?
The most valuable features of the solution are its areas like performance and stability.
What needs improvement?
The product is perfect, in my opinion. The product's high prices are an area of concern where improvements are required.
For how long have I used the solution?
I have been using Palo Alto Networks PA-Series for seven years. My company operates as a system integrator for Palo Alto Networks. My company also has a partnership with Palo Alto Networks.
What do I think about the stability of the solution?
Stability-wise, I rate the solution a nine out of ten.
What do I think about the scalability of the solution?
Scalability-wise, I rate the solution a nine out of ten.
The product is suitable for enterprise-sized companies.
How are customer service and support?
I have contacted the solution's technical support. I rate the technical support an eight and a half out of ten.
How would you rate customer service and support?
Positive
How was the initial setup?
I have deployed the product in a multi-site environment.
The product's initial setup process was simple.
The product's deployment and configuration phases are easy.
The solution is deployed on an on-premises model.
Not too much time is required to deploy the product.
What's my experience with pricing, setup cost, and licensing?
The product is offered to users at high prices compared to the pricing model of the other vendors in the market.
Which other solutions did I evaluate?
I feel that Palo Alto Networks PA-Series offers better performance when compared to the other vendors in the market.
What other advice do I have?
I don't have many details about the product's application control and visibility features since I had to deal with a lot of features in the tool during the deployment of the solution for our company's customers.
The tool is good enough to deal with cyberattacks and meet the requirements of our company's customers.
Considering the product's usability and user interface, I would say that it is easy to use the tool.
I recommend the product to those who plan to use it.
I rate the tool a nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner/Integrator
Automation-OT Manager at a non-profit with 1,001-5,000 employees
Offers a user-friendly interface, customizable security options, and ease of management and deployment
Pros and Cons
- "The most effective features for threat prevention in the PA-Series are its integration with Cortex and the use of machine learning AI for advanced threat detection."
- "There is room for improvement in streamlining this process for smoother transitions."
What is our primary use case?
In our network security architecture, we utilize the PA-Series firewalls by integrating them seamlessly. Migration from Cisco to PA-Series was surprisingly easy, and we have centralized management using Panorama.
What is most valuable?
The most effective features for threat prevention in the PA-Series are its integration with Cortex and the use of machine learning AI for advanced threat detection. These capabilities, especially present in the newer generation firewalls like the PA-4000 series, enhance our security posture significantly.
What needs improvement?
Migrating from old to new Palo Alto Networks firewalls can sometimes encounter hiccups, and there is room for improvement in streamlining this process for smoother transitions.
For how long have I used the solution?
I have been working with Palo Alto Networks PA-Series for nine years.
What do I think about the stability of the solution?
I would rate the stability of the product as a nine out of ten. We have not faced any issues with it.
What do I think about the scalability of the solution?
I would rate the scalability of the product as a nine out of ten. We have approximately 3,000 end users.
How are customer service and support?
I have had a great experience with Palo Alto Networks technical support. Response time and quality have been excellent, especially for RMA cases. Any issues, whether for functionality or hardware, were resolved quickly. I would rate the support as a nine out of ten.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
Palo Alto Networks stands out from other solutions because they consistently strive to innovate and stay ahead of the curve. Their user-friendly interface and customizable security options make them a top choice. Additionally, they offer a wide range of security solutions without forcing you to invest in unnecessary features, similar to SecurePoint's approach with blades.
How was the initial setup?
The initial setup of Palo Alto Networks PA-Series was straightforward, especially with prior network and security knowledge and a helpful training course. The intuitive web UI made the process comfortable, and overall, Palo Alto Networks seems to be heading in the right direction with user experience improvements.
What other advice do I have?
I have experience deploying and managing PA-Series firewalls in a multi-site environment, including international locations connected via MPLS. We use them for perimeter security and have centralized management through Panorama. Deploying and managing them across sites has been straightforward and effective which makes Palo Alto Networks a preferred choice for our network security needs.
The PA-Series has consistently helped us prevent cyber-attacks through its threat prevention and vulnerability profiles. By configuring security profiles effectively, including antivirus and threat prevention, we have successfully mitigated various threats.
Overall, I would rate Palo Alto Networks PA-Series as a nine out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Buyer's Guide
Download our free Palo Alto Networks PA-Series Report and get advice and tips from experienced pros
sharing their opinions.
Updated: June 2026
Product Categories
FirewallsPopular Comparisons
Fortinet FortiGate
Netgate pfSense
Sophos Firewall
Cisco Secure Firewall
Palo Alto Networks NG Firewalls
WatchGuard Firebox
Check Point Quantum Force (NGFW)
Check Point Harmony SASE (formerly Perimeter 81)
Cisco Meraki MX
Azure Firewall
Palo Alto Networks VM-Series
SonicWall TZ
Juniper SRX Series Firewall
SonicWall NSa
Buyer's Guide
Download our free Palo Alto Networks PA-Series Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What do you recommend for a corporate firewall implementation?
- Comparison of Barracuda F800, SonicWall 5600 and Fortinet
- Sophos XG 210 vs Fortigate FG 100E
- Which is the best network firewall for a small retailer?
- When evaluating Firewalls, what aspect do you think is the most important to look for?
- Cyberoam or Fortinet?
- Fortinet, Palo Alto or Check Point?
- If you could go back, would you change your decision to buy that firewall and why?
- Sophos XG vs Fortigate UTM
- Can you recommend a solution to replace Cyberoam 200ing Firewall?


















