Try our new research platform with insights from 80,000+ expert users
Marcin Chudzik - PeerSpot reviewer
Senior Security Engineer Implementation&Support at a comms service provider with 201-500 employees
Real User
Jul 18, 2022
It has strong protection with dynamic analysis but it's pricier than some competitors
Pros and Cons
  • "The most significant benefit is threat protection. Anti-malware uses signatures, so dynamic analyzers like WildFire are the best way to protect the company. It is a firewall based on application control, user ID, and security policy. We can use it based on user and application ID without a stateless firewall or TCPIP ports."
  • "Unfortunately, Palo Alto Networks products aren't cheap, but you have to pay the price for good security technology. I don't know the exact price, but it's about $10,000 to $15,000 without a subscription. Cisco is priced similarly. FortiGate is inexpensive in Poland, so a lot of customers prefer that."

What is our primary use case?

Some of my customers have Palo Alto firewalls, and the use cases include security policies, VPN connections, remote access, side-to-side VPN, and some user ID functionality. To solve these problems, I usually use the web UI monitor, system logs, end capture, CLI, etc. 

We don't have large-scale implementations in Poland as you'd find in Western Europe, but last year I did a big Palo Alto project with 20 Next-Generation firewalls and it was a success. We deployed eighteen PA 800 CVS firewalls for branch offices and a PA 52 series and NPA 5200 series at the data center. It was a high-availability model. The project was a migration from previously used Palo Alto firewalls, including the PA 500, 3000 series, PA 800 series, and PA 32 series. About 95 percent of our firewalls are on-premises, but some customers in Poland want to move to cloud solutions like Prisma Cloud. 

How has it helped my organization?

The most significant benefit is threat protection. Anti-malware uses signatures, so dynamic analyzers like WildFire are the best way to protect the company. It is a firewall based on application control, user ID, and security policy. We can use it based on user and application ID without a stateless firewall or TCPIP ports.

Palo Alto Next-Generation Firewalls have security functionality like a traditional IPS system. You can configure it to download new signatures from the threat intel cloud every five minutes. We also have data filtering, disk protection, SD-1, and machine learning functions. We only have one full working path on a Palo Alto Networks solution, but it is not a classic UTM. In a traditional UTM, checks occur in a series, but everything in Palo Alto Networks is inspected in parallel. 

What is most valuable?

The security features are the most valuable aspect of Palo Alto's Next-Generation Firewalls. It has all the typical static threat protection based on signatures and WildFire dynamic analyzers. I love this feature. Palo Alto Networks updates the signatures of global threats on the cloud every 60 seconds, so we are protected against the latest threats. 

It also has SD-1, but unfortunately, very few customers in Poland want to enable SSL decryption. From time to time, we have customers who want to test this. Machine learning is crucial to security features like anti-spyware and URL security profiles. Palo Alto was one of the first firewalls to have this capability. It helps us analyze real-time traffic using machine learning instead of signatures. Palo Alto has a better web interface than other firewalls I've used.

The DNS Security checks if your DNS queries are valid because infected computers try to connect to the DNS domain. We have this configuration to block access to the domain. We can use the application to block the DNS tunnel link. 

What needs improvement?

When we enable security functions like threat prevention, performance generally degrades, but this is normal. Of course, Palo Alto could always improve its security. 

Buyer's Guide
Palo Alto Networks NG Firewalls
January 2026
Learn what your peers think about Palo Alto Networks NG Firewalls. Get advice and tips from experienced pros sharing their opinions. Updated: January 2026.
882,032 professionals have used our research since 2012.

For how long have I used the solution?

I have been working with Palo Alto's Next Generation Firewalls for four or five years because some of my customers use them. 

What do I think about the stability of the solution?

Palo Alto firewalls are stable compared to Fortinet, Check Point, or Cisco. From time to time, the firewall is unstable, but that's related to the connection 99 percent of the time. I recommend doing a test with a resource monitor to see if the model is right for you. 

What do I think about the scalability of the solution?

Palo Alto firewalls are scalable because we can find models suitable for any infrastructure in the company's portfolio. 

How are customer service and support?

I rate Palo Alto Networks' support eight out of ten. I periodically have problems, but I typically try to resolve the issue myself. Sometimes I need to send a troubleshooting file to support, but that's rare. Palo Alto Networks provides us with lots of troubleshooting information we can use.

Which solution did I use previously and why did I switch?

I worked with Fortinet and Cisco firewalls, like PEAK, FirePOWER, and ISA. I also used Check Point firewalls from time to time. I believe Palo Alto has the best technology in the world, and there is a significant demand for these solutions in Poland, so I want to be a person who can implement and configure this technology.  

Many customers think about security in terms of their entire ecosystem, so we have on-premises firewalls and Prisma Cloud, plus endpoint protection solutions like Cortex XDR. I have two customers in Poland who have WildFire in an on-premise sandbox. 

How was the initial setup?

Before implementation, I have to prepare a technical project document containing information about what I will do on this infrastructure, like migration or something like that. I start implementation once the customer approves this document. 

Prior to the physical installation in the server rooms, I need to connect the management interface to the network to update the software and signatures. I have to perform tasks to prepare a device to work. Once I've configured the device, I can switch the firewalls from the current security setup to Palo Alto's firewall. 

It depends on the customer, but sometimes my customers want to enable dynamic protocols first, but they don't enable them. About 95 percent are in working route mode, but we have L3 interfaces from time to time. Generally, migration is simple because I don't use an expedition tool. I made some changes, switching the firewall from the older models to the new ones. After that, I used the optimizer to convert rules, including the TCP UTP power services. 

Then I enabled this project's network and security functions, like the aggregation interface and the trunk. I use aggregation interfaces with virtual interfaces, like the 802.1 queues, sub interfaces with VLAN, and DHCP server relay. I haven't used dynamic working protocols. I only used static working protocols, but maybe my customer will be ready for dynamic working protocols in the future.

The time it takes to deploy depends on the project. Usually, it's about two weeks for the basic installation. However, my current project took between one and two months. Some customers require a lot of other tasks, so the installation might take six to eight weeks.

What about the implementation team?

I'm able to do everything by myself, but I have some problems with functionality every now and then. For example, I recently had a problem with the side-to-side VPN, but the configuration was okay. In the end, I found it was a problem with the internet connection, not the VPN. Initially, our internet provider told us that everything was okay on our networks. 

What's my experience with pricing, setup cost, and licensing?

Unfortunately, Palo Alto Networks products aren't cheap, but you have to pay the price for good security technology. I don't know the exact price, but it's about $10,000 to $15,000 without a subscription. Cisco is priced similarly. FortiGate is inexpensive in Poland, so a lot of customers prefer that.

Though it's pricey, customers ultimately realize Palo Alto is the best security solution because it's stable and the network security functions are practical. Cisco has some problems from time to time, but I feel comfortable with Palo Alto Networks. 

What other advice do I have?

I rate Palo Alto Networking Next-Gen Firewalls seven out of ten. I have to qualify that by saying that I probably don't know enough about Palo Alto Networks technology because we don't have advanced projects in Poland. I want more opportunities to develop my skills with this technology. I want to know more about Prisma Cloud and Strata products. 

Depending on the client's infrastructure, I would recommend a different Palo Alto firewall. I would use PA 220 or maybe a PA 420 maybe for a small office. These devices are for small and medium-sized businesses. We would use a 52 and a 54 series or a 7000 series for a large enterprise.

A VM deployment might be suitable for some security projects. We've even deployed Palo Alto in Polish government institutions. For example, I implemented a VM 500 security solution two years ago. This device works in high availability mode. I think VM is a good starting point for a customer. It allows them to try the security product, open the Web UI, etc. After that, we should develop a proof of concept test and show the customer how this device works on their infrastructure. 

I would recommend a Palo Alto firewall with next-generation security functions like IPS, and the ability to use user or application IDs. I will tell my customers about dynamic functionality and threat intelligence in the Palo Alto Networks cloud.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
reviewer2169336 - PeerSpot reviewer
Head Of CERT at a logistics company with 10,001+ employees
Real User
May 3, 2023
Is easy to deploy, has good technical support, and integrates well with other components in our network
Pros and Cons
  • "Compared to other firewalls from Check Point, Fortinet, and Cisco, for example, Palo Alto Networks NG Firewalls use the most advanced techniques. They have sandbox integration and others in the orchestrator. Palo Alto's security features are at a higher level than those of the competitors at the moment."
  • "Palo Alto needs to provide more support during the design phase and with proposals. They need to be more proactive, try to anticipate issues, and then help us to implement the transformation quickly."

What is our primary use case?

We protect certain applications in the data center with Palo Alto Networks NG Firewalls.

What is most valuable?

Application layer security and integration with other components that we have in our networks are valuable features.

Compared to other firewalls from Check Point, Fortinet, and Cisco, for example, Palo Alto Networks NG Firewalls use the most advanced techniques. They have sandbox integration and others in the orchestrator. Palo Alto's security features are at a higher level than those of the competitors at the moment.

It's very important that we be able to integrate all security capabilities within the firewall. This is one of the key reasons why we chose to go with Palo Alto Networks NG Firewalls.

We are heavily investing in technology that uses machine learning. Thus, it is important for us that Palo Alto Networks NG Firewalls embed machine learning in the core of the firewall to provide inline, real-time attack prevention.

What needs improvement?

Palo Alto needs to provide more support during the design phase and with proposals. They need to be more proactive, try to anticipate issues, and then help us to implement the transformation quickly.

For how long have I used the solution?

I have been using Palo Alto Networks NG Firewalls for five years now.

What do I think about the stability of the solution?

We have not had any issues with stability. I have not heard from our SOC about issues with devices either.

What do I think about the scalability of the solution?

The scalability has been good. We are the biggest bank in Italy with 100,000 employees.

How are customer service and support?

Palo Alto's technical support is extremely good and responsive. The ticketing system, however, is a little bureaucratic especially when you are in a hurry or are dealing with an emergency. On a scale from one to ten, overall, I would rate technical support a nine.

How would you rate customer service and support?

Positive

How was the initial setup?

The deployment was quite easy.

What was our ROI?

We have seen a return on investment in general. Our company is moving to the cloud and toward digital transformation in the financial sector. Palo Alto plays a key role in this return on investment.

What other advice do I have?

My advice to you, if you're looking for the cheapest and fastest firewall, is that the cheapest firewall is not the best for security.

We use firewall solutions from multiple vendors, and from a security point of view, Palo Alto Networks NG Firewalls are one of the best in comparison. Also, you get the best value from Palo Alto with application layer security, machine learning, and integration.

Overall, I would rate Palo Alto Networks NG Firewalls a nine out of ten.

I find it valuable to attend an RSA Conference because I get the opportunity to participate in several seminars, share, and learn from other people as well.

Attending RSAC also impacts our purchasing decisions because what I see at the conference will end up in the budget the following year or the year after that.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Palo Alto Networks NG Firewalls
January 2026
Learn what your peers think about Palo Alto Networks NG Firewalls. Get advice and tips from experienced pros sharing their opinions. Updated: January 2026.
882,032 professionals have used our research since 2012.
Ishan Kumara - PeerSpot reviewer
Manager Data Servicers at a financial services firm with 1,001-5,000 employees
Real User
Top 20
May 2, 2023
Performs well and protects our internal network from external threats
Pros and Cons
  • "The performance of Palo Alto Networks NG Firewalls is the most valuable feature."
  • "The analytics could be improved."

What is our primary use case?

We use the solution to protect our internal network from external threats.

Up until recently we were not using multilayer firewalls and were using several solutions that are combined in Palo Alto Networks NG Firewalls.

How has it helped my organization?

We are required to provide our network test results to our central bank, and Palo Alto Networks NG Firewalls offer a robust report for this purpose that would otherwise be a cumbersome human task.

What is most valuable?

The performance of Palo Alto Networks NG Firewalls is the most valuable feature.

What needs improvement?

The analytics could be improved. I would like to have a unified analysis tool within Palo Alto, as we currently use Perimeter 81 and Fortinet FortiGate, which makes the analysis process take a long time.

For how long have I used the solution?

I have been using the solution for almost four years.

What do I think about the stability of the solution?

The solution is stable.

What do I think about the scalability of the solution?

The solution is scalable. We have three people that monitor the solution and maintain it.

How was the initial setup?

The initial setup is straightforward. We had to secure our parameter network. We required two engineers from a reseller and two from our organization.

What about the implementation team?

The implementation was completed with the help of a partner.

What's my experience with pricing, setup cost, and licensing?

The solution is worth the price, as it can be utilized without the need for high-processing CPUs and resources, thus saving us overall.

Which other solutions did I evaluate?

I evaluated Check Point and decided to use Palo Alto because of its performance. Palo Alto can be used with fewer CPUs. 

What other advice do I have?

I give the solution a nine out of ten.

Before using Palo Alto Networks NG Firewalls you must first know what our requirements are.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer2134368 - PeerSpot reviewer
Security and IT Infrastruture Senior Manager at a retailer with 1,001-5,000 employees
Real User
May 2, 2023
Helps to eliminate security holes and enables us to manage our firewall security in-house
Pros and Cons
  • "The technical support is great."
  • "There is a tradeoff between security and network performance, as security is always top-notch, but performance can sometimes lag and has room for improvement."

What is our primary use case?

We use the solution as a firewall for our network. We can manage our traffic between internal traffic and external traffic handling. The solution protects the traffic and we manage the standard firewall issues.

How has it helped my organization?

The solution's embedded machine learning in the core of the firewall that provides in-line real-time attack prevention is important and provides good insight for us. The machine learning actions and learning activities provide some useful information. 

The solution's machine learning for securing our networks against rapidly evolving threats is good. We utilize an IoT tool that comprehends IoT devices, such as webcams, and can therefore interpret their behavior and send information on their activity. The tool also applies appropriate firewall rules to these devices, taking into account the clearance level of each device based on its traffic.

Before implementing Palo Alto, we had to rely on a management company to handle our firewall security. However, now that we have Palo Alto, we can manage our firewall security in-house.

Palo Alto Networks NG Firewalls unified platform helped to eliminate security holes.

The zero-delay signature feature helps keep our security updated against new attacks.

What is most valuable?

Palo Alto Networks NG Firewalls provides a unified platform that natively integrates all security capabilities which is important to our organization.

Palo Alto Networks NG Firewalls' zero-delay signature feature is important, and it receives daily updates.

What needs improvement?

At times, server capacity can result in issues. While Palo Alto is a top firewall company, it's crucial to properly size the firewall to meet our needs. In the case of larger attacks, the capacity of our current firewall may not be adequate, requiring us to obtain more advanced and expensive versions to ensure network protection.

There is a tradeoff between security and network performance, as security is always top-notch, but performance can sometimes lag and has room for improvement.

The cost of the solution has room for improvement.

For how long have I used the solution?

I have been using the solution for one year.

What do I think about the stability of the solution?

I give the stability an eight out of ten.

What do I think about the scalability of the solution?

The solution is not very scalable. We need to define our requirements and purchase the correct product for our needs.

We are an enterprise company with over 3,000 people. All the network traffic goes through the solution but we have five people that work directly on the solution.

How are customer service and support?

The technical support is great.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

We previously used Check Point NGFW and switched to Palo Alto Networks NG Firewalls because of the stability.

How was the initial setup?

I give the initial setup a five out of ten. The deployment took one month.

What about the implementation team?

Implementation was completed in-house by a consultant.

What's my experience with pricing, setup cost, and licensing?

Compared to other firewall solutions, this is an expensive solution.

What other advice do I have?

I give the solution an eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer2171682 - PeerSpot reviewer
Compliance Analyst at a international affairs institute with 11-50 employees
Real User
May 1, 2023
The ability to provide secure access to people without having to carry an additional device around really benefits us
Pros and Cons
  • "Prisma Access is the most valuable feature of Palo Alto Networks NG Firewalls."
  • "In my opinion, the training provided is satisfactory, but there is certainly room for improvement. It would be great to have more comprehensive training at a lower cost, or even for free."

What is our primary use case?

We use Palo Alto Networks NG Firewalls to protect small businesses that work within the defense industrial base.

How has it helped my organization?

By using Prisma Access, we can easily connect to our network from different locations around the world without having to deploy multiple firewalls. This not only makes it more convenient but also saves us a lot of expenses.

What is most valuable?

Prisma Access is the most valuable feature of Palo Alto Networks NG Firewalls.

The ability to provide secure access to people without having to carry an additional device around really benefits us in the defense industrial base.

What needs improvement?

The training provided is satisfactory, but there is certainly room for improvement. It would be great to have more comprehensive training at a lower cost, or even for free.

I would say that Palo Alto Networks NG Firewalls provide a unified platform for many, but not all.

Having everything in one pane of glass is important to me because I have a lot of responsibilities. It would be really nice to have everything in one place, so I don't have to switch around between different applications and can stay focused on one platform.

It's important to have machine learning embedded, but it's equally important to not solely rely on it. We still need human interaction to ensure proper security measures. Nonetheless, machine learning is a vital component of our security strategy.

For how long have I used the solution?

I have been using Palo Alto Networks NG Firewalls for five years.

What do I think about the stability of the solution?

Palo Alto Networks NG Firewalls have been instrumental in reducing our downtime as we moved away from less robust devices. By implementing Palo Alto firewalls, we have significantly improved our network stability.

If I had to estimate, it has saved us 10 to 15 hours per year.

Palo Alto Networks NG Firewalls is a very stable solution.

What do I think about the scalability of the solution?

I haven't encountered the need to scale the solution yet. Our current setup meets our requirements and has been working well for us. Given that we are a small company, we have not felt the need to look into scaling it at this point.

How are customer service and support?

The technical support provided by Palo Alto Networks is excellent. Although I have only needed to contact them a few times, they have always been quick to respond, and their team is very knowledgeable.

I would rate the technical support a nine out of ten.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

Before, we used SonicWall, but we decided to switch to Palo Alto Networks NG Firewalls because they offer a much better solution and are leading the market.

How was the initial setup?

I was part of the deployment team, but since I was new to Palo Alto devices, the deployment process was more complex for me. That's where the training came into play.

I had to familiarize myself with their user interface and terminologies since I was used to using a different system. It took some time for me to learn and compare it with what I've used before.

What about the implementation team?

We purchased from a reseller.

It was a straightforward process. We made the purchase online and they shipped it to us. After that, it was a matter of getting it up and running.

What was our ROI?

It's difficult to determine. When looking at the ten to fifteen hours a year, it's unclear whether or not I would consider that as part of the return on investment. It's a bit challenging to assess from an IT perspective.

What's my experience with pricing, setup cost, and licensing?

Reducing costs is important, especially since Prisma can be expensive. It would be great if it were more affordable.

Although the hardware can be expensive, the quality of Palo Alto Networks NG Firewalls is excellent. While a lower cost would be desirable, we recognize the value of investing in a reliable and effective solution.

Which other solutions did I evaluate?

When we were moving away from SonicWall, we evaluated FortiGate and Meraki's solutions.

In my opinion, I was impressed with FortiGate's system on a chip. It was really fast compared to Palo Alto's, but I think Palo Alto has a better feature set and interface. As for SonicWall, we had several reasons for leaving. Regarding Meraki, I find their management interface not suitable for my needs, and they seem to be more of a consumer-grade or prosumer-grade product.

What other advice do I have?

I am not in a position to comment on the solution's ability to secure data centers consistently across all workplaces, from the smallest office to the largest data centers since I have only used their smaller solutions.

My advice to those who are seeking a firewall solution is not to prioritize the cheapest or the fastest options, as it could be risky. Instead, it is important to invest in the best quality firewall that is within your budget. This is something that I have experienced with Palo Alto Networks, which provides a high-quality solution that is worth the investment.

I would rate Palo Alto Networks NG Firewalls a nine out of ten.

The experience has been amazing, with a few sessions resulting in new services that I can offer my company directly. The best part is that I can do it without having to invest in an expensive tool that costs hundreds of thousands of dollars.

It does impact the purchases we will make throughout the year.

If I can perform 95% of the work at a lower cost, we are unlikely to consider Mandiant and spend a significant amount of money. 

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer2171643 - PeerSpot reviewer
IT Specialist at a government with 501-1,000 employees
Real User
May 1, 2023
Robust security infrastructure, user-friendly, and intuitive
Pros and Cons
  • "In my opinion, Palo Alto has consistently been one of the best firewalls for enterprise security."
  • "I would like to see some Machine Learning because I have observed new types of attacks that are able to bypass existing security rules."

What is our primary use case?

We have had use cases for defending our resources against external access or authenticating particular traffic or appropriate traffic for access.

How has it helped my organization?

The key factor here is reliability. In my previous company, we had a different vendor's firewall before switching to Palo Alto network devices. 

Unfortunately, during that time, our security team was on vacation and had to be called back urgently due to a severe incident. This experience led us to switch to a more dependable, reliable, and robust system, which turned out to be the Palo Alto network device. 

Fortunately, the transition from our old system to the new one was relatively seamless, and we now have a reliable and robust security infrastructure.

What is most valuable?

In my opinion, Palo Alto has consistently been one of the best firewalls for enterprise security. 

We have encountered numerous instances where we have observed threats and attacks targeting our systems, and Palo Alto has proven to be highly reliable in blocking any malicious activity.

What needs improvement?

I would like to see some Machine Learning because I have observed new types of attacks that are able to bypass existing security rules. It is possible that implementing some form of continuous learning or education could be beneficial in addressing this issue.

Some way to learn what is normal it isn't, you know, something like that, I think that would be probably the most beneficial thing to me.

What do I think about the stability of the solution?

To say it's a set-and-forget system wouldn't be entirely accurate, but it is an incredibly stable and reliable system. Once it's set up and configured properly, you really just need to keep an eye on it for any necessary updates or new rules. In my experience, it's one of the most reliable systems available.

What do I think about the scalability of the solution?

The original installation we were considering was for a small organization, and we had to take into account the fact that we were going to expand the endpoints to our entire user base, not just a select few like marketing.

We were assured that the system would have no issues handling the additional workload as we added more devices or upgraded the device.

The firewall solution that I have referred to the most during this conversation is one that I have implemented for small to medium-sized organizations.

How was the initial setup?

I found the initial setup very straightforward.

I recall that the setup process for the device was straightforward and could be completed quickly. However, while the device did come out of the box, it wasn't as secure as it could have been, and I had to go in and tighten up the security settings. Despite that, compared to other firewalls with complex and cryptic interfaces, Palo Alto's firewall interface was relatively easy to use and comprehend.

There were certainly benefits in terms of time-saving and ease of learning for the user. The straightforward setup process and user-friendly interface of the Palo Alto network devices made it easier and quicker to implement, thus saving time. Additionally, the easy-to-use interface also helped in reducing the learning curve for users, enabling them to become proficient in using the device more rapidly.

Using Palo Alto has reduced the amount of downtime considerably.

Determining the impact of blocking threats is not straightforward because it depends on the severity of the threat. For example, if a threat only affected one server, the downtime would be minimal. However, if it caused an outage in the entire environment, the impact would be much greater. It is challenging to quantify the amount of downtime prevented by blocking threats.

Usually, when setting up a new firewall, it's common to get around 80% of the work done within a few days. However, with the Palo Alto network device, I recall that we were able to achieve 95% to 99% completion within just a couple of days. The device's user-friendly interface and straightforward configuration process made it easier to accomplish more in less time.

What about the implementation team?

Technical support was helpful during the deployment process.

During the deployment process, I thought they were great. I had no complaints they were very knowledgeable, and we were able to resolve everything very quickly.

What was our ROI?

The organization has seen a return on investment with Palo Alto firewalls as we haven't experienced any significant breaches.

Which other solutions did I evaluate?

When when we first looked at Palo Alto, it came in as the top recommendation from a source that we trusted. We didn't actually look at other vendors at that time. 

At the time, we had the full support of our CEO and team, who recognized the urgency of the situation as our entire system was down. This rare backing from everyone helped us to quickly implement a solution.

What other advice do I have?

We frequently recommend Palo Alto to others as we believe it is a highly effective solution for network security. It is one of those things where if someone does not have a Palo Alto, we advise them to consider it as a worthwhile investment.

For those seeking the cheapest or quickest solution, I would advise that while it may seem like a good idea in the short term, you will likely encounter issues that will require you to replace the solution soon after. Investing in a reliable and reputable solution like Palo Alto Networks may require a larger investment upfront, but will ultimately save you time and money in the long run.

The biggest value that I gain from being here is networking and finding out what other products are out there without having to go to, like, a search engine and wait or rely on the results of the search engine. I can literally wander around. And if something catches my eye, I can be like, well, that's really cool. Let me go get some more information about that.

It's really easy to just look at all the different vendors, looks at the various talks, looks at everything that's here, and get information tailored to what I wanna learn about.

I definitely can make recommendations on various products they get based on my experience, but I don't have a say in it directly.

I would rate Palo Alto Networks NG Firewalls a nine out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer2171625 - PeerSpot reviewer
Cloud Infrastructure Engineer at a energy/utilities company with 10,001+ employees
Real User
May 1, 2023
Allowed for more flexibility in defining rules, as it was based on applications rather than strict port and protocol definitions
Pros and Cons
  • "The key aspect of this solution that provides the most value is its next-gen capabilities, which represented a significant change for us."
  • "It's too expensive."

What is our primary use case?

We deployed Palo Alto Networks NG Firewalls for inbound and outbound protection, as well as DMC protection, in our data center.

What is most valuable?

The key aspect of this solution that provides the most value is its next-gen capabilities, which represented a significant change for us. Previously, we had been using Check Point.

We switched to this solution due to its advanced next-gen capabilities, which allowed us to create rules based on applications rather than ports or protocols. As a result, the solution became much more relevant to our needs compared to our previous solution.

Palo Alto Networks NG Firewalls allowed for more flexibility in defining rules, as it was based on applications rather than strict port and protocol definitions. This made it easier to adapt to changing needs and configurations.

We were able to automate things using the API. Savings are minimal, but we save a significant amount of time when we deploy rules that we learn when we deploy the policy. Is the process still the same? Perhaps the implementation will take only a few hours or minutes.

We have been exclusively using it for the Next-Gen firewall, MDPN, and remote access for a while.

It integrates the core capabilities into one.

To make it more affordable, we had to separate the integrated features into individual components. The integrated solution was more expensive than when we broke it down into separate components.

For how long have I used the solution?

I have been using Palo Alto Networks NG Firewalls for over five years, and perhaps even as long as ten years.

What do I think about the stability of the solution?

The stability of Palo Alto Networks NG Firewalls is very good.

We have upgraded it several times for additional features, and we have never experienced any crashes or performance issues. Overall, it has been quite stable.

What do I think about the scalability of the solution?

In terms of scalability, the cost is a limiting factor. We can buy a large number of them, but it would not make financial sense for us to do so due to the high cost.

In contrast to the cloud environment where you can scale incrementally and horizontally, in our case, we have to purchase the entire unit. As a result, scaling our responsibilities becomes challenging.

We have around 2,000 compute resources that need protection, so getting a large firewall is necessary to safeguard our environment.

How are customer service and support?

Technical support is very good.

I would rate the technical support an eight out of ten.

F5 and Cloudflare are types of support that were really good. There is no escalation whatsoever. The first person you get to already is the top-notch technical person.

With Palo Alto, you have to escalate, but eventually, you get to a good one.

How would you rate customer service and support?

Positive

How was the initial setup?

The deployment process was easy.

We used a migration tool to transfer from our previous firewall to Palo Alto, and it proved to be quick.

What about the implementation team?

We received support from a Palo Alto sales engineer.

What was our ROI?

While Palo Alto is expensive, it's still the better option compared to the other two vendors that were evaluated since they didn't provide the necessary performance and benefits.

Overall, the expenses for Palo Alto are manageable, and it's worth the investment.

What's my experience with pricing, setup cost, and licensing?

It's too expensive.

Although Palo Alto is a good and fast product, it is not the most affordable option out there, and it may not be the easiest to use.

Which other solutions did I evaluate?

We evaluated Cisco and Fortinet.

During our evaluation process for selecting a firewall vendor, we prioritize performance as the number one factor. 

Price range is ranked second in importance. 

Other important factors include ease of use, API support, and next-gen features, all of which are used as evaluation criteria. We have previously used Magic Quadrant, but it is important for us to carefully choose our firewall vendor.

What other advice do I have?

Integrating machine learning at the core of Palo Alto Networks NG Firewalls would be highly beneficial. The ability to automatically detect threats without the need to create rule sets manually would be a game changer.

Attending events like RSA is valuable to me because it allows me to explore different vendors and products. Sometimes, I come across new vendors that I haven't heard of before, which is good.

Attending events like RSA can have a significant impact on our company's cybersecurity purchases throughout the year. If we come across a new vendor with a fresh approach to protecting the company or identifying threats, we are definitely interested in exploring their offerings.

I would rate Palo Alto Networks NG Firewalls an eight out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer2171676 - PeerSpot reviewer
Sr Network Engineer/DBA at a energy/utilities company with 201-500 employees
Real User
May 1, 2023
Elegant, thorough, and has automated alerts and detection
Pros and Cons
  • "The DNS sync code in your filtering is the most valuable feature of the Palo Alto Networks NG Firewalls."
  • "Technical support is an area that could be improved."

What is our primary use case?

For security purposes, we use Palo Alto Networks NG Firewalls for both the edge and data center.

How has it helped my organization?

The IT operations side provides us with more freedom as we don't have to worry about it as much due to the automated alerts and detection.

What is most valuable?

The DNS sync code in your filtering is the most valuable feature of the Palo Alto Networks NG Firewalls.

It helps us stay informed about the activities of our end users.

As I learn more about the unified platform, I see that Palo Alto is integrating well with other standards and are innovating, so the solution works effectively.

Maintaining a good security posture is important for our organization, particularly when it comes to threats like ransomware. ITM Security plays a vital role in this, and Palo Alto Networks equipped us well to be proactive in our approach. As a result, we prioritize the importance of ITM Security within our group.

Incorporating machine learning into the firewall's core to provide real-time attack prevention is highly beneficial, particularly with features like WildFire. We have had instances where it effectively stopped zero-day attacks on the first day, and we were one of the first to encounter the issue. Within a couple of hours, they notified us that it was a security issue, allowing us to take action promptly.

What needs improvement?

I am not aware of anything that could be improved.

I think that they have been doing a good job at this point in time.

Technical support is an area that could be improved.

For how long have I used the solution?

I have been working with Palo Alto Networks NG Firewalls for six years.

What do I think about the stability of the solution?

Our downtime has not been reduced by Palo Alto Networks NG Firewalls. We experienced a DSL firewall incident that resulted in a five-hour downtime while we discovered the bug, and although I cannot entirely blame the firewall, it was still a part of the issue. However, we have learned to deal with this inconvenience.

It's quite stable. We had one issue because of a bug. Aside from that, everything has been fine.

What do I think about the scalability of the solution?

The scalability is excellent. We were able to enlarge the network and install additional firewalls. There haven't been many problems with that.

How are customer service and support?

Technical support has fallen off. It was much better up front. The first four years were spectacular.

In the last couple of years, we're getting a lot of overseas support that seems to have little training. In the beginning, it was high, but now I would rate it a five out of ten.

How would you rate customer service and support?

Neutral

Which solution did I use previously and why did I switch?

Previously, we used Cisco.

Compared to Cisco, Palo Alto Networks NG Firewalls are much better in terms of being more elegant and thorough, especially when it comes to navigating log files and similar tasks.

How was the initial setup?

By the nature of coming from Cisco Firewall to Palo Alto Networks NG Firewall, there was complexity involved. But with the help of third-party resources, we were able to get it done pretty quickly.

What about the implementation team?

We had assistance from a consultant. They were very helpful.

What's my experience with pricing, setup cost, and licensing?

The pricing is competitive.

If someone is looking for the cheapest or the fastest option, I am not quite sure what other vendors are offering in terms of pricing. However, my recommendation would be to go with Palo Alto so that they don't have to worry about the security of their job.

Which other solutions did I evaluate?

After evaluating Cisco Firepower and Palo Alto, we decided to go with these two options. However, after trying out Firepower, we realized that it was not a good fit for us and we knew we didn't want to proceed with it.

What other advice do I have?

Our current design is efficient as all our sites are routed to the Palo Alto firewall, allowing us to segregate VLANs and maintain communication between users. It's a great setup that simplifies a lot of our work.

I would rate Palo Alto Networks NG Firewalls a nine out of ten.

In my overall assessment, I would give the conference a seven out of ten. It seems like many presentations focus on industry trends, and there is some repetition across different companies covering the same three or four topics. However, I found that Palo Alto Networks NG Firewalls had some valuable insights into what the industry is doing.

It helps, as we are the ones making decisions.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Download our free Palo Alto Networks NG Firewalls Report and get advice and tips from experienced pros sharing their opinions.
Updated: January 2026
Product Categories
Firewalls
Buyer's Guide
Download our free Palo Alto Networks NG Firewalls Report and get advice and tips from experienced pros sharing their opinions.