We use this solution for WAN routing, NAT, VPN tunnels, granular security policies, URL filtering, antivirus, threat prevention, sandboxing, decryption, high availability, and reporting.
System Engineer at E-smart systems
Improved traffic visibility and management after replacing our open-source solution
Pros and Cons
- "With our High availability pair, we have had no downtime for several years, since it was first put it in production."
- "When you delete and add a new rule, because of the one hundred rule limit, if the new rule has an ID that is greater than one hundred, even though you have fewer than that, it will not work."
What is our primary use case?
How has it helped my organization?
Palo Alto has improved traffic visibility, and the ability to manage it. With Palo Alto, we have more flexibility and our network is more secure. With our High availability pair, we have had no downtime for several years, since it was first put it in production. We have even changed boxes for new models during this time.
What is most valuable?
Palo Alto is easy to use, feature-rich, and it has good technical support. You can fetch users, so you have visibility by username, IP address, destination, application, and you can even define a custom application.
In the GUI, you can easily find blocked traffic and the reason for it.
What needs improvement?
The only thing that is a little strange is in Policy-Based Forwarding. When you delete and add a new rule, because of the one hundred rule limit, if the new rule has an ID that is greater than one hundred, even though you have fewer than that, it will not work. The same thing happens when you are renaming a rule. The new rule will have a new ID, so it is possible for it to be greater than one hundred. This can be easily fixed by using one command from CLI, but you have to be aware of it.
Buyer's Guide
Palo Alto Networks NG Firewalls
January 2025
Learn what your peers think about Palo Alto Networks NG Firewalls. Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
831,265 professionals have used our research since 2012.
For how long have I used the solution?
Six years.
How are customer service and support?
The technical support for this solution is good.
Which solution did I use previously and why did I switch?
Our previous solution was open source, and not so easy to manage. We had a Linux Iptables firewall, Squid + DansGuardian proxy, and an OpenVPN server. We replaced all of these solutions with Palo Alto.
What's my experience with pricing, setup cost, and licensing?
If you have some network experience then you can set it up on your own, with no setup costs. Don't buy a device with more power than you really need, because licensing depends on the cost of the box you have.
Which other solutions did I evaluate?
We evaluated Sophos, SonicWall, and Fortinet.
What other advice do I have?
PA is a product that continuously improves, so, I have nothing to add in terms of features.
My advice is not to look for a cheaper solution, as the price/performance ratio on Palo Alto is great.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
ITSM Engineer at a comms service provider with 11-50 employees
Reliable with good App-ID, Content-ID, User-ID, and encryption and decryption features
Pros and Cons
- "The App-ID, Content-ID, User-ID, and encryption and decryption are valuable features."
- "They can improve the handling and management of User-ID. They should also improve its price. Their technical support can also be improved."
What is our primary use case?
We are using it for data center protection, intrasystem security, endpoints protection, load balancing, and DHCP.
What is most valuable?
The App-ID, Content-ID, User-ID, and encryption and decryption are valuable features.
What needs improvement?
They can improve the handling and management of User-ID. They should also improve its price. Their technical support can also be improved.
For how long have I used the solution?
I have been using this solution for three years.
What do I think about the stability of the solution?
It is stable and reliable.
What do I think about the scalability of the solution?
We went from 4 devices to 16 devices, and it was not a big problem. Currently, we don't have any plans to increase its usage. Our network won't grow over the next two years. It will stay as it is.
How are customer service and technical support?
Their technical support is sometimes lousy, but sometimes, it is okay. Their technical support can be improved.
How was the initial setup?
Its initial setup is not too complex for an environment like this.
What's my experience with pricing, setup cost, and licensing?
Its price should be improved.
What other advice do I have?
I would recommend this solution. I would rate Palo Alto Networks NG Firewalls an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Palo Alto Networks NG Firewalls
January 2025
Learn what your peers think about Palo Alto Networks NG Firewalls. Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
831,265 professionals have used our research since 2012.
Technical Manager El Salvador at a tech services company with 51-200 employees
A feature-rich solution that works very well and has excellent stability
Pros and Cons
- "Overall, it is a good solution. It is stable. We use URL filtering, which is useful for blocking undesired URLs."
- "Currently, they don't have email protection. They can maybe add it in the future. Currently, if you want to do so, you need to go with another solution."
What is our primary use case?
We use it for perimeter security.
What is most valuable?
Overall, it is a good solution. It is stable. We use URL filtering, which is useful for blocking undesired URLs.
What needs improvement?
Currently, they don't have email protection. They can maybe add it in the future. Currently, if you want to do so, you need to go with another solution.
For how long have I used the solution?
I have been using this solution for two years.
What do I think about the stability of the solution?
Its stability is perfect. It has excellent stability.
What do I think about the scalability of the solution?
With this kind of solution, you need to be careful in terms of planning because once you have the appliance, it is very difficult to scale too much. You need to carefully select the right appliances because if you need to run more services and traffic beyond the ones you have selected, you would have to replace the appliance. You would have to upgrade it. We currently have 100 users in our organization who use this solution.
How are customer service and technical support?
We never had the need to open a support case. It never happened that something that was supposed to work was not working. If required, we can find the answers in the product documentation.
How was the initial setup?
If you have the right experience, it is okay. It is not very easy, but if you know how to manage it and configure it, it is okay. It takes maybe 5 to 10 hours or a day.
What other advice do I have?
I would advise others to go for it. They will not get disappointed. It is complex at the beginning because it has a lot of features, but this is something that you overcome with training. With training and experience, you can manage it.
I would rate Palo Alto Networks NG Firewall a nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Technology Engineer at a computer software company with 51-200 employees
Stable, very reliable, and easy to use
Pros and Cons
- "I have found it to be reliable and very easy to use. I haven't really encountered many problems with it because its documentation is clear and readily available on their website."
- "Based on the features that I have seen so far, I do not see any room for improvement, but they can improve their CLI documentation. I haven't really seen much when it comes to CLI documentation."
What is our primary use case?
I am currently testing Palo Alto and preparing for an exam.
How has it helped my organization?
The Global Protect Feature has allowed our organization to support our remote workforce.
What is most valuable?
I have found it to be reliable and very easy to use. I haven't really encountered many problems with it because its documentation is clear and readily available on their website.
What needs improvement?
They need to provide documentation for CLI, as most of the commands, we get from Community Forums.
For how long have I used the solution?
I have been doing research on Palo Alto for the past nine months.
What do I think about the stability of the solution?
It is stable.
What do I think about the scalability of the solution?
Highly scalable as the HA deployment allows you to pair up to eight devices at once.
How are customer service and technical support?
I haven't had a chance to contact them.
Which solution did I use previously and why did I switch?
Palo Alto is my first solution.
How was the initial setup?
Initial setup is easy and subsequent changes have been easy to implement as well.
What about the implementation team?
In-house expertise.
Which other solutions did I evaluate?
What other advice do I have?
I would say go for it because it seems to be stable and very reliable. I've spoken to some specialists who vouch for Palo Alto. They say they've been using it in their environment, and it hasn't let them down so far.
I would rate this solution a nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
CIO/CTO at a manufacturing company with 501-1,000 employees
User-friendly GUI, reliable, and the application firewall performs well
What is our primary use case?
We primarily use this product to protect our network.
What is most valuable?
The most valuable feature is the application firewall.
The GUI is user-friendly.
What needs improvement?
The way that the roles are made, specifically with how you specify the path, could be simpler.
For how long have I used the solution?
I have been working with Palo Alto Networks NG Firewalls for one year.
What do I think about the stability of the solution?
We used the product on a daily basis and have had no critical issues so far.
What do I think about the scalability of the solution?
We have hundreds of users in the company and have not tried scaling it.
How are customer service and technical support?
With regards to support, they have a lot of things to improve.
Which solution did I use previously and why did I switch?
We also use Check Point as a firewall. Both have their advantages but for my part, Palo Alto is better because of the way it handles applications. Check Point is better if you are only using ports and TCP/IP.
How was the initial setup?
The initial setup is of medium difficulty. It is not simple yet not complex.
What about the implementation team?
We implement in-house with some assistance from the vendor. It took a few hours to deploy.
What's my experience with pricing, setup cost, and licensing?
Palo Alto is more affordable than some competing products, such as Check Point.
What other advice do I have?
In summary, this is a good product and I recommend it.
I would rate this solution a nine out of ten.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Lead Consultant at a tech services company with 1-10 employees
Good security, integrates well with third-party services, includes DLP, and the support is good
Pros and Cons
- "They are regularly releasing new versions that include more integration with third-party services."
- "Having a better pricing model would make this product more competitive, and more affordable for our customers."
What is our primary use case?
We are a solution provider and one of the Palo Alto products that we implement for our clients is the Next-Generation Firewall. It is used to protect your workflows in cloud environments, be it Azure, AWS, or Google. It can also protect your applications' databases that are on-premises.
What is most valuable?
This firewall will scan the network for vulnerabilities and malware.
It can prevent unauthorized access to the network.
This solution has a DLP function.
They are regularly releasing new versions that include more integration with third-party services. Examples of services that have already been integrated are Splunk and two-factor authentication.
What needs improvement?
Having a better pricing model would make this product more competitive, and more affordable for our customers.
For how long have I used the solution?
We have been dealing with next-generation firewalls from Palo Alto for more than five years.
What do I think about the stability of the solution?
So far, this solution has been stable.
What do I think about the scalability of the solution?
The product is scalable and it can be integrated with third-party solutions.
We have many clients who are using this firewall.
How are customer service and technical support?
The technical support from Palo Alto is good.
Which solution did I use previously and why did I switch?
In terms of firewalls, we use Palo Alto, Cisco, and Fortinet FortiGate.
How was the initial setup?
The next-generation firewall can be installed either on-premises or in a cloud-based deployment.
What's my experience with pricing, setup cost, and licensing?
The NG firewall is an expensive solution.
What other advice do I have?
I would rate this solution a ten out of ten.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Cyber Security Solutions Architect at a tech services company with 10,001+ employees
Offers innovative, advanced threat protection
Pros and Cons
- "Innovative, advanced threat protection is the most valuable feature."
- "The user interface is probably not as slick as it could be."
What is our primary use case?
Our primary use case was for perimeter protection.
What is most valuable?
Innovative, advanced threat protection is the most valuable feature.
What needs improvement?
I don't see any specific room for improvement.
The user interface is probably not as slick as it could be.
For how long have I used the solution?
I have been using Palo Alto for three years.
We're on-premises primarily at the moment, but also a cloud product.
What do I think about the stability of the solution?
The stability is generally pretty good. I haven't heard any complaints from our customers around Palo Alto's stability. It's one of the reasons why they're the leaders in this space.
We've got our own team for maintenance. My company is a large multinational with 20,000 employees.
How are customer service and technical support?
I have contacted their support once. It's very good support. They help me to fix our problem quickly.
How was the initial setup?
The initial setup was complex. It's not very intuitive. You need to know what you're doing for the initial setup, you need to be a Palo Alto expert.
If you compare it to their competitor Fortinet, Fortinet's FortiGate product is a lot easier to install, if you're not an expert.
The time it takes to deploy depends on how complex the deployment needs to be for the client. If it's a basic deployment, is going to take around two days.
What other advice do I have?
My advice would be to make sure the firewall is configured properly.
I would rate it an eight out of ten. Not a ten because you have to be really excellent before you get a ten out of me.
In the next release, I would like to have the ability to auto-generate rule and policy, based on known traffic, based on the baseline. That is a feature that I think Palo Alto should be able to have in some form or fashion to auto-generate and propose a policy and rules set, after putting the file into a learning mode for some period.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Team Leader at a tech services company with 501-1,000 employees
Plenty of useful features, reliable, but priced high
Pros and Cons
- "There are plenty of features available in this solution, such as attack blocker and spam blocker. Additionally, it is very robust and in-depth."
- "The solution is not straightforward."
What is our primary use case?
We use this solution to protect our network.
How has it helped my organization?
This solution has helped our organization by protecting the perimeter of our network from both internal and external threats.
What is most valuable?
There are plenty of features available in this solution, such as attack blocker and spam blocker. Additionally, it is very robust and in-depth.
What needs improvement?
The solution is not straightforward.
For how long have I used the solution?
I have been using this solution for approximately eight years.
What do I think about the stability of the solution?
The solution is very stable.
What do I think about the scalability of the solution?
The scalability is good. We have approximately 500 users using this solution in my company.
How was the initial setup?
The initial setup was complex. The full installation, including customize to meet our requirements, took approximately one month.
What about the implementation team?
We used the help from an integrator team for the implementation.
What was our ROI?
The technical support is satisfactory.
What's my experience with pricing, setup cost, and licensing?
The price of the solution is on the higher side compared to competitors.
Which other solutions did I evaluate?
We are currently looking for a better-priced solution.
What other advice do I have?
This is a very good solution but it is very expensive.
I rate Palo Alto Networks NG Firewalls a six out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Download our free Palo Alto Networks NG Firewalls Report and get advice and tips from experienced pros
sharing their opinions.
Updated: January 2025
Product Categories
FirewallsPopular Comparisons
Fortinet FortiGate
Netgate pfSense
Cisco Secure Firewall
Azure Firewall
Check Point NGFW
WatchGuard Firebox
SonicWall TZ
Juniper SRX Series Firewall
Fortinet FortiGate-VM
Untangle NG Firewall
SonicWall NSa
KerioControl
Buyer's Guide
Download our free Palo Alto Networks NG Firewalls Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Is Palo Alto the best firewall for an on-premise/cloud hybrid IT network?
- What are the main differences between Palo Alto and Cisco firewalls ?
- Expert Opinion on Palo-Alto Required.
- Which is the best IPS - Cisco Firepower or Palo Alto?
- Features comparison between Palo Alto and Fortinet firewalls
- Is Palo Alto Networks NG Firewalls better than Check Point NGFW?
- Which is better - Palo Alto Networks NG Firewalls or Sophos XG?
- What are the main differences between Palo Alto firewalls and Cisco Secure Firepower?
- What is a better choice, Azure Firewall or Palo Alto Networks NG Firewalls?
- Which Palo Alto Networks NG Firewalls model is recommended for 1200 users?