Try our new research platform with insights from 80,000+ expert users
reviewer2186784 - PeerSpot reviewer
Network Engineer at a computer software company with 5,001-10,000 employees
Real User
May 25, 2023
The solution uses machine learning embedded in the core of the firewall to provide in-line, real-time attack prevention
Pros and Cons
  • "I like the remote access and URL filtering features that are available on global products."
  • "The analysis of the ITS ID by Palo Alto Networks NG Firewalls could be improved."

What is our primary use case?

We use Palo Alto Networks NG Firewalls to protect our end-to-end environment.

How has it helped my organization?

Palo Alto Networks NG Firewalls use machine learning embedded in the core of the firewall to provide in-line, real-time attack prevention.

Palo Alto Networks NG Firewalls use predictive analytics and machine learning to instantly block DNS-related attacks. The data for attacks or prevention is based on a segmented mask. Palo Alto Networks also keeps signatures updated on a holiday and on the Palo Alto Network and cloud. This helps to prevent signature leaks and secures dynamic web applications.

The solution is able to detect and resolve the initial tunneling attack.

Palo Alto Networks NG Firewalls are constantly being updated with new feature packages, and the improvements are the best we have seen compared to any other product in the industry. This is due to the company's deep knowledge of technology and the field.

The solution provides a unified platform that natively integrates all security capabilities. The ability to integrate all of the capabilities is good because it is ready to use right out of the box. Additionally, it is an ECPU. The security is quite robust.

The unified platform helps to eliminate security holes in our organization by providing multiple layers of security. This is important because it can help to prevent any attack.

The unified platform helps eliminate the need for multiple network security tools and the effort required to get them working together. If we are filtering traffic using any other firewall, we will be using different processing methods. However, when we use a firewall or a third-party tool, it then has access to the restriction using the firewall. We can then use this feature to centralize and combine with this.

The zero-delay signature feature handles Wi-Fi. It analyzes each file type that is downloaded during a session and then sends the file analysis signature to the file cloud. This has made our network more secure.

Palo Alto Networks NG Firewalls' single pass architecture provides greater security and performance because all security functions are consolidated into a single device.

What is most valuable?

I like the remote access and URL filtering features that are available on global products. There are also other features, such as application-based access, that allow us to provide user IDs based on the type of access needed.

What needs improvement?

The analysis of the ITS ID by Palo Alto Networks NG Firewalls could be improved.

Buyer's Guide
Palo Alto Networks NG Firewalls
January 2026
Learn what your peers think about Palo Alto Networks NG Firewalls. Get advice and tips from experienced pros sharing their opinions. Updated: January 2026.
881,360 professionals have used our research since 2012.

For how long have I used the solution?

I have been using Palo Alto Networks NG Firewalls for six years.

What do I think about the stability of the solution?

Palo Alto Networks NG Firewalls are stable.

What do I think about the scalability of the solution?

Palo Alto Networks NG Firewalls are scalable. We have around 10,000 users.

How are customer service and support?

The technical support is generally good, but it can be difficult to get the right person on the phone.

How would you rate customer service and support?

Positive

How was the initial setup?

The initial setup is moderate. We can deploy within an hour or two. The deployment requires two people. Four to five people can handle the maintenance.

What about the implementation team?

We implement the solution for our clients. 

What was our ROI?

Our clients have seen a return on investment with the solution.

What's my experience with pricing, setup cost, and licensing?

Palo Alto Networks NG Firewalls are expensive compared to other firewalls such as FortiGate Next-Generation Firewall.

What other advice do I have?

I give Palo Alto Networks NG Firewalls a nine out of ten.

Organizations that require network security should not choose a firewall based on cost. I recommend Palo Alto Networks NG Firewalls to harden security posture.

I definitely recommend Palo Alto Networks NG Firewalls for medium and large organizations.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Cybersecurity architect at a consultancy with 10,001+ employees
Real User
Top 10
May 3, 2023
Provides a unified platform that natively integrates all security capabilities
Pros and Cons
  • "There are many valuable features, such as wireless cloud features."
  • "The bugs can be improved."

What is our primary use case?

We use Palo Alto Networks NG Firewalls for our network security. We deployed the solution on both the cloud and on-prem.

How has it helped my organization?

Palo Alto Networks NG Firewalls machine learning secures our network against threats that evolve rapidly.

The DNS security feature is already commonly used for authentication by clients, with many threats being pushed from the inside to the outside. DNS security helps improve our network.

The DNS security feature is integral in protecting against DNS tunneling.

The solution provides a unified platform that natively integrates all security capabilities. Palo Alto Networks NG Firewalls' unified platform helps us eliminate security threats. We use all the Palo Alto Networks NG Firewalls' features including the UTM, WiFi, and VPN feature to protect our network. 

Both the network performance and security of the single-pass architecture are good. 

What is most valuable?

There are many valuable features, such as wireless cloud features. The IP and signals are updated regularly, and all UTM features provide good basic gateway-level security.

Palo Alto Networks NG Firewalls machine learning in the core of the firewall to provide real-time attack prevention is a basic requirement for our private security network.

What needs improvement?

The bugs can be improved.

For how long have I used the solution?

I have been using the solution for eight years.

What do I think about the stability of the solution?

The solution is stable. We encounter small bugs sometimes but they are not a problem.

What do I think about the scalability of the solution?

The solution is scalable.

How are customer service and support?

The technical support is good.

How would you rate customer service and support?

Positive

How was the initial setup?

For experienced people, the initial setup is straightforward. Cloud deployment can be challenging for someone new. The deployment takes around one hour.

What about the implementation team?

We implement the solution for our clients.

What other advice do I have?

I give the solution a nine out of ten.

Our clients are enterprise-level.

The PA400 series has good performance and security.

I recommend Palo Alto Networks NG Firewalls to others.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Implementer
PeerSpot user
Buyer's Guide
Palo Alto Networks NG Firewalls
January 2026
Learn what your peers think about Palo Alto Networks NG Firewalls. Get advice and tips from experienced pros sharing their opinions. Updated: January 2026.
881,360 professionals have used our research since 2012.
reviewer2169324 - PeerSpot reviewer
CIO at a government with 201-500 employees
Real User
May 2, 2023
Provides a consistent experience for the management team as well as the end user
Pros and Cons
  • "The fact that I can perform several security functions in one device at wire speed is a valuable feature. I don't have to slow down my business transactions, and I don't have to inconvenience my users with 16 different solutions. I can have it all in one box, and it protects my organization at wire speed."
  • "Surfacing actionable intelligence right away could be better. You have to dig far to get some of the information. If the solution could surface the two or three things out of the 10,000 a day that we really need to deal with, it would be helpful."

What is our primary use case?

We use this solution as our external firewall and VPN.

What is most valuable?

The fact that I can perform several security functions in one device at wire speed is a valuable feature. I don't have to slow down my business transactions, and I don't have to inconvenience my users with 16 different solutions. I can have it all in one box, and it protects my organization at wire speed.

Palo Alto Networks NG Firewalls catch a lot of things that other firewalls may not catch and support more current security practices. We get updates several times a day from WildFire, and the firewalls do a great job of keeping us protected.

Within their domain, Palo Alto Networks NG Firewalls provide a unified platform that natively integrates all security capabilities. This is critical because I don't want to deal with multiple devices. I want to do it all with as few devices as possible and have it all work successfully.

It's very important that these firewalls embed machine learning into their core because the only way to keep up with the changing threat environment is to keep learning about it.

Palo Alto Networks NG Firewalls are the gold standard right now for securing data centers consistently across all workplaces, and I'm using them across all of my locations. They provide a consistent experience for the management team as well as the end user.

What needs improvement?

Surfacing actionable intelligence right away could be better. You have to dig far to get some of the information. If the solution could surface the two or three things out of the 10,000 a day that we really need to deal with, it would be helpful.

For how long have I used the solution?

I've been working with Palo Alto Networks NG Firewalls for about 20 years.

What do I think about the stability of the solution?

It is a rock-solid solution in terms of stability. You very rarely have to worry about it. If there's a problem, it's usually because a rule got configured incorrectly.

What do I think about the scalability of the solution?

Across the product line, the NG firewalls scale very well. Within the individual units, however, there are some limitations. It's not always clear to resellers as to what those limitations are. Therefore, as your organization grows you may start to bump into those limitations unexpectedly.

How are customer service and support?

Palo Alto's technical support is pretty good and is among the best. We have called them several times, and they've been on it. Sometimes, it can take a bit longer for them to understand an issue, but overall, I would rate technical support at eight.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

We have used several firewalls including Cisco, Fortinet, and Check Point. We chose Palo Alto because it's the only one that brings it all together in one platform and lets me manage it. It also removes the complexity of what I have to manage and deal with.

How was the initial setup?

The initial setup is fairly straightforward. You put the firewall in with whatever might be there right now in learning mode, and then you can figure out where the holes are.

What was our ROI?

Palo Alto Networks NG Firewalls have prevented a number of things from happening. We would not have been able to prevent those things from happening had we had other firewalls.

What's my experience with pricing, setup cost, and licensing?

Palo Alto Networks NG Firewalls are the Cadillac standard, and you do pay Cadillac pricing. However, the protection is worth the steep price. 

What other advice do I have?

If you're looking for the fastest firewall, Palo Alto needs to be on your list. They seem to be the only ones that perform at wire speed right now. If you want the cheapest firewall, you will be able to find cheaper options, but you won't find better options than Palo Alto Networks NG Firewalls.

Overall, I would rate Palo Alto Networks NG Firewalls a nine on a scale from one to ten.

The biggest value of RSAC is being able to see everything I don't know anything about. It helps me keep up with where the industry is going.

Also, attending RSAC impacts our organization’s cybersecurity purchases made throughout the year. I chat with my existing vendors when I attend and have conversations with those my team recommends. We then make purchasing decisions based on what I see at RSAC.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer1296072 - PeerSpot reviewer
IT Supervisor at a educational organization with 51-200 employees
Real User
May 1, 2023
Powerful solution that provides good visibility, a user-friendly interface, and has good reporting
Pros and Cons
  • "It is an extremely powerful solution as it provides visibility into all the network traffic, and offers a range of actions such as blocking websites or graphics, as well as load balancing. It's a great tool."
  • "I believe it would be beneficial if the solution could integrate with Google Chrome, especially for students who use Chromebooks. However, as far as I know, the solution currently does not support Google Chrome."

What is our primary use case?

We use Palo Alto Networks NG Firewalls for cybersecurity and network security for our infrastructure for our districts, worldwide. 

What is most valuable?

The SIM's ability to analyze traffic and take appropriate action is the most valuable feature of this solution.

It is an extremely powerful solution as it provides visibility into all the network traffic, and offers a range of actions such as blocking websites or graphics, as well as load balancing. It's a great tool.

The solution's user-friendly interface and clear network visibility are highly valuable to us. It makes management easier, especially for those without extensive technical knowledge.

The benefit we derive from this solution is not only its ease of use but also how it enables collaboration among our team for special activities in our network.

Additionally, the reports that we can generate from the software are very valuable.

Using Palo Alto Networks NG Firewalls has helped us reduce downtime.

Compared to our previous solution, I believe it was Fortinet. It saves a lot of time, you know, especially running your reports and analyzing the traffic. I believe we save thirty to forty percent.

It provides a unified platform that natively integrates all security capabilities.

It has seamless integration with all our devices, including Mac and Windows, and also with our secret server. Moreover, it is even integrated with the Microsoft streaming application that we use.

The embedded machine learning functions seamlessly and can be easily accessed through the dashboard's dedicated tools. Its ease of use is impressive.

What needs improvement?

I believe it would be beneficial if the solution could integrate with Google Chrome, especially for students who use Chromebooks. However, as far as I know, the solution currently does not support Google Chrome.

For how long have I used the solution?

I have been using Palo Alto Networks NG Firewalls for five years.

What do I think about the stability of the solution?

The solution is incredibly stable. 

We have installed patches and updates, and they have all gone smoothly without any issues.

What do I think about the scalability of the solution?

We haven't fully used the capabilities of the firewall, but we purchased a larger scale to prepare for potential future growth.

The firewall is deployed across all six schools and the district office, protecting the entire infrastructure, including switches, access points, and other devices.

This is approximately 3,500 to 4,000 devices.

How are customer service and support?

The technical support team is readily available and very helpful. They provide great assistance whenever we encounter any issues.

There are delays at times, but overall, they are great. I would rate them a nine out of ten.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

Previously, we used Fortinet.

How was the initial setup?

I was involved in the deployment.

What about the implementation team?

We received assistance from the technical support team who helped us implement the project.

What was our ROI?

We have seen a return on our investment.

As previously mentioned, the firewall is easy to use and has helped us save a significant amount of time, approximately thirty to forty percent.

What's my experience with pricing, setup cost, and licensing?

The cost is quite high.

Which other solutions did I evaluate?

We evaluated Fortinet as well as Cisco.

The firewall we use is recommended by our county office of education, which also uses the same application. 

This makes it easier for us to collaborate with the county and share reports between different departments.

What other advice do I have?

I'm thoroughly impressed during my inaugural visit here. The array of products and the advanced technology showcased are truly exceptional. It's a great experience.

I plan to revisit it in the future.

Certainly, my attendance would have a significant impact on my cybersecurity-related buying choices as I would gain better insights into various vendors and their products available in the market. It would provide me with increased visibility and enable me to make informed purchasing decisions.

By attending the event and gaining insights into the different vendors and products available in the market, we can make informed decisions about which route to take in the future.

I would rate Palo Alto Networks NG Firewalls a nine out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer2168706 - PeerSpot reviewer
Security Architect at a government with 10,001+ employees
Real User
Apr 30, 2023
Natively integrates all security capabilities and decrypts by category
Pros and Cons
  • "Decryption is one of Palo Alto Networks NG Firewalls' best features because we can decrypt by category. For instance, we can decrypt everything except for bank traffic so that we don't interfere with the passwords and two-factor authentication of those checking their bank accounts at work. We can still monitor for malware and other threats that come through a secure channel. It's seamless for users. The URL filtering and IPS are both great as well."
  • "Palo Alto Networks NG Firewalls need better training modules. You have to do a lot of reading prior to watching the training videos, and it's good for people who are really into it. However, often you want to use a video for a TID. You want to see how to do something rather than spend 30 minutes reading and then another 30 minutes watching the class. As a result, I take third-party training classes rather than Palo Alto's training because they are a lot better."

What is our primary use case?

We started using this solution as a basic firewall, and then, we ended up with URL filtering, IPS, and decryption.

How has it helped my organization?

It increased visibility, and we can see things that we couldn't see before and are able to decrypt as well. We can actually see what's going on in our network.

What is most valuable?

Decryption is one of Palo Alto Networks NG Firewalls' best features because we can decrypt by category. For instance, we can decrypt everything except for bank traffic so that we don't interfere with the passwords and two-factor authentication of those checking their bank accounts at work. We can still monitor for malware and other threats that come through a secure channel. It's seamless for users. The URL filtering and IPS are both great as well.

Palo Alto Networks NG Firewalls provide a unified platform that natively integrates all security capabilities. WildFire stops a lot of viruses and malware that come in from the outside. In addition, when you decrypt the traffic you'll be able to see a lot that you couldn't before. You can then integrate that into a SIEM and have visibility into all the different things that are going on. Integration with WildFire provides sandboxing and tells you if it's malicious content or not. Then, you can do URL filtering for the endpoints. All of this data goes into the SIEM. Thus, it's a really good, well-integrated software.

This native integration is very important to us because of the cost. When we get an enterprise license and get all these features on one device, we don't have to buy five devices or virtuals or set up a virtual or cloud farm to do the five things that the solution will do automatically, natively out of the box. We have been able to save money because we are able to get rid of our decryption software and are getting close to letting go of our filtering software.

It's important to us that Palo Alto Networks NG Firewalls embed machine learning in the core of the firewall to provide inline, real-time attack prevention. This is important because those who exploit us daily use new tactics that are not seen at all times. They employ tactics that use applications that we currently use, such as PowerShell. If a PowerShell script comes in and it's decrypted, launched in WildFire in a sandbox, and blocked, it cuts our threat vector down tremendously.

When we go across all the workspaces, it's simple. The web-facing servers are protected with IPS, and the endpoints are protected with URL filtering in the sandbox and decryption. We log all of the MAC addresses, so we block hackers from getting into different websites when staff use a Wi-Fi connection off-site. In terms of securing data centers consistently across all workspaces, our whole ecosystem depends on having Palo Alto so that we can have one centralized SIEM where all the data is. Our SOC can investigate all the alerts that we get from all of these different areas.

What needs improvement?

Palo Alto Networks NG Firewalls need better training modules. You have to do a lot of reading prior to watching the training videos, and it's good for people who are really into it. However, often you want to use a video for a TID. You want to see how to do something rather than spend 30 minutes reading and then another 30 minutes watching the class. As a result, I take third-party training classes rather than Palo Alto's training because they are a lot better.

The training should be more accessible because if everybody has to pay for training, it makes it harder for us to get in techs who are qualified to do the work. If there are clear levels and schemes for certification, it would be great.

For how long have I used the solution?

I've been using this solution for probably five years now.

What do I think about the stability of the solution?

The firewalls are always on, and we haven't had any stability problems. We haven't even had any hardware failures, and the perishables are great.

What do I think about the scalability of the solution?

The firewall's scalability is nice because you can take a VM and put more memory in it. If you virtualize, then you can scale it out. With an enterprise license, you can load several to get all different points of your internet access. For example, one could do URL filtering just for the desktop, and another one could be an IPS in front of something else.

It's very flexible, and you can use these virtuals to contain all these different situations from an architectural standpoint without having to buy other software.

How are customer service and support?

Palo Alto's technical support is great, and I'd give them a ten out of ten.

How would you rate customer service and support?

Positive

How was the initial setup?

The initial setup is straightforward in the sense that when you put it in it starts doing what it's supposed to do. Then, you have to turn on all the features that you want.

What about the implementation team?

We mainly worked with Palo Alto Networks. They taught us a lot and have been very helpful in getting us onboarded with all of the different features.

What was our ROI?

We see a return on our investment every day. We have threat hunters who go through the data and tell other state agencies where the problems are or what we were able to stop.

What's my experience with pricing, setup cost, and licensing?

We haven't had a problem with pricing or licensing because we consolidated other software to make Palo Alto more affordable.

What other advice do I have?

If you're just looking for the cheapest and fastest firewall, remember that you'll get what you pay for. Check if the company is able to support its product 24/7. You have to be able to get technical support on the phone at any time of the day or night. In addition, the company has to be able to do training on its firewall, and there has to be a job market for it so that there's an employee pool from which you can pick someone who knows the software. If it's an obscure software company, and they only have two or three people in the country who are certified on it, then it would hurt you a lot because you won't be able to call these two or three people in the middle of the night and expect them to always be there. Palo Alto has a very deep bench, so they can go globally and get you tech support at any time. That's very helpful.

The price is dependent upon how many features you use. If you have a Palo Alto ecosystem where you use Prisma, IPS, URL filtering, and decryption, it's going to be affordable because you will be able to eliminate other software. However, if you're looking to use Palo Alto as just a firewall, it may not help you that much because everybody out there competes to provide a firewall experience.

On a scale from one to ten, I would rate Palo Alto Networks NG Firewalls a ten.

The value I get by attending an RSA Conference is being able to see new up-and-coming software. Some products are new to the market, and others are trying to get their product to market. A lot of times, these products have key features that others don't.

Attending RSAC helps to influence cybersecurity purchases throughout the year because we are able to see a product that we didn't know was available. We learn that there is software that does certain functions that we didn't even know we needed. There are some products at RSAC that may be too expensive, but there are others that we would consider because they are cost-effective and have feature sets that we didn't know about.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer1531437 - PeerSpot reviewer
Sr. Infrastructure Solution Architect and Engineer at a aerospace/defense firm with 10,001+ employees
Real User
Apr 30, 2023
Helped us meet our security requirements but the technical support needs improvement
Pros and Cons
  • "The fact that the Next-Gen firewalls are integrated with identity is the best. It gives us the ability to track what an individual is doing and helps us provide access to only what they need in order to do their job."
  • "Palo Alto Networks NG Firewalls don't provide a unified platform that natively integrates all security capabilities. It's missing some features for geofencing and understanding locations."

What is our primary use case?

We mainly use the solution for traditional firewall boundaries.

How has it helped my organization?

The solution helped us meet our security requirements.

What is most valuable?

The fact that the Next-Gen firewalls are integrated with identity is the best. It gives us the ability to track what an individual is doing and helps us provide access to only what they need in order to do their job.

Because we want to free up our operators from the routine tasks of investigations, it's important to us that Palo Alto Networks NG Firewalls embed machine learning in the core of the firewall to provide inline, real-time attack prevention.

What needs improvement?

Technical support could be improved. Palo Alto's technical support used to be great. Whenever I had a problem, I could pick up the phone and call and get answers. That's not the case any longer.

Palo Alto Networks NG Firewalls don't provide a unified platform that natively integrates all security capabilities. It's missing some features for geofencing and understanding locations.

These firewalls are primarily used for edge defense. In terms of securing data centers consistently across all workplaces, that is, from the smallest office to the largest data centers, Palo Alto Networks NG Firewalls don't have a strong zero trust model.

NG Firewalls have not helped us reduce downtime in our organization. Because of technical support issues, we've taken some hits.

For how long have I used the solution?

I've been using Palo Alto Networks NG Firewalls for 20 years.

What do I think about the stability of the solution?

It's always been a stable product.

What do I think about the scalability of the solution?

This solution is a firewall that's a hardware appliance, and that's not the direction the industry is heading. Everybody is going toward a software-defined perimeter. Palo Alto doesn't have a strong say on it. They took what they had for their hardware and just put it in the cloud without understanding what being cloud-centric is all about.

How are customer service and support?

I would rate the technical support a three out of ten.

How would you rate customer service and support?

Negative

What was our ROI?

Our ROI is that the firewalls have been used quite a few times for investigations. We've gathered the evidence we needed to act upon an issue.

What's my experience with pricing, setup cost, and licensing?

These firewalls are not cheap, but they have a reasonable licensing model.

What other advice do I have?

If you are considering attending an RSA Conference, note that you won't gain enough information by attending one conference. However, when you attend year after year, go through the expo, and talk to vendors, you will begin to see trends. You'll see that what's hype one year is no longer a reality another year. Thus, the experience with RSA is a multiple-year experience.

Attending RSAC has made an impact on our organization’s cybersecurity purchases. We've brought products back into our infrastructure based on what we discovered from talking to vendors at the RSAC.

Overall, I would rate Palo Alto Networks NG Firewalls a seven out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
MartinFerguson - PeerSpot reviewer
Managing Director/Co-Founder at a tech services company with 1-10 employees
Real User
Nov 30, 2022
The solution simplifies operations, ties into existing services, and uses machine learning
Pros and Cons
  • "I can enable the features I want and configure the policies based on the user and not all users and network traffic, making firewall management much easier."
  • "We have not taken Palo Alto's firewall management solution because it's too expensive and we don't feel it delivers significant value."

What is our primary use case?

We use the solution for all the capabilities that the firewall offers, including proxy filtering, VPN connection, and Next-Gen firewall capability. We integrate the solution with clients that use ExpressRoute, which is a very common and popular service in Australia. We route all our client's local traffic, 10.x, and the client's Class B public address traffic all into Palo Alto Networks NG Firewalls. We use the solution to provide hub and spoke integration, web filtering, and for VPN. 

The solution is a fully managed centralized firewall service for both public and private traffic, including on-prem traffic and Azure traffic.

How has it helped my organization?

The solution ties into existing services. We offer network-based services and SD-WAN overlay. We use VeloCloud appliances and put the solution at the heart of that to provide Next-Gen security capability. The solution benefits our clients by reducing the number of firewalls required in their organization, which is hosted in Azure. The solution's aggregation gives us the ability to service our clients by reducing their firewall footprint. The solution also enables us to route all traffic, including internet outbound traffic from a client's side onto Palo Alto NG Firewalls across an ExpressRoute connection.

Palo Alto NG Firewalls provide a unified platform that natively integrates all security capabilities.

In combination with additional tools and services we offer, the solution makes a significant contribution to eliminating security holes.

The solution helps eliminate multiple network security tools and the effort required to have them work together. The solution simplified our operations. We only support and deliver Palo Alto NG firewalls as a service. We don't offer a firewall as a service on any other appliance. We chose Palo Alto because of its Next-Gen capabilities and being the market leader in terms of security appliances. 

What is most valuable?

I like the native integration into Azure AD and the solution is fantastic from the perspective of managing user access and using the VPN client. The TLS inspection is a fantastic service that's offered in Palo Alto NG Firewalls. In my opinion, the solution is best of breed, which is one of the reasons why we adopted it in the first place.

We have had a couple of DNS attacks and predictive analytics and machine learning for instantly blocking DNS attacks worked well. 

Depending on the license skew, we implement the zero delay signatures feature for some of our customers.

I can enable the features I want and configure the policies based on the user and network traffic, making firewall management much easier.

What needs improvement?

There are some features of Fortinet such as the virtual domain capability, that I would love to see in this solution, but they don't outweigh the technical capabilities of Palo Alto as the firewall.

We have not taken Palo Alto's firewall management solution because it's too expensive and we don't feel it delivers significant value. We have developed our own reporting. Sometimes there are limitations around the APIs and it would be great if the APIs could be enhanced.

For how long have I used the solution?

I have been using Palo Alto Networks for about 10 years, but not the Next-Generation version. Five years ago, we set up a Palo Alto firewall as a service with Palo Alto in the back end. We did this for Telstra in Australia, and we're the only company in the world that can support the default route over ExpressRoute, using the Palo Alto Networks NG Firewalls as a service that we offer.

What do I think about the stability of the solution?

The stability of this solution is unbelievable and the best on the market. We've never had an outage as a result of a technical problem on hundreds of firewalls that we run or thousands when we include the HA pairs and clusters that we've built.

What do I think about the scalability of the solution?

The solution is scalable and we have never reached the limits. We stuck with Palo Alto because of their Next-Gen capabilities, and we have about 500 clients using this solution as a service.

How are customer service and support?

The technical support is exceptionally good. They have more capabilities in Australia now and we've had no problems. The technical support has been so good, we haven't had to look for another vendor.

How would you rate customer service and support?

Positive

How was the initial setup?

The initial setup is straightforward. We have a multi-tenanted version and a single version. We have different flavors of the implementation and it's all scripted. We can build a fully operational firewall HA pair with follow-the-sun, 24-hour, seven-days-a-week support in about 30 minutes. We use DevOps to set everything up and it is effective because it is all scripted.

What about the implementation team?

The implementation was completed in-house.

What was our ROI?

Our service is incredibly profitable. We don't feel we can offer an alternative that will give us the same return on investment.

What's my experience with pricing, setup cost, and licensing?

The pricing is straightforward with no hidden costs. There is a cost for the licensing, the Virtual Network if the solution is run in Azure, and there is also a cost for the operational support.

I suggest sizing correctly when in the cloud because the skew can always be changed at a later time.

Which other solutions did I evaluate?

We've evaluated a couple of other products in the past to make sure that we still have the right solution in the market.

What other advice do I have?

I give the solution a nine out of ten.

The embedded machine learning included in the solution's firewall core used to provide inline real-time attack prevention is an important capability because it gives us the heuristics. The solution uses existing knowledge of the service and how we use the firewall, to determine if something nefarious is being undertaken. I don't believe that we are using the feature to its fullest capability.

We integrate Palo Alto NG Firewalls into Sentinel and we use additional data points to determine attacks.

We use the solution's DNS security for some of our clients.

We use a lot of data points from various systems and not only this solution to determine if a threat is live and active. We don't recommend publishing using the solution. We do local DNS resolution using the Palo Alto NG Firewalls. We're purely an Azure consultancy. We use Azure publishing services to publish. We integrate the solution into virtual networks from a DNS point of view, but we are always on the safe side, and we never use the solution for DNS publishing to the public internet. We are an ISB. We provide managed services, but we are primarily an integrator.

In terms of a trade-off between security and network performance, there will always be a performance lag when doing TLS inspections because the traffic has to be decrypted in real-time, however, the benefit outweighs the disadvantages from a network performance perspective. When the TLS inspections are sized properly, the performance lag is hardly noticeable.

We sometimes work with Palo Alto, for example, to support the default route over ExpressRoute.

The maintenance is all scripted and fully automated. We are always at the current stable release and we update as regularly as we get the updates from Palo Alto. There is no impact, no downtime, and no loss of service unless we've got a customer with a single firewall that requires a reboot, in which case we schedule the outage.

I have worked with many different appliances in Azure over the years, and I still do with some clients who already have incumbent NBAs, but for our firewall as a service, I have always used Palo Alto.

What we find is that clients want to utilize the features but don't know how to implement them or have the capability. We offer that support. Palo Alto is extremely good value for the money if we maximize its capabilities. If we want a cheap firewall, then Palo Alto isn't the answer. If we want a capable value-for-money firewall, when we are utilizing all of the services available, Palo Alto is the best on the market. If we want a cheap solution we can go to Fortinet which is not as technically sound but for someone who is price sensitive and doesn't want to use all the features and functions of Palo Alto NG Firewalls that is an option. We work with Palo Alto for our firewall as a service, and we work with Velo for our network as a service. The operational run cost for us is low with these vendors because those firewalls are extremely reliable and because we don't have problems with the firewalls, we don't need a big operational support team.

We did some work with the NHS Test and Trace program and they had a multi-client solution that we deployed hundreds of firewalls across Azure and AWS, using Palo Alto. The client did explore other vendors that were cheaper and after looking at the operational support capability, features, and how reliable the firewall was, the option was clear and not driven by price. 

I would automate the solution. I would use infrastructure as code deployment and manage my devices using IHC. If I was going for a larger state, I would use the solution's management tool.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Microsoft Azure
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
Sachin Vinay - PeerSpot reviewer
Assistant Manager-Networks at a university with 1,001-5,000 employees
Real User
Top 5Leaderboard
Nov 3, 2022
Supports single-pass architecture, provides comprehensive security, and is cost-effective
Pros and Cons
  • "It has a unique approach to packet processing. It has single-pass architecture. We can easily perform policy lookups, application decoding, and integration or merging. This can be all done with a single pass. It effectively reduces the amount of processing required to perform multiple actions. This is the main advantage of using Palo Alto."
  • "It is a complete product, but the SSL inspection feature requires some improvements. We need to deploy certificates at each end point to completely work out the UTM solutions. If you enable SSL encryption, it is a tedious process. It takes a lot of time to deploy the certificates to all endpoints. Without SSL inspection, UTM features will not work properly. So, we are forced to enable this SSL inspection feature."

What is our primary use case?

We are using PA-820. This Palo Alto series is being used in our separate branch office. We are managing surveillance and internet activities with this Next-Generation security firewall. We are using the UTM features and running best security practices through this firewall. Moreover, VPNs and other remote access security features are being implemented in our environment with this firewall.

How has it helped my organization?

It has a very good security database for attack prevention. There are many security breaches, and most of the 2022 security breaches use automation. It has a really good automation engine that clearly prevents new types of attacks. We recently avoided an attack with Palo Alto.

DNS security is super good in this. Its DNS attack coverage is 40% more, and it can disrupt 80% of attacks that use DNS. Without requiring any change in your infrastructure, you can avoid the attacks. With this Palo Alto firewall, we are able to manage DNS security in a single device because it has single-pass architecture.

It provides a unified platform that natively integrates all security capabilities. It has a VPN. We don't need to go for additional security features or devices in our environment. It is an all-in-one solution. With other firewalls, such as FortiGate, you require separate licenses. For example, for high availability, you would require an additional license, which is not the case with Palo Alto. In this way, Palo Alto is completely in line with our budget requirements. We are also planning to go with the higher version of Palo Alto firewalls in our environments.

It has helped to eliminate security holes. It creates a usage pattern with its machine learning and artificial intelligence features. It uses a good amount of artificial intelligence to create a pattern. If there are any changes in the usage pattern, it notifies us, and we are able to take action.

In our environment, we are running a lot of production servers. So, we cannot compromise on security. We give more priority to security than performance in our architecture. We put 70% focus on security and 30% on performance. Palo Alto completely suits our requirements. They have three-tier security. We can see the application layer traffic, network layer traffic, and session layer traffic.

It integrates perfectly. It integrates with SIEM solutions such as Darktrace. For log analysis, we are able to completely retrieve the logs.

What is most valuable?

The most important feature is advanced threat prevention. It stops most malware. It provides 96% or 97% prevention against malware. It has a leading intrusion prevention system in the industry. It is really good at malware prevention. It ensures that files are saved in a good and secure environment. It automatically detects and prevents unknown malware with its powerful malware prevention engine. 

It has a unique approach to packet processing. It has single-pass architecture. We can easily perform policy lookups, application decoding, and integration or merging. This can be all done with a single pass. It effectively reduces the amount of processing required to perform multiple actions. This is the main advantage of using Palo Alto.

What needs improvement?

It is a complete product, but the SSL inspection feature requires some improvements. We need to deploy certificates at each end point to completely work out the UTM solutions. If you enable SSL encryption, it is a tedious process. It takes a lot of time to deploy the certificates to all endpoints. Without SSL inspection, UTM features will not work properly. So, we are forced to enable this SSL inspection feature. 

For how long have I used the solution?

It has been three years.

What do I think about the stability of the solution?

It is extremely stable.

What do I think about the scalability of the solution?

It is scalable. There is a VM solution also, so it is completely scalable. 

We have about 3,000 users in our branch office. In terms of our plans to increase its usage, we are also planning to go for Palo Alto as our main firewall. We are planning to go with the higher-end version.

How are customer service and support?

I would rate them an eight out of ten.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

In our branch office, before the Palo Alto firewall implementation, we have been using FortiGate. We switched because of the budgetary requirements. With FortiGate, for the high availability feature, we required two devices. We had to buy two licenses, whereas Palo Alto required only one license. It was completely in tune with our budget. So, we had to go with Palo Alto.

FortiGate did not have single-pass architecture. It took a huge amount of resources for each action. For policy lookups, it took a considerable amount of system resources, such as CPU, RAM, etc. The waiting time was too high for policy lookup, application decoding, and signature matching. All this is carried out in a single pass in Palo Alto. So, it is considerably fast and also secure. There is no compromise in terms of security. It is completely secure, and we are able to do more functions in a single pass with the Palo Alto firewall. So, we save a lot of resources. With FortiGate, security was around 50%. After the implementation of PA 820, it has increased to 80%. We have achieved about a 30% increase in security. Even though PA 820 is not a higher-end series, performance-wise, it matches the higher-end series of FortiGate. So, there is a considerable amount of cost savings. We are able to save 20% to 30% extra.

In our organization, we have multiple vendors. We have FortiGate, Cisco ASA, and other security implementations. We have already purchased many other products. So, we cannot simply suggest Palo Alto across the organization. We have to consider the older purchases.

Palo Alto is a good competitor to FortiGate. Cisco, FortiGate, and Palo Alto are the three main competitors. When we compare these products, they have similarities, but I would suggest going with Palo Alto for higher security. If you are giving more priority to security and less priority to performance, definitely consider this. Cisco ASA and FortiGate are more performance-oriented. So, if you are planning to give more priority to security, I would definitely suggest Palo Alto.

How was the initial setup?

Its initial setup was complex. It was not straightforward. It required a considerable amount of time and effort. Migration was a little bit complex because we had a different vendor product. Migrating to this product required a considerable amount of time and planning because we didn't want to disrupt the networking in our existing environment. It took a good amount of planning and decision-making to migrate to Palo Alto.

Its deployment took about a week. In terms of the implementation strategy, we were deploying it at the branch office. We already had a solution there. So, we had to completely migrate the policies and everything else. We also had to identify the interfaces with the utmost urgency. We first migrated important interfaces and made sure that they all are working fine and all the security features are working fine. After that, we enabled all the policies and other features. In this way, we were able to completely migrate in seven days.

What about the implementation team?

It required three network administrators. They are responsible for actively managing the firewall configurations, taking backups, etc.

What was our ROI?

With this highly secure environment, we are able to maintain our production-level servers on-premises. We were planning to move them to the cloud for security, but with the implementation of Palo Alto, we were able to maintain them on-premises. We could create a considerable amount of production service, and thereby, we had a great return on investment through this.

What's my experience with pricing, setup cost, and licensing?

It is not that expensive. I would rate it an eight out of ten in terms of pricing. Other than the licensing, there are no additional costs.

Which other solutions did I evaluate?

We didn't evaluate anything other than FortiGate and Palo Alto.

What other advice do I have?

I would recommend this solution if security is more important to you. If the performance of the users is more important, I would not suggest Palo Alto. It gives more priority and weight to security. It has a complete security mechanism with AI, log-based analysis, etc. I would recommend it for higher cybersecurity and IT-related environments.

I would rate it a nine out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Download our free Palo Alto Networks NG Firewalls Report and get advice and tips from experienced pros sharing their opinions.
Updated: January 2026
Product Categories
Firewalls
Buyer's Guide
Download our free Palo Alto Networks NG Firewalls Report and get advice and tips from experienced pros sharing their opinions.