It can do sandboxing on the premises, and it can be directly integrated with Palo Alto NGFW. The malware information on the file that has been sandboxing will be directly updated to the Palo Alto NGFW, and added to the Palo Alto Networks NGFW malware signature library. Also, the credential data within the file that has been sandboxing still be kept on the premises.
Data and Storage Systems Manager at a media company with 1,001-5,000 employees
Palo Alto is an easy to manage firewall.
Palo Alto is an easy to manage firewall. It connects successfully in AD and LADP for user based policy. It has rich application info for app.based policies and it gives enough IDS performance. New policy compile is speedy.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
IT Security Engineer at a tech services company with 51-200 employees
It can do on-premises sandboxing and detect attacks by malware embedded on files and URLs, but it should handle many more file types without sending .APK files to the cloud for sandboxing.
What is most valuable?
How has it helped my organization?
Palo Alto Networks WildFire can detect many types of attacks that are using malware embedded on files/URLs with minimum time, and it can increase the effectiveness of resources (time and people) to prevent the malware.
What needs improvement?
In my opinion, it could be developed to be dependent not only on signatures, but also on patterns and behavior of malware. What I would like to see in the next version/release is to be able to handle much more file types on premises during deployment, because now on premises deployment a .APK file must be sent to the cloud for sandboxing.
For how long have I used the solution?
I can't remember exactly, but probably more than six months.
What was my experience with deployment of the solution?
For now, I have no issues with the deployment.
What do I think about the stability of the solution?
For now, I have no issues with the stability.
What do I think about the scalability of the solution?
For now, I have no issues with the scalability.
How are customer service and technical support?
Customer Service:
Both customer server and technical support are very good.
In our case, before we contact Palo Alto Networks technical support, we can contact the Palo Alto Networks local distributor, who provide Palo Alto Networks technical support locally.
Which solution did I use previously and why did I switch?
I forgot what the name or product that used previously, but the reason I choose Palo Alto Networks wildfire is it integrated with Palo Alto Networks NGFW that already used on the network environment
How was the initial setup?
The initial setup of Palo Alto Networks WildFire is simple.
What about the implementation team?
We’re the ones who implement the Palo Alto Networks WildFire in our customers environments.
What was our ROI?
It’s not about what we will get directly from having Palo Alto Networks WildFire as an ATD device, but it’s all about the loss of resources you suffer if you don't have it implemented.
Disclosure: My company has a business relationship with this vendor other than being a customer. We are Palo Alto Networks partner and reseller.
Buyer's Guide
Palo Alto Networks WildFire
October 2025
Learn what your peers think about Palo Alto Networks WildFire. Get advice and tips from experienced pros sharing their opinions. Updated: October 2025.
873,003 professionals have used our research since 2012.
Network Systems Manager with 51-200 employees
A custom script is required to put the SSL Decryption certificate into Mozilla Firefox but it is a very comprehensive and secure firewall.
What is most valuable?
User identification and the Applipedia are the most useful. The integration of the Applipedia with the application identification at layer seven makes it a very comprehensive, and secure, firewall.
How has it helped my organization?
We have the ability to see what traffic is coming and going in a much deeper and more detailed fashion. We have also found, and stopped, several malware applications before they infected the endpoints.
For how long have I used the solution?
I've used it for five months.
What was my experience with deployment of the solution?
During initial testing we were too strict on what was allowed outbound. We ended up needing to open up more broad categories. We also found that several websites do not function well with the SSL Decryption feature. We also found that a custom script is required to put the SSL Decryption certificate into Mozilla Firefox.
What do I think about the stability of the solution?
No the product has been very stable and reliable.
What do I think about the scalability of the solution?
We implemented it in a smaller environment but, find that the 3000 series has plenty of power and has the ability to grow with us as we provide north-south as well as east-west security between internal environments.
How are customer service and technical support?
Customer Service:
Customer service is very friendly and responsive to any request.
Technical Support:I have found the tech support to be impressive. Support agents are available 24/7, and I have never waited for more than an hour to speak with an agent. I would consider the first team you call to be equivalent to most level two or three engineers.
Which solution did I use previously and why did I switch?
Previously we used Cisco ASA 5510 and Fortinet. Fortinet was an old version and was phased out due to this. The Cisco ASA was replaced do to the limited capability of the out of box functionality and reporting.
How was the initial setup?
Initial set-up was straightforward and easy. We were able to get both devices on the network and set-up to look at traffic within a few hours on split up time. The products complexity came from the terms and the overall thinking of how the product works.
What about the implementation team?
We did it in-house.
Which other solutions did I evaluate?
Before choosing Palo Alto we also reviewed Cisco ASA, Fortinet, and Sophos.
What other advice do I have?
The product is straightforward to implement, though if you are looking for a quick implementation, I would suggest bringing in an expert.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Could you let me know the bandwidth before and after installation of the device. How much was the reduction in speed. How about performance in VPN ?
Chief Information Security Officer at a financial services firm with 51-200 employees
The deployment of Wildfire was surprisingly easy but inspection over different protocols needs to be improved.
What is most valuable?
Being able to discover malicious files unknown to most AV vendors.
How has it helped my organization?
It has allowed me to stop new attacks before they could gain a foothold in my network.
What needs improvement?
- Inspection over different protocols (not just HTTP/FTP)
- Inspecting more file types
- Providing information back to the community that it uses to support its product.
For how long have I used the solution?
I've used it for three years. However, my current company isn't using the product. I took a different engineering route into the company and I decided to use other protection solutions and not Wildfire.
What was my experience with deployment of the solution?
The deployment of Wildfire was surprisingly easy.
What do I think about the stability of the solution?
Wildfire itself was a very stable product.
What do I think about the scalability of the solution?
I never had any issues with scalability. When I enabled it, it seemed to work in the environment that the firewall was already servicing.
How are customer service and technical support?
Customer Service:
Great when I was at a large company but average or less than average at a small company.
Technical Support:Overall their support people are better than most tech companies.
Which solution did I use previously and why did I switch?
There was no solution in this space before Wildfire. Both FireEye and Wildfire came onto the market right around the same time.
How was the initial setup?
It was straightforward as I could, literally, turn on the firewall settings in five minutes or less.
What about the implementation team?
You really don't need to pay to turn it on. The configuration is very simple.
What was our ROI?
There are two levels of Wildfire.
- The free version which is great, so I would guess there is no ROI on this version
- Then there is the subscription version of the service and this is a very affordable yearly subscription per firewall
What's my experience with pricing, setup cost, and licensing?
Initially, the product doesn't cost anything for the first tier of usage you can prove the product before buying it.
Which other solutions did I evaluate?
- FireEye
- Blue Coat
- ProofPoint.
- Even as the more the list of products I look at each year is pretty long.
What other advice do I have?
If you're running Palo Alto firewalls there is no reason not to use it at the free level. Once you have run it for a while at the basic level, you can make an educated decision if it's worth paying for the subscription (it is).
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
it_user333885EMEA Corporate Sales - Advanced Cyber Security Solutions at a tech company with 5,001-10,000 employees
Real User
Best bit is out of 27000 customers of Palo Alto Networks, you are getting intel from every single PA appliance which resembles to millions of users' data. The time for wait is about to drop to 5min from 15min.
Security Technical Lead at a tech services company with 11-50 employees
Sandboxing prototype and the ability to analyze a broad spectrum of file types ensure effective threat detection
Pros and Cons
- "The threat intelligence from WildFire supports our proactive defense strategies."
- "Palo Alto doesn't do much to support the on-premise version. It wants too much self-support for the on-premise version of WildFire."
What is our primary use case?
Sandboxing is the primary use case. WildFire is used for that. There are two options: one is on the cloud, and one is on-premise. The cloud version is perfect. It is working very well. But on the on-premise version, we have faced a lot of problems previously.
How has it helped my organization?
The threat intelligence from WildFire supports our proactive defense strategies. Palo Alto has a unit 42 team, which is one of the best in the market for threat intelligence. Their threat intelligence is comprehensive.
Also, Palo Alto is a pioneer in AI and ML integration, so I think there are some AI processes running in clusters.
What is most valuable?
It can detect new threats, particularly. It's a sandboxing prototype.
We send mostly emails or connections with context or files. The most important thing is how many kinds of files the sandbox can handle. Also, Palo Alto is good at this. There are more than 20 different file types, this product can understand.
The important thing for sandboxing is how many different types of files the sandbox product is analyzing. And so, also, Palo Alto is good at it, compared to other sandboxes.
What needs improvement?
Palo Alto doesn't do much to support the on-premise version. It wants too much self-support for the on-premise version of WildFire.
But for regulation purposes, some of our customers don't want to use the cloud environment, so they have to use the on-premise version.
Integration is okay, not too hard, with Palo Alto. But we are facing a lot of issues, and most of the issues go unresolved. So, the on-premise version is not very stable.
With my experience, the cloud version is stable. So I need the on-premises version to be more stable.
For how long have I used the solution?
I have been working with Palo Alto for four years, but I have been familiar with WildFire for one and a half years.
What do I think about the stability of the solution?
I would rate the stability a seven out of ten.
The cloud version is very stable. It is working very fine. Integration is very easy. There are not too many issues. I like it. Compared to the on-premise version, it is very easy and very effective for customers.
Which solution did I use previously and why did I switch?
Some of my colleagues work on SD-WAN.
How was the initial setup?
The initial setup is a little bit complex on-premise, but not too complex because it can only connect to a Palo Alto firewall. On the cloud, it is very easy; you only need to enable it with a click, and it is done. After that, you can set up the configuration on the firewall.
But on-premise, it is not a configuration issue; it's a little bit of a stability issue.
Integration with existing infrastructure:
WildFire can only integrate with the Palo Alto firewall. Right now, maybe XDR can integrate on the cloud version, but you cannot integrate it with other vendors or put it standalone without any Palo Alto product.
What about the implementation team?
We are an integrator. We also work with some other vendors.
What was our ROI?
WildFire has improved our customer's security posture and reduced costs overall.
It's not hard to configure as it connects to the firewall. After integration, you don't need much configuration and don't waste too much time, so the return on investment is very rapid.
What's my experience with pricing, setup cost, and licensing?
In general, all Palo Alto products are a little bit higher in price compared to competitors.
What other advice do I have?
I recommend it, but mostly the cloud version.
I recommend it to any company who needs sandboxing or this kind of file analysis. But they must be careful if they have to use on-premise, because of the stability issues.
Overall, I would rate the solution an eight out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Network Engineer at a tech services company with 51-200 employees
Lacking features, but good technical support, and scalable
Pros and Cons
- "The solution is easy to use and the Panorama feature is good. The software management or the malware blocking and some authentication management system are good."
- "When comparing this solution to others it is not as good overall."
What is our primary use case?
We are using Palo Alto Networks WildFire as our network firewall.
How has it helped my organization?
The solution has helped our company stay secure from the security features it provides.
What is most valuable?
The solution is easy to use and the Panorama feature is good. The software management or the malware blocking and some authentication management system are good.
What needs improvement?
When comparing this solution to others it is not as good overall.
For how long have I used the solution?
I have been using Palo Alto Networks WildFire for approximately one year.
What do I think about the stability of the solution?
Palo Alto Networks WildFire is a stable solution.
What do I think about the scalability of the solution?
I have found Palo Alto Networks WildFire to be scalable.
We have 10 users that use this solution. We plan to increase usage in the future.
How are customer service and support?
The technical support is good.
Which solution did I use previously and why did I switch?
I have used other similar solutions, such as HP, Checkpoint, and Fortinet.
How was the initial setup?
The implementation is not difficult and the full process took approximately two days.
What about the implementation team?
We have an internal team that did the implementation of the solution. We do some of the maintenance ourselves but if we have trouble we contact the support.
What other advice do I have?
I rate Palo Alto Networks WildFire a five out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Information Technology Security Engineer at a tech services company with 11-50 employees
Enhance threat detection for diverse formats with proactive defense capabilities
Pros and Cons
- "I have files tickets and their support was great. I was able to solve the problems of my customers."
- "Improving detection on non-Windows formats would be beneficial as there are many samples, such as Linux or ransomware for macOS."
What is our primary use case?
I use WildFire mostly for customers, especially when they ask about firewalls. We recommend Palo Alto, FortiGate, Check Point, and then a customer decides what is the best firewall for their tasks.
I generally recommend WildFire for telecom companies, banks, supermarkets, or any company which has its own IT infrastructure.
How has it helped my organization?
It provides threat intelligence that supports customers' proactive defense strategies. If a customer has an updated database of signatures or behavior, it is useful for their protection.
What is most valuable?
The features depend on the file format. For Windows, there is one set of features, and for Linux binaries, it is another. All sandboxes basically work with new binaries for Linux or macOS since they are not able to emulate behavior, and they are unable to analyze what code snippets or what behavior is malicious for binaries.
What needs improvement?
Improving detection on non-Windows formats would be beneficial as there are many samples, such as Linux or ransomware for macOS. Enhancing detection in these areas would be great.
For how long have I used the solution?
I have been familiar with WildFire for two to three years, but it depends on the customer because it can be rather periodic.
How are customer service and support?
I have files tickets and their support was great. I was able to solve the problems of my customers.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I have interacted with Microsoft Box and some online sandboxes.
What was our ROI?
Generally speaking, it is hard to analyze ROI since no one in Ukraine did analytics on sandbox networks.
What's my experience with pricing, setup cost, and licensing?
It is hard to say because there is a significant difference between some European countries and Ukraine in the ability to buy expensive products. European countries may not find it a huge problem to spend $10,000, however, it is a significant issue for Ukrainian companies, especially given the current situation with war.
Which other solutions did I evaluate?
I use any online sandbox which is allowed to be public and frequently check malicious files in virus or sandboxes, including virus total information.
What other advice do I have?
I would recommend improving detection in non-Windows formats. Currently, scripts like PHP scripts, Bash scripts, and other issues not related to Windows rank much worse.
I'd rate the solution nine out of ten.
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
Buyer's Guide
Download our free Palo Alto Networks WildFire Report and get advice and tips from experienced pros
sharing their opinions.
Updated: October 2025
Product Categories
Advanced Threat Protection (ATP)Popular Comparisons
Microsoft Defender for Endpoint
Microsoft Defender for Office 365
Microsoft Defender for Identity
Trend Micro Deep Discovery
Digital Guardian
Barracuda CloudGen Firewall
Fortinet FortiSandbox
Trellix Network Detection and Response
Check Point SandBlast Network
Check Point Infinity
Symantec Advanced Threat Protection
Proofpoint Targeted Attack Protection
Trellix Advanced Threat Defense
Buyer's Guide
Download our free Palo Alto Networks WildFire Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Fortinet, Palo Alto or Check Point?
- What Is The Biggest Difference Between Cisco Firepower and Palo Alto?
- Expert Opinion on Palo-Alto Required.
- What is the biggest difference between Fortinet FortiGate and Palo Alto Networks WildFire?
- Palo Alto Networks Firewalls has been in Gartner's Leaders quadrant for 3 years. Agree/Disagree?
- Palo Alto 5060 or Fortigate FG-1500D
- How does Cisco Firepower NGFW Firewall compare with Palo Alto Networks Wildfire?
- Which is better - Wildfire or FortiGate?
- How does Cisco ASA Firewall compare with Palo Alto's WildFire?
- How do Palo Alto Networks' security features compare to other security vendors like Cisco?













Please refer to hybrid cloud deployment for WF500, with this setup you may pass the APK files which is not likely to have any confidential information to Wildfire Threat Intelligence Cloud and get the verdict. www.paloaltonetworks.com