Try our new research platform with insights from 80,000+ expert users
reviewer1152024 - PeerSpot reviewer
Senior Security Architecture Specialist at a computer software company with 201-500 employees
Reseller
Stable and easy to scale, but it needs better integration with MDM
Pros and Cons
  • "The most valuable feature is the ability to join your network and provide access through the VPN."
  • "Better integration with the MDM solution would be useful."

What is our primary use case?

We are a system integrator and Prisma Access is one of the security products that we implement for our clients. We handle all products, from high-level to low-level, and we propose an end-to-end solution for each customer. I am a pre-sales architect and engineer.

Prisma Access is the name of the GlobalProtect Cloud Service.

Normally, it is sold to users who want to use a VPN agent.

What is most valuable?

The most valuable feature is the ability to join your network and provide access through the VPN.

What needs improvement?

It is integrated with the MDM solution but it is not a VPN, so this is something that can be improved. Better integration with the MDM solution would be useful.

What do I think about the stability of the solution?

We don't hear from customers for a long time when they have this solution, so I think that it is stable.

Buyer's Guide
Prisma Access by Palo Alto Networks
January 2025
Learn what your peers think about Prisma Access by Palo Alto Networks. Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
832,138 professionals have used our research since 2012.

What do I think about the scalability of the solution?

Scaling is easy because it is just a license that you extend.

Our clients for this solution are typically small to medium-sized companies.

Which solution did I use previously and why did I switch?

We work with similar solutions from a number of vendors including Fortinet, F5, Trend Micro, and others.

What about the implementation team?

We have an in-house team that is responsible for implementing products for our clients.

We also perform the required maintenance, as well as technical support.

What's my experience with pricing, setup cost, and licensing?

This is not an expensive product and everything is included with one license. We normally sell GlobalProtect bundled with a firewall if the customer wants an endpoint solution.

What other advice do I have?

We have to pitch it to smaller customers. When it comes to medium-sized organizations, they are almost dedicated to a VPN solution. This is a good solution and I can recommend it, although it would be improved with better MDM integration.

I would rate this solution a seven out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller
PeerSpot user
Prismaa677 - PeerSpot reviewer
Consultant at a political organization with 201-500 employees
Consultant
Good interface and valuable feature set with an easy setup
Pros and Cons
  • "The initial setup is very straightforward."
  • "Dependencies of applications sometimes is a bit confusing."

What is our primary use case?

We primarily use the solution for firewall technologies.

What is most valuable?

The interface is very good and the feature set is very good. The investigation options, for example, in the data are very useful.

What needs improvement?

The dependencies of applications sometimes are a bit confusing. All the dependencies you have between applications can be confusing when you fill in things. It's mostly the configuration with the different applications. Extra guidance in using applications and things like that might be helpful.

In terms of features, at the moment, the features we use are all in there. But we don't even use the full feature set at the moment. So I don't really have any need for anything else. For now, there's not really anything missing.

For how long have I used the solution?

I have been using the solution for seven years.

What do I think about the scalability of the solution?

We've had no issue over the whole lifespan with any failures so we didn't have any problem with that. In terms of the scalability, supposedly the model you choose the scale goes up at the beginning. You can buy a firewall device and scalability is dependant on the model.

How are customer service and technical support?

We used an integrator so we don't need to contact their technical support directly. 

How was the initial setup?

The initial setup is very straightforward. With the standard deployment, I think it took a few days.

What about the implementation team?

We used an integrator for the initial setup. They were very good.

What's my experience with pricing, setup cost, and licensing?

I think that the Palo Alto solution is very good. The licensing in comparison to other competitors is not really an issue. The price is not low but you can't compare with all the premium firewalls in its range. The licensing cost is about 18,000 euros. 

What other advice do I have?

I would recommend the solution. The solution really depends on your budget, of course. If you have a really low budget it's not a low budget solution, so it can really depend on the budget you have. But if you have a budget for enterprise or best of firewalls I think you should take this solution into consideration.

I would rate this solution at 8.5 or 9 out of 10. No product, of course, is totally perfect and a ten is something that I don't think that exists. I think maybe it needs a bit more ease of how applications and dependencies run. Because sometimes you push a firewall rule and you get lots of dependencies so that could be a more manageable thing. Extra guidance in using applications and things like that would be helpful.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Prisma Access by Palo Alto Networks
January 2025
Learn what your peers think about Prisma Access by Palo Alto Networks. Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
832,138 professionals have used our research since 2012.
reviewer1551603 - PeerSpot reviewer
DevOps Engineer at a tech services company with 10,001+ employees
Real User
Useful predefined rules, multiple integrations, descriptive alerts, and great stability
Pros and Cons
  • "It has predefined or preconfigured rules, which are getting periodically updated. They are providing continuous improvements and periodically updating all search queries that they are looking for. That is one thing that helps us to stay vigilant and focused. If we query our AWS account for any breaches or vulnerabilities with any of the cloud tests, and it alerts us based on these predefined rules. It also provides an option to configure our own rules, and based on these rules, it can query the cloud trail logs, pull the information, and trigger alerts in real-time. I haven't explored this feature much because there are multiple accounts, and we don't have enough time to explore this feature. It also provides multiple integrations. When vulnerabilities or breaches are happening, you should be aware of them immediately. It provides integration with tools such as Slack, PagerDuty so that you can get alerted as soon as the high severity stuff comes up. For example, you have a security group that has allowed public traffic on port 22. As TechOps, you should be aware of this immediately. You cannot scan each machine or look into all security groups to identify it. So, Prisma helps us and alerts us when this kind of high-priority stuff comes up. It has different statistics, analytics, and graphs for data. The description of alerts is also pretty good. They describe what are the possible causes for this and what are the solutions. From Prisma Cloud, you can directly go to the AWS account. When you click on an alert, a resource, or a resource ID, it takes you to the AWS console where you need to log in. If you are already logged in, it will take you to that instance directly, and you can fix the issue there. I have found this feature very useful."
  • "We are using the SaaS offering. We use our applications for microservices. We use Twistlock to scan containers, and it displays these results in Prisma, which is a good feature because we can see vulnerabilities with respect to these containers. We can see everything in a very detailed manner. However, when you have different environments for a single application, such as DEV, QA, PROD, and TEST, all these environments run multiple containers, which can lead to a very high number of containers. In such a scenario, it shows you the alerts for all those containers that have vulnerabilities. If you show the results of all the containers that share the same image, it is not going to add any value. Therefore, they should narrow down the alerts based on a container. It should show information for a single container. Otherwise, the person who is looking at the results gets the impression that he has to fix all these issues. This is something that they can improve."

What is our primary use case?

We are basically using it for cloud governance. We have AWS as our public cloud service, and we have multiple cloud accounts that we manage. We're using Prisma SaaS for the cloud governance of these accounts. 

How has it helped my organization?

It has been very useful so far. We are a part of a small team, and we have almost 20 accounts. Therefore, it is difficult for us to log in to each account and look at cloud trail and other things. It is not possible to log in manually and check each of the vulnerabilities. Prisma has helped us a lot. It shows the alerts in real-time, and we are pretty happy with the service it offers. We now know how to categorize alerts, which ones need immediate attention, and on which ones can we act a bit later.

What is most valuable?

It has predefined or preconfigured rules, which are getting periodically updated. They are providing continuous improvements and periodically updating all search queries that they are looking for. That is one thing that helps us to stay vigilant and focused. If we query our AWS account for any breaches or vulnerabilities with any of the cloud tests, and it alerts us based on these predefined rules. It also provides an option to configure our own rules, and based on these rules, it can query the cloud trail logs, pull the information, and trigger alerts in real-time. I haven't explored this feature much because there are multiple accounts, and we don't have enough time to explore this feature. 

It also provides multiple integrations. When vulnerabilities or breaches are happening, you should be aware of them immediately. It provides integration with tools such as Slack, PagerDuty so that you can get alerted as soon as the high severity stuff comes up. For example, you have a security group that has allowed public traffic on port 22. As TechOps, you should be aware of this immediately. You cannot scan each machine or look into all security groups to identify it. So, Prisma helps us and alerts us when this kind of high-priority stuff comes up. 

It has different statistics, analytics, and graphs for data. The description of alerts is also pretty good. They describe what are the possible causes for this and what are the solutions. From Prisma Cloud, you can directly go to the AWS account. When you click on an alert, a resource, or a resource ID, it takes you to the AWS console where you need to log in. If you are already logged in, it will take you to that instance directly, and you can fix the issue there. I have found this feature very useful.

What needs improvement?

We are using the SaaS offering. We use our applications for microservices. We use Twistlock to scan containers, and it displays these results in Prisma, which is a good feature because we can see vulnerabilities with respect to these containers. We can see everything in a very detailed manner. However, when you have different environments for a single application, such as DEV, QA, PROD, and TEST, all these environments run multiple containers, which can lead to a very high number of containers. In such a scenario, it shows you the alerts for all those containers that have vulnerabilities. If you show the results of all the containers that share the same image, it is not going to add any value. Therefore, they should narrow down the alerts based on a container. It should show information for a single container. Otherwise, the person who is looking at the results gets the impression that he has to fix all these issues. This is something that they can improve.

For how long have I used the solution?

I have been using this solution for two years.

What do I think about the stability of the solution?

Its stability has been great. 

Which solution did I use previously and why did I switch?

I have used different tools previously. I have used Evident. Prisma is much better than Evident in terms of the information it provides for alerts. In Evident, they provide a little bit of information about the triggered alert, whereas Prisma provides in-depth details.

How was the initial setup?

It is pretty straightforward. It is a two-step procedure. You need to create the roles and mention the role in the Prisma config. You have to create a role in the corresponding AWS account or Azure account and give that role information while configuring Prisma. So, you need to provide the account ID number, the role that you have created, and a short description of the account that you're using. You also need to enable a couple of other things, such as VPC flow logs and cloud trail for Prisma. If these are not configured, Prisma will still get configured, but it will alert you that you have not configured the flow logs, cloud trail, and all other events. After that, Prisma will immediately start scanning the account. 

It also has a provision for grouping your accounts into a particular group. If you have a project that has multiple accounts, you can group them together as a central group. If all those accounts are managed by a single team, you can enable alert notifications for that single team instead of each account. Everything is pretty good in terms of management activities.

Deployment hardly takes five to ten minutes. It is a SaaS offering. It is a managed service by Palo Alto. You don't have to configure anything at your site for Prisma. You don't have to create any sort of instances or deploy it. You just need to onboard the accounts.

What about the implementation team?

It doesn't require any maintenance. It is managed by our corporate IT team. They have onboarded all the AWS accounts with respect to my organization. These AWS accounts belong to multiple groups of people. 

My department has around 30 people who use this solution as DevOps, and we have the access to the portal. We have enabled read-only access for certain groups so that they can go and look into the alerts and do the necessary things. We have created multiple read-only groups, and we have assigned a set of users to each read-only group.

What was our ROI?

It has definitely provided an ROI.

Which other solutions did I evaluate?

We looked into multiple options, and we chose Prisma considering the price and the features it offered.

We started off with AWS three years ago. As the number of accounts grew, we felt the need to use some sort of cloud governance tool because it is not possible for us to log in to each account and look for issues that may impact the organization. That's why we started to use Prisma. We are using multiple solutions from Palo Alto. We use Twistlock for container scanning and things like that.

What other advice do I have?

I have positive feedback about this product. We are happy with this product and the features it offers for the price. 

I would rate Prisma SaaS an eight out of ten.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
PeerSpot user
Network Engineer at Acliv Technologies Pvt Ltd
Real User
Enables us to easily monitor everything coming over the network and work accordingly
Pros and Cons
  • "Monitoring is the most valuable feature because we can easily monitor all kinds of stuff coming over the network. We can check the dashboard and work accordingly."
  • "One thing that would help is if we could get a guide. With Cisco, for example, you can just type the problem regarding your Cisco product and you will easily get your solution. In Palo Alto, however, it's not easy to find the solutions."

What is our primary use case?

We use this solution to secure the network. We block unwanted traffic.

How has it helped my organization?

We had a government project. When I was there, they asked to open some kind of port. We just had to initiate that traffic. Then we checked what kind of ports were blocked. We gave them the ports and after that they asked to open the port for the traffic application. We did the work accordingly.

What is most valuable?

Monitoring is the most valuable feature because we can easily monitor all kinds of stuff coming over the network. We can check the dashboard and work accordingly.

What needs improvement?

Overall it is actually very good. I haven't yet had any issue at all. One thing that would help is if we could get a guide. With Cisco, for example, you can just type the problem regarding your Cisco product and you will easily get your solution. In Palo Alto, however, it's not easy to find the solutions.

For how long have I used the solution?

We've been using this solution for about three years.

What do I think about the stability of the solution?

Stability is good. 

What do I think about the scalability of the solution?

Currently, our network security team is taking charge of the firewall but behind that, the users have to go through the firewall. Initially, we had three or four firewalls, so two or three engineers were enough for the deployment and maintenance. 

How was the initial setup?

The initial setup was a bit complex. It took two or three months and we are still continually working on it.

What's my experience with pricing, setup cost, and licensing?

The solution is actually very expensive. I don't know the particulars since the purchasing team dealt with it.

Which other solutions did I evaluate?

We just checked which firewall was top rated. We selected two such firewalls. One was Check Point and the other was Palo Alto. Both of them are comparatively good.

What other advice do I have?

Ultimately, Palo Alto is a very advanced firewall. The firewall uses activation awareness. This firewall can easily identify what applications are running behind the network. This is a good solution to use.

I would rate this solution as eight out of ten.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Director at a tech services company with 51-200 employees
Real User
Good architecture, software, and interface with strong endpoint protection
Pros and Cons
  • "It's very stable. Sometimes after installing the boxes, we leave them for one or two years. We would just touch the box in the case of the customer needing new requirements or changes to the setup."
  • "Their next release should provide solutions for the mobile environment."

What is our primary use case?

Most of our customers here in Egypt are looking for how to manage their boxes in simple ways. They want good performance as well.

How has it helped my organization?

We sometimes need to apply proactive service on specific applications. We can do it with Palo Alto Networks in just a few clicks. On some projects, we work with other vendors like Juniper or Check Point and we are really facing some obstacles applying policies and proactive service in specific applications. But Palo Alto and its next next-generation firewall offers especially proactive services on a specific type of application, and in applications like tracking features.

What is most valuable?

The next-gen firewall performance is very good. The solution has very good architecture, software, and interface.

What needs improvement?

They could improve the proactive service on this application and application tracking in their next release.

Their next release should provide solutions for the mobile environment.

For how long have I used the solution?

I've been using the solution since 2009.

What do I think about the stability of the solution?

It's very stable. Sometimes after installing the boxes, we leave them for one or two years. We would just touch the box in the case of the customer needing new requirements or changes to the setup. It has a very stable performance because they have very good architecture and software.

How are customer service and technical support?

We don't usually need technical support. My company is certified to provide the Tier 1 support for Palo Alto here in Egypt. Most of the time we are fielding the cases here in the technical support center in our company. Sometimes we need to escalate to their Tier 2 and Tier 3, and the response is very good. We are talking about just two hours to escalate to the next level of support. They have a very good policy about help features and support centers in our region here and in India.

How was the initial setup?

There are many ways to deploy for the firewall in general. Sometimes we propose a firewall as a perimeter firewall, to protect the internet connections. Sometimes, we propose the firewalls to protect the data center and protecting the institutional traffic between servers. So it depends on the deployment model and the customer requirements.

Depending on the client, it may take time to gather the info and requirements from the customers, so it takes anywhere from two business days to two months to finalize the whole deployment for the Palo Alto Networks.

What about the implementation team?

We have a technical team in our company that handles the implementation.

What's my experience with pricing, setup cost, and licensing?

Palo Alto is not a cheap product. It's expensive because they provide very good technology.

Which other solutions did I evaluate?

Here in Egypt, there are about 93 system integrators and we have a partnership with Fortinet. We consider our connections because we need to avoid conflict with our partners and conflict with other solutions in our portfolio. We choose Palo Alto and Check Point to avoid conflict with our partners. The market is very crowded with FortiGate technical solutions and partners, so we avoid these.

What other advice do I have?

We had a very good experience with their solutions, especially with their endpoint protections and the next-generation firewalls. We are a local distributor in Palo Alto here in Egypt. So we propose this technology to our customers and our partners here in Egypt.

Palo Alto offers very good technology and hardware. Its very good in this category of solution. You have options of providing or proposing to a customer a small box, or sometimes a mid range. It depends on the model and the deployment.

I would rate this solution 8 out of 10.

Disclosure: My company has a business relationship with this vendor other than being a customer: Partner.
PeerSpot user
reviewer2274375 - PeerSpot reviewer
Solution Architect // Network Consultant at a consultancy with 501-1,000 employees
Consultant
Top 20
Provides robust cloud security along with a host of valuable features
Pros and Cons
  • "Palo Alto Firewall is one of the best firewalls in the world."
  • "Though the monitoring is fine, the solution should improve its application graphs and interface monitoring."

What is our primary use case?

My clients used Prisma Access essentially for security in the cloud. We integrated their SD-WAN into Prisma Access.

What is most valuable?

Palo Alto Firewall is one of the best firewalls in the world. It's very clear about the policies and all the security features they have. Also, the user integration works very well in Palo Alto. The WiFi, anti-threat, web filtering features and IT/OT separation are also good.

What needs improvement?

Though the monitoring is fine, the solution should improve its application graphs and interface monitoring. Additionally, the pricing could be improved.

For how long have I used the solution?

I worked as a consultant on Prisma Access for one year for one integration project.

What do I think about the stability of the solution?

The product is very stable.

What do I think about the scalability of the solution?

The product is scalable. Our clients are medium-sized businesses. There are 1,500 users worldwide.

How are customer service and support?

The support is good. I rate the support an eight or nine out of ten.

How would you rate customer service and support?

Positive

How was the initial setup?

The solution is not easy to implement. The first setup is a bit more difficult, but it gets better. The solution is easy to maintain.

What about the implementation team?

A global partner did the setup.

What's my experience with pricing, setup cost, and licensing?

I'm still comparing, but the solution is quite expensive.

What other advice do I have?

I recommend people try the product out because it's really good. I rate Prisma Access an eight out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer: Consultant
PeerSpot user
reviewer1463202 - PeerSpot reviewer
Senior Executive at a tech services company with 1,001-5,000 employees
Real User
User-friendly, straightforward to set up with good integration, and the remediation process is easy
Pros and Cons
  • "The remediation process is easy compared to other platforms."
  • "My clients would like to see a more feature-rich product."

What is our primary use case?

We are a solution provider and we have implemented Prism Cloud for a couple of clients.

Our clients use this product for their container security.

What is most valuable?

The remediation process is easy compared to other platforms.

The interface is user-friendly.

What needs improvement?

My clients would like to see a more feature-rich product.

For how long have I used the solution?

We have been using Prisma SaaS for about three months.

What do I think about the stability of the solution?

Stability-wise, I feel that it is good.

What do I think about the scalability of the solution?

We have not yet tried to expand beyond our integration with one cloud platform. This is something that we may do in the future.

There are three people in my organization who use it.

How are customer service and technical support?

Technical support from Palo Alto has been responsive and they are good.

Which solution did I use previously and why did I switch?

We implemented Azure Secure Center before trying this product.

How was the initial setup?

This product is straightforward to set up and the integration is good.

What's my experience with pricing, setup cost, and licensing?

The licensing fees are paid on a yearly basis and for what we get, the price is good. However, the pricing should be better.

Which other solutions did I evaluate?

We did not have a great deal of time to evaluate other products.

What other advice do I have?

For anybody who is looking for a contained-based solution, I definitely recommend this product.

I would rate this solution an eight out of ten.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
reviewer1167384 - PeerSpot reviewer
General Manager - CyberSecurity Practice at a aerospace/defense firm with 1,001-5,000 employees
Real User
Remote access using a zero-trust platform with easy cloud deployment
Pros and Cons
  • "The most valuable feature is the zero-trust part of this solution."
  • "The cloud setup is straightforward, and the onboarding process is much better, but the on-premises initial setup is slightly complex."

What is our primary use case?

We are a services organization at the diagnostic stage. We generally see what matches the customer's requirements.

The primary use case of this solution mostly serves as remote access to the applications, and the secure access of applications both for the cloud and for their private data centers.

They are mainly using the zero-trust platform, which is very commonly used right now.

What is most valuable?

The most valuable feature is the zero-trust part of this solution.

This solution addresses most of our requirements.

What needs improvement?

I would like to see an increase in third-party integration, in terms of identity and access management, or strong authentication.

For how long have I used the solution?

I have been working with this solution for the last six months.

What do I think about the stability of the solution?

This solution is stable we have not had any major issues with it.

What do I think about the scalability of the solution?

This solution is scalable. Our customers are large enterprise companies with anywhere from 4,000 to 10,000 users.

How was the initial setup?

The cloud setup is straightforward, and the onboarding process is much better, but the on-premises initial setup is slightly complex.

What other advice do I have?

Anyone who is considering working with Prisma Access should go ahead and implement it. This is a product that I recommend.

I would rate this solution a nine out of ten.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer: partner
PeerSpot user
Buyer's Guide
Download our free Prisma Access by Palo Alto Networks Report and get advice and tips from experienced pros sharing their opinions.
Updated: January 2025
Buyer's Guide
Download our free Prisma Access by Palo Alto Networks Report and get advice and tips from experienced pros sharing their opinions.