We changed our name from IT Central Station: Here's why
Cyber Security Solutions Architect at a tech services company with 10,001+ employees
MSP
Offers innovative, advanced threat protection
Pros and Cons
  • "Innovative, advanced threat protection is the most valuable feature."
  • "The user interface is probably not as slick as it could be."

What is our primary use case?

Our primary use case was for perimeter protection.

What is most valuable?

Innovative, advanced threat protection is the most valuable feature. 

What needs improvement?

I don't see any specific room for improvement.

The user interface is probably not as slick as it could be.

For how long have I used the solution?

I have been using Palo Alto for three years. 

We're on-premises primarily at the moment, but also a cloud product. 

What do I think about the stability of the solution?

The stability is generally pretty good. I haven't heard any complaints from our customers around Palo Alto's stability. It's one of the reasons why they're the leaders in this space.

We've got our own team for maintenance. My company is a large multinational with 20,000 employees.

How are customer service and technical support?

I have contacted their support once. It's very good support. They help me to fix our problem quickly.

How was the initial setup?

The initial setup was complex. It's not very intuitive. You need to know what you're doing for the initial setup, you need to be a Palo Alto expert.

If you compare it to their competitor Fortinet, Fortinet's FortiGate product is a lot easier to install, if you're not an expert.

The time it takes to deploy depends on how complex the deployment needs to be for the client. If it's a basic deployment, is going to take around two days. 

What other advice do I have?

My advice would be to make sure the firewall is configured properly.

I would rate it an eight out of ten. Not a ten because you have to be really excellent before you get a ten out of me.

In the next release, I would like to have the ability to auto-generate rule and policy, based on known traffic, based on the baseline. That is a feature that I think Palo Alto should be able to have in some form or fashion to auto-generate and propose a policy and rules set, after putting the file into a learning mode for some period.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Service Delivery Engineer - Network Security Lead at a tech services company with 51-200 employees
Reseller
Top 5Leaderboard
Very flexible, integrates well with apps and other security tools; robust
Pros and Cons
  • "Flexible and integrates well with apps and other security tools."
  • "Interface could be improved visually and simplified."

What is our primary use case?

I deploy this solution for our clients. Firewalls can be used when you want to achieve SD-WAN connectivity. In a client's VPN or site-to-site VPN, it can be used to secure networks locally. If you have an extender or server room, you can secure your IT infrastructure for your servers. The solution can be installed on edge to protect your internal network. If you have services running on AWS or Google Cloud, or Alibaba Cloud, it can be deployed there. Some clients have a hybrid kind of infrastructure. I'm a service delivery engineer and network security lead and we are customers of Palo Alto. 

What is most valuable?

It's a flexible solution and integrates well with apps and other security tools like SIEM, web applications. They can share their data orchestration. It's robust and fast in terms of architecture and data processing, there aren't any bottlenecks.  

What needs improvement?

The interface could be improved visually and simplified. It sometimes feels like some of the features are hidden and not easy to find. 

What do I think about the stability of the solution?

This is a very stable solution. 

How are customer service and technical support?

In terms of technical support, I've noticed that as long as you have an enterprise license the support is good. 

How was the initial setup?

For a beginner, the initial setup might be somewhat complex because the interface is a bit different, so there's a learning curve. It's not that steep, and once you get it, it's okay. In terms of other solutions, the Palo Alto deployment takes longer than Fortinet, for example, because of the intricacy of the user interface. In a medium size organization, deployment can take three to four days. 

What other advice do I have?

I would recommend this solution. The uptake is mostly with medium and large enterprise, it's strong there. For small to medium size businesses, the preference is usually Fortinet or Sophos. It's really about what suits the client. 

I would rate this solution an eight out of 10. 

Disclosure: My company has a business relationship with this vendor other than being a customer: Integrator
Learn what your peers think about Palo Alto Networks NG Firewalls. Get advice and tips from experienced pros sharing their opinions. Updated: January 2022.
563,780 professionals have used our research since 2012.
Sr. Product Management Specialist at a comms service provider with 10,001+ employees
Reseller
Top 5Leaderboard
A stable and easy-to-deploy solution with good support and useful UTM module
Pros and Cons
  • "The Unified Threat Management (UTM) module, which consists of the basic firewall and IPS services, is what the majority of our customers use in Palo Alto Firewall."
  • "Its scalability for on-prem deployments can be better. For an on-prem deployment, the hardware has to be replaced if the volume goes up to a certain level."

What is our primary use case?

We're basically an MSSP service provider. We use this solution as a network firewall for URL filtering, IPS, and IDS proxy services.

What is most valuable?

The Unified Threat Management (UTM) module, which consists of the basic firewall and IPS services, is what the majority of our customers use in Palo Alto Firewall.

What needs improvement?

Its scalability for on-prem deployments can be better. For an on-prem deployment, the hardware has to be replaced if the volume goes up to a certain level.

For how long have I used the solution?

We have been using this solution for a couple of years.

What do I think about the stability of the solution?

It is stable.

What do I think about the scalability of the solution?

It is much more scalable in a cloud deployment, but for an on-prem deployment, the hardware has to be replaced if the volume goes up to a certain level.

We have very few customers of this solution. We probably have five to ten customers.

How are customer service and technical support?

Their technical support is very good. It is more often the AMC support that we have to take. 

How was the initial setup?

It is fairly easy. We're not seeing many challenges in these installations. The complete installation can take a lot of time because we have to configure all the policies and other things. After the hardware is installed and the network is connected, you need one or two people for configuring the policies for use cases.

What's my experience with pricing, setup cost, and licensing?

After the hardware and software are procured, it is the AMC support that has to be renewed yearly.

What other advice do I have?

We plan to keep using this solution depending on the customers' needs. We also have a cloud-based platform on Fortinet, and we provide it as a service.

I would rate Palo Alto Networks NG Firewalls an eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Technical Manager El Salvador at a tech services company with 51-200 employees
Real User
A feature-rich solution that works very well and has excellent stability
Pros and Cons
  • "Overall, it is a good solution. It is stable. We use URL filtering, which is useful for blocking undesired URLs."
  • "Currently, they don't have email protection. They can maybe add it in the future. Currently, if you want to do so, you need to go with another solution."

What is our primary use case?

We use it for perimeter security.

What is most valuable?

Overall, it is a good solution. It is stable. We use URL filtering, which is useful for blocking undesired URLs.

What needs improvement?

Currently, they don't have email protection. They can maybe add it in the future. Currently, if you want to do so, you need to go with another solution.

For how long have I used the solution?

I have been using this solution for two years.

What do I think about the stability of the solution?

Its stability is perfect. It has excellent stability.

What do I think about the scalability of the solution?

With this kind of solution, you need to be careful in terms of planning because once you have the appliance, it is very difficult to scale too much. You need to carefully select the right appliances because if you need to run more services and traffic beyond the ones you have selected, you would have to replace the appliance. You would have to upgrade it. We currently have 100 users in our organization who use this solution.

How are customer service and technical support?

We never had the need to open a support case. It never happened that something that was supposed to work was not working. If required, we can find the answers in the product documentation.

How was the initial setup?

If you have the right experience, it is okay. It is not very easy, but if you know how to manage it and configure it, it is okay. It takes maybe 5 to 10 hours or a day.

What other advice do I have?

I would advise others to go for it. They will not get disappointed. It is complex at the beginning because it has a lot of features, but this is something that you overcome with training. With training and experience, you can manage it.

I would rate Palo Alto Networks NG Firewall a nine out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Senior Network Engineer at a tech services company with 201-500 employees
Real User
Top 20
Great GlobalProtect and App-ID features; easy implementation and good integration
Pros and Cons
  • "GlobalProtect and App-ID features are very good."
  • "Lacks mobility between on-prem and cloud based."

What is our primary use case?

We deploy and provide support for this solution to our customers. The use case depends on customer requirements because Palo Alto Next Generation Firewall can be used as a data center firewall, perimeter firewall or on the cloud for a perimeter firewall or used with communications. Some customers use it for global protect connectivity. I am a senior network engineer and we are partners with Palo Alto Networks. 

What is most valuable?

The best feature of this solution is the GlobalProtect, followed by the App-ID feature which is very good. I also like the VMS feature. 

What needs improvement?

They've improved a lot of things but we'd like to see more mobility between on-prem and cloud based. I'd also like to see security synchronization between the firewalls. Managing can be difficult. 

For how long have I used the solution?

I've been providing this solution for over two years. 

What do I think about the stability of the solution?

There are occasionally issues with reporting, otherwise stability is fine. 

What do I think about the scalability of the solution?

The scalability of this solution is fine. 

How are customer service and technical support?

Technical support is fine, although sometimes there have been delays. From a technical perspective, they are knowledgeable. 

How was the initial setup?

Now that I have some experience with it, the initial setup is simple. If it's being deployed on-prem, deployment takes a couple of days. But if it's a cloud deployment, we can complete deployment in a day. 

What's my experience with pricing, setup cost, and licensing?

Palo Alto is more expensive in comparison to Fortinet and other firewalls. It's okay because they do provide quality. 

What other advice do I have?

I would recommend this firewall still. Our system integrates well but it depends on customer requirements so we sometimes choose to go with an alternative firewall.

I would rate this solution an eight out of 10. 

Which deployment model are you using for this solution?

Hybrid Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Director IT Security at a healthcare company with 501-1,000 employees
Real User
Good threat hunt capabilities, good support, and easy to deploy
Pros and Cons
  • "Mechanically, all firewalls work in a similar fashion, but what makes Palo Alto different is that it also has some of the threat hunt capabilities. It is a little bit better than other vendors."
  • "As things are evolving, we want to make sure that Palo Alto is able to keep up with what is going on outside. They should continue to do more intelligence-related enhancements and integrate with some of the other security tools. We want to have a more intelligent toolset down the road."

What is our primary use case?

Basically, it is for protection and security. We are using it to make sure that our network is as secure as possible. We are able to evaluate each stack in each pocket and take certain actions as needed when we look into some of the content of the payload. 

We have on-prem deployments, and we also have SaaS-based services.

What is most valuable?

Mechanically, all firewalls work in a similar fashion, but what makes Palo Alto different is that it also has some of the threat hunt capabilities. It is a little bit better than other vendors.

What needs improvement?

As things are evolving, we want to make sure that Palo Alto is able to keep up with what is going on outside. They should continue to do more intelligence-related enhancements and integrate with some of the other security tools. We want to have a more intelligent toolset down the road.

For how long have I used the solution?

We implemented this solution last year.

What do I think about the scalability of the solution?

We currently have 25,000 users. Its usage won't increase a lot, but IT is changing very rapidly, and it would depend on the security model towards which we are moving. 

How are customer service and technical support?

Palo Alto provides pretty good support.

How was the initial setup?

It is straightforward. The deployment duration varies because there are different modules and components, but it doesn't mean that we have to complete everything to make it work. For the core piece of it, it would probably take a couple of months to install, configure, and test.

What about the implementation team?

We have a vendor to help us. We have two or three people for its deployment.

What's my experience with pricing, setup cost, and licensing?

It has a yearly subscription.

What other advice do I have?

I would recommend this solution. I would rate Palo Alto Networks NG Firewalls an eight out of ten.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
Flag as inappropriate
Network Manager at a financial services firm with 1,001-5,000 employees
Real User
Top 5
Easy to install and easy to configure policies, but needs better integration with SD-WAN and better pricing
Pros and Cons
  • "The ease of use and the ease of configuration of our policies are the most valuable features."
  • "Palo Alto could do better with integrating the Palo Alto Next-Gen Firewall with SD-WAN. The biggest issue with Palo Alto is that they are expensive. They are very expensive for what they offer. They should improve their pricing."

What is our primary use case?

It is our edge appliance. We use it for our edge security, and we also use it for our VPN termination.

We're using an old version of this solution. At this moment, I'm looking at migrating away from Palo Alto.

What is most valuable?

The ease of use and the ease of configuration of our policies are the most valuable features.

What needs improvement?

Palo Alto could do better with integrating the Palo Alto Next-Gen Firewall with SD-WAN.

The biggest issue with Palo Alto is that they are expensive. They are very expensive for what they offer. They should improve their pricing.

For how long have I used the solution?

I have been using this solution for six or seven years.

What do I think about the scalability of the solution?

We have about a thousand users.

How are customer service and technical support?

We have third-party support.

Which solution did I use previously and why did I switch?

I used Cisco ASA.

How was the initial setup?

Its installation was pretty straightforward. There were no problems there.

Deployment duration is difficult to tell because there is a whole world of planning and other things. It probably took a couple of days. You are, of course, always tweaking these things.

What about the implementation team?

I haven't installed it here, but where I was before, we had two people doing it. I and a colleague did it ourselves.

What's my experience with pricing, setup cost, and licensing?

It is expensive.

What other advice do I have?

There are multiple firewalls out there. I am moving away from them because they are expensive, and they don't do what I want to do with them. I have plans of getting FortiGate instead.

I would rate Palo Alto Networks NG Firewalls a six out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Network Security Head at a government with 51-200 employees
Real User
An innovative platform that secures our network

What is our primary use case?

We plan to continue using this solution. Within our organization, there are roughly 1,000 employees using this solution.

What is most valuable?

We chose Palo Alto for its security features. It's quite nice. It's very user-friendly, powerful, and there are barely any bugs. 

For how long have I used the solution?

We have been using this solution for roughly two years.

What do I think about the stability of the solution?

This solution is very stable.

What do I think about the scalability of the solution?

The scalability of the firewalls could be improved. You can't scale the physical firewalls because Palo Alto doesn't support clustering. 

How are customer service and technical support?

The support could be improved. They could be faster.…

What is our primary use case?

We plan to continue using this solution. Within our organization, there are roughly 1,000 employees using this solution.

What is most valuable?

We chose Palo Alto for its security features. It's quite nice. It's very user-friendly, powerful, and there are barely any bugs. 

For how long have I used the solution?

We have been using this solution for roughly two years.

What do I think about the stability of the solution?

This solution is very stable.

What do I think about the scalability of the solution?

The scalability of the firewalls could be improved. You can't scale the physical firewalls because Palo Alto doesn't support clustering. 

How are customer service and technical support?

The support could be improved. They could be faster.

They have a multi-layer model of support. If we're experiencing any issues, we have to go to our local partner. If our local partner can't help, then we have to go through a distribution layer that's certified from Palo Alto. If our issues can't be fixed, they will escalate them to the vendor. This can be quite annoying, to be honest.

With Cisco, for example, you can open a ticket directly with the vendors themselves, and they can escalate it internally, which is much faster.

Which solution did I use previously and why did I switch?

We used to use Juniper Firewalls.

How was the initial setup?

The initial setup is quite straightforward. 

What about the implementation team?

We deployed this solution with some help from our local partners. Overall, deployment took a couple of days. A team of three deployed this solution.

What's my experience with pricing, setup cost, and licensing?

This solution is quite expensive.

What other advice do I have?

I would absolutely recommend this solution to others. Overall, on a scale from one to ten, I would give this solution a rating of nine.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Product Categories
Firewalls
Buyer's Guide
Download our free Palo Alto Networks NG Firewalls Report and get advice and tips from experienced pros sharing their opinions.