TrustRadius: an HG Insights company

Palo Alto Networks Advanced Threat Prevention

Score8.5 out of 10

41 Reviews and Ratings

What is Palo Alto Networks Advanced Threat Prevention?

Palo Alto Networks Advanced Threat Prevention is an intrusion prevention system (IPS) used to stop zero-day attacks inline in real-time. In addition to the prevention of known threats, the solution helps to stop never-before-seen exploit attempts and command and control with its inline deep learning engines that aims to provide prevention of zero-day injection attacks and evasive command and control.

Read more details.

Categories & Use Cases

Who Buys & Uses Palo Alto Networks Advanced Threat Prevention

Securing your systems is now easier with Palo Alto Threat Protection

Use Cases and Deployment Scope

The main reason to use Palo Alto Networks in our organisation it acts as key component of our cyber security strategy to detect and block advanced threats. It also focus on the critical endpoints to provide real time inspection of the traffic ensuring that malicious activities are identified and prevented before they can cause damage. It has played a vital role in resolving various business problems like protection against zero day threats which means this acts a barrier for any real time issue that block the enterprise system. Earlier in the cloud there was no such specific threat blocking mechanism as a part of which multiple jammers has blocked our complete enterprise infrastructure that way blocked the complete site as we have implemented Advance threat protection it helped us in Safeguarding hybrid and cloud environments as more workload running in the cloud we need a consistent way to secure traffic across on premises and cloud environments. Alto Networks Threat prevention provides unified threat prevention capabilities

Pros

  • Preventing the data breaches
  • Safeguarding Hybrid and cloud environments
  • Reducing the false alarms
  • Network Perimeter secuirty

Cons

  • Though ATP performs very well in the cloud environments deep inspection across east west traffic in cloud native architectures need to be strengthned
  • Considering the Palo Alto networks though it seems to be great brand this is considered to be premium subscription add on to Palo Alto firewalls which is considered to be the expensive for mid-size organisations
  • Complexity in configuration and policy management sometimes fine tuning policies to balance security and usability sometime requires trial and error which consumes so much time to make decisions

Return on Investment

  • Compliance and Audit readiness
  • Lower Incident response cost
  • Reduced security breaches
  • Operational overhead
  • High intial investment

Usability

Alternatives Considered

Cisco Network Assistant

Other Software Used

Falcon, Zscaler Data Security, Avast CloudCare

Is Palo Alto Threat Prevention or TP subscription a must with Palo Alto Firewall?

Use Cases and Deployment Scope

We are using Palo Alto Networks Next-Generation firewall along with Threat Protection Module. Palo Alto Networks Threat Protection helps users stay protected from external threats, intruders, vulnerability exploits, and also prevents users from accessing or downloading malicious contents and files, enforces traffic inspection with gateway anti-virus, vulnerability protection, and anti-spyware modules.

Pros

  • Anti virus
  • Vulnerability protection
  • Anti spyware

Cons

  • It can ingest feeds from other tools and security solutions
  • Threat protection should share it intel data with other vendors
  • Users should be able to allow/bypass or create [their] own signatures from intel shared from SOC team

Most Important Features

  • Vulnerability protection
  • Gateway anti virus
  • Anti spyware

Return on Investment

  • After adding PA Threat Protection, we are now getting our network traffic completely inspected.
  • We are now applying security checks and scans like AV scan and Anti Spyware checks.
  • This is also giving visibility into threat and attack vectors that are using vulnerabilities and exploits to enter our environment.

Alternatives Considered

SonicWall Capture Advanced Threat Protection (ATP), Fortinet FortiGate and Sophos UTM

Other Software Used

SonicWall Analytics, SonicWall NSA Series, SonicWall TZ

A Bombshell Security Suite

Pros

  • Palo Alto NTP allows for a very, very granular approach to protection by the use of profiles. You can tailor as many profiles as you need say for URL Filtering or Malware scanning to accommodate different business needs. Once your profiles are all setup you can choose them to attach to your firewall policies on a policy-by-policy basis. It really couldn't be simpler.
  • Very easy to monitor the activity of the profiles in the Monitoring Pane, which makes for agile adjustments or exceptions to be made.

Cons

  • Some of the deeper features, like making exceptions for virus false-positives can be a little tricky, but I think that is just the nature of the beast. Maybe some guides/tutorials from Palo Alto would help navigate some of that more successfully. Fortunately, we haven't had many of those!

Most Important Features

  • Ease to implementation and agile management
  • Behind the scenes, automatic updating of all NTP databases, some even on an hourly basis
  • Great cost-to-value ratio

Return on Investment

  • We have various compliance standards we have to meet and the Palo Alto with its Networks Threat Protection suite has checked off pretty much all the boxes we needed and at a price point that couldn't be easily beat for comparable features, throughput, etc.
  • IT/Network staff has saved a A LOT of time using this platform for protection (coming from an ASA)

Alternatives Considered

Cisco ASA 5500-X with FirePOWER Services and Fortinet FortiGate

Other Software Used

Cisco Catalyst 9300 Series Switches, Cisco Catalyst 9800-L Wireless Controller

Palo Alto Threat Protection suite provides good layers of protection

Pros

  • Data filtering.
  • URL categorization.
  • File blocking.

Cons

  • Sometimes I struggle to find the deny or specific traffic log for file blocking profile under Unified logs.
  • Reporting around Threat Prevention suite could be much better.
  • Possibly a specific threat prevention search function that spans across of threat features.

Most Important Features

  • URL categorization/filtering.
  • File blocking.
  • Data filtering.

Return on Investment

  • Threat Protection adds a positive multi layered defense.
  • Reduces time to review and triage unwanted network connections by implementing Geo Blocking.
  • Ease of deploying a single Security Group Profile across multiple existing or new rules reduces management time.

Alternatives Considered

Palo Alto Networks Prisma Cloud and Digital Guardian

Other Software Used

Palo Alto Panorama

Threat Review during Implementation

Pros

  • The threat engine has constant updates for important threats.
  • Wildfire helps supplement the Threat engine to help protect against 0 day threats.
  • The way the threat engine can be added at different levels to different zones and policies helps to ensure business essential traffic can have policies that are tuned to ensure traffic will flow.

Cons

  • Visibility into signatures and how they function/what triggers them would be very beneficial.
  • Lacking customizability compared to other tools.
  • Inability to write custom signatures easily and for traffic with small (less than 8 bit) signatures.

Return on Investment

  • New deployment hasn't been fully calculated yet.
  • With the addition of Panorama and central logging, event investigation has become more streamlined.

Alternatives Considered

Palo Alto Networks WildFire, Palo Alto Networks Traps and Cisco Sourcefire SNORT

Other Software Used

Palo Alto Networks WildFire, Palo Alto Panorama, HP Arcsight