TrustRadius: an HG Insights company

Palo Alto Networks Next-Generation Firewalls - PA Series

Score9.5 out of 10

173 Reviews and Ratings

What is Palo Alto Networks Next-Generation Firewalls - PA Series?

Palo Alto Network’s Next-Generation Firewalls is a firewall option integrated with other Palo Alto security products. Released in late 2023, the PA-7500 ML-Powered NextGeneration Firewall (NGFW) enables enterprise-scale organizations and service providers to deploy security in high-performance environments.

Read more details.

Categories & Use Cases

Videos

Top Performing Features

  • Identification Technologies

    Policy-based visibility and control over applications, users and content

    Category average: 8.5

  • Content Inspection

    Inspecting permitted application traffic by means of threat prevention, URL filtering and data filtering

    Category average: 8.7

  • Policy-based Controls

    Firewall policy controls enable administrators to create firewall policies controlling what data is allowed to traverse the firewall

    Category average: 8.9

Areas for Improvement

  • VPN

    VPN's implement encryption and anonymize IP addresses

    Category average: 9.2

  • Proxy Server

    A proxy server changes your IP address and masks the origin of your network traffic

    Category average: 8.6

  • Visualization Tools

    Visualization tools present administrators with data on applications traversing the network, who is using them, and the potential security impact.

    Category average: 8.3

Who Buys & Uses Palo Alto Networks Next-Generation Firewalls - PA Series

Palo Alto Next Gen Firewall lives up to expectations.

Use Cases and Deployment Scope

I utilize my Palo Alto Next-Gen firewall to protect a school district comprising approximately 6,500 students and over 1,000 staff members. I can see that we are constantly attacked from almost every angle. Still, I never have to stress, because I can also see that in nearly every situation, Palo Alto is stopping the threats before they ever reach my network.

Pros

  • Easy to create rules that make sense.
  • Identifies current threats and automatically downloads updates that help it stop them.
  • Integrates with my authentication system to allow me multiple ways to create rules based on various factors.

Cons

  • Setting up certain things can be somewhat complicated due to the numerous options and abstractions involved.
  • It would be nice to have somewhere to get simple canned reports easily.
  • It would be nice to be able to remove options we never use from various setup dialogs.

Return on Investment

  • We have seen multiple other local school districts compromised by the same attacks we face. Although the threats are stopped for us, they have been successful for them, resulting in hundreds of thousands of dollars in mitigation and cleanup costs.
  • We have been able to affordably provide all our users with secure remote accessibility through Global Protect VPN.
  • We have been able to quickly and easily make changes to our configuration without costly and annoying delays.

Usability

Alternatives Considered

Cisco ASA 5500-X with FirePOWER Services

Other Software Used

PaperCut, Snipe-IT, SolarWinds Kiwi Syslog Server

Palo Alto Next Gen Firewalls Real World Review

Use Cases and Deployment Scope

We are using Palo Alto Networks Next-Generation Firewalls - PA Series as on prem edge security solution and cloud application security solution. These next gen firewalls are helping to allow traffic based on application classification and limiting the noise in the network. Also, use of Strata Cloud manager is an addon which helps in the centralized management of these devices. Feature like Wildfire is providing the support in mitigating zero day attacks. We are utilizing the User-ID feature to restrict the users to the application and services which they need access to. Overall, Palo Alto Networks firewalls are helping us in getting least privilege access implementation in our corporate network.

Pros

  • Wildfire
  • Application Filtering
  • User-ID based access policies
  • DNS protection
  • Remote access VPN support

Cons

  • Menu items on GUI needs to be arranged in a way that it could be easy to find.
  • GUI fonts needs to be on a bit larger side.
  • Instead of graying out the unavailable option on GUI, some different colors should be used.
  • Management web page load time in the browser is on the higher side
  • It takes a lot of time to push any config to the firewall while using Panorama/SCM

Return on Investment

  • Securing the network at edge help in saving the confidential data from getting exposed. The value saved it significant.
  • Restricting the endpoints to specific access, using ZTNA connectors secures internal breaches. It saves the costs of paying for costly endpoint security solutions.
  • Application level filtering and use of User-ID feature with least privilege helps in saving the cost of getting multiple zero trust security solutions.

Usability

Alternatives Considered

Palo Alto Panorama, Palo Alto Networks Prisma Access and Palo Alto Networks Prisma SD-WAN

Other Software Used

Cisco Firepower 9300 Series, Fortinet FortiGate, Cisco Umbrella

Palo Alto Networks Next-Generation Firewalls - PA Series Bugatti of this industry

Use Cases and Deployment Scope

We have Palo Alto Networks Next-Generation Firewalls - PA Series deployed at network edge for outbound /inbound security protection like IPS/IDS, Vuln protection, DDoS protection.... And outbound URL filtering and threat protection.
We have other Palo Alto Networks Next-Generation Firewalls - PA Series set for our internal network micro segmentation and segregation ; the firewall is the gateway for each segment and authorized access rules are in place between the segments.

Pros

  • Vulnerability protection
  • Rich and actionable log and search details
  • Threat Prevention/DNS security
  • APP-ID and SaaS Application integration

Cons

  • SDWAN integration with other vendors
  • PANOS update testing - Upgrade always comes with new issues.
  • OneClick integration for SaaS apps like Talkdesk, Ring, Salesforce

Return on Investment

  • Reduced Risk of Breach
  • Operational Efficiency via Centralized Management using panorama
  • Visibility & Control

Usability

Alternatives Considered

Fortinet FortiGate, FortiAnalyzer, Cisco ASA 5500-X with FirePOWER Services, Zscaler Posture Control, Zscaler Private Access and Zscaler Internet Access

Other Software Used

Zscaler Internet Access, Zscaler Private Access, Radware Alteon

The best of both worlds for cyber security and network performance.

Use Cases and Deployment Scope

We utilize Palo Alto Networks Next-Generation Firewalls - PA Series for our physical locations as well as the virtual appliances to extend capabilities to our cloud infrastructure. The high availability pairing and centralized management through Panorama provide ease of management with solid performance. We have used several other firewall vendors in the past (Checkpoint, and Fortinet) but ultimately replaced them all with Palo Alto Networks Next-Generation Firewalls - PA Series in favour of stronger security and performance.

Pros

  • Panorama product provides ease of management and visibility of multiple firewalls within one console.
  • App-id rules allow for enhanced rule creation.
  • Global Protect VPN extends firewall capabilities to devices not on internal networks. Great for remote workforce.

Cons

  • The interface is a little complicated at first. This is common for all firewall products I've used but Palo Alto could definitely update the UI.
  • Firewall rule audits are cumbersome. I have been using third-party tools to assist with the management. It would be great if Palo Alto could build out this functionality within Panorama.
  • Best-Practice Assessment (BPA) is not well advertised. These are very useful but require reaching out to your rep. Palo Alto should look at automating this and building it into QBR touchpoints with their customers.

Return on Investment

  • Palo Alto Networks Next-Generation Firewalls - PA Series devices generally are on the higher price point; however, I have found the benefits to vastly outweigh the purchase price.
  • Great customer support from pre-sales through to post-sales.
  • Palo Alto is a market leader so they have a lot of integrations with other tooling.

Usability

Alternatives Considered

Check Point 13000 Appliances and Fortinet FortiGate

Other Software Used

Check Point 13000 Appliances, Fortinet FortiGate

Palo Alto Networks Next-Generation Firewalls - PA Series for the win

Use Cases and Deployment Scope

We use Palo Alto Networks Next-Generation Firewalls - PA Series at all our locations. They function as router/firewall appliances, perform web filtering, and provide both client and clientless VPN access. Additionally, they are set up for site-to-site VPN connectivity between locations. They are robust in all they do and are an integral part of our networking. I recommend the Palo Alto Networks Next-Generation Firewalls - PA Series devices to anyone looking for a better router/firewall appliance.

Pros

  • Routing
  • Web Filtering
  • Security
  • VPN

Cons

  • Commit speed is slow when modifying the settings
  • Reporting is there but lacking

Return on Investment

  • All High Availability devices must also be fully licensed. We did not know this until deciding to roll out HA.
  • Many types of updates, such as security policy updates, can be scheduled to auto-update.

Usability

Alternatives Considered

Cisco 4000 Series Integrated Services Routers (ISR 4000) and Barracuda CloudGen Firewall

Other Software Used

Palo Alto Networks Cortex XDR