TrustRadius: an HG Insights company

Palo Alto Networks Virtualized Next-Generation Firewalls - VM Series

Score10 out of 10

20 Reviews and Ratings

What is Palo Alto Networks Virtualized Next-Generation Firewalls - VM Series?

The VM-Series is a virtualized form of Palo Alto next-generation firewall that can be deployed in a range of cloud environments. The VM-Series natively analyzes all traffic in a single pass to determine the application identity, the content within, and the user identity.

Read more details.

Categories & Use Cases

Top Performing Features

  • Content Inspection

    Inspecting permitted application traffic by means of threat prevention, URL filtering and data filtering

    Category average: 8.7

  • Stateful Inspection

    Stateful inspection analyzes packet headers and contents of packets

    Category average: 8.8

  • Identification Technologies

    Policy-based visibility and control over applications, users and content

    Category average: 8.5

Areas for Improvement

  • Reporting and Logging

    Custom and summary reports, and log files enabling analysis of security incidents, application usage and traffic patterns

    Category average: 8.3

  • VPN

    VPN's implement encryption and anonymize IP addresses

    Category average: 9.1

  • High Availability

    Built-in capacity to prevent exposure if primary firewall stops working

    Category average: 9.3

Who Buys & Uses Palo Alto Networks Virtualized Next-Generation Firewalls - VM Series

Most Frequent Users

Top 3 industries using Palo Alto Networks Virtualized Next-Generation Firewalls - VM Series.

Based on HG Insights installation data
Powered by
View all Reviews

PA Virtual NGFW what I think about it

Use Cases and Deployment Scope

virtual NGFW address the hardware footprint issue which help us and our customer to provision site pre-requisites to host a appliance based firewall like rack/power space/operation overheads etc. it extend the flexibility to accommodate this NGFW in hybrid infra environment.

Pros

  • it helps putting policies based on application and not only port or IP
  • it provide all the features and functionality with the flexibility of virtual footprint, so scalability is not a challenge.
  • comparatively easy to implement policies like SAML for SSo etc.
  • well suited for a SSE environment,
  • overall reliability is good for a virtual NGF of PAL, we used multiple models on VMxx

Cons

  • I think if we can do a better on resource requirement like vCPU, Memory etc. it is a bit higher side versus the competition.
  • can we simply the licenses like BYOC or PAYG.
  • can we see some development to have features like policy as code for cloud native requirement. it can be better from current situation

Return on Investment

  • cloud ready and flexible deployment options gives better ROI in terms of scalability
  • consistence across appliance and virtual for policies.
  • flexibility in licensing help better ROI
  • all in one platform with reduced breach risk

Usability

Alternatives Considered

Fortinet FortiGate, CheckPoint and Cisco Firepower 4100 Series

Other Software Used

Palo Alto Panorama, Zscaler Private Access, Fortinet FortiGate

Great features and performance for a relatively small cost.

Use Cases and Deployment Scope

We use these firewalls in our production systems networks (Operational Technology) to manage the various security zones and traffic between them. This is part of our production-critical network and a critical component of our security infrastructure.

Pros

  • Manage Zones & VLANS.
  • Define and manage traffic rules.
  • Enforce and monitor traffic flows.

Cons

  • Major Version Upgrades.
  • Managing Large amounts of rules.
  • Debugging rules.

Return on Investment

  • Reliability
  • Cost Effective.
  • Longevity & ongoing support - not tied to hardware.

Usability

Alternatives Considered

Fortinet FortiGate

Other Software Used

AVEVA Production Management, AVEVA Historian, AVEVA Work Tasks, SAP Integration Suite, SAP S/4HANA Cloud

Palo Alto Firewall is The Firewall of the Future.

Use Cases and Deployment Scope

The Palo Alto Networks Virtualized Next-Generation Firewall is deployed at one of our customers' datacenter. It is serving as a parameter firewall and a site-to-site VPN gateway. It is running Global Protect for management access out of band access. The firewall protects against threats via websites and emails. Any attempts to breach the firewall is logged and an email is sent to all administrators including management and a ticket is logged.

Pros

  • Sink holing access to command and control threats
  • Deep packet inspection
  • Secure remote access VPN via Global protect

Cons

  • High Availability can be improved to allow active-active deployment
  • All command line documentation to provide and support automation
  • It will be nice to have link aggregation just like in the hardware firewall models.

Return on Investment

  • The ability for the firewall to dynamically update its threat database means that the business has less risk since the firewall is capable of blocking known and unknown threats and that increase the business's Return on Investment.
  • Backups and restores take a few minutes to accomplish which reduces engineering costs to the business.
  • Network reporting and visibility provided by the firewall allows us to rely on this firewall only rather than having to deploy additional software to monitor and report on the network, that alone allows the business to save on other software costs and realize a big margin on ROI provided the Palo Alto Networks Virtualized Next-Generation Firewall.

Alternatives Considered

Cisco ASA 5500-X with FirePOWER Services, WatchGuard Network Security and Fortinet FortiGate

Other Software Used

Cisco ASA 5500-X with FirePOWER Services, WatchGuard Network Security, Fortinet FortiGate

Best in class Datacenter Solution

Use Cases and Deployment Scope

We decided to purchase VM Series because we implement micro-segmentation into the Datacenter. We needed performance, scalability, and l7 feature are using Palo Alto physical appliances so why not implement their VM Solution into a High Density VMWare environment

Pros

  • L7 Firewall policies
  • Virtualized performance
  • Credit usage to scaleup o scaledown solution

Cons

  • SD-WAN implementation
  • No compatibility with OpenVPN clients
  • Historical logging

Return on Investment

  • Credit usage solution is a great solution to scale VM Series

Other Software Used

Trend Micro Cloud One - Workload Security, Trend Micro Deep Discovery, Trend Micro Vision One

Awesome Secure Web Gateway

Pros

  • Decrypt internet traffic
  • daily reporting of top internet users
  • classify internet traffic in real-time to allow us to understand the organization needs.
  • Strong AI capabilities

Cons

  • needs SD-WAN and cloud security in an integrated solution.
  • need stronger state-side support
  • requires significant compute resources

Return on Investment

  • It has help us determine the necessary spend for internet bandwidth
  • Has helped us easily monitor policy compliance
  • Provided tools that increase understanding of security for non-IT staff

Alternatives Considered

FireEye Network Security and Cisco ASA