Link to home
Start Free TrialLog in
Avatar of totaram
totaramFlag for United States of America

asked on

Palo Alto

I see Palo Alto gaining more and more popularity, How are the Palo Alto FWs any different from other FWs ? What is something that PA brings to the table that others can not?
Avatar of Andrew Porter
Andrew Porter
Flag of United States of America image

I was an avid Cisco ASA guy for 10+ years, and the PANs blow them out of the water in every respect. Given that it's all about your personal/companies needs in terms of choosing the firewall, here is what I'll say about the PANs:

Palo Alto Pros:
  • GUI is more intuitive
  • GlobalProtect VPN client is seamless and highly configurable
  • Wildfire subscription keeps you up-to-date
  • TCO is lower than other firewalls w/ similar features
  • The HA (pairing) failover works beautifully - I have it paired with failover ISPs as well
    • The "sync to peer" option is great for updating OS, GP client, etc.
  • Updates are much easier to perform than other firewalls I've used
  • I hear great things about Panorama from colleagues - though I've never used it personally

Palo Alto Cons:
  • Can get pricey when you purchase all the bells and whistles
  • Management plane on smaller PANS (220s) could be better (can be slow at times)
  • Wasn't a middle of the road (medium sized) solution - although now I think they are offering one
PaloAlto firewalls are considered NGFW next generation firewalls
PaloAlto has been the industry leader in firewall sales and increased market share for seven years in a row
top of Gartner and forester reports
Andrew mentioned Wildfire which is a threat intelligence cloud
only one in the entire industry to come close to this is FireEye - the difference is wildfire is built into the firewall machine learning and on top of the firewall and it doesn’t cost what FireEye does
They took Threat intelligence -Content filtering -Data Filtering  -application identification -VPN AV AS Vulnerability Detection and  put it all together in one box that is ….by default a firewall
Panorama (Separate management tool) looks exactly like the firewall - easiest tool ever
They also support SDN and SASE directly with firewall
Decent reporting 40 canned reports and a report query
Plus they have a ton of vendor APIs if you need something extra
The Wildfire / threat / Unit 42 team are THE industry  leaders in bug/malware detection
Unit42 just won that award again
PAN did just come out with a branch level 400 series to address the small/medium space
GUI is intuitive - admins learn it quickly
Device and CLI have a lot of Juniper similarity

cons - bit expensive depending on licensing
Cisco /Juniper have stronger routing in their Hybrid devices

Side note
I have used and taught all three vendors


Avatar of totaram

ASKER

I have been told that there are 5 zones, Management/MPLS/Internet/Internal and DMZ, can you please shine some light on that?
Thanks in advance;
ASKER CERTIFIED SOLUTION
Avatar of DarinTCH
DarinTCH
Flag of United States of America image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of totaram

ASKER

Thanks Darin