Carbon Black Endpoint vs. Palo Alto Networks Next-Generation Firewalls - PA Series

Overview
ProductRatingMost Used ByProduct SummaryStarting Price
Carbon Black Endpoint
Score 7.3 out of 10
N/A
Carbon Black Endpoint is an endpoint security and "next-gen antivirus (NGAV)" that uses machine learning and behavioral models to analyze endpoint data and uncover malicious activity to stop all types of attacks before they reach critical systems.N/A
Palo Alto Networks Next-Generation Firewalls - PA Series
Score 9.0 out of 10
N/A
Palo Alto Network’s Next-Generation Firewalls is a firewall option integrated with other Palo Alto security products. Released in late 2023, the PA-7500 ML-Powered NextGeneration Firewall (NGFW) enables enterprise-scale organizations and service providers to deploy security in high-performance environments.
$1.50
per hour per available zone
Pricing
Carbon Black EndpointPalo Alto Networks Next-Generation Firewalls - PA Series
Editions & Modules
No answers on this topic
No answers on this topic
Offerings
Pricing Offerings
Carbon Black EndpointPalo Alto Networks Next-Generation Firewalls - PA Series
Free Trial
NoYes
Free/Freemium Version
NoNo
Premium Consulting/Integration Services
NoNo
Entry-level Setup FeeNo setup feeNo setup fee
Additional DetailsUsers may also choose to pay per gigabyte of data used starting at .065/GB. Note that prices listed here reflect installations via Amazon Web Services. Pricing may differ if other service providers are used.
More Pricing Information
Community Pulse
Carbon Black EndpointPalo Alto Networks Next-Generation Firewalls - PA Series
Considered Both Products
Carbon Black Endpoint
Chose Carbon Black Endpoint
Cb Defense was easy to use and configure and the price point was perfectly acceptable. The company is trusted in the EDR space.
Palo Alto Networks Next-Generation Firewalls - PA Series

No answer on this topic

Features
Carbon Black EndpointPalo Alto Networks Next-Generation Firewalls - PA Series
Endpoint Security
Comparison of Endpoint Security features of Product A and Product B
Carbon Black Endpoint
9.1
4 Ratings
7% above category average
Palo Alto Networks Next-Generation Firewalls - PA Series
-
Ratings
Anti-Exploit Technology10.04 Ratings00 Ratings
Endpoint Detection and Response (EDR)10.04 Ratings00 Ratings
Centralized Management8.04 Ratings00 Ratings
Hybrid Deployment Support8.02 Ratings00 Ratings
Infection Remediation10.04 Ratings00 Ratings
Vulnerability Management9.03 Ratings00 Ratings
Malware Detection9.04 Ratings00 Ratings
Firewall
Comparison of Firewall features of Product A and Product B
Carbon Black Endpoint
-
Ratings
Palo Alto Networks Next-Generation Firewalls - PA Series
8.7
27 Ratings
0% above category average
Identification Technologies00 Ratings9.127 Ratings
Visualization Tools00 Ratings7.626 Ratings
Content Inspection00 Ratings9.527 Ratings
Policy-based Controls00 Ratings9.727 Ratings
Active Directory and LDAP00 Ratings9.026 Ratings
Firewall Management Console00 Ratings8.827 Ratings
Reporting and Logging00 Ratings8.327 Ratings
VPN00 Ratings8.727 Ratings
High Availability00 Ratings8.826 Ratings
Stateful Inspection00 Ratings9.026 Ratings
Proxy Server00 Ratings7.413 Ratings
Best Alternatives
Carbon Black EndpointPalo Alto Networks Next-Generation Firewalls - PA Series
Small Businesses
ThreatLocker
ThreatLocker
Score 9.4 out of 10
pfSense
pfSense
Score 8.8 out of 10
Medium-sized Companies
CrowdStrike Falcon
CrowdStrike Falcon
Score 9.1 out of 10
Quantum Firewalls and Security Gateways
Quantum Firewalls and Security Gateways
Score 9.3 out of 10
Enterprises
BeyondTrust Endpoint Privilege Management
BeyondTrust Endpoint Privilege Management
Score 10.0 out of 10
Palo Alto Networks Virtualized Next-Generation Firewalls - VM Series
Palo Alto Networks Virtualized Next-Generation Firewalls - VM Series
Score 9.1 out of 10
All AlternativesView all alternativesView all alternatives
User Ratings
Carbon Black EndpointPalo Alto Networks Next-Generation Firewalls - PA Series
Likelihood to Recommend
9.0
(8 ratings)
9.0
(43 ratings)
Likelihood to Renew
-
(0 ratings)
10.0
(1 ratings)
Usability
10.0
(2 ratings)
8.5
(8 ratings)
Support Rating
8.8
(3 ratings)
8.4
(9 ratings)
User Testimonials
Carbon Black EndpointPalo Alto Networks Next-Generation Firewalls - PA Series
Likelihood to Recommend
Broadcom
Cb Defense has been working very well in our organization. It is giving us much better insight into the applications that people are running on their systems (without authorization). This software is also great because it provides visibility into systems that are remote (off the network but still have Internet access). The out of band feature is great to help ensure that the systems are protected even when a user is traveling.
Read full review
Palo Alto Networks
It is well-suited for a company needing strong edge security with ease of administration. It comes standard with many features such as VPN, Application ID and "Day-1 Config" that make the networks it protects secure from the very start. Palo is definitely a premium product and is much more expensive than other firewalls, but the value is realized immediately. The robust options for firewall rules/policies allow the administrator to apply security in new and creative ways to hit the sweet spot between security and usability.
Read full review
Pros
Broadcom
  • History of Process Execution, really anything that happens in the system is easily seen within the Dashboard. I can determine if a bad actor has infected the system, be it malware, backdoor, rootkit, Trojan, then from that point, I can put the system into Quarantine.
  • Being able to quarantine the system from the Dashboard. With these type of tools, pulling the power and running a hard drive image is not needed. Put the system in quarantine, start the analysis. A year ago, the network engineer might move the system into a VLAN that has no access to anything, except the system performing the remote analysis... Now I do not have to rely on anyone to move a system, power it down, pull the drive, or image the drive. I can just start the analysis right from my workstation.
  • The Live Response, again goes hand in hand with the quarantine feature.
  • By now, I am sure you see a process. Its simple, and easy and all done from a cloud-based console, called the dashboard. .. deploy the agent, create the policy, and active live response, set up email alerts, and monitor your endpoints... you are now ready to perform a triage in the event of an infection. We have step 1, step 2, step 3... but, just remember, things do happen, nothing is perfect, but this product has its advantages.
Read full review
Palo Alto Networks
  • The PA handles VPN connectivity without missing a beat. We have multiple VPN tunnels in use for redundancy to cloud-based services.
  • The PA has great functionality in supporting failover internet connections, again with the ability to have multiple paths out to our cloud-based services.
  • The PA is updated on the regular with various security updates, we are not concerned with the firewall's ability to see what packets are really flowing across the network. Being able to see beyond just IP and port requests lets you know things are locked down better than traditional firewalls.
  • It is a great overall kit, with URL filtering and other services that fill in the gaps between other solutions without breaking the bank.
Read full review
Cons
Broadcom
  • Policy management can be cumbersome. It is simple to set up a single policy but you have no way to apply the rules to multiple groups. If you need to set up the same rule to multiple policies, you need to type it over again.
  • Agent updates can be very slow to deploy. We use a mix of rolling out updates via the web console and our management appliance. It can take several weeks to update all agents.
  • We can be confused on why a rule will apply to a file. Sometimes something is blocked but we don't understand why.
Read full review
Palo Alto Networks
  • Setting up certain things can be somewhat complicated due to the numerous options and abstractions involved.
  • It would be nice to have somewhere to get simple canned reports easily.
  • It would be nice to be able to remove options we never use from various setup dialogs.
Read full review
Likelihood to Renew
Broadcom
No answers on this topic
Palo Alto Networks
The PA5220s have far exceeded what we have expected out of them. It was a bit of a learning curve coming from another vendor, but everything falls into place now with ease. The capabilities of the solution still surprise us, allowing us to remove other costly hardware and providing a single point of management needed
Read full review
Usability
Broadcom
The console of the product is very easy to use. It provides great detailed information about all aspects of things occurring on the endpoint. It was easy to deploy and set up. The centralized cloud-based interface has made it easy to add two domains and manage them under a single pane with multiple admins. The only reason I wouldn't give it a higher score is a little bit of lag between updated info from the clients and also the lack of accountability in the deployment process. You set the deployment up for multiple machines and can't easily see if it was successful and/or it takes a while to see if it succeeded or failed.
Read full review
Palo Alto Networks
It can be a little tricky at first if you have never used the product or a firewall before. If you have experience with firewalls in general, it does not take long to learn the Palo Alto Networks Next-Generation Firewalls - PA Series interface. They offer great training resources and knowledge base articles to help get up to speed.
Read full review
Support Rating
Broadcom
First, I need to disclose that our support is provided by SecureWorks. We purchased CB Defense from them, and they provide 24x7 monitoring and notification services for the solution and its deployment on our endpoints. To date, we are very pleased with this arrangement
Read full review
Palo Alto Networks
We've run into a couple undocumented bugs, but that seems to happen with every brand and technology. Any time we've had to engage Palo Alto support they've always been professional, knowledgeable and prompt. In almost all cases we've been able to resolve our issues without having to escalate our tickets.
Read full review
Alternatives Considered
Broadcom
Cb is cloud-based and has a more advanced policy management. It also has better forensics information. Cost was similar, but Cb added cost savings in terms of IT management resources. We also have the ability to talk directly with engineers and have input on feature updates.
Read full review
Palo Alto Networks
We are using Cisco ASA before in our environment but when it comes to deep scanning & layer 7 security it doesn't have that capability. After using Palo Alto Networks Next-Generation Firewall we are using sandboxing & advance malware protection that provides high-level end-user security. Also after implementing it we can easily monitor user-level traffic.
Read full review
Return on Investment
Broadcom
  • Cb Defense has had a positive impact on the business objectives since we've been able to check off "advanced threat prevention".
Read full review
Palo Alto Networks
  • We used to outsource our Firewall and it's management. Not only did we find their SLA's to be lacking, in general, but communication between us was horrible. Many times we could not understand them and that resulted in less than desirable rule creation or troubleshooting.
  • Since we no longer have to pay a company for 24/7 management (and SLOW SLA's) we are saving a ton of money each year. Also our fellow employee's are much happier that things can be resolved in a timely manner.
Read full review
ScreenShots

Carbon Black Endpoint Screenshots

Screenshot of Cb Defense Dashboard
See every attack and potential threat at a glance in this interactive viewScreenshot of Cb Defense Alert Triage
Get answers to how and why each attack occurredScreenshot of Cb Defense Response
Strengthen your defenses with every attack