Cisco Secure Web Appliance (formerly Cisco Web Security Appliance [WSA]), powered by Cisco Talos, protects by automatically blocking risky sites and testing unknown sites before allowing users to link to them, helping with compliance. It is available models S690, S390, and S190.
N/A
Palo Alto Networks Advanced URL Filtering
Score 9.3 out of 10
N/A
The
majority of attacks and exposure to malicious content occurs during the
normal course of web browsing activities, which requires the ability to allow
safe, secure web access for all users. URL Filtering with PAN-DB
automatically prevents attacks that leverage the web as an attack vector,
including phishing links in emails, phishing sites, HTTP-based command and
control, malicious sites and pages that carry exploit kits.
Considering we're with Cisco IronPort Web Security Appliances for the last 9 years, as I stated, we don't have too much experience with other producs. What I can say is that in the past, we evaluated Websense before it became Forcepoint and we also used MS ISA Server for …
We have both scenarios where we can describe that. For example, in the HQ, where we have about 3,000 users, Cisco IronPort Web Security Appliance is the ideal solution, because we can consolidate all the Internet access, policies, rules, etc. in the same box. However, if you have small offices with a few users, it's hard to justify one big and expensive box that could cost more than the whole office infrastructure.
Because of it's complexity, Palo may not be well suited for a small organization that may not have dedicated networking staff. But for a mid to large-sized enterprise, Palo shines.
I think that the interface could need updates to adapt it to a much more current system, achieve quick access to necessary tools and adapt the platform to a much more customizable and comfortable system to work with.
It is undoubtedly a platform that is worth having, however, the license costs could be better adjusted to small businesses so that it can be accessed more easily.
It could be a bit complex to use, the use of codes is quite extensive, it could be adjusted to something much more practical but just as efficient.
Because it's one of those products you almost don't realize it exists from the end user. From the administrator perspective, you can do everything on its web interface and it's very intuitive to manage, once you know the concepts behind identities, acls, etc. Also, once you build the control structure, I mean, you link 'local' groups with your own Active Directory groups, as we did here, you don't need to be managing those things on the appliance itself.
Our experience with Cisco's support was terrible. Other than the fact that they don't respond to service-related emails with urgency, they also keep on changing the policies that affected us. Recently, they came up with a new look for the same software, which was insanely slow. Renewal of keys for the old interface took months. Overall, the support was not very friendly from the users' point of view.
Palo support is excellent, and I have never had to wait when contacting them for support. One of the best support teams in the business, in my opinion.
At home I have a McAfee service that does similar tasks and helps manage the users of my internet. McAfee seems more user friendly and easier to set exceptions.
Palo Alto Networks Advanced URL Filtering is the best solution to work with Palo Alto Firewalls and Panorama as an orchestrator. We choose Palo Alto Networks Advanced URL Filtering as it could reach the success criteria during the PoC.
Security! Security! Security! We are financial company that work with very sensitive information. A lot of unsafe traffic was blocked on the Cisco IronPort WSA over years of using it. We did not earn on it but absolutely sure that we did not lose 'gazillion' of dollars being infected or scammed.
Easy to configure and use, no need to teach new personnel how work with this product (hopefully saving time = saving money).
Unfortunately the price of license subscription made financial managers push IT dept. to look for something cheaper.