Likelihood to Recommend Well suited to data center deployments with storage and compute to host applications. When deployed with VMWARE and/or hyperconverged infrastructure you get a good solution that is reliable and robust and can support a vast array of solutions. Cisco Application Centric Infrastructure works on any sized solution however, it's more appropriate to mid to large scale deployments.
Read full review I think Palo Alto Panorama is suited for administrators of all levels because certain things can be locked down to certain permission levels. But there are executive dashboards all the way down to the weeds for the highest of administrators. This truly is a single pane of glass tool because you never have to go into the individual firewalls for anything.
Read full review Pros The REST API allows your to programmatically interact with the network and make massive changes very quickly when needed. The API allows you to tie together Server Provisioning tools, storage provisioning tools, into an orchestration platform such as Ansible to streamline new deployments and builds. New Deployments are extremely simple once you've worked out your programatic deployment process. We can deploy new clients/tenants in seconds rather than days or weeks like it used to take. Replacing failed switches/apics/etc is also extremely easy. Tightly couple the underlying Network Infrastructure to VMWare Deployments to allow VMs to move anywhere in the datacenter at the drop of a hat. Read full review If you need to push a setting or config to multiple firewalls Panorama can do that flawlessly. Panorama has its logging centralized and this makes it easy to locate and reviews logs compared to having to get logs from each device. I love how the interface matches the interface on the firewall. This makes the learning curve less steep. Adding new firewalls to Panorama is super easy and not complex. Panorama can push a lot of the config and settings so you don't have to manually do it. Read full review Cons The APIC web UI is slow. Even on the newer UCS systems it is laggy. The terminology for some of the objects is really confusing for someone that never used Cisco Application Centric Infrastructure. It would be at least helpful if there would be a link to a reference of the "classical" terms in the web UI. The cost of the hardware, together with the management platform, is high. It is difficult to convince my management layer why the ease of manageability outweighs the high price. Read full review The ability to push out OS updates could be improved in Panorama. It has the abilities, but the use is not intuitive, to the point that we generally connect directly to the firewalls to download the OS updates directly. Scheduling. It would be nice to be able to schedule jobs to run at certain times. Pushing out updates, like OS updates mentioned above, can require significant bandwidth. So being able to schedule that work for hours that would not directly affect the users would be a welcome addition. The list of devices in the Templates tabs should be sorted the same way that he devices are grouped in the Device Group tab, rather than just alphabetical. If there was a way to chose the order of the devices, maybe by tag, that would work as well. Read full review Likelihood to Renew Cisco ACI is doing exactly what was intended for it to do, that is support our next generation data centre, improve security, and increase resiliency. Migrating to another platform would be a waste of time, resource and energy, which could be better spent migrating more legacy applications into the Cisco ACI fabric.
Read full review Panorama has given us much more than we expected and the support for the product, by Palo Alto Networks has been great. We would like to see some improvements that I mentioned in another review, like scheduling changes, but overall Panorama has provided a very capable product and we are very happy with it.
Read full review Usability Cisco ACI has changed the traditional data center model into a new era of automation and agility. The product was considerably easy to deploy met all the expectations. In terms of usability, ACI provides a unified interface for managing the whole infrastructure in one place which is the main benefit for users (admins)
Read full review You can do anything via the GUI without going to the CLI. High real time security as every five minutes, it updates the list of phishing websites. High protection as the firewall communicates with the cloud, a machine running artificial intelligence helps to detect malware or other threats.
Read full review Reliability and Availability no outages
Read full review Performance I do not give it 10 because the platform evolves more and more every day in the data traffic of the datacenter. But the implementations that they carry out for different clients of the platform are very happy with the result of the same over time. Another point that you notice about the platform, despite its good performance, is the low use of energy used by this 24x7 on, it is a good fact to take into account for our environment.
Read full review Support Rating Cisco provides users and partners with a multitude of data for you to consume. I think that the stuff in the public domain goes a long way to assisting you find any answers you may need, plus insights and information from areas such as DevNet provide you with access to more than just the traditional release notes and the like
Read full review Palo Alto has a very nice customer support. People are very nice and were quick to reply, whenever we had an issue with the subscription or the blacklist tool. There is also a great deal of information on their website that covers each and every detail about the uses and the threat signatures. The community keeps on updating their information very frequently. Small issues are easily solved from the documentation, and for other issues, the customer support service is always present. However, on Fridays it becomes a little delayed as per my observation.
Read full review In-Person Training The Cisco ACI training provided by Cisco was in depth, covered all of our requirements, and allowed us to implement and maintain the platform without issues.
Read full review Implementation Rating Not applicable
Read full review Alternatives Considered NSX-T and ACI both are definitely awesome products. I tend to use ACI in networks that have more barebone and/or alternative hypervisors. NSX still works best in VMware heavy networks. Another consideration is where the network is managed, by which team. If the network is solely managed by the network team ACI tends to be a better fitting solution. Also since ACI is a complete solution you don't need any other products. If you implement NSX you will still need a physical network.
Read full review Palo Alto Panorama and Junos Space Security Director have many similar features but Palo Alto Panorama excels in almost all of them. The monitoring tools in Palo Alto Panorama are easy to use and give more in-depth insight into what is going on in your network. Palo Alto's security is ranked much higher and the Web Application Security is also superior to that of the Junos counterpart.
Read full review Scalability Cisco ACI scales well and is suited in scenarios such as multi-cloud or large data centre implementations. It is not suited to smaller deployments as the efficiencies that it provides are not fully realised. It is well suited in large environments that contain both virtual and bare-metal machines allowing a great deal of flexibility. It is also perfect to support multi-tenancy platforms.
Read full review Return on Investment Positive impact moving off of legacy to ACI has shorten costs of operations. Native support for automation makes deployment easier and takes few mins than large amount of hours that can bring costs (OT over time) since it takes minutes to deploy this OT cost has decreased. Troubleshooting made easier, this gains customer trust, therefore we get to spend less time trying to solve an issue and less operations costs. Read full review At a previous company, I deployed Palo Alto firewalls to a data center, and 12 branch locations. This allowed us to replace MPLS links with IPSec tunnels between the sites. This resulted in significantly more throughput and soft savings of increased productivity. However, the estimated net of $220,000 in hard savings over five years is what is most impressive. I could not have effectively managed all those devices without Palo Alto Panorama. Read full review ScreenShots