Top Rated
78 Ratings
<a href='https://www.trustradius.com/static/about-trustradius-scoring' target='_blank' rel='nofollow noopener noreferrer'>trScore algorithm: Learn more.</a>
Score 9.1 out of 100
29 Ratings
<a href='https://www.trustradius.com/static/about-trustradius-scoring' target='_blank' rel='nofollow noopener noreferrer'>trScore algorithm: Learn more.</a>
Score 8.5 out of 100

Likelihood to Recommend

Next-Generation Firewalls - PA Series

The Palo Alto device is well suited for a direct replacement for any traditional or other firewall. There is little room for error on this device, it will do exactly what you have it configured for. Between security zones, security policies, nat policies, policy based forwarding, and everything in between, you have to keep your head on straight when making big or small changes.
The Palo Alto does have one overall issue our users report more than anything. The Palo Alto is a strict NAT device, so unless you have the ability to 1 to 1 map IP addresses for your users who need something beside strict NAT limitations, the Palo Alto will cause you grief.
Anonymous | TrustRadius Reviewer

Zscaler Internet Access

As far as content filtering goes, Zscaler has met all of our needs. We feel that is doing the job well but we also feel like we could get more out of it. The ability for a downloaded file to be ran in a sandbox before delivering to the use is an awesome feature. The end user gets frustrated that they have to wait up to 10 minutes to receive their download but from a security standpoint it is working well.
Cody Plassmeyer | TrustRadius Reviewer

Feature Rating Comparison

Firewall

Next-Generation Firewalls - PA Series
8.4
Zscaler Internet Access
Identification Technologies
Next-Generation Firewalls - PA Series
8.4
Zscaler Internet Access
Visualization Tools
Next-Generation Firewalls - PA Series
7.8
Zscaler Internet Access
Content Inspection
Next-Generation Firewalls - PA Series
8.6
Zscaler Internet Access
Policy-based Controls
Next-Generation Firewalls - PA Series
8.8
Zscaler Internet Access
Active Directory and LDAP
Next-Generation Firewalls - PA Series
8.6
Zscaler Internet Access
Firewall Management Console
Next-Generation Firewalls - PA Series
8.0
Zscaler Internet Access
Reporting and Logging
Next-Generation Firewalls - PA Series
8.3
Zscaler Internet Access
VPN
Next-Generation Firewalls - PA Series
8.1
Zscaler Internet Access
High Availability
Next-Generation Firewalls - PA Series
9.1
Zscaler Internet Access
Stateful Inspection
Next-Generation Firewalls - PA Series
9.1
Zscaler Internet Access
Proxy Server
Next-Generation Firewalls - PA Series
8.0
Zscaler Internet Access

Pros

Next-Generation Firewalls - PA Series

  • AppID is able to see what the actual internet traffic is. For instance instead of port 443 just being "Internet traffic" we can define access to Facebook-base or all the other facets of facebook.
  • UserID allows us to define policies based on group or user access and integrates with our Active Directory. This helps to configure a least access privilege and if we find misuse of the network we can tighten specific users to a stricter policy.
  • GlobalProtect VPN connection helps our employee's connect from home remotely. This provides a very secure connection with minimal configuration.
  • Wildfire provides very up-to-date information regarding global attack mitigations and stopping techniques.
Christopher St.Amand | TrustRadius Reviewer

Zscaler Internet Access

  • DAS program helps ensure that you get set up properly the first time around.
  • Reports are easily customizable from minute details that you may want as IT to high-level overviews for executive presentations.
  • Lots of capability.
Anonymous | TrustRadius Reviewer

Cons

Next-Generation Firewalls - PA Series

  • The CLI is a bit confusing, and it's difficult to find what you're looking for. Takes a lot of practice. Definitely not as good as the Cisco CLI.
  • Updating the firmware is often a very dangerous process, especially when jumping minor or major releases. More QA should be done to validate and ensure no issues during upgrades. I'll admit it's gotten better over time, but there is still room for improvement.
Anonymous | TrustRadius Reviewer

Zscaler Internet Access

  • Securing third party access is a bit complex to implement. These are our third party partners who require access to our data center on a temporary basis.
  • It is a bit of a learning curve to transform from the VPN and appliance architecture to this model.
Joseph Imbimbo | TrustRadius Reviewer

Likelihood to Renew

Next-Generation Firewalls - PA Series

Next-Generation Firewalls - PA Series 10.0
Based on 1 answer
The PA5220s have far exceeded what we have expected out of them. It was a bit of a learning curve coming from another vendor, but everything falls into place now with ease. The capabilities of the solution still surprise us, allowing us to remove other costly hardware and providing a single point of management needed
Anonymous | TrustRadius Reviewer

Zscaler Internet Access

No score
No answers yet
No answers on this topic

Usability

Next-Generation Firewalls - PA Series

Next-Generation Firewalls - PA Series 10.0
Based on 2 answers
In my opinion, the Palo Alto Firewall is the simplest firewall in terms of management interfaces; though it has more advanced options that apply to more advanced use cases. Configuring basic features on the firewall is nearly self-explanatory; configuring more advanced features can be met with very thorough vendor documentation.
Anonymous | TrustRadius Reviewer

Zscaler Internet Access

No score
No answers yet
No answers on this topic

Support Rating

Next-Generation Firewalls - PA Series

Next-Generation Firewalls - PA Series 8.5
Based on 9 answers
We've run into a couple undocumented bugs, but that seems to happen with every brand and technology. Any time we've had to engage Palo Alto support they've always been professional, knowledgeable and prompt. In almost all cases we've been able to resolve our issues without having to escalate our tickets.
Paul Luchini | TrustRadius Reviewer

Zscaler Internet Access

Zscaler Internet Access 8.0
Based on 4 answers
While overall support was always nice and polite, most of the time it was hard to reach them and it took awhile for them to respond back in urgent cases. It was probably an isolated case but, still, it's hard to manage a tool without proper support from the vendor when in need.
Samuel Hadid | TrustRadius Reviewer

Alternatives Considered

Next-Generation Firewalls - PA Series

I have used Cisco & Sonicwall primarily in most of my 23+ years of network security experience. Over the years all of these platforms have matured, but Palo Alto beats them all in terms of user interface.

The ability to run reports, get access to data immediately, and have the data be extremely accurate and granular is what sets Palo Alto apart from the others. Deployment of the VPN client(s) on multiple platforms is simple to manage and doesn't break other applications like many other VPN client software does. The performance of the firewall from a throughput and monitoring standpoint is second to none.
Anonymous | TrustRadius Reviewer

Zscaler Internet Access

I have previously used Websense and Bluecoat, both with mixed results. Zscaler is the superior product if for no other reason that is far easier to deploy and manage
Anonymous | TrustRadius Reviewer

Return on Investment

Next-Generation Firewalls - PA Series

  • Utilizing Panorama to manage all of our Firewalls Policies by creating device groups is a real time saver. We only need to configure policies once and push them to the appropriate firewalls saving a lot of time.
  • Having the added security feature protection is good peace of mind in an ever-increasing threat landscape.
  • Monitoring traffic by IP, URL or username provides excellent insight into our traffic.
Anonymous | TrustRadius Reviewer

Zscaler Internet Access

  • Positive Impact - Ease of deployment - Product works very well, very few obstacles to deployment. Hosted PAC files make things easy. IPSEC tunnels supported for traffic routing
  • Positive Impact - High ROI
Anonymous | TrustRadius Reviewer

Pricing Details

Next-Generation Firewalls - PA Series

General

Free Trial
Free/Freemium Version
Premium Consulting/Integration Services
Entry-level set up fee?
No

Zscaler Internet Access

General

Free Trial
Free/Freemium Version
Premium Consulting/Integration Services
Entry-level set up fee?
No

Rating Summary

Likelihood to Recommend

Next-Generation Firewalls - PA Series
9.3
Zscaler Internet Access
8.3

Likelihood to Renew

Next-Generation Firewalls - PA Series
10.0
Zscaler Internet Access

Usability

Next-Generation Firewalls - PA Series
10.0
Zscaler Internet Access

Support Rating

Next-Generation Firewalls - PA Series
8.5
Zscaler Internet Access
8.0

Add comparison