PAN - Solid Choice!
December 06, 2018

PAN - Solid Choice!

Anonymous | TrustRadius Reviewer
Score 9 out of 10
Vetted Review
Verified User

Software Version

VM-100 Series

Overall Satisfaction with Palo Alto Networks Virtualized Next-Generation Firewalls - VM Series

PAN has been a fantastic boon to our users by doing full inline threat protection, Easy VPN configuration, including a uniform interface that scales from small devices to large devices.
  • Easy deployment.
  • Backups, snapshotting, etc. make returning to pre-change state a snap.
  • Threat management, data leak protection, etc. can be done in-line with ease.
  • I feel like there is not enough of a support community, similar to checkpoint.
  • VPN client is not as user-friendly as Anyconnect.
  • No root access to device.
  • ROI has been achieved quickly through lack of security incidents.
  • Inline filtering happens at line rate, unline Sourcefire from Cisco.
  • Great incentives from PAN to switch made a difference in the choice to change.
PAN was a much more solid choice, with less infrastructure needs required than Checkpoint. Cost was also a factor, with PAN being cheaper, even without the discounts given by our rep. VPN's are much easier to configure with non-heterogeneous products where the checkpoint is an absolute mess to configure a VPN with.
PAN does a great job at classifying traffic, and rate-limiting said traffic at line rate. (Very similar to Bluecoat/Packetteer's Packet Shaper) This also alleviates the need for a second device to do bandwidth control. I believe that it's a great user-based, and security-focused device, and one of the few that can produce a positive enforcement model (Deny first).