I like the ability to see exactly who is on the network and what specific applications they are using, and the fact that I can write rules based on that rather than dealing with messy IP addresses, which is unmatched. The built-in cloud threat intelligence and machine learning consistently catch zero-day exploits and malware faster and more accurately than any other firewall we've used. It stops brand new threats in seconds without requiring us to wait for manual updates. The accuracy of these features ensures our team doesn't waste time chasing false alarms, allowing us to focus only on real threats. Review collected by and hosted on G2.com.
The upfront hardware cost is already high, but the ongoing licensing is where it really hurts. Every essential security feature like URL filtering, advanced threat prevention, and WildFire requires its own separate, expensive subscription. It takes up a massive chunk of our budget. Every time you make a change to the configuration, you have to run a commit to apply it. This process can take a surprisingly long time to complete, which is a big daily annoyance when you are trying to make quick tweaks or troubleshoot an issue in real time. It was a steep learning curve and definitely not a plug and play experience. Because Palo Alto firewalls are so feature rich and fundamentally different from legacy port based firewalls, the initial architecture setup took a lot of careful planning. Review collected by and hosted on G2.com.