We use this product to secure our entire network, for ZTNA structure, and for VPN purposes, allowing access to our servers behind the firewall.
VM-Series Virtual Next-Generation Firewall (BYOL)
Palo Alto Networks | PAN-OS 11.1.6-h7Linux/Unix, Other 11.1.6-h7 - 64-bit Amazon Machine Image (AMI)
External reviews
External reviews are not included in the AWS star rating for the product.
A short Note on VM-Series Palo Alto
I have share my experiance about this and also describe issues which i have face on daily basis.
If you don't remember the serial number of the firewall then you can not reterive the license directly from the firewall so either you find the serial number or check from the Palo Alto support portal.
Also, VM-Series firewalls are cheaper than hardware base and easy to take care.
I've been using Palo Alto VM version and it is fast and easy to backup since it is on cloud.
Good performance, powerful CLI, and offers zero-day signature updates
What is our primary use case?
How has it helped my organization?
Using this product has increased our security and has given us much better results in terms of security scans.
Palo Alto embeds machine learning into the core of the firewall to provide online real-time attack prevention, and I would rate that capability an 8 out of 10. It's definitely effective in terms of securing our network against threats that are able to evolve and morph rapidly.
This solution provides a unified platform that natively integrates all of the security capabilities, although we are not using parts of it. For example, we don't use the configuration tools like Panorama.
What is most valuable?
The most valuable feature is the CLI.
We have the firewall configured for zero-day signatures, which is very important to us. We must be HIPAA and PCI compliant, which means that we need those signatures immediately.
There is no noticeable trade-off between security and network performance. In fact, so far, we've not seen any negative network performance with it. We're very impressed in that regard.
What needs improvement?
The web interface is still slow, even after recent improvements.
For how long have I used the solution?
I have been working with the Palo Alto Networks VM-Series for three years.
What do I think about the stability of the solution?
This product is very stable. We have had zero problems with stability.
What do I think about the scalability of the solution?
The scalability is fantastic. We're using the lowest-end product right now, and I don't foresee when we'll have to upgrade. We've got a long way where we can continue to scale up.
We currently have multiple people that use it for VPN purposes, to access our servers behind the firewall. It is not used nearly as extensively as it should be. However, next year, we're going to start flowing all of our internet traffic through it.
We're all working remotely, and we're going to be connecting through the firewall. This means that our traffic is going to greatly increase, meaning that our usage will also increase. We'll also be using many more of the features.
How are customer service and support?
The technical support from Palo Alto is good, overall. However, their response times could be a little quicker.
We have not really had any big complaints with the technical support and I would rate them a seven out of ten.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
Prior to using Palo Alto, we were using an on-premises solution by Juniper. When we switched from onsite to the cloud, we changed products.
We made the switch because Juniper became unbearable regarding complexity and performance. It was getting very bad; we couldn't manage it well, and the performance was quite poor.
How was the initial setup?
The initial setup is quite complex. There is a steep learning curve and we failed at it a couple of times.
Our final deployment took between three and four hours.
What about the implementation team?
Our in-house team was responsible for the deployment.
What was our ROI?
We have absolutely seen a return on our investment. We are definitely more secure. With the features that are in Palo Alto, we do not have to worry about people busting into our network. Even just out of the box, with the base features, it's really solid. The default configurations are very secure.
Our return on investment comes from the fact that we're not having to spend hours monitoring stuff the way we did before. We've saved man hours and we've saved stress. I can't put a monetary value to that, but that would be the return.
What's my experience with pricing, setup cost, and licensing?
This is not the cheapest firewall but it's not the most expensive of the options on the market.
There's a new licensing structure coming in that we're really trying to understand, so I would suggest studying up on it. I recommend getting a partner involved for purchasing the product.
Which other solutions did I evaluate?
Beyond Palo Alto, we evaluated two or three other products. Two of them that I can recall are Fortinet and the Microsoft Azure Firewall.
We did some extensive reviews and some extensive testing and what we found is that for the price, Palo Alto gave us the best options. It had the best set of security features. It wasn't the cheapest product but it was the best solution that fit our requirements.
What other advice do I have?
We have not yet implemented the DNS security features. However, we will likely be doing so next year.
If one of my colleagues at another company were to say that they were just looking for the cheapest and fastest firewall, I would suggest that they be careful. Palo Alto has a great balance. It's not super expensive compared to other options on the market, and it's quite quick when it comes to throughput and performance.
In summary, this is a good product but I do suggest that people shop around a little bit.
I would rate this solution an eight out of ten.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
The best firewall solution for any and all networks.. Period!!!
Launch at an older version
How can we launch the instance at an older version? like 10.1.4? when we launch an instance, it doesn't ask for the software version and launches by default to the latest version
Palo Alto VM-Series Firewalls
Install Version
There is no way to Select the OS Version we want when deploying Palo from the AWS Market Place. Deploying the default version is not acceptable.
Best secure firewall in VM series
2. Initial configuration is simple via management interface in VM.
3. Lot of security features and anti-spam profiles are available.
4. High availability (HA) works perfectly as same as physical firewalls.
2. Saving the configuration changes takes time.
3. Configuration of some security profiles is a long process.
1. Configuring appropriate security policies to protect internal servers.
2. Configuring VPN profiles to access the servers from the internet.
3. Configuring the Antivirus and Antispoof profile to protect servers from brute force and exploitation attacks.