
Prisma SD-WAN ION Virtual Appliance (BYOL)
Palo Alto NetworksReviews from AWS customer
0 AWS reviews
-
5 star0
-
4 star0
-
3 star0
-
2 star0
-
1 star0
External reviews
63 reviews
from
External reviews are not included in the AWS star rating for the product.
Sub-second path steering and App-SLA insight across our 100 sites with Prisma SD-WAN
What do you like best about the product?
I run the day-to-day SD-WAN fabric for 98 clinics and two data centers, using ION 3200/5200 appliances and Prisma policies pushed from Panorama. The traffic-engine looks at loss, jitter, and one-way delay every 200 ms with built-in synthetic probes, then flips sessions to the cleaner link in under 300 ms—fast enough that our SIP handsets never click. App-ID fingerprints more than 3,000 SaaS and medical apps, so I can pin Epic Hyperspace and PACS image pulls to the 500-Mbps DIA link while sending Windows updates out the cheaper broadband path. The device OS exposes a full REST API; I use a 120-line Python script to pull JSON metrics, merge them with Splunk HEC events, and show branch MOS scores in a single glass. Template-based configs mean I only set the BGP ASN, loopback IP, and site tag once; the box auto-generates IPSec tunnels with AES-256-GCM, IKEv2, and SHA-256 checks. Zero-touch deploy really works—we ship an ION, the nurse plugs in power and WAN, and it dials home through TLS 1.2 to claim its config. All this cut circuit outages by 42 % and helped slash P1 ticket volume by about a third.
What do you dislike about the product?
Code upgrades still drop forwarding for 60-90 seconds—fine for web, but bad for HL7 streams that hold TCP sockets open for hours. The policy UI hides object IDs deep in nested menus, so bulk edits with the mouse are slow; a typo in a JSON import can leave the device stuck in “staged” until support clears the lock. IPv6 support exists, but you can’t do dual-stack path rules yet, so I run NAT64 as a band-aid. Flow reporting exports NetFlow v9 only; if you want IPFIX you need to push logs to Cortex Data Lake and pull them back out, which adds delay. On 1 Gbps links, the in-line IPSec engine tops out near 840 Mbps with AES-GCM—enough for now, but we’ll hit the ceiling as we move more imaging to the cloud. Finally, TAC response on complex BFD-flap bugs can take two business days, and you often bounce between SD-WAN and firewall queues before getting the right engineer.
What problems is the product solving and how is that benefiting you?
Before the rollout, every clinic rode a single MPLS loop, and when that 20-ms link hit 3 % loss, Epic screens froze and providers had to fall back to paper. Now each site has two cheap broadband lines plus LTE fail-over. The appliance shoots 200-ms synthetic probes, scores loss / jitter / delay, and flips TCP sessions to the cleaner link inside 300 ms, so chart pulls and HL7 feeds keep flowing. Built-in App-ID fingerprints more than 3 k apps, letting us nail Epic and PACS to the 500-Mbps DIA while shoving Windows updates down the cheaper broadband. IPSec with AES-256-GCM keeps PHI safe in motion, and the REST API feeds 60-second stats into Splunk HEC so our NOC dashboard shows live MOS and tunnel health. Outage-related tickets dropped 42 %, mean time to repair fell from 58 minutes to 19, and we saved about $1.3 million a year by retiring MPLS
Stable, and top tier cloud management
What do you like best about the product?
I've worked with these products by Palo Alto in my organization ( +5000 employees) and the thing I enjoyed the most is that in my 3 year experince with it it has sempliefied my daily job and saved many costs in the 3 years. It's a well designed and well built product.
What do you dislike about the product?
VRF features are less implementable compared to Ciscos or Fortinet, this product is also mostly designed for hub-spoke and this gave us quite some limitations and the documentation they provide is not enough.
What problems is the product solving and how is that benefiting you?
The main reason we had to deploy it is cause we as service provider had to manage a large IaaS covering 300 corporate customer and Prisma offered a great centralized and friendly management with security integreted features and some great improvement in our network performance
Review of Prisma SD-WAN by Palo Alto Networks
What do you like best about the product?
Prisma SD-WAN provides excellent application-aware routing, ensuring that critical applications receive the necessary bandwidth and low latency. This has greatly improved our overall network performance.
What do you dislike about the product?
The initial setup can be somewhat complex and time-consuming, especially for organizations without prior experience with SD-WAN solutions. However, the comprehensive documentation and support from Palo Alto Networks help mitigate this issue.
What problems is the product solving and how is that benefiting you?
Prisma SD-WAN helps solve problems like complex network management, inconsistent application performance, security vulnerabilities, and high costs. It benefits you by making network management easier, improving application performance, enhancing security, and reducing costs. Overall, it simplifies operations and ensures your network runs smoothly and securely.
From 5 years of using PA
What do you like best about the product?
Ease of Use
Palo Alto SD-WAN excels in its intuitive interface, which simplifies policy management and traffic prioritization. Leveraging my experience with CheckPoint and Stormshield NGFW platforms, I found Palo Alto’s centralized dashboard particularly streamlined for configuring QoS policies and monitoring application performance. The visual topology mapping reduces complexity in troubleshooting, aligning with my work in global WAN environments (MPLS, IPSEC, SSLVPN).
Palo Alto SD-WAN excels in its intuitive interface, which simplifies policy management and traffic prioritization. Leveraging my experience with CheckPoint and Stormshield NGFW platforms, I found Palo Alto’s centralized dashboard particularly streamlined for configuring QoS policies and monitoring application performance. The visual topology mapping reduces complexity in troubleshooting, aligning with my work in global WAN environments (MPLS, IPSEC, SSLVPN).
What do you dislike about the product?
Cost and Licensing Overhead
The platform’s premium pricing model and feature-tiered licensing (e.g., advanced security modules, cloud integrations) may strain budgets for small-to-medium enterprises. This contrasts with open-source or cost-flexible solutions like pfSense or Fortinet, which you’ve likely encountered in past roles at smaller firms.
The platform’s premium pricing model and feature-tiered licensing (e.g., advanced security modules, cloud integrations) may strain budgets for small-to-medium enterprises. This contrasts with open-source or cost-flexible solutions like pfSense or Fortinet, which you’ve likely encountered in past roles at smaller firms.
What problems is the product solving and how is that benefiting you?
Deploying Prisma SD‑WAN at the Hungarian State Treasury has given me a single, cohesive platform to manage thousands of encrypted tunnels, enforce uniform security postures, and deliver predictable performance to all branches—without the typical silos, manual overhead, or visibility gaps of legacy WAN architectures.
Very helpful for daily tasks
What do you like best about the product?
Clear dashboard . It gives strong insights into network activity, which really helps with troubleshooting. Details like threat detection and URL filtering are good, and WildFire adds an additional layer of safety through catching threats before.
What do you dislike about the product?
Everything is fine for now.
There is nothing I dislike.
The price is ok, no high prices and comparing to other tools, I find it the best. Very easy to use.
There is nothing I dislike.
The price is ok, no high prices and comparing to other tools, I find it the best. Very easy to use.
What problems is the product solving and how is that benefiting you?
Protect the network with the cloud network security.
Allows us to stop the latest and most sophisticated web-based threats.
We benefit from deep visibility and command of all applications with controls and contextual policies to protect our sensitive data.
Allows us to stop the latest and most sophisticated web-based threats.
We benefit from deep visibility and command of all applications with controls and contextual policies to protect our sensitive data.
SD-WAN makes life easier
What do you like best about the product?
What I really like is how much simpler it makes network management, especially across multiple sites. The interface is clean and easy to work with, and being able to monitor traffic and performance in real-time has been a huge plus. It handles routing decisions smartly based on app performance, which saves a lot of time and troubleshooting.
What do you dislike about the product?
We also ran into a few hiccups integrating it with some of our older systems. Another small gripe is that some features you might expect to be included require extra licensing, which adds up. Support has been okay, but there were a few times we had to wait longer than we’d like for responses.
What problems is the product solving and how is that benefiting you?
One of the main things Prisma SD-WAN helped us with was simplifying how we connect all our branch locations. Before, managing that was a bit of a mess and took a lot of time. Now we can see everything in one place and don’t have to rely on MPLS like we used to.
efficient
What do you like best about the product?
it's super nice to have auto routing within an SD-wan solution and it integrates so well with cloud environments within an organization, centralizing the essentials on a secure, monitored and well thought out protection on the wan area that a network engineer would like to stablish.
What do you dislike about the product?
the only issue I encountered it's that everything it's so centralized, that in order to get the most out of the tool, you will need a loot of time digging into the different options that the platform has, some things could more segmented.
What problems is the product solving and how is that benefiting you?
Load balance for certain services that are not suppose to demand such extreme bandwidth and to have dedicated bandwidth to certain services such as video and calls, it's nice to have that measured.
Is not friendly user for new users
What do you like best about the product?
One of the best aspects of Prisma SD-WAN is its intelligent, application-aware traffic steering. Unlike traditional SD-WAN solutions that rely solely on static policies, Prisma SD-WAN uses machine learning and AI-driven insights to dynamically optimize traffic based on real-time network conditions. This results in better application performance, reduced latency, and improved user experience, especially for cloud and SaaS applications.
Additionally, its tight integration with Prisma Access provides end-to-end security with zero trust principles, ensuring that remote users and branch offices are securely connected without adding complexity to network management. The centralized management and automation capabilities also help streamline deployments and reduce operational overhead.
Additionally, its tight integration with Prisma Access provides end-to-end security with zero trust principles, ensuring that remote users and branch offices are securely connected without adding complexity to network management. The centralized management and automation capabilities also help streamline deployments and reduce operational overhead.
What do you dislike about the product?
One potential drawback of Prisma SD-WAN is its learning curve and initial complexity. While the AI-driven automation and centralized management are powerful, they can be overwhelming for teams unfamiliar with Palo Alto Networks' ecosystem. Organizations migrating from traditional SD-WAN solutions may require additional training and adaptation time to fully leverage its capabilities.
Another concern is licensing and cost, as Prisma SD-WAN can be more expensive than some competitors, especially for smaller businesses. The tight integration with Prisma Access is a strength, but it also means that organizations heavily invested in other security solutions might face compatibility or redundancy challenges.
Another concern is licensing and cost, as Prisma SD-WAN can be more expensive than some competitors, especially for smaller businesses. The tight integration with Prisma Access is a strength, but it also means that organizations heavily invested in other security solutions might face compatibility or redundancy challenges.
What problems is the product solving and how is that benefiting you?
Security Gaps in Remote Branches → Integrated Zero Trust Security Tight integration with Prisma Access ensures secure, policy-driven connectivity for branch offices without requiring additional firewalls.
Efficient, Secure, and Scalable SD-WAN Solution
What do you like best about the product?
Prisma SD-WAN simplifies network management through automation and AI-driven analytics. The centralized cloud-based orchestration allows seamless deployment and monitoring of branch offices, reducing operational overhead. The built-in security features, such as next-gen firewall integration, improve overall protection against cyber threats. Additionally, the application-aware routing optimizes network performance, ensuring a smooth user experience.
What do you dislike about the product?
While Prisma SD-WAN is a powerful solution, the initial setup can be complex, especially for organizations without prior SD-WAN experience. The pricing may also be a concern for small businesses, as it leans toward the higher end compared to some competitors. Additionally, occasional software updates can introduce minor compatibility issues, requiring quick fixes from support.
What problems is the product solving and how is that benefiting you?
Prisma SD-WAN simplifies network management with AI-driven automation, enhances security with built-in Palo Alto protections, and optimizes traffic for better performance. It reduces reliance on costly MPLS, lowers IT overhead, and provides real-time visibility for quick troubleshooting. This has improved our network’s efficiency, security, and scalability while reducing costs.
Prisma SD-WAN recommendation
What do you like best about the product?
I enjoy how Prisma SD-WAN offers a great amount of connectivity and also ensures that the connectivity is safe and secure to use. I feel at ease knowing all devices are using this.
What do you dislike about the product?
One thing I dislike about Prisma SD-WAN is that it feels much more complicated to initially set up compared to other many alternatives I have used in the past.
What problems is the product solving and how is that benefiting you?
Prisma SD-WAN has helped with making all work functions over my network much simpler than it was working before. I appreciate how the ADEM leads to a much easier user experience for me.
showing 11 - 20