<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Palo Alto Networks NGFW VS Open Source Firewall in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-networks-ngfw-vs-open-source-firewall/m-p/552951#M112471</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/150709"&gt;@JASONWONG&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;It's honestly not very often that you see someone make a comparison to an open-source free product versus a PAN firewall, the capability differences between the two are just going to be rather significant. Usually it's that someone wants to compare Firepower, Sonicwall, Fortinet, and stuff like that to PAN.&lt;/P&gt;
&lt;P&gt;Bluntly if a customer I was pitching PAN equipment towards honestly wanted me to compare it to something like pfSense, either it's going to be a very quick overview of differences or I'm going to need to start looking at other enterprise solutions. If a proposed solution is "free" (with the heavy caveat that time to implement and update will increase) versus a product that will have high yearly costs, you really have to know the people that are asking for the comparison and how you need to target the solution.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Broadly, you could point towards the following basic quick items. Substitute pfSense with any other open-source solution, because they all have the same issue:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Turnkey Solution - pfSense needs a whole lot of add-ons and configuration to function anywhere near what PAN has to offer. That increases complexity and time to get everything configured and vetted, and even when that's done the capability of DansGuardian and ClamAV simply don't match what PAN is offering. (Again, know your audience, good enough at the cost of free&amp;nbsp;&lt;EM&gt;can&amp;nbsp;&lt;/EM&gt;have a lot of appeal in SMB).&lt;/LI&gt;
&lt;LI&gt;Central Management - pfSense doesn't have central management capabilities like PAN does. You could setup PFMonitor, but that's not a pretty elegant solution and it's going to add a monthly cost to something that is "free".&amp;nbsp; If you don't care about that or are good at scripting, you can get around some of that limitation.&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;Culpability - If you deploy pfSense and there's an issue with it or an add-on, that culpability is on you. It's your chicken to catch and return to the pen; you won't really have that "PAN pushed a bad update, I'm waiting on them to fix it". If you don't know how to fix it or where the issue even is, that's a bad day and you don't have that many options to turned towards. "I'm trying to figure out the issue, but I don't know what's wrong and pfSense doesn't think it's an issue with their software" doesn't sound as good as "I've engaged vendor support and we're working through the issue".&lt;/LI&gt;
&lt;LI&gt;Add-Ons - I've said it a lot here, but something like pfSense depends on using add-ons to make it an okay security product. That's a double-edged sword when it comes to an administration aspect; you can add more capability to the product, but you also introduce more complexity. What happens when you have an issue with DansGuardian or ClamAV and their add-on, who do you call? What happens if something you've configured in pfBlockerNG causes an issue with pfSense and you can't figure it out? What happens when one of the add-ons that you're using isn't being supported anymore?&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'll also say this, there's a lot of SMBs where I've advised a properly managed pfSense installation over a Fortinet or PAN installation.&amp;nbsp; When you get into that 10-15 people SMB or someone who isn't willing to actually renew subscriptions a properly managed pfSense installation&amp;nbsp;&lt;EM&gt;can&amp;nbsp;&lt;/EM&gt;be a really good way forward. I'd rather someone pay for a managed pfSense installation than pay for a single year of PAN licenses and never renew the subscriptions or have the money for someone to actually manage things.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 08 Aug 2023 14:16:54 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2023-08-08T14:16:54Z</dc:date>
    <item>
      <title>Palo Alto Networks NGFW VS Open Source Firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-networks-ngfw-vs-open-source-firewall/m-p/552376#M112396</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kindly how do we justify the benefit of Palo Alto Networks NGFW vs Open Source Firewall.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there any whitepaper or battle-card?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Aug 2023 09:18:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-networks-ngfw-vs-open-source-firewall/m-p/552376#M112396</guid>
      <dc:creator>JASONWONG</dc:creator>
      <dc:date>2023-08-03T09:18:12Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Networks NGFW VS Open Source Firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-networks-ngfw-vs-open-source-firewall/m-p/552739#M112434</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/150709"&gt;@JASONWONG&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Which Open Source Firewall is in question?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Aug 2023 08:27:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-networks-ngfw-vs-open-source-firewall/m-p/552739#M112434</guid>
      <dc:creator>JayGolf</dc:creator>
      <dc:date>2023-08-07T08:27:06Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Networks NGFW VS Open Source Firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-networks-ngfw-vs-open-source-firewall/m-p/552951#M112471</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/150709"&gt;@JASONWONG&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;It's honestly not very often that you see someone make a comparison to an open-source free product versus a PAN firewall, the capability differences between the two are just going to be rather significant. Usually it's that someone wants to compare Firepower, Sonicwall, Fortinet, and stuff like that to PAN.&lt;/P&gt;
&lt;P&gt;Bluntly if a customer I was pitching PAN equipment towards honestly wanted me to compare it to something like pfSense, either it's going to be a very quick overview of differences or I'm going to need to start looking at other enterprise solutions. If a proposed solution is "free" (with the heavy caveat that time to implement and update will increase) versus a product that will have high yearly costs, you really have to know the people that are asking for the comparison and how you need to target the solution.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Broadly, you could point towards the following basic quick items. Substitute pfSense with any other open-source solution, because they all have the same issue:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Turnkey Solution - pfSense needs a whole lot of add-ons and configuration to function anywhere near what PAN has to offer. That increases complexity and time to get everything configured and vetted, and even when that's done the capability of DansGuardian and ClamAV simply don't match what PAN is offering. (Again, know your audience, good enough at the cost of free&amp;nbsp;&lt;EM&gt;can&amp;nbsp;&lt;/EM&gt;have a lot of appeal in SMB).&lt;/LI&gt;
&lt;LI&gt;Central Management - pfSense doesn't have central management capabilities like PAN does. You could setup PFMonitor, but that's not a pretty elegant solution and it's going to add a monthly cost to something that is "free".&amp;nbsp; If you don't care about that or are good at scripting, you can get around some of that limitation.&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;Culpability - If you deploy pfSense and there's an issue with it or an add-on, that culpability is on you. It's your chicken to catch and return to the pen; you won't really have that "PAN pushed a bad update, I'm waiting on them to fix it". If you don't know how to fix it or where the issue even is, that's a bad day and you don't have that many options to turned towards. "I'm trying to figure out the issue, but I don't know what's wrong and pfSense doesn't think it's an issue with their software" doesn't sound as good as "I've engaged vendor support and we're working through the issue".&lt;/LI&gt;
&lt;LI&gt;Add-Ons - I've said it a lot here, but something like pfSense depends on using add-ons to make it an okay security product. That's a double-edged sword when it comes to an administration aspect; you can add more capability to the product, but you also introduce more complexity. What happens when you have an issue with DansGuardian or ClamAV and their add-on, who do you call? What happens if something you've configured in pfBlockerNG causes an issue with pfSense and you can't figure it out? What happens when one of the add-ons that you're using isn't being supported anymore?&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'll also say this, there's a lot of SMBs where I've advised a properly managed pfSense installation over a Fortinet or PAN installation.&amp;nbsp; When you get into that 10-15 people SMB or someone who isn't willing to actually renew subscriptions a properly managed pfSense installation&amp;nbsp;&lt;EM&gt;can&amp;nbsp;&lt;/EM&gt;be a really good way forward. I'd rather someone pay for a managed pfSense installation than pay for a single year of PAN licenses and never renew the subscriptions or have the money for someone to actually manage things.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Aug 2023 14:16:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-networks-ngfw-vs-open-source-firewall/m-p/552951#M112471</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2023-08-08T14:16:54Z</dc:date>
    </item>
  </channel>
</rss>

