What is still missing or needs to be improved in PA Next Generation Firewalls ?

Showing results for 
Show  only  | Search instead for 
Did you mean: 

What is still missing or needs to be improved in PA Next Generation Firewalls ?

L1 Bithead

Hi, will like to understand the oppinion from the PAN community about the features that are still missing or needs to be improved.

Will appreciate if you can specify by functionality like :


Must Have : A,B,C

Nice to Have : D,E,F




Not applicable

Nice to Have : cisco integration with Filtering Service on Palo Alto, like websense or SurfControl

L4 Transporter

Nice to have: Applipedia should include the information if a specific application requires an exclusion for SSL decryption in order to work. E.g. dropbox

L4 Transporter

Ability to define and fold up groups of security rules.  The tags are very cool but a way to fold up groups of rules to a single line would be nice.

Longer captive portal, ability to put in length of captive portal based on user/group and/or timeout and/or native client etc.  Bottom line is BYOD is here.

Free copy of Panorama for small rollouts.  Why?  Word of mouth for larger installations, ability to gain experience with Panorama.

Real world examples of implementation, rules etc.  It is a different way of thinking and honestly is difficult to get a grip on it for complex situations.

Graphical interface for schedules.


L2 Linker

What i really would like to see in PA device is usable DLP. A few days ago i powered up old fortigate device and damn their DLP is quite nice to work with. They even had a chance to search for keywords in mail subject or body.

The ability to import user and group information periodically, and the ability to use those imported objects to create groups on the box. Our management does not like the fact that I need to rely on our IT group for firewall ACL's. Nor do they want to create another process in which we have to monitor more group memberships/changes to AD.

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!