Dyang, my recommendation is that Palo Alto work with top DLP vendors to figure out some sort of DLP solution, doesn't have to be ICAP. The Palo Alto strategy is not realistic for most customers and I've seen PA lose a number of engagements to customers who want a real DLP strategy. The fact that Palo Alto doesn't integrate with anyone out of the box is an issue. I haven't run into a customer yet that wants to create custom connectors with the API. If you put anything in Gartner, which I don't, at least Checkpoint has a more robust DLP strategy. That's just my 2 cents. We work with a ton of customers and a lot of PA customers and this (and global protect) are my only two complaints against the platform.
... View more