


So far, I’ve enabled decryption for a few devices on my lab network. Palo Alto does have a few subscription features, but it includes quite a bit of functionality in the base price. So, if you get the smallest firewall for your lab, you’ll be able to see how the high-end units will operate (the higher-end units are much faster at committing config changes, of course). With Palo Alto, the highest end firewall has the same user interface as the low end. Then you have to worry about what blades to get. One thing that is a little difficult to get used to with the PA series is that they are all the same! I’m used to having CheckPoints for small business, and for Enterprise having completely different feature sets. Don’t get me wrong, there are tradeoffs with a Web interface, but I really do like the fact that there is no need to load a client to manage it.

This is nice, as I once connected via my iPhone and was able to make a firewall change, though I don’t recommend doing that often! But you absolutely can’t do that on the large CheckPoint firewalls. Everything from configuration to looking at logs, it’s all right there. To manage a PA firewall? It’s all in the WebGUI. With the large CheckPoint firewalls, we manage them using Smart Dashboard. This lets you group interfaces together, put them in the same zone, and traffic between those interfaces is routed without any firewall in the path. First, the concept of Zones is something that Palo Alto embraces. Coming from a CheckPoint background, I had plenty of experience with firewalls, but the way things are done is just different in the Palo Alto world. The Palo Alto is not without a learning curve. I’ve got a good bit of experience with CheckPoint, so I was eager to see what this competitor brought to the party. According to the Gartner report, Palo Alto and CheckPoint are locked in an epic battle for #1 in the enterprise firewall space. If you don’t know, it’s the lowest-end model firewall from Palo Alto Networks. I was very happy to get a lab licensed PA-200 in the mail early this week.
