Community guidelines
Be specific and constructive. No vendor spam — promoting your own product belongs in a listing. Anyone can read; posting needs a free account.
We moved ten branches to Palo Alto Prisma Access. Connectivity is easier and remote users finally have the same policy, but licensing, log retention and traffic charges are harder to predict than the old firewalls. For teams a year or two into this, did the operating model get simpler or did the complexity just move to the vendor portal?
It moved. We removed boxes and three VPN designs, which was good. Then we gained identity mapping, connector placement, service edges and a support dependency for every weird routing case. I still prefer the new setup, but the business case was faster change and consistent policy, not lower cost
Log retention caught us too. The included window was useless for investigations, and the upgrade was not cheap. Ask for a full price with realistic traffic, private app connectors, sandboxing and two years of logs. The base license is not the number you will operate at.
That's exactly where we are. Network team likes it, finance thinks we bought a fixed price service, and security wants longer retention. I'm starting to think we need FinOps for network products now
Pretty much. Export usage and policy data monthly and assign an owner. Also test the escape hatch. If the provider has a major outage, can a branch reach anything useful directly? We found out our documented bypass depended on the same identity service that was down