New tech guy wants to switch from Pfsense to Palo Alto
-
This post is deleted! -
@dgall Never let the chickens run the hen house. Ive introduced a few people to pfsense over the last 15+ years and they are glad I did.
My guess is that if you contacted Netgate sales they could provide you with something close to what you desire to help you compare.
Ive run pfsense at multiple customer locations for many years but they are all simple installs. Only had one customer running a domain and only had my primary here in front of our company web and email servers. Nothing too fancy.
If you asked how certain feature you use now compare you might find many with input.
Introduce your tech to this.. https://www.netgate.com/training/pfsense-fundamentals-and-advanced-application?hss_channel=tw-435119060
-
Search for the CVE's on the Palo Altos and see if they're as troublesome as some of the other commercial firewalls.
Some have been caught out using hard-coded passwords, buffer overflow errors, null pointer exceptions, etc. Commercial <> better.
Even so, the 25.11 "upgrade" experiences here have shaken my confidence in Netgate's software QA. I know it's not a proper statistical sampling, but there's a lot going on with this version that's troubling. I'm waiting.
I guess it could be worse. It's not Windows 11.
-
Fire him.
Three possibilities: 1.) doesn't know what he's talking about; 2.) hype follower; 3.) very much relies upon commerical support hand-holding. These are not mutually exclusive, either.
-
@tinfoilmatt hahah - not sure if serious, but he makes a few good points. Maybe he is also wanting to use this as learning ground. Yeah I used Palo's at my last gig sort of thing for his next gig as he uses this as spring board.
My previous gig, the team I was on managed the 50+ some palos across the enterprise - with panorama of course with that many firewalls. My current gig we use palos as well, but the cyber team manages them.
They are not immune to issues - and they sure and the hell are not cheap that is for sure!! A small business just bringing on 1 tech guy, not sure how you would justify the cost increase. Tell him you split the cost with him, taking 50% of the cost of the palos out of his salary ;) heheh
Not sure why you want to open the huge can of worms with ssl interception for - what exactly are you doing that would be justified?
I would have him put together a summary of how the switch is going to make the company that much safer and easier to manage, and what is the ROI for making the switch. There for sure will be a cost difference - how does the switch save the company in the long run, be it more secure environment, faster and easier changes to the firewall rule base.. What is the business need to make the switch, which sure isn't going to be free in cost of running them, and for the switch over.
What exactly are you wanting to do that your current 7100 can't do or handle - or is it he just doesn't know how to do it?
-
@dgall said in New tech guy wants to switch from Pfsense to Palo Alto:
he wants to switch to a Palo Alto firewall
Oh, does he now?
- Is he willing to pay for it?
:) - Has he run it by Palo Alto yet?
:)
Seriously though, Palo Alto is both expensive and picky. You have to convince them to take you on as a customer. That entails meeting their expectations on two separate issues, (1) contract size, and (2) size and quality of your in-house IT workforce.
- Is he willing to pay for it?
-
@johnpoz I am still studying this some of the things he mentions on anti virus and malware protection I have a good paid anti-virus on all the computers and with pfsense I use the paid version of snort and I use pfblocker with some really good feeds that are updated regularly with an old computer not hooked up to the network I went bunch of websites that list malware sites, threats and bad ip addresses between pfsense and my antivirus everything was blocked a 100% but then again its the threats in the wild that get you.
Bottom line I hired a tech guy I cant micro manage him and he knows Palo Alto I have still have many pros and cons to look at if nothing else if I do let him go with Palo Alto I get a really nice Netgate 7100 for my home lab.
-
@dgall Some a/v have SSL scanning built in via a certificate that gets installed on the PC. That also moves decryption to the endpoint not the router. On a router I imagine that’s much more manual, and certs will only be valid for 47 days by the time we get to 2029.
-
@SteveITS said in New tech guy wants to switch from Pfsense to Palo Alto:
be valid for 47 days by the time we get to 2029
Doesn't that mean : constantly 'micro manage' every local network device ?
@dgall said in New tech guy wants to switch from Pfsense to Palo Alto:
antivirus everything was blocked a 100%
It blocks known viruses. Not the latest and greatest, who are all unknown when created

-
@Gertjan it is not going to be 47 days for a local ca, that would be just stupid and insane.
What I can find about safari is 825 days or something limit, and again that makes no sense for a local ca. My current safari on ios 26.2 has no issues with a local ca and certs that are valid for 10 years.
What it does on macOS not sure, since I don't have anything that runs that.
-
@dgall said in New tech guy wants to switch from Pfsense to Palo Alto:
he wants to switch to a Palo Alto firewall
When I hire someone they are fully aware we run Red Hat. We are not going to change. Did you talk about pfSense in the interview?
Changing firewalls in non-trivial and should be treated as a major change, by the time your new guy has enough information to convert to Palo Alto firewalls he will be at least very familiar with pfSense. -
@johnpoz Correct on the CA cert. My point was supposed to be the problem getting that on all devices on the network, such as phones, if all traffic was going to be intercepted. On our a/v the actual cert is created on the fly.
-
@SteveITS Oh maybe confusing threads about 47 days time limit.. Yeah never in a million years would open up ssl inspection.. Even at an enterprise - not doing it here current gig 4k some employees, 60 sites world wide, last gig I was at on the firewall team. Fortune 100 company - guess what not doing it there either.. ;)
SSL interception and doing mitm on users connections - say to their bank or their doctor office - huge issue with privacy, etc.. That is such a can of worms, wouldn't touch it..
That some small company with 1 tech guy would open up mitm ssl inspection seems insane..
Privacy Policy · Cookie Policy