Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login
    Introducing Netgate Nexus: Multi-Instance Management at Your Fingertips.

    New tech guy wants to switch from Pfsense to Palo Alto

    Scheduled Pinned Locked Moved General pfSense Questions
    13 Posts 9 Posters 2.7k Views 10 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • D Offline
      dgall
      last edited by dgall

      This post is deleted!
      chpalmerC NC1N AndyRHA 3 Replies Last reply Reply Quote 0
      • chpalmerC Offline
        chpalmer @dgall
        last edited by chpalmer

        @dgall Never let the chickens run the hen house. Ive introduced a few people to pfsense over the last 15+ years and they are glad I did.

        My guess is that if you contacted Netgate sales they could provide you with something close to what you desire to help you compare.

        Ive run pfsense at multiple customer locations for many years but they are all simple installs. Only had one customer running a domain and only had my primary here in front of our company web and email servers. Nothing too fancy.

        If you asked how certain feature you use now compare you might find many with input.

        Introduce your tech to this.. https://www.netgate.com/training/pfsense-fundamentals-and-advanced-application?hss_channel=tw-435119060

        Triggering snowflakes one by one..
        Primary- Intel(R) Pentium(R) CPU G4400 @ 3.30GHz on an M470 WG box. pfSense CE 2.8.1
        Lab Unit- Intel(R) Core(TM) i5-4590T CPU @ 2.00GHz on an M400 WG box. pfSense+

        1 Reply Last reply Reply Quote 0
        • M Offline
          Mission-Ghost
          last edited by Mission-Ghost

          Search for the CVE's on the Palo Altos and see if they're as troublesome as some of the other commercial firewalls.

          Some have been caught out using hard-coded passwords, buffer overflow errors, null pointer exceptions, etc. Commercial <> better.

          Even so, the 25.11 "upgrade" experiences here have shaken my confidence in Netgate's software QA. I know it's not a proper statistical sampling, but there's a lot going on with this version that's troubling. I'm waiting.

          I guess it could be worse. It's not Windows 11.

          1 Reply Last reply Reply Quote 0
          • tinfoilmattT Offline
            tinfoilmatt LAYER 8
            last edited by

            Fire him.

            Three possibilities: 1.) doesn't know what he's talking about; 2.) hype follower; 3.) very much relies upon commerical support hand-holding. These are not mutually exclusive, either.

            johnpozJ 1 Reply Last reply Reply Quote 1
            • johnpozJ Offline
              johnpoz LAYER 8 Global Moderator @tinfoilmatt
              last edited by

              @tinfoilmatt hahah - not sure if serious, but he makes a few good points. Maybe he is also wanting to use this as learning ground. Yeah I used Palo's at my last gig sort of thing for his next gig as he uses this as spring board.

              My previous gig, the team I was on managed the 50+ some palos across the enterprise - with panorama of course with that many firewalls. My current gig we use palos as well, but the cyber team manages them.

              They are not immune to issues - and they sure and the hell are not cheap that is for sure!! A small business just bringing on 1 tech guy, not sure how you would justify the cost increase. Tell him you split the cost with him, taking 50% of the cost of the palos out of his salary ;) heheh

              Not sure why you want to open the huge can of worms with ssl interception for - what exactly are you doing that would be justified?

              I would have him put together a summary of how the switch is going to make the company that much safer and easier to manage, and what is the ROI for making the switch. There for sure will be a cost difference - how does the switch save the company in the long run, be it more secure environment, faster and easier changes to the firewall rule base.. What is the business need to make the switch, which sure isn't going to be free in cost of running them, and for the switch over.

              What exactly are you wanting to do that your current 7100 can't do or handle - or is it he just doesn't know how to do it?

              An intelligent man is sometimes forced to be drunk to spend time with his fools
              If you get confused: Listen to the Music Play
              Please don't Chat/PM me for help, unless mod related
              SG-4860 26.03.1 | Lab VMs 2.8.1, 26.07

              D 1 Reply Last reply Reply Quote 0
              • NC1N Offline
                NC1 @dgall
                last edited by

                @dgall said in New tech guy wants to switch from Pfsense to Palo Alto:

                he wants to switch to a Palo Alto firewall

                Oh, does he now?

                • Is he willing to pay for it? :)
                • Has he run it by Palo Alto yet? :)

                Seriously though, Palo Alto is both expensive and picky. You have to convince them to take you on as a customer. That entails meeting their expectations on two separate issues, (1) contract size, and (2) size and quality of your in-house IT workforce.

                1 Reply Last reply Reply Quote 0
                • D Offline
                  dgall @johnpoz
                  last edited by

                  @johnpoz I am still studying this some of the things he mentions on anti virus and malware protection I have a good paid anti-virus on all the computers and with pfsense I use the paid version of snort and I use pfblocker with some really good feeds that are updated regularly with an old computer not hooked up to the network I went bunch of websites that list malware sites, threats and bad ip addresses between pfsense and my antivirus everything was blocked a 100% but then again its the threats in the wild that get you.

                  Bottom line I hired a tech guy I cant micro manage him and he knows Palo Alto I have still have many pros and cons to look at if nothing else if I do let him go with Palo Alto I get a really nice Netgate 7100 for my home lab.

                  SteveITSS 1 Reply Last reply Reply Quote 0
                  • SteveITSS Offline
                    SteveITS Rebel Alliance @dgall
                    last edited by

                    @dgall Some a/v have SSL scanning built in via a certificate that gets installed on the PC. That also moves decryption to the endpoint not the router. On a router I imagine that’s much more manual, and certs will only be valid for 47 days by the time we get to 2029.

                    To upgrade, select your branch in System/Update/Update Settings. When upgrading, allow 10-15 minutes to reboot, or more depending on packages, CPU, and/or disk speed.
                    Only install packages for your version of pfSense.
                    Upvote 👍 helpful posts!

                    GertjanG 1 Reply Last reply Reply Quote 0
                    • GertjanG Offline
                      Gertjan @SteveITS
                      last edited by Gertjan

                      @SteveITS said in New tech guy wants to switch from Pfsense to Palo Alto:

                      be valid for 47 days by the time we get to 2029

                      Doesn't that mean : constantly 'micro manage' every local network device ?

                      @dgall said in New tech guy wants to switch from Pfsense to Palo Alto:

                      antivirus everything was blocked a 100%

                      It blocks known viruses. Not the latest and greatest, who are all unknown when created 😊

                      No "help me" PM's please. Use the forum, the community will thank you.

                      johnpozJ 1 Reply Last reply Reply Quote 0
                      • johnpozJ Offline
                        johnpoz LAYER 8 Global Moderator @Gertjan
                        last edited by johnpoz

                        @Gertjan it is not going to be 47 days for a local ca, that would be just stupid and insane.

                        What I can find about safari is 825 days or something limit, and again that makes no sense for a local ca. My current safari on ios 26.2 has no issues with a local ca and certs that are valid for 10 years.

                        What it does on macOS not sure, since I don't have anything that runs that.

                        An intelligent man is sometimes forced to be drunk to spend time with his fools
                        If you get confused: Listen to the Music Play
                        Please don't Chat/PM me for help, unless mod related
                        SG-4860 26.03.1 | Lab VMs 2.8.1, 26.07

                        SteveITSS 1 Reply Last reply Reply Quote 0
                        • AndyRHA Offline
                          AndyRH @dgall
                          last edited by

                          @dgall said in New tech guy wants to switch from Pfsense to Palo Alto:

                          he wants to switch to a Palo Alto firewall

                          When I hire someone they are fully aware we run Red Hat. We are not going to change. Did you talk about pfSense in the interview?
                          Changing firewalls in non-trivial and should be treated as a major change, by the time your new guy has enough information to convert to Palo Alto firewalls he will be at least very familiar with pfSense.

                          o|||||||o
                          8200

                          1 Reply Last reply Reply Quote 2
                          • SteveITSS Offline
                            SteveITS Rebel Alliance @johnpoz
                            last edited by

                            @johnpoz Correct on the CA cert. My point was supposed to be the problem getting that on all devices on the network, such as phones, if all traffic was going to be intercepted. On our a/v the actual cert is created on the fly.

                            To upgrade, select your branch in System/Update/Update Settings. When upgrading, allow 10-15 minutes to reboot, or more depending on packages, CPU, and/or disk speed.
                            Only install packages for your version of pfSense.
                            Upvote 👍 helpful posts!

                            johnpozJ 1 Reply Last reply Reply Quote 0
                            • johnpozJ Offline
                              johnpoz LAYER 8 Global Moderator @SteveITS
                              last edited by johnpoz

                              @SteveITS Oh maybe confusing threads about 47 days time limit.. Yeah never in a million years would open up ssl inspection.. Even at an enterprise - not doing it here current gig 4k some employees, 60 sites world wide, last gig I was at on the firewall team. Fortune 100 company - guess what not doing it there either.. ;)

                              SSL interception and doing mitm on users connections - say to their bank or their doctor office - huge issue with privacy, etc.. That is such a can of worms, wouldn't touch it..

                              That some small company with 1 tech guy would open up mitm ssl inspection seems insane..

                              An intelligent man is sometimes forced to be drunk to spend time with his fools
                              If you get confused: Listen to the Music Play
                              Please don't Chat/PM me for help, unless mod related
                              SG-4860 26.03.1 | Lab VMs 2.8.1, 26.07

                              1 Reply Last reply Reply Quote 3
                              • First post
                                Last post
                              Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.
                              Privacy Policy · Cookie Policy