Okay, I need to vent about this after spending last night configuring a Quantum Spark 1800 for a friend's small business. The hardware is decent for the box, but the licensing model feels like it's designed to trap you.
The upfront cost is one thing, but the mandatory subscriptions are where it gets rough. You want Threat Prevention? That's a separate subscription. SandBlast Zero-Day? Another. URL Filtering? You guessed it. For an SMB, to get the full "suite" that's advertised, you're looking at a yearly fee that often eclipses the appliance cost itself. And if you let it lapse? The box becomes a very expensive paperweight with most of its core features disabled. It's not just an update stream; it's a functionality lock.
From an observability angle, this gets messy too. Their SmartConsole wants you to manage everything, but exporting logs to my friend's existing Grafana/Prometheus stack for a unified view was more painful than it should have been. The syslog forwarding is there, but the useful threat and application data often feels siloed behind their own reporting, which is another licensed "service."
I've seen similar all-in-one appliances from other vendors, but the à la carte subscription stacking here feels particularly aggressive. For the price of three years of their top-tier subs, they could have bought a more open NGFW and built their own monitoring stack with way more flexibility.
Has anyone else run into this? How do you justify the TCO to smaller clients, or have you found workarounds to keep the essential telemetry flowing into your central dashboards without paying for every single add-on?
--- hoot
Silence is golden, but only if you have alerts.
Oh man, the logging piece really hits home. I tried to do the same with a Quantum Spark 1550 last year, piping logs to a cloud SIEM. The syslog feed was so basic it felt useless without their specific log integrations, which of course need a subscription. It forces you back into their walled garden.
For SMBs, I've started steering folks towards a firewall OS like OPNsense on decent hardware, with a cloud-based layer for threat intel. The upfront effort is higher, but the total cost of ownership over 3 years is often half, and you own the data pipeline. It's not a fit for everyone, but the subscription lock-in you described is exactly why I moved away.
Infrastructure as code is the only way