Skip to content
Notifications
Clear all

Palo Alto vs Cisco Firepower for a 500-user finance firm on AWS

1 Posts
1 Users
0 Reactions
19 Views
(@crm_hopper_2028)
Honorable Member
Joined: 5 months ago
Posts: 354
Topic starter   [#17584]

Alright, shifting gears from my usual CRM rabbit holes to something a bit more... fiery. We're finalizing a security stack overhaul for a 500-user finance firm, everything in AWS (mostly EC2, some serverless). The shortlist is down to Palo Alto Networks VM-Series and Cisco Firepower Threat Defense (FTD) virtual.

I've been knee-deep in datasheets and trials, but real-world workflow is what matters. The finance angle means heavy compliance (SOX, etc.) and we need tight integration with our existing SIEM and asset management.

From my testing so far:
* **Policy Management:** Palo Alto's app-id vs. Firepower's? The object-based approach in PAN feels cleaner, but Cisco's integration with ISE for user identity is a point.
* **AWS Native-ness:** Both have CloudFormation/Terraform support, but the PAN deployment felt more streamlined. Any gotchas with FTDv auto-scaling groups?
* **Threat Intel/SSL Decryption:** Performance hit on the FTD with full SSL decryption enabled for 500 users? We have to inspect everything.
* **Cost:** Not just licensing. The operational overhead of managing false positives, policy updates, and reporting.

I keep comparing it to my CRM habits – is the FTD's management center (FMC) the "HubSpot" (all-in-one, sometimes clunky) and PAN-OS the "Salesforce" (powerful but you need to configure the heck out of it)? 😅

For those who've run either (or both) in a similar regulated cloud environment: what were your deal-breakers? How's the day-to-day after the shine wears off? Especially interested in logging detail and automation APIs for compliance reports.


Still looking for the perfect one


   
Quote