Skip to content
Migrated from Check...
 
Notifications
Clear all

Migrated from Check Point to Palo Alto for cloud security - 4 month report

2 Posts
2 Users
0 Reactions
3 Views
(@danielh)
Reputable Member
Joined: 3 months ago
Posts: 323
Topic starter   [#29551]

Hey folks! Wanted to share our team's experience after swapping out our cloud firewall provider. We were long-time Check Point users for on-prem and tried to extend that love to our AWS/Azure footprint, but honestly, the cloud-native experience felt... bolted on. We made the jump to Palo Alto's Prisma Cloud (specifically the Cloud NGFW for Kubernetes and VM-Series) about four months ago. The tl;dr? It's been a game-changer for our GitOps flows, but not without some learning curves.

**The Good Stuff:**
* **IaC Integration:** This was the biggest win. Their Terraform provider is robust. We can now define and version our entire security posture alongside our infra. No more manual console config drifts!
```hcl
resource "prismacloudcompute_policies" "container_audit" {
learning_disabled = true
rule {
name = "block-suspicious-exec"
processes {
effect = "alert"
blacklist = ["sh", "python"]
}
}
}
```
* **K8s Native Feel:** The Cloud NGFW deploys as a DaemonSet. Security policies follow the workload, which is perfect for our dynamic namespaces. Visibility into East-West traffic is finally clear.
* **Unified Policy:** Managing network, workload, and host security from a single pane (even across clouds) has cut our "context switching" time in half.

**The "Oh, Right..." Moments:**
* **Cost Model:** Be prepared for sticker shock. It's powerful, but you pay for it. We had to be much more deliberate with our rule granularity.
* **Learning Curve:** The policy constructs are different. "Security Profiles" and "App-IDs" are powerful but require a mindset shift from port/protocol thinking.
* **API Early Days:** Some of the newer Prisma Cloud APIs for CWPP feel a bit raw compared to the mature Panorama ones. We hit a few weird gaps when automating compliance checks.

**Bottom Line:** If you're all-in on cloud native and need deep, integrated security that works with your CI/CD pipeline, Palo Alto feels like the right fit. If you're mostly managing static environments or are extremely cost-sensitive, the move might be harder to justify.

Would love to hear from others who've made a similar switch or are evaluating these tools. Any tips for optimizing those policy sets? 😅

Keep deploying!


Keep deploying!


   
Quote
(@charliep)
Prominent Member
Joined: 3 months ago
Posts: 803
 

I run security for a series of e-commerce platforms, around 400 employees. We've had Palo Alto NGFWs on-prem for years and evaluated both for a major Azure migration last year. We run Prisma Cloud Compute (the container/VM part) now.

**Real price tag:** Check Point's cloud licensing was opaque. Palo's is worse. Expect to negotiate hard, and know the list price is a fantasy. The VM-Series alone can be $4-5k per instance per year before support. Prisma Cloud Compute is another $50k+ annual commitment for a medium footprint. The "unified" console is a license to upsell.
**Deployment reality:** That "robust" Terraform provider for Prisma? It's for their *own* SaaS config, not your firewall rules. You still need separate automation (Ansible, Terraform) for the VM-Series boxes. It's two automation stacks, not one.
**Where it clearly wins:** The dynamic address group feature, linking security policy to Azure/GCP tags, is legit. If your cloud tagging is immaculate, you can enforce policy on new VMs instantly. Check Point's cloud object sync felt like a nightly batch job.
**Where it breaks:** The "K8s native" Cloud NGFW DaemonSet has a hefty footprint per node. In my last shop, it added about 500MB RAM and 0.5 vCPU overhead. For dense nodes, fine. For smaller dev clusters, it ate our budget. Also, their admission control webhook will fail open if it can't reach the management plane, which is a design choice you need to test.

I'd pick Palo if you're already in their ecosystem and have the team to manage the two-tier automation. If you're a Check Point shop that just needs basic cloud segmentation, tell us your team size and whether you have dedicated firewall engineers.


Your stack is too complicated.


   
ReplyQuote