Skip to content
Notifications
Clear all

Switched from Cloudflare One to Palo Alto - why we left after 8 months

3 Posts
3 Users
0 Reactions
2 Views
(@eval_newbie_2025)
Reputable Member
Joined: 2 months ago
Posts: 172
Topic starter   [#21772]

Hi everyone, I’m pretty new to evaluating these big B2B platforms, so I wanted to share our recent experience. We’re a small team and we switched from Cloudflare One to a Palo Alto Networks solution about a month ago after using Cloudflare for eight months.

We chose Cloudflare One originally because it seemed simpler to manage network and security from one place, especially with their global network. The setup was fairly straightforward, which was great for us newcomers. We mainly used it for Zero Trust network access to our internal apps and for some basic DNS filtering.

But after a few months, we started hitting some walls. The biggest thing for us was the reporting and visibility. When we needed to dig into why a specific access attempt was blocked, or get a clear view of user activity across all the services we use, it felt like we were piecing together fragments. Our more security-minded team members felt they were working with a partial picture. We also found some of the policy controls for SaaS apps weren’t as granular as we needed them to be as we grew.

I’m curious if others have had a similar journey? We moved to Palo Alto largely for that deeper inspection and more detailed logging, even though it’s a more complex setup. I’m grateful for any insights—was there a way to get that level of detail out of Cloudflare One that we missed? Or is this just a known trade-off with their platform?



   
Quote
(@cost_cutter_ray)
Estimable Member
Joined: 2 months ago
Posts: 122
 

I'm a FinOps lead at a mid-market e-commerce platform (~500 employees) handling our own infrastructure across AWS and Azure. We've been running both Cloudflare One and Palo Alto Prisma Access in production for different segments of our workforce for about two years now, allowing for a direct operational comparison.

* **Target Fit & Complexity:** Cloudflare One is optimal for lean teams (sub-200) prioritizing developer-friendly, global-edge deployment. Palo Alto is built for organizations with a dedicated security or network team. The shift typically happens when you need more than 40-50 distinct L7 firewall rules or granular SaaS app controls that go beyond "allow/block."
* **Real Cost & Scaling:** Cloudflare's pricing is simpler (roughly $6-9 per user/month on Zero Trust) and scales predictably. Palo Alto's true cost is higher (starting ~$12/user/month for Prisma Access) and requires careful capacity planning; hidden costs emerge from required support SKUs and the compute credits for advanced threat prevention, which can add 15-25% to the bill at our scale.
* **Visibility & Reporting Limitation:** OP's experience is accurate. Cloudflare's logs are comprehensive but require you to build your own dashboards and correlation in a SIEM for a unified view. Palo Alto's native Panorama console provides out-of-the-box, correlated views across network, DNS, and identity that we found reduced mean time to resolution for access denials from ~90 minutes to under 20.
* **Deployment & Control Shift:** Cloudflare's agentless model via WARP can be deployed company-wide in a few hours. Migrating to Palo Alto's GlobalProtect agent took us three weeks of phased rollout due to per-device posture assessment tuning and inevitable helpdesk tickets for non-standard user configurations. The trade-off is the control: Palo Alto's policy engine allows for conditions we couldn't implement in Cloudflare, like restricting specific Salesforce report exports only when on an untrusted network.

Given your mention of a small team and a need for deeper inspection, I'd recommend sticking with Palo Alto only if you have, or are hiring for, dedicated security operations bandwidth. If not, tell us the size of your security team and whether you've integrated a SIEM yet; the right choice becomes clear with those details.


Every dollar counts.


   
ReplyQuote
(@data_meets_ops)
Estimable Member
Joined: 2 months ago
Posts: 81
 

That reporting gap you mentioned resonates. I've seen similar issues where the data pipeline for audit logs just isn't there for proper troubleshooting.

We're not on Palo Alto, but we hit the same wall with a different "simplified" platform last year. It's fine for greenfield, but when you need to answer a specific security question, you end up needing to join events from three different API endpoints that don't share a common key. Makes building any reliable dashboard for your stakeholders a real headache.

Did you find Palo Alto's logging easier to integrate into your existing data stack, like a SIEM or even a data warehouse for internal reporting? That's usually the make-or-break for us.



   
ReplyQuote