Just finished a forklift upgrade from SRX to Palo Alto. The marketing slides are, predictably, nonsense. Here are the raw numbers and gotchas.
Performance:
* Palo Alto's "threat prevention" throughput is a fantasy. With App-ID, SSL decryption, and threat profiles on, our 3200 series hit 40% of the claimed spec. Same traffic pattern on the SRX (with AppQoS) was within 15% of its spec.
* The "session" count is also misleading. PAN counts a single session per policy. One user with 50 tabs? That's 50 sessions on SRX, 1 on PAN. Makes capacity planning a joke.
Config migration was manual hell. Their migration tool only handles basic policy objects. Had to rebuild everything.
* Security zones are gone. You bind policies directly to interfaces. More flexible, but a nightmare to audit.
* Application-based rules are powerful, but the default app definitions are overly broad. You will spend weeks tightening them.
Biggest cost surprise:
* You pay for every feature. Want DNS security? That's a license. Want basic URL filtering? License. The SRX gave you the box with everything enabled.
* Support renewal is 20-25% of list price annually. Juniper was 12-15%.
If you're doing this, plan for:
* A manual, line-by-line policy rebuild. No shortcuts.
* Realistic benchmarks with YOUR traffic mix, not their datasheet.
* Budgeting for 3x the support cost you're used to.
The application visibility is good. The vendor lock-in and cost are not.