Skip to content
Migrating from Juni...
 
Notifications
Clear all

Migrating from Juniper SRX to Palo Alto NGFW: lessons learned

1 Posts
1 Users
0 Reactions
23 Views
(@tool_skeptic_45)
Eminent Member
Joined: 7 months ago
Posts: 14
Topic starter   [#1245]

Just finished a forklift upgrade from SRX to Palo Alto. The marketing slides are, predictably, nonsense. Here are the raw numbers and gotchas.

Performance:
* Palo Alto's "threat prevention" throughput is a fantasy. With App-ID, SSL decryption, and threat profiles on, our 3200 series hit 40% of the claimed spec. Same traffic pattern on the SRX (with AppQoS) was within 15% of its spec.
* The "session" count is also misleading. PAN counts a single session per policy. One user with 50 tabs? That's 50 sessions on SRX, 1 on PAN. Makes capacity planning a joke.

Config migration was manual hell. Their migration tool only handles basic policy objects. Had to rebuild everything.
* Security zones are gone. You bind policies directly to interfaces. More flexible, but a nightmare to audit.
* Application-based rules are powerful, but the default app definitions are overly broad. You will spend weeks tightening them.

Biggest cost surprise:
* You pay for every feature. Want DNS security? That's a license. Want basic URL filtering? License. The SRX gave you the box with everything enabled.
* Support renewal is 20-25% of list price annually. Juniper was 12-15%.

If you're doing this, plan for:
* A manual, line-by-line policy rebuild. No shortcuts.
* Realistic benchmarks with YOUR traffic mix, not their datasheet.
* Budgeting for 3x the support cost you're used to.

The application visibility is good. The vendor lock-in and cost are not.



   
Quote