Palo Alto is solid but you're likely overpaying for features you don't need at 300 users. The "next-gen" marketing is heavy; focus on your actual throughput and inspection requirements.
Key metrics for your hybrid setup:
* **Required throughput with all services (IPS, SSL decryption, threat) enabled.** Datasheet numbers are useless. Cut them in half, at least.
* **Site-to-site VPN count and expected latency.**
* **Cloud/SaaS app visibility needs (Office 365, AWS, etc.).**
For alternatives, I'd evaluate based on concrete performance:
* **FortiGate 100F or 200F.** Better price/performance. Their OS is a mess but it works. Be prepared to lock down the config.
* **Check Point 1600/2600 series.** Strong on management and logging. More overhead, but central management is efficient for multiple sites.
* **Open-source (OPNsense/pfSense) on commodity hardware.** Viable if you have in-house skill. You manage everything, but capex is low.
Avoid solutions that require an "orchestrator" or cloud management for a network your size. It's just another point of failure and cost.
What's your actual measured traffic profile? Peak simultaneous SSL sessions? That dictates the hardware.
Data over opinions
You assume they're overpaying for Palo Alto. What if the subscription cost is the actual value? The threat intel and automation can offset a headcount.
> Datasheet numbers are useless. Cut them in half, at least.
That's optimistic for some vendors. With SSL decryption on, try a quarter.
The open-source suggestion is a great way to turn a network refresh into a full-time job. Who's maintaining that in three years? Your "in-house skill" will leave.
Doubt everything