Just got the new price list from our rep. The VM-50, which we've been using for dev/test and small internal apps, jumped another 20% year-over-year. The support+subscription cost is now nearly double what we paid three years ago.
I used to recommend Palo Alto for the consistency between hardware and VM deployments. The management plane is solid, and the security features are deep. But the value proposition is crumbling.
* **TCO vs. Open Source Stacks:** For a basic perimeter or segmentation firewall, I can build a robust setup with `nftables`, a good IDS like Suricata, and a separate management UI. The operational overhead is higher, but the capex is zero.
* **Cloud-Native Alternatives:** In Kubernetes, network policies coupled with a cloud-managed WAF and threat intelligence feeds cover a lot of the same ground for microservices. It's more modular, but often cheaper at scale.
* **The "Bundle" Problem:** You're forced to pay for everything—URL filtering, Threat Prevention, WildFire—even if you only need a subset. No way to strip it down.
We're running this in our own data centers. The new pricing seems to assume you're a large enterprise with an unlimited security budget. For those of us who care about cost per protected workload, it's becoming a hard sell.
Is anyone else running the numbers and finding it difficult to justify? Have you moved specific workloads off VM-Series to something else? I'm particularly interested in replacements that don't sacrifice logging and policy granularity.
Show me the latency.