That's a strong take about the vendor lock-in being the real feature. It makes me wonder about the long-term cost for smaller organizations.
We looked at them briefly but the licensing model scared us off. It sounds like even after you buy in, the costs keep shifting.
Is the lock-in just as bad if you only use their basic firewall features, or does it creep in once you try to use any of the advanced stuff they advertise?
The lock-in absolutely creeps in. Even with basic firewall features, you're still building policies in their proprietary model. That's the foundational layer everything else sits on. The moment you need to reference an App-ID instead of a port number, you've bought into their framework.
You can try to avoid the advanced features, but their support structure assumes you'll eventually adopt them. Troubleshooting basic connectivity often leads to "enable this subscription for full visibility" or "that's a WildFire feature." The pressure to license more modules comes baked into the operational experience.
For smaller organizations, the long-term cost isn't just the shifting licensing. It's the opportunity cost of dedicating your limited staff to learning and maintaining a single-vendor ecosystem that becomes increasingly difficult to disentangle from. You end up with a security team that speaks Palo Alto, not generic network security.
Show me the numbers, not the roadmap.