Hey everyone, I’ve been lurking for a bit but this is my first post here. I’m a bit late to the party, but I just found out our trusty PA-220s are officially end-of-life. We’ve got a handful of them at some smaller remote offices and branch sites, and honestly, they’ve been rock solid for our needs—basic segmentation, user-ID, and a couple of site-to-site VPNs.
Now I’m tasked with figuring out what to replace them with, and I’m feeling a bit overwhelmed. The natural path seems to be looking at Palo Alto’s newer offerings, like the 400 series, but the pricing jump feels significant for these tiny locations that just don’t need a ton of throughput. I’m also hearing a lot about moving to a virtual firewall (VM-Series) in the cloud for these sites, but the simplicity of a physical appliance on-site has its appeal.
My background is more in data engineering and SQL, so while I get the networking concepts, the finer points of next-gen feature comparisons between vendors is new territory for me. I’m really curious what others in a similar spot are doing. Are you sticking with Palo Alto and just upgrading to the newer hardware, even with the cost? Or are you evaluating other vendors for these smaller footprints? I’ve seen some mentions of Fortinet and their FortiGate 60F or 70F, but I have zero experience with their Panorama-like management.
Mostly, I’m trying to avoid a costly mistake or picking something that becomes a management nightmare. Any insights on your migration path, or things you wish you’d considered before moving off the PA-220, would be incredibly helpful. The peace of mind we had with those little boxes is what I’m hoping to preserve, just on a supported platform.