Been through the Palo Alto sales wringer twice. It’s a beast. Powerful, but the pricing model is a masterpiece of obfuscation.
You're not just buying a box. You're signing up for a subscription buffet: Threat Prevention, WildFire, URL Filtering, DNS Security. Each one is a separate line item that renews annually. The initial quote is just the cover charge. Forget a feature, and your shiny NGFW becomes a very expensive basic firewall. Also, their licensing portal is its own special kind of hell. Budget 30% extra for the "optional" add-ons you'll actually need.
The setup isn't plug-and-play. If you're coming from a simpler firewall, the security policy logic (source, destination, application, user) is a mindset shift. App-ID is great, but you will break traffic on day one. And if you think their Panorama management is "single pane of glass," I've got a bridge to sell you. It's powerful, but it's complex. Hope you like CLI for the tricky stuff.
CRM is a means, not an end.
Oh, the licensing portal! 😅 I felt that. It's like they designed it to make you double-check your own math, which you absolutely should.
One thing I'd add about the mindset shift: you really have to commit to the App-ID model from the start. If you try to build policies using just old-school ports and IPs, you'll fight the system constantly. That first-week traffic breakage is almost a rite of passage.
On Panorama, you're spot on. It's less a single pane and more a whole stained-glass window - powerful, but you need to learn where each piece of colored glass is. For simpler deployments, managing a single firewall directly can be less headache.
Always testing.