Okay, I've got to get this off my chest because I'm genuinely curious if I'm seeing a pattern or just had a string of bad luck. Ever since the big merger/acquisition shake-up a while back, has anyone else noticed a tangible dip in the quality of Prisma Access support?
I'm talking about the nitty-gritty, technical-deep-dive kind of support. It used to feel like you were talking to an engineer who lived and breathed the PAN-OS stack and the cloud fabric. Now, more often than not, my recent tickets feel like they're being handled by a script. The initial responses are slower, and they often miss the core of the complex issue, asking for basic troubleshooting steps we've already documented in the ticket. It's like the first line has lost the context or the permission to dig in.
Let me give you a concrete example from last month:
* We had a bizarre scenario where a specific SaaS application was being intermittently blocked for a subset of users in one of our global locations, but the policy logs weren't showing a clear deny. The traffic just seemed to vanish.
* Pre-merger, I'd expect a support engineer to maybe ask for a pcap from the Prisma Access connector, dive into the session details, and correlate it with the Tenant-Infra logs in a way I couldn't.
* What I got instead was a three-day ping-pong game: "Please confirm your app-ID is up to date," "Please run the packet capture on the endpoint," (which we'd already done and attached!), and "Can you confirm the security policy is correctly ordered?" It felt like they were just reading from a flowchart without understanding the architecture. We eventually solved it ourselves by tracing a weird routing asymmetry issue.
It's not just me being impatient! I'm an enthusiast—I love tearing into these problems. But part of the value proposition of a platform this intricate is having that expert backstop. Lately, it feels like that backstop is getting farther away, hidden behind more layers of generic support.
Is this just the growing pains of a larger organization, or has the core of the support engineering team fundamentally changed? Have others run into this with more nuanced problems involving:
* Custom URL categories and API integration quirks?
* Performance tuning between specific service connections and hyperscalers?
* Really gnarly packet capture analysis from within the service itself?
I'm hoping I'm an outlier, but my spidey-sense says otherwise. Would love to compare notes.
Yeah, I've seen that scripted feel too. The time-to-resolution on our last migration-related ticket nearly doubled because of the back-and-forth on basic steps.
What's the actual ROI on paying for premium support if tier one can't triage effectively? Makes me wonder if they're spreading their senior engineers too thin across the new combined product stack.
Ask me about hidden egress costs.
Yeah, the "bizarre scenario" you described is exactly where it falls apart now. Before, they'd skip the script and go straight for a kernel debug or session table dump. Now you're stuck in a week-long loop of "please confirm your policy is attached" when you already attached the logs showing it is.
Our last complex ticket took so long to escalate that we just rebuilt the config from scratch ourselves. Finished before they even assigned an L2.
Makes you wonder where the actual cost is. Premium support contract vs. engineer hours wasted on basic triage.
show the math