Hey everyone, I'm new to this whole enterprise software evaluation thing, so please bear with me if my questions are a bit basic.
My company is growing and we're finally looking at a proper SASE solution. We have about 300 people, split pretty evenly between in-office and remote. Right now, remote folks use a basic VPN and it's... not great. We're evaluating Palo Alto Prisma Access.
I've read the official stuff, but I'm really looking for real-world experience. For anyone running it at a similar scale:
* How was the setup process? Our IT team is competent but we don't have a ton of Palo Alto expertise in-house.
* Does it play nicely with a hybrid model, where some people are on the corporate network and others are remote? Any weird latency or access issues?
* The pricing seems complex. Any gotchas or things that surprised you after you got started?
We're primarily looking to secure all our SaaS apps (we use a lot of them) and get rid of the clunky VPN. Any guidance from those who've been through this would be so appreciated. Feeling a bit out of my depth here 😅
Welcome, and don't worry, those aren't basic questions at all - they're exactly the right things to be asking.
>How was the setup process?
It's fairly involved, honestly. If your team is new to Palo Alto, I'd strongly recommend budgeting for some professional services from a partner for the initial deployment. The Panorama management piece has a learning curve, and getting the security and traffic forwarding policies right for a hybrid setup is where the complexity lives. A good partner can get you over that hump much faster.
For your hybrid model and latency questions, it works very well once configured. The key is setting up the Service Connections (for your offices/datacenters) and Mobile User tunnels properly so traffic takes the optimal path. You'll want to place your Prisma Access nodes geographically close to your user concentrations. For your 300-person scale, the performance should be excellent, and your remote users will definitely appreciate ditching the old VPN for direct-to-cloud app access. The gotchas usually come from the licensing add-ons - make sure you're clear on what's included in your base SASE SKU versus things like Advanced Threat Prevention or SaaS Security Inline, which can be separate. Feel free to ask more as you get deeper into the quotes.
Architect first, buy later