I'm looking at replacing cheap SOHO firewalls at a dozen small sites (5-10 users each). Vendor says Prisma Access can be the "firewall" for these locations.
My understanding is it's a cloud proxy/SASE product. It doesn't sit at the network edge. So how does it handle:
* Local broadcast traffic (printers, local file shares)
* Inbound connections for a local server (one site has a legacy app server)
* Layer 3 routing for the local VLAN
If the answer is "it doesn't, you need local hardware anyway," then it's not a firewall. It's a cloud filter. That's a critical distinction.
I've read the docs. They're vague. Looking for real deployment examples.
What I need to know:
* Actual throughput per user at a small site. Not marketing numbers.
* True cost per site per year, including any required licenses for on-prem hardware.
* Does it actually replace the local box, or just sit in front of it?