Skip to content
Notifications
Clear all

Prisma Access or Fortinet Secure SD-WAN for a Fortune 500 manufacturing site

2 Posts
2 Users
0 Reactions
0 Views
(@cloud_infra_newbie)
Reputable Member
Joined: 4 months ago
Posts: 177
Topic starter   [#9006]

Hi everyone. I'm pretty new to enterprise networking, but my team is being asked to help evaluate options for a big manufacturing site rollout. We're looking at Palo Alto Prisma Access vs. Fortinet Secure SD-WAN.

I mostly deal with Terraform and AWS, so this SASE/zero-trust world is a bit new. From my basic research, Prisma Access seems super integrated with their NGFW stuff, and Fortinet talks a lot about cost-effective performance.

My naive questions:
1. How do these actually handle site deployments? Is it all vendor-specific hardware, or can you use generic white boxes?
2. For a factory floor with lots of IoT/OT devices, which one has a smoother onboarding for "non-IT" assets?
3. I saw both have Terraform providers. Is one noticeably easier to automate? Example for setting up a basic site would be awesome.

```hcl
# Something like this for a basic site connector?
resource "prismacloud_site" "manufacturing_plant" {
name = "plant-a"
cidr = "10.10.0.0/16"
}
```

Any gotchas from real-world deployments would be a huge help. Thanks!



   
Quote
(@crm_hopper_2026)
Reputable Member
Joined: 3 months ago
Posts: 164
 

Your Terraform example is actually more Prisma SD-WAN, not Prisma Access. That's a common initial point of confusion in their portfolio. Prisma Access is their cloud-delivered security service; you'd deploy their dedicated physical or virtual Next-Generation Firewalls (like a PA-220 or VM-Series) at your site, which then connect to their global backbone. Fortinet also requires their FortiGate appliances, though their hardware options can be more varied for cost tiers.

For IoT/OT onboarding, Fortinet often gets cited as easier for passive device fingerprinting and profiling due to their internal switch and access point integrations. However, Prisma's integration with their own Panorama management for consistent policy is more rigorous if you're already in that stack.

On automation, I've scripted both. The Fortinet Terraform provider feels more mature for basic SD-WAN and firewall object creation. The Prisma Access Terraform modules are powerful but require a very specific understanding of their Tenant and Remote Network constructs. Your simple `cidr` block won't be sufficient; you'll be dealing with `prismacloud_access_tenant` and `prismacloud_remote_network` resources, which have dependencies that can trip up a rollout.



   
ReplyQuote