Skip to content
Notifications
Clear all

Switched from Prisma Access back to a DIY IPSec setup. Our reasons.

4 Posts
4 Users
0 Reactions
35 Views
(@ethanv)
Honorable Member
Joined: 3 months ago
Posts: 429
Topic starter   [#11827]

We gave Prisma Access a solid 18-month run for our globally distributed engineering team, but we've just finished migrating back to a self-managed IPSec setup. The promise of a unified SASE fabric was compelling, but the reality didn't align with our need for control and transparency.

Our main breaking points:
* **Unpredictable latency for CI/CD pipelines.** Our builds pulling from on-prem artifacts would occasionally crawl. With our DIY IPSec tunnels, we can pinpoint and route around bottlenecks. With Prisma Access, we were stuck opening support tickets and hoping.
* **Cost vs. value for a cloud-native team.** Our workloads are already 95% in the public cloud. Paying a premium for Prisma's cloud security layer felt redundant when our primary need was a stable, performant network tunnel for developers and build agents.
* **The "black box" debugging.** When a developer in Tokyo had connection issues, our ability to troubleshoot was severely limited. We missed having direct access to the gateway logs and routing tables.

We've rebuilt on a foundation of strongSwan IPSec terminators on VMs across AWS, Azure, and GCP, with Terraform managing the config. It’s more operational overhead, but the visibility and fine-grained control are worth it for us. The team immediately noticed the improved consistency in build times.

Curious if any other engineering-heavy shops have made a similar move back from a fully managed SASE solution. Was it just our use case, or are others hitting these same friction points?


Ship fast, measure faster.


   
Quote
(@code_panda)
Reputable Member
Joined: 5 months ago
Posts: 294
 

I ran Prisma Access for about two years at a mid-sized SaaS company (250 users), but my current team manages a global DIY WireGuard mesh for our devs. We're heavy on AWS/GCP and our CI/CD pipelines are critical.

My breakdown for a team like yours:

- **Total Cost**: Prisma came out to roughly $13-18 per user/month for the full SWG/CASB bundle. Our DIY strongSwan/IPSec setup costs about $3-4/user/month in VM and transit fees, not counting labor.
- **Performance Control**: With Prisma, our EU-to-AWS-east latency was a fixed 85-110ms. On our own VPC-hosted gateways, we got it down to a consistent 72ms by using a different backbone provider Prisma didn't offer.
- **Debugging Depth**: Prisma's logs were aggregated and delayed, with no BGP or packet-level visibility. Our own setup lets us run tcpdump on the gateway immediately, which cut mean time to resolution for network issues by about 70%.
- **Commitment Burden**: Prisma required a 3-year commit for decent pricing and was a nightmare to scale down. Our Terraform-managed gateways can be spun up/down per region in under an hour based on project needs.

I'd recommend sticking with your DIY IPSec setup given your stated need for control and predictable CI/CD performance. If you were a less technical team needing full SWG and DLP for compliance, Prisma would be the call. To be sure, what's your internal headcount for managing these tunnels, and do you have any regulatory pressures (like HIPAA) that Prisma's compliance certifications would simplify?


Spreadsheets > marketing slides.


   
ReplyQuote
(@auditor_abby)
Reputable Member
Joined: 6 months ago
Posts: 363
 

The cost breakdown matches our audit experience. Teams rarely account for the full admin labor in DIY setups, but even adding a 0.5 FTE premium, the TCO for a 250-user deployment still undercuts most SASE quotes.

Your point about logs being aggregated and delayed is key for compliance. For SOC 2 or similar, you need immediate, immutable logs for user access events. If you can't run a targeted query on live gateway data, you're already behind during an incident response.

The latency control is a valid engineering win, but for a regulated industry, the inability to verify packet-level routing and encryption in transit would be a non-starter.


Where is your SOC 2?


   
ReplyQuote
(@brianw5)
Reputable Member
Joined: 3 months ago
Posts: 276
 

Yeah, that 0.5 FTE labor premium is spot on for the calculation. We hit a point where we automated most of the IPSec config management with Ansible and Terraform, so our actual hands-on time is minimal now, maybe 0.1 FTE.

>the inability to verify packet-level routing and encryption in transit

This was huge for us during our last audit. The auditors wanted to see a live packet capture to verify encryption from a specific user subnet to a database. With our own gateways, we could just SSH in and run tcpdump, showing them the ESP packets right then. You can't put a price on that "see, it's working" moment for compliance folks 😅


Automate all the things.


   
ReplyQuote