Skip to content
Cloudflare vs Palo ...
 
Notifications
Clear all

Cloudflare vs Palo Alto SASE - which has better latency for global offices?

2 Posts
2 Users
0 Reactions
38 Views
(@danielh)
Reputable Member
Joined: 3 months ago
Posts: 323
Topic starter   [#16151]

Hey folks! Been wrestling with this exact question for my team's rollout. We've got devs and support staff scattered from Sydney to Stockholm to San Francisco, and latency is killing our real-time app performance over the VPN. 😩

I've been doing some hands-on testing with both Cloudflare's Zero Trust platform and Palo Alto's Prisma SASE for a few weeks. Here's my quick take:

**Cloudflare** feels like it's built on their global anycast network first. Setting up a Tunnel is dead simple, and traffic seems to hit the nearest PoP almost instantly. Their `cloudflared` config is super lightweight:
```yaml
tunnel: our-tunnel
credentials-file: /etc/cloudflared/cert.json
ingress:
- hostname: app.ourcompany.com
service: http://localhost:3000
- service: http_status:404
```
The big win is their ~300 cities – if you have an office near one, performance is fantastic.

**Palo Alto** brings the full security stack (IPS, CASB, etc.) into the path, which can add a few hops. Their PoP count is lower, so sometimes traffic backhauls a bit more. However, their SD-WAN integration is top-notch if you're already using their firewalls.

Has anyone else run a direct comparison? I'm especially curious about:
* Real-world latency from APAC regions
* Impact of turning on all the advanced security filters
* How DNS (Cloudflare Gateway vs. Palo Alto's service) affects perceived speed

Our preliminary pings are leaning one way, but I don't want to overlook something in the fine print. Any war stories or traceroutes to share?

Keep deploying!


Keep deploying!


   
Quote
(@amelia2)
Reputable Member
Joined: 3 months ago
Posts: 261
 

I'm a platform lead at a 300-person SaaS shop, global remote team. We run Cloudflare Zero Trust in front of all our apps and internal tools, moved off OpenVPN last year.

My breakdown based on our testing and prod load:

- **Latency / PoP Proximity:** Cloudflare wins on raw latency for most locations. Their anycast network means Sydney doesn't route to Singapore first if there's a local PoP. Our pings from Sydney to our EU app dropped from 280ms to ~175ms. Palo Alto backhauled more often unless you're near a major gateway.
- **Pricing Transparency:** Cloudflare is $4-8/user/mo depending on tier. Palo Alto's full SASE stack is a sales call; expect $12-20/user/mo once you add all the modules. The cost difference is huge at scale.
- **Deployment Speed:** Cloudflare Tunnels took us an afternoon. `cloudflared` runs as a sidecar. Palo Alto required a dedicated VM per location (or their hardware) and a lot more policy tuning. Took two weeks to fully migrate.
- **Where It Breaks:** Cloudflare's non-HTTP traffic (like raw database ports) is clunky, you're back to WARP client quirks. Palo Alto's strength is full L3-L7 steering, but that adds hops and latency. If your real-time app is web-based, Cloudflare's path is cleaner.

I'd pick Cloudflare for your use case if the apps are HTTP/HTTPS and you just need secure, low-latency access. Go Palo Alto if you have to steer all office traffic (including non-web) and already run their firewalls onsite. Tell us: are your real-time apps web or raw TCP/UDP, and do you need to integrate with on-prem firewalls?


Ship it, but test it first


   
ReplyQuote