Skip to content
Palo Alto Prisma Ac...
 
Notifications
Clear all

Palo Alto Prisma Access vs Cloudflare One for a remote-first team

1 Posts
1 Users
0 Reactions
2 Views
(@jakeb)
Reputable Member
Joined: 1 week ago
Posts: 160
Topic starter   [#16597]

Hey everyone, been lurking for a bit and learning a ton here. I'm helping evaluate a SASE/SSE shift for our team of about 120, fully remote across 20+ countries. We're coming from a messy stack of a traditional VPN, a separate cloud SWG, and some endpoint stuff that doesn't talk to each other.

The shortlist has come down to Palo Alto's Prisma Access and Cloudflare One. I've read the whitepapers, but I'm hitting a wall on concrete, day-to-day differences that matter to us.

My main questions are around the actual user experience and admin reality:

1. **Performance for daily work:** We do a lot of real-time collaboration in Figma, Miro, and video calls. How noticeable is the latency difference in practice, especially for users in APAC and South America? Both vendors claim a great network, but is one consistently better for non-web app traffic?

2. **Security granularity vs. simplicity:** Palo Alto's security policy depth is legendary, but also seems complex. For a team that just needs solid zero-trust app access, data loss prevention for SaaS, and threat prevention, is Cloudflare One's (arguably) simpler model "good enough" and easier to manage? Or will we regret not having Palo's detail later?

3. **The "full stack" vs. "best-of-breed" feel:** Prisma Access feels like a complete, integrated suite from one vendor. Cloudflare One feels like a brilliant assembly of services (like Magic WAN, Access, Gateway) that we'd stitch together. Does that integration gap cause real headaches in logging, policy sync, and support?

4. **Cost transparency:** Everyone hides their true pricing. Beyond the per-user/month, what are the hidden cost drivers? Is it data volume, certain premium features, or support tiers that really change the quote?

I'm cautious about getting locked into a ecosystem that's overkill, but also don't want to outgrow a simpler platform in 18 months. Any experiences from teams who made this specific choice? What were the trade-offs you felt most acutely after deployment?



   
Quote