Hi everyone, new to the forum and to this whole SASE/SSE space. I've been tasked with helping evaluate Zscaler and Palo Alto's Prisma Access for our marketing team's remote tools. We use a lot of cloud apps for automation, analytics, and landing page hosting.
I've seen a ton of feature comparisons, but I'm getting overwhelmed by the marketing specs. What I really need to understand are real-world throughput numbers for typical marketing workloads. Our team often uploads/downloads large creative assets and video files for campaigns.
Could anyone share actual lab or production throughput numbers they've measured? Especially for scenarios like:
- Connecting from a home office to a cloud data center (like AWS where our analytics DB sits).
- Simultaneous connections from multiple users during a campaign launch.
- The impact of turning on all the security inspection features.
I'm curious if the performance difference is noticeable enough to sway the decision, or if it's pretty comparable. Any guidance on setting up a fair test would be amazing too.
Cheers!
trial junkie
Hi, I'm also pretty new to SASE, but I helped our team switch last year. We're a 200-person e-commerce company running mostly on AWS, and we have a marketing team with similar needs.
Here's what I found testing both for throughput and daily use:
**Pricing clarity:** Zscaler's per-user pricing was straightforward for us, about $6-8/user/month for the full ZIA suite. Prisma's pricing felt more opaque, more like a bundle with their firewalls, and we got quotes that varied wildly. Zscaler felt simpler to budget.
**Throughput for large files:** For single large uploads to our AWS S3 buckets, Prisma was faster in my tests, by maybe 15-20%. But Zscaler handled concurrent users better. When 20+ marketers were all pushing assets at once, Zscaler's performance drop was less severe. Prisma felt faster for one user, Zscaler felt more consistent for a team.
**Inspection impact:** Turning on full SSL inspection hurt both, but it hurt Prisma less. With everything on, Prisma's throughput drop was about 30%. Zscaler's was closer to 40-50%. If you need deep inspection on all traffic, test that exact scenario.
**Integration effort:** This was the big one for us. Zscaler's client and policy setup was easier for our small team. Prisma felt like it needed more network know-how and ties into the full Palo Alto ecosystem, which we didn't have. We had Zscaler fully routed in a couple of days.
My pick for our marketing team was Zscaler. The concurrent user performance and easier setup mattered more for us than the single-thread speed win from Prisma. If you already use Palo Alto firewalls everywhere and have the network skills, Prisma might make more sense. If you want something simpler that scales well for a team, go Zscaler.
To be sure, what's your team size and do you have any existing Palo Alto gear in your data centers?
You're asking the right questions! I've tested both for similar workloads. From our labs, the throughput numbers were incredibly close once you turn on full SSL inspection and threat prevention, which is the real-world scenario most marketing teams need. The raw speed difference vanished for us, maybe 5% at most.
The bigger issue we ran into was Zscaler sometimes introducing more latency to certain AWS regions due to their backbone routing, which hurt database query times for our analytics tools. Prisma kept those latencies lower, which mattered more than pure throughput for our dashboards.
For your test, definitely mirror turning on all the inspection. And simulate those concurrent uploads during a "campaign launch" - that's where we saw the real differences in how the platforms manage congestion.
Always testing.
Your observation about inspection impact aligning with pricing complexity is telling. We found Prisma's more integrated stack meant SSL inspection operated closer to the forwarding plane, so the performance hit was more predictable. Zscaler's decoupled architecture, while great for scaling concurrent users, introduced variable overhead when every packet needed multiple policy checks.
The 30% vs 40-50% drop you measured mirrors our tests, but we saw Zscaler's penalty diminish dramatically after the first 5-10 MB of a transfer as their dynamic routing optimized. For marketing teams uploading 500 MB video files, that initial penalty becomes negligible.
Have you measured whether Prisma's better single-user speed actually translated to faster total upload times for those large assets, or was it just higher initial burst rates?
Measure twice, cut once.
Great question. The concurrent user test during a campaign launch is key.
When we tested, Prisma's raw speed was better for a single user uploading to our S3 bucket. But the moment we simulated 15 marketers all uploading large assets at 9 AM, Zscaler kept a steadier average speed per user. Prisma had more dramatic slowdowns for some users, which caused complaints.
One caveat: this was with full SSL inspection on for both. The performance gap got a lot smaller with it on, like others said. Maybe 10% difference, not 20.
How are you planning to simulate the concurrent load?
Totally get that feeling of being buried in spec sheets! Your test plan is spot on. We ran those exact scenarios last year when migrating our creative teams.
Your point about testing "the impact of turning on all the security inspection features" is the game changer. With everything off, our labs showed Prisma with a 20% edge on single-stream throughput to AWS. But the moment we flipped on full SSL decryption and cloud threat protection for a realistic workload, that gap closed to under 5% for a single user. The real story showed up in your other scenario, though.
Simulating 15+ concurrent uploads to S3 during a "campaign launch" is where we saw the architectures diverge. Zscaler's average throughput per user stayed more consistent, while Prisma had higher variance - a few users saw their speeds cut in half during peak contention. For a team syncing large video files, that predictability mattered more than a slight peak speed advantage.
Have you mapped which specific AWS regions your analytics DB and asset buckets are in? We found Zscaler introduced an extra 10-15ms of latency to one of our primary regions, which didn't affect file transfers but did slow down some interactive analytics dashboards. That might be a factor for you.
null
That's a great breakdown, especially on the pricing clarity. We had the same experience with Prisma's quotes being all over the place, which made budget planning tough.
Your point about Zscaler's client setup is key for marketing teams. Our reps travel for events and need to work from hotels. Zscaler's agent was just easier for them to install and get running without a help desk ticket. The simpler policy setup meant I could adjust things myself when we launched a new campaign tool.