Network Security Aug 08, 2026 8 min read 1,402 words 75 views Updated Aug 2026

Palo Alto Networks Products

What Palo Alto NGFW and Cortex actually deliver for UAE enterprises, where deployments go wrong, and how to decide what to buy.

Table of Contents
Palo Alto Networks Products – cybersecurity guide by Basim Ibrahim

Palo Alto Networks sells two product families that matter to UAE buyers: the PAN-OS firewall line (PA-Series hardware, VM-Series virtual firewalls, Prisma Access for cloud-delivered security) and Cortex, its detection and response family covering XDR, XSOAR, Xpanse and XSIAM. The firewall controls and inspects traffic; Cortex is where detection, investigation and response live.

TL;DR
  • App-ID and User-ID are the reason to buy a Palo Alto firewall. A port-based rule base migrated from an old firewall wastes the platform.
  • Without TLS decryption the firewall inspects a fraction of modern traffic. Size hardware against decryption-enabled throughput, not the datasheet headline.
  • Cortex is four products, not one. Buy the piece that maps to a gap you actually have, and be clear about what it displaces.
  • Subscriptions, not hardware, dominate the bill over a three-year term. Budget for the term.

What you are actually buying

Palo Alto Networks is easiest to understand as two businesses. The first is the firewall business: PA-Series appliances, VM-Series and CN-Series virtual firewalls, and Prisma Access for cloud-delivered security, all running PAN-OS. The second is Cortex, a detection and response family built largely through acquisition: Cortex XDR for endpoint detection, XSOAR for automation and case management, Xpanse for attack surface discovery, and XSIAM as the SOC platform that pulls the rest together.

The firewall appliance is only part of the firewall purchase. The inspection features that justify the price are subscriptions: Advanced Threat Prevention for IPS and inline malware blocking, Advanced URL Filtering, WildFire for detonating unknown files, DNS Security, and GlobalProtect for remote access. Panorama sits above the estate for central management. Every subscription is priced per firewall and renews on a term, so the shape of your estate sets the bill more than the model number does.

App-ID is the point, and most rule bases ignore it

The architectural idea that made Palo Alto's name is App-ID: policy written against the application inside the traffic rather than the port it rides on. User-ID adds identity, so a rule can say which group of people may use which application wherever they connect from. Content-ID then inspects what moves inside the sessions you allow.

Most deployments never get there. The typical migration lifts a port-based rule base off a legacy firewall, converts it, and goes live. Traffic passes, the project closes, and the platform runs on as an expensive stateful filter. Converting that into application-aware policy is unglamorous work: run the converted rules, read the traffic logs to learn which applications each rule actually carries, then rewrite each rule against those applications and tighten the service field. PAN-OS ships tooling for exactly this in Policy Optimizer, and it still takes weeks of sustained attention that projects rarely budget.

A quick self-test: pick ten allow rules at random. If most say "any" in the application column over a broad port range, the organisation bought an NGFW and is operating a packet filter.

The decryption decision nobody wants to make

The majority of enterprise traffic is TLS-encrypted, and no firewall can apply App-ID or threat inspection to traffic it cannot read. SSL Forward Proxy decryption is therefore the single configuration decision that most changes what the platform is worth, and it is the one most often deferred indefinitely.

It gets deferred for real reasons. Decryption requires the firewall's certificate to be trusted on every managed endpoint, documented carve-outs for banking, health and government categories, handling for applications that pin certificates, and a performance budget, because decryption-enabled throughput is a fraction of the headline figure on every model. Two rules follow. Size the hardware against the decrypted throughput number for the feature set you intend to run. And write the decryption policy, including its privacy exclusions, before the first session is decrypted; assessors ask to see that document, and "we decrypt nothing" quietly undercuts most of the threat prevention story a board has been told.

Cortex, product by product

Cortex is a family name. Buying conversations go wrong when it is discussed as if it were one SKU.

Cortex XDR

The endpoint agent, with prevention plus detection built on analytics that stitch endpoint telemetry together with firewall and identity logs into causality chains. It is a strong product in a category with strong competition: in UAE tenders it lands against CrowdStrike Falcon and Microsoft Defender for Endpoint on nearly every shortlist. If you already run a mature EDR, the case for switching rests on the firewall log stitching and the analytics, not on a generational leap in endpoint protection.

Cortex XSOAR

The former Demisto, and on its own merits the strongest product in the family: playbook automation, case management and a large integration library. It is also the most commonly shelved. An XSOAR licence without an engineer who owns playbook development produces a ticketing system with an automation tab. Budget a dedicated engineer or contracted playbook delivery, or do not buy it.

Cortex Xpanse

External attack surface management: continuous discovery of what your organisation exposes to the internet, including assets nobody registered with security. Genuinely useful in the GCC, where group structures and subsidiary IT produce forgotten estate. It overlaps with cheaper ASM tools, so judge it on discovery quality against assets you already know about, not on the interface.

Cortex XSIAM

The consolidation play: SIEM, XDR, SOAR and ASM delivered as one consumption-priced platform, positioned to replace a SIEM outright. It is the right conversation for a greenfield SOC or a SIEM the team already resents, and a hard sell midway through a Microsoft Sentinel or Splunk commitment. Pricing follows data volume, so insist on a sizing exercise against your real ingest before anyone quotes a number.

Where UAE deployments go wrong

The failure patterns repeat across the region, and almost none of them are product faults.

  • Threat Prevention profiles left on defaults, or set to alert while everyone waits for a tuning phase that never arrives.
  • Decryption postponed year after year, which hollows out App-ID, URL filtering and WildFire at once.
  • GlobalProtect portals and management interfaces reachable from the internet and running behind on PAN-OS updates. The platform has had serious, actively exploited authentication flaws; the PAN-OS GlobalProtect auth bypass episode is the case study worth reading before you decide patch windows.
  • No Panorama on multi-firewall estates, so branch configurations drift until nobody can say what policy is actually in force.
  • Log retention left at appliance defaults, which is too short for incident investigation and for what assessors expect in regulated sectors.
  • XSOAR purchased alongside XDR because it is "a platform", then never staffed.

What assessors ask for

UAE and wider GCC assessors have converged on evidence over brochures. For a Palo Alto estate, expect to produce: a change-controlled rule base with named owners for each rule; the output of the last rule review, with a stated cadence; the decryption policy and its privacy carve-outs; proof that content updates and PAN-OS versions are current, with dates; retained logs deep enough to reconstruct an incident; and segmentation evidence showing that regulated zones are separated by enforced policy rather than by diagram. None of this is generated by buying the product. All of it is generated by running it.

Questions to settle before you sign

  • What does each component displace? If the answer is "nothing, it runs alongside", the consolidation argument is gone and the price should reflect that.
  • Can your endpoints trust a decryption certificate, and will legal sign the carve-out policy? If not, buy smaller hardware and adjust the threat prevention story you tell the board.
  • Who rewrites the rule base for App-ID, and by which date after cutover?
  • For Cortex: who operates it day to day, in-house or through a managed SOC partner?
  • Where will Cortex tenant data be hosted, and can you get the answer in writing? Data residency questions arrive late in UAE procurement and are cheaper to answer early.
  • What does the full stack cost across the whole term, subscriptions included? The hardware quote is the smallest number you will see; the Cortex XDR pricing breakdown for UAE firms shows how the recurring side behaves.
Run properly, a Palo Alto estate is among the best network security platforms an enterprise can operate. Run as installed, it is an expensive way to keep doing what the old firewall did. The difference between the two is operations, not procurement.

Frequently Asked Questions

Next-Generation Firewalls (NGFW) are a type of firewall that provides advanced threat protection by filtering traffic based on user identity, application, and content. For UAE enterprises, NGFW is crucial in protecting against emerging threats and meeting local regulatory requirements.

To implement Palo Alto Networks Cortex, UAE enterprises should start by assessing their current security infrastructure and identifying areas for improvement. Then, they can work with a certified partner to deploy Cortex and integrate it with their existing systems, ensuring seamless security analytics and threat detection.

The cost of deploying Palo Alto Networks NGFW and Cortex for a medium-sized enterprise in the UAE can vary depending on the specific requirements and infrastructure. However, on average, the cost can range from AED 500,000 to AED 1.5 million, including hardware, software, and implementation services.
Basim Ibrahim, Senior Cybersecurity Presales Consultant Dubai
Basim Ibrahim OSCP CEH CySA+ Pentest+
Senior Cybersecurity Presales Consultant, Dubai, UAE

5+ years delivering enterprise cybersecurity presales, VAPT assessments, and security advisory across the UAE and GCC. Currently Senior Presales & Technical Consultant at iConnect IT, Dubai.

Connect on LinkedIn

Was this article helpful?


Comments

Leave a Comment

Comments are moderated before appearing.

Related Articles

Weekly Cyber Insights

One email per week. UAE/GCC focused. No spam, unsubscribe any time.