Application-level control
Policies based on App-ID and User-ID, not ports: you allow the specific application, not the range.
We are an official Palo Alto Networks partner. We design, deploy and operate the perimeter and the endpoint, and feed all their telemetry into our SOC’s SIEM so it is watched 24x7.
Palo Alto Networks is one of the reference vendors in network security. Its next-generation firewall (NGFW) identifies traffic by application and by user —not just by port and IP— and inspects content with Threat Prevention, the WildFire sandbox, advanced URL filtering and DNS Security; GlobalProtect covers remote access and Panorama the central management of multiple sites. IBERSYA is an official Palo Alto Networks partner: we license, design and deploy the perimeter, migrate from the previous firewall and operate it from our managed SOC in Spain, feeding firewall logs and Cortex XDR detections into our SIEM, with 8x5 technical analysis and automated 24x7 response. It is the premium alternative to our Fortinet FortiGate standard and to the Bitdefender GravityZone EDR included in the SOC price.
Most powerful firewalls are underused: inherited policies, any-any rules and logs nobody reviews. The value lies in the design and in continuous operation.
Policies based on App-ID and User-ID, not ports: you allow the specific application, not the range.
Isolating servers, OT environments and guests to contain an incident before it spreads.
Perimeter logs are correlated with those from endpoints and Microsoft 365.
Design, changes and policy review handled by the IBERSYA technical team.
From the perimeter to the endpoint, with policy design and day-to-day operation included in the service.
Physical and virtual firewalls running PAN-OS: traffic identification by application and user, encrypted traffic inspection and intrusion prevention.
IPS, network antivirus and anti-spyware, plus the WildFire sandbox to analyse unknown files before letting them into the network.
Blocking navigation to malicious sites and DNS resolutions linked to phishing, newly registered domains and command-and-control channels.
Remote access and home working under the same security policy inside and outside the office, with device posture checks before connecting.
Central management of every firewall in the organisation: shared policies, change control and unified visibility across multiple sites.
Endpoint protection and extended detection, correlating device, network and identity activity. The premium alternative to the EDR included in the SOC.
Firewall logs are one of the SIEM’s most valuable sources, and one of the least reviewed. These are the events that raise an alert in our circuit.
Immediate notice of any policy or rule modification, with a record of who made it and when.
Detection of repeated access attempts against the VPN, device administration or published services.
VPN sign-ins from locations or at times incompatible with the user’s usual activity.
Traffic towards command-and-control infrastructure: the clearest sign that an internal machine is already compromised.
An isolated network event may be noise; alongside a detection on the same user’s machine, it is an incident.
On serious indicators the IP is blocked or the affected host isolated without waiting for human validation.
We work with both vendors and both integrate into the SOC. The choice comes down to the size of the environment, the number of sites and the requirements the organisation brings with it.
| Criterion | Fortinet FortiGate | Palo Alto Networks |
|---|---|---|
| Position in the service | Standard for SMEs and mid-sized businesses | Premium option by requirement or environment |
| Cost | Best cost-to-capability ratio | Larger investment in hardware and subscriptions |
| Traffic control | Deep packet inspection and IPS | Identification by application and user with App-ID and User-ID |
| Multi-site | SD-WAN and management with FortiManager | Central management with Panorama |
| Telemetry in our SIEM | €60/month add-on | Integration included in the service design |
| Typical fit | One or few sites, homogeneous estate | Multiple sites, strict segmentation, OT environments or a group requirement |
If you already have a Palo Alto firewall installed, nothing needs moving: we review the policy design, connect the logs to our SIEM and the perimeter becomes monitored.
A badly configured next-generation firewall behaves like a firewall from fifteen years ago: permissive rules inherited from the migration, inspection disabled for performance and logs nobody looks at. We run the project the other way round: first an inventory of real applications and flows, then policies by application and user, and finally the migration with a planned rollback window.
Tell us how many sites you have, which firewall you use today, how many remote users and whether there is an industrial environment. With that we can size the hardware and the service.
Leave your phone number and we will contact you within 1 hour.
By submitting you accept our privacy policy.