Palo Alto Networks for business: managed NGFW firewall and Cortex XDR

We are an official Palo Alto Networks partner. We design, deploy and operate the perimeter and the endpoint, and feed all their telemetry into our SOC’s SIEM so it is watched 24x7.

Palo Alto Networks is one of the reference vendors in network security. Its next-generation firewall (NGFW) identifies traffic by application and by user —not just by port and IP— and inspects content with Threat Prevention, the WildFire sandbox, advanced URL filtering and DNS Security; GlobalProtect covers remote access and Panorama the central management of multiple sites. IBERSYA is an official Palo Alto Networks partner: we license, design and deploy the perimeter, migrate from the previous firewall and operate it from our managed SOC in Spain, feeding firewall logs and Cortex XDR detections into our SIEM, with 8x5 technical analysis and automated 24x7 response. It is the premium alternative to our Fortinet FortiGate standard and to the Bitdefender GravityZone EDR included in the SOC price.

Official Palo Alto Networks partner

A top-tier perimeter only protects if somebody reads what it records

Most powerful firewalls are underused: inherited policies, any-any rules and logs nobody reviews. The value lies in the design and in continuous operation.

Application-level control

Policies based on App-ID and User-ID, not ports: you allow the specific application, not the range.

Real segmentation

Isolating servers, OT environments and guests to contain an incident before it spreads.

Telemetry in the SIEM

Perimeter logs are correlated with those from endpoints and Microsoft 365.

Operated from Spain

Design, changes and policy review handled by the IBERSYA technical team.

What we deploy and operate from Palo Alto Networks

From the perimeter to the endpoint, with policy design and day-to-day operation included in the service.

PA-Series and VM-Series NGFW

Physical and virtual firewalls running PAN-OS: traffic identification by application and user, encrypted traffic inspection and intrusion prevention.

Threat Prevention and WildFire

IPS, network antivirus and anti-spyware, plus the WildFire sandbox to analyse unknown files before letting them into the network.

URL Filtering and DNS Security

Blocking navigation to malicious sites and DNS resolutions linked to phishing, newly registered domains and command-and-control channels.

GlobalProtect

Remote access and home working under the same security policy inside and outside the office, with device posture checks before connecting.

Panorama

Central management of every firewall in the organisation: shared policies, change control and unified visibility across multiple sites.

Cortex XDR

Endpoint protection and extended detection, correlating device, network and identity activity. The premium alternative to the EDR included in the SOC.

Perimeter plus SOC

What our SOC watches on your firewall

Firewall logs are one of the SIEM’s most valuable sources, and one of the least reviewed. These are the events that raise an alert in our circuit.

1

Configuration changes

Immediate notice of any policy or rule modification, with a record of who made it and when.

2

Brute-force attacks

Detection of repeated access attempts against the VPN, device administration or published services.

3

Suspicious access

VPN sign-ins from locations or at times incompatible with the user’s usual activity.

4

C2 connections

Traffic towards command-and-control infrastructure: the clearest sign that an internal machine is already compromised.

5

Correlation with the endpoint

An isolated network event may be noise; alongside a detection on the same user’s machine, it is an incident.

6

Automated 24x7 response

On serious indicators the IP is blocked or the affected host isolated without waiting for human validation.

How to choose

Palo Alto Networks or Fortinet FortiGate

We work with both vendors and both integrate into the SOC. The choice comes down to the size of the environment, the number of sites and the requirements the organisation brings with it.

CriterionFortinet FortiGatePalo Alto Networks
Position in the serviceStandard for SMEs and mid-sized businessesPremium option by requirement or environment
CostBest cost-to-capability ratioLarger investment in hardware and subscriptions
Traffic controlDeep packet inspection and IPSIdentification by application and user with App-ID and User-ID
Multi-siteSD-WAN and management with FortiManagerCentral management with Panorama
Telemetry in our SIEM€60/month add-onIntegration included in the service design
Typical fitOne or few sites, homogeneous estateMultiple sites, strict segmentation, OT environments or a group requirement

If you already have a Palo Alto firewall installed, nothing needs moving: we review the policy design, connect the logs to our SIEM and the perimeter becomes monitored.

Does your firewall log everything and nobody review it?

Request a proposal

Design, migration and continuous operation of the perimeter

A badly configured next-generation firewall behaves like a firewall from fifteen years ago: permissive rules inherited from the migration, inspection disabled for performance and logs nobody looks at. We run the project the other way round: first an inventory of real applications and flows, then policies by application and user, and finally the migration with a planned rollback window.

  • Inventory of applications, flows and sites before sizing the hardware
  • Policy design by application and user, and segmentation of servers and OT
  • Migration from the previous firewall with a planned rollback window
  • Secure publishing of services and remote access with GlobalProtect
  • Connection of logs to our SIEM and periodic review of stale rules
Palo Alto Networks next-generation firewall at a company network perimeter

Frequently asked questions about Palo Alto Networks

What is Palo Alto Networks and which products do you deploy?
Palo Alto Networks is a cybersecurity vendor best known for its next-generation firewall (NGFW). We deploy and operate its PA-Series and VM-Series firewalls running PAN-OS, central management with Panorama, remote access with GlobalProtect, the security subscription services (Threat Prevention, WildFire, Advanced URL Filtering and DNS Security) and the Cortex XDR endpoint and XDR platform.
Is IBERSYA a Palo Alto Networks partner?
Yes. IBERSYA is an official Palo Alto Networks partner. We handle licensing, firewall design and deployment, definition of policies by application and user, migration from the previous perimeter device, and continuous operation from our SOC in Spain, feeding firewall and Cortex XDR telemetry into our SIEM.
What is the difference between a Palo Alto firewall and a Fortinet firewall?
Both are next-generation firewalls with deep inspection, IPS, web filtering and VPN. Fortinet FortiGate is our standard option for SMEs and mid-sized businesses because of its cost-to-capability ratio, and its telemetry integrates into the SOC as a €60/month add-on. Palo Alto Networks is the premium alternative: granular control by application and user with App-ID and User-ID, the WildFire sandbox and central management with Panorama that fits better in multi-site environments or where corporate requirements are demanding.
Can you integrate my Palo Alto firewall into the IBERSYA SOC?
Yes. We connect the firewall logs to our SIEM and the SOC starts watching the perimeter: configuration changes, brute-force attacks, suspicious VPN and administrative sign-ins, and connections towards command-and-control servers. Those events are correlated with endpoint telemetry, so an anomalously used credential plus a suspicious connection stop looking like coincidence.
What is Cortex XDR and how does it fit with the SOC?
Cortex XDR is Palo Alto Networks’ extended detection and response platform: it protects the endpoint and correlates that information with network and identity telemetry. It is the premium alternative to the Bitdefender GravityZone EDR included in the SOC price. When an organisation runs Cortex XDR, we feed its detections into our SIEM and handle them through the same circuit: 8x5 technical analysis, threat-intelligence enrichment and automated 24x7 response.
Is Palo Alto Networks suitable for an SME?
It depends on the case. For most SMEs of 20 to 100 employees, a well-configured FortiGate covers the need at a significantly lower cost. Palo Alto makes sense when there are several sites to manage centrally, strict segmentation requirements, an industrial or OT environment that has to be isolated, or a parent company or customer that imposes the vendor. We do that analysis before proposing anything.
How much does a Palo Alto Networks firewall cost?
The cost has two parts: the appliance or virtual instance, and the annual security subscriptions (Threat Prevention, WildFire, URL filtering, DNS Security and support). It is quoted case by case according to bandwidth, number of users and sites to cover. The IBERSYA SOC service is billed separately, per device per month, from €6 per device/month.
Does a Palo Alto firewall help with NIS2 or the Spanish National Security Framework?
It contributes, but it is not enough on its own. NIS2 and the ENS require network segmentation, access control, detection capability and incident traceability. The firewall provides the segmentation and the control; the centralised event logging, the correlation and the incident report come from the SOC. It is the combination of a managed firewall plus a SOC that produces evidence an auditor can use.

Request a Palo Alto Networks proposal

Tell us how many sites you have, which firewall you use today, how many remote users and whether there is an industrial environment. With that we can size the hardware and the service.

Phone 665 87 93 46
Hours Monday to Friday: 8:00 - 20:00
We call you!
Shall we call you?

Leave your phone number and we will contact you within 1 hour.