Services
Partners
Use cases
Clients
Company
Contact
FRENDE
Technology partner

Palo Alto Networks integrator in Switzerland

We design and operate Palo Alto Networks architectures, from the perimeter firewall to endpoint detection. Three certifications in the team, including PCNSE and PSE Strata Pro.

Why this vendor

Palo Alto Networks built its reputation on one precise technical point: application identification. Where a classic firewall reasons in ports and addresses, App-ID names the application whatever port it travels on, and User-ID attaches an identity to it rather than a machine. A policy then stops being a list of flows and becomes a readable sentence: who is allowed to use what.

That is what makes segmentation sustainable over time. A rule written in applications and user groups survives a change of addressing, a server migration, the arrival of a new application version. A rule written in ports survives nothing, and that is how policies become, within a few years, a pile nobody dares touch.

The downside is well known: that precision has a design cost. A poorly scoped Palo Alto deployment produces a verbose policy that is slow to evaluate. This is exactly where we come in — the value is not in powering up the appliance, it is in the structure of the policy and the discipline of maintaining it.

We cover the full cycle: audit of the existing estate, design, proof of concept, migration in waves, then operations or a handover.

Palo Alto Networks
What we bring
  • PCNSE, PCNSA and PSE Strata Pro in the team
  • Policy design in App-ID and User-ID
  • Migration from a third-party firewall, in waves
  • Taking over policies that have become unmanageable
  • Central administration through Panorama
Vendor website
Diagram

The architecture, from perimeter to cloud

Palo Alto Networks architecture: central administration and four domains Next-generationfirewallsPA-SeriesVM-SeriesAccess and SASEPrisma SASEPrisma BrowserDetection andcloudCortex XDRCortex CloudAI securityPrisma AIRSPanoramaone policy, unified logsPanorama
Panorama at the centre: a single policy, pushed to every firewall whatever its form — hardware, virtual or service.

The products we integrate

From the firewall to the cloud, under a shared policy. Not every building block is justified on the same project — sorting them is part of the work.

Next-generation firewalls

The PA-Series covers the physical perimeter, from the branch office to the data centre, with TLS decryption and application inspection. The VM-Series carries the same policy into virtualised and cloud environments — which is what lets you write a rule once and apply it everywhere, rather than maintain two sets that drift apart.

PA-SeriesVM-Series

Central administration

Panorama pushes configuration across the estate, keeps the change history and allows rollback. It also aggregates logs, which is the precondition for correlating a perimeter event with an endpoint event. Without it, each firewall becomes an island — and configuration debt settles in without anyone seeing it.

Panorama

Remote access and SASE

Prisma SASE applies the corporate policy to users outside the walls without backhauling their traffic to headquarters, which settles both the latency and the load on the central link. Prisma Browser handles unmanaged endpoints — contractors, personal devices — by confining access to a corporate browser rather than opening a tunnel into the network.

Prisma SASEPrisma Browser

Detection and response

Cortex XDR correlates endpoint, network and cloud signals into one timeline. The point is not to multiply alerts but to bring them together: one incident stops appearing as three unrelated events in three different consoles.

Cortex XDR

Cloud security

Cortex Cloud covers the chain from code to runtime: application security upstream, cloud posture, and protection at the moment the container runs. The value lies in the shared context — a vulnerability in an image becomes a wholly different priority depending on whether that image is deployed in production and exposed, or sleeping in a registry.

Cortex Cloud

Artificial intelligence security

Prisma AIRS answers a recent and real need: applications built on language models expose a surface that classic controls do not see — prompt injection, leakage through the response, undeclared use of an external service. We treat it as an architecture question, not as a product to install.

Prisma AIRS
The starting point

On an existing estate we always start with Panorama and with the policy audit: rules never triggered, orphaned objects, duplicates, rules that shadow one another. It is the least spectacular and most profitable work — everything else depends on it, and it often reveals that the problem was never the appliance.

Panorama

Our Palo Alto Networks certifications

Three badges held within the team, including the PCNSE engineer certification and the PSE Strata Pro pre-sales track.

PCNSE — Palo Alto Certified Network Security Engineer
PCNSEPalo Alto Certified Network Security Engineer
PCNSA — Palo Alto Certified Network Security Administrator
PCNSAPalo Alto Certified Network Security Administrator
PSE Strata Pro — System Engineer — Hardware Firewall Professional
PSE Strata ProSystem Engineer — Hardware Firewall Professional
Our approach

How we proceed

A firewall migration is not decided on cutover night but in the weeks before it, on the rule mapping table.

Palo Alto Networks integration approach, from audit to operations ScopingImplementationDuration01Policyaudit02App-IDdesign03Proof ofconcept04Migrationin waves05Tuning andacceptanceOperationsor handover
Policy cleanup comes before migration: moving a policy you have not cleaned simply carries the debt from one appliance to the next.
Frequently asked questions

Frequently asked questions

Yes, it is a significant part of what we do. The technical migration is tooled; the real work is translating the policy. A port-based rule does not convert mechanically into an application rule — you have to observe the real traffic, identify what actually passes, and write the target policy. That is what takes time, and it is what separates a successful migration from a deferred debt.

Not in itself. What costs is a badly structured policy: too many rules, poorly ordered, with decryption applied where it adds nothing. Sizing is calculated on decrypted traffic and on the features enabled, not on the raw throughput of the link — the most frequent sizing error we encounter.

Not necessarily, but from the second one, yes. Two appliances administered separately drift apart within months, and reconciling them costs more than the tool. Panorama also brings the change history, which is the first thing anyone looks at when something has started to misbehave.

Yes, through our support and managed service offering: day-to-day operations, upgrades, policy changes and incident handling. Or through a handover, if your teams take it on — we then document the architecture and remain available for structural changes.

A policy to design or to take over?

Describe your situation — on an existing estate, we always start by looking at the policy in place.