Practice · Palo Alto Networks
Palo Alto Networks engineering, delivered by someone who actually runs the platform.
Led by Jack Miller, PCNSE. We design, deploy, migrate, and continuously optimize the full PAN stack: because the platform only delivers when it’s run by people who understand it deeply.
The full PAN portfolio.
Most engagements touch two or three of these. We can lead any of them end-to-end.
PA-Series, VM-Series, CN-Series
Hardware appliance design, virtual firewall deployments in VMware/Hyper-V/cloud, and CN-Series for containerized workloads. HA design, routing integration, decryption planning.
Panorama centralized management
Proper Panorama architecture, scalable device-group design, and migrations from messy local management to centralized control.
Cortex XDR, XSIAM, XSOAR
Endpoint deployment, alert tuning, exclusions done right, integrations with identity and email security, and SOAR playbook design for repeatable response.
Prisma Access & Prisma Cloud
Mobile-user and remote-network design for Prisma Access (SASE), and posture management plus runtime protection across major clouds with Prisma Cloud.
Strata Cloud Manager
Unified management onboarding, SD-WAN where it fits, AIOps recommendations triage, and integrating SCM with existing Panorama estates.
Health checks & rule cleanup
Policy hygiene, shadowed/unused rule cleanup, App-ID conversion from port-based, decryption coverage gaps, and threat-prevention tuning.
How we get hired.
Greenfield deployment
Architecture, sizing, build, cutover. From a single PA-Series pair to multi-site Panorama-managed estates.
Migration from another vendor
Legacy firewall to PAN with proper App-ID conversion: not just a translated rulebase that re-creates the old problems.
Policy optimization
Shadow rule audits, rule consolidation, App-ID and User-ID adoption, decryption rollout, and threat-prevention tuning that actually reduces noise.
Panorama design or rebuild
Device-group and template hierarchies built to scale: not the organic mess that grows when nobody planned the structure.
Cortex XDR rollout & tuning
Endpoint coverage, exclusion strategy, IOC and BIOC tuning, response actions, and SOC integration.
Threat hunting & detection tuning
Hunting against your own telemetry, detection content tuned to your environment, and BIOCs that catch what the defaults miss.
A misconfigured Palo Alto firewall is still a Palo Alto firewall, but it is a very expensive one. The platform's value comes from App-ID, User-ID, decryption, and threat-prevention features that all require thoughtful design and ongoing care. We have seen too many seven-figure investments running essentially port-based ACLs.
Cisco to Palo Alto, four sites, rebuilt right.
A mid-market client across four production sites, delivered on a six-week timeline. The client is anonymized; the numbers are real.
NGFWs across four sites
Design to final cutover
Downtime per site
Below a competing integrator
The scope
- Full replacement of aging Cisco firewalls with eight Palo Alto Networks NGFWs.
- Greenfield Panorama for centralized policy, logging, and template management from day one.
- Routing redesign from brittle static routes to iBGP across all four sites, enabling dynamic failover.
- Security policy rebuilt from Cisco ACLs into App-ID and User-ID aware rules, not a one-to-one port conversion.
The outcome
- Landed 15 to 20% under a competing integrator's quote, through tighter scoping and direct PAN-OS expertise instead of subcontracted labor.
- 30 to 45 minutes of downtime per site, well inside the maintenance windows the client had negotiated with their business units.
- iBGP convergence removed the manual failover steps the old static configuration required during prior ISP events.
- Within weeks of cutover, threat prevention and URL filtering caught traffic the legacy Cisco policy had been allowing, including outbound connections to known command-and-control infrastructure.
ADK Cyber AI For PAN engineers
Parse policies, audit rulebases, generate config snippets, and troubleshoot CLI output in plain English. Built by Jack, engineered for the engineers who run this platform every day.
Have a Palo Alto project on the horizon?
From a clean greenfield deployment to a tangled Panorama you inherited. Let's talk.