Discover Configuration Defects
Paid Falco tiers continuously scan your devices for hard-to-catch misconfigurations and notify your team when risk increases.
Falco continuously audits firewall and Panorama configurations, scores risky security rules, flags drift, and gives your team clear remediation guidance.
Combine the automated insights from Falco with expert guidance from our team to improve your security posture and reduce risk across your Palo Alto fleet.
Paid Falco tiers continuously scan your devices for hard-to-catch misconfigurations and notify your team when risk increases.
Once you've identified the misconfiguration, you can rely on our guidance and links to relevant documentation to quickly address the issue.
Go beyond configuration health with on-demand scans, configuration backups, license visibility, and vulnerability management across your fleet.
We built Falco to solve the problems we faced as network engineers managing lots of Palo Alto Networks firewalls. Staying on top of configuration drift, misconfigurations, and vulnerabilities across your fleet is hard, especially for smaller teams.
Our customers asked for a solution that would continuously audit their devices and alert them to issues as they arise, so we built Falco to do just that. We also know that finding configuration defects is only half the battle, so we built in detailed remediation guidance and links to relevant documentation for every issue we surface.
Enterprise Falco gives your team access to over 700 curated External Dynamic Lists that help keep your policy current for cloud platforms, SaaS services, and vendor infrastructure that frequently changes IPs or URLs.
Instead of manually maintaining whitelists for Microsoft 365, cloud providers, and other moving dependencies, your engineers can work from a large catalog that is ready to operationalize in your Palo Alto environments.
Enterprise Command Center helps your team execute operational commands across multiple firewalls from one place, which is especially useful when you need quick answers during troubleshooting or validation work.
That means less repetitive clicking across device UIs and more consistent execution when your engineers need to gather state, confirm changes, or support incident response at speed.
Plans
Start with clear configuration visibility, then move to continuous monitoring when your team is ready.
Most Popular
Continuous auditing, alerting, config backups, and access to our support team.
Unlock advanced features and work closely with our expert engineers.
| Feature | Lite | Standard | Enterprise |
|---|---|---|---|
| Automated PAN Configuration Audits | Yes | Yes | Yes |
| Panorama Support | Yes | Yes | Yes |
| PAN-OS Vulnerability Scanning | Yes | Yes | Yes |
| Config Scan Interval | Monthly | Hourly | Hourly |
| Connected Devices | Unlimited | Unlimited | Unlimited |
| On-Demand Scans and Check Refreshes | No | Yes | Yes |
| Config Regression Alerts | No | Yes | Yes |
| VSYS Support | Yes | Yes | Yes |
| Access to our Support Team | No | Yes | Yes |
| Hourly Config Backups | No | Yes | Yes |
| Rule Analysis Workspace | No | No | Yes |
| Access to 400+ EDLs | No | No | Yes |
| Run commands on multiple devices at once (Command Center) | No | No | Yes |
| Automatic Check Remediation via Playbooks | No | No | Yes |
| Tickets and Meetings | N/A | Flexible by contract | Flexible by contract |
| Response Times | Lite | Standard | Enterprise |
|---|---|---|---|
| Critical | N/A | < 8 hours | < 8 hours |
| High | N/A | < 2 days | < 2 days |
| Normal | N/A | < 4 days | < 4 days |
Ready to improve your firewall security posture?