The enterprise VPN attached to your NGFW, versus a network that never needed the gateway in the first place.
| OpenVLAN | GlobalProtect | |
|---|---|---|
| Gateway dependency | None — mesh | PAN-OS gateway (appliance/VN) |
| License | Per user, published | GP subscription on top of firewall |
| Client size & updates | Light, auto-update | Heavier; version-matrix with PAN-OS |
| Remote work scaling | Peer-to-peer, no hairpin | Traffic via gateway capacity |
| Split tunnel policy | Moot — per-user ACLs | Configured + debated |
| Posture checks | Device posture in ACLs | HIP profiles |
| Time to value | Minutes | Gateway, certs, portal config |
Panorama manages everything, HIP posture drives policy org-wide, and the VPN is one line item in a full PAN estate.
Gateway capacity tickets, client upgrade matrices, and split-tunnel arguments are the pain — not the firewalling itself.
Palo Alto stays at the perimeter; GlobalProtect retires. Users reach resources over OpenVLAN; the internet still passes the NGFW.