Are you sure, that PAN is ‘it’? If you ask CheckPoint, they will say, it’s crap…
Sure, Gartner has put PAN heaven high in their latest quadrant, but more I look at Gartner, more I believe, they give away points for best storytelling. No doubt, PAN is the greatest, when it comes to tell you a story (usually these begin with ‘Only we…’ or ‘We are the only…’).
Another analyst, NSS Labs, doesn’t listen at stories, but wants to see facts. Wonder why in their ranking the cards are completely mixed up, not a bit like those of Gartner?
And yet NSS Labs is not ‘it’. They show one aspect, a snapshot in time, that could be completely different a week earlier or later. Also their results may very much depend on the configuration/optimization for their tests (guess that’s why vendors often have very bad results, when they are tested by NSS Labs for the first time).
With 50 users you are still far away from a ‘Large Enterprise’ user as Gartner&Co do see them, when they talk about ‘Enterprises’. Large Enterprise products that are designed for companies with thousands of users may lack SME features YOU will be missing. That may result in adding additional solutions to fill the gap, adding administrative burden, you probably wouldn’t want to have.
I can just recommend not to listen to any of those analysts, stories or smart*****. Take your time and test different products from different vendors. Build your own opinion on each of the solutions and go with the one, that best fits your company and your way of managing the network. Having an ‘unlimited’ budget is great - but that doesn’t mean, that the most expensive solution out there has to be the one, that will be the best for you. Sometimes much cheaper solutions can be really surprising…
In terms of ‘rightsizing’ the solution, you should be very careful about VLAN’s and LAN segments. E.g. the PA-3000 series goes from 2 up to 4Gbps firewall throughput. If you have a lot of intra-VLAN routed traffic, than just the VLANs could already consume 1Gbps - or even more. If you than add a datacenter segment and have some VLANs inside that too, than the small PA-3020 could start becoming a bottleneck at some point.
I think, that your Sonicwall allows you to collect enough statistics, to be able to foresee how heavy traffic you may expect on your segments and VLANs. Use this information to rightsize the appliance model you will choose. And don’t forget to add 50-100% for future growth!