We performed a comparison between Cisco IOS Security and Palo Alto Networks NG Firewalls based on real PeerSpot user reviews.
Find out in this report how the two Firewalls solutions compare in terms of features, pricing, service and support, easy of deployment, and ROI."One of the valuable features is a standardized OS."
"The simplicity of the configuration and the stability of the product are most valuable. The VPN concentrator is very useful."
"It has very easy management and an amazing ETM configuration."
"Easy to use support and licensing portal as well as activation process."
"FortiGate's web and URL filtering are unlike any other firewall I've used. The functionality of URL filtering in those solutions is problematic because everything is encrypted, and firewalls can't break that encryption protocol. Fortinet has an SSL proxy, so the encryption is done before the packet ever leaves the FortiGate. The URL filter is definitely one of the most helpful features."
"The interface is very user-friendly and I like it very much."
"The solution is very user-friendly."
"The application control features, such as Facebook blocking and Spotify blocking, are the most valuable."
"The VPN is the most valuable feature."
"Cisco is head-and-shoulders above all of the competition when it comes to technical support."
"You can scale it when you need to."
"Completely integrates branch offices with perimeter security."
"The solution is easy to use."
"Cisco IOS allows us to keep the same security features as our principal offices."
"Cisco has always been a premium product. There's a lot of other entry-level solutions. This is more robust."
"Cisco IOS Security is a mature product with extensive capabilities, serving as the base for the defense layer. It offers good network visibility, which helps in rapid response through the Rapid Threat Containment feature. Its deployment and configuration are straightforward."
"Compared to other firewalls from Check Point, Fortinet, and Cisco, for example, Palo Alto Networks NG Firewalls use the most advanced techniques. They have sandbox integration and others in the orchestrator. Palo Alto's security features are at a higher level than those of the competitors at the moment."
"I like all the functions and features."
"I like that they are more stable than the previous ones, and they allow a lot of other features."
"The user ID, Wildfire, UI, and management configuration are all great features."
"The fact that the Next-Gen firewalls are integrated with identity is the best. It gives us the ability to track what an individual is doing and helps us provide access to only what they need in order to do their job."
"Palo Alto NGFW provides a unified platform that natively integrates all security capabilities, which is very useful. This prevents us from having to go to a lot of different systems, and in some cases, many different systems in many different regions, because we are a global company with 60 remote offices around the world in 30 different countries. Its centralized platform is really what we look for in all services, whether it be security or otherwise."
"Some of Palo Alto Networks NG Firewalls' valuable features are their powerful capabilities and user-friendliness."
"Decryption is one of Palo Alto Networks NG Firewalls' best features because we can decrypt by category. For instance, we can decrypt everything except for bank traffic so that we don't interfere with the passwords and two-factor authentication of those checking their bank accounts at work. We can still monitor for malware and other threats that come through a secure channel. It's seamless for users. The URL filtering and IPS are both great as well."
"Bandwidth usage in reporting could be improved for Fortinet FortiGate."
"If I had any criticism that I would give FortiGate, it would be that they need to stop changing their logging format. Every time we do a firmware upgrade, it is a massive issue on the SIM. Parsers have to be rebuilt. Even the FortiGate guys came in and said that they don't play well in the sandbox."
"Fortinet FortiGate could improve by having more capabilities for troubleshooting VPN connections. For example, I do get some feedback about the current status, but I could use some history and logging of important events. The information is logged in our Syslog server, but I could use that information from the device. If they could provide a GUI to have some more insight on what's going with my VPN would be useful."
"Fortinet FortiGate could improve by having better visibility. Palo Alto has better visibility."
"A lack of integration between our data centers."
"Monitoring and reporting could be better."
"The sniffing packets or packet captures, can be simplified and improved because it's a little confusing."
"Its reporting capabilities can be improved. It should have some out-of-the-box reporting capabilities and some degree of customization. The basic reporting that it currently has is not sufficient to create more usable reports. It needs some sort of out-of-the-box reporting. They try to make customers purchase FortiAnalyzer for this kind of reporting, which is an additional cost. Other firewall vendors, such as SonicWall and Sophos, provide this sort of reporting without any additional cost."
"The pricing is the only con for this product."
"I think setup could be one area for improvement, because sometimes we don't have people inside so we have to move to the place."
"The user interface needs to be improved."
"We cannot directly upgrade the system. The tool's deployment is also very difficult in legacy environments. The tool needs to have bigger ports as well."
"In the security portfolio from Cisco, the issue is marketing. Cisco is still seen primarily as an enterprise network player rather than being acknowledged as a security vendor."
"I think they should bring back remote VPN for users."
"It takes too much time to deploy a policy to FMC. It takes around eight minutes. You can't afford any downtime when you're changing policies."
"I would like to see much more embedded security that works and that isn't a bolt-on."
"Palo Alto should improve their support. It's sometimes difficult to get the right technician or engineer to fix the problem as soon as possible."
"I would like them to improve their GUI interface, making it more user-friendly."
"People sometimes find it more expensive as compared to other solutions. There are also fewer training opportunities for Palo Alto than Cisco and other vendors."
"Need improvement with their logs, especially the command line interface."
"The level of control and granularity in terms of rule customization could be enhanced. However, compared to our previous solution, Palo Alto provides much better drill-down capabilities."
"We would like to see improvement in the web interface for this solution, so that it can handle updates without manual intervention to put the data in order."
"The built-in machine learning features provide some automation, but I think there should be an option for manual review because nothing replaces the human eye."
"Over the past one or two years, Palo Alto Networks has added a lot of features into the NG Firewall products. I think this is becoming more complicated for our customers. Therefore, we could use some best practices, best practice tools, and implementation guides for some of the complicated features."
More Palo Alto Networks NG Firewalls Pricing and Cost Advice →
Cisco IOS Security is ranked 22nd in Firewalls with 47 reviews while Palo Alto Networks NG Firewalls is ranked 6th in Firewalls with 164 reviews. Cisco IOS Security is rated 8.0, while Palo Alto Networks NG Firewalls is rated 8.6. The top reviewer of Cisco IOS Security writes "User-friendly and excels in documentation, making it easier to resolve issues". On the other hand, the top reviewer of Palo Alto Networks NG Firewalls writes "We get reports back from WildFire on a minute-by-minute basis". Cisco IOS Security is most compared with Cisco Secure Firewall, Meraki MX, Fortinet FortiOS and Netgate pfSense, whereas Palo Alto Networks NG Firewalls is most compared with Check Point NGFW, Azure Firewall, Meraki MX, Sophos XG and Netgate pfSense. See our Cisco IOS Security vs. Palo Alto Networks NG Firewalls report.
See our list of best Firewalls vendors.
We monitor all Firewalls reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.