We performed a comparison between Fortinet FortiGate-VM and Palo Alto Networks NG Firewalls based on our users’ reviews in five categories. After reading all of the collected data, you can find our conclusion below.
Features: Fortinet FortiGate-VM is highly regarded for its robust security features, including geofencing, firewalling, IPS, antivirus, and a user-friendly interface. Palo Alto Networks NG Firewalls excel in embedded machine learning, real-time attack prevention, and the ability to accurately identify applications.
Fortinet FortiGate-VM needs enhancements in key activation, log management, cloud management, MFA offerings, web filter options, application inspection, GUI features, bandwidth issues, VPN connectivity, pricing, performance, and documentation. Palo Alto Networks NG Firewalls require improvements in SD-WAN customization, best practices, machine learning capabilities, troubleshooting tools,next-generation capabilities, rule creation, monitoring interface, bug fixing, configuration support, IoT security, traffic shaping, machine learning for virus prevention, security functions, usability, training programs, SSL inspection, external dynamic list feature, internet filtering, API integration, and bug fixing.
Service and Support: Some customers have praised the support team of Fortinet FortiGate-VM for their quick response times and knowledge. However, other customers have mentioned slow response times and difficulties in finding information quickly. Customer service for Palo Alto Networks NG Firewalls has received mixed reviews. Some customers have praised the knowledgeable support team and timely issue resolution. However, others have mentioned difficulties in reaching the support team and issues with the support ticketing system.
Ease of Deployment: The setup process for Fortinet FortiGate-VM is generally straightforward and easy, while Palo Alto Networks NG Firewalls is not complex and easy. Prior knowledge can simplify Fortinet's setup, whereas Palo Alto may require proper planning.
Pricing: Fortinet offers flexible pricing options with no extra expenses, while Palo Alto is considered pricier. Nevertheless, Palo Alto is known for its reliability and high performance as a firewall solution.
ROI: Fortinet FortiGate-VM offers enhanced stability and heightened security. Palo Alto Networks NG Firewalls provide greater visibility, reporting capabilities, and streamlined management.
Comparison Results: Fortinet FortiGate-VM is the preferred solution as it is highly recommended due to its easy setup, robust security features, cost-effectiveness, and satisfactory ROI. Users find it user-friendly, easy to deploy, and with an intuitive interface.
"It's a user-friendly firewall. Most of the tasks are very simple. It's simple to configure and troubleshoot this firewall."
"The most valuable features of Fortinet FortiGate are remote access, web filtering, and IPS."
"Fortinet FortiGate's reliability is valuable."
"It's super reliable. I don't think I've ever had a reliability issue with it."
"The most valuable feature of this solution is the analytics."
"FortiGate has a very strong unified threat management system."
"The threat prevention is the solution's most valuable aspect."
"The SD-WAN function is very developed. It has SD-WAN functionality with security features in one device. We can manage from one single console SD-WAN and the security policy."
"The most valuable features are the web proxy for protection and web gateway for deployment."
"I did like the ability to back up the configuration into the cloud, as opposed to having to store the configurations or just downloading them, the backups, to local devices."
"It provides an ease of management and configuration as well."
"The user interface is the most valuable aspect of the solution."
"The most valuables features are the ease of use and deployment."
"FortiGate-VM's firewall is excellent."
"The product can scale."
"In spite of the solution being inexpensive, it has everything one would need."
"I like all the threat alerts and WildFire. I also like scanning because everything that comes into our network via customers is scanned. We're an electric company, so every one of the bills is scanned and emailed in and out of our network."
"I like that they are more stable than the previous ones, and they allow a lot of other features."
"One of the key features for us is product stability. We are a bank, so we require 24/7 service."
"We have not had to replace hardware routers nor purchase additional hardware. So, that has provided a little bit of an ROI."
"The key aspect of this solution that provides the most value is its next-gen capabilities, which represented a significant change for us."
"The basic configuration will only take 15 minutes to set up"
"The most valuable feature of the solution is the network protection."
"The initial setup process is quite easy."
"The security of Fortinet FortiGate could improve."
"The solution could be more secure and stable."
"The main aspect of FortiGate that could be improved is load balancing. Our management team does not want to buy another appliance for only load balancing."
"This product needs to have an analysis feature, rather than having the analysis done through the integration of a different product."
"We would like to have the ability to disable some of the security functionalities."
"You do need some IT knowledge in order to effectively work with the solution."
"The pricing could be a bit better, especially when you consider how they have the most basic offering priced."
"My only complaint about FortiGate is a lack of QinQ VLAN tunneling. I haven't found this feature in any Fortinet product. You can do this on all Cisco routers, including the smaller models. However, QinQ isn't available on the biggest, most expensive Fortinet units. They still don't have that. I think now we're on software version 6.0, and they still haven't found a solution for QinQ. It isn't a dealbreaker, but that's my main complaint."
"We are experiencing a failed login issue. There should also be improvements in functionalities we store to enhance our services."
"The one thing that could be improved is the integration with the exchange. The gateway level controls can be enhanced a bit more. For example, it's still little here and there. You do get malicious attacks and suspicious emails like spam. It's not like Sophos where we got a lot of spam email, and yet, it's still relatively vulnerable. It can be upgraded, maybe with a fifth-generation firmware that it is ready for unknown threats."
"It is difficult to size the VM in terms of machine resources, and for this reason, clients prefer the appliance."
"Technical support could be improved."
"We'd like to have more customization and easier customization of policies."
"Right now, we have two data centers that are a thousand kilometers apart. It would be nice to be able to string them together."
"The key activation is very complicated at times."
"Capacity-wise, I think the solution's log storage area is something that needs to be increased since, by default, it stores logs for only seven days."
"The biggest thing that needs to be improved with them is their training. I took a training class for the 8.0 build, then I took it again for the 9.0 and 10 builds. They add new features every time that they do a new major release, but the training doesn't keep up. It is the same basic training that probably was with the 3.0 build, and they just change the screenshots. I would love to see them do some more work since they have all these bells and whistles, but we don't know how to use those features on a large scale."
"Having a better pricing model would make this product more competitive, and more affordable for our customers."
"The VPN has room for improvement."
"We have not taken Palo Alto's firewall management solution because it's too expensive and we don't feel it delivers significant value."
"Could also use better customer support."
"I would like a collaboration system and reporting ASA policy needs to be smarter."
"I'm thinking about a new feature. They have decryption. It's a good idea to use decryption on Palo Alto. It would be good if they had offloading of the traffic, and if they could decrypt the traffic and offload it. Like, for example, ASM on our site. We have an SSL decryption to offload the traffic. We could use that on Palo Alto."
"Surfacing actionable intelligence right away could be better. You have to dig far to get some of the information. If the solution could surface the two or three things out of the 10,000 a day that we really need to deal with, it would be helpful."
More Palo Alto Networks NG Firewalls Pricing and Cost Advice →
Fortinet FortiGate-VM is ranked 9th in Firewalls with 113 reviews while Palo Alto Networks NG Firewalls is ranked 6th in Firewalls with 161 reviews. Fortinet FortiGate-VM is rated 8.4, while Palo Alto Networks NG Firewalls is rated 8.6. The top reviewer of Fortinet FortiGate-VM writes "An easy-to-manage and configure tool that provides ample documentation to help with the setup phase". On the other hand, the top reviewer of Palo Alto Networks NG Firewalls writes "We get reports back from WildFire on a minute-by-minute basis". Fortinet FortiGate-VM is most compared with Azure Firewall, Palo Alto Networks VM-Series, Fortinet FortiOS, OPNsense and Netgate pfSense, whereas Palo Alto Networks NG Firewalls is most compared with Check Point NGFW, Azure Firewall, Meraki MX, Sophos XG and Netgate pfSense. See our Fortinet FortiGate-VM vs. Palo Alto Networks NG Firewalls report.
See our list of best Firewalls vendors.
We monitor all Firewalls reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.
In the best tradition of these questions, Feature-wise both are quite similar, but each has things it's better at, it kind of depends what you value most.
PA is good at app control, web filtering and such like, they have always been top of the pile there. The GUI is very good, and their product is very user-focused.
Fortinet is good for scalability and predictable high throughput (ASICs in the hardware), and useful things like authentication flexibility, CLI config (if you have any networking/Cisco people, they always seem to prefer CLI over GUI) and have better OT features, maybe relevant to your manufacturing use?
Fortinet seem to have a broader integration offering with their security fabric than PA do, plus they can do Fortinet-based wifi, switching, etc. Depends if you are prepared to go all-in with a single vendor.
Hi,
Both FT and PA have compelling features for large Enterprises. I would like to add a few good points about Fortinetwhich might be helpful ( from my 13 years of engagement with them as Distributor and Partner)
Fortinet:
Have higher throughput; which comes with competitive rates
Wide range of models to select to meet your requirement, without spending heavliy
Outstanding customer support and very active customer care team
Easly available skilled resources from the channel for deployment and post-implementation support
Regards
Abhilash
Hello. The question is what you are going to have as a result of application