We just raised a $30M Series A: Read our story

Compare Fortinet FortiGate vs. Fortinet FortiGate-VM

Cancel
You must select at least 2 products to compare!
Comparison Summary
Question: How is FortiGate-VM different from the physical FortiGate firewall?
Answer: The root of all is VM. A virtual environment is software running on someone else machine/s. Welcome to the the cloud. Sadly, no one stops to think but with the excuse of "lower costs" many fall for it. Performance is the key word. Avoid VMware and the likes. What appears cheap may have a big price in the end. There is no way performance on your own physical machine will be close to the cloud, and there are heaps more things in the equation. Fortinet appliances have their own semiconductors chips to handle in hardware traffic and other duties. Harry Potter does not exist. Costs or prices, are figures in invoices, but the coefficient of elasticity with time may be a surprise. Needless to say the networking traffic handling and the security implication in multi tenancy instances. Yes, in some things could work, but I personally avoid them as much as I can.
Featured Review
Find out what your peers are saying about Fortinet FortiGate vs. Fortinet FortiGate-VM and other solutions. Updated: November 2021.
554,676 professionals have used our research since 2012.
Quotes From Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:

Pros
"Its Snort 3 IPS has better flexibility as far as being able to write rules. This gives me better granularity.""If you compare the ASA and the FirePOWER, the best feature with FirePOWER is easy to use GUI. It has most of the same functionality in the Next-Generation FirePOWER, such as IPS, IPS policies, security intelligence, and integration and identification of all the devices or hardware you have in your network. Additionally, this solution is user-friendly.""The dashboard is the most important thing. It provides good visibility and makes management easy. Firepower also provides us with good application visibility and control.""The solution offers very easy configurations.""The most valuable features of this solution are the integrations and IPS throughput.""The most valuable feature that Cisco Firepower NGFW provides for us is the Intrusion policy.""It has a good security level. It is a next-generation firewall. It can protect from different types of attacks. We have enabled IPS and IDS.""I have integrated it for incidence response. If there is a security event, the Cisco firewall will automatically block the traffic, which is valuable."

More Cisco Firepower NGFW Firewall Pros »

"Some of the key features of the solution is that it has good reporting, you can receive many details from the connection, for example, clients and website information.""I like that they have given me a solution at a fair price.""The next-generation firewall is great.""The main reason why I purchased the particular unit was that it had good reviews and what other people were saying as far as its completeness and its leading capabilities in terms of endpoint security was very good.""The solution has very good threat and content filtering switches.""The management console is pretty simple, so anyone who understands networking can initially deploy the solution.""Good anti-malware and web filtering features.""Fortinet FortiGate is easy to use."

More Fortinet FortiGate Pros »

"The most valuable feature is the UTM, which gives them an advantage over other firewalls.""The most valuable feature is geofencing, where we can block all access from all non-domestic locations.""The initial setup is very user-friendly.""The EPM bundle is a good feature.""The most valuable features are locking applications from in and out of my test network and testing malware on different devices. I use malware detection, antivirus, and basic firewall policies to check for different types of security breaches. The UI is really nice and easy to use.""Primarily, the VPN solution is most valuable. It allows you to have more flexibility in terms of what is there on the end-user device, and what is not there. You can check and make sure that they're current. It has more flexibility than just a straight VPN solution. It works really well. It has the features that 99% of people need.""I have worked on some of the largest and smallest solutions that Fortinet sells and they all scale really well.""FortiGate-VM has many valuable features: it's easy to use, it's intuitive, it's got very good traffic inspection features, it's got comprehensive filtering categories, and it has an extensive threat database, using FortiGuard."

More Fortinet FortiGate-VM Pros »

Cons
"We're getting support but there's a big delay until we get a response from their technical team. They're in the USA and we're in Africa, so that's the difficulty. When they're in the office, they respond.""The central management tool is not comfortable to use. You need to have a specific skill set. This is an important improvement for management because I would like to log into Firepower, see the dashboard, and generate a real-time report, then I question my team.""The performance should be improved.""The initial setup was a bit complex. It wasn't a major challenge, but due to our requirements and network, it was not very straightforward but still easy enough.""The solution could offer better control that would allow the ability to restrictions certain features from a website.""I would like it to have faster deployment times. A typical deployment could take two to three minutes. Sometimes, it depends on the situation. It is better than it was in the past, but it could always use improvement.""The change-deployment time can always be improved. Even at 50 seconds, it's longer than some of its competitors. I would challenge Cisco to continue to improve in that area.""Cisco Firepower NGFW Firewall can be more secure."

More Cisco Firepower NGFW Firewall Cons »

"There aren't really any negative aspects to discuss.""A lack of integration between our data centers.""The pricing could be a bit better, especially when you consider how they have the most basic offering priced.""Technical support is good but the response time could be faster.""It is stable, but its stability can be improved.""It would be a benefit if Fortinet would release a one-stop solution that is better integrated with other products and an automated emergency response system.""There are some cloud-based features that could be much more flexible than they currently are.""Security is a continuous process. In every product, there is a requirement for improvement. Its pricing should also be improved according to Indian market requirements. They must also improve on the reporting part. Its reporting can be more precise. If we can get a real-time report in a specific format, it will be helpful for customers to know about the current status of their security."

More Fortinet FortiGate Cons »

"I have had a data issue with physical devices that could improve.""We haven't attempted to scale the solution just yet. If we want to scale this solution we may have to look at other models. With certain requirements, we probably wouldn't be able to scale it so well as it is right now.""It should have the SD-WAN feature. This would increase the number of features that are available in the box.""The technical support is not very responsive and is an area that needs to be improved.""The interface needs to be updated and simplified.""There are certain GUI features that should be present but are not.""The one thing that could be improved is the integration with the exchange. The gateway level controls can be enhanced a bit more. For example, it's still little here and there. You do get malicious attacks and suspicious emails like spam. It's not like Sophos where we got a lot of spam email, and yet, it's still relatively vulnerable. It can be upgraded, maybe with a fifth-generation firmware that it is ready for unknown threats.""With FortiGate, we sometimes encounter bugs in various operating systems."

More Fortinet FortiGate-VM Cons »

Pricing and Cost Advice
"Cisco pricing is premium. However, they gave us a 50 to 60 percent discount.""Pricing is the same as other competitors. It is comparable. The licensing has gotten better. It has been easier with Smart Licensing.""I like the Smart Licensing, because it is more dynamic and easier to keep track of where you are at. If we have a high availability firewall pair and they are deployed in active/standby rather than active/active, I would expect that we would only pay for one set of licenses because you are using only one firewall at any one time. The other is there just for resiliency. The licensing, from a Firepower perspective, still requires you to have two licenses, even if the firewalls are in active/standby, which means that you pay for the two licenses, even though you might only be using one firewall any one time. This is probably not the best way to do it and doesn't represent the best value for money. This could be looked at to see if it could be done in a fairer way.""This solution is expensive and other solutions, such as FortiGate, are cheaper.""Cisco is not for a small mom-and-pop shop because of the cost, but if you're in a regulated industry where a breach could cost you a million dollars, it's a bargain.""Its pricing is good and competitive. There is a maintenance cost. It includes SecureX that makes it cost-effective as compared to the other solutions where you have to pay for XDR and SOAR capabilities.""There are additional implementation and validation costs.""The solution was chosen because of its price compared to other similar solutions."

More Cisco Firepower NGFW Firewall Pricing and Cost Advice »

"The price for the device and software is high. However, the solution is of good quality and has a lot of features.""The Indian market is different than the European and American markets. When you compare they need to be a bit more aggressive on pricing.""The pricing of the solution is very competitive.""Fortinet FortiGate's price can be reduced.""It has a competitive price.""It is too expensive for us. My organization is very small, and we have a total of ten users. We have three internal users and seven external users. The FortiGate 100D series is too expensive for renewing the licenses.""It's expensive, but compared to the competition it's okay.""As far as I'm aware, in our case, it's just a yearly pricing arrangement with no additional licensing costs."

More Fortinet FortiGate Pricing and Cost Advice »

"There is no additional cost. Once you get the licensing fee, you're good.""It's a mid-ranged product.""We pay for a yearly license.""With Fortinet FortiGate-VM you can bring your own licensing, or it can be paid on a yearly basis.""The customer must buy his own license.""We are on an annual license for this solution and it could be cheaper.""The price is similar to Symantec Endpoint, but it's more expensive than Forcepoint solutions. Fortinet is better than Forcepoint.""It's not a cheap solution but it comes with its benefits."

More Fortinet FortiGate-VM Pricing and Cost Advice »

report
Use our free recommendation engine to learn which Firewalls solutions are best for your needs.
554,676 professionals have used our research since 2012.
Answers from the Community
Rose Taherzadeh
author avatarLindsay Mieth
Real User

Purpose-built appliances offer tested performance measures and provide proven results for the specified traffic and service configuration.  


VM can only provide vCPUs, RAM, and hard disk resources.  However, in some cloud environments, you only have the VM option, no appliances accepted.  


We have several Fortigate VM firewalls operating for 3 years now in the cloud and appliances in our centers that handle the traffic just fine. We have not had to increase the resources above the recommendations and they work just fine.

author avatarABHILASH TH
Reseller

FortiGate VM 



  • FortiGate-VM delivers the same FortiOS and FortiGuard real-time threat intelligence as the hardware models, in a virtual form factor.

  • FortiGate-VM offers flexible licensing and provisioning for virtual network deployments.

  • Support for multiple virtualizations and cloud platforms.

  • Full support for Forti Hypervisor deployments enabling line-speed security in vCPE requirement.

  • The architecture of a VM is a little more complex than that of Hardware.


  • Virtual machines are less efficient than real machines because they access the hardware indirectly.


FortiGate Hardware



  • The hardware firewall is an ASIC-based device.

  • It has hardware limitation, for example, Memory, CPU, etc

  • Easy deployment in the network

  • No complexity

author avatarWilliam Yragui
User

Fortigate appliance is purpose built with NPU and SPUs designed to increase throughput while maximizing the ability to decrypt packets in search of malware. 


VM deployments are software only and do not include the NPU and SPUs. 

Questions from the Community
Top Answer:  When you compare these firewalls you can identify them with different features, advantages, practices and… more »
Top Answer:  The Cisco Firepower NGFW Firewall is a very powerful and very complex piece of anti-viral software. When one considers… more »
Top Answer: It is easy to integrate Cisco ASA with other Cisco products and also other NAC solutions. When you understand the Cisco… more »
Top Answer: As a solution, Sophos UTM offers a lot of functionality, it scales well, and the stability and performance are quite… more »
Top Answer: In the best tradition of these questions, Feature-wise both are quite similar, but each has things it's better at, it… more »
Top Answer: I have experience on both from Disti and channel experience. Please find below my comments (nothing new as such)… more »
Top Answer: Both of these solutions are excellent options that provide flexible scalability and solid security. Fortinet Fortigate… more »
Top Answer: The most valuable feature is the WAN optimization.
Top Answer: Our licensing costs are of a general nature. There are no additional costs beyond the standard fee.
Comparisons
Also Known As
Cisco Firepower NGFW, Cisco Firepower Next-Generation Firewall, FirePOWER, Cisco NGFWv
FortiGate 60b, FortiGate 60c, FortiGate 80c, FortiGate 50b, FortiGate 200b, FortiGate 110c, FortiGate
FortiGate Virtual Appliance, FortiGate-VM
Learn More
Overview

Cisco NGFW firewalls deliver advanced threat defense capabilities to meet diverse needs, from
small/branch offices to high performance data centers and service providers. Available in a wide
range of models, Cisco NGFW can be deployed as a physical or virtual appliance. Advanced threat
defense capabilities include Next-generation IPS (NGIPS), Security Intelligence (SI), Advanced
Malware Protection (AMP), URL filtering, Application Visibility and Control (AVC), and flexible VPN
features. Inspect encrypted traffic and enjoy automated risk ranking and impact flags to reduce event
volume so you can quickly prioritize threats. Cisco NGFW firewalls are also available with clustering
for increased performance, high availability configurations, and more.
Cisco Firepower NGFWv is the virtualized version of Cisco's Firepower NGFW firewall. Widely
deployed in leading private and public clouds, Cisco NGFWv automatically scales up/down to meet
the needs of dynamic cloud environments and high availability provides resilience. Also, Cisco NGFWv
can deliver micro-segmentation to protect east-west network traffic.
Cisco firewalls provide consistent security policies, enforcement, and protection across all your
environments. Unified management for Cisco ASA and FTD/NGFW physical and virtual firewalls is
delivered by Cisco Defense Orchestrator (CDO), with cloud logging also available. And with Cisco
SecureX included with every Cisco firewall, you gain a cloud-native platform experience that enables
greater simplicity, visibility, and efficiency.
Learn more about Cisco’s firewall solutions, including virtual appliances for public and private cloud.

The FortiGate family of NG firewalls provides proven protection with unmatched performance across the network, from internal segments, to data centers, to cloud environments. FortiGates are available in a large range of sizes and form factors and are key components of the Fortinet Security Fabric, which enables immediate, intelligent defense against known and new threats throughout the entire network.

FortiGate Virtual Appliances allow you to mitigate blind spots by implementing critical security controls within your virtual infrastructure. They also allow you to rapidly provision security infrastructure whenever and wherever it is needed. FortiGate virtual appliances feature all of the security and networking services common to traditional hardware-based FortiGate appliances. With the addition of virtual appliances from Fortinet, you can deploy a mix of hardware and virtual appliances, operating together and managed from a common centralized management platform.

Offer
Learn more about Cisco Firepower NGFW Firewall
Learn more about Fortinet FortiGate
Learn more about Fortinet FortiGate-VM
Sample Customers
Rackspace, The French Laundry, Downer Group, Lewisville School District, Shawnee Mission School District, Lower Austria Firefighters Administration, Oxford Hospital, SugarCreek, Westfield
Pittsburgh Steelers, LUSH Cosmetics, NASDAQ, Verizon, Arizona State University, Levi Strauss & Co. Whitepaper and case studies here
Security7 Networks, COOPENAE
Top Industries
REVIEWERS
Comms Service Provider22%
Financial Services Firm16%
Manufacturing Company8%
Non Profit8%
VISITORS READING REVIEWS
Comms Service Provider32%
Computer Software Company21%
Government7%
Manufacturing Company4%
REVIEWERS
Comms Service Provider14%
Computer Software Company10%
Financial Services Firm8%
Manufacturing Company6%
VISITORS READING REVIEWS
Comms Service Provider36%
Computer Software Company20%
Government5%
Educational Organization4%
REVIEWERS
Comms Service Provider19%
Financial Services Firm13%
Retailer6%
Manufacturing Company6%
VISITORS READING REVIEWS
Comms Service Provider32%
Computer Software Company30%
Government5%
Energy/Utilities Company4%
Company Size
REVIEWERS
Small Business43%
Midsize Enterprise28%
Large Enterprise29%
VISITORS READING REVIEWS
Small Business21%
Midsize Enterprise13%
Large Enterprise66%
REVIEWERS
Small Business48%
Midsize Enterprise25%
Large Enterprise28%
VISITORS READING REVIEWS
Small Business35%
Midsize Enterprise25%
Large Enterprise39%
REVIEWERS
Small Business53%
Midsize Enterprise27%
Large Enterprise20%
Find out what your peers are saying about Fortinet FortiGate vs. Fortinet FortiGate-VM and other solutions. Updated: November 2021.
554,676 professionals have used our research since 2012.

Fortinet FortiGate is ranked 1st in Firewalls with 97 reviews while Fortinet FortiGate-VM is ranked 13th in Firewalls with 58 reviews. Fortinet FortiGate is rated 8.4, while Fortinet FortiGate-VM is rated 8.2. The top reviewer of Fortinet FortiGate writes "Stable, easy to set up, and offers good ROI". On the other hand, the top reviewer of Fortinet FortiGate-VM writes "Slightly unstable, needs a better user interface, and lacks good monitoring capabilities ". Fortinet FortiGate is most compared with Cisco ASA Firewall, pfSense, Meraki MX, Check Point NGFW and SonicWall TZ, whereas Fortinet FortiGate-VM is most compared with Azure Firewall, Palo Alto Networks VM-Series, OPNsense, Cisco ASA Firewall and Sophos XG. See our Fortinet FortiGate vs. Fortinet FortiGate-VM report.

See our list of best Firewalls vendors.

We monitor all Firewalls reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.