Check Point NGFW vs Palo Alto Networks VM-Series comparison

Sponsored
 

Comparison Buyer's Guide

Executive Summary
 

Categories and Ranking

Fortinet FortiGate
Sponsored
Ranking in Firewalls
2nd
Average Rating
8.4
Number of Reviews
309
Ranking in other categories
Software Defined WAN (SD-WAN) Solutions (2nd), WAN Edge (1st)
Check Point NGFW
Ranking in Firewalls
7th
Average Rating
8.8
Number of Reviews
281
Ranking in other categories
Unified Threat Management (UTM) (1st)
Palo Alto Networks VM-Series
Ranking in Firewalls
11th
Average Rating
8.6
Number of Reviews
53
Ranking in other categories
Advanced Threat Protection (ATP) (11th)
 

Mindshare comparison

As of June 2024, in the Firewalls category, the mindshare of Fortinet FortiGate is 22.6%, up from 20.2% compared to the previous year. The mindshare of Check Point NGFW is 3.1%, down from 3.9% compared to the previous year. The mindshare of Palo Alto Networks VM-Series is 0.9%, down from 0.9% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Firewalls
Unique Categories:
Software Defined WAN (SD-WAN) Solutions
21.5%
WAN Edge
24.4%
Unified Threat Management (UTM)
18.3%
Advanced Threat Protection (ATP)
0.7%
 

Featured Reviews

William Nogueira - PeerSpot reviewer
Dec 11, 2023
Helps reduce our mean time to remediate and our security risk, and provides good visibility into our environment
While FortiGate offers a wide range of security features, I sometimes feel that the platform could benefit from more extensive improvements. Given the multitude of functions it provides, I wonder if the developers have enough time to adequately refine each aspect. However, for our specific needs, FortiGate currently performs adequately. The debugging and troubleshooting has room for improvement. I would like to see greater integration with third-party solutions. For instance, one example would be integrating Endpoint Protection with FortiGate, such that if an issue arises with Endpoint Protection, an action could be automatically triggered on FortiGate. I am concerned about Fortinet's ability to help us meet regulatory compliance because its optimal functionality requires deploying all solutions within the mesh as Fortinet products. This raises questions about the compatibility and integration of non-Fortinet technologies within the Fortinet Security Fabric.
Prateek Agarwal - PeerSpot reviewer
Jan 24, 2024
Comprehensive network protection providing robust security features, seamless integration with on-premises infrastructure and exceptional customer support
The primary use case is for safeguarding against various threats. Our organization utilizes NGFW for secure on-premises computing, particularly for users in sectors like government, banks, and government departments who prefer to maintain their private computing environments It performs…
JL
Sep 21, 2020
An excellent solution for the right situations and businesses
We would really like to see Palo Alto put an effort into making a real Secure Access Service Edge (SASE). Especially right now where we are seeing companies where everybody is working from home, that becomes an important feature. Before COVID, employees were all sitting in the office at the location and the requirements for firewalls were a different thing. $180 billion a year is made on defense contracts. Defense contracts did not stop because of COVID. They just kept going. It is a situation where it seems that no one cared that there was COVID they just had to fulfill the contracts. When people claimed they had to work from home because it was safer for them, they ended up having to prove that they could work from home safely. That became a very interesting situation. Especially when you lack a key element, like the Secure Access Services. Palo Alto implemented SASE with Prisma. In my opinion, they made a halfhearted attempt to put in DLP (Data Loss Prevention), those things need to be fixed.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The most valuable features are the enterprise modeling and the simple interface."
"I am "headache free" that I don't have to categorize all the websites and that security has been pre categorized by the people, and that the services are getting updated. At least one part of my problem is over."
"I really like the captive portal feature for our guest network. It has nice VLAN features in terms of separating our network. The anti-virus is also good."
"The solution is very user friendly. The user interface in particular is quite nice."
"The web tutor and automatic rules by schedule are good features."
"One of the nice things about FortiGate is that it can be deployed on the cloud or on-premises. You can actually do both. That's the biggest reason why I stick with this solution as opposed to something like Cisco Meraki. Another nice thing is that I can log directly into a FortiGate or get to it through their FortiCloud access products. They're pretty reliable and consistent. One of the reasons why I started using the product was their single pane of management. I can deploy their line of firewalls in conjunction with their switching and access points, and I can manage the entire network from one interface. I don't have to log into one interface for the firewall, another one for the access points, and another one for the switches. These firewalls have access point controller functionality built right into the system, so I don't even have to purchase additional devices to manage them."
"The most important features of Fortinet FortiGate are the Intrusion Prevention System (IPS) and firewall control applications."
"The initial installation is very straightforward."
"It is easy to control from the central management system. For example, if we have 10 firewalls, and we want to push that same configuration among them, we can use this solution's central management system to do that simultaneously. So, there is time saving in that way. The time savings does depend on the situation. For example, if I am running half an hour of work on each firewall, that will take around 300 minutes. However, if I do this work from the central management system, then it will only take 30 minutes to push the same configuration to those same 10 devices."
"From the logs, you can trace back to the rule with a click, which makes it easy to investigate cases."
"The initial setup is easy."
"AV, IPS, AntiSpam, Sandbox. That's gentlemen set for any basic security, and it was implemented very well. In our reports, the most exciting results belong to AV and IPS. It can be explained by using ThreatCloud - a global knowledge base, which accumulates signatures for all existing and new coming malware, and all the Check Point solutions are always up to date with potential threats."
"The fact that these can be separated and made in different layers provides excellent convenience for the administrators who regulate the rules."
"The console or the single interface on the blades is most valuable."
"The dashboard provides a quick overview of the security status, including key metrics, alerts, and recent events."
"Advanced logging capabilities: Check Point generates extensive logs which may be very useful to figure out the issues. Its logs also contain too much information which can be used to modify the policy as per user need and organizational security environment. The same can be used to figure out probable attack surface or necessary steps for mitigation."
"The most valuable features are the User ID, URL filtering, and application filtering."
"The main advantage of Palo Alto Networks VM-Series stems from the fact that you can access it with the help of cloud services."
"It scales linearly with load and no issues."
"What I like about the VM-Series is that you can launch them in a very short time."
"I have not actually called their support line, because we have a direct contact to a senior engineer in the company for any issues that we handle with them. I will say they are very responsive, and they do give you the information you need when you need it.​"
"The tool's cloud version makes application migration easy."
"You already can scale it if you put it in Auto Scaling groups. If you put it in a load balancer, it should already be able to scale."
"In the newer version, there are 3850s, all of them are scalable. They fit better into the medium or small businesses."
 

Cons

"The reporting in Fortinet FortiGate could improve. Customers are having to purchase additional reporting components. When I have used the Sophos solution it is a complete solution, in Fortinet FortiGate you have to use additional tools to have the features needed."
"We would like to have the ability to disable some of the security functionalities."
"One of the features that I would like to have is to do with endpoint production, it should be integrated. For example, the firewall gets notified of any kind of forensic event that needs to be done, such as if there is a ransomware attack and how it originated, all those records have to be available from the firewall, which is not."
"They have to just improve its performance when we enable all UTM features. When you enable all the features, the performance of FortiGate, as well as of Sophos and SonicWall, goes down."
"They need faster serviceability and more security features."
"The initial setup and configuration are not intuitive and require training."
"With the reports, you can see it, and you can get good feelings so upper management can go, "Oh, wow. That looks pretty." However, it's very basic."
"The support system could be improved."
"One of the main features that need improvement is the rule filter export."
"If you have a long ruleset, you may experience performance issues on the GUI, and installing rule changes on gateways can take a comparatively long time."
"Check Point can improve a little better in their technical services, especially in the Indian market."
"Several security modules are based on HTTPS inspection, losing a relevant security capability if you don't implement it in your network."
"While the logs are very good and easy to understand, when you want to download these customized logs, they don't have as many features compared to competitive firewalls."
"Debugging could be improved when compared to the competition."
"Currently, some prices are very expensive."
"The user interface should be user-friendly"
"The reporting part of the product is an area of concern where improvements are required."
"The only minor issue we've faced is with the app's ID configuration, which requires specific matching for application filtering."
"On the cloud side, they need to come up with more HA solutions to support the multi-region."
"At the beginning of the implementation, we had some difficulties with the scripts, but Palo Alto Networks support together with a local partner finally fixed it."
"With Palo Alto Networks VM-Series, it is hard for me to manage its network configuration part."
"There are various reports that come with the box or with the VMware, but you can only run them daily."
"The disadvantage with Palo Alto is that they don't have a cloud-based solution that includes a secure web gateway."
"All areas need improvement: manufacturing, education, financial, etc."
 

Pricing and Cost Advice

"The price of Fortinet FortiGate is reasonable."
"The price range is quite acceptable and normal."
"A year or two years back, its price was competitive and reasonable. That was one of the reasons that people easily switched to Fortinet. Over the last two years, the prices have increased drastically. However, the prices of others have also increased. An advantage is there from the price point but not as much as it was previously."
"The pricing is perfect."
"Fortinet has more device options that are affordable for small businesses than Palo Alto, and its enterprise-level models are also cheaper. Palo Alto also has a separate license for VPN connections and SD-WAN, but FortiGate offers these features standard."
"We purchased a five-year bundle package, which worked out cheaper than competing solutions."
"The value is the capability of having multiple services with one unique license, not having the limitation per user licensing schema, like other vendors."
"The price is okay."
"There are three types of licensing: Threat Prevention, NGTP, and Next Generation Threat Extraction. Before, it used to be you would just enable the license of whatever blade you wanted to buy. Nowadays, Threat Prevention would be sufficient for most clients, so I would think people would go for the NGTP, license which includes all the blades."
"When comparing the price of Check Point NGFW to other solutions it's difficult to compare because even though everything is included in the Fortinet price, there are large differences between the models. You need to go to a quite expensive Fortinet firewall to receive the same throughput and functionality as in a Check Point firewall. In the end, they are quite similar in price, Fortinet might be a bit cheaper."
"Maybe the pricing is a bit high but you get the durability and the duration."
"There are competitors that have more expensive solutions than Check Point NGFW, such as Palo Alto. There are times when Check Point NGFW can have good offerings with a three-year license. The presence of Palo Alto has been heavily invested in marketing."
"The product is not that expensive for what it is offering, but it could be cheaper."
"Licensing is on a yearly basis and I am happy with the pricing."
"Before you buy, check which features you need, and if possible, I recommend signing up for at least a three-year license."
"The product provides value for pricing in terms of performance and technical features compared to other firewalls."
"For what you get, it does do what it says. It is a good value for an enterprise firewall.​"
"It is a little bit of crazy if you compare it to Vanguard, Sophos, or even Cisco. The newest version of Cisco, the Next-Generation Firewall of Cisco, is less expensive than Palo Alto. It is more comparable to Check Point."
"AWS is available as a AMI that you can purchase from the AWS Marketplace. Therefore, you need to purchase the licensing, since it is per AMI. Then, you deploy it on a regular EC2. Then, for on-premise, you can use both Palo Alto's software and hardware."
"​The licensing is pretty much like everyone else."
"This is not the cheapest firewall but it's not the most expensive of the options on the market."
"We found purchasing process the product on the AWS Marketplace to be very good."
"The VM series is licensed annually."
"Do not buy larges box if you do not need them. Rightsizing is a great task to do before​hand."
report
Use our free recommendation engine to learn which Firewalls solutions are best for your needs.
787,779 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Educational Organization
21%
Computer Software Company
15%
Comms Service Provider
7%
Manufacturing Company
6%
Educational Organization
51%
Computer Software Company
7%
Financial Services Firm
5%
Government
4%
Computer Software Company
16%
Financial Services Firm
11%
Manufacturing Company
7%
Government
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

Which is the better NGFW: Fortinet Fortigate or Cisco Firepower?
When you compare these firewalls you can identify them with different features, advantages, practices and usage a...
What is the biggest difference between Sophos XG and FortiGate?
From my experience regarding both the Sophos and FortiGate firewalls, I personally would rather use FortiGate. I know...
What are the biggest technical differences between Sophos UTM and Fortinet FortiGate?
As a solution, Sophos UTM offers a lot of functionality, it scales well, and the stability and performance are quite ...
How does Check Point NGFW compare with Fortinet Fortigate?
I have experience on both from Disti and channel experience. Please find below my comments (nothing new as such). -Ch...
Which would you recommend - Azure Firewall or Check Point NGFW?
Azure Firewall is easy to use and provides excellent support. Valuable features include integration into the overall ...
What do you like most about Check Point NGFW?
Check Point NGFW provides essential security, featuring no-obligation access for secure connections, strong intrusion...
Features comparison between Palo Alto and Fortinet firewalls
In the best tradition of these questions, Feature-wise both are quite similar, but each has things it's better at, it...
How does Azure Firewall compare with Palo Alto Networks VM Series?
Both products are very stable and easily scalable. The setup of Azure Firewall is easy and very user-friendly and the...
 

Also Known As

FortiGate 60b, FortiGate 60c, FortiGate 80c, FortiGate 50b, FortiGate 200b, FortiGate 110c, FortiGate
Check Point NG Firewall, Check Point Next Generation Firewall
No data available
 

Overview

 

Sample Customers

1. Amazon Web Services 2. Microsoft 3. IBM 4. Cisco 5. Dell 6. HP 7. Oracle 8. Verizon 9. AT&T 10. T-Mobile 11. Sprint 12. Vodafone 13. Orange 14. BT Group 15. Telstra 16. Deutsche Telekom 17. Comcast 18. Time Warner Cable 19. CenturyLink 20. NTT Communications 21. Tata Communications 22. SoftBank 23. China Mobile 24. Singtel 25. Telus 26. Rogers Communications 27. Bell Canada 28. Telkom Indonesia 29. Telkom South Africa 30. Telmex 31. Telia Company 32. Telkom Kenya
Control Southern, Optimal Media
Warren Rogers Associates
Find out what your peers are saying about Check Point NGFW vs. Palo Alto Networks VM-Series and other solutions. Updated: May 2024.
787,779 professionals have used our research since 2012.