Cisco Secure Firewall vs Palo Alto Networks VM-Series comparison

Sponsored
 

Comparison Buyer's Guide

Executive Summary
 

Categories and Ranking

Fortinet FortiGate
Sponsored
Ranking in Firewalls
2nd
Average Rating
8.4
Number of Reviews
309
Ranking in other categories
Software Defined WAN (SD-WAN) Solutions (2nd), WAN Edge (1st)
Cisco Secure Firewall
Ranking in Firewalls
4th
Average Rating
8.2
Number of Reviews
404
Ranking in other categories
Cisco Security Portfolio (4th)
Palo Alto Networks VM-Series
Ranking in Firewalls
11th
Average Rating
8.6
Number of Reviews
53
Ranking in other categories
Advanced Threat Protection (ATP) (11th)
 

Mindshare comparison

As of June 2024, in the Firewalls category, the mindshare of Fortinet FortiGate is 22.6%, up from 20.2% compared to the previous year. The mindshare of Cisco Secure Firewall is 6.3%, up from 6.3% compared to the previous year. The mindshare of Palo Alto Networks VM-Series is 0.9%, down from 0.9% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Firewalls
Unique Categories:
Software Defined WAN (SD-WAN) Solutions
21.5%
WAN Edge
24.4%
Cisco Security Portfolio
7.1%
Advanced Threat Protection (ATP)
0.7%
 

Q&A Highlights

MM
Oct 03, 2021
 

Featured Reviews

AV
May 10, 2023
Feature-rich, affordable, and has good performance
It is deployed on-premises. Our customers prefer to deploy not only Fortinet devices but all security devices on-premises. They rarely use cloud licenses. Some customers only buy it from us, and for some customers, we also set it up. Its setup is easy for us, but not every company wants to use our service for setting it up because of the cost. They prefer to install it themselves. In some cases, it could be hard for them. In terms of the implementation strategy, we first try to understand what problem a customer wants to solve by using FortiGate. We collect a lot of information about a customer's network, such as protocols and devices being used. We try to prepare this device in our local lab. We preload the device and send it to the customer, and then we finalize the installation in the customer's building. We have very technical staff, and we do not have difficulties with installations. We have had situations where customers do not have much experience with it, and then we recommend them to go for certain features such as IPS, antivirus, etc. The deployment duration depends on the size of the environment, but generally, it does not take more than one or two months.
PS
Feb 21, 2023
Scales well, has good documentation, and helps with secure access
One con of Cisco Secure Firewalls is that Java is used a lot for the older generation of these firewalls. Java is used for the ASA and the ASDM tool for administration. It's an outdated way of administering, and it's also a security risk to use this kind of solution. This is a pro of Firepower or the newer generation of firewalls because they are using HTML for administration. In general, they can make it easier to manage the solutions. They can make it easier in terms of administration and provide a single tool for different firewalling solutions. They have different tools to manage different firewalls, such as Firepower or ASA. Sometimes, both are on the same thing. You have ASA with Firepower modules, so you manage some of the things via HTML, and then you manage some of the things via another management tool. It's not seamless. It should be bundled together in one solution.
Mitul Rajput - PeerSpot reviewer
Jan 31, 2024
A stable and straightforward solution that provides valuable features and strengthens an organization’s IT posture
We are using the solution for IDS, IPS, and security We need a perimeter firewall to expose anything on the internet. Our inbound and outbound traffic is controlled via Palo Alto. It has multiple features. We have Palo Alto in every location and have a central console where we control all the…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Allows for firewall rules to be programmed and named in a way that makes it “readable”"
"The most valuable features of Fortinet FortiGate are the APIs. They are the most widely known."
"The most valuable feature is the SSL VPN, as it allows us to connect and it separates this product from other firewalls."
"The usage in general is pretty good."
"This solution has helped our organization by having strong functions and a reliable firewall."
"The security fabric is excellent."
"It's user-friendly and easy to operate."
"Centralized monitoring, policy management, and virtualized appliances allow us to take control over our public and private infrastructure."
"My confidence continues to build upon using Cisco firewalls."
"Everything is all documented in the file or in the command line script that gets uploaded to the device. It gives us great visibility."
"We find all of its features very useful. Its main features are policies and access lists. We use both of them, and we also use routing."
"Malicious URLs are being blocked."
"The user interface, the UI, is excellent on the solution."
"Cisco's technical support is the best and that's why everybody implements their products."
"Its VPN and ASN features are very stable."
"We use the solution for deep packet inspection, Internet Edge functionality, IDS, and IDP."
"Embedding it into my application development lifecycle prevents data loss and business disruption, allowing the adoption to operate at the speed of my AWS Cloud."
"It has excellent scalability."
"In the newer version, there are 3850s, all of them are scalable. They fit better into the medium or small businesses."
"It provides complete security posture from end-to-end. This has given us better visibility into what our security aspects are."
"The filtering feature is good."
"It has the ability to create Palo Alto VM-series using software."
"Centralized management is valuable because it allows us to configure settings in one location and apply them across all three locations."
"They now know the details about their network traffic that they did not know before: Applications that they are using and some application they did not know they were using."
 

Cons

"Fortinet FortiGate could improve by adding FortiAnalyzer to its solution, we should not have to use another solution. FortiAnalyzer can provide more detailed information."
"Some of the web policy reports could be improved."
"Pricing for it is a bit high. It could be cheaper."
"One area for improvement is the performance on bandwidth demands for smaller devices, as well as better web filtering."
"We had a minor problem where there was a major system upgrade on the hardware platfrom and the Mac client was not available as soon as it might have been. The PC client was available immediately, but we had to wait a month or so, before there was a mac client. I was slightly irritated that it was not ready on time, but it was eventually resolved."
"Some of the filtering is not robust, you can escape it with a VPN. Some of the users bypass some of the filters. It catches some but it also misses some, that area could be improved. It's functioning reasonably but there's room for improvement in that area."
"I would like to see improvements with the antivirus and IPS as they are not working properly all the time."
"The ease of use could be improved."
"It seems very clunky and slow. I would like to be able to tune it to be a more efficient product."
"The usability of Cisco Firepower Threat Defense is an issue. The product is still under development, and the user interface is very difficult to deal with."
"I think they need to review their whole UI because it feels like it was created by a whole bunch of different teams of developers who didn't fully talk to each other. The net policy screen is just a mess. It should look like the firewall policy screen, and they should both act the same, but they don't. I feel like it's two different buildings or programming, who don't talk to each other, and that really annoys me."
"The integration between the on-prem proxy world and the cloud proxy would benefit us. One single policy setting would make sense."
"One of the challenges we've had with the Cisco ASA is the lack of a strong controller or central management console that is dependable and reliable all the time."
"The software was very buggy, to the point it had to be removed."
"The solution is overcomplicated in some senses. Simplifying it would be an improvement."
"We found it difficult to publish an antennae sidewalk with the ASDM. I think Cisco should improve this by creating a simpler interface for the firewall."
"The web interface is very slow, and it needs to be faster."
"The product could be better in terms of performance than one of its competitors."
"The user interface could use some improvement."
"The implementation should be simplified."
"The tool is very costly."
"All areas need improvement: manufacturing, education, financial, etc."
"In the next release, I would like to see better integration of multi-factor authentication vendors."
"Its web interface is a bit outdated, and it needs to be updated. They can also improve the NAT functionality. We have had issues with the NAT setup."
 

Pricing and Cost Advice

"The price could be lower."
"The licensing costs are very low."
"The price of FortiGate is average and I would say that based on the top five products available on the market, it is in the affordable range."
"In the Asian economy in which we operate, FortiGate is expensive."
"The product pricing is reasonable."
"It is an inexpensive solution."
"Fortinet FortiGate as a less expensive solution than Palo Alto."
"The price of Fortinet FortiGate could improve, it is expensive."
"In terms of costs, other solutions are more expensive than Cisco. Palo Alto is more expensive than Cisco."
"We bought a three-year license as a part of the enterprise agreement, which includes help with implementation and troubleshooting. We have a big data center with many applications, so implementation was not straightforward. We had to put effort into it. It wasn't an easy or straightforward implementation. The support that we got from Cisco engineers with the three-year premium license was helpful. The enterprise agreement helped to consume the licenses in a practical and faster way and streamline the implementation."
"The Firepower series of appliances is not cheap. I just got a quote recently for six firewalls that was in the range of over half-a-million dollars. That's what could push us to look to other vendors..."
"This is an expensive product, although when you buy this solution, you can do many things so it provides good value for the investment."
"If we compare it with FortiGate and the co-existing ASA, FortiGate is better in price."
"The price for Firepower is more expensive than FortiGate. The licensing is very complex. We usually ask for help from Solutel because of its complexity. I have a Cisco account where I can download the VPN client, then connect. Instead, I create an issue with Solutel, then Solutel solves the case."
"Watch out for hidden licensing and incredibly high annual maintenance costs."
"Always consider what you might need to reduce your wasted time and invest it in other solutions."
"For licensing, It depends how they want to use the firewall. The firewall can be used only for IPS purposes. If you only want that firewall IPSs, you will only need a license that is called threat prevention. That license, threat prevention, includes vulnerabilities, antivirus signatures and one additional measure (that I can't remember), but it includes three measures and security updates."
"Purchasing on the AWS Marketplace was simple, effective, and easy."
"​The licensing is pretty much like everyone else."
"Palo Alto can be as much as two times the price of competing products that have twice the capabilities."
"Do not buy larges box if you do not need them. Rightsizing is a great task to do before​hand."
"We used BYOL, because of the cost to own."
"The pricing for Palo Alto is quite high compared to FortiGate, which is more affordable. I don't have the exact figures as my manager handles that, but from my research, Palo Alto's licensing costs are significantly higher."
"The box, if you do not want to buy the threat prevention license in the box, you can buy it only with the support license. It is for the support of the hardware. It works like a simple firewall. It integrates what it calls user IDs and application IDs. If you do not buy any other license, only the firewall, Palo Alto will also help you improve a lot of your security."
report
Use our free recommendation engine to learn which Firewalls solutions are best for your needs.
787,779 professionals have used our research since 2012.
 

Comparison Review

it_user206346 - PeerSpot reviewer
Mar 11, 2015
Cisco ASA vs. Palo Alto Networks
Cisco ASA vs. Palo Alto: Management Goodies You often have comparisons of both firewalls concerning security components. Of course, a firewall must block attacks, scan for viruses, build VPNs, etc. However, in this post I am discussing the advantages and disadvantages from both vendors concerning…
 

Answers from the Community

MM
Oct 3, 2021
Oct 3, 2021
hello. Capability is on par between the two vendors. Your best bet is to think about integration and how the FW will work with other tools/processes in your environment. Thanks
2 out of 4 answers
EB
Apr 30, 2021
Hello @Muhammed Eslami, @Mike Bulyk, @Javed Hashmi ​, @VishalGilatar. Can you please assist @M Mari? 
MB
Apr 30, 2021
hello. Capability is on par between the two vendors. Your best bet is to think about integration and how the FW will work with other tools/processes in your environment. Thanks
 

Top Industries

By visitors reading reviews
Educational Organization
21%
Computer Software Company
15%
Comms Service Provider
7%
Manufacturing Company
6%
Educational Organization
23%
Computer Software Company
16%
Comms Service Provider
7%
Government
6%
Computer Software Company
16%
Financial Services Firm
11%
Manufacturing Company
7%
Government
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

Which is the better NGFW: Fortinet Fortigate or Cisco Firepower?
When you compare these firewalls you can identify them with different features, advantages, practices and usage a...
What is the biggest difference between Sophos XG and FortiGate?
From my experience regarding both the Sophos and FortiGate firewalls, I personally would rather use FortiGate. I know...
What are the biggest technical differences between Sophos UTM and Fortinet FortiGate?
As a solution, Sophos UTM offers a lot of functionality, it scales well, and the stability and performance are quite ...
Which is better - Fortinet FortiGate or Cisco ASA Firewall?
One of our favorite things about Fortinet Fortigate is that you can deploy on the cloud or on premises. Fortinet Fort...
How does Cisco's ASA firewall compare with the Firepower NGFW?
It is easy to integrate Cisco ASA with other Cisco products and also other NAC solutions. When you understand the Cis...
Which is better - Meraki MX or Cisco ASA Firewall?
Cisco Adaptive Security Appliance (ASA) software is the operating software for the Cisco ASA suite. It supports netw...
Features comparison between Palo Alto and Fortinet firewalls
In the best tradition of these questions, Feature-wise both are quite similar, but each has things it's better at, it...
How does Azure Firewall compare with Palo Alto Networks VM Series?
Both products are very stable and easily scalable. The setup of Azure Firewall is easy and very user-friendly and the...
 

Also Known As

FortiGate 60b, FortiGate 60c, FortiGate 80c, FortiGate 50b, FortiGate 200b, FortiGate 110c, FortiGate
Cisco ASA Firewall, Cisco Adaptive Security Appliance (ASA) Firewall, Cisco ASA NGFW, Cisco ASA, Adaptive Security Appliance, ASA, Cisco Sourcefire Firewalls, Cisco ASAv, Cisco Firepower NGFW Firewall
No data available
 

Overview

 

Sample Customers

1. Amazon Web Services 2. Microsoft 3. IBM 4. Cisco 5. Dell 6. HP 7. Oracle 8. Verizon 9. AT&T 10. T-Mobile 11. Sprint 12. Vodafone 13. Orange 14. BT Group 15. Telstra 16. Deutsche Telekom 17. Comcast 18. Time Warner Cable 19. CenturyLink 20. NTT Communications 21. Tata Communications 22. SoftBank 23. China Mobile 24. Singtel 25. Telus 26. Rogers Communications 27. Bell Canada 28. Telkom Indonesia 29. Telkom South Africa 30. Telmex 31. Telia Company 32. Telkom Kenya
There are more than one million Adaptive Security Appliances deployed globally. Top customers include First American Financial Corp., Genzyme, Frankfurt Airport, Hansgrohe SE, Rio Olympics, The French Laundry, Rackspace, and City of Tomorrow.
Warren Rogers Associates
Find out what your peers are saying about Cisco Secure Firewall vs. Palo Alto Networks VM-Series and other solutions. Updated: May 2024.
787,779 professionals have used our research since 2012.