Check Point NGFW vs Fortinet FortiGate-VM comparison

Cancel
You must select at least 2 products to compare!
Fortinet Logo
122,353 views|90,183 comparisons
Check Point Logo
30,268 views|18,828 comparisons
Fortinet Logo
15,634 views|8,871 comparisons
Comparison Buyer's Guide
Executive Summary
Updated on Jul 11, 2023

We performed a comparison between Check Point NGFW and Fortinet FortiGate-VM based on our users’ reviews in five categories. After reading all of the collected data, you can find our conclusion below.

Features: Check Point NGFW is praised for its extensive security features, centralized management, and virtualization capabilities. Fortinet FortiGate-VM receives appreciation for its stability, reliability, and user-friendly interface.

Check Point NGFW needs enhancements in integration, hardware upgrades, cost and pricing, stability and security, setup process, load balancing capabilities, technical support, and reporting. Fortinet FortiGate-VM requires improvements in key activation, log management, cloud management, IPsec failover, monitoring tool, setup and configuration, performance, firmware updates, log settings, GUI capabilities, costs, technical support, and integration.

Service and Support: The customer service for Check Point NGFW has garnered varying opinions, with some customers appreciating its helpfulness and responsiveness, while others believe there is room for improvement. Fortinet FortiGate-VM's support has received a mix of feedback. Certain customers commend its prompt response times and expertise, while others highlight concerns regarding delayed responses.

Ease of Deployment: Check Point NGFW's initial setup can be complex and may require expertise and experience for certain configurations and migrations. Fortinet FortiGate-VM offers a generally straightforward and easy setup process, aided by Fortinet's support and assistance.

Pricing: Check Point NGFW has a high setup cost, yet offers flexible licensing options. Fortinet FortiGate-VM has competitive pricing and includes support without extra charges.

ROI: Check Point NGFW provides cost savings, simplicity, and strong security enforcement, resulting in a favorable ROI. Fortinet FortiGate-VM offers stability and enhanced security, guaranteeing a positive ROI when purchased initially.

Comparison Results: Check Point NGFW is the preferred choice when comparing it to Fortinet FortiGate-VM. Check Point NGFW stands out for its extensive security features, such as URL filtering, intrusion prevention systems, identity and access management, and application control capabilities. Additionally, it offers centralized management and virtualization options, as well as stability, user-friendliness, and scalability.

To learn more, read our detailed Check Point NGFW vs. Fortinet FortiGate-VM Report (Updated: November 2023).
745,775 professionals have used our research since 2012.
Featured Review
Quotes From Members
We asked business professionals to review the solutions they use.
Here are some excerpts of what they said:
Pros
"The feature I like most is the SD-WAN. It allows you to manage more than one ISP at the same time. And there is a high-availability mode, so if one of your ISPs is down, you still have a backup.""I like several features that this product has, such as antivirus and internet navigation inspection. It is also simple to use.""Fortinet offers the latest versions to cater to the needs of enterprises.""The scalability of Fortinet FortiGate is good.""Whenever I need something, Fortinet improves and updates the software for me.""The security features that they have are quite good. On top of that, their licensing model is quite nice where they don't charge you anything for the SD-WAN functionality for the firewall.""It is easy to use. We chose this product for the possibility to have virtual domains (VDOMs). We are building another company in the group, and we would like to split the firewalling rules and policies between these two companies. Each company would be able to manage its own policies and security rules, which is an advantage of Fortinet FortiGate. We can define VDOMs, and every company can manage its own VDOM as if it has its own physical firewall, but in fact, we would be using the same physical appliance because we are also using the same internet lines. So, it allows us to reuse the existing resources without the disadvantage of having to compromise on policies and security. Each company can choose its own way of working.""The multi-tenancy feature is most valuable. It integrates very well with FortiManager and FortiAnalyzer."

More Fortinet FortiGate Pros →

"Only allows authorized connections and prevents vulnerabilities in a network.""Log storage gives us insights when required.""The successful performance of the security blades has shown the value of the investment along with the comparable success of leveraging the NGFW over a separate specialized security solution.""We found a very successful implementation of the virtual private network client, since, for some time now, everyone has been working from home.""When applying application control, we can ensure user access to the internet in accordance with company policy and easy implementation if some users need exception access.""The initial setup is easy.""The detection rate for any cyberattacks/suspicious activity is very high (more than 90%).""If you want to share traffic loads to both cluster members you can use the active-active feature, if you don't want to share traffic loads you can prefer active standby."

More Check Point NGFW Pros →

"The thing that I like the most is that they're very willing to work with us to resolve issues that they haven't taken care of before in their product.""We like FortiGate-VM's IPS features and its ability to create multiple virtual firewalls.""The most valuable features of Fortinet FortiGate-VM are its flexibility and scalability. This solution is available as a license, which allows us to activate it based on the specific needs of the customer. This gives us and the customer a great deal of versatility and customization options.""I did like the ability to back up the configuration into the cloud, as opposed to having to store the configurations or just downloading them, the backups, to local devices.""The setup is simple.""The solution is stable.""FortiGate integrates well.""The reporting is good."

More Fortinet FortiGate-VM Pros →

Cons
"Fortinet FortiGate could improve by adding enhancements to FortiMail, FortiSOAR, and FortiDeceptor.""The solution's framework needs to be frequently updated in order to have a stable solution.""I would prefer to have more detailed logs within the FortiGate products themselves rather than relying on a separate tool.""The pricing could always be better.""I haven't had a single issue since using Fortinet.""Fortinet FortiGate needs to improve to be on par with its competitors, such as Palo Alto and Sophos. They are the market leaders. Fortinet FortiGate needs to improve its capabilities. However, we are happy with Fortinet FortiGate.""The non-error conserve mode has room for improvement.""With the addition of some features, it is possible that FortiGate can be used in all verticals."

More Fortinet FortiGate Cons →

"Something worth mentioning is the need for Spanish support and better representation for teams in the Latin American area.""In the future, some of the features that I would like to see would be the ability to integrate environmental solutions such as the metaverse or blockchain so that we can see them also in applications directly and on mobile devices or natively.""Check Point can improve a little better in their technical services, especially in the Indian market.""The policy installation module should be improved.""We have run into an interface expansion limitation, and thus it would be helpful if products lower in the stack would offer more interface expansion options.""It could be easier to access the installation of the Hostfix for VSX solutions. The CLI commands help us understand how virtual firewalls behave in terms of processor, memory, and other aspects. More graphic visualizations of CPUSE commands would be a welcome improvement, and Check Point could expand scripts to run within the solution for multiple tasks.""The whole solution has room for improvement.""I really want to see geo-blocking as a feature of NGFW."

More Check Point NGFW Cons →

"Technical support could be better.""The product has issues with integration. I would like to see better integration in future releases of the product.""It would be better if it could provide you with options before completely blocking anything through the web filter. If you are doing a deep SSL inspection on the site if it says it's expired, it doesn't give you the option to continue at your own risk. I can't say that it's bad, but SSL internally isn't really a requirement. However, its security features can help. Right now, we have people going out and spending on purchasing the SSL certificates for internal sites.""Fortinet devices are acknowledged as highly potent and come with a notable cost. These devices offer extensive visibility, an array of configurations, and a range of security features. However, there's room for enhancement in their routing and switching security aspects, akin to Cisco's offerings. A noteworthy aspect here is Meraki, which offers cloud controllers. If FortiGate were to introduce a similar cloud management solution, it could strongly compete with both Meraki and Cisco products. Cisco operates in two sectors: enterprise and SMB. Particularly in the SMB market, they hold sway due to their convenient cloud management features. For instance, Meraki's cameras and wireless access points can be easily controlled through their cloud management portal. If FortiGate were to provide cloud-based management solutions for SMB customers, it could cater to a significant portion of the market, considering that a substantial number of customers fall within the SMB and mid-level enterprise categories.""Support could be improved a little.""The users must buy FortiSIEM to get advanced analytics.""The solution can improve by adding separate interfaces for proxy and flow-based usage.""The operating system isn't stable, so it goes to memory counters every night."

More Fortinet FortiGate-VM Cons →

Pricing and Cost Advice
  • "It is more expensive than Sophos. Fortinet is overall more expensive than Sophos. The small range of Fortinet, such as 60F and 80F, is more expensive than the small range of Sophos. Sophos is cheaper. In addition, if you jump from 80F Series to 100F Series, the price doubles."
  • "The license is yearly. We pay for the top end. It's called 360."
  • "Here in Brazil, we're going through difficult economic times and the tax on the dollar is high. All the solutions from minor competitors are growing in the market. The prices have come more competitive."
  • "Licensing for Fortinet FortiGate is on a yearly basis. Pricing for it is a bit high. It could be cheaper."
  • "The licensing scheme of Fortinet is better than Cisco. It is more logical."
  • "The solution requires a license annually, it is not a user license, you can have as many users as your want. I must renew the license regularly per device."
  • "It was probably about $2,500 per firewall. It was all included. It included support, services, threat management software, and 24/7 FortiCare on it. Cisco products are more expensive."
  • "There is a license to use Fortinet FortiGate."
  • More Fortinet FortiGate Pricing and Cost Advice →

  • "I don't see that Check Point is very high, but it is geared more towards enterprises."
  • "Its cost is a little higher than other products."
  • "Check Point NGFW can be expensive compared to other competitors, but the price matches the functionality and efficiency of the solution."
  • "Before you buy, check which features you need, and if possible, I recommend signing up for at least a three-year license."
  • "Check Point needs to lower its price drastically, and the licensing model is very complex."
  • "There are competitors that have more expensive solutions than Check Point NGFW, such as Palo Alto. There are times when Check Point NGFW can have good offerings with a three-year license. The presence of Palo Alto has been heavily invested in marketing."
  • "It's expensive."
  • "It may be considered relatively expensive, but the investment is justified when compared to other competitors."
  • More Check Point NGFW Pricing and Cost Advice →

  • "The license we pay is a yearly fee. I can't say it's very expensive; it is a good price and is highly suitable for our usage."
  • "We have been waiting a long time for the vendor to give us licenses, it has been five months and we are still waiting. However, the price is reasonable."
  • "The price of the solution could be less expensive. There are some features that have to be purchased separately that have their own license."
  • "It is more expensive than its competitor, e.g. Sophos."
  • "Installation does not require another license making it an inexpensive solution."
  • "I would rate the product's pricing as four out of five."
  • "The price of the solution is competitive. Fortinet FortiGate-VM had a lot of advantages when it came to pricing. However, the competition has also geared up to a larger extent and it has become comparable now to the other solutions."
  • "Our license is yearly, but we're thinking of going monthly. I think it's somewhere around 100,000 for VM04. Nowadays, everyone wants to be a hacker, so we believe in security. That's why we also have third-party people that we involve to make sure that we're secure. I don't think the costs are too bad. You still want to get advice from people who worked in security for many years, so you add a third party. The third party also said they would give their share like 100K, or 200K or something like that, so I don't think it's too expensive for security. I think it just adds more trust."
  • More Fortinet FortiGate-VM Pricing and Cost Advice →

    report
    Use our free recommendation engine to learn which Firewalls solutions are best for your needs.
    745,775 professionals have used our research since 2012.
    Questions from the Community
    Top Answer: When you compare these firewalls you can identify them with different features, advantages, practices and usage at… more »
    Top Answer:From my experience regarding both the Sophos and FortiGate firewalls, I personally would rather use FortiGate. I know… more »
    Top Answer:As a solution, Sophos UTM offers a lot of functionality, it scales well, and the stability and performance are quite… more »
    Top Answer:I have experience on both from Disti and channel experience. Please find below my comments (nothing new as such)… more »
    Top Answer:Azure Firewall is easy to use and provides excellent support. Valuable features include integration into the overall… more »
    Top Answer:I rate the tool's stability a ten out of ten.
    Top Answer:In the best tradition of these questions, Feature-wise both are quite similar, but each has things it's better at, it… more »
    Top Answer:Both of these solutions are excellent options that provide flexible scalability and solid security Fortinet Fortigate… more »
    Top Answer:The ease of access and user-friendly setup is a valuable feature. Fortinet proves to be particularly straightforward to… more »
    Comparisons
    Also Known As
    FortiGate 60b, FortiGate 60c, FortiGate 80c, FortiGate 50b, FortiGate 200b, FortiGate 110c, FortiGate
    Check Point NG Firewall, Check Point Next Generation Firewall
    FortiGate Virtual Appliance, FortiGate-VM
    Learn More
    Overview

    Fortinet FortiGate is an innovative line of firewalls that aim to protect organizations from all types of web-based network threats. They come in a wide variety of product types. Fortinet FortiGate’s solutions are available in a large range of sizes and form factors and are key components of the Fortinet Security Fabric, which enables immediate, intelligent defense against known and new threats throughout the entire network.

    Fortinet FortiGate provides users with next-generation firewall solutions that provide proven protection with unmatched performance across the network, from internal segments to data centers to cloud environments. You can protect every part of your network without exception. Additionally, your protections can be managed from a single central location. This ensures that the task of protecting your network is infinitely easier to accomplish.

    Benefits of Fortinet FortiGate

    Some of the benefits of using Fortinet FortiGate include:

    • The ability to manage your firewalls from a centralized automated control console. Fortinet FortiGate’s FortiManager enables administrators to exercise control of their firewalls in a streamlined manner. Administrators have full visibility and control over their system from a single location. It utilizes automation that collects information in real time, which greatly simplifies and reduces the cost of running various types of workflows. Administrators can free up resources by automating the most basic tasks.
    • The ability to produce uniform, appropriate, and coordinated responses to threats across networks. Fortinet FortiGate’s FortiGuard feature generates system protections in near real time. This allows administrators to address threats to the system with custom-made solutions that can be uniformly enforced.
    • The ability to scale up your security to fit your changing security needs. Fortinet FortiGate’s design allows users to accelerate the transfer of data between users and escalate the number of users that are covered without compromising security of performance. This means that users can grow their networks and continue to collaborate without worrying about the system slowing down or coming under attack.

    Reviews from Real Users

    Fortinet FortiGate’s firewall solutions are cutting edge. They stand out from competitors for a number of reasons. Two major ones are the robustness and power of their firewalls. Fortinet FortiGate’s firewall provides users with many valuable features that allow them to maximize what they can do with the solution. These firewalls enable users to use a single piece of software to accomplish tasks that often require the use of multiple pieces of software.

    PeerSpot user Eric S., a Solutions Engineer and Consultant at a tech-services company, notes the robustness of this solution when he writes, "One of the nice things about FortiGate is that it can be deployed on the cloud or on-premises. You can actually do both. That's the biggest reason why I stick with this solution as opposed to something like Cisco Meraki. Another nice thing is that I can log directly into a FortiGate or get to it through their FortiCloud access products. They're pretty reliable and consistent. One of the reasons why I started using the product was their single pane of management. I can deploy their line of firewalls in conjunction with their switching and access points, and I can manage the entire network from one interface.”

    PeerSpot user Jim M., a network admin at Penobscot Valley Hospital, notes the power of Fortinet FortiGate’s security software when he writes, "It does a lot for you for intrusion protection and as an antivirus. The threat management bundle is worth the money. You don't need another company to monitor your web traffic for you. You can do everything yourself on the firewall. You restrict your own black list for people on the firewall.”

    Check Point NGFW is a next generation firewall that enables safe usage of internet applications by blocking malicious applications and unblocking safe applications. Check Point NGFW, which uses deep packet inspection to identify and control applications, has features such as application and user control and integrated intrusion prevention (IPS), as well as more advanced malware prevention capabilities like sandboxing.

    Check Point NGFW includes 23 firewall models optimized for running all threat prevention technologies simultaneously, including full SSL traffic inspection, without compromising on security or performance.

    Benefits of Check Point's Next Generation Firewall

    • Robust security: Check Point NGFW delivers the best possible threat prevention with SandBlast Zero Day protection. The SandBlast protection agent constantly inspects passing network traffic for exploits and vulnerabilities. Suspicious files are then emulated in a virtual sandbox in order to detect and report malicious behavior.

    • Security at hyperscale: On-demand hyperscale threat prevention performance provides cloud level expansion and resiliency on premises.

    • Unified management: Check Point's SmartConsole makes it easy to manage and configure network security environments and policies. With the SmartConsole, users can manage all the firewall gateways and access logs and install databases from one location. Unified management control across the network increases the efficiency of security operations and reduces IT costs.
    • Continuous logging: Check Point NGFW’s Threat Management feature detects vulnerabilities and logs them. Using the logged data, users can easily create and implement efficient security policies.

    • Remote access: The remote access VPN provides a seamless connection for remote users.

    Check Point NGFW is suitable for organizations of all sizes, from small businesses to larger enterprises.

    Reviews from Real Users

    Check Point NGFW stands out among its competitors for a number of reasons. Two major ones are its intrusion prevention feature as well as its centralized management, which makes it very easy to deploy firewall policies to many firewalls with one click.

    Shivani J., a network security administrator, writes, "Check Point has a lot of features. The ones I love are the antivirus, intrusion prevention, and data loss prevention."

    G., a network administrator at Secretaría de Finanzas de Aguascalientes, writes, “Within the organization, the inspection of packages has given us great help in detecting traffic that may be a threat to the institution. The configuration of policies has allowed us to maintain control of access and users for each institution that is incorporated into our headquarters.”

    Arun J., a senior network engineer, notes, “The nicest feature is the centralized management of multiple firewalls. With the centralized management, we can easily use and operate multiple firewalls as well as create a diagram of them.”

    FortiGate Virtual Appliances allow you to mitigate blind spots by implementing critical security controls within your virtual infrastructure. They also allow you to rapidly provision security infrastructure whenever and wherever it is needed. FortiGate virtual appliances feature all of the security and networking services common to traditional hardware-based FortiGate appliances. With the addition of virtual appliances from Fortinet, you can deploy a mix of hardware and virtual appliances, operating together and managed from a common centralized management platform.

    Offer
    Learn more about Fortinet FortiGate
    Learn more about Check Point NGFW
    Learn more about Fortinet FortiGate-VM
    Sample Customers
    Pittsburgh Steelers, LUSH Cosmetics, NASDAQ, Verizon, Arizona State University, Levi Strauss & Co. Whitepaper and case studies here
    Control Southern, Optimal Media
    Security7 Networks, COOPENAE
    Top Industries
    REVIEWERS
    Comms Service Provider16%
    Computer Software Company9%
    Financial Services Firm8%
    Manufacturing Company7%
    VISITORS READING REVIEWS
    Educational Organization21%
    Computer Software Company15%
    Comms Service Provider8%
    Manufacturing Company5%
    REVIEWERS
    Financial Services Firm23%
    Computer Software Company14%
    Comms Service Provider7%
    Manufacturing Company6%
    VISITORS READING REVIEWS
    Educational Organization48%
    Computer Software Company8%
    Financial Services Firm5%
    Comms Service Provider5%
    REVIEWERS
    Comms Service Provider16%
    Manufacturing Company11%
    Financial Services Firm9%
    Computer Software Company9%
    VISITORS READING REVIEWS
    Computer Software Company22%
    Comms Service Provider9%
    Financial Services Firm7%
    Government7%
    Company Size
    REVIEWERS
    Small Business48%
    Midsize Enterprise23%
    Large Enterprise30%
    VISITORS READING REVIEWS
    Small Business27%
    Midsize Enterprise32%
    Large Enterprise41%
    REVIEWERS
    Small Business31%
    Midsize Enterprise19%
    Large Enterprise50%
    VISITORS READING REVIEWS
    Small Business14%
    Midsize Enterprise56%
    Large Enterprise29%
    REVIEWERS
    Small Business53%
    Midsize Enterprise23%
    Large Enterprise24%
    VISITORS READING REVIEWS
    Small Business31%
    Midsize Enterprise17%
    Large Enterprise51%
    Buyer's Guide
    Check Point NGFW vs. Fortinet FortiGate-VM
    November 2023
    Find out what your peers are saying about Check Point NGFW vs. Fortinet FortiGate-VM and other solutions. Updated: November 2023.
    745,775 professionals have used our research since 2012.

    Check Point NGFW is ranked 5th in Firewalls with 103 reviews while Fortinet FortiGate-VM is ranked 8th in Firewalls with 27 reviews. Check Point NGFW is rated 8.8, while Fortinet FortiGate-VM is rated 8.8. The top reviewer of Check Point NGFW writes "Robust control and security that enables a comprehensive application management". On the other hand, the top reviewer of Fortinet FortiGate-VM writes "Flexible with good cloud management and a straightforward user interface". Check Point NGFW is most compared with Palo Alto Networks NG Firewalls, Netgate pfSense, Sophos XG, Azure Firewall and Cisco Secure Firewall, whereas Fortinet FortiGate-VM is most compared with Azure Firewall, Palo Alto Networks VM-Series, Fortinet FortiOS, OPNsense and Netgate pfSense. See our Check Point NGFW vs. Fortinet FortiGate-VM report.

    See our list of best Firewalls vendors.

    We monitor all Firewalls reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.