We performed a comparison between Check Point NGFW and Fortinet FortiGate-VM based on our users’ reviews in five categories. After reading all of the collected data, you can find our conclusion below.
Features: Check Point NGFW is praised for its extensive security features, centralized management, and virtualization capabilities. Fortinet FortiGate-VM receives appreciation for its stability, reliability, and user-friendly interface.
Check Point NGFW needs enhancements in integration, hardware upgrades, cost and pricing, stability and security, setup process, load balancing capabilities, technical support, and reporting. Fortinet FortiGate-VM requires improvements in key activation, log management, cloud management, IPsec failover, monitoring tool, setup and configuration, performance, firmware updates, log settings, GUI capabilities, costs, technical support, and integration.
Service and Support: The customer service for Check Point NGFW has garnered varying opinions, with some customers appreciating its helpfulness and responsiveness, while others believe there is room for improvement. Fortinet FortiGate-VM's support has received a mix of feedback. Certain customers commend its prompt response times and expertise, while others highlight concerns regarding delayed responses.
Ease of Deployment: Check Point NGFW's initial setup can be complex and may require expertise and experience for certain configurations and migrations. Fortinet FortiGate-VM offers a generally straightforward and easy setup process, aided by Fortinet's support and assistance.
Pricing: Check Point NGFW has a high setup cost, yet offers flexible licensing options. Fortinet FortiGate-VM has competitive pricing and includes support without extra charges.
ROI: Check Point NGFW provides cost savings, simplicity, and strong security enforcement, resulting in a favorable ROI. Fortinet FortiGate-VM offers stability and enhanced security, guaranteeing a positive ROI when purchased initially.
Comparison Results: Check Point NGFW is the preferred choice when comparing it to Fortinet FortiGate-VM. Check Point NGFW stands out for its extensive security features, such as URL filtering, intrusion prevention systems, identity and access management, and application control capabilities. Additionally, it offers centralized management and virtualization options, as well as stability, user-friendliness, and scalability.
"Easy to use support and licensing portal as well as activation process."
"The reporting you receive out of this appliance is excellent. You will not need an external management system."
"It's an easy solution to set up."
"Mainly the FortiGate reporting system is very good. It guides us through all the expectations of security. Fortinet provides us all that we need for security. Also, Fortinet FortiGate is a next-generation firewall. It is much more advanced than others."
"This solution has solid UTM features combined with a nice GUI."
"FortiGate has a strong security topic which allows all of the Fortinet devices to communicate and share information which makes their security more powerful."
"Fortinet FortiGate is stable. It's used across all the countries, this is the way most multinationals run their system."
"Their proxy-based inspection is responsive and secure."
"Check Point is more expensive but easier to manage, and their presales and after-sale support are way better than Fortinet's."
"Check Point has an awesome price-to-benefit ratio, netting you an awesome throughput of IDS/IPS capability compared to Palo Alto, Cisco, and so on."
"It's quite a stable solution."
"The most valuable feature of the firewall is the packet inspection. That is an amazing feature from Check Point."
"I like the GUI."
"I like the Next-Generation Firewall."
"In the four years I have worked on the five firewalls we have not had any downtime caused by stability issues."
"The most valuable feature for us is the VSX, the virtualization."
"Regarding specific features, I appreciate the option for external selection, where you can choose either to use a default or create a self-description. This simplifies the process compared to other vendors that require creating a test extension profile and then applying it to the installation. With FortiGate, there is a streamlined approach. From the benefits perspective, clients mainly see cost reduction, especially with FortiGate VM Firewall, as it eliminates the need for additional hardware."
"FortiGate integrates well."
"The stability of the solution is good. We haven't faced any issues at all while using the product."
"The solution offers good documentation."
"It is highly scalable because it has a mesh architecture that allows consistent policies."
"Technical support is very helpful."
"The web GUI is easy to use."
"We work in the archiving domain where a secure environment is very important. We have some special requirements regarding the security of infrastructure."
"They should make the rule sets more understandable for the end user. When you're trying to explain to somebody how a computer network is secured, sometimes it's difficult for an end user or customer to understand. If there was a way to make the terminology more accessible to the end user, the set up could be easier. They should translate the technical jargon to an easily relatable and understandable conversation for the end user, the customer, that would be brilliant. Particularly in an environment where the IT structure is audited regularly, there's always pressure from the auditor to up the standards and up the security and you get your USCERT's that come out and there's a warning about this and the customer will want to lock out so much and when you apply it they run into issue where they can't search the internet or print to their remote office. Of course they can't print to your remote office, they just locked it up. They should make the language more understandable for the customer. If there's a product out there that made the jargon understandable to John Q. Public, I would buy that."
"The solution lacks multi-language support."
"The customization could be improved. Cisco, for example, is much better at this. They need to work to be at least as good as they are."
"Fortinet should focus on enhancing the capabilities of FortiGate by consolidating its various products, such as FortiGate Cloud, FortiManager, and FortiAnalyzer."
"In terms of what could be improved, the SD-WAN is quite difficult, because if you install the new box, 15 is okay, but if you change from an old configuration, if there is already configuration and a policy when you change to SD-WAN, you must change the whole policy that you see in the interface."
"Fortinet currently has many products bundled with FortiGate including the basic firewall and load balancer, and I think that that they need to have separate product portfolios for each of these specialized services."
"They are doing good, but they can improve the distributor assignment. The availability of the product and the timeline of delivery are the main things. The distribution should be swift, and the distributor should not reach out to end customers directly. They should work as a distributor. There should also be one more local distributor. Currently, there is only one distributor in Pakistan, and the rest of them are in UAE. It is difficult to work with only one distributor. Sometimes, you don't get along with the same distributor, and that's why they should have one more distributor. Their licensing should also be improved. The activation or renewal of the product should be done from the date of renewal, not from the date on which the license expired."
"One area for improvement is the performance on bandwidth demands for smaller devices, as well as better web filtering."
"The upgrade is something we would like to be improved in the future as the frequency of hotfixes is too much, and by the time we finish the one round, we already have the new version released and are required to upgrade."
"The VPN part was actually one of the most complex parts for us. It was not easy for us to switch from Cisco, because of one particular part of the integration: connecting the Check Point device to an Entrust server. Entrust is a solution that provides two-factor authentication. We got around it by using another server, a solution called RADIUS."
"Check Point NGFW could improve by introducing machine learning and more modeling dividing the way they manage the ports. However, they have evolved over the last year."
"The virtual environment is not stable at all. We have some customers who are using the virtual environment feature, and sometimes it crashes. We have many tickets open and the response is not as good as expected. We have to wait months for a resolution."
"The antivirus is not as effective as it could be because updates are not that frequent."
"There have been a few requests/issues about the Identity Awareness feature."
"It could be easier to access the installation of the Hostfix for VSX solutions. The CLI commands help us understand how virtual firewalls behave in terms of processor, memory, and other aspects. More graphic visualizations of CPUSE commands would be a welcome improvement, and Check Point could expand scripts to run within the solution for multiple tasks."
"The interface can be more user-friendly in terms of design and the location of critical and commonly used icons."
"The performance could be better. Some features need to have quality control when the switch is working. The dedicated bandwidth for some users is not reliable."
"The costs could be lowered."
"They should keep us up to date about the latest version. That's the biggest thing. Currently, we have to go looking for the latest version. We should get notified about what's going on with the versions. I would like to see easier dual-factor authentication."
"The operating system isn't stable, so it goes to memory counters every night."
"The solution can improve by adding separate interfaces for proxy and flow-based usage."
"The price is sometimes very expensive."
"The user interface needs to be improved."
"We have had some stability issues."
Check Point NGFW is ranked 5th in Firewalls with 275 reviews while Fortinet FortiGate-VM is ranked 9th in Firewalls with 113 reviews. Check Point NGFW is rated 8.8, while Fortinet FortiGate-VM is rated 8.4. The top reviewer of Check Point NGFW writes "Good antivirus protection and URL filtering with very good user identification capabilities". On the other hand, the top reviewer of Fortinet FortiGate-VM writes "An easy-to-manage and configure tool that provides ample documentation to help with the setup phase". Check Point NGFW is most compared with Palo Alto Networks NG Firewalls, Sophos XG, Cisco Secure Firewall, Netgate pfSense and Azure Firewall, whereas Fortinet FortiGate-VM is most compared with Azure Firewall, Palo Alto Networks VM-Series, Fortinet FortiOS, OPNsense and Netgate pfSense. See our Check Point NGFW vs. Fortinet FortiGate-VM report.
See our list of best Firewalls vendors.
We monitor all Firewalls reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.