Try our new research platform with insights from 80,000+ expert users

Check Point NGFW vs Fortinet FortiGate vs Zscaler Internet Access comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
7.6
Check Point NGFW decreases costs and enhances security, resulting in productivity gains and high user confidence with advanced features.
Sentiment score
7.1
Fortinet FortiGate provides cost-effective security, reducing operational costs and enhancing efficiency with quick ROI for enterprises.
Sentiment score
7.5
Zscaler Internet Access offers cost and complexity reduction, improved security, and quick ROI, especially for SMBs, despite regional challenges.
This is a time-saving measure because we don't need to deploy a cluster or a firewall each time; we just create a virtual system on the management server using the same appliance.
Incident response time has reduced significantly, and downtime due to network issues has been minimized, leading to an improved return on investment.
I have seen a return on investment with Check Point NGFW in terms of time saved and fewer people needed for operations.
Clients are now comfortable and not wasting productive hours on IT support.
The automation part is giving us a cost benefit and speed; we can react faster.
It's a very useful tool to mitigate and protect your enterprise.
The managed service aspect of Zscaler Internet Access has allowed for reduced staffing costs, resulting in a saving of approximately 20-25% compared to prior expenses.
 

Customer Service

Sentiment score
7.1
Check Point NGFW's support is generally positive, with praised expertise, but response time and initial experience vary.
Sentiment score
6.9
Fortinet FortiGate support varies, praised for responsiveness but criticized for slow responses and regional inconsistencies in efficiency.
Sentiment score
7.1
Zscaler Internet Access support is strong and responsive, though some users seek quicker resolutions and better online resources.
The support team we engaged was knowledgeable and well-versed with the application.
We have escalated issues to Check Point technical support multiple times and have received timely and very good responses.
Even challenging issues like those with VPNs have been resolved efficiently with their help.
They offer very accurate solutions.
The quick resolution of issues with Fortinet FortiGate is due to the support of the company and the fact that the equipment is easy to work with.
I would rate the technical support for Fortinet FortiGate a ten out of ten.
The technical support for Zscaler Internet Access is rated around seven out of ten due to some response time issues and the engagement model.
I find customer support to be quite adequate
 

Scalability Issues

Sentiment score
8.2
Check Point NGFW offers robust scalability with seamless upgrades and high availability, efficiently meeting diverse organizational needs.
Sentiment score
7.3
Fortinet FortiGate is scalable with ease of expansion, though hardware integration and sizing can pose challenges for users.
Sentiment score
7.9
Zscaler Internet Access is highly scalable, cloud-based, and supports large user volumes with positive feedback on integration and performance.
If specified correctly, even the smaller boxes offer high session and bandwidth rates, making the solution highly scalable, even up to telco-level requirements.
Scalability must be carefully planned for, considering future growth and user base increases.
They offer multiple solutions from SMBs to enterprise data centers, making it an easily scalable solution with no issues in scalability.
They scale up really well from smaller models like the FortiGate 40 and 50 to bigger sites with the FortiGate 100 for more throughput - up to enterprise datacenters.
The variation comes in terms of the interfaces and throughputs, but from a security perspective, you get the same benefit, irrespective of whether you have an entry-level unit or an enterprise.
We determine sizing based on multiple factors: number of users, available links, traffic types, server count, services in use, and whether services will be published.
I find Zscaler Internet Access to be highly scalable, which was one of the reasons for choosing it.
Zscaler Internet Access is scalable and has points of presence across the globe to ensure low latency and reliable connections.
 

Stability Issues

Sentiment score
7.9
Check Point NGFW is praised for stability, reliability, proactive updates, and high performance, despite occasional bugs and configuration issues.
Sentiment score
7.8
Fortinet FortiGate is favored for its stability and reliability, with some performance issues resolved through updates and sizing.
Sentiment score
7.7
Zscaler Internet Access offers stable performance globally, though regions like China and South Africa occasionally face latency challenges.
While the solution is generally stable, there are complications, such as requiring SmartConsole for deployment and upgrades, which can be time-consuming.
I have worked with Check Point products for 15 years and haven't found any stability or performance issues.
The use of Check Point firewalls has helped improve our security posture without any downtime.
We're experiencing 99.999% availability consistently.
I would rate the stability of Fortinet FortiGate a ten out of ten.
The solution is very stable.
Zscaler Internet Access is stable and capable of building resilient architectures.
Zscaler Internet Access is very stable, and I would rate its stability as nine out of ten.
 

Room For Improvement

Check Point NGFW faces stability, support, and integration issues, with complex GUI, high costs, and challenging policy management.
Fortinet FortiGate users seek improvements in stability, integration, scalability, cost, and advanced features like monitoring and zero-trust technology.
Zscaler Internet Access needs better integration, user-friendly features, improved support, and competitive pricing to enhance user experience.
Other products, like FortiGate, are perceived as more intuitive because they are easier to configure from the start.
More granularity and control for threat prevention, especially on the OT side, would be beneficial.
I believe Check Point NGFW can be improved by making its initial configuration and deployment easier in the future because the first-time setup is really hard.
Investing in a solution that can accommodate such growth would be more cost-effective than repeatedly purchasing new hardware.
The constant daily revisions necessitate meticulous identification of the relevant documents to prevent the use of outdated information that could jeopardize our environment.
While Fortinet claims to offer a comprehensive network solution, it falls short in addressing computer application issues, particularly server security.
The response time and engagement model for technical support could be improved to handle complex outages more efficiently.
One feature I am missing is the ability to connect automatically to internal monitoring systems.
 

Setup Cost

Check Point NGFW pricing is high but feature-rich, requiring negotiation and support; opinions vary on cost-effectiveness.
Fortinet FortiGate offers various licensing models, balancing affordability and performance, though renewals can increase costs.
Zscaler Internet Access is seen as costly but premium compared to traditional solutions, offering unmatched services and global coverage.
In comparison to Fortinet and other products, the pricing may be considered high.
Compared to other solutions, the pricing of Check Point NGFW is high.
The perception is that Check Point NGFW is expensive, especially when all software modules are included.
FortiGate is priced lower than Palo Alto.
Last year, I renewed the support for three years, which can sometimes be expensive but depends on the security benefits and how it helps us.
It is about 20% cheaper.
Zscaler Internet Access is recognized as an expensive solution.
Zscaler Internet Access is less expensive than competitors like Palo Alto, offering a premium service justified by security enhancements and cost-effective scalability.
 

Valuable Features

Check Point NGFW excels with VPN, IPS, centralized management, intuitive interface, and robust threat prevention, enhancing security and performance.
Fortinet FortiGate provides robust security features, user-friendly management, and scalability, making it a preferred choice for organizations.
Zscaler Internet Access delivers comprehensive cloud-native security with threat protection, ease of use, and centralized management for remote users.
The firewall's default behavior of blocking all traffic, including a cleanup rule that blocks everything from external to internal sources, is highly valuable for protecting our network.
The most valuable features in my experience include perimeter firewalling, cloud and mobile security, application control, URL filtering, DLP, threat prevention, intrusion protection, and safeguarding against malware, botnets, and zero-day attacks.
Since implementing it, we have noticed a lot less getting through that maybe other antivirus within firewalls had failed to catch.
In terms of security, we have not experienced any security flaws or loopholes, and it has proven to be quite stable.
FortiGate has helped reduce the risk of cyberattacks that might disrupt our client's production.
These features help reduce our downtime, manage the ISPs, and deploy SLAs for all the website traffic.
The most valuable feature for me is the ability to see how my network and traffic looks with modules like analytics and insights.
Some of the most valuable features of Zscaler Internet Access include secure web gateways, URL filtering, data loss prevention, anti-malware defense, file extension blocking, and a comprehensive categorization system.
 

Mindshare comparison

Firewalls
Firewalls
Secure Web Gateways (SWG)
 

Featured Reviews

Hailemichael Yigrem - PeerSpot reviewer
Advanced security features enhance threat detection and prevention
Check Point NGFW provides granular application control and detailed visibility over application and user activity. It integrates with the ThreatCloud ecosystem, enabling real-time threat detection and prevention. The User Identity Awareness blade integrates with Active Directory, identifying user traffic sources. Check Point NGFW is highly scalable and has centralized management through SmartConsole, which manages policies, logs, and threat data. It reduced our incidents and decreased the time to analyze cyber threats by 70 percent.
Vasu Gala - PeerSpot reviewer
A stable solution with an intuitive interface and quick customer service
I have been working with Fortinet FortiGate, WatchGuard, Sophos, and SonicWall. I'm not as comfortable with SonicWall because of their UI and limitations. I prefer Fortinet above all other options. When it comes to configuration, I am confident in my ability to handle various tasks, including creating policies such as firewall rules, web policies, and application policies. Additionally, I can configure VPNs and implement load balancing, among other tasks. Overall, I feel much more comfortable working with Fortinet. Fortinet has made significant improvements by integrating AI with firewalls for threat analysis and prevention. In the past 2-3 years, they have launched FortiSASE and SIEM, and they also provide SOC services. Both Palo Alto and Fortinet FortiGate are excellent. While Fortinet FortiGate comes at higher prices, the functionality and support justify the cost. They promptly resolve firmware issues and inform all support providers about configuration changes.
ShanavasVK - PeerSpot reviewer
Helps maintain a consistent posture of internet security while getting rid of VPN and hovering into zero trust
There could be a better way for the tool to categorize the traffic. For example, the tool does exceptions and everything overall. If I want to give guest access or provide access to guest users or any other internet access and if it does not go through the SSL inspection because, in our company, we can't have the root certificate on a device that we don't manage, which can be called out as an exception or an exclusion, but that doesn't provide a proper reflection of the picture of what is happening in the environment. There are granularities bringing it down. The tool I used or still have is Zscaler Cloud Connector to protect the cloud environment, which can have a bit more user-friendly installation and setup, and it would help a lot. The deployment process of Zscaler Cloud Connector needs to be more user-friendly. Improvements are required in the exception category. For example, suppose I report on a monthly basis what the breaches and traffic violating the SSL inspection area are coming from. In that case, I may find that half of them may be coming through some guest network, meaning the tool doesn't differentiate between the guest or normal networks or the corporate networks. Having options to differentiate different networks would be ideal so that it can show a true picture of things to users, as half of the things in the tool are not in our control and are not of our concern.
report
Use our free recommendation engine to learn which Firewalls solutions are best for your needs.
860,592 professionals have used our research since 2012.
 

Comparison Review

it_user216600 - PeerSpot reviewer
Jan 3, 2016
Sophos UTM vs. Fortinet FortiGate
I have used both Sophos and Fortinet products in production and I have found the Sophos UTM appliances (hardware and virtual) to be a better fit most of the time -- with a few caveats which I will touch on below. In both instances, the transition from TMG will be mostly straightforward. The main…
 

Top Industries

By visitors reading reviews
Educational Organization
37%
Computer Software Company
10%
Financial Services Firm
7%
Comms Service Provider
4%
Computer Software Company
15%
Educational Organization
12%
Comms Service Provider
8%
Manufacturing Company
7%
Computer Software Company
15%
Manufacturing Company
10%
Educational Organization
10%
Financial Services Firm
10%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

How does Check Point NGFW compare with Fortinet Fortigate?
I have experience on both from Disti and channel experience. Please find below my comments (nothing new as such). -Ch...
Which would you recommend - Azure Firewall or Check Point NGFW?
Azure Firewall is easy to use and provides excellent support. Valuable features include integration into the overall ...
What do you like most about Check Point NGFW?
Check Point NGFW provides essential security, featuring no-obligation access for secure connections, strong intrusion...
Which is the better NGFW: Fortinet Fortigate or Cisco Firepower?
When you compare these firewalls you can identify them with different features, advantages, practices and usage a...
What is the biggest difference between Sophos XG and FortiGate?
From my experience regarding both the Sophos and FortiGate firewalls, I personally would rather use FortiGate. I know...
What are the biggest technical differences between Sophos UTM and Fortinet FortiGate?
As a solution, Sophos UTM offers a lot of functionality, it scales well, and the stability and performance are quite ...
Which is the better security solution - Cisco Umbrella or Zscaler?
Cisco Umbrella and Zscaler Internet Access are two broad-spectrum Internet security solutions that I have tried. Zs...
Which is better, Zscaler internet access or Netsckope CASB?
We researched Netskope but ultimately chose Zscaler. Netskope is a cloud access security broker that helps identify ...
 

Also Known As

Check Point NG Firewall, Check Point Next Generation Firewall
FortiGate 60b, FortiGate 60c, FortiGate 80c, FortiGate 50b, FortiGate 200b, FortiGate 110c, FortiGate, Fortinet Firewall
ZIA
 

Overview

 

Sample Customers

Control Southern, Optimal Media
Amazon Web Services, Microsoft, IBM, Cisco, Dell, HP, Oracle, Verizon, AT&T, T-Mobile, Sprint, Vodafone, Orange, BT Group, Telstra, Deutsche Telekom, Comcast, Time Warner Cable, CenturyLink, NTT Communications, Tata Communications, SoftBank, China Mobile, Singtel, Telus, Rogers Communications, Bell Canada, Telkom Indonesia, Telkom South Africa, Telmex, Telia Company, Telkom Kenya
Ulster-Greene ARC, BanRegio, HDFC, Ralcorp Holdings Inc., British American Tobacco, Med America Billing Services Inc., Lanco Group, Aquafil, Telefonica, Swisscom, Brigade Group
Find out what your peers are saying about Netgate, Fortinet, OPNsense and others in Firewalls. Updated: May 2025.
860,592 professionals have used our research since 2012.