Check Point NGFW vs Palo Alto Networks NG Firewalls comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on May 15, 2022
 

Categories and Ranking

Fortinet FortiGate
Sponsored
Ranking in Firewalls
2nd
Average Rating
8.4
Number of Reviews
314
Ranking in other categories
Software Defined WAN (SD-WAN) Solutions (2nd), WAN Edge (1st)
Check Point NGFW
Ranking in Firewalls
6th
Average Rating
8.8
Number of Reviews
286
Ranking in other categories
Unified Threat Management (UTM) (1st)
Palo Alto Networks NG Firew...
Ranking in Firewalls
5th
Average Rating
8.6
Number of Reviews
165
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of July 2024, in the Firewalls category, the mindshare of Fortinet FortiGate is 22.6%, up from 18.8% compared to the previous year. The mindshare of Check Point NGFW is 2.9%, down from 3.9% compared to the previous year. The mindshare of Palo Alto Networks NG Firewalls is 2.1%, down from 3.3% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Firewalls
Unique Categories:
Software Defined WAN (SD-WAN) Solutions
19.7%
WAN Edge
21.4%
Unified Threat Management (UTM)
16.8%
No other categories found
 

Q&A Highlights

MS
Dec 12, 2023
 

Featured Reviews

AV
May 10, 2023
Feature-rich, affordable, and has good performance
It is deployed on-premises. Our customers prefer to deploy not only Fortinet devices but all security devices on-premises. They rarely use cloud licenses. Some customers only buy it from us, and for some customers, we also set it up. Its setup is easy for us, but not every company wants to use our service for setting it up because of the cost. They prefer to install it themselves. In some cases, it could be hard for them. In terms of the implementation strategy, we first try to understand what problem a customer wants to solve by using FortiGate. We collect a lot of information about a customer's network, such as protocols and devices being used. We try to prepare this device in our local lab. We preload the device and send it to the customer, and then we finalize the installation in the customer's building. We have very technical staff, and we do not have difficulties with installations. We have had situations where customers do not have much experience with it, and then we recommend them to go for certain features such as IPS, antivirus, etc. The deployment duration depends on the size of the environment, but generally, it does not take more than one or two months.
Prateek Agarwal - PeerSpot reviewer
Jan 24, 2024
Comprehensive network protection providing robust security features, seamless integration with on-premises infrastructure and exceptional customer support
The primary use case is for safeguarding against various threats. Our organization utilizes NGFW for secure on-premises computing, particularly for users in sectors like government, banks, and government departments who prefer to maintain their private computing environments It performs…
TI
Jan 12, 2024
The configuration is quite simple to understand, but the functionalities are limited
We use the solution to access clients I like the configuration of the product. The configuration is quite simple to understand. The product is easy to manage. The solution has a lot of features. However, there are no deep configurations available. The functionalities are limited. Other products…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"FortiGate is flexible and easy to use."
"The stability of the solution is excellent, as it is with other Fortinet products."
"We purchased Fortinet because of the pricing, its functionality, because it met our requirements, and the total cost of ownership over five years was quite reasonable. In the market, Fortinet is rated quite well."
"We use a lot of function on the IPS and it works well for us."
"The most valuable features are SD-WAN, application control, IPS control, and FortiSandbox."
"It's very easy to set up, it's very easy to make policies and, for an organization, that means you don't need IT expert in firewalls. You just need to have somebody who knows a little bit of IT, and that's it. With other products, you need someone with a "Masters" degree in firewalls."
"The email protection and VPN features are the most valuable."
"Fortinet FortiGate is easy to use."
"One of the most valuable features is the data center object integration with Azure. We are using Azure a lot and there is very nice synchronization between the objects in Azure, and it's very easy to implement rules using this feature."
"It creates granular security policies based on users or groups to identify, block or limit the usage of web applications."
"I like the SmartEvent feature. When we see a threat, SmartEvent can create a rule for that. SmartEvent works with the SmartCenter to block a threat attack with a block monitor. The SmartCenter has the management for all the firewalls and data centers in a single dashboard."
"We use Check Point to complete the network compliance rules."
"Newer versions are much more stable."
"The interface and the IPS intrusion prevention are the most valuable features of this solution."
"I think that the most valuable feature is the prevention of known and zero-day threats because they are constantly trying to access your company and compromise its data."
"The security posture assessment with two-factor authentication has saved more time and commercial costs by avoiding deploying having to deploy another solution."
"GlobalProtect and App-ID features are very good."
"The most valuable features are the IPS/IDS subscriptions."
"I like the architecture because it separates the management plan process and the data plan process."
"The machine learning in the core of the firewalls, for inline, real-time attack prevention, is very important to us. With the malware and ransomware threats that are out there, to keep abreast of and ahead of those types of attacks, it's important for our devices to be able to use AI to distinguish when there is malicious traffic or abnormal traffic within our environment, and then notify us."
"The key aspect of this solution that provides the most value is its next-gen capabilities, which represented a significant change for us."
"Some of Palo Alto Networks NG Firewalls' valuable features are their powerful capabilities and user-friendliness."
"The strengths of Palo Alto Networks NG Firewalls are application visibility and application awareness. Their strong point is identifying applications for traffic. So all of the policies that are configured are related to the application and not to a port."
"The most valuable feature of the solution is the network protection."
 

Cons

"There are some cloud-based features that could be much more flexible than they currently are."
"We had a minor problem where there was a major system upgrade on the hardware platfrom and the Mac client was not available as soon as it might have been. The PC client was available immediately, but we had to wait a month or so, before there was a mac client. I was slightly irritated that it was not ready on time, but it was eventually resolved."
"Some of the filtering is not robust, you can escape it with a VPN. Some of the users bypass some of the filters. It catches some but it also misses some, that area could be improved. It's functioning reasonably but there's room for improvement in that area."
"I haven't had a single issue since using Fortinet."
"Performance and technical support are the main issues with this solution."
"The solution could be more user friendly."
"The support we receive when we need to upgrade is not satisfactory and has room for improvement."
"The support costs and licensing are sometimes so expensive."
"I would like the graphic user interface to be easier to use. For example, the NAT policy should be easier to use. Check Point's NAT policy is somewhat confused compared to other competitors."
"Until you have some experience, the installation and configuration are difficult."
"Although there is a lot of automation and pattern that can be classified automatically, the IPS systems are sometimes a little bit complicated, and doing the fine-tuning in over 20,000 patterns is hard to do."
"I would like the user interface to be more user-friendly. I want the UI to be easier to use than Check Point's competitors."
"The training for Check Point Firewall should increase, including the number of Training Centers. For most new people in our organization, we have to provide them training from our end, as they are not trained in Check Point Firewalls. So, we have to do the training, from our point of view, to make our engineers able to use Check Point Firewalls. However, with other firewalls, they are already trained, so we are not require to provide them training. This could be improved by the Check Point Community."
"The upgrade is something we would like to be improved in the future as the frequency of hotfixes is too much, and by the time we finish the one round, we already have the new version released and are required to upgrade."
"The end-user VPN could be improved. It could benefit from some modification."
"We find the GUI to be wrong and the CLI doesn't always show all of the connections."
"The biggest thing that needs to be improved with them is their training. I took a training class for the 8.0 build, then I took it again for the 9.0 and 10 builds. They add new features every time that they do a new major release, but the training doesn't keep up. It is the same basic training that probably was with the 3.0 build, and they just change the screenshots. I would love to see them do some more work since they have all these bells and whistles, but we don't know how to use those features on a large scale."
"Sometimes some of the applications the customer has do not respond as they normally should."
"Once in a while, they have new features being released that can be buggy. My criticism is more general to all sorts of network or security devices. In general, everybody is releasing less-tested software. Then, it usually ends up that the first few customers who get a new release need to end up troubleshooting it."
"The configuration part could be improved. It's very difficult to configure. It doesn't have a user-friendly interface. You have to know Palo Alto deeply to use it."
"In the last three years at least, they have been lagging behind their competitors. The main issue is the support that we can get... You have to wait for them to get back to you and sometimes it's random. And the biggest problem I have is that you have to wait hours on the line when you're calling them to get a hold of the next available engineer."
"I am in GCC in the Middle East. The support that we are getting from Palo Alto is disastrous. The problem is that the support ticket is opened through the distributor channel. Before opening a ticket, we already do a lot of troubleshooting, and when we open a ticket, it goes to a distributor channel. They end up wasting our time again doing what we have already done. They execute the same things and waste time. The distributor channel's engineer tries to troubleshoot, and after spending hours, they forward the ticket to Palo Alto. It is a very time-consuming process. The distributor channels also do not operate 24/7, and they are very lazy in responding to the calls."
"I would like to see more integration."
"The first level of support will usually do nothing for you. If you're an IT company, you're not looking for level one support. You need to escalate. Other vendors have a direct support line for enterprise clients, but not Palo Alto."
 

Pricing and Cost Advice

"FortiGate's pricing falls within the mid-range when compared to other leading firewall solutions."
"The price is fair compared to the other competitors."
"The price of Fortinet FortiGate is reasonable."
"​We saved a bundle by not needing all the past appliances from an NGFW.​"
"The price of Fortinet FortiGate could improve, it is expensive."
"I would say that all things considered, the pricing is pretty good."
"The price of FortiGate support is too expensive."
"The price of FortiGate is good."
"They sell it in one box. In that one box, they sell Antivirus and Threat Prevention. They have everything, so we are not required to purchase additional IPS hardware for it."
"The hardware cost is not huge, but you need to push for good pricing on software licensing and blades."
"The vendor offered a special promotion at the time, providing us with this solution at a highly discounted rate through the marketplace."
"The price of the appliance should be decreased."
"Though we did not take issue with the price of Check Point NGFW, we felt that it was providing us with inadequate support here in Uganda."
"It's an expensive solution"
"Check Point NGFW can be expensive compared to other competitors, but the price matches the functionality and efficiency of the solution."
"The pricing is good. It is less than Palo Alto's firewalls. Check Point has the same features as Palo Alto, but the licensing and cost of these firewalls are not too expensive. It is one of the best firewalls in the market in this range."
"Annually, the licensing costs are too much."
"After the hardware and software are procured, it is the AMC support that has to be renewed yearly."
"It is an expensive solution."
"The pricing is very high."
"It's too expensive."
"Cheap and faster are the opposite sides of security. Security inspections have some technical and money costs. If you just purchase some cheap, fast firewalls, then you will lose a lot of the security features and fraud protection capabilities."
"I rate the product’s pricing an eight out of ten."
"We always aim to reduce the pricing, as it is currently a bit high and needs to be lowered."
report
Use our free recommendation engine to learn which Firewalls solutions are best for your needs.
793,295 professionals have used our research since 2012.
 

Answers from the Community

MS
Dec 12, 2023
Dec 12, 2023
Hi, I would suggest going for Checkpoint, the suitability depends on your specific security needs, budget constraints, network infrastructure, Integration capabilities, cloud integration, compliance and reporting, user-friendly interface but the support and the specific behavior for some solutions for routing, networking balance or specific connectivity is better known constraints, Checkpoint M...
2 out of 3 answers
Ajenthan Aiyathurai - PeerSpot reviewer
May 22, 2023
Hi, I would suggest going for Check Point.I'm with Check Point now, for more than 2 years. IPS, threat prevention, antibot identification, and antivirus notification are up to the mark. Moreover, it has a friendly user interface where anyone can create policies and work on it. 
MOHAMEDELSHERIF - PeerSpot reviewer
May 23, 2023
Both of them are expensive when it comes to hardware or support. For me, Check Point is more focused on Cyber Security threats, IPS, application visibility, and malware detection. The interface really gives more insights when it comes to cybersecurity than Palo Alto, however when it comes to Network capability in the Environment "Routing, Switching, VRF, NAT" Check Point can't compare with Palo Alto, Palo Alto has more routing and design flexibility than checkpoint. So to Wrap up: Check Point- more threats and prevention-focused but for Network Capability it doesn't exceed a Linux server capability. Palo Alto- also has good threats and prevention capability "Less Than Checkpoint". But provide more Network Flexibility than Check Point.
 

Top Industries

By visitors reading reviews
Educational Organization
21%
Computer Software Company
15%
Manufacturing Company
6%
Comms Service Provider
6%
Educational Organization
54%
Computer Software Company
8%
Financial Services Firm
5%
Government
4%
Computer Software Company
17%
Financial Services Firm
9%
Manufacturing Company
8%
Government
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

Which is the better NGFW: Fortinet Fortigate or Cisco Firepower?
When you compare these firewalls you can identify them with different features, advantages, practices and usage a...
What is the biggest difference between Sophos XG and FortiGate?
From my experience regarding both the Sophos and FortiGate firewalls, I personally would rather use FortiGate. I know...
What are the biggest technical differences between Sophos UTM and Fortinet FortiGate?
As a solution, Sophos UTM offers a lot of functionality, it scales well, and the stability and performance are quite ...
How does Check Point NGFW compare with Fortinet Fortigate?
I have experience on both from Disti and channel experience. Please find below my comments (nothing new as such). -Ch...
Which would you recommend - Azure Firewall or Check Point NGFW?
Azure Firewall is easy to use and provides excellent support. Valuable features include integration into the overall ...
What do you like most about Check Point NGFW?
Check Point NGFW provides essential security, featuring no-obligation access for secure connections, strong intrusion...
What is a better choice, Azure Firewall or Palo Alto Networks NG Firewalls?
Azure Firewall Vs. Palo Alto Network NG Firewalls Both solutions provide stellar stability and security. Azure Firew...
Features comparison between Palo Alto and Fortinet firewalls
In the best tradition of these questions, Feature-wise both are quite similar, but each has things it's better at, it...
Which is better - Palo Alto Networks NG Firewalls or Sophos XG?
Palo Alto Networks NG Firewalls have both great features and performance. I like that Palo Alto has regular threat si...
 

Also Known As

FortiGate 60b, FortiGate 60c, FortiGate 80c, FortiGate 50b, FortiGate 200b, FortiGate 110c, FortiGate
Check Point NG Firewall, Check Point Next Generation Firewall
Palo Alto NGFW, Palo Alto Networks Next-Generation Firewall
 

Overview

 

Sample Customers

1. Amazon Web Services 2. Microsoft 3. IBM 4. Cisco 5. Dell 6. HP 7. Oracle 8. Verizon 9. AT&T 10. T-Mobile 11. Sprint 12. Vodafone 13. Orange 14. BT Group 15. Telstra 16. Deutsche Telekom 17. Comcast 18. Time Warner Cable 19. CenturyLink 20. NTT Communications 21. Tata Communications 22. SoftBank 23. China Mobile 24. Singtel 25. Telus 26. Rogers Communications 27. Bell Canada 28. Telkom Indonesia 29. Telkom South Africa 30. Telmex 31. Telia Company 32. Telkom Kenya
Control Southern, Optimal Media
SkiStar AB, Ada County, Global IT Services PSF, Southern Cross Hospitals, Verge Health, University of Portsmouth, Austrian Airlines, The Heinz Endowments
Find out what your peers are saying about Check Point NGFW vs. Palo Alto Networks NG Firewalls and other solutions. Updated: July 2024.
793,295 professionals have used our research since 2012.