No more typing reviews! Try our Samantha, our new voice AI agent.

Cisco Hybrid Mesh Firewall vs IPFire comparison

Sponsored
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Fortinet FortiGate
Sponsored
Ranking in Firewalls
1st
Average Rating
8.4
Reviews Sentiment
6.9
Number of Reviews
592
Ranking in other categories
Secure Web Gateways (SWG) (2nd), Intrusion Detection and Prevention Software (IDPS) (1st), Software Defined WAN (SD-WAN) Solutions (1st), WAN Edge (1st), ZTNA (1st), Unified Threat Management (UTM) (1st)
Cisco Hybrid Mesh Firewall
Ranking in Firewalls
71st
Average Rating
8.6
Reviews Sentiment
7.7
Number of Reviews
6
Ranking in other categories
Firewall Security Management (20th)
IPFire
Ranking in Firewalls
35th
Average Rating
8.0
Reviews Sentiment
8.3
Number of Reviews
3
Ranking in other categories
No ranking in other categories
 

Featured Reviews

JK
IP Network Security Specialist at MTN Ghana
Process-Level CPU Visibility: Introduce detailed CPU-usage metrics per subsystem (e.g., IPS engine, logging) so administrators can quickly identify and address performance spikes.
Analytics with FortiAnalyzer. Being able to pull in logs not just from our FortiGates but from all our other firewalls and then get them in one view has been a game changer. Whether I’m building an executive dashboard or doing a deep dive forensics session, I get everything I need without navigating consoles.Straightforward Application Control. FortiGate spots and blocks unwanted apps (eq. like BitTorrent or streaming services) with accuracy. Segmentation with VDOMs. We’ve carved our data center into four logical ‘mini-firewalls’ enterprise, core, billing, and WAF—all on one box. Each has its own rules and logs, and any traffic between them still gets inspected. It’s like having multiple appliances without the extra hardware. Always-Up-to-Date Threat Feeds. Daily signature updates and AI-driven threat sensing mean we’re blocking the latest vulnerabilities almost as soon as they’re announced.
BC
Sales And Brand Strategist at CrossConnect
Smart switching has transformed data center security and now simplifies stateful segmentation
To improve Cisco Hybrid Mesh Firewall, I think right now awareness is the biggest area for improvement. Cisco should focus on raising awareness about what the firewall on the switch actually is and how policy has changed. That is a massive story that has not been emphasized enough regarding saving time and effort due to the combination of all these tools. From a feature perspective, I am discovering new features as we deploy, so I do not know if there is a good answer yet because we are at the forefront of this technology. I can tell you that whenever we ask for a feature while working with Cisco, within a day, we get the feature added. For instance, understanding flow data is crucial. Within the N9300, to be able to apply the policy as we are discussing, you need to understand your network flow and what communicates with what. We were able to collaborate with the Cisco BU to refine how we consume that data and migrate old policies to the new structure necessary with Cisco Hybrid Mesh Firewall and HyperShield.
AE
Chief Technology Officer at Agileware Limited
Firewall deployment has secured mission-critical public apps and simplifies Linux-based management
The best features IPFire offers include its very intuitive nature because, even though it has a Linux back-end, in terms of configuration, it has a very rich GUI interface. The GUI and configuration features of IPFire have made my work easier and more efficient because their positioning and the sequence with which I follow is easy. In terms of all the processes, what you need to do at first and the next thing that you need to do is clear. The GUI is well arranged in sequential order, so you can follow that from whatever you want to do until you get the target objective. IPFire includes features with a very robust and rich community that is very much valid in terms of content. IPFire has positively impacted my organization by giving us some mileage. At least, a lot of organizations now know that we have a solution that can deliver the same value.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The product is easy to configure."
"The SD-WAN function is very developed; it has SD-WAN functionality with security features in one device, and we can manage from one single console SD-WAN and the security policy."
"The multi-threat protection feature helps us secure our organization."
"The solution is stable and reliable."
"The solution has very good threat and content filtering switches."
"Fortinet Secure SD-WAN delivered the lowest total cost of ownership (TCO) per Mbps among all other vendors."
"FortiGate improved our security. It's one of the best hardware firewalls."
"It provides security purposes, and it makes our network safe from outside attacks."
"Specific outcomes that show the positive impact of Cisco Hybrid Mesh Firewall include that, with a single management environment to perform many different network changes on, we find that we can aggregate different change requests through the change management program without having to split things up."
"I believe there is a return on investment with Cisco Hybrid Mesh Firewall for every company that deploys it, as they typically see returns quickly, often within a few months, and the value measured is reasonable and comes back quickly."
"What I appreciate most about Cisco Hybrid Mesh Firewall is the visibility that I gain into the network."
"Cisco Hybrid Mesh Firewall optimizes the experience in a hybrid or distributed enterprise setup, and it has improved considerably with centralized management enhancements, making the experience much better now."
"A year and a half after working with them, it has paid off tenfold, and we would not have been where we are now if we had gone with the traditional Nexus platform."
"The most valuable feature is the integration with all of the other Cisco tools that we have, and its platform-first approach."
"I would rate the stability as ten out of ten for IPFire."
"Regarding IPFire's AI capabilities, I think they are quite focused; in all the deployments I have done, I have not had any incidents or breaches."
"IPFire has prevented any kind of hacking and enables us to comply with customer requirements."
 

Cons

"The firmware needs improvement because there are bugs when a new release comes through. Sometimes, the configuration changes, and it's a bit harder to see where the fail is. The first time that you have the firmware, it tends to have some issues, and it's better to wait a bit to update the equipment."
"We also have FortiAnalyzer deployed here, so we want to enable the soft functionality of FortiGate and built-in compression for a firewall VPN use case. We want the ability to deploy a gateway for HTTPS enabled on this firewall. It is currently only for use in our headquarters."
"The only problem that we have here in China is that the whole subscription process on Fortinet is a little bit difficult if you are doing it from China."
"They have recently acquired a CNAP solution which should be integrated into FortiGate boxes natively for protection at any application layer. Since Fortinet FortiGate has Layer 7 protection, they should integrate that as soon as they can for threat detection and network detection."
"Fortinet FortiGate could improve by having more capabilities for troubleshooting VPN connections. For example, I do get some feedback about the current status, but I could use some history and logging of important events. The information is logged in our Syslog server, but I could use that information from the device. If they could provide a GUI to have some more insight on what's going with my VPN would be useful."
"Fortinet Fortigate could benefit by simplifying some of their processes."
"There are SD-WAN network monitoring, SD-WAN features, Industrial Databases, Internet of Things, Detection, etc., however, we do have not licenses for those features. We thought that if you bought a product, you should have all of the features it offers. Why should you need to make so many extra purchases to enable features? They should have one price for the entire offering."
"Monitoring and reporting could be better."
"My experience with deploying Cisco Hybrid Mesh Firewall has been effective, with certain challenges and successes."
"The biggest issue we encountered was a gap between expectations for features relating to the design team versus the coding team."
"For improving Cisco Hybrid Mesh Firewall, licensing is always a pain point and represents the worst aspect of the solution."
"Regarding how Cisco Hybrid Mesh Firewall can be improved, I would say pricing and discount structures could be enhanced."
"Cisco Hybrid Mesh Firewall could be improved by refining the documentation around the migration path from Cisco Defense Orchestrator or Farsight Manager because when we were early adopters, the migration path was quite unset and very vague and ambiguous."
"The graphical interface could be much better."
"I would rate IPFire 8 out of 10 because I do not think there is any solution anywhere in the world that is 100 percent efficient."
"Accessing the internet was a bit complicated."
 

Pricing and Cost Advice

"The pricing for the product is alright."
"The value is the capability of having multiple services with one unique license, not having the limitation per user licensing schema, like other vendors."
"FortiGate Next Generation Firewall is an expensive solution with a yearly subscription."
"Pricing for this product is comparatively lower than other products. It's an affordable solution, but when expanding the number of users, they'll ask you to replace the model, so that's an added cost."
"The pricing is justified. It's a little pricey, but what you pay for is what you get."
"The pricing or licensing of Fortinet FortiGate is quite effective as it offers different bundles that aggregate most required features, while also allowing clients the option to select specific components alone."
"It's very competitive."
"Fortigate's pricing is competitive."
Information not available
Information not available
report
Use our free recommendation engine to learn which Firewalls solutions are best for your needs.
902,495 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Comms Service Provider
10%
Computer Software Company
9%
Manufacturing Company
9%
Financial Services Firm
7%
No data available
Comms Service Provider
21%
Computer Software Company
10%
University
8%
Government
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business369
Midsize Enterprise139
Large Enterprise195
No data available
No data available
 

Questions from the Community

Which is the better NGFW: Fortinet Fortigate or Cisco Firepower?
When you compare these firewalls you can identify them with different features, advantages, practices and usage a...
What is the biggest difference between Sophos XG and FortiGate?
From my experience regarding both the Sophos and FortiGate firewalls, I personally would rather use FortiGate. I know...
What are the biggest technical differences between Sophos UTM and Fortinet FortiGate?
As a solution, Sophos UTM offers a lot of functionality, it scales well, and the stability and performance are quite ...
What is your experience regarding pricing and costs for Cisco Hybrid Mesh Firewall?
My experience with the pricing, setup cost, and licensing of Cisco Hybrid Mesh Firewall is that it was minimal compar...
What needs improvement with Cisco Hybrid Mesh Firewall?
Cisco Hybrid Mesh Firewall could be improved by refining the documentation around the migration path from Cisco Defen...
What is your primary use case for Cisco Hybrid Mesh Firewall?
My main use case for Cisco Hybrid Mesh Firewall is the consolidation of multiple tools into one management platform.A...
What needs improvement with IPFire?
The graphical interface could be much better.
What is your primary use case for IPFire?
I use IPFire ( /products/ipfire-reviews ) to protect my home.
What advice do you have for others considering IPFire?
Sometimes configuring IPFire is challenging. Overall, I would rate this solution as eight out of ten.
 

Also Known As

Fortinet FortiGate Next-Generation Firewall
No data available
No data available
 

Overview

 

Sample Customers

Amazon Web Services, Microsoft, IBM, Cisco, Dell, HP, Oracle, Verizon, AT&T, T-Mobile, Sprint, Vodafone, Orange, BT Group, Telstra, Deutsche Telekom, Comcast, Time Warner Cable, CenturyLink, NTT Communications, Tata Communications, SoftBank, China Mobile, Singtel, Telus, Rogers Communications, Bell Canada, Telkom Indonesia, Telkom South Africa, Telmex, Telia Company, Telkom Kenya
Information Not Available
1. Siemens 2. IBM 3. Cisco 4. Dell 5. HP 6. Intel 7. Oracle 8. Google 9. Microsoft 10. Amazon 11. Apple 12. Facebook 13. Twitter 14. Netflix 15. Adobe 16. SAP 17. VMware 18. Juniper Networks 19. Ericsson 20. Nokia 21. AT&T 22. Verizon 23. T-Mobile 24. Vodafone 25. Orange 26. Deutsche Telekom 27. British Telecom 28. Comcast 29. Time Warner 30. Sony 31. Samsung 32. LG
Find out what your peers are saying about Cisco Hybrid Mesh Firewall vs. IPFire and other solutions. Updated: June 2026.
902,495 professionals have used our research since 2012.