Try our new research platform with insights from 80,000+ expert users

FireMon Security Manager vs Palo Alto Networks Panorama vs Skybox Security Suite comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Mindshare comparison

As of September 2025, in the Firewall Security Management category, the mindshare of FireMon Security Manager is 17.8%, up from 15.8% compared to the previous year. The mindshare of Palo Alto Networks Panorama is 7.1%, down from 10.2% compared to the previous year. The mindshare of Skybox Security Suite is 9.5%, down from 10.8% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Firewall Security Management Market Share Distribution
ProductMarket Share (%)
Palo Alto Networks Panorama7.1%
FireMon Security Manager17.8%
Skybox Security Suite9.5%
Other65.6%
Firewall Security Management
 

Featured Reviews

Ganesh-Khutwad - PeerSpot reviewer
Rapid policy insights with robust dashboards and cross-vendor automation
FireMon Security Manager is excellent for real-time compliance management. It allows us to quickly retrieve any policy needed for testing and easily analyze it for loopholes. If a loophole exists, FireMon provides comprehensive details within the policy manager. It alerts us to firewall rule additions or changes that violate compliance policies. It supports various firewall platforms, including Checkpoint, Zscaler, Fortinet, Cisco, and AWS, and provides centralized management for all configured policies through a single console. FireMon Security Manager provides many features, like whether my firewall is compatible with required standards such as NTP and SNMP. Each compliance included in our RFPs is shown in the UI of FireMon. It gives robust and clear dashboards, making it easier to understand risks because the policies have ratings showing usage, and the number of hit attacks. It streamlines our compliance reporting processes by providing comprehensive risk and compliance assessments. It offers a range of features, including verification of firewall compatibility with protocols like NTP and SNMP, and detection of signal charges. FireMon effectively addresses all compliance requirements outlined in our RFPs. For instance, it can determine if firewalls or proxies within a stack are configured in Secure Mode or Active-Active mode. FireMon Security Manager enables us to generate reports on all these aspects, ensuring thorough compliance monitoring and documentation. FireMon Security Manager is robust and can help automate firewall policy changes across large multi-vendor enterprise environments. FireMon Security Manager helps automate firewall policy changes across various environments, including on-premises, cloud, hybrid, SASE, and SD-WAN. It also simplifies cleaning up firewall rules in our environment. The time required to accurately create, approve, and deploy firewall policy rules has been reduced. Tasks that took 30 minutes can now be completed in just five minutes using FireMon. FireMon provides immediate visibility into our policies through a robust and clear dashboard, making it easy to identify errors or misconfigurations based on the policy rating.
Waleed Aboda - PeerSpot reviewer
Centralized monitoring enhances control while seeking greater flexibility and rapid response
I am still working for Lotus. We work with Palo Alto three series, Panorama, and Firewall Banu, specifically Firewall three series and five series I find this solution valuable for full monitoring, centralized control for reporting, and centralized management. These features are instrumental in…
NenadMijatovic - PeerSpot reviewer
Efficient in vulnerability management, stable and easy to use
Vulnerability management is the most valuable feature because it lets you focus on the most critical vulnerabilities. That's the important thing. Here in Serbia, there are not so many companies that have too many firewalls inside one company. So, they usually don't buy this model for Firewall Assurance unless there is some compliance. So you can prove that your firewalls are compliant. So, that model is not so important here in Serbia. It's for bigger companies. So, they usually buy network assurance to build the model of the network and vulnerability management to focus on the most important vulnerabilities. Moreover, Skybox can collect data for many vendors. From the endpoint protection vendors to the network equipment vendors to other security vendors. So, it supports more than one hundred vendors to collect data from them.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Firewall auditing is very important. We also use the solution for rule traffic analysis, traffic flow discovery and hidden/shadow rules within over 100 firewalls spanning five different brands."
"FireMon decreases errors and misconfigurations by 10% that increase risk in our environment. That has to do a lot with the change reporting that is in place, but also with the built-in controls and custom controls that we have made. Those all decrease the errors that people naturally make on a day-to-day basis for firewall administration."
"The most effective feature is the general reporting on compliance."
"Compared to other applications, it is user-friendly. The appearance of the menus and titles is clear and they are easy to follow. Of course, it requires some experience through using it, to go through everything, but it is not very difficult. It is an easy application to use."
"It provides us with a single pane of glass for our on-prem environment, to see configuration. We have not implemented into the cloud yet. We can search for an object group and see where it lives on any firewall in the enterprise or find security rules, no matter what firewall they're on."
"Its user-friendly interface allows for easy viewing and searching of network policies, including proxies, all on one console."
"What I like about FireMon is the ability to track changes made by network engineers on the network."
"The ease of use is the most valuable feature. There are a lot of products out there, but the ability to navigate through and use Firemon is very good."
"Technical support is helpful and knowledgeable."
"The solution is easy to use."
"The solution is suitable for all sized businesses."
"Networks Panorama has improved our organizational security"
"One valuable feature is centralized management. We are able to manage it centrally for two to three remote offices, our head office and our data centers. So, it is very simple to manage."
"The most valuable aspect of Palo Alto Networks Panorama for me is the centralized management of multiple firewalls."
"Panorama has improved the organization by enabling log collection, administration, and optimization of firewall policies. It supports policy migration and offers platform stability and decent uptime."
"It's a reliable solution."
"Robust modules can be used for different parts of network security."
"The ability to appropriately prioritize vulnerabilities inside the environment, and then to have visibility into the traffic and rule sets of an organization, are two of the top capabilities that I recommend. Skybox is the only one that does both of those in a single platform."
"Skybox allows organizations to reprioritize the vulnerability they attempt to patch and mitigate, based on the contextual awareness of the network."
"instead of asking for firewall rules which may or may not be relevant, or could already be there, or could be over-permissioned, Skybox can be used to map out the resources that that application is going to use and provide the exact rules that an application would require to function correctly. If the traffic isn't able to flow for the application, if it's erring out, Skybox can be used to troubleshoot that and say, "All right, where is the traffic being stopped and why, and how do I fix that.""
"The most valuable features of Skybox Security Suite are all the modules that are provided, such as vulnerability assessments and network, and firewall assessments."
"Skybox deployment is simple, and it's very useful."
"The performance could be good because we chose it at the time, but it is too complex for us to appreciate its performance because we lack the necessary skills."
"Change Manager is most important because of the impact on each other of a network change or a firewall change. We want to understand this and to know, beforehand, what the impact of a change will be. We are a large network so that is a very important tool."
 

Cons

"When it comes to real-time compliance management, something that is missing is alerting on certain, predefined controls. It would be good to have a predefined set of controls which, if not complied with in a newly set up rule, would create an alert for us. That is something that is missing, out-of-the-box."
"FireMon could improve its end-user practices. As an end user, I am just trying to catch up on all the alerts. There are so many, and you still have to go through them and document what was found."
"Policy Planner requirements section is good, but could use some improvement to allow flexibility to enter different types of requests (modifying an existing policy, object or service group, for example) in a structured task format that can be auto-verified."
"While I like the reporting, I think that has the biggest room for improvement. Right now, as a user of FireMon, if I create a report, I am the only one who can see it inside FireMon. If someone on my team creates a report, they are the only person who can see that report on FireMon. It doesn't matter if you're admin in FireMon or not. The way we have to do it now is that we have created a service account user and that service account user runs all the reports. This way, all the reports, which are running, are just run under a single user so we can always access them. This definitely needs to change so users can see other users' reports or we can share reports within FireMon."
"The training for configuring new users or operators is confusing because the UI is not user-friendly and has room for improvement."
"Its reporting can be improved. I am the only one who works a lot with it, and I am having problems in terms of reporting. In the case of Palo Alto, I'm okay with it, but with some of the Cisco devices, such as routers, when I provide the reports to other teams for review, they always say that the hit count is incorrect. So, I was struggling for a long time to work with them. When working with other teams, they have a lot of questions about reporting, such as how it reports, and we are still struggling with that."
"We've had recurring issues managing FireMon's internal backups. Sometimes, the space allocated for the backup is full, and there is no process where it deletes files that are older than I certain date. It's just waiting for the storage to get full and then it's cleaned up. It isn't something that creates serious issues for us."
"The advanced features are complex in setting up the rules."
"The solution should improve the speed at which they make changes on the system. Historically, they've been a bit slow in that respect. They should apply changes to the box quicker and more often."
"In our version, there is no feature to transfer or upload a database of third-party vulnerabilities or signatures so that Panorama can convert them into its own database. This kind of feature might already have come in version 10."
"The price of Palo Alto Networks Panorama could be better."
"The setup cost is too high."
"The ability to add scheduled jobs would be a significant improvement. Panorama has the ability to push out OS updates, but it would be nice to be able to schedule those updates so not to affect the site during normal business hours."
"An area for improvement would be the connectivity, which sometimes means logs can be slow to display."
"The ease of use of Palo Alto Networks Panorama is an area for improvement. Another downside is that you need a lot of comprehension to understand what it is."
"There could be more integrations with third parties."
"It's expensive."
"If anything could be improved it would be staying on top of the collector scripts, but I understand that's a very tough challenge."
"The solution needs improvement in firewall configuration checks. I would also like to see more configuration checks for Forcepoint and for other non-supported firewalls."
"Modifications and the deletion of existing policies are currently unavailable."
"The tool does not offer options for customization."
"The solution does not support certain devices or vendors in some regions or countries due to regulations."
"Skybox should improve their UX features by making them easier to use."
"The most recent update was not tested with all of the vendors before it was released, so some of the features are misbehaving."
 

Pricing and Cost Advice

"We pay for it yearly."
"Relative to what it offers, the price is fair."
"Pricing is reasonable."
"Regarding additional costs, if you want things like Policy Optimizer, extra features, that's extra."
"We don't license all of the devices in our network, so it does not provide us with a comprehensive visibility of all devices in a hybrid network at this time."
"Its pricing is good. Compared to others, it is not so expensive."
"The pricing was very good during our initial year, but they increased it this year a little bit. The price is okay. It is not cheap, but it is still average."
"Pricing model seems fair."
"Sometimes the company prefers to give a license to test the product in our environment before we go to the customer. But the customer should buy his own license, and that's the system here. The system is different between one country and another. Some countries say that the IT solutions provider should provide the license."
"Although I don't have direct knowledge of the setup cost I believe it is mid-range."
"We're a reseller, and we're an MSSP. So, we get some extreme discounts."
"It is pretty reasonable as compared to other companies."
"Licensing fees are paid yearly."
"Pricing is high compared to other vendors in the same space. Licensing is also fairly high for different functions to be added on."
"The price of Palo Alto Networks Panorama is high. There is a pay-per-use model."
"The licensing is not cheap. There are always hidden costs. You have support costs, or maybe you need to buy more optics on how the solution fits into the rest of your environment. It is possible some of the rest of your environment will need to change too."
"The price of the Skybox Security Suite can be expensive."
"When compared with other companies, the license is more costly."
"I think the price is fair."
"I would rate the tool's pricing an eight out of ten."
"The product's pricing is excellent value. In terms of licensing, make sure you understand your network components, all your hops through your network, thoroughly, before you decide on the total cost. If you want to do point-to-point flow analysis and such, you need to have the configuration of all the devices in between point A and point B. A lot of people don't realize all their network components until they start using this product."
"The pricing is high, and the licensing model needs more flexibility."
"Currently, the licensing costs me about $300 USD for the year. This is a huge amount for my environment."
"Pricing is on the higher side. In terms of licensing, you should buy the complete suite rather than buying only the Change Manager. I think Change Manager with Vulnerability Control is something that would be interesting to look at."
report
Use our free recommendation engine to learn which Firewall Security Management solutions are best for your needs.
868,183 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
15%
Financial Services Firm
14%
Manufacturing Company
11%
Comms Service Provider
7%
Financial Services Firm
13%
Computer Software Company
12%
Manufacturing Company
11%
Comms Service Provider
11%
Financial Services Firm
18%
Computer Software Company
12%
Manufacturing Company
10%
Energy/Utilities Company
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business9
Midsize Enterprise9
Large Enterprise44
By reviewers
Company SizeCount
Small Business32
Midsize Enterprise14
Large Enterprise47
By reviewers
Company SizeCount
Small Business21
Midsize Enterprise4
Large Enterprise20
 

Questions from the Community

What do you like most about FireMon?
I like the Security Manager console where we can see any changes that have been made or pull the results of an assess...
What is your experience regarding pricing and costs for FireMon?
Comparatively, FireMon has a very good price and is below the general competition in cost. I have not seen any additi...
What needs improvement with FireMon?
For one company I work with, I use Fortinet, and FireMon is not able to understand the zones that Fortinet uses. Part...
What do you like most about Palo Alto Networks Panorama?
The most valuable aspect of Palo Alto Networks Panorama for me is the centralized management of multiple firewalls.
What is your experience regarding pricing and costs for Palo Alto Networks Panorama?
If you go with the cloud-based deployment, it is pretty much affordable. If you go with the physical bare-metal hardw...
What needs improvement with Palo Alto Networks Panorama?
I do see some disadvantages with Panorama. If your staff is not technical enough, you have to be very careful if you ...
What do you like most about Skybox Security Suite?
Overall, the tool has helped us reduce risks. If any step is missing, it's easier for my team or engineers to identif...
What is your experience regarding pricing and costs for Skybox Security Suite?
From a commercial perspective, AlgoSec is more expensive compared to Skybox Security Suite. Skybox Security Suite is ...
What needs improvement with Skybox Security Suite?
The dashboard's UI is not interesting; it is quite normal. It would be better if something more attractive or similar...
 

Overview

 

Sample Customers

Convey, MGM Resorts International, Southwest Airlines, Alkami, Costco, Aetna, IBM, Verizon, Wells Fargo
University of Arkansas, JBG SMITH, Temple University, Telkom Indonesia
ADP, Blue Cross Blue Shield, BT, USAID, Delta Dental, EDF Energy, EMC, HSBC, Johnson & Johnson
Find out what your peers are saying about AlgoSec, Tufin, Palo Alto Networks and others in Firewall Security Management. Updated: August 2025.
868,183 professionals have used our research since 2012.