Try our new research platform with insights from 80,000+ expert users

Forcepoint Next Generation Firewall vs Palo Alto Networks URL Filtering with PAN-DB comparison

Sponsored
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Fortinet FortiGate
Sponsored
Average Rating
8.4
Reviews Sentiment
7.2
Number of Reviews
335
Ranking in other categories
Firewalls (2nd), Software Defined WAN (SD-WAN) Solutions (1st), WAN Edge (1st)
Forcepoint Next Generation ...
Average Rating
7.6
Reviews Sentiment
6.7
Number of Reviews
44
Ranking in other categories
Firewalls (25th), Software Defined WAN (SD-WAN) Solutions (9th), WAN Edge (9th)
Palo Alto Networks URL Filt...
Average Rating
8.6
Reviews Sentiment
6.7
Number of Reviews
13
Ranking in other categories
Intrusion Detection and Prevention Software (IDPS) (12th)
 

Mindshare comparison

Firewalls
Intrusion Detection and Prevention Software (IDPS)
 

Featured Reviews

EhabAli - PeerSpot reviewer
Efficient, user-friendly, and affordable
In the past, NSS Labs was utilized to test files and verify the numbers and datasheets. It would be beneficial to have an organization or testing lab that can verify the numbers in our datasheets since changes are frequently made, which can be inconvenient for review. For instance, when comparing different competitors such as Forcepoint, Palo Alto, and Check Point, the throughput or numbers in the datasheet may be lower than the actual numbers. Conversely, Fortinet typically reports very high numbers, but they cannot be replicated in the real world. Therefore, it would be advantageous for them to partner with a neutral testing organization such as NSS Labs to validate these numbers, thus providing more credibility and comfort to everyone regarding the accuracy of the datasheets. For the migration, everyone has a firewall in use and I am selling Fortinet. Typically, I am replacing another firewall. Previously, there was a tool available to convert configurations from one firewall, such as Palo Alto, to Fortinet, but this tool is no longer free. If it could be made free again, it would be very beneficial. This tool shows a lot of promise and is very good. Making it free would help many companies deliver their products in a more efficient and integrated way. It would also be more valuable to include the tool with the firewall package or license instead of having to pay extra for it. Paying extra puts more pressure on small companies to deliver the firewall and complete the configuration, especially if they have hundreds or thousands of policies. It's very painful to move through these policies line by line. The stability has room for improvement. When it comes to Secure SD-WAN, everything is fine. They are going the right way. SD-WAN is very promising. They can provide the SD-WAN solution separately, but they will not take this approach because even the smallest firewall can support the features, so there is no need to have a separate service or appliance. They are following the right steps, and there is nothing to be improved. Feature-wise, I'm really satisfied with the new release, and the features they have added. For now, it's fine.
OusaidAbaz - PeerSpot reviewer
Provides decent protection for the LAN but complicated interface
We had some licensing issues with its web filtering capabilities. That's why we migrated our web filtering to Cisco Umbrella. Moreover, the interface is complicated. It's difficult to locate all the necessary menus and functions. For example, one of the many issues is with SSH. Even now, we haven't successfully opened the port to connect using SSH mode when we want to change the configuration. It's like a black box—not very open to changes and customization. It's simply not easy to configure. There are other problems, too. For example regarding Forcepoint's Websense component. We had a lot of problems managing the web settings within Websense. That's why we migrated to Cisco Umbrella for cloud-based web filtering. It's not that Forcepoint is inherently bad. The issue is that it's not user-friendly. It is not easy to use. The developers need to redesign the interface (GUI) for better management. It is very difficult to manage. For example, simple actions require too many clicks compared to FortiGate or Palo Alto. That's the main problem.
Abdul  Basit - PeerSpot reviewer
Advanced features and robust support elevate overall network management experience
I think URL filtering could be better to some extent. Improvements could be made in Palo Alto Networks URL Filtering with PAN-DB compared to Sophos. The URL filtering option in Palo Alto gives a very clear vision of the network and the applications using URL filtering. If you assign a user in a group not to access certain URLs, that user should only be allowed to access LinkedIn without running videos. However, deep URL filtering in Palo Alto is not configurable. One user can have access to LinkedIn with video running, while another cannot. They should improve this deep analysis of URL filtering options.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Run Script is the best tool to use in Fortinet FortiGate with multiple environments."
"FortiGate Secure SD-WAN includes best-of-breed next-generation firewall (NGFW) security, SD-WAN, advanced routing, and WAN optimization capabilities, delivering a security-driven networking WAN edge transformation in a unified offering."
"We were looking for the VPN feature and controlling the inflow and outflow of all the traffic within the site and across the sites. We are also using it for the VPN and VLANs."
"We can use our devices to check all of the perimeters. It secures email websites."
"I like that you are able to manage FortiGate from the FortiManager to create a more centralized environment."
"The most valuable feature of Fortinet FortiGate is URL filtering."
"The email protection and VPN features are the most valuable."
"The product has been very stable, based on my ten to eleven years of experience."
"Forcepoint is a complete package because it has network and systems applications. Other firewalls are only for the network."
"One of the most valuable features is having the ability to cluster multiple firewalls even if they are different versions."
"I have two offices, and I can route the internet of both offices using the same product. The connectivity is great."
"The most valuable feature of this solution is the support."
"It is a scalable solution."
"When comparing this solution to others this one has better reporting, user management, and is easy to use."
"The central security management center and the content management center are very good."
"The solution offers sandboxing, which can be integrated at any time."
"The tool blocks URLs."
"The stability of the solution is perfect and totally useful."
"Prohibited URLs can be listed by category."
"Palo Alto Networks URL Filtering with PAN-DB is easy to use, easy to operate, and easy to edit."
"Being able to manage blacklists and whitelists easily is very useful, especially for internal access and limiting outbound access."
"It's allowed us to have better visibility and protection from threats."
"I do not have to use additional security solutions to block the URLs, as PAN-DB and URL filtering are both powerful tools when it comes to security."
"The most valuable feature is that the product can do everything in a single device, including the firewall, rules, and the PBL. It also has good routing and switching."
 

Cons

"There could be more integration between the logging and analytical platforms to make it more seamless and integrated."
"Cisco Meraki products are rising very quickly in the cloud and the connected era. Meraki products offer much better ROI, upgradability, and manageability."
"In terms of what could be improved, the SD-WAN is quite difficult, because if you install the new box, 15 is okay, but if you change from an old configuration, if there is already configuration and a policy when you change to SD-WAN, you must change the whole policy that you see in the interface."
"Fortinet FortiGate could improve by having more storage in the hardware for log data."
"The product does need better support in the cloud environment. It's not exactly cloud-native right now."
"Areas of improvement for Fortinet FortiGate include the need for more training and certification, especially when dealing with distributors globally, which presents challenges in product availability and delivery timelines."
"FortiGate support could do some improvements on their IPv6 configuration. Right now it's still in the very early stage for utilizing in an enterprise level network environment."
"Sometimes you do need to know some CLI commands, so it's a bit harder for technicians or new people that don't know it."
"A VPN client feature is missing in our region, which we hope Forcepoint will address in future updates."
"While they offer a comprehensive bundled solution, some users may prefer on-premise deployments for certain features, such as URL filtering."
"The company should update the URL filtering database. They need to enhance the URL filtering and make it easier to customize."
"Its interface is complex when compared with a firewall like FortiGate. Forcepoint Next Generation Firewall needs a management console, whereas FortiGate doesn't need any console. When you have a few devices, a console is not really necessary. It's good to have a private console only when you have a lot of devices."
"This solution would be improved with the inclusion of custom reporting."
"Forcepoint is a little difficult to configure compared to its competitors."
"Its management center should be easier to use. The management interface of Forcepoint is unique and a little bit different from some of the firewall solutions on which people might have worked before. Sometimes, the customers say that it is not very friendly, and we help them with how to use this management interface. It just takes a little bit of time, and after some time, it gets easy to manage or use. It is quite similar to Palo Alto, Fortinet, and legacy Juniper solutions. Their support should be faster. We have received complaints that they are not responding fast, which is not good for the vendor and us."
"Making this solution easier to use would be an improvement."
"Some software management-wise scalability features need improvement."
"Support needs to be enhanced."
"I think Palo Alto Networks URL Filtering with PAN-DB is too costly compared to others."
"One way Palo Alto can improve is by offering sandboxing. I don't know if they currently offer a sandboxing feature together with the firewall or not. They should provide secure sandboxing with the firewalls."
"It is an expensive solution and not everyone has the budget for it."
"An area for improvement would be the technical support, which can be slow."
"The licensing costs and setup costs are very expensive for us. The price is significantly higher compared to other competitive products."
"The main limitation is that it needs a live Internet connection for ongoing updates."
 

Pricing and Cost Advice

"Fortinet has one or two license types, and the VPN numbers are only limited by the hardware chassis make."
"The price is fair compared to the other competitors."
"The solution requires a license annually, it is not a user license, you can have as many users as your want. I must renew the license regularly per device."
"There is a license to use Fortinet FortiGate."
"The pricing of the solution is very competitive."
"The license is too expensive to renew. The license renewal process is also complex."
"The license is yearly. We pay for the top end. It's called 360."
"Its pricing is good. The advantages of Fortinet FortiGate over its competitors include good pricing and meeting our requirements at a lower cost."
"There is a need to make payments towards the licensing charges attached to the product. The product is not expensive."
"Everything in Forcepoint comes with an individual license, which is kind of a problem. In our last meeting, they said that it may change at the beginning of 2021, and they will try to merge some licenses together. Customers will get more features than what they got previously. We will wait and see."
"It is an affordable product. We purchase its yearly license."
"We have found the price could be reduced. It is a little expensive."
"The solution is expensive."
"Next Generation Firewall is moderately priced."
"It is expensive."
"I believe the licensing fee is for one year, three years, and five years, or something like that. If you wants to increase the support level from a simpler level to platinum, I think that there's a cost. There are differences between every kind of support, but I don't know the numbers."
"Expensive, but that's because it provides everything."
"It is more expensive than ASA but is far cheaper than Checkpoint. So, pricing wise, it is right in the middle."
report
Use our free recommendation engine to learn which Firewalls solutions are best for your needs.
852,098 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Educational Organization
19%
Computer Software Company
14%
Comms Service Provider
7%
Manufacturing Company
6%
Computer Software Company
19%
Financial Services Firm
11%
Manufacturing Company
10%
Government
9%
Financial Services Firm
15%
Computer Software Company
7%
Manufacturing Company
7%
University
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

Which is the better NGFW: Fortinet Fortigate or Cisco Firepower?
When you compare these firewalls you can identify them with different features, advantages, practices and usage a...
What is the biggest difference between Sophos XG and FortiGate?
From my experience regarding both the Sophos and FortiGate firewalls, I personally would rather use FortiGate. I know...
What are the biggest technical differences between Sophos UTM and Fortinet FortiGate?
As a solution, Sophos UTM offers a lot of functionality, it scales well, and the stability and performance are quite ...
What is your experience regarding pricing and costs for Forcepoint Next Generation Firewall?
The licensing model is dependent on negotiation skills, but there is room for improvement. The costs can be high sinc...
What needs improvement with Forcepoint Next Generation Firewall?
The licensing model should be more flexible. I recommend that additional features be included in a single license to ...
What is your experience regarding pricing and costs for Palo Alto Networks URL Filtering with PAN-DB?
Palo Alto Networks URL Filtering with PAN-DB is a bit more expensive than other solutions we have analyzed, but it is...
What needs improvement with Palo Alto Networks URL Filtering with PAN-DB?
I am a fan of Palo Alto Networks and do not notice many negative aspects. However, Palo Alto should not be expected t...
What is your primary use case for Palo Alto Networks URL Filtering with PAN-DB?
Today, we use our firewall for internet and for the consumption of our users. It's also used for internal networks an...
 

Also Known As

FortiGate 60b, FortiGate 60c, FortiGate 80c, FortiGate 50b, FortiGate 200b, FortiGate 110c, FortiGate, Fortinet Firewall
Forcepoint NGFW, Stonesoft Next Generation Firewall, McAfee Network Security Platform, Intel Security Network Security Platform
Palo Alto Networks URL Filtering PAN-DB
 

Overview

 

Sample Customers

Amazon Web Services, Microsoft, IBM, Cisco, Dell, HP, Oracle, Verizon, AT&T, T-Mobile, Sprint, Vodafone, Orange, BT Group, Telstra, Deutsche Telekom, Comcast, Time Warner Cable, CenturyLink, NTT Communications, Tata Communications, SoftBank, China Mobile, Singtel, Telus, Rogers Communications, Bell Canada, Telkom Indonesia, Telkom South Africa, Telmex, Telia Company, Telkom Kenya
California Department of Corrections and Rehabilitation (CDCR)
TRI-AD, Telkom Indonesia
Find out what your peers are saying about Netgate, Fortinet, OPNsense and others in Firewalls. Updated: April 2025.
852,098 professionals have used our research since 2012.