Try our new research platform with insights from 80,000+ expert users

FortiGate Next Generation Firewall (NGFW) vs Palo Alto Networks CN-Series comparison

Sponsored
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Fortinet FortiGate
Sponsored
Ranking in Firewalls
2nd
Average Rating
8.4
Reviews Sentiment
7.2
Number of Reviews
330
Ranking in other categories
Software Defined WAN (SD-WAN) Solutions (1st), WAN Edge (1st)
FortiGate Next Generation F...
Ranking in Firewalls
10th
Average Rating
8.4
Reviews Sentiment
7.4
Number of Reviews
50
Ranking in other categories
ZTNA (5th), Unified Threat Management (UTM) (9th)
Palo Alto Networks CN-Series
Ranking in Firewalls
34th
Average Rating
9.6
Reviews Sentiment
7.4
Number of Reviews
2
Ranking in other categories
No ranking in other categories
 

Featured Reviews

EhabAli - PeerSpot reviewer
Efficient, user-friendly, and affordable
In the past, NSS Labs was utilized to test files and verify the numbers and datasheets. It would be beneficial to have an organization or testing lab that can verify the numbers in our datasheets since changes are frequently made, which can be inconvenient for review. For instance, when comparing different competitors such as Forcepoint, Palo Alto, and Check Point, the throughput or numbers in the datasheet may be lower than the actual numbers. Conversely, Fortinet typically reports very high numbers, but they cannot be replicated in the real world. Therefore, it would be advantageous for them to partner with a neutral testing organization such as NSS Labs to validate these numbers, thus providing more credibility and comfort to everyone regarding the accuracy of the datasheets. For the migration, everyone has a firewall in use and I am selling Fortinet. Typically, I am replacing another firewall. Previously, there was a tool available to convert configurations from one firewall, such as Palo Alto, to Fortinet, but this tool is no longer free. If it could be made free again, it would be very beneficial. This tool shows a lot of promise and is very good. Making it free would help many companies deliver their products in a more efficient and integrated way. It would also be more valuable to include the tool with the firewall package or license instead of having to pay extra for it. Paying extra puts more pressure on small companies to deliver the firewall and complete the configuration, especially if they have hundreds or thousands of policies. It's very painful to move through these policies line by line. The stability has room for improvement. When it comes to Secure SD-WAN, everything is fine. They are going the right way. SD-WAN is very promising. They can provide the SD-WAN solution separately, but they will not take this approach because even the smallest firewall can support the features, so there is no need to have a separate service or appliance. They are following the right steps, and there is nothing to be improved. Feature-wise, I'm really satisfied with the new release, and the features they have added. For now, it's fine.
Juan Solano - PeerSpot reviewer
Implementation improves efficiency and provides greater visibility over issues
One of the most valuable features of FortiGate Next Generation Firewall (NGFW) ( /products/fortigate-next-generation-firewall-ngfw-reviews ) is the ease of usability it offers. It is quite easy for me to learn to use. Additionally, FortiGate Next Generation Firewall (NGFW) has improved our efficiency in setting up security and provided us with more visibility over some issues and incidents we previously faced.
Ahmed_Shalaby - PeerSpot reviewer
Application control excels and integration with monitoring system boosts efficiency
I am an integrator working with Palo Alto Networks CN-Series and Panorama. I have been involved with the implementation of Palo Alto Networks CN-Series The stability of Palo Alto Networks CN-Series is excellent. Application control is one of the most valuable features. Its monitoring capability…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"FortiGate's ability to perform as expected and fulfil our needs has been the most compelling feature for network security."
"The solution provides good threat intelligence feeds."
"The integration with Active Directory is one of the good features. Most of the customers are now looking for the Single Sign-on feature. So, being able to integrate Active Directory with the firewall is useful. It is also easy."
"The solution is highly scalable because they have devices that can handle a large amount of traffic."
"The most valuable feature of the solution revolves around SSL VPN."
"All of the features of Fortinet FortiGate are useful and the security protection is good."
"Fortinet FortiGate's ease of management is the most valuable feature."
"It is useful for protecting and segregating the internal networks from the internet. Most of our customers also use the FortiGate client to connect to their offices by using the VPN client, and of course, they usually activate the antivirus, deep inspection, and intrusion prevention services. They are also using it for web filtering and implementing various policies dealing with forwardings, NAT, etc."
"The solution has helped our organization secure our network and connect remote sites."
"User identification and application identification are valuable features."
"It is easy to install. There is not much complexity involved."
"The firewall and VPN features are the most valuable in protecting our customers' networks."
"The IPS and the application control feature are the most valuable."
"FortiGate Next Generation Firewall (NGFW) 's most valuable features are reporting and filtering."
"FortiGate's threat detection capability is excellent."
"The most valuable feature of FortiGate Next Generation Firewall is its SD-WAN."
"The app inspection is very helpful for network security."
"The stability of Palo Alto Networks CN-Series is excellent."
 

Cons

"In the next release, I would like to see the interface simplified to be more user-friendly."
"Fortinet FortiGate could improve by having more storage in the hardware for log data."
"In my opinion, Fortinet FortiGate could be improved by making the appliance smaller than what we have here, as it is pretty big."
"My only complaint about FortiGate is a lack of QinQ VLAN tunneling. I haven't found this feature in any Fortinet product. You can do this on all Cisco routers, including the smaller models. However, QinQ isn't available on the biggest, most expensive Fortinet units. They still don't have that. I think now we're on software version 6.0, and they still haven't found a solution for QinQ. It isn't a dealbreaker, but that's my main complaint."
"Fortinet needs more memory to save the log files. We need it to save the logs on the hardware and not in the cloud. I know this feature is available in FortiCloud, but if we need this log locally, it is not available."
"There are some complex administration tasks in their administration portal. That needs to be improved."
"The process of configuring firewall rules appears excessively complex."
"One of the features that I would like to have is to do with endpoint production, it should be integrated. For example, the firewall gets notified of any kind of forensic event that needs to be done, such as if there is a ransomware attack and how it originated, all those records have to be available from the firewall, which is not."
"I would like to see improvements in the IPS/IDS feature to enhance protection against attacks from attackers, including ransomware protection."
"The pricing of the solution should be more affordable"
"Someone without certification and experience with other firewalls might find it a bit more challenging to grasp the FortiGate format and its platform layout."
"One area for improvement is the IPS engine."
"The solution's stability should be improved because it is extremely unstable."
"Its technical support could be better."
"There should be better customization in the IPS."
"There should be more testing before releasing software since it can be a little buggy sometimes when new features come out after updates."
"Palo Alto Networks CN-Series could improve on its pricing as it is quite expensive."
"I'd like to see more IOPs features."
 

Pricing and Cost Advice

"The initial setup is super straight forward and as far as the licensing goes for the small product that we have, the pricing was pretty competitive. It wasn't as simple and as cheap as a SonicWall but for the service we would get it was a good price."
"Its price is affordable and lesser than Cisco. Cisco is expensive. In terms of licensing, there is only one issue. If a customer's license has expired a month ago and they do the renewal after one month, Fortinet renews the license from the start of the previous month. The activation of the product is done from the previous month, not from the date of renewal. The customers usually shout and complain that because they are paying today, the renewal should start from today. The support contract renewals or licensing should be renewed from the date of renewal, but Fortinet starts from the day it had expired. It is a loss for customers. They might have had some problems because of which they did not take the license one month before. Fortinet should work on this. Cisco doesn't do this. Cisco always starts from the day they apply for the license."
"It is an inexpensive solution."
"The licensing scheme of Fortinet is better than Cisco. It is more logical."
"We purchased a five-year bundle package, which worked out cheaper than competing solutions."
"We pay for the solution annually."
"I would rate the pricing a five out of ten"
"The pricing is flexible."
"It is an expensive solution."
"The solution is more expensive than Sophos. It could be cheaper. The licensing is on a yearly basis. We have had it for about three years. We must only pay extra for the license, additional requirements, and the hardware box."
"FortiGate Next-Generation Firewall is cheaper than Cisco or CheckPoint."
"The solution's pricing is competitive."
"It's an expensive solution"
"FortiGate Next Generation Firewall is a very cheap solution."
"FortiGate Next Generation Firewall costs our company around $12000 per year."
"I rate FortiGate Next Generation Firewall a five out of ten for pricing."
Information not available
report
Use our free recommendation engine to learn which Firewalls solutions are best for your needs.
850,028 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Educational Organization
20%
Computer Software Company
14%
Comms Service Provider
7%
Manufacturing Company
6%
Computer Software Company
19%
Comms Service Provider
11%
Financial Services Firm
9%
Manufacturing Company
7%
No data available
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
 

Questions from the Community

Which is the better NGFW: Fortinet Fortigate or Cisco Firepower?
When you compare these firewalls you can identify them with different features, advantages, practices and usage a...
What is the biggest difference between Sophos XG and FortiGate?
From my experience regarding both the Sophos and FortiGate firewalls, I personally would rather use FortiGate. I know...
What are the biggest technical differences between Sophos UTM and Fortinet FortiGate?
As a solution, Sophos UTM offers a lot of functionality, it scales well, and the stability and performance are quite ...
What do you like most about FortiGate Next Generation Firewall (NGFW)?
The tool's most valuable feature is IPS. In my experience, I haven't encountered any issues with integration. It easi...
What is your experience regarding pricing and costs for FortiGate Next Generation Firewall (NGFW)?
The pricing of the FortiGate firewall is good. It offers cost savings as it is generally cheaper than the competition.
What needs improvement with FortiGate Next Generation Firewall (NGFW)?
There should be more testing before releasing software since it can be a little buggy sometimes when new features com...
What is your experience regarding pricing and costs for Palo Alto Networks CN-Series?
The pricing of Palo Alto Networks CN-Series is quite expensive, rating around eight on a scale of one to ten for cost.
What needs improvement with Palo Alto Networks CN-Series?
Palo Alto Networks CN-Series could improve on its pricing as it is quite expensive. The SD-WAN implementation using P...
What is your primary use case for Palo Alto Networks CN-Series?
I am an integrator working with Palo Alto Networks CN-Series ( /products/palo-alto-networks-cn-series-reviews ) and P...
 

Also Known As

FortiGate 60b, FortiGate 60c, FortiGate 80c, FortiGate 50b, FortiGate 200b, FortiGate 110c, FortiGate, Fortinet Firewall
No data available
No data available
 

Overview

 

Sample Customers

Amazon Web Services, Microsoft, IBM, Cisco, Dell, HP, Oracle, Verizon, AT&T, T-Mobile, Sprint, Vodafone, Orange, BT Group, Telstra, Deutsche Telekom, Comcast, Time Warner Cable, CenturyLink, NTT Communications, Tata Communications, SoftBank, China Mobile, Singtel, Telus, Rogers Communications, Bell Canada, Telkom Indonesia, Telkom South Africa, Telmex, Telia Company, Telkom Kenya
Information Not Available
Information Not Available
Find out what your peers are saying about FortiGate Next Generation Firewall (NGFW) vs. Palo Alto Networks CN-Series and other solutions. Updated: April 2025.
850,028 professionals have used our research since 2012.