Fortinet FortiGate vs Fortinet FortiGate-VM comparison

Cancel
You must select at least 2 products to compare!
Comparison Buyer's Guide
Executive Summary
Updated on Sep 5, 2022

We performed a comparison between Fortinet Fortigate and Fortinet Fortigate VM based on our users’ reviews in five categories. After reading all of the collected data, you can find our conclusion below.

  • Ease of Deployment: Most reviewers of both solutions say that their initial setup is straightforward.
  • Features: Users of both products are happy with their stability and scalability.

    Fortinet Fortigate users say that it is flexible and secure with very good threat and content filtering switches. Several users note that they would like better integration options with third-party tools.

    Fortinet Fortigate VM reviewers say that it provides them with good visibility and it has good monitoring features and an intuitive UI. Some users mention that it needs better automation.
  • Pricing: Most users of both solutions say that they are fairly priced.
  • ROI: Reviewers of both solutions report seeing an ROI.
  • Service and Support: Fortinet Fortigate reviewers report being satisfied with the level of support they receive. In contrast, Fortinet Fortigate VM reviewers say that the support needs to improve.

Comparison Results: Fortinet Fortigate is the winner in this comparison. According to reviews, it has better support than Fortinet Fortigate VM.

To learn more, read our detailed Fortinet FortiGate vs. Fortinet FortiGate-VM Report (Updated: January 2023).
672,411 professionals have used our research since 2012.
Q&A Highlights
Question: How is FortiGate-VM different from the physical FortiGate firewall?
Answer: The root of all is VM. A virtual environment is software running on someone else machine/s. Welcome to the the cloud. Sadly, no one stops to think but with the excuse of "lower costs" many fall for it. Performance is the key word. Avoid VMware and the likes. What appears cheap may have a big price in the end. There is no way performance on your own physical machine will be close to the cloud, and there are heaps more things in the equation. Fortinet appliances have their own semiconductors chips to handle in hardware traffic and other duties. Harry Potter does not exist. Costs or prices, are figures in invoices, but the coefficient of elasticity with time may be a surprise. Needless to say the networking traffic handling and the security implication in multi tenancy instances. Yes, in some things could work, but I personally avoid them as much as I can.
Featured Review
Quotes From Members
We asked business professionals to review the solutions they use.
Here are some excerpts of what they said:
Pros
"With the pandemic, people began working from home. That was a pretty big move, having all our users working from a home. More capacity needed to be added to our remote VPN. ASA did this very well.""Even in very big environments, Cisco comes in handy with configuration and offers reliability when it comes to managing multiple items on one platform.""It brings us the ability to work from anywhere and has allowed us to work remotely without having to incur a lot of other costs. If we didn't have this type of solution, since we have so many on-prem services that are required, we would have likely lost money and been unable to deliver. We have a video services team who helped build the content for our sporting events. When you are watching a Leaf game and those swipes come by as well as the clips and things, those are all generated in-house. Without the ability to access our on-premise resources, we would have been dead in the water. So, the return on that is pretty impressive.""I have found the most valuable feature to be the access control and IPsec VPN.""Firepower has reduced our firewall operational costs by about 25 percent.""It has definitely improved our organization. It gives us remote connectivity, helps workers connect remotely, and also gives us good connectivity to our other branches.""Cisco ASA provides us with very good application visibility and control.""Its Snort 3 IPS has better flexibility as far as being able to write rules. This gives me better granularity."

More Cisco Secure Firewall Pros →

"Some of the valuable features are the firewall, IPS, web filter, and gateway capabilities. Additionally, it is easy to use and flexible.""It increases security posture and is helpful for firewall reporting, intrusion protection, web filtering, and SD-WAN implementation.""Initial setup is easy to configure.""The dashboard I have found the most valuable in Fortinet FortiGate.""The scalability of Fortinet FortiGate is good.""The most valuable feature is the interface, which is very user friendly. We are utilizing most of the features, like content filtering. The firewall is powerful.""It is easy to use. We chose this product for the possibility to have virtual domains (VDOMs). We are building another company in the group, and we would like to split the firewalling rules and policies between these two companies. Each company would be able to manage its own policies and security rules, which is an advantage of Fortinet FortiGate. We can define VDOMs, and every company can manage its own VDOM as if it has its own physical firewall, but in fact, we would be using the same physical appliance because we are also using the same internet lines. So, it allows us to reuse the existing resources without the disadvantage of having to compromise on policies and security. Each company can choose its own way of working.""FortiGate Secure SD-WAN includes best-of-breed next-generation firewall (NGFW) security, SD-WAN, advanced routing, and WAN optimization capabilities, delivering a security-driven networking WAN edge transformation in a unified offering."

More Fortinet FortiGate Pros →

"The initial setup is very user-friendly.""The solution offers good documentation.""FortiGate-VM's firewall is excellent.""The most valuable features of Fortinet FortiGate-VM are the servers, analyzer, and track protection.""The most valuable features are the IPS and Antivirus.""Good for the servers and can stop network attacks, including spam.""The most valuable feature is geofencing, where we can block all access from all non-domestic locations.""Its performance is adequate. We are quite satisfied with its performance. The fact that it is a complete ecosystem with all kinds of integrations is valuable. It did take us a couple of months to get a grip on the new software, but all in all, it replaced our on-premise and single-point solution environment."

More Fortinet FortiGate-VM Pros →

Cons
"Licensing is complex, and I'd like it to be simplified. This is an area for improvement.""We are replacing ASA with FTD which offers many new features not available using ASA.""Sometimes, it is not easy to troubleshoot. You need to know where to go. It took me quite awhile. It's like, "Okay, if it doesn't go smoothly here, then go find the documentation." Once you do it, it is not so bad. However, it is sometimes a steep learning curve on the troubleshooting part of it.""The solution has not had any layer upgrades. It does not have layer five and upwards, it only has up to layer four. This has caused some problems for us.""It would be good if Cisco made sure that the solution supports all routing protocols. Sometimes it doesn't.""Nowadays, nobody is in the office, so I need to figure out how to put the firewall outside. If I could have a centralized firewall that also receives information from external locations, like peoples' home offices, that would help us consolidate everything into one appliance.""The Firepower FTD code is missing some old ASA firewalls codes. It's a small thing. But Firepower software isn't missing things that are essential, anymore.""The ability to better integrate with other tools would be an improvement."

More Cisco Secure Firewall Cons →

"The stability of Fortinet FortiGate could improve.""Fortinet FortiGate could improve by having a frequent ask questions(FAQ) area for people to receive quick answers to popular questions. Additionally, it would be beneficial to have an SMS notification feature. For example, if you cannot access your email you could receive an SMS message.""The solution's framework needs to be frequently updated in order to have a stable solution.""The solution could be more secure and stable.""Fortinet FortiGate could improve the user interface. There should be more functionality and options through the GUI.""We had some issues in the beginning while setting it up, but after doing the firmware update, it is working fine.""The support team for Fortinet FortiGate needs to be more customer friendly.""There are some tiny bugs that sometimes affect the operations. In the past revision of it, there was a bug. Because of the bug, we had to downgrade the version. It happened only with the last revision."

More Fortinet FortiGate Cons →

"It needs an Application Inspection.""They should keep us up to date about the latest version. That's the biggest thing. Currently, we have to go looking for the latest version. We should get notified about what's going on with the versions. I would like to see easier dual-factor authentication.""The solution should provide more useful GUI features.""To improve FortiGate-VM, Fortinet needs to harden it more. For example, if you are using Hyper-V, then you need guidelines for hardening FortiGate-VM that are specific to the Hyper-V environment. If it's VMware, there should be at least a guideline on how to harden the firewall.""I have worked on some of the largest and smallest solutions that Fortinet sells and they all scale really well.""There are certain GUI features that should be present but are not.""The performance could be better. Some features need to have quality control when the switch is working. The dedicated bandwidth for some users is not reliable.""Their offering for MFA isn't the cleanest."

More Fortinet FortiGate-VM Cons →

Pricing and Cost Advice
  • "The price for Firepower is more expensive than FortiGate. The licensing is very complex. We usually ask for help from Solutel because of its complexity. I have a Cisco account where I can download the VPN client, then connect. Instead, I create an issue with Solutel, then Solutel solves the case."
  • "I know that licensing for some of the advanced solutions, like Intrusion Prevention and Secure Malware Analytics, are nominal costs."
  • "It is affordable. The hardware is not that expensive anymore. It is a matter of licensing these days."
  • "Cisco is not for a small mom-and-pop shop because of the cost, but if you're in a regulated industry where a breach could cost you a million dollars, it's a bargain."
  • "I like the Smart Licensing, because it is more dynamic and easier to keep track of where you are at. If we have a high availability firewall pair and they are deployed in active/standby rather than active/active, I would expect that we would only pay for one set of licenses because you are using only one firewall at any one time. The other is there just for resiliency. The licensing, from a Firepower perspective, still requires you to have two licenses, even if the firewalls are in active/standby, which means that you pay for the two licenses, even though you might only be using one firewall any one time. This is probably not the best way to do it and doesn't represent the best value for money. This could be looked at to see if it could be done in a fairer way."
  • "We are happy with its price. Licensing is on a yearly basis for technical support. There is one license for technical support. There is another license for IP Version 2 VPN and IPS."
  • "I am happy with the product in general, including the pricing."
  • "Their pricing is very aggressive and good. Even a small company can afford it. I am happy with its pricing. Its licensing is on a yearly basis."
  • More Cisco Secure Firewall Pricing and Cost Advice →

  • "Fortinet Secure SD-WAN delivered the lowest total cost of ownership (TCO) per Mbps among all other vendors."
  • "I had to pay for the license for the firewall, but it is guaranteed to have updates. I expect a good service for it. It was about €1000 for a year, and there was no additional cost."
  • "It is more expensive than Sophos. Fortinet is overall more expensive than Sophos. The small range of Fortinet, such as 60F and 80F, is more expensive than the small range of Sophos. Sophos is cheaper. In addition, if you jump from 80F Series to 100F Series, the price doubles."
  • "The license is yearly. We pay for the top end. It's called 360."
  • "Here in Brazil, we're going through difficult economic times and the tax on the dollar is high. All the solutions from minor competitors are growing in the market. The prices have come more competitive."
  • "Licensing for Fortinet FortiGate is on a yearly basis. Pricing for it is a bit high. It could be cheaper."
  • "The licensing scheme of Fortinet is better than Cisco. It is more logical."
  • "The solution requires a license annually, it is not a user license, you can have as many users as your want. I must renew the license regularly per device."
  • More Fortinet FortiGate Pricing and Cost Advice →

  • "There is no additional cost. Once you get the licensing fee, you're good."
  • "There should be a reduction in the setup price and licensing costs."
  • "The price could be lower."
  • "There is a support fee that can be bought on a yearly or two-yearly basis. I don't think they do five years. The best benefit is that the same pricing is guaranteed for that duration. If you can afford it, I would recommend using the longest possible time span."
  • "We are on an annual license for this solution and it could be cheaper."
  • "At present, the SD-WAN licenses are on an annual basis."
  • "The customer must buy his own license."
  • "Licensing is pretty standard. It's approximately 15% of the total cost per year as a subscription cost."
  • More Fortinet FortiGate-VM Pricing and Cost Advice →

    report
    Use our free recommendation engine to learn which Firewalls solutions are best for your needs.
    672,411 professionals have used our research since 2012.
    Answers from the Community
    Rose Taherzadeh
    Lindsay Mieth - PeerSpot reviewerLindsay Mieth
    Real User

    Purpose-built appliances offer tested performance measures and provide proven results for the specified traffic and service configuration.  


    VM can only provide vCPUs, RAM, and hard disk resources.  However, in some cloud environments, you only have the VM option, no appliances accepted.  


    We have several Fortigate VM firewalls operating for 3 years now in the cloud and appliances in our centers that handle the traffic just fine. We have not had to increase the resources above the recommendations and they work just fine.

    ABHILASH TH - PeerSpot reviewerABHILASH TH
    Reseller

    FortiGate VM 



    • FortiGate-VM delivers the same FortiOS and FortiGuard real-time threat intelligence as the hardware models, in a virtual form factor.

    • FortiGate-VM offers flexible licensing and provisioning for virtual network deployments.

    • Support for multiple virtualizations and cloud platforms.

    • Full support for Forti Hypervisor deployments enabling line-speed security in vCPE requirement.

    • The architecture of a VM is a little more complex than that of Hardware.


    • Virtual machines are less efficient than real machines because they access the hardware indirectly.


    FortiGate Hardware



    • The hardware firewall is an ASIC-based device.

    • It has hardware limitation, for example, Memory, CPU, etc

    • Easy deployment in the network

    • No complexity

    William Yragui - PeerSpot reviewerWilliam Yragui
    User

    Fortigate appliance is purpose built with NPU and SPUs designed to increase throughput while maximizing the ability to decrypt packets in search of malware. 


    VM deployments are software only and do not include the NPU and SPUs. 

    Questions from the Community
    Top Answer: When you compare these firewalls you can identify them with different features, advantages, practices and… more »
    Top Answer:One of our favorite things about Fortinet Fortigate is that you can deploy on the cloud or on premises. Fortinet… more »
    Top Answer:It is easy to integrate Cisco ASA with other Cisco products and also other NAC solutions. When you understand the Cisco… more »
    Top Answer:From my experience regarding both the Sophos and FortiGate firewalls, I personally would rather use FortiGate. I know… more »
    Top Answer:As a solution, Sophos UTM offers a lot of functionality, it scales well, and the stability and performance are quite… more »
    Top Answer:We have Meraki Mx devices now, we are looking to replace them. But that is because the Meraki MX platform lacks SSL… more »
    Top Answer:In the best tradition of these questions, Feature-wise both are quite similar, but each has things it's better at, it… more »
    Top Answer:Both of these solutions are excellent options that provide flexible scalability and solid security. Fortinet Fortigate… more »
    Comparisons
    Also Known As
    Cisco ASA Firewall, Cisco Adaptive Security Appliance (ASA) Firewall, Cisco ASA NGFW, Cisco ASA, Adaptive Security Appliance, ASA, Cisco Sourcefire Firewalls, Cisco ASAv, Cisco Firepower NGFW Firewall
    FortiGate 60b, FortiGate 60c, FortiGate 80c, FortiGate 50b, FortiGate 200b, FortiGate 110c, FortiGate
    FortiGate Virtual Appliance, FortiGate-VM
    Learn More
    Overview

    The Cisco Secure Firewall portfolio delivers greater protections for your network against an increasingly evolving and complex set of threats. With Cisco, you’re investing in a foundation for security that is both agile and integrated- leading to the strongest security posture available today and tomorrow.

      From your data center, branch offices, cloud environments, and everywhere in between, you can leverage the power of Cisco to turn your existing network infrastructure into an extension of your firewall solution, resulting in world class security controls everywhere you need them.

      Investing in a Secure Firewall appliance today gives you robust protections against even the most sophisticated threats without compromising performance when inspecting encrypted traffic. Further, integrations with other Cisco and 3rd party solutions provides you with a broad and deep portfolio of security products, all working together to correlate previously disconnected events, eliminate noise, and stop threats faster.

      Fortinet FortiGate is an innovative line of firewalls that aim to protect organizations from all types of web-based network threats. They come in a wide variety of product types. Fortinet FortiGate’s solutions are available in a large range of sizes and form factors and are key components of the Fortinet Security Fabric, which enables immediate, intelligent defense against known and new threats throughout the entire network.

      Fortinet FortiGate provides users with next-generation firewall solutions that provide proven protection with unmatched performance across the network, from internal segments to data centers to cloud environments. You can protect every part of your network without exception. Additionally, your protections can be managed from a single central location. This ensures that the task of protecting your network is infinitely easier to accomplish.

      Benefits of Fortinet FortiGate

      Some of the benefits of using Fortinet FortiGate include:

      • The ability to manage your firewalls from a centralized automated control console. Fortinet FortiGate’s FortiManager enables administrators to exercise control of their firewalls in a streamlined manner. Administrators have full visibility and control over their system from a single location. It utilizes automation that collects information in real time, which greatly simplifies and reduces the cost of running various types of workflows. Administrators can free up resources by automating the most basic tasks.
      • The ability to produce uniform, appropriate, and coordinated responses to threats across networks. Fortinet FortiGate’s FortiGuard feature generates system protections in near real time. This allows administrators to address threats to the system with custom-made solutions that can be uniformly enforced.
      • The ability to scale up your security to fit your changing security needs. Fortinet FortiGate’s design allows users to accelerate the transfer of data between users and escalate the number of users that are covered without compromising security of performance. This means that users can grow their networks and continue to collaborate without worrying about the system slowing down or coming under attack.

      Reviews from Real Users

      Fortinet FortiGate’s firewall solutions are cutting edge. They stand out from competitors for a number of reasons. Two major ones are the robustness and power of their firewalls. Fortinet FortiGate’s firewall provides users with many valuable features that allow them to maximize what they can do with the solution. These firewalls enable users to use a single piece of software to accomplish tasks that often require the use of multiple pieces of software.

      PeerSpot user Eric S., a Solutions Engineer and Consultant at a tech-services company, notes the robustness of this solution when he writes, "One of the nice things about FortiGate is that it can be deployed on the cloud or on-premises. You can actually do both. That's the biggest reason why I stick with this solution as opposed to something like Cisco Meraki. Another nice thing is that I can log directly into a FortiGate or get to it through their FortiCloud access products. They're pretty reliable and consistent. One of the reasons why I started using the product was their single pane of management. I can deploy their line of firewalls in conjunction with their switching and access points, and I can manage the entire network from one interface.”

      PeerSpot user Jim M., a network admin at Penobscot Valley Hospital, notes the power of Fortinet FortiGate’s security software when he writes, "It does a lot for you for intrusion protection and as an antivirus. The threat management bundle is worth the money. You don't need another company to monitor your web traffic for you. You can do everything yourself on the firewall. You restrict your own black list for people on the firewall.”

      FortiGate Virtual Appliances allow you to mitigate blind spots by implementing critical security controls within your virtual infrastructure. They also allow you to rapidly provision security infrastructure whenever and wherever it is needed. FortiGate virtual appliances feature all of the security and networking services common to traditional hardware-based FortiGate appliances. With the addition of virtual appliances from Fortinet, you can deploy a mix of hardware and virtual appliances, operating together and managed from a common centralized management platform.

      Offer
      Learn more about Cisco Secure Firewall
      Learn more about Fortinet FortiGate
      Learn more about Fortinet FortiGate-VM
      Sample Customers
      There are more than one million Adaptive Security Appliances deployed globally. Top customers include First American Financial Corp., Genzyme, Frankfurt Airport, Hansgrohe SE, Rio Olympics, The French Laundry, Rackspace, and City of Tomorrow.
      Pittsburgh Steelers, LUSH Cosmetics, NASDAQ, Verizon, Arizona State University, Levi Strauss & Co. Whitepaper and case studies here
      Security7 Networks, COOPENAE
      Top Industries
      REVIEWERS
      Financial Services Firm16%
      Comms Service Provider13%
      Computer Software Company9%
      Government8%
      VISITORS READING REVIEWS
      Computer Software Company20%
      Comms Service Provider17%
      Government8%
      Educational Organization5%
      REVIEWERS
      Comms Service Provider16%
      Financial Services Firm10%
      Computer Software Company10%
      Manufacturing Company7%
      VISITORS READING REVIEWS
      Comms Service Provider20%
      Computer Software Company19%
      Government6%
      Educational Organization5%
      REVIEWERS
      Comms Service Provider16%
      Manufacturing Company11%
      Financial Services Firm11%
      Government5%
      VISITORS READING REVIEWS
      Computer Software Company26%
      Comms Service Provider14%
      Government7%
      Financial Services Firm5%
      Company Size
      REVIEWERS
      Small Business35%
      Midsize Enterprise25%
      Large Enterprise40%
      VISITORS READING REVIEWS
      Small Business28%
      Midsize Enterprise18%
      Large Enterprise53%
      REVIEWERS
      Small Business47%
      Midsize Enterprise23%
      Large Enterprise29%
      VISITORS READING REVIEWS
      Small Business30%
      Midsize Enterprise20%
      Large Enterprise50%
      REVIEWERS
      Small Business49%
      Midsize Enterprise27%
      Large Enterprise24%
      VISITORS READING REVIEWS
      Small Business31%
      Midsize Enterprise18%
      Large Enterprise51%
      Buyer's Guide
      Fortinet FortiGate vs. Fortinet FortiGate-VM
      January 2023
      Find out what your peers are saying about Fortinet FortiGate vs. Fortinet FortiGate-VM and other solutions. Updated: January 2023.
      672,411 professionals have used our research since 2012.

      Fortinet FortiGate is ranked 1st in Firewalls with 84 reviews while Fortinet FortiGate-VM is ranked 9th in Firewalls with 49 reviews. Fortinet FortiGate is rated 8.4, while Fortinet FortiGate-VM is rated 8.4. The top reviewer of Fortinet FortiGate writes "SSL proxy makes URL filtering easier because the encryption is done before the packet ever leaves ". On the other hand, the top reviewer of Fortinet FortiGate-VM writes "Flexible with good cloud management and a straightforward user interface". Fortinet FortiGate is most compared with pfSense, Sophos XG, Meraki MX, Check Point NGFW and Palo Alto Networks NG Firewalls, whereas Fortinet FortiGate-VM is most compared with Azure Firewall, pfSense, Palo Alto Networks VM-Series, OPNsense and Sophos XG. See our Fortinet FortiGate vs. Fortinet FortiGate-VM report.

      See our list of best Firewalls vendors.

      We monitor all Firewalls reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.