No more typing reviews! Try our Samantha, our new voice AI agent.

IPFire vs Palo Alto Networks NG Firewalls comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Jan 25, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Fortinet FortiGate
Sponsored
Ranking in Firewalls
1st
Average Rating
8.4
Reviews Sentiment
6.8
Number of Reviews
591
Ranking in other categories
Secure Web Gateways (SWG) (2nd), Intrusion Detection and Prevention Software (IDPS) (1st), Software Defined WAN (SD-WAN) Solutions (1st), WAN Edge (1st), ZTNA (1st), Unified Threat Management (UTM) (1st)
IPFire
Ranking in Firewalls
35th
Average Rating
8.0
Reviews Sentiment
8.5
Number of Reviews
2
Ranking in other categories
No ranking in other categories
Palo Alto Networks NG Firew...
Ranking in Firewalls
6th
Average Rating
8.6
Reviews Sentiment
7.2
Number of Reviews
199
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of May 2026, in the Firewalls category, the mindshare of Fortinet FortiGate is 16.0%, down from 21.6% compared to the previous year. The mindshare of IPFire is 1.2%, down from 1.7% compared to the previous year. The mindshare of Palo Alto Networks NG Firewalls is 5.1%, up from 3.6% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Firewalls Mindshare Distribution
ProductMindshare (%)
Fortinet FortiGate16.0%
Palo Alto Networks NG Firewalls5.1%
IPFire1.2%
Other77.7%
Firewalls
 

Featured Reviews

Abhinandan Yadav - PeerSpot reviewer
Network Security Engineer at a retailer with 11-50 employees
Unified security and sd-wan have improved uptime and cut wan costs for multi-site branches
Users report stability issues in certain versions, which requires regular updates. Real-world attacks have also highlighted the need for urgent patching of vulnerabilities.Fortinet FortiGate, while a powerful and feature-rich web firewall, could improve in areas like firmware stability, documentation, and ease of use. The learning curve can be steep for some users. For beginners, support quality can vary, and frequent updates with occasional vulnerabilities call for careful patch management. However, once Fortinet FortiGate is configured, it remains highly reliable and efficient. Customer support needs improvement, as I find it very slow, with reports from other users reflecting that customer support is inadequate.
DS
Head Competence Team IT at Duktig Brand
Blocking access from specific countries and ensuring robust security have been effortlessly achieved
I use IPFire to protect my home The best feature of IPFire is the location block functionality. It allows me to block certain countries from accessing my site. Additionally, it is a solution that is available for free, which is perfect. The graphical interface could be much better. I have…
Abhinandan Yadav - PeerSpot reviewer
Network Security Engineer at a retailer with 11-50 employees
Advanced visibility has transformed security policies and provides proactive threat prevention
Palo Alto Networks NG Firewalls are powerful, but there are areas for improvement that could enhance their effectiveness, such as cost and licensing models. One of the main challenges we face is the high cost, especially for small to mid-sized businesses (SMBs), with licensing for features such as threat prevention, URL filtering, and WildFire being quite expensive. Additionally, centralized management with Panorama is a dependency for managing multiple firewalls, leading to added costs and complexity, and the built-in centralized management features could be made more user-friendly. Moreover, the learning curve associated with the initial setup and advanced configuration including NAT, decryption, and routing can be complex for new users, and enhancements in logging and reporting could also improve the user experience. There are a few more areas where improvements could streamline operations, such as optimizing commit times. Sometimes committing changes takes a noticeable amount of time, particularly for larger configurations, so a faster commit option would significantly help during urgent troubleshooting. Easier policy troubleshooting is necessary as well. Even though logs are detailed, finding the exact rule match and issue can still be time-consuming in complex environments, so having automated policy simulation and a recommendation tool would expedite troubleshooting. Additionally, better default templates and best practices for SMB data centers and branch offices would speed up deployment and reduce errors. Enhancing integration visibility through a unified dashboard would simplify monitoring, and improving the firmware upgrade process to allow for a more seamless zero downtime upgrade would also enhance operations, as upgrades are stable but typically require careful planning and downtime.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"It has a good UI and overall integration, including FortiGate Manager for controlling all firewalls from a single place."
"We find it's good for managing the network and offers good defense against attacks."
"There is a tool called FSSO, which is a single sign-on user ID agent that works perfectly."
"ROI is very high, it has hands-down the best price/performance/features ratio in the market."
"The most valuable features of Fortinet FortiGate are the APIs. They are the most widely known."
"The most valuable feature of Fortinet FortiGate is security, as they are known for efficiency and are on the top of Gartner Quadrant reviews, with an easy-to-use platform, a good graphical interface, simple configuration, and an overall good layer of security."
"I advise others Fortinet FortiGate has an easy configuration and it does not take much time to learn about the rules that you will need to apply for your company."
"I have found Fortinet FortiGate to be scalable."
"IPFire has prevented any kind of hacking and enables us to comply with customer requirements."
"I would rate the stability as ten out of ten for IPFire."
"Decryption is one of Palo Alto Networks NG Firewalls' best features because we can decrypt by category. For instance, we can decrypt everything except for bank traffic so that we don't interfere with the passwords and two-factor authentication of those checking their bank accounts at work. We can still monitor for malware and other threats that come through a secure channel. It's seamless for users. The URL filtering and IPS are both great as well."
"One of the simple features I like about Palo Alto firewalls is that it's extremely easy to find out what's happening in the network. The reporting is phenomenal, and it's easy to find which threats have been detected and what traffic is going through the box. When a customer notices something is wrong, you can quickly check the amount of traffic going through the firewall around that time. If there is anything out of the ordinary, you can decide it needs to be investigated further."
"I like the firewall's vulnerability management features, which give you reminders to update your system and update your OS."
"The tool's most valuable features are its security features, which are highly valued based on market standards and Gartner reports. We conducted a POC before procuring it, and from that perspective, it is very good. The machine learning feature helps prevent more threats, but no device or firewall can be 100 percent secure because threats evolve daily."
"The application IDs, application controls, URL filtering, visibility, monitoring, and reporting are the most valuable features."
"The solution is scalable"
"The structure is much faster and more sophisticated than Cisco."
"Palo Alto Networks NG Firewalls is an all-in-one solution; it provides every entity log, which is a very good functionality of this firewall, giving every packet and aspect that the firewall is performing through its logs, and it does it very well."
 

Cons

"The central management for the FortiGate Fortinet Firewall needs improvement. They have the manager to do the essential management for both SD-WAN and the security policy."
"The cloud management and automation capability could be improved."
"While the security is good, we'd always prefer if it was even better to ensure protection."
"Their software support needs improvement. I would prefer to have better support for bug fixes. Sometimes, we open a ticket, and it is very difficult to get a solution. Specifically, we are not at all happy with their support for load balancing."
"Not all features are available in the web UI. Features such as enabling multiple MPLS circuits can only be accomplished through the command line, so these need to be made available in the web UI."
"The pricing of the solution is expensive, so it could be cheaper."
"The way everything is set up could be easier. Currently, people need a lot of experience and knowledge to administer it and to link it to devices."
"The solution has many heightened points which we cannot get to without working on CLI."
"The graphical interface could be much better."
"Accessing the internet was a bit complicated."
"When the primary Palo Alto Networks firewall fails over to the secondary, it requires manual intervention to bounce the IPsec for it to work properly. Unlike BGP peering, which automatically changes from idle to established, this process needs automation."
"Sometimes some of the applications the customer has do not respond as they normally should."
"Palo Alto recently introduced a security analyzer in version ten, but this feature could be enhanced, and the URL filtering improved."
"Palo Alto Networks NG Firewalls should be more flexible and user-friendly. There should be more comprehensive documentation, case histories, and technical training on new technologies available on their portal."
"The advanced manual protection needs to be improved a little bit because they used to make a cloud manual analysis for the cloud."
"In the cloud, the HA could be a lot better."
"The reports it provides are not helpful. They should include more executive summaries and other important information — they're too technical."
"In terms of what could be improved, comparatively the price is very high. That would be the one thing."
 

Pricing and Cost Advice

"I would rate the pricing a six out of ten, where one is cheap and ten is expensive."
"FortiGate Next-Generation Firewall is cheaper than Cisco or CheckPoint."
"FortiGate Next Generation Firewall is a very cheap solution."
"Fortinet FortiGate IPS' licensing is quite simple to understand."
"Fortinet prices are around $600 for the small 40F model, and for licenses, the simplest option is about $300 for a year. They sell licenses that can last for 1, 2, 3, or 5 years."
"The solution's price is average."
"It is expensive. You need to pay for the subscription every year, which is very expensive. The subscription includes technical support and hardware exchange in case of failure."
"The product is expensive."
Information not available
"Its price can be better. Licensing is on a yearly basis."
"I do not have much opinion on that because I have not been involved in the procurement process of the Palo Alto devices with the exception of pay-as-you-go through AWS, but all of this stuff is very expensive, in my opinion."
"The licensing leaves a lot to be desired. We buy the license and then we can't transfer the license without paying an exorbitant fee to our client if they leave us, and that just seems to be a bit of a pain point for us, and there's really no way to partner effectively to make that more reasonable."
"I am not sure about the specific licensing costs of Palo Alto Networks NG Firewalls, but FortiGate and Palo Alto are generally cheaper than some high-end Cisco devices."
"The price is expensive, especially in Turkey, where I am located... Palo Alto is very expensive compared to other vendors, like Fortinet."
"Palo Alto Networks NG Firewalls are expensive compared to other solutions."
"The cost is steep, but most firewalls cost a lot."
"It's an expensive product."
report
Use our free recommendation engine to learn which Firewalls solutions are best for your needs.
893,915 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
10%
Comms Service Provider
10%
Manufacturing Company
9%
Financial Services Firm
7%
Comms Service Provider
21%
Computer Software Company
10%
Manufacturing Company
8%
University
7%
Computer Software Company
10%
Manufacturing Company
9%
Financial Services Firm
8%
Comms Service Provider
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business367
Midsize Enterprise135
Large Enterprise193
No data available
By reviewers
Company SizeCount
Small Business77
Midsize Enterprise56
Large Enterprise85
 

Questions from the Community

Which is the better NGFW: Fortinet Fortigate or Cisco Firepower?
When you compare these firewalls you can identify them with different features, advantages, practices and usage a...
What is the biggest difference between Sophos XG and FortiGate?
From my experience regarding both the Sophos and FortiGate firewalls, I personally would rather use FortiGate. I know...
What are the biggest technical differences between Sophos UTM and Fortinet FortiGate?
As a solution, Sophos UTM offers a lot of functionality, it scales well, and the stability and performance are quite ...
What needs improvement with IPFire?
The graphical interface could be much better.
What is your primary use case for IPFire?
I use IPFire ( /products/ipfire-reviews ) to protect my home.
What advice do you have for others considering IPFire?
Sometimes configuring IPFire is challenging. Overall, I would rate this solution as eight out of ten.
What is a better choice, Azure Firewall or Palo Alto Networks NG Firewalls?
Azure Firewall Vs. Palo Alto Network NG Firewalls Both solutions provide stellar stability and security. Azure Firew...
Features comparison between Palo Alto and Fortinet firewalls
In the best tradition of these questions, Feature-wise both are quite similar, but each has things it's better at, it...
Which is better - Palo Alto Networks NG Firewalls or Sophos XG?
Palo Alto Networks NG Firewalls have both great features and performance. I like that Palo Alto has regular threat si...
 

Also Known As

Fortinet FortiGate Next-Generation Firewall
No data available
Palo Alto NGFW, Palo Alto Networks Next-Generation Firewall
 

Overview

 

Sample Customers

Amazon Web Services, Microsoft, IBM, Cisco, Dell, HP, Oracle, Verizon, AT&T, T-Mobile, Sprint, Vodafone, Orange, BT Group, Telstra, Deutsche Telekom, Comcast, Time Warner Cable, CenturyLink, NTT Communications, Tata Communications, SoftBank, China Mobile, Singtel, Telus, Rogers Communications, Bell Canada, Telkom Indonesia, Telkom South Africa, Telmex, Telia Company, Telkom Kenya
1. Siemens 2. IBM 3. Cisco 4. Dell 5. HP 6. Intel 7. Oracle 8. Google 9. Microsoft 10. Amazon 11. Apple 12. Facebook 13. Twitter 14. Netflix 15. Adobe 16. SAP 17. VMware 18. Juniper Networks 19. Ericsson 20. Nokia 21. AT&T 22. Verizon 23. T-Mobile 24. Vodafone 25. Orange 26. Deutsche Telekom 27. British Telecom 28. Comcast 29. Time Warner 30. Sony 31. Samsung 32. LG
SkiStar AB, Ada County, Global IT Services PSF, Southern Cross Hospitals, Verge Health, University of Portsmouth, Austrian Airlines, The Heinz Endowments
Find out what your peers are saying about IPFire vs. Palo Alto Networks NG Firewalls and other solutions. Updated: April 2026.
893,915 professionals have used our research since 2012.