No more typing reviews! Try our Samantha, our new voice AI agent.

IPFire vs Palo Alto Networks NG Firewalls comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Jan 25, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Fortinet FortiGate
Sponsored
Ranking in Firewalls
1st
Average Rating
8.4
Reviews Sentiment
6.9
Number of Reviews
592
Ranking in other categories
Secure Web Gateways (SWG) (2nd), Intrusion Detection and Prevention Software (IDPS) (1st), Software Defined WAN (SD-WAN) Solutions (1st), WAN Edge (1st), ZTNA (1st), Unified Threat Management (UTM) (1st)
IPFire
Ranking in Firewalls
35th
Average Rating
8.0
Reviews Sentiment
8.3
Number of Reviews
3
Ranking in other categories
No ranking in other categories
Palo Alto Networks NG Firew...
Ranking in Firewalls
6th
Average Rating
8.6
Reviews Sentiment
7.1
Number of Reviews
199
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of June 2026, in the Firewalls category, the mindshare of Fortinet FortiGate is 15.1%, down from 21.7% compared to the previous year. The mindshare of IPFire is 1.1%, down from 1.8% compared to the previous year. The mindshare of Palo Alto Networks NG Firewalls is 5.1%, up from 3.7% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Firewalls Mindshare Distribution
ProductMindshare (%)
Fortinet FortiGate15.1%
Palo Alto Networks NG Firewalls5.1%
IPFire1.1%
Other78.7%
Firewalls
 

Featured Reviews

JK
IP Network Security Specialist at MTN Ghana
Process-Level CPU Visibility: Introduce detailed CPU-usage metrics per subsystem (e.g., IPS engine, logging) so administrators can quickly identify and address performance spikes.
Analytics with FortiAnalyzer. Being able to pull in logs not just from our FortiGates but from all our other firewalls and then get them in one view has been a game changer. Whether I’m building an executive dashboard or doing a deep dive forensics session, I get everything I need without navigating consoles.Straightforward Application Control. FortiGate spots and blocks unwanted apps (eq. like BitTorrent or streaming services) with accuracy. Segmentation with VDOMs. We’ve carved our data center into four logical ‘mini-firewalls’ enterprise, core, billing, and WAF—all on one box. Each has its own rules and logs, and any traffic between them still gets inspected. It’s like having multiple appliances without the extra hardware. Always-Up-to-Date Threat Feeds. Daily signature updates and AI-driven threat sensing mean we’re blocking the latest vulnerabilities almost as soon as they’re announced.
AE
Chief Technology Officer at Agileware Limited
Firewall deployment has secured mission-critical public apps and simplifies Linux-based management
The best features IPFire offers include its very intuitive nature because, even though it has a Linux back-end, in terms of configuration, it has a very rich GUI interface. The GUI and configuration features of IPFire have made my work easier and more efficient because their positioning and the sequence with which I follow is easy. In terms of all the processes, what you need to do at first and the next thing that you need to do is clear. The GUI is well arranged in sequential order, so you can follow that from whatever you want to do until you get the target objective. IPFire includes features with a very robust and rich community that is very much valid in terms of content. IPFire has positively impacted my organization by giving us some mileage. At least, a lot of organizations now know that we have a solution that can deliver the same value.
Nitin Yadav - PeerSpot reviewer
Network & Security Engineer at Arrow PC Network Pvt.Ltd.
Strong threat prevention has reduced phishing and malware while I monitor traffic in depth
Palo Alto Networks NG Firewalls offers application and user awareness, which allow me to control traffic based on threats. The product includes threat prevention, advanced threat prevention, and deep packet inspection that really helps prevent issues in our network. Deep packet inspection inspects full traffic content, even inside applications and encrypted sessions. Deep packet inspection makes a very practical difference day to day because it lets me see and control what is actually inside the traffic, not just the open port or IP. I have real visibility of which application is running instead of just seeing HTTPS. Palo Alto Networks NG Firewalls WildFire sandboxing is really good at detecting and blocking zero-day malware automatically, along with its GlobalProtect and DNS security features. Using Palo Alto Networks NG Firewalls positively impacts my organization by providing strong security, better visibility, faster response, and simplified operations. After deploying Palo Alto Networks NG Firewalls in our network, it blocks malicious traffic and prevents compromises that occurred before Palo Alto Networks NG Firewalls. I can now block outside IPs to prevent issues. After Palo Alto Networks NG Firewalls installation, I reduced 60 to 70 percent of malware and phishing attacks. Its threat prevention and DNS security features detect these attacks, block malicious domains, and reduce manual efforts for the security team.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The solution is used in my company since its management is very comfortable"
"The most valuable features of the FortiGate firewall include SSL inspection, VPN functionality, and threat intelligence features for preventing threats."
"Application control and the web filter are the best features of Fortinet FortiGate."
"One good thing about FortiGate is that you have got free training."
"Fortinet FortiGate provides combined features that other firewalls do not offer, offering a full package cost-effective manager with all integration supported."
"Fortinet scores very high against security threats when you compare it with Check Point and Palo Alto."
"I appreciate the ease of use, ease of setup, and the different abilities it has; I have been very pleased with it over SonicWall, the interface of Fortinet FortiGate is a lot easier to use and more robust, plus their VPN option is much better."
"FortiGate is very good if you're thinking of expanding where you have remote offices, then it's a good solution."
"I would rate the stability as ten out of ten for IPFire."
"IPFire has prevented any kind of hacking and enables us to comply with customer requirements."
"Regarding IPFire's AI capabilities, I think they are quite focused; in all the deployments I have done, I have not had any incidents or breaches."
"The NG Firewall has many functions like user control, access control for servers, natural controls based on applications, schedules, ports, RTs, and IPS functionality with antivirus or security functionality."
"It's very important that Palo Alto NG Firewalls embed machine learning into the core of the firewall to provide inline, real-time attack prevention. That increases our security posture... The firewall is able to capture it and flag it and it is easy to mitigate as soon as we see something like that happening, to secure the environment more, in real time."
"Palo Alto Networks NG Firewalls have a Single Pass Parallel Processing (SP3) Architecture, which has a different kind of code doing the work. It increases the packet processing rate. Whereas, without the SP3 Architecture, you are waiting for each job to complete, even if you have 100 jobs assigned."
"With its single pane of glass, it makes monitoring and troubleshooting a bit more homogeneous. We are not looking at multiple platforms and monitoring management tools. It is more efficient from that perspective. It is more of a common monitoring and control system for multiple aspects of what used to be different systems. It provides efficiency and time savings."
"The App-ID feature is the coolest feature because you don't need to open a new port. Apps are directly linked to the port. It provides one of the best ways to lock down the additional port switch."
"The best feature is the packet inspection; compared to solutions like Cisco and FortiGate, Palo Alto's packet inspection is much less CPU intensive, allowing it to detect threats embedded within packages more quickly and efficiently."
"Palo Alto is more expensive in comparison to Fortinet and other firewalls, but it's okay because they do provide quality."
"We previously had Check Point and eventually compared it with the Palo Alto screening, which proved that Palo Alto was the best."
 

Cons

"It should be more stable."
"They need faster serviceability and more security features."
"Technical support is good but the response time could be faster."
"Fortinet FortiGate can improve performance. There was a huge challenge in terms of CPU and memory where the IPS engine would keep triggering. There were random spikes of overutilization in the CPU and memory resources. They have to work on CPU and memory stability considering these IPS engines. A few versions were very unstable."
"It would be a benefit if Fortinet would release a one-stop solution that is better integrated with other products and has an automated emergency response system."
"The support package being an additional extra, even with an enterprise package purchase, is pathetic. Though I haven't had direct experience with support, the fact that it doesn't come by default, which is very misleading compared to other brands, warrants a rating of two out of ten."
"There are a lot of bugs I have found in the solution and it is difficult to upgrade. These areas need improvement."
"FortiGate is really good. We have been using it for quite some time. Initially, when we started off, we had around 70 plus devices of FortiGate, but then Check Point and Palo Alto took over the place. From the product perspective, there are no issues, but from the account perspective, we have had issues. Fortinet's presence in our company is very less. I don't see any Fortinet account managers talking to us, and that presence has diluted in the last two and a half or three years. We have close to 1,500 firewalls. Out of these, 60% of firewalls are from Palo Alto, and a few firewalls are from Check Point. FortiGate firewalls are very less now. It is not because of the product; it is because of the relationship. I don't think they had a good relationship with us, and there was some kind of disconnect for a very long time. The relationship between their accounts team and my leadership team seems to be the reason for phasing out FortiGate."
"I would rate IPFire 8 out of 10 because I do not think there is any solution anywhere in the world that is 100 percent efficient."
"Accessing the internet was a bit complicated."
"The graphical interface could be much better."
"The price is high and has room for improvement."
"In the cloud, the HA could be a lot better. Its price could also be better. It is very expensive."
"Lacks mobility between on-prem and cloud based."
"It is probably as good as it can be in terms of being highly sophisticated but having a very small leap to learn the platform and deploy it. I do not have many complaints about the platform."
"From a normal IPS after attack, routine attack and threat detection attack, in other words, the standard IPS detection attack, I don't see Palo Alto as very good compared to others."
"Scalability is the main disadvantage of Palo Alto. They call themselves a firewall with router capabilities but it's not a router and it requires a good bandwidth in VPN which could become a problem because you have to scale to really big hardware."
"In some countries, the support flexibility is very good. For others, you have different strategies."
"Palo Alto's various products need better integration to ensure they work harmoniously."
 

Pricing and Cost Advice

"FortiGate SWG is reasonably priced."
"The pricing is flexible."
"It is quite affordable for our customers. There is a separate cost for IPS, antivirus, web filtering, and other features. They have a great choice of licenses. You can go for the license that you want, which is quite useful."
"I do not have first-hand experience with the rice of Fortinet FortiGate, but I have heard the price was reasonable."
"It is affordable. Palo Alto is much more expensive than Fortinet."
"It is not expensive as compared to Cisco."
"The solution requires a license annually, it is not a user license, you can have as many users as your want. I must renew the license regularly per device."
"There is a license required to use Fortinet FortiGate with all the features. It has to be updated with the threats on an ongoing basis for the signatures to prevent threats and a license is needed to receive those security updates."
Information not available
"Compared to other firewall solutions, this is an expensive solution."
"Palo Alto Networks NG Firewalls are expensive compared to other firewalls such as FortiGate Next Generation Firewall."
"Annually, the licensing costs are too much."
"Reducing costs is important, especially since Prisma can be expensive. It would be great if it were more affordable."
"Cost-wise, I don't see much difference in network-related costs, but this is a premium-grade firewall. There is a cost involved, and you must pay for that to get the most out of it. Its licensing costs are straightforward. There aren't any hidden costs."
"We pay for the licensing annually and the price could be cheaper."
"Palo Alto Networks NG Firewalls are expensive compared to other solutions."
"If someone doesn't have a security platform in their network, then the following licenses will be required: antivirus, anti-spyware, vulnerability, and Wildfire analysis. There are also licenses for GlobalProtect and support."
report
Use our free recommendation engine to learn which Firewalls solutions are best for your needs.
902,417 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Comms Service Provider
10%
Computer Software Company
9%
Manufacturing Company
9%
Financial Services Firm
7%
Comms Service Provider
21%
Computer Software Company
10%
University
8%
Government
7%
Manufacturing Company
10%
Computer Software Company
9%
Financial Services Firm
9%
Comms Service Provider
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business369
Midsize Enterprise139
Large Enterprise195
No data available
By reviewers
Company SizeCount
Small Business77
Midsize Enterprise57
Large Enterprise87
 

Questions from the Community

Which is the better NGFW: Fortinet Fortigate or Cisco Firepower?
When you compare these firewalls you can identify them with different features, advantages, practices and usage a...
What is the biggest difference between Sophos XG and FortiGate?
From my experience regarding both the Sophos and FortiGate firewalls, I personally would rather use FortiGate. I know...
What are the biggest technical differences between Sophos UTM and Fortinet FortiGate?
As a solution, Sophos UTM offers a lot of functionality, it scales well, and the stability and performance are quite ...
What needs improvement with IPFire?
The graphical interface could be much better.
What is your primary use case for IPFire?
I use IPFire ( /products/ipfire-reviews ) to protect my home.
What advice do you have for others considering IPFire?
Sometimes configuring IPFire is challenging. Overall, I would rate this solution as eight out of ten.
What is a better choice, Azure Firewall or Palo Alto Networks NG Firewalls?
Azure Firewall Vs. Palo Alto Network NG Firewalls Both solutions provide stellar stability and security. Azure Firew...
Features comparison between Palo Alto and Fortinet firewalls
In the best tradition of these questions, Feature-wise both are quite similar, but each has things it's better at, it...
Which is better - Palo Alto Networks NG Firewalls or Sophos XG?
Palo Alto Networks NG Firewalls have both great features and performance. I like that Palo Alto has regular threat si...
 

Also Known As

Fortinet FortiGate Next-Generation Firewall
No data available
Palo Alto NGFW, Palo Alto Networks Next-Generation Firewall
 

Overview

 

Sample Customers

Amazon Web Services, Microsoft, IBM, Cisco, Dell, HP, Oracle, Verizon, AT&T, T-Mobile, Sprint, Vodafone, Orange, BT Group, Telstra, Deutsche Telekom, Comcast, Time Warner Cable, CenturyLink, NTT Communications, Tata Communications, SoftBank, China Mobile, Singtel, Telus, Rogers Communications, Bell Canada, Telkom Indonesia, Telkom South Africa, Telmex, Telia Company, Telkom Kenya
1. Siemens 2. IBM 3. Cisco 4. Dell 5. HP 6. Intel 7. Oracle 8. Google 9. Microsoft 10. Amazon 11. Apple 12. Facebook 13. Twitter 14. Netflix 15. Adobe 16. SAP 17. VMware 18. Juniper Networks 19. Ericsson 20. Nokia 21. AT&T 22. Verizon 23. T-Mobile 24. Vodafone 25. Orange 26. Deutsche Telekom 27. British Telecom 28. Comcast 29. Time Warner 30. Sony 31. Samsung 32. LG
SkiStar AB, Ada County, Global IT Services PSF, Southern Cross Hospitals, Verge Health, University of Portsmouth, Austrian Airlines, The Heinz Endowments
Find out what your peers are saying about IPFire vs. Palo Alto Networks NG Firewalls and other solutions. Updated: June 2026.
902,417 professionals have used our research since 2012.