Juniper SRX Series Firewall vs Palo Alto Networks WildFire comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Jan 4, 2023
 

Categories and Ranking

Fortinet FortiGate
Sponsored
Average Rating
8.4
Number of Reviews
314
Ranking in other categories
Firewalls (2nd), Software Defined WAN (SD-WAN) Solutions (2nd), WAN Edge (1st)
Juniper SRX Series Firewall
Average Rating
7.8
Number of Reviews
88
Ranking in other categories
Firewalls (18th), Unified Threat Management (UTM) (5th)
Palo Alto Networks WildFire
Average Rating
8.4
Number of Reviews
63
Ranking in other categories
Advanced Threat Protection (ATP) (3rd)
 

Mindshare comparison

As of July 2024, in the Firewalls category, the mindshare of Fortinet FortiGate is 22.6%, up from 18.8% compared to the previous year. The mindshare of Juniper SRX Series Firewall is 1.4%, down from 1.7% compared to the previous year. The mindshare of Palo Alto Networks WildFire is 1.7%, up from 1.3% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Firewalls
Unique Categories:
Software Defined WAN (SD-WAN) Solutions
19.7%
WAN Edge
21.4%
Unified Threat Management (UTM)
12.0%
Advanced Threat Protection (ATP)
13.5%
 

Featured Reviews

Javed Hashmi - PeerSpot reviewer
May 24, 2023
Easy to configure, has a robust OS, and offers a lot of features at a very good price
Fortinet has a very strong OS. They have a single OS through which they integrate all the networks and security operations. Our experience has been very good. Fortinet gives us a single fabric for the security and network teams. This unification has helped us a lot in providing Secure SD-WAN and other solutions, such as network switches, wireless controllers, FortiNAC, FortiAuthenticator, etc. They have a single pane of glass for all these from the monitoring and visibility aspect. The integrated application protection provided by Secure SD-WAN is very good. Fortinet is a security-focused company. The features related to application recognition and how to enhance the performance and security of applications are pretty good. The customers for whom we deployed FortiGate have become long-term customers of Fortinet. Even when they compare the solution with some of the other vendors, they're more comfortable with going with Fortinet and upgrading and refreshing the hardware and the software. It's a very good product, and the customer satisfaction is pretty good. It impacts operational efficiency because we can quickly make the changes. For example, Cisco has some limitations in terms of the time it takes for any change to take effect, which impacts the operational efficiency, whereas in the case of Fortinet, they've got a very quick way of doing the changes and reverting them, which eliminates any downtimes because of the configurations. Their method for configuring and applying policies is very simple and easy. Because of that, it's very easy to do complex changes, and in the case of misconfiguration, revert those changes without much of an impact. Overall, Fortinet FortiGate brings a lot of operational improvements because of the strength of FortiOS. Secure SD-WAN has helped us remediate threats more quickly. Normally, with the WAN solutions or the simple SD-WAN solutions, security is done on the hub side. With the Secure SD-WAN solution, we can apply security at the branch level, so unnecessary or malicious traffic doesn't reach the data centers or the hub site, which helps in improving the overall security posture. Also, we can tighten and apply a single security policy across all the branches or different segments of the WAN, which improves overall security. Fortinet offers different security measures for blocking malicious traffic and having a uniform policy across the entire organization. Secure SD-WAN has helped reduce our mean time to detect (MTTD) and mean time to resolve (MTTR). Applying a central security policy at the branch level immediately helps us to detect any malicious traffic and block it there, so the chances of anything reaching the hub or the data center side are less. It improves MTTD and MTTR because it has a very good interface where we can easily respond to all the attacks and manipulate things. Applying security with the help of Secure SD-WAN helps to mitigate attacks from where they are originating, which improves MTTD and MTTR. Secure SD-WAN has helped reduce help desk tickets. Because of the operational efficiency and security, there are not many issues that impact the number of tickets. With the help of Secure SD-WAN, we can provide operational efficiency because we can apply policies on an application-level basis. With Secure SD-WAN, we can apply a security policy per application. The central security application structure helps to apply all the measures from one central place and from the cloud. Because it's connected to many intelligence centers, it future-proofs a business and improves it overall.
SM
Oct 25, 2021
Easy to maintain, easy to extract the logs, and very stable
It is scalable. We haven't used the scalability up till now, but we know that we can extend it. We have 150 users here, and then we have around 30 to 40 users in different countries such as Singapore, Hong Kong, and Norway. They're using some parts of it. They are using some smaller units to connect to the main office. We don't have any plans to increase its usage as of now. Any expansion would be in terms of getting new offices around the world. We may install more of those smaller ones, but for the time being, as far as I know, we will not expand it in the office because it is already performing as it should. It actually did a very good job when we were working remotely because it allows us to connect to the office very easily and work remotely.
Mohamed Nabil Mohamed - PeerSpot reviewer
Jul 8, 2024
Respond to any attack effectively, latest framework and filter any attacks with a predefined signature in its database
There are multiple features like management, intrusion prevention (IPS), URL filtering, anti-spam, and antivirus. If it is between one vendor and another vendor. I've also had to use threat prevention, but just to have an IP access list and intrusion prevention. It depends on the decision of the firewall itself. Because when we're talking about the edge firewall, we are talking about web traffic. So you are filtering based on encryption, IP addresses, threat prevention, spam, ransomware, and so on. And in that center firewall, we need intelligence as a core function. So we don't need any more URL filtering licenses in the center because the customer or users don't usually access the Internet. So the center is used to defend against internal attacks or any DoS/DDoS attacks, not for filtering any websites. I see that the latest release of Palo Alto enabled our features to develop and make it easy to configure over all features in the firewall based on the AI engine. So I did AI Firewall with AI 3.0.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The most valuable feature of Fortinet FortiGate is URL filtering."
"The most valuable feature of this solution is Quota."
"The solution is stable."
"I like how we can achieve total integration."
"We purchased Fortinet because of the pricing, its functionality, because it met our requirements, and the total cost of ownership over five years was quite reasonable. In the market, Fortinet is rated quite well."
"We were looking for the VPN feature and controlling the inflow and outflow of all the traffic within the site and across the sites. We are also using it for the VPN and VLANs."
"Provides good firewall security and has great VPN features."
"The response is very quick and they can visually resolve our problems in a short period."
"The solution has been good for fulfilling our basic needs."
"Juniper has the "recovery safety feature", so if you perform a "commit confirmed" and the new configuration disconnects you. then there is no "confirmed" command with X mins (default = 10 mins). It automatically reverts (recovers) to the previous configuration. This is handy for when you do not want to make that trip down range just to reboot a router."
"Technical support is good. They quickly respond, and they even have local help here. They can actually give you an answer very quickly."
"Using a Juniper CLI, you configure a "candidate configuration", then "commit" it to bring it live. If you do not like it or messed up something, you just "rollback" to the previous configuration. It can all be done in a matter of minutes. This is super handy once you get use to it."
"The command line in Juniper SRX is extremely powerful, in my opinion. It's one of the best command lines I've used in networking products."
"We think they have a good interface, the operating system is good, it's robust. It has plenty of great features, and the relation between the cost and benefits works for our business."
"User-friendly solution with security bundle and USB blocking features"
"The technical support is quite good."
"The technical support is good."
"My primary use case for this solution is for a secure gateway."
"The solution has plenty of features."
"The most valuable features of this solution are sandbox capabilities."
"We get support in the free version."
"The way that the solution quickly updates to adjust to threats is the solution's most valuable aspect. When there's a security attack, within five minutes, all Wildfire subscribers have access to updates so that all systems will be safe. Its threat prevention is way better than other vendor products."
"I give the initial setup an eight out of ten."
"You have better control because you define apps. You just don't define ports. You define apps, and the apps are monitored in the traffic. It is more specific than the Cisco firewall when it comes to our needs."
 

Cons

"The web-cache feature which was previously on the FortiGate device, but was deleted with the recent upgrade should be returned. It was a very valuable feature for us."
"The reports are very basic."
"A couple of things I've seen that need improvement, especially in terms of a hard coding. The driver-level active moment really is out-of-the-box and we have to have contact the customer support and sometimes it is difficult to resolve."
"The platform's interface could improve."
"There are just some services that aren't available. For example, the Ethernet or point-to-point protocols. They could add these services to their product offering - especially services for ISPs."
"The reporting in Fortinet FortiGate could improve. Customers are having to purchase additional reporting components. When I have used the Sophos solution it is a complete solution, in Fortinet FortiGate you have to use additional tools to have the features needed."
"Fortinet FortiGate can improve the integration with Active Directory. Additionally, I would like to have a Cloud Controller, such as they do in the Cisco Meraki solution."
"The platform's compatibility with Wi-Fi equipment needs improvement."
"In comparison to other enterprise-level firewalls, such as Cisco FTD, Cisco has improved significantly. In the past, I believed that Juniper SRX was superior, but after seeing the advancements in the FTD platform, Cisco has better functionality. I have not recently explored Juniper SRX's next-generation firewall capabilities as we only use basic firewall filtering in our enterprise network."
"I would like them to add a dashboard because it's difficult to operate."
"I think Juniper SRX should have a GUI. Some of the competitors are already implementing GUI for the firewall."
"It must be 5G ready. The 5G network is rolling out soon in India, and Juniper must upgrade their firewall slot to the 5G network, or they must manufacture a 5G dongle card for the Juniper firewall. I want Juniper to upgrade their dongle from 4G to 5G. Presently, they have an expansion slot in the SRX 322 series and higher firewalls. In that expansion slot, they can put a 4G mobility SIM card so that whenever our primary link is down, it will automatically connect through this GSM network and form a tunnel."
"We tried configuring the IDS for more than four months, but it did not work properly."
"The GUI needs to be easier to handle."
"J-Web, Juniper Web, is sometimes not working great when users are increasing their internet use. Additionally, they need to improve the GUI, graphical user interface, and the firewall management needs to improve. Their CLI is good, but sometimes the GUI is very slow."
"The user interface is something that Juniper needs to improve."
"​The VPN and decryption need improvement."
"The technical support response needs improvement."
"The configuration should be made a little bit easier. I understand why it is as it is, but there should be a way to make it easier from the user side."
"The size of Palo Alto's cloud is big but it could be easier to use from a product management perspective."
"The only complaint that we receive from our customers is in regards to the price."
"The system uptime data is unavailable"
"The cost of this solution could still be improved, in particular, giving product discounts for charitable causes."
"In the future, I would like to see more automation in the reporting."
 

Pricing and Cost Advice

"Its pricing is good. It's average or normal as compared to Palo Alto and Check Point firewalls."
"Pricing for this product is comparatively lower than other products. It's an affordable solution, but when expanding the number of users, they'll ask you to replace the model, so that's an added cost."
"The price is fair compared to the other competitors."
"The initial setup is super straight forward and as far as the licensing goes for the small product that we have, the pricing was pretty competitive. It wasn't as simple and as cheap as a SonicWall but for the service we would get it was a good price."
"Fortinet bundles FortiGate with other products and because of this, the price is a little expensive to some SMB enterprises."
"The pricing is fair."
"Licensing for Fortinet FortiGate is on a yearly basis. Pricing for it is a bit high. It could be cheaper."
"The price is fair for what we get with FortiGate."
"It has a low price."
"The prices are very good as compared to other vendors."
"The price is reasonable"
"Pricing is good. Most of the costs are in the UTM (IDS/IPS, virus scanning, etc) subscription."
"When you consider performance, price, and features, maybe Juniper is not so cost-effective compared to other solutions like MikroTik."
"Palo Alto was nice, but much more expensive."
"It is best suited to an enterprise-level, as the mid-range companies may find that the cost is not affordable."
"Juniper SRX is reasonably priced."
"Palo Alto Networks WildFire is quite expensive, and this is what puts people off."
"Palo Alto Networks WildFire is an expensive product."
"The price of Palo Alto Networks WildFire could improve. It is expensive. There is an annual subscription to use the solution."
"We are on an annual subscription. When we purchased the firewall, we had activated this solutions license for a minimum of one year. The price of the solution is fair."
"The price is fair and comparable to other solutions."
"The price is a bit higher than the other products such as TrendMicro, or FireEye."
"WildFire is a little bit pricey. Sometimes it's difficult to sell it to customers at the current price."
"The solution is overpriced."
report
Use our free recommendation engine to learn which Firewalls solutions are best for your needs.
793,295 professionals have used our research since 2012.
 

Comparison Review

it_user206346 - PeerSpot reviewer
Mar 11, 2015
Cisco ASA vs. Palo Alto Networks
Cisco ASA vs. Palo Alto: Management Goodies You often have comparisons of both firewalls concerning security components. Of course, a firewall must block attacks, scan for viruses, build VPNs, etc. However, in this post I am discussing the advantages and disadvantages from both vendors concerning…
 

Top Industries

By visitors reading reviews
Educational Organization
21%
Computer Software Company
15%
Manufacturing Company
6%
Comms Service Provider
6%
Educational Organization
46%
Computer Software Company
10%
Government
5%
Financial Services Firm
4%
Computer Software Company
16%
Financial Services Firm
10%
Government
9%
Manufacturing Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

Which is the better NGFW: Fortinet Fortigate or Cisco Firepower?
When you compare these firewalls you can identify them with different features, advantages, practices and usage a...
What is the biggest difference between Sophos XG and FortiGate?
From my experience regarding both the Sophos and FortiGate firewalls, I personally would rather use FortiGate. I know...
What are the biggest technical differences between Sophos UTM and Fortinet FortiGate?
As a solution, Sophos UTM offers a lot of functionality, it scales well, and the stability and performance are quite ...
What do you like most about Juniper SRX?
Juniper SRX Series Firewall is a stable solution.
What is your experience regarding pricing and costs for Juniper SRX?
I would rate the pricing an eight out of ten, with ten being very expensive. There is an opportunity to reduce the pr...
What advice do you have for others considering Juniper SRX?
It is more suitable for medium to enterprise businesses. Overall, I would rate it a ten out of ten.
How does Cisco Firepower NGFW Firewall compare with Palo Alto Networks Wildfire?
The Cisco Firepower NGFW Firewall is a very powerful and very complex piece of anti-viral software. When one conside...
Which is better - Wildfire or FortiGate?
FortiGate has a lot going for it and I consider it to be the best, most user-friendly firewall out there. What I like...
How does Cisco ASA Firewall compare with Palo Alto's WildFire?
When looking to change our ASA Firewall, we looked into Palo Alto’s WildFire. It works especially in preventing advan...
 

Also Known As

FortiGate 60b, FortiGate 60c, FortiGate 80c, FortiGate 50b, FortiGate 200b, FortiGate 110c, FortiGate
Juniper SRX
No data available
 

Overview

 

Sample Customers

1. Amazon Web Services 2. Microsoft 3. IBM 4. Cisco 5. Dell 6. HP 7. Oracle 8. Verizon 9. AT&T 10. T-Mobile 11. Sprint 12. Vodafone 13. Orange 14. BT Group 15. Telstra 16. Deutsche Telekom 17. Comcast 18. Time Warner Cable 19. CenturyLink 20. NTT Communications 21. Tata Communications 22. SoftBank 23. China Mobile 24. Singtel 25. Telus 26. Rogers Communications 27. Bell Canada 28. Telkom Indonesia 29. Telkom South Africa 30. Telmex 31. Telia Company 32. Telkom Kenya
7-Eleven, AARNet Pty Ltd, Allegro Networks, alltours GmbH, Apollo Hotel Papendrecht, Armstrong Atlantic State University, Atlantech Online, Availity, Bajaj Capital, Baloise Insurance, BancABC, BAS Group, Black Lotus, Blue Box, Borealis, Carilion Clinic, Catholic Health System, CATV, Champlain College, Chinas Ministry of Railways, China University of Mining and Technology (CUMT), Cloud Dynamics, CloudSeeds, Cloudwatt, CODONiS, Colt Technology Services, Cork Internet Exchange, CSS Versicherung AG, CyrusOne, Danish Crown, Deloitte Belgium, Department of Energy, Divona Telecom, DQE Communications, DreamHost, European Government Agency, Expedient, Financial Market Information Services Provider, Fluidata, Fonality, Fox Sports, Global Financial Institution, Global Investment Bank, Global Investment Company, Energy Sciences Network (ESnet), Goethe University, HEAnet, High Performance Networks Inc., Hillenbrand
Novamedia, Nexon Asia Pacific, Lenovo, Samsonite, IOOF, Sinogrid, SanDisk Corporation
Find out what your peers are saying about Netgate, Fortinet, OPNsense and others in Firewalls. Updated: July 2024.
793,295 professionals have used our research since 2012.