Try our new research platform with insights from 80,000+ expert users

Netgate pfSense Plus Firewall/VPN/Router vs Palo Alto Networks NG Firewalls comparison

Sponsored
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Fortinet FortiGate
Sponsored
Ranking in Firewalls
1st
Average Rating
8.4
Reviews Sentiment
6.9
Number of Reviews
580
Ranking in other categories
Secure Web Gateways (SWG) (2nd), Intrusion Detection and Prevention Software (IDPS) (1st), Software Defined WAN (SD-WAN) Solutions (1st), WAN Edge (1st), ZTNA (1st), Unified Threat Management (UTM) (1st)
Netgate pfSense Plus Firewa...
Ranking in Firewalls
27th
Average Rating
9.4
Reviews Sentiment
4.3
Number of Reviews
3
Ranking in other categories
No ranking in other categories
Palo Alto Networks NG Firew...
Ranking in Firewalls
6th
Average Rating
8.6
Reviews Sentiment
7.2
Number of Reviews
197
Ranking in other categories
No ranking in other categories
 

Featured Reviews

Vasu Gala - PeerSpot reviewer
Manager, Information Technology Operation/Presales at TechMonarch
A stable solution with an intuitive interface and quick customer service
I have been working with Fortinet FortiGate, WatchGuard, Sophos, and SonicWall. I'm not as comfortable with SonicWall because of their UI and limitations. I prefer Fortinet above all other options. When it comes to configuration, I am confident in my ability to handle various tasks, including creating policies such as firewall rules, web policies, and application policies. Additionally, I can configure VPNs and implement load balancing, among other tasks. Overall, I feel much more comfortable working with Fortinet. Fortinet has made significant improvements by integrating AI with firewalls for threat analysis and prevention. In the past 2-3 years, they have launched FortiSASE and SIEM, and they also provide SOC services. Both Palo Alto and Fortinet FortiGate are excellent. While Fortinet FortiGate comes at higher prices, the functionality and support justify the cost. They promptly resolve firmware issues and inform all support providers about configuration changes.
Jim Voige - PeerSpot reviewer
Site Manager at a consultancy with 11-50 employees
High availability routing has secured our network and delivers reliable support every day
One downside of Netgate pfSense Plus Firewall_VPN_Router is the need for a better understanding of what hardware it would run on. Right now, we're using Netgate's hardware, but I'm interested in knowing if there are other hardware options available, particularly heavier duty hardware, because the Supermicro 1537 version we have only has a single power supply, which is a shortcoming in an IT environment where dual power supplies are ideal. The pricing for the hardware of Netgate pfSense Plus Firewall_VPN_Router is steep, which is one reason I'd explore other options. I'm familiar with the costs of Supermicro servers, and I believe Netgate charges a premium for their server hardware without enough upside to justify it. The pricing is not justified.
SV
Solution Architect // Network Consultant at Group S
Network security has improved and allows detailed user-based control over encrypted traffic
Bandwidth usage is not something we use much, but it depends on the SD-WAN plugin because the application load balancing is based on the SD-WAN product. That functionality does not work as it should, although the App-ID is working very well. SD-WAN functionality is working, but when you compare it with other products on the market, it is very limited. Palo Alto also has ION devices, and ION devices together with Prisma Access or Strata Cloud Manager now are more the way to go than using Palo Alto Networks NG Firewalls on-premises. At the moment I have some issues, but the issues are more related to the general way of working of many vendors. They implement new things very fast and it is not always bug-free. With new releases, sometimes you still have some issues. This is the main concern. If you look back five or maybe ten years ago, the products were more stable and you had more decent releases, but that is something in general for many vendors. Palo Alto is also a factor with that. They want to bring new features to the market too fast. Features are a concern because all vendors try to compete against each other. If one vendor comes out with a new feature, then other vendors do the same. Sometimes they want to be the first on the market with it, and that sometimes introduces bugs or issues with the product.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The most valuable features of Fortinet FortiGate are its SD-WAN capabilities, such as dynamic routing, and other features, including security options such as antivirus, IPS, and IDS—all integrated into one device."
"Initial setup is easy to configure."
"The solution is stable."
"Fortinet FortiGate provides combined features that other firewalls do not offer, offering a full package cost-effective manager with all integration supported."
"The product is easy to install since we only need to follow the user manual, documents, and articles provided by Fortinet to install the product."
"We can use our devices to check all of the perimeters. It secures email websites."
"The most important features with FortiGate are the web filter and application controls. We can control our internet usage and use the web filter for application purposes."
"It is a scalable solution."
"I do not have complaints about Netgate pfSense Plus Firewall_VPN_Router with Firewall, VPN, and Router; it is really comfortable for use, and it does a pretty good job."
"Overall, the entire Netgate pfSense Plus Firewall_VPN_Router product has been reliable, though some of their smaller gear aimed at remote offices hasn't been cost-effective."
"It's very simple to use, efficient, up to date, and the hardware is very available; it's very safe."
"The solution is user-friendly. It's secure and easy to understand your network visibility, control the network, and prevent attacks."
"The basic configuration will only take 15 minutes to set up"
"The WildFire reporting and Cortex XDR platform have huge infrastructures in the cloud that secures the network against threats. So, we have the potential on the system, specifically for users, where we take care of this since the user is the most dangerous. We get reports back from WildFire on a minute-by-minute basis, rather than a daily or weekly update like I used to with different AV vendors. These features can detect viruses and malware more quickly, which is super important."
"The centralization capability is the most valuable feature of this solution as it enables us to monitor our systems efficiently."
"Palo Alto Networks NG Firewalls are the best in the field in terms of usability and coverage."
"It is very scalable."
"I can enable the features I want and configure the policies based on the user and not all users and network traffic, making firewall management much easier."
"Palo Alto offers better Layer 7 protection than competing solutions by Cisco and Fortinet. I also like the VPN client more. The interface is simple, so administrators can deploy and configure it much faster than other firewalls"
 

Cons

"Maybe they can offer a smaller scope for a cheaper price for smaller organizations."
"Fortinet FortiGate could improve the user interface. There should be more functionality and options through the GUI."
"I would like to see improvements in Fortinet FortiGate regarding the active-active scenario. The active-active scenario is supported but not recommended, whereas other vendors are implementing active-active without issues. Perhaps in the future, we could effectively use both firewalls to increase the throughput. If there are two boxes, they both should be able to work."
"One issue that I have had is that sometimes I need to monitor the traffic, so I need to filter it according to the user and which user is using it the most. I experience a bottleneck most of the time, particularly at the peak time when the number of contracts and users are at maximum."
"There is room for improvement related to the logging and reporting aspect."
"Though the tool's GUI is user-friendly, it can be considered as an area with certain shortcomings where improvements are required."
"FortiGate's reporting features could provide a better picture of what is happening in the box."
"The firmware needs improvement because there are bugs when a new release comes through. Sometimes, the configuration changes, and it's a bit harder to see where the fail is. The first time that you have the firmware, it tends to have some issues, and it's better to wait a bit to update the equipment."
"The effectiveness of Netgate pfSense Plus Firewall_VPN_Router traffic shaping is quite good, but I am not very satisfied with the interface for control."
"The pricing for the hardware of Netgate pfSense Plus Firewall_VPN_Router is steep, which is one reason I'd explore other options."
"Palo Alto Networks NG Firewalls do not provide a unified platform that natively integrates all security capabilities."
"The solution has normal authentication, but does not have two-factor or multi-factor authentication. There is room for development there."
"The solution needs some management tool enhancements. It could also use more reporting tools."
"The stability, scalability for enterprise-level organizations, and technical documentation have room for improvement."
"Palo Alto keeps coming out with antivirus and malware updates. When we have to integrate those updates we face some problems with the cloud platform, not the on-prem setup. The device works fine, but sometimes the sync doesn't happen on time."
"When the primary Palo Alto Networks firewall fails over to the secondary, it requires manual intervention to bounce the IPsec for it to work properly. Unlike BGP peering, which automatically changes from idle to established, this process needs automation. In Cisco, there is no need to bounce the IPsec traffic during failover, and I suggest automation for Palo Alto Networks in that process."
"From a documentation standpoint, there is room for improvement. Even Palo Alto says that their documentation is terrible."
"Palo Alto recently introduced a security analyzer in version ten, but this feature could be enhanced, and the URL filtering improved."
 

Pricing and Cost Advice

"It is very cost-effective. You get features similar to other firewalls, such as Palo Alto, but at a lower price."
"At the time we bought them, I was satisfied with their pricing; I don't know how the new pricing will be."
"It was pretty affordable. We did go a little bit above MSRP, but the service pack that was included was quite worth the additional costs. It is competitively priced compared to other major players in the market. It is significantly cheaper than Check Point, which is a primary competitor. Additionally, its pricing is comparable to that of Cisco's ASA and a few other vendors."
"Its price is affordable and lesser than Cisco. Cisco is expensive. In terms of licensing, there is only one issue. If a customer's license has expired a month ago and they do the renewal after one month, Fortinet renews the license from the start of the previous month. The activation of the product is done from the previous month, not from the date of renewal. The customers usually shout and complain that because they are paying today, the renewal should start from today. The support contract renewals or licensing should be renewed from the date of renewal, but Fortinet starts from the day it had expired. It is a loss for customers. They might have had some problems because of which they did not take the license one month before. Fortinet should work on this. Cisco doesn't do this. Cisco always starts from the day they apply for the license."
"Its price could be better."
"When you look at these end security systems and firewalls, these firewalls even five years ago were $50,000 or perhaps $25,000 to implement in some types of customer sites. Now we're talking about tools that are $1,000. In this case, it might have been $500 or something like that."
"It cost us around $73,000 for three years."
"The license of Fortinet FortiGate should be reduced."
Information not available
"It is not that expensive. I would rate it an eight out of ten in terms of pricing. Other than the licensing, there are no additional costs."
"It is very expensive. You pay for a year."
"Palo Alto Networks NG Firewalls' price is expensive."
"Palo Alto NGFW is relatively expensive compared to the competition."
"Palo Alto Networks NG Firewalls are overpriced."
"The licensing is annual, and there aren't any additional fees on top of that."
"It can be quite expensive, but there's a good incentive for the three-year contracts. The part that is especially confusing is for the virtual environment. The credits or the licensing system can be very confusing."
"Annually, the licensing costs are too much."
report
Use our free recommendation engine to learn which Firewalls solutions are best for your needs.
881,082 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
12%
Comms Service Provider
9%
Manufacturing Company
8%
Financial Services Firm
6%
No data available
Computer Software Company
10%
Financial Services Firm
9%
Manufacturing Company
8%
Educational Organization
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business357
Midsize Enterprise133
Large Enterprise188
No data available
By reviewers
Company SizeCount
Small Business74
Midsize Enterprise56
Large Enterprise85
 

Questions from the Community

Which is the better NGFW: Fortinet Fortigate or Cisco Firepower?
When you compare these firewalls you can identify them with different features, advantages, practices and usage a...
What is the biggest difference between Sophos XG and FortiGate?
From my experience regarding both the Sophos and FortiGate firewalls, I personally would rather use FortiGate. I know...
What are the biggest technical differences between Sophos UTM and Fortinet FortiGate?
As a solution, Sophos UTM offers a lot of functionality, it scales well, and the stability and performance are quite ...
What needs improvement with Netgate pfSense Plus Firewall/VPN/Router?
One downside of Netgate pfSense Plus Firewall_VPN_Router is the need for a better understanding of what hardware it w...
What is your primary use case for Netgate pfSense Plus Firewall/VPN/Router?
We use Netgate pfSense Plus Firewall_VPN_Router as a high availability BGP solution.
What advice do you have for others considering Netgate pfSense Plus Firewall/VPN/Router?
We use the Plus version of Netgate pfSense Plus Firewall_VPN_Router, which comes automatically with any Netgate hardw...
What is a better choice, Azure Firewall or Palo Alto Networks NG Firewalls?
Azure Firewall Vs. Palo Alto Network NG Firewalls Both solutions provide stellar stability and security. Azure Firew...
Features comparison between Palo Alto and Fortinet firewalls
In the best tradition of these questions, Feature-wise both are quite similar, but each has things it's better at, it...
Which is better - Palo Alto Networks NG Firewalls or Sophos XG?
Palo Alto Networks NG Firewalls have both great features and performance. I like that Palo Alto has regular threat si...
 

Also Known As

Fortinet FortiGate Next-Generation Firewall
No data available
Palo Alto NGFW, Palo Alto Networks Next-Generation Firewall
 

Overview

Information not available
 

Sample Customers

Amazon Web Services, Microsoft, IBM, Cisco, Dell, HP, Oracle, Verizon, AT&T, T-Mobile, Sprint, Vodafone, Orange, BT Group, Telstra, Deutsche Telekom, Comcast, Time Warner Cable, CenturyLink, NTT Communications, Tata Communications, SoftBank, China Mobile, Singtel, Telus, Rogers Communications, Bell Canada, Telkom Indonesia, Telkom South Africa, Telmex, Telia Company, Telkom Kenya
Information Not Available
SkiStar AB, Ada County, Global IT Services PSF, Southern Cross Hospitals, Verge Health, University of Portsmouth, Austrian Airlines, The Heinz Endowments
Find out what your peers are saying about Netgate pfSense Plus Firewall/VPN/Router vs. Palo Alto Networks NG Firewalls and other solutions. Updated: January 2026.
881,082 professionals have used our research since 2012.