No more typing reviews! Try our Samantha, our new voice AI agent.

Netgate pfSense Plus Firewall/VPN/Router vs Palo Alto Networks NG Firewalls comparison

Sponsored
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Fortinet FortiGate
Sponsored
Ranking in Firewalls
1st
Average Rating
8.4
Reviews Sentiment
6.8
Number of Reviews
591
Ranking in other categories
Secure Web Gateways (SWG) (2nd), Intrusion Detection and Prevention Software (IDPS) (1st), Software Defined WAN (SD-WAN) Solutions (1st), WAN Edge (1st), ZTNA (1st), Unified Threat Management (UTM) (1st)
Netgate pfSense Plus Firewa...
Ranking in Firewalls
24th
Average Rating
9.0
Reviews Sentiment
4.3
Number of Reviews
5
Ranking in other categories
No ranking in other categories
Palo Alto Networks NG Firew...
Ranking in Firewalls
6th
Average Rating
8.6
Reviews Sentiment
7.2
Number of Reviews
199
Ranking in other categories
No ranking in other categories
 

Featured Reviews

Abhinandan Yadav - PeerSpot reviewer
Network Security Engineer at Arrow PC Network Pvt Ltd
Unified security and sd-wan have improved uptime and cut wan costs for multi-site branches
Users report stability issues in certain versions, which requires regular updates. Real-world attacks have also highlighted the need for urgent patching of vulnerabilities.Fortinet FortiGate, while a powerful and feature-rich web firewall, could improve in areas like firmware stability, documentation, and ease of use. The learning curve can be steep for some users. For beginners, support quality can vary, and frequent updates with occasional vulnerabilities call for careful patch management. However, once Fortinet FortiGate is configured, it remains highly reliable and efficient. Customer support needs improvement, as I find it very slow, with reports from other users reflecting that customer support is inadequate.
Jim Voige - PeerSpot reviewer
Site Manager at a consultancy with 11-50 employees
High availability routing has secured our network and delivers reliable support every day
One downside of Netgate pfSense Plus Firewall_VPN_Router is the need for a better understanding of what hardware it would run on. Right now, we're using Netgate's hardware, but I'm interested in knowing if there are other hardware options available, particularly heavier duty hardware, because the Supermicro 1537 version we have only has a single power supply, which is a shortcoming in an IT environment where dual power supplies are ideal. The pricing for the hardware of Netgate pfSense Plus Firewall_VPN_Router is steep, which is one reason I'd explore other options. I'm familiar with the costs of Supermicro servers, and I believe Netgate charges a premium for their server hardware without enough upside to justify it. The pricing is not justified.
Abhinandan Yadav - PeerSpot reviewer
Network Security Engineer at Arrow PC Network Pvt Ltd
Advanced visibility has transformed security policies and provides proactive threat prevention
Palo Alto Networks NG Firewalls are powerful, but there are areas for improvement that could enhance their effectiveness, such as cost and licensing models. One of the main challenges we face is the high cost, especially for small to mid-sized businesses (SMBs), with licensing for features such as threat prevention, URL filtering, and WildFire being quite expensive. Additionally, centralized management with Panorama is a dependency for managing multiple firewalls, leading to added costs and complexity, and the built-in centralized management features could be made more user-friendly. Moreover, the learning curve associated with the initial setup and advanced configuration including NAT, decryption, and routing can be complex for new users, and enhancements in logging and reporting could also improve the user experience. There are a few more areas where improvements could streamline operations, such as optimizing commit times. Sometimes committing changes takes a noticeable amount of time, particularly for larger configurations, so a faster commit option would significantly help during urgent troubleshooting. Easier policy troubleshooting is necessary as well. Even though logs are detailed, finding the exact rule match and issue can still be time-consuming in complex environments, so having automated policy simulation and a recommendation tool would expedite troubleshooting. Additionally, better default templates and best practices for SMB data centers and branch offices would speed up deployment and reduce errors. Enhancing integration visibility through a unified dashboard would simplify monitoring, and improving the firmware upgrade process to allow for a more seamless zero downtime upgrade would also enhance operations, as upgrades are stable but typically require careful planning and downtime.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"I'm pretty happy with its reliability. It is also very scalable."
"It is easy to use and performs very well."
"I think it's very easy to implement this solution because one person can do it."
"We can use our devices to check all of the perimeters, and it secures email websites."
"By utilizing features such as dynamic path selection and application-aware routing, we've been able to reduce latency for critical applications such as VoIP and video by 20-30% during peak times."
"The virtual firewall feature is the most valuable. We have around 1,500 firewalls. We did not buy individual hardware, and the virtual firewalls made sense because we don't have to keep on buying the hardware. FortiGate is easier to use as compared to Checkpoint devices. It is user friendly and has a good UI. You don't need much expertise to work on this firewall. You don't need to worry much about DCLA, commands, and things like that."
"The most valuable feature is the policy routing and application control."
"There are lots of features and most of them are deployed for internet security. Users are protected if they accidentally go to some malicious sites."
"Overall, the entire Netgate pfSense Plus Firewall_VPN_Router product has been reliable, though some of their smaller gear aimed at remote offices hasn't been cost-effective."
"I do not have complaints about Netgate pfSense Plus Firewall_VPN_Router with Firewall, VPN, and Router; it is really comfortable for use, and it does a pretty good job."
"My experience with the product is that it is a stable and good product that is easy to use."
"We use pfSense and Netgate pfSense Plus Firewall/VPN/Router to establish a VPN tunnel between our client and our headquarters to transfer data between client and our equipment; it's very simple to use, efficient, up to date, and the hardware is very available; it's very safe."
"They are more satisfied with Netgate pfSense Plus Firewall_VPN_Router in terms of its flexibility and customer support."
"It's very simple to use, efficient, up to date, and the hardware is very available; it's very safe."
"Compared with Check Point, it's excellent."
"This is arguably the best security protection that you can buy."
"There are plenty of features available in this solution, such as attack blocker and spam blocker, and it is very robust and in-depth."
"This is arguably the best security protection that you can buy."
"The application layer to the hardware layer is good, as are all layers it offers, and it's a very comprehensive solution."
"Palos Alto's firewalls have machine learning software and sandboxing, and everything is one step ahead of all the competitors."
"The DNS sync code in your filtering is the most valuable feature of the Palo Alto Networks NG Firewalls."
"Overall, it is a good solution; it is stable, and we use URL filtering, which is useful for blocking undesired URLs."
 

Cons

"There are some tiny bugs that sometimes affect the operations. In the past revision of it, there was a bug. Because of the bug, we had to downgrade the version. It happened only with the last revision."
"Fortinet FortiGate IPS could improve the VPN. There are times it is slow."
"In the future, I would like to see improvements made to cloud-based management."
"Sometimes you do need to know some CLI commands, so it's a bit harder for technicians or new people that don't know it."
"The solution lacks multi-language support."
"This product needs to have an analysis feature, rather than having the analysis done through the integration of a different product."
"The solution's real-time connection with the cloud could be improved."
"The reporting was limited."
"I would assess the effectiveness of Netgate pfSense Plus Firewall_VPN_Router's traffic shaping as good, but I would give a six marks only for that compared to others because in the past few years, there has been a stop of improvement or lack of improvement showing in Netgate pfSense Plus Firewall_VPN_Router."
"The pricing for the hardware of Netgate pfSense Plus Firewall_VPN_Router is steep, which is one reason I'd explore other options."
"The effectiveness of Netgate pfSense Plus Firewall_VPN_Router traffic shaping is quite good, but I am not very satisfied with the interface for control."
"They have to learn something more from FortiGate."
"The most significant drawback in recent years has been the cessation of firmware release downloads."
"We have not taken Palo Alto's firewall management solution because it's too expensive and we don't feel it delivers significant value."
"They can work on the price. They are a little bit expensive, and not all customers are able to afford this solution. Taking into consideration that there is huge competition in the market and there are multiple firewall companies that are much cheaper than them and offer almost the same features, it would be good to improve the price."
"I would like more reporting and metrics in the solution."
"The tech support was once great, but now it is poor. The tech support has gone south. It is really difficult. I had a Priority 1 case last a week in their queue, and after multiple complaints, I finally got somebody to take the case. These are things that are unacceptable in the business world. They could train their employees better."
"The initial configuration is complicated to set up."
"Palo Alto hardware is not equal to the level of the Cisco Device. The hardware is weak."
"Over the past one or two years, Palo Alto Networks has added a lot of features into the NG Firewall products. I think this is becoming more complicated for our customers."
"Most of the time, they were pretty good, but sometimes technical support couldn't resolve the issue, and they don't know what to do."
 

Pricing and Cost Advice

"The pricing is better compared to other solutions like Check Point, Arista, or Cisco."
"The solution is offered as an annual license."
"Pricing is good. They offer a lot of things, the most important is the support. Every time you upgrade your license, you also get insurance for the equipment. If you have any problem with equipment, they send in new equipment."
"The price of Fortinet FortiGate is affordable. Most of our customers are on a three-year license to use the solution. All the features and support are included in the price."
"Easy to understand licensing requirements."
"I pay €1,200 per year for the license along with Fortinet's 81E firewall appliance. I would rate this pricing as 3/5 stars, and I believe the price is reasonably similar to its competitors in the market, being somewhere in the middle."
"Fortinet FortiGate is reasonably priced."
"While Fortinet FortiGate has a higher price point compared to Sophos XG, its user-friendly interface justifies the cost."
Information not available
"It is a little bit expensive than other firewalls, but it is worth every penny. There are different licenses for the kinds of services you want to use. When we buy a new product, we go for a three-year subscription."
"Palo Alto is like Mercedes-Benz. It is quite expensive, but the price is definitely justified."
"There are security licenses."
"The tool's pricing is similar to that of Cisco. It's a security appliance; the cost depends on your network topology and specific requirements. The suitability of NG firewalls should be chosen based on your network and what you need. If a colleague from a different company asked for the cheapest and fastest firewall, I suggest they consider options like Sophos. Sophos took over Cyberoam, which was previously a leader in NG firewalls"
"I am not involved in the commercial side, but I believe that Palo Alto is quite expensive compared to others."
"Definitely look into a multi-year license, as opposed to a single-year. That will definitely be more beneficial in terms of cost... Palo Alto is definitely not the cheapest, but if you scale it the right way it will be very comparable to what's out there."
"You get what you pay for."
"Pricing is yearly, but it depends. You could pay on a yearly basis, or every three years. If you want to add a device or two, there would be an additional cost. Also, if you want to do an assessment, or other similar add-on, you have to pay accordingly for the additional service."
report
Use our free recommendation engine to learn which Firewalls solutions are best for your needs.
894,738 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
10%
Comms Service Provider
10%
Manufacturing Company
9%
Financial Services Firm
7%
Construction Company
39%
Comms Service Provider
11%
Healthcare Company
8%
Financial Services Firm
6%
Computer Software Company
10%
Manufacturing Company
9%
Financial Services Firm
8%
Comms Service Provider
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business367
Midsize Enterprise135
Large Enterprise193
No data available
By reviewers
Company SizeCount
Small Business77
Midsize Enterprise56
Large Enterprise85
 

Questions from the Community

Which is the better NGFW: Fortinet Fortigate or Cisco Firepower?
When you compare these firewalls you can identify them with different features, advantages, practices and usage a...
What is the biggest difference between Sophos XG and FortiGate?
From my experience regarding both the Sophos and FortiGate firewalls, I personally would rather use FortiGate. I know...
What are the biggest technical differences between Sophos UTM and Fortinet FortiGate?
As a solution, Sophos UTM offers a lot of functionality, it scales well, and the stability and performance are quite ...
What needs improvement with Netgate pfSense Plus Firewall/VPN/Router?
Netgate pfSense Plus Firewall/VPN/Router regularly provides updates. One aspect they can improve is that most people ...
What is your primary use case for Netgate pfSense Plus Firewall/VPN/Router?
We work with Netgate products. We are a reseller and consultant. We have been working with Netgate and Fortinet for a...
What advice do you have for others considering Netgate pfSense Plus Firewall/VPN/Router?
For metrics to measure its impact, we do not measure in a formal way. We use bandwidth monitoring to check how effect...
What is a better choice, Azure Firewall or Palo Alto Networks NG Firewalls?
Azure Firewall Vs. Palo Alto Network NG Firewalls Both solutions provide stellar stability and security. Azure Firew...
Features comparison between Palo Alto and Fortinet firewalls
In the best tradition of these questions, Feature-wise both are quite similar, but each has things it's better at, it...
Which is better - Palo Alto Networks NG Firewalls or Sophos XG?
Palo Alto Networks NG Firewalls have both great features and performance. I like that Palo Alto has regular threat si...
 

Also Known As

Fortinet FortiGate Next-Generation Firewall
No data available
Palo Alto NGFW, Palo Alto Networks Next-Generation Firewall
 

Overview

 

Sample Customers

Amazon Web Services, Microsoft, IBM, Cisco, Dell, HP, Oracle, Verizon, AT&T, T-Mobile, Sprint, Vodafone, Orange, BT Group, Telstra, Deutsche Telekom, Comcast, Time Warner Cable, CenturyLink, NTT Communications, Tata Communications, SoftBank, China Mobile, Singtel, Telus, Rogers Communications, Bell Canada, Telkom Indonesia, Telkom South Africa, Telmex, Telia Company, Telkom Kenya
Information Not Available
SkiStar AB, Ada County, Global IT Services PSF, Southern Cross Hospitals, Verge Health, University of Portsmouth, Austrian Airlines, The Heinz Endowments
Find out what your peers are saying about Netgate pfSense Plus Firewall/VPN/Router vs. Palo Alto Networks NG Firewalls and other solutions. Updated: April 2026.
894,738 professionals have used our research since 2012.