No more typing reviews! Try our Samantha, our new voice AI agent.

Netgate pfSense Plus Firewall/VPN/Router vs Palo Alto Networks NG Firewalls comparison

Sponsored
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Fortinet FortiGate
Sponsored
Ranking in Firewalls
1st
Average Rating
8.4
Reviews Sentiment
6.9
Number of Reviews
589
Ranking in other categories
Secure Web Gateways (SWG) (2nd), Intrusion Detection and Prevention Software (IDPS) (1st), Software Defined WAN (SD-WAN) Solutions (1st), WAN Edge (1st), ZTNA (1st), Unified Threat Management (UTM) (1st)
Netgate pfSense Plus Firewa...
Ranking in Firewalls
23rd
Average Rating
9.0
Reviews Sentiment
4.3
Number of Reviews
5
Ranking in other categories
No ranking in other categories
Palo Alto Networks NG Firew...
Ranking in Firewalls
7th
Average Rating
8.6
Reviews Sentiment
7.2
Number of Reviews
197
Ranking in other categories
No ranking in other categories
 

Featured Reviews

Vasu Gala - PeerSpot reviewer
Manager, Information Technology Operation/Presales at TechMonarch
A stable solution with an intuitive interface and quick customer service
I have been working with Fortinet FortiGate, WatchGuard, Sophos, and SonicWall. I'm not as comfortable with SonicWall because of their UI and limitations. I prefer Fortinet above all other options. When it comes to configuration, I am confident in my ability to handle various tasks, including creating policies such as firewall rules, web policies, and application policies. Additionally, I can configure VPNs and implement load balancing, among other tasks. Overall, I feel much more comfortable working with Fortinet. Fortinet has made significant improvements by integrating AI with firewalls for threat analysis and prevention. In the past 2-3 years, they have launched FortiSASE and SIEM, and they also provide SOC services. Both Palo Alto and Fortinet FortiGate are excellent. While Fortinet FortiGate comes at higher prices, the functionality and support justify the cost. They promptly resolve firmware issues and inform all support providers about configuration changes.
Jim Voige - PeerSpot reviewer
Site Manager at a consultancy with 11-50 employees
High availability routing has secured our network and delivers reliable support every day
One downside of Netgate pfSense Plus Firewall_VPN_Router is the need for a better understanding of what hardware it would run on. Right now, we're using Netgate's hardware, but I'm interested in knowing if there are other hardware options available, particularly heavier duty hardware, because the Supermicro 1537 version we have only has a single power supply, which is a shortcoming in an IT environment where dual power supplies are ideal. The pricing for the hardware of Netgate pfSense Plus Firewall_VPN_Router is steep, which is one reason I'd explore other options. I'm familiar with the costs of Supermicro servers, and I believe Netgate charges a premium for their server hardware without enough upside to justify it. The pricing is not justified.
SV
Solution Architect // Network Consultant at Group S
Network security has improved and allows detailed user-based control over encrypted traffic
Bandwidth usage is not something we use much, but it depends on the SD-WAN plugin because the application load balancing is based on the SD-WAN product. That functionality does not work as it should, although the App-ID is working very well. SD-WAN functionality is working, but when you compare it with other products on the market, it is very limited. Palo Alto also has ION devices, and ION devices together with Prisma Access or Strata Cloud Manager now are more the way to go than using Palo Alto Networks NG Firewalls on-premises. At the moment I have some issues, but the issues are more related to the general way of working of many vendors. They implement new things very fast and it is not always bug-free. With new releases, sometimes you still have some issues. This is the main concern. If you look back five or maybe ten years ago, the products were more stable and you had more decent releases, but that is something in general for many vendors. Palo Alto is also a factor with that. They want to bring new features to the market too fast. Features are a concern because all vendors try to compete against each other. If one vendor comes out with a new feature, then other vendors do the same. Sometimes they want to be the first on the market with it, and that sometimes introduces bugs or issues with the product.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Virtual Domains (VDOMs) are a feature that we found valuable."
"The solution has a user-friendly interface."
"The most valuable feature is the VDOM, which allows the customer to have multiple firewalls in a single campus."
"FortiGate Next Generation Firewall has a stateless balance proposition"
"It does a lot for you for intrusion protection and as an antivirus. The threat management bundle is worth the money. You don't need another company to monitor your web traffic for you. You can do everything yourself on the firewall. You restrict your own black list for people on the firewall. You don't need to pay some other company for another product to do that for you. The firewall can do that for you. So, it's an easy-to-use product for people to be independent. They don't need to rely on other vendors to do what the firewall can do. They can do everything."
"I love the interface."
"It's very good and very stable for businesses. It works very well."
"The most important feature is that it's easy to use, it is user-friendly and has all the features you need."
"My experience with the product is that it is a stable and good product that is easy to use."
"Overall, the entire Netgate pfSense Plus Firewall_VPN_Router product has been reliable, though some of their smaller gear aimed at remote offices hasn't been cost-effective."
"We use pfSense and Netgate pfSense Plus Firewall/VPN/Router to establish a VPN tunnel between our client and our headquarters to transfer data between client and our equipment; it's very simple to use, efficient, up to date, and the hardware is very available; it's very safe."
"They are more satisfied with Netgate pfSense Plus Firewall_VPN_Router in terms of its flexibility and customer support."
"It's very simple to use, efficient, up to date, and the hardware is very available; it's very safe."
"I do not have complaints about Netgate pfSense Plus Firewall_VPN_Router with Firewall, VPN, and Router; it is really comfortable for use, and it does a pretty good job."
"I like that Palo Alto does a good job of keeping the firewall updated with the latest threat signatures."
"We like the fact that this product can provide multiple layers of protection depending on our clients requirements, and can be configured to whatever level of protection and the specific protocols that they want."
"The application layer to the hardware layer is good, as are all layers it offers, and it's a very comprehensive solution."
"This is arguably the best security protection that you can buy."
"I like the sandbox feature, and it's very good. It kills each malware deployment in the sense of signatures within five minutes. So, we can secure our network and infrastructure very well within the stipulated time. The WildFire functionality is very good because a few files are also getting blocked. It's critical as malware attacks are also getting ignored, and the logging is very well maintained in this firewall. The most valuable solutions in this field are application-based firewalls. That is the main criteria of the firewall and functionality. We can get all the logs related to this and each and every packet. I like that the firewall is working as an application. The application-based entity we have deployed is well maintained and working very well. We were able to find lots of vulnerabilities when we deployed it, but we could not disclose all. But there were vulnerabilities we could block by updating the firewall and taking actions on clientside machines. So, we got to know that we have lots of vulnerabilities inside the organization too, and we took lots of steps and resolved the number of vulnerabilities. Palo Alto Networks NG Firewalls is an all-in-one solution. It provides every entity log, which is a very good functionality of this firewall. It gives every packet and aspect that the firewall is performing through its logs, and it does it very well. This firewall's unified platform helped eliminate multiple network security tools. If anyone uses P2P sites, cryptocurrency websites, or any illegal sites, we can block it easily. It gives us a proper alert for these kinds of sites, and it properly secures our network. Monitoring is the best thing we are doing here, and we can block this kind of vulnerability as soon as it comes to us."
"With Palo Alto NG Firewalls, we can pass all compliance requirements; we trust it and we are building the security of our environment based on it, and we feel that we are secure in our network."
"Palo Alto is very stable; I worked on Cisco products like FTD and Firepower, and they are not as stable as Palo Alto, and also some FortiGates are not stable, so Palo Alto, as far as I know, is the most stable firewall compared to these others."
"Its machine learning seems pretty good, and it seems like it is catching quite a few things."
 

Cons

"The user interface could be improved."
"FortiGate can only retain logs for 24 hours or 7 days. I'm not sure if it holds them for a longer period, such as for a month. It will be useful for assessing our strategy and monitoring our environment without investing in FortiGate Analyzer. It would be beneficial if Fortinet could enhance the FortiGate by providing more statistical and monitoring views for a longer timeframe, rather than requiring access to FortiGate Analyzer."
"I want some additional features. For example, I want something to ensure that when we are using Google email or Microsoft email, or Google Workspace, emails can only be accessed on designated machines given to our employees. I would like them to access data from designated machines, not from any machine. It should work for designated mobiles and laptops. I don't know if Fortinet provides something like that out of the box."
"Fortinet FortiGate could improve by adding FortiAnalyzer to its solution, we should not have to use another solution. FortiAnalyzer can provide more detailed information."
"Some of the software stability could improve."
"Fortinet needs more memory to save the log files. We need it to save the logs on the hardware and not in the cloud. I know this feature is available in FortiCloud, but if we need this log locally, it is not available."
"The price of the solution could be cheaper."
"The monitor and the visibility, in this proxy, is very weak."
"They have to learn something more from FortiGate."
"The most significant drawback in recent years has been the cessation of firmware release downloads."
"The effectiveness of Netgate pfSense Plus Firewall_VPN_Router traffic shaping is quite good, but I am not very satisfied with the interface for control."
"I would assess the effectiveness of Netgate pfSense Plus Firewall_VPN_Router's traffic shaping as good, but I would give a six marks only for that compared to others because in the past few years, there has been a stop of improvement or lack of improvement showing in Netgate pfSense Plus Firewall_VPN_Router."
"The pricing for the hardware of Netgate pfSense Plus Firewall_VPN_Router is steep, which is one reason I'd explore other options."
"There could be improvement with their logs, especially their CLI. When you go to the command line to understand the command line interface it's tricky and requires a deep understanding of the product."
"In the cloud, the HA could be a lot better."
"Palo Alto Networks NG Firewalls offer best-in-breed security but could improve by reducing their pricing."
"The solution has normal authentication, but does not have two-factor or multi-factor authentication."
"There are some options available in other firewall products that are not supported, so there is room for improvement in that regard."
"It is a good product, but they can add some functions for port scanning and network scanning."
"Palo Alto is like Microsoft. It has varied features, but it's too technical."
"When there was change from IPv4 to IPv6, some of the firewalls still didn't support IPv6."
 

Pricing and Cost Advice

"The product is not very expensive."
"The cost has increased since the update so I would rate it eight out of ten."
"It is not expensive as compared to Cisco."
"I rate the product's pricing a seven out of ten. Its one-year license cost is competitive with three and five-year licenses offered by other products."
"The licensing cost is at the intermediate level."
"The pricing is justified. It's a little pricey, but what you pay for is what you get."
"In the Asian economy in which we operate, FortiGate is expensive."
"The price is fine."
Information not available
"We haven't had a problem with pricing or licensing because we consolidated other software to make Palo Alto more affordable."
"It could be less expensive."
"Palo Alto Networks NG Firewalls are expensive compared to WatchGuard XTM firewalls."
"Reducing costs is important, especially since Prisma can be expensive. It would be great if it were more affordable."
"The cost is quite high."
"This is not the firewall to choose if you are looking for the cheapest and fastest solution. Palo Alto NGFWs are expensive. By the time you license them up and get them fully functional, you have spent quite a bit of money. If it is a small branch office with 10 to 15 users, that is hard to justify."
"It is expensive as compared to other brands."
"I am not sure about the specific licensing costs of Palo Alto Networks NG Firewalls, but FortiGate and Palo Alto are generally cheaper than some high-end Cisco devices."
report
Use our free recommendation engine to learn which Firewalls solutions are best for your needs.
885,311 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
11%
Comms Service Provider
9%
Manufacturing Company
8%
Financial Services Firm
6%
Construction Company
44%
Manufacturing Company
7%
Healthcare Company
5%
Performing Arts
5%
Computer Software Company
10%
Manufacturing Company
9%
Financial Services Firm
8%
Educational Organization
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business363
Midsize Enterprise135
Large Enterprise190
No data available
By reviewers
Company SizeCount
Small Business74
Midsize Enterprise56
Large Enterprise85
 

Questions from the Community

Which is the better NGFW: Fortinet Fortigate or Cisco Firepower?
When you compare these firewalls you can identify them with different features, advantages, practices and usage a...
What is the biggest difference between Sophos XG and FortiGate?
From my experience regarding both the Sophos and FortiGate firewalls, I personally would rather use FortiGate. I know...
What are the biggest technical differences between Sophos UTM and Fortinet FortiGate?
As a solution, Sophos UTM offers a lot of functionality, it scales well, and the stability and performance are quite ...
What needs improvement with Netgate pfSense Plus Firewall/VPN/Router?
Netgate pfSense Plus Firewall/VPN/Router regularly provides updates. One aspect they can improve is that most people ...
What is your primary use case for Netgate pfSense Plus Firewall/VPN/Router?
We work with Netgate products. We are a reseller and consultant. We have been working with Netgate and Fortinet for a...
What advice do you have for others considering Netgate pfSense Plus Firewall/VPN/Router?
For metrics to measure its impact, we do not measure in a formal way. We use bandwidth monitoring to check how effect...
What is a better choice, Azure Firewall or Palo Alto Networks NG Firewalls?
Azure Firewall Vs. Palo Alto Network NG Firewalls Both solutions provide stellar stability and security. Azure Firew...
Features comparison between Palo Alto and Fortinet firewalls
In the best tradition of these questions, Feature-wise both are quite similar, but each has things it's better at, it...
Which is better - Palo Alto Networks NG Firewalls or Sophos XG?
Palo Alto Networks NG Firewalls have both great features and performance. I like that Palo Alto has regular threat si...
 

Also Known As

Fortinet FortiGate Next-Generation Firewall
No data available
Palo Alto NGFW, Palo Alto Networks Next-Generation Firewall
 

Overview

Information not available
 

Sample Customers

Amazon Web Services, Microsoft, IBM, Cisco, Dell, HP, Oracle, Verizon, AT&T, T-Mobile, Sprint, Vodafone, Orange, BT Group, Telstra, Deutsche Telekom, Comcast, Time Warner Cable, CenturyLink, NTT Communications, Tata Communications, SoftBank, China Mobile, Singtel, Telus, Rogers Communications, Bell Canada, Telkom Indonesia, Telkom South Africa, Telmex, Telia Company, Telkom Kenya
Information Not Available
SkiStar AB, Ada County, Global IT Services PSF, Southern Cross Hospitals, Verge Health, University of Portsmouth, Austrian Airlines, The Heinz Endowments
Find out what your peers are saying about Netgate pfSense Plus Firewall/VPN/Router vs. Palo Alto Networks NG Firewalls and other solutions. Updated: March 2026.
885,311 professionals have used our research since 2012.