No more typing reviews! Try our Samantha, our new voice AI agent.

Netgate pfSense Plus Firewall/VPN/Router vs Palo Alto Networks NG Firewalls comparison

Sponsored
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Fortinet FortiGate
Sponsored
Ranking in Firewalls
1st
Average Rating
8.4
Reviews Sentiment
6.9
Number of Reviews
592
Ranking in other categories
Secure Web Gateways (SWG) (2nd), Intrusion Detection and Prevention Software (IDPS) (1st), Software Defined WAN (SD-WAN) Solutions (1st), WAN Edge (1st), ZTNA (1st), Unified Threat Management (UTM) (1st)
Netgate pfSense Plus Firewa...
Ranking in Firewalls
22nd
Average Rating
9.0
Reviews Sentiment
4.3
Number of Reviews
5
Ranking in other categories
No ranking in other categories
Palo Alto Networks NG Firew...
Ranking in Firewalls
6th
Average Rating
8.6
Reviews Sentiment
7.1
Number of Reviews
199
Ranking in other categories
No ranking in other categories
 

Featured Reviews

JK
IP Network Security Specialist at MTN Ghana
Process-Level CPU Visibility: Introduce detailed CPU-usage metrics per subsystem (e.g., IPS engine, logging) so administrators can quickly identify and address performance spikes.
Analytics with FortiAnalyzer. Being able to pull in logs not just from our FortiGates but from all our other firewalls and then get them in one view has been a game changer. Whether I’m building an executive dashboard or doing a deep dive forensics session, I get everything I need without navigating consoles.Straightforward Application Control. FortiGate spots and blocks unwanted apps (eq. like BitTorrent or streaming services) with accuracy. Segmentation with VDOMs. We’ve carved our data center into four logical ‘mini-firewalls’ enterprise, core, billing, and WAF—all on one box. Each has its own rules and logs, and any traffic between them still gets inspected. It’s like having multiple appliances without the extra hardware. Always-Up-to-Date Threat Feeds. Daily signature updates and AI-driven threat sensing mean we’re blocking the latest vulnerabilities almost as soon as they’re announced.
Jim Voige - PeerSpot reviewer
Site Manager at a consultancy with 11-50 employees
High availability routing has secured our network and delivers reliable support every day
One downside of Netgate pfSense Plus Firewall_VPN_Router is the need for a better understanding of what hardware it would run on. Right now, we're using Netgate's hardware, but I'm interested in knowing if there are other hardware options available, particularly heavier duty hardware, because the Supermicro 1537 version we have only has a single power supply, which is a shortcoming in an IT environment where dual power supplies are ideal. The pricing for the hardware of Netgate pfSense Plus Firewall_VPN_Router is steep, which is one reason I'd explore other options. I'm familiar with the costs of Supermicro servers, and I believe Netgate charges a premium for their server hardware without enough upside to justify it. The pricing is not justified.
Nitin Yadav - PeerSpot reviewer
Network & Security Engineer at Arrow PC Network Pvt.Ltd.
Strong threat prevention has reduced phishing and malware while I monitor traffic in depth
Palo Alto Networks NG Firewalls offers application and user awareness, which allow me to control traffic based on threats. The product includes threat prevention, advanced threat prevention, and deep packet inspection that really helps prevent issues in our network. Deep packet inspection inspects full traffic content, even inside applications and encrypted sessions. Deep packet inspection makes a very practical difference day to day because it lets me see and control what is actually inside the traffic, not just the open port or IP. I have real visibility of which application is running instead of just seeing HTTPS. Palo Alto Networks NG Firewalls WildFire sandboxing is really good at detecting and blocking zero-day malware automatically, along with its GlobalProtect and DNS security features. Using Palo Alto Networks NG Firewalls positively impacts my organization by providing strong security, better visibility, faster response, and simplified operations. After deploying Palo Alto Networks NG Firewalls in our network, it blocks malicious traffic and prevents compromises that occurred before Palo Alto Networks NG Firewalls. I can now block outside IPs to prevent issues. After Palo Alto Networks NG Firewalls installation, I reduced 60 to 70 percent of malware and phishing attacks. Its threat prevention and DNS security features detect these attacks, block malicious domains, and reduce manual efforts for the security team.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The pricing is excellent. It's much less expensive than Cisco."
"Overall, this is a very good solution and I personally haven't had any problems with it."
"ROI is very high, it has hands-down the best price/performance/features ratio in the market."
"Customer Service: They're good. Technical Support: They're very good."
"I never encountered any stability issues; it is a very stable product."
"The most significant aspect of IPS is self-explanatory as it primarily focuses on intrusion prevention, which is crucial for Fortinet's internal outbreak prevention efforts and ensuring compliance on endpoint devices."
"The ease of use and the user-friendly interface are the beauty of this firewall."
"It has very easy management and an amazing ETM configuration."
"Overall, the entire Netgate pfSense Plus Firewall_VPN_Router product has been reliable, though some of their smaller gear aimed at remote offices hasn't been cost-effective."
"It's very simple to use, efficient, up to date, and the hardware is very available; it's very safe."
"I do not have complaints about Netgate pfSense Plus Firewall_VPN_Router with Firewall, VPN, and Router; it is really comfortable for use, and it does a pretty good job."
"My experience with the product is that it is a stable and good product that is easy to use."
"We use pfSense and Netgate pfSense Plus Firewall/VPN/Router to establish a VPN tunnel between our client and our headquarters to transfer data between client and our equipment; it's very simple to use, efficient, up to date, and the hardware is very available; it's very safe."
"They are more satisfied with Netgate pfSense Plus Firewall_VPN_Router in terms of its flexibility and customer support."
"Palo Alto Networks NG Firewalls are one of the best security products in the market at the moment, and they have a very good team."
"Overall, I really do prefer Palo Alto to other options, as it is very reliable, easy to configure, highly regarded on Gartner for its feature set and usability, and can easily integrate into a larger holistic security system to help keep a company safe."
"It has a unique approach to packet processing. It has single-pass architecture. We can easily perform policy lookups, application decoding, and integration or merging. This can be all done with a single pass. It effectively reduces the amount of processing required to perform multiple actions. This is the main advantage of using Palo Alto."
"You just need a web browser to manage it, unlike Cisco, which requires another management system."
"With our High availability pair, we have had no downtime for several years, since it was first put it in production."
"The functionality is good and so are the features."
"Palo Alto Networks NG Firewalls enabled us to have better visibility overall."
"I like that Palo Alto does a good job of keeping the firewall updated with the latest threat signatures."
 

Cons

"The FortiGate Next Generation Firewall (NGFW) could be improved in application control if they can have a bigger baseline of applications that they can identify, because this is something that is always growing."
"The web process often has a memory leak."
"When it's overloaded, it works slower and overheats."
"They can probably improve the reporting feature. Reporting and report alerting are the main key features of this solution. They can always find ways to improve these."
"As far as wanting more scalability or things in the network diagram, it's going to cost you."
"The performance could be a bit better. Right now, I find it to be lacking. Having good performance is very important for our work."
"It is essential to leverage its capabilities more professionally to achieve an even higher level of security."
"I think they could improve the monitoring."
"The pricing for the hardware of Netgate pfSense Plus Firewall_VPN_Router is steep, which is one reason I'd explore other options."
"The most significant drawback in recent years has been the cessation of firmware release downloads."
"They have to learn something more from FortiGate."
"The effectiveness of Netgate pfSense Plus Firewall_VPN_Router traffic shaping is quite good, but I am not very satisfied with the interface for control."
"I would assess the effectiveness of Netgate pfSense Plus Firewall_VPN_Router's traffic shaping as good, but I would give a six marks only for that compared to others because in the past few years, there has been a stop of improvement or lack of improvement showing in Netgate pfSense Plus Firewall_VPN_Router."
"The level of control and granularity in terms of rule customization could be enhanced. However, compared to our previous solution, Palo Alto provides much better drill-down capabilities."
"When we looked at it originally, we needed to host the Panorama environment ourselves. I would prefer it if we could take this as a service. It might be that it is available, but for some reason we didn't choose it. The downsides of hosting are that we need to feed and water the machines. We are trying to move to a more SaaS environment where we have less things in our data centers, whether they be in our cloud data centers or physical data centers, which can reduce our physical data center footprint."
"This is a difficult product to manage, so the administrator needs to have a good knowledge of it, otherwise, they will not be able to handle it properly."
"Palo Alto can do a little bit better when it comes to the User-ID part. I've been facing problems related to double authentication."
"The machine learning component on the firewall level requires more computing power to perform at the full production level. Therefore, the ML is currently providing partial real-time attack prevention."
"I'm thinking about a new feature. They have decryption. It's a good idea to use decryption on Palo Alto. It would be good if they had offloading of the traffic, and if they could decrypt the traffic and offload it. Like, for example, ASM on our site. We have an SSL decryption to offload the traffic. We could use that on Palo Alto."
"From a financial perspective, this solution is quite expensive."
"We need better affiliations for profiling the user."
 

Pricing and Cost Advice

"Fortinet bundles FortiGate with other products and because of this, the price is a little expensive to some SMB enterprises."
"While slightly more affordable than competitors, it remains relatively expensive due to its inclusive subscription."
"The solution could be better priced."
"The price of Fortinet FortiGate could improve, it is expensive."
"Their licensing costs are annual. The UTM feature license along with their support is called FortiCare. We include that as a part of the annual maintenance cost. Palo Alto or Juniper also have an annual subscription charge for UTM. Price, of course, can always be more competitive, but it is not the most expensive product. The price-performance ratio is quite high for FortiGate."
"We have the full license that included all of the features and support."
"Before choosing a piece of equipment you have to take into account the cost-benefit offered by each one. Sometimes it is not worth paying a very cheap price to have a minimum level of security."
"If we have an older version, the support costs get quite high."
Information not available
"The cost of Palo Alto Network NG Firewalls is significantly higher compared to Huawei."
"It can be quite expensive, but there's a good incentive for the three-year contracts. The part that is especially confusing is for the virtual environment. The credits or the licensing system can be very confusing."
"Pricing is yearly, but it depends. You could pay on a yearly basis, or every three years. If you want to add a device or two, there would be an additional cost. Also, if you want to do an assessment, or other similar add-on, you have to pay accordingly for the additional service."
"While Palo Alto Networks Next-Generation Firewalls may be considered expensive, their quality justifies the cost."
"If someone doesn't have a security platform in their network, then the following licenses will be required: antivirus, anti-spyware, vulnerability, and Wildfire analysis. There are also licenses for GlobalProtect and support."
"Its price can be better. Licensing is on a yearly basis."
"The solution is worth the price, as it can be utilized without the need for high-processing CPUs and resources, thus saving us overall."
"The price is based on that selected package, with the lowest starting at $3,000 annually."
report
Use our free recommendation engine to learn which Firewalls solutions are best for your needs.
902,588 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Comms Service Provider
10%
Computer Software Company
9%
Manufacturing Company
9%
Financial Services Firm
7%
Construction Company
38%
Comms Service Provider
10%
Healthcare Company
8%
Manufacturing Company
7%
Manufacturing Company
10%
Computer Software Company
9%
Financial Services Firm
9%
Comms Service Provider
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business369
Midsize Enterprise139
Large Enterprise195
No data available
By reviewers
Company SizeCount
Small Business77
Midsize Enterprise57
Large Enterprise87
 

Questions from the Community

Which is the better NGFW: Fortinet Fortigate or Cisco Firepower?
When you compare these firewalls you can identify them with different features, advantages, practices and usage a...
What is the biggest difference between Sophos XG and FortiGate?
From my experience regarding both the Sophos and FortiGate firewalls, I personally would rather use FortiGate. I know...
What are the biggest technical differences between Sophos UTM and Fortinet FortiGate?
As a solution, Sophos UTM offers a lot of functionality, it scales well, and the stability and performance are quite ...
What needs improvement with Netgate pfSense Plus Firewall/VPN/Router?
Netgate pfSense Plus Firewall/VPN/Router regularly provides updates. One aspect they can improve is that most people ...
What is your primary use case for Netgate pfSense Plus Firewall/VPN/Router?
We work with Netgate products. We are a reseller and consultant. We have been working with Netgate and Fortinet for a...
What advice do you have for others considering Netgate pfSense Plus Firewall/VPN/Router?
For metrics to measure its impact, we do not measure in a formal way. We use bandwidth monitoring to check how effect...
What is a better choice, Azure Firewall or Palo Alto Networks NG Firewalls?
Azure Firewall Vs. Palo Alto Network NG Firewalls Both solutions provide stellar stability and security. Azure Firew...
Features comparison between Palo Alto and Fortinet firewalls
In the best tradition of these questions, Feature-wise both are quite similar, but each has things it's better at, it...
Which is better - Palo Alto Networks NG Firewalls or Sophos XG?
Palo Alto Networks NG Firewalls have both great features and performance. I like that Palo Alto has regular threat si...
 

Also Known As

Fortinet FortiGate Next-Generation Firewall
No data available
Palo Alto NGFW, Palo Alto Networks Next-Generation Firewall
 

Overview

 

Sample Customers

Amazon Web Services, Microsoft, IBM, Cisco, Dell, HP, Oracle, Verizon, AT&T, T-Mobile, Sprint, Vodafone, Orange, BT Group, Telstra, Deutsche Telekom, Comcast, Time Warner Cable, CenturyLink, NTT Communications, Tata Communications, SoftBank, China Mobile, Singtel, Telus, Rogers Communications, Bell Canada, Telkom Indonesia, Telkom South Africa, Telmex, Telia Company, Telkom Kenya
Information Not Available
SkiStar AB, Ada County, Global IT Services PSF, Southern Cross Hospitals, Verge Health, University of Portsmouth, Austrian Airlines, The Heinz Endowments
Find out what your peers are saying about Netgate pfSense Plus Firewall/VPN/Router vs. Palo Alto Networks NG Firewalls and other solutions. Updated: June 2026.
902,588 professionals have used our research since 2012.