Try our new research platform with insights from 80,000+ expert users

Netgate pfSense vs Palo Alto Networks CN-Series comparison

Sponsored
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Fortinet FortiGate
Sponsored
Ranking in Firewalls
1st
Average Rating
8.4
Reviews Sentiment
6.9
Number of Reviews
580
Ranking in other categories
Secure Web Gateways (SWG) (2nd), Intrusion Detection and Prevention Software (IDPS) (1st), Software Defined WAN (SD-WAN) Solutions (1st), WAN Edge (1st), ZTNA (1st), Unified Threat Management (UTM) (1st)
Netgate pfSense
Ranking in Firewalls
2nd
Average Rating
8.6
Reviews Sentiment
7.1
Number of Reviews
220
Ranking in other categories
No ranking in other categories
Palo Alto Networks CN-Series
Ranking in Firewalls
31st
Average Rating
9.6
Reviews Sentiment
7.4
Number of Reviews
2
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of January 2026, in the Firewalls category, the mindshare of Fortinet FortiGate is 18.8%, down from 20.7% compared to the previous year. The mindshare of Netgate pfSense is 9.9%, down from 16.1% compared to the previous year. The mindshare of Palo Alto Networks CN-Series is 0.2%, up from 0.0% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Firewalls Market Share Distribution
ProductMarket Share (%)
Fortinet FortiGate18.8%
Netgate pfSense9.9%
Palo Alto Networks CN-Series0.2%
Other71.1%
Firewalls
 

Featured Reviews

Vasu Gala - PeerSpot reviewer
Manager, Information Technology Operation/Presales at TechMonarch
A stable solution with an intuitive interface and quick customer service
I have been working with Fortinet FortiGate, WatchGuard, Sophos, and SonicWall. I'm not as comfortable with SonicWall because of their UI and limitations. I prefer Fortinet above all other options. When it comes to configuration, I am confident in my ability to handle various tasks, including creating policies such as firewall rules, web policies, and application policies. Additionally, I can configure VPNs and implement load balancing, among other tasks. Overall, I feel much more comfortable working with Fortinet. Fortinet has made significant improvements by integrating AI with firewalls for threat analysis and prevention. In the past 2-3 years, they have launched FortiSASE and SIEM, and they also provide SOC services. Both Palo Alto and Fortinet FortiGate are excellent. While Fortinet FortiGate comes at higher prices, the functionality and support justify the cost. They promptly resolve firmware issues and inform all support providers about configuration changes.
MC
Chief information security officer at Center for Information Management, Inc.
Provides visibility that enables users to make data-driven decisions
pfSense flexibility overall is pretty good. They are making some really big improvements. That said, they're a long way from enterprise. They advertise things that they don't have. I've worked for probably 30% of the Corporate 100, and they won't tolerate the high availability and it being as buggy as it is. The fact that if you configure it incorrectly without any visual indications that it's not done in the way Netscape does, then it will not only break the firewall, it will break both firewalls. The only way you can even try to recover is by getting new images from Netgate. You have to open up a tech support case, download the image for, then reimage the firewalls, and reapply your configuration. The fact that you can completely brick your firewalls just by having a configuration that they allow, and they don't even don't tell you there's a problem until they both go down. That's totally unacceptable in an enterprise. As a standalone firewall, they're excellent. As an enterprise, we're not touching it with a ten-foot pole. It’s difficult to configure and use add-on features. It's really easy to add them. On the website, they say “Oh, we do this, this, and this.” However, they do a lot through third-party add-ons. The problem is, if there's any problems at all, the very first thing they want you to do is disable those add-ons. So that's not really supporting anything. There are two ways that firewalls are viewed: talking to the firewall and talking through the firewall. If you're talking about “to the firewall,” then it's a very robust, very secure firewall. However, it doesn't have things that they claim helps with protecting data, most of it's third party. If you want to do all these things that are typically associated with enterprise-level firewalls, most of them are done by a third party. It's not actually cooked into their product. I like their OSPF. I wish it was more current. The only bugs that are in the OSPF are ones that have been known about for almost two years. Maybe they're they're victims of their own success. Their growth curve has outstripped their technical support and has outstripped their ability to develop. They're just growing so fast. They're trying to do everything. Updates from third parties can take too long. For example, if there's a problem with a package and no available update is available, you have to wait. Since it's via a third party, there's no definable schedule, as the update needs to come from a third-party open organization with no financial interest to make the process faster. Sometimes, there's more finger-pointing than resolution. In, OSPF, they give you lots of information. However, when it comes to hardcore troubleshooting of different routing zones or things like that, then you had to keep dropping down to the CLI in order to get it. And that's where your experience can change quite a bit. If you're running OSPF on Cumulus or some of the other big routing or switching solutions, then they're running much newer versions of it, which are all bug-patched and fixed. However, pfSense is running on an operating system that is not theirs. They don't necessarily have full control over it. When you get a real enterprise firewall, and when you hook up the redundancy, you expect redundancy to work and be predictable. And never ever will the redundancy crash your system. If you don't create the interfaces in the exact same order on both firewalls every single time, if so much as one interface is out of order, if the command line is different because of the way the operating system works, you will slowly corrupt your configuration to the point where it'll break.
Ahmed_Shalaby - PeerSpot reviewer
Senior Cyber Security Engineer at Beta Information Technology
Application control excels and integration with monitoring system boosts efficiency
I am an integrator working with Palo Alto Networks CN-Series and Panorama. I have been involved with the implementation of Palo Alto Networks CN-Series The stability of Palo Alto Networks CN-Series is excellent. Application control is one of the most valuable features. Its monitoring capability…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Fortinet is the best choice for small enterprises because it provides security as per their requirement and comes under their budget, making the pricing very acceptable for medium-level and small-level enterprise customers."
"When I survey FortiGate products, I see that they have a good performance, especially in terms of next generation firewalls."
"Stateful packet inspection is valuable. It also does SSL packet inspection. It is able to provide a VPN for remote users with secure connectivity."
"The stability and scalability of this solution are satisfactory. Its SD-WAN, VPN, and URL filtering features are very useful."
"FortiGate Next Generation Firewall has a stateless balance proposition"
"We are using the FortiGate 100D series. VPN, firewall, anti-malware, OTM, and intrusion prevention are useful features."
"The price-to-performance ratio for using Fortinet FortiGate is always better compared to any other competitor, so they are rated better than the likes of Check Point or Palo Alto."
"The main benefit is the grouping of our security monitoring."
"Support is excellent."
"Remote access with two-factor authentication was a big one for us. Pulling in things like Endpoint NG to monitor traffic has been quite helpful. The pfBocker has been good. It helps us limit who's trying to bash away at access to the systems."
"It is a robust tool that can replace your consumer-grade firewall router solution."
"They're very affordable for what they offer."
"It has a very nice web interface, and it is very simple to use. The way policies are working is also good."
"One of the advantages of pfSense is that it is very easy to work with. It is a very good open-source solution, and it works really well. pfSense provides a complete package. For some features, it could be the first solution in the world. It is a very good alternative in the market for a firewall solution. You don't need to go to Cisco or other brands with expensive firewalls. pfSense also allows us to offer some support services."
"The tools' most valuable feature is load balancing."
"The plugins or add-ons are most valuable. Sometimes, they are free of charge, and sometimes, you have to pay for them, but you can purchase or download very valuable plugins or add-ons to perform internal testing of your network and simulate a denial-of-service attack or whichever attack you want to simulate. You can also remote and monitor your network and see where the gap is. Did you forget a printer port? Most attacks at the moment are happening through printers, and they can tell you immediately that you forgot to close the port of the printer. There are more than one million printers that are in danger, and everybody knows that hackers are using them to enter the network. So, you can download plugins to protect your network."
"The app inspection is very helpful for network security."
"The stability of Palo Alto Networks CN-Series is excellent."
 

Cons

"In my case, the 101F is not scalable. I faced problems with scalability related to memory. When we hit 100% memory usage, it stops the internet connection, so we need to control the traffic. We cannot increase the memory."
"Application management can be improved."
"We had a minor problem where there was a major system upgrade on the hardware platfrom and the Mac client was not available as soon as it might have been. The PC client was available immediately, but we had to wait a month or so, before there was a mac client. I was slightly irritated that it was not ready on time, but it was eventually resolved."
"We also have FortiAnalyzer deployed here, so we want to enable the soft functionality of FortiGate and built-in compression for a firewall VPN use case. We want the ability to deploy a gateway for HTTPS enabled on this firewall. It is currently only for use in our headquarters."
"Some of the software stability could improve."
"One area for improvement involves FortiAnalyzer, specifically regarding the SOC part and log interpretation. Sometimes interpretation is very difficult."
"My only complaint about FortiGate is a lack of QinQ VLAN tunneling. I haven't found this feature in any Fortinet product. You can do this on all Cisco routers, including the smaller models. However, QinQ isn't available on the biggest, most expensive Fortinet units. They still don't have that. I think now we're on software version 6.0, and they still haven't found a solution for QinQ. It isn't a dealbreaker, but that's my main complaint."
"The solution's GUI is not very appealing."
"I tried pfSense, and it has a big issue with file system consistency, and this is what drove me to OPNsense. The file system stability is quite a big issue for us. We have a lot of outages related to power issues, and OPNsense is much more stable on this side."
"If pfSense could change its framework from FreeBSD and PHP to a different language and Linux OS, that could enhance security."
"One area of improvement would be better communication. They kind of left a lot of people in the dark and misled them about the pfSense Plus Edition. I feel like they automatically switched people over and then followed that up with a required subscription model. That aggravated a lot of customers, including me, but I stuck with it regardless."
"If you want to take advantage of all of the solution's options, you need to have a bit of a technical background. It's not for a layperson."
"pfSense's dashboard offers basic monitoring, but it lacks centralized management for multiple PSM devices and a unified event interface for various services."
"Perhaps the documentation is not clear and because it is supported in the community there is no basic documentation."
"It needs to be more secure."
"The solution could improve by adding in some sort of user account credentials in in the sense of accommodating more levels of users. From what I've found, everybody has basically the same access."
"Palo Alto Networks CN-Series could improve on its pricing as it is quite expensive."
"I'd like to see more IOPs features."
 

Pricing and Cost Advice

"For the price, I'd rate it a ten because it's very cost-effective."
"The price could be lower."
"Fortinet has one or two license types, and the VPN numbers are only limited by the hardware chassis make."
"It was probably about $2,500 per firewall. It was all included. It included support, services, threat management software, and 24/7 FortiCare on it. Cisco products are more expensive."
"It is cost-effective, and provides a good value for your money. The pricing, and license renewal, is very reasonable for us."
"Compared to other firewall products, it's a little cheaper in terms of pricing."
"When comparing the price of Fortinet FortiGate SWG to other solutions it is expensive. The price could be better."
"The price for the device and software is high. However, the solution is of good quality and has a lot of features."
"Looking at what it does, I think that it is fairly priced."
"Because the Community edition is free, we only charge for our services to the customers. In Turkey, we cannot demand normal pricing; if we were in Europe or the United States, we might collect more money from customers."
"The pricing is lower than some of its competitors."
"The tool is flexible; even the free, open-source version offers many features. From a cost perspective, even the subscription model for commercial support isn't too costly. However, it's important to have someone knowledgeable about Netgate pfSense to take advantage of it. While there are online resources, a professional or someone experienced can get much more out of the solution. I've heard that the IPS/IDS licenses and other features can be costly."
"The pricing seems fair overall, but I think they need more reasonably priced options for very small offices."
"I spent a couple of $1,000 on hardware, and the OS was free. A comparable firewall would cost me probably 20 grand. It saved a lot of money."
"There is no licensing fee except for the enterprise support, if you want it."
"There is an open-source community version that is available."
Information not available
report
Use our free recommendation engine to learn which Firewalls solutions are best for your needs.
881,114 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
12%
Comms Service Provider
9%
Manufacturing Company
8%
Financial Services Firm
6%
Comms Service Provider
14%
Computer Software Company
12%
Manufacturing Company
7%
Educational Organization
6%
No data available
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business357
Midsize Enterprise133
Large Enterprise188
By reviewers
Company SizeCount
Small Business168
Midsize Enterprise33
Large Enterprise29
No data available
 

Questions from the Community

Which is the better NGFW: Fortinet Fortigate or Cisco Firepower?
When you compare these firewalls you can identify them with different features, advantages, practices and usage a...
What is the biggest difference between Sophos XG and FortiGate?
From my experience regarding both the Sophos and FortiGate firewalls, I personally would rather use FortiGate. I know...
What are the biggest technical differences between Sophos UTM and Fortinet FortiGate?
As a solution, Sophos UTM offers a lot of functionality, it scales well, and the stability and performance are quite ...
Help me find the best open source router
You don't really specify what type of router you are looking for but if you are talking about a gateway router I reco...
How do I choose between Fortinet FortiGate and pfSense?
Fortinet’s Fortigate is a firewall solution we use and are very much satisfied with its performance. We find Fortigat...
What is the difference between PfSense and OPNsense?
Two of the most common and well recognized firewalls, PfSense and OPNsense both support site-to-site IPsec VPN and cl...
What is your experience regarding pricing and costs for Palo Alto Networks CN-Series?
The pricing of Palo Alto Networks CN-Series is quite expensive, rating around eight on a scale of one to ten for cost.
What needs improvement with Palo Alto Networks CN-Series?
Palo Alto Networks CN-Series could improve on its pricing as it is quite expensive. The SD-WAN implementation using P...
What is your primary use case for Palo Alto Networks CN-Series?
I am an integrator working with Palo Alto Networks CN-Series ( /products/palo-alto-networks-cn-series-reviews ) and P...
 

Also Known As

Fortinet FortiGate Next-Generation Firewall
No data available
No data available
 

Overview

 

Sample Customers

Amazon Web Services, Microsoft, IBM, Cisco, Dell, HP, Oracle, Verizon, AT&T, T-Mobile, Sprint, Vodafone, Orange, BT Group, Telstra, Deutsche Telekom, Comcast, Time Warner Cable, CenturyLink, NTT Communications, Tata Communications, SoftBank, China Mobile, Singtel, Telus, Rogers Communications, Bell Canada, Telkom Indonesia, Telkom South Africa, Telmex, Telia Company, Telkom Kenya
Nerds On Site Inc., RKC Development Inc., Expertech, Fisher's Technology, Ncisive, Consulting, CPURX, Vaughn's Computer House Calls, Imeretech LLC, Digital Crisis, Carolina Digital Phone, Technigogo Technology Services, The Simple Solution, SwiftecITInc, Rocky Mountain Tech Team, Free Range Geeks, Alaska Computer Geeks, Lark Information Technology, Renaissance Systems Inc., Cutting Edge Computers, Caretech LLC, GoVanguard, Network Touch Ltd, P.C. Solutions.Net, Vision Voice and Data Systems LLC, Montgomery Technologies, Techforce, Concero Networks, ASONInc, CPS Electronics and Consulting, Darkwire.net LLC, IT Specialists, MBS-Net Inc., VOICE1 LLC, Advantage Networking Inc., Powerhouse Systems, Doxa Multimedia Inc., Pro Computer Service, Virtual IT Services, A&J Computers Inc., Envision IT LLC, CommunicaONE Inc., Bone Computer Inc., Amax Engineering Corporation, QPG Ltd. Co., IT 101 Inc., Perfect Cloud Solutions, Applied Technology Group Inc., The Digital Sun Group LLC, Firespring
Information Not Available
Find out what your peers are saying about Netgate pfSense vs. Palo Alto Networks CN-Series and other solutions. Updated: December 2025.
881,114 professionals have used our research since 2012.