No more typing reviews! Try our Samantha, our new voice AI agent.

Palo Alto Networks CN-Series vs Palo Alto Networks NG Firewalls comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Jan 25, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Fortinet FortiGate
Sponsored
Ranking in Firewalls
1st
Average Rating
8.4
Reviews Sentiment
6.9
Number of Reviews
592
Ranking in other categories
Secure Web Gateways (SWG) (2nd), Intrusion Detection and Prevention Software (IDPS) (1st), Software Defined WAN (SD-WAN) Solutions (1st), WAN Edge (1st), ZTNA (1st), Unified Threat Management (UTM) (1st)
Palo Alto Networks CN-Series
Ranking in Firewalls
33rd
Average Rating
9.6
Reviews Sentiment
7.4
Number of Reviews
2
Ranking in other categories
No ranking in other categories
Palo Alto Networks NG Firew...
Ranking in Firewalls
6th
Average Rating
8.6
Reviews Sentiment
7.1
Number of Reviews
199
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of June 2026, in the Firewalls category, the mindshare of Fortinet FortiGate is 15.1%, down from 21.7% compared to the previous year. The mindshare of Palo Alto Networks CN-Series is 0.4%, up from 0.0% compared to the previous year. The mindshare of Palo Alto Networks NG Firewalls is 5.1%, up from 3.7% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Firewalls Mindshare Distribution
ProductMindshare (%)
Fortinet FortiGate15.1%
Palo Alto Networks NG Firewalls5.1%
Palo Alto Networks CN-Series0.4%
Other79.4%
Firewalls
 

Featured Reviews

JK
IP Network Security Specialist at MTN Ghana
Process-Level CPU Visibility: Introduce detailed CPU-usage metrics per subsystem (e.g., IPS engine, logging) so administrators can quickly identify and address performance spikes.
Analytics with FortiAnalyzer. Being able to pull in logs not just from our FortiGates but from all our other firewalls and then get them in one view has been a game changer. Whether I’m building an executive dashboard or doing a deep dive forensics session, I get everything I need without navigating consoles.Straightforward Application Control. FortiGate spots and blocks unwanted apps (eq. like BitTorrent or streaming services) with accuracy. Segmentation with VDOMs. We’ve carved our data center into four logical ‘mini-firewalls’ enterprise, core, billing, and WAF—all on one box. Each has its own rules and logs, and any traffic between them still gets inspected. It’s like having multiple appliances without the extra hardware. Always-Up-to-Date Threat Feeds. Daily signature updates and AI-driven threat sensing mean we’re blocking the latest vulnerabilities almost as soon as they’re announced.
Ahmed_Shalaby - PeerSpot reviewer
Senior Cyber Security Engineer at Beta Information Technology
Application control excels and integration with monitoring system boosts efficiency
I am an integrator working with Palo Alto Networks CN-Series and Panorama. I have been involved with the implementation of Palo Alto Networks CN-Series The stability of Palo Alto Networks CN-Series is excellent. Application control is one of the most valuable features. Its monitoring capability…
Nitin Yadav - PeerSpot reviewer
Network & Security Engineer at Arrow PC Network Pvt.Ltd.
Strong threat prevention has reduced phishing and malware while I monitor traffic in depth
Palo Alto Networks NG Firewalls offers application and user awareness, which allow me to control traffic based on threats. The product includes threat prevention, advanced threat prevention, and deep packet inspection that really helps prevent issues in our network. Deep packet inspection inspects full traffic content, even inside applications and encrypted sessions. Deep packet inspection makes a very practical difference day to day because it lets me see and control what is actually inside the traffic, not just the open port or IP. I have real visibility of which application is running instead of just seeing HTTPS. Palo Alto Networks NG Firewalls WildFire sandboxing is really good at detecting and blocking zero-day malware automatically, along with its GlobalProtect and DNS security features. Using Palo Alto Networks NG Firewalls positively impacts my organization by providing strong security, better visibility, faster response, and simplified operations. After deploying Palo Alto Networks NG Firewalls in our network, it blocks malicious traffic and prevents compromises that occurred before Palo Alto Networks NG Firewalls. I can now block outside IPs to prevent issues. After Palo Alto Networks NG Firewalls installation, I reduced 60 to 70 percent of malware and phishing attacks. Its threat prevention and DNS security features detect these attacks, block malicious domains, and reduce manual efforts for the security team.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The solution is superior to Cisco in terms of security."
"With Fortinet, we're able to control how users utilize resources and pull back on certain things while allowing more access in others, which has led to fewer expenses, less time wasted addressing issues related to reporting, and more order and better analysis of exactly what is going on in the network."
"The most valuable feature of Fortinet FortiGate IPS is its efficiency."
"The solution is stable and reliable."
"We have been able to offer several services to customers in a single box."
"The pipe filter application is an outstanding feature."
"The product is very user-friendly, it is quite scalable, I love the interface, the power is great, and I have a limited embedded team in IT with one man on the team for 1,000 users who can manage all the infrastructure due to the fact that the console is very easy, and the people are very happy with the results pertaining to that interface."
"It has improved the security posture and visibility of our traffic."
"The stability of Palo Alto Networks CN-Series is excellent."
"The app inspection is very helpful for network security."
"This solution is easy to understand, reliable, and user-friendly."
"The most valuable features of Palo Alto Networks NG Firewalls are DNS sync calls, enabled security features, and Wildfire."
"The effectiveness of this technology improves with each release, bolstering confidence in the product's ability to provide robust security."
"The fact that I can perform several security functions in one device at wire speed is a valuable feature. I don't have to slow down my business transactions, and I don't have to inconvenience my users with 16 different solutions. I can have it all in one box, and it protects my organization at wire speed."
"One of the things I really like about it is that we have the same features and functions available on the entry-level device (PA-220), as do large corporations with much more costly appliances."
"The unified platform provided is very important to us as it allows us to manage all traffic and ensure security without using separate tools. It has AI and ML capabilities, which work well for real-time attack prevention."
"I like that Palo Alto does a good job of keeping the firewall updated with the latest threat signatures."
"I'm using most of its features such as antivirus, anti-spam, and WAF. I'm also using its DNS Security and DNS sinkhole features, as well as the URL filtering and application security features."
 

Cons

"The process of configuring firewall rules appears excessively complex."
"The AI with Fortinet FortiGate is not very well integrated on their devices, and their cloud infrastructure is not as good as Cisco's."
"I would like Fortinet to add more automation to FortiGate."
"We have an issue with hotel guest vouchers."
"There should be more testing before releasing software since it can be a little buggy sometimes when new features come out after updates."
"Fortinet FortiGate firewall is good, but other products like the switching part and all that fabric, in handling very audio-video traffic, sometimes it struggles on the switching part, but on the routing part, it is fine."
"Some configuration elements cannot be easily altered once created."
"I would like to have logs, monitoring, and reporting for a month without extra fees."
"Palo Alto Networks CN-Series could improve on its pricing as it is quite expensive."
"I'd like to see more IOPs features."
"I would like to see more in terms of reporting tools and the threat analysis capabilities."
"I'm thinking about a new feature. They have decryption. It's a good idea to use decryption on Palo Alto. It would be good if they had offloading of the traffic, and if they could decrypt the traffic and offload it. Like, for example, ASM on our site. We have an SSL decryption to offload the traffic. We could use that on Palo Alto."
"Palo Alto NG firewalls can be improved in support of finance and banking. We need better affiliations for profiling the user."
"When the primary Palo Alto Networks firewall fails over to the secondary, it requires manual intervention to bounce the IPsec for it to work properly. Unlike BGP peering, which automatically changes from idle to established, this process needs automation. In Cisco, there is no need to bounce the IPsec traffic during failover, and I suggest automation for Palo Alto Networks in that process."
"Palo Alto claims their NG Firewalls are highly customizable, but this isn't always true."
"Palo Alto Networks NG Firewalls technical support is very poor."
"The machine learning in Palo Alto NG Firewalls for securing networks against threats that are able to evolve and morph rapidly is good, in general. But there have been some cases where we get false positives and Palo Alto has denied traffic when there have been new updates and signature releases. Valid traffic gets blocked. We have had some bad experiences with this. If there were an ability, before it denies traffic, to get some kind of notification that some traffic is going to be blocked, that would be good."
"Everything has been great. More machine learning would be something great to see, but I don't know if it's a priority for Palo Alto."
 

Pricing and Cost Advice

"It is too expensive for us. My organization is very small, and we have a total of ten users. We have three internal users and seven external users. The FortiGate 100D series is too expensive for renewing the licenses."
"The price for the Fortinet FortiGate is reasonable. Secure SD-WAN is free of charge. If you have their firewall, it's free of charge. It's very tempting."
"Their licensing costs are annual. The UTM feature license along with their support is called FortiCare. We include that as a part of the annual maintenance cost. Palo Alto or Juniper also have an annual subscription charge for UTM. Price, of course, can always be more competitive, but it is not the most expensive product. The price-performance ratio is quite high for FortiGate."
"Before choosing a piece of equipment you have to take into account the cost-benefit offered by each one. Sometimes it is not worth paying a very cheap price to have a minimum level of security."
"It's a year based license."
"Its pricing is good. The advantages of Fortinet FortiGate over its competitors include good pricing and meeting our requirements at a lower cost."
"I do not have first-hand experience with the rice of Fortinet FortiGate, but I have heard the price was reasonable."
"The price of Fortinet FortiGate is reasonable for an SME."
Information not available
"This is an expensive product, which is why some of our customers don't adopt it."
"I am not sure about the specific licensing costs of Palo Alto Networks NG Firewalls, but FortiGate and Palo Alto are generally cheaper than some high-end Cisco devices."
"If someone doesn't have a security platform in their network, then the following licenses will be required: antivirus, anti-spyware, vulnerability, and Wildfire analysis. There are also licenses for GlobalProtect and support."
"We haven't had a problem with pricing or licensing because we consolidated other software to make Palo Alto more affordable."
"Its price can be better. Licensing is on a yearly basis."
"If you compare Palo Alto with other firewalls, it's a bit expensive."
"I would assume that it's still within mid-range given its company structure and everything else. My guess is it's still okay."
"Cost-wise, I don't see much difference in network-related costs, but this is a premium-grade firewall. There is a cost involved, and you must pay for that to get the most out of it. Its licensing costs are straightforward. There aren't any hidden costs."
report
Use our free recommendation engine to learn which Firewalls solutions are best for your needs.
902,588 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Comms Service Provider
10%
Computer Software Company
9%
Manufacturing Company
9%
Financial Services Firm
7%
No data available
Manufacturing Company
10%
Computer Software Company
9%
Financial Services Firm
9%
Comms Service Provider
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business369
Midsize Enterprise139
Large Enterprise195
No data available
By reviewers
Company SizeCount
Small Business77
Midsize Enterprise57
Large Enterprise87
 

Questions from the Community

Which is the better NGFW: Fortinet Fortigate or Cisco Firepower?
When you compare these firewalls you can identify them with different features, advantages, practices and usage a...
What is the biggest difference between Sophos XG and FortiGate?
From my experience regarding both the Sophos and FortiGate firewalls, I personally would rather use FortiGate. I know...
What are the biggest technical differences between Sophos UTM and Fortinet FortiGate?
As a solution, Sophos UTM offers a lot of functionality, it scales well, and the stability and performance are quite ...
What is your experience regarding pricing and costs for Palo Alto Networks CN-Series?
The pricing of Palo Alto Networks CN-Series is quite expensive, rating around eight on a scale of one to ten for cost.
What needs improvement with Palo Alto Networks CN-Series?
Palo Alto Networks CN-Series could improve on its pricing as it is quite expensive. The SD-WAN implementation using P...
What is your primary use case for Palo Alto Networks CN-Series?
I am an integrator working with Palo Alto Networks CN-Series ( /products/palo-alto-networks-cn-series-reviews ) and P...
What is a better choice, Azure Firewall or Palo Alto Networks NG Firewalls?
Azure Firewall Vs. Palo Alto Network NG Firewalls Both solutions provide stellar stability and security. Azure Firew...
Features comparison between Palo Alto and Fortinet firewalls
In the best tradition of these questions, Feature-wise both are quite similar, but each has things it's better at, it...
Which is better - Palo Alto Networks NG Firewalls or Sophos XG?
Palo Alto Networks NG Firewalls have both great features and performance. I like that Palo Alto has regular threat si...
 

Also Known As

Fortinet FortiGate Next-Generation Firewall
No data available
Palo Alto NGFW, Palo Alto Networks Next-Generation Firewall
 

Overview

 

Sample Customers

Amazon Web Services, Microsoft, IBM, Cisco, Dell, HP, Oracle, Verizon, AT&T, T-Mobile, Sprint, Vodafone, Orange, BT Group, Telstra, Deutsche Telekom, Comcast, Time Warner Cable, CenturyLink, NTT Communications, Tata Communications, SoftBank, China Mobile, Singtel, Telus, Rogers Communications, Bell Canada, Telkom Indonesia, Telkom South Africa, Telmex, Telia Company, Telkom Kenya
Information Not Available
SkiStar AB, Ada County, Global IT Services PSF, Southern Cross Hospitals, Verge Health, University of Portsmouth, Austrian Airlines, The Heinz Endowments
Find out what your peers are saying about Palo Alto Networks CN-Series vs. Palo Alto Networks NG Firewalls and other solutions. Updated: June 2026.
902,588 professionals have used our research since 2012.