No more typing reviews! Try our Samantha, our new voice AI agent.

Palo Alto Networks NG Firewalls vs Stormshield Network Security comparison

Sponsored
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Fortinet FortiGate
Sponsored
Average Rating
8.4
Reviews Sentiment
6.9
Number of Reviews
592
Ranking in other categories
Secure Web Gateways (SWG) (2nd), Firewalls (1st), Intrusion Detection and Prevention Software (IDPS) (1st), Software Defined WAN (SD-WAN) Solutions (1st), WAN Edge (1st), ZTNA (1st), Unified Threat Management (UTM) (1st)
Palo Alto Networks NG Firew...
Average Rating
8.6
Reviews Sentiment
7.1
Number of Reviews
199
Ranking in other categories
Firewalls (6th)
Stormshield Network Security
Average Rating
7.8
Reviews Sentiment
5.4
Number of Reviews
18
Ranking in other categories
Unified Threat Management (UTM) (14th)
 

Featured Reviews

JK
IP Network Security Specialist at MTN Ghana
Process-Level CPU Visibility: Introduce detailed CPU-usage metrics per subsystem (e.g., IPS engine, logging) so administrators can quickly identify and address performance spikes.
Analytics with FortiAnalyzer. Being able to pull in logs not just from our FortiGates but from all our other firewalls and then get them in one view has been a game changer. Whether I’m building an executive dashboard or doing a deep dive forensics session, I get everything I need without navigating consoles.Straightforward Application Control. FortiGate spots and blocks unwanted apps (eq. like BitTorrent or streaming services) with accuracy. Segmentation with VDOMs. We’ve carved our data center into four logical ‘mini-firewalls’ enterprise, core, billing, and WAF—all on one box. Each has its own rules and logs, and any traffic between them still gets inspected. It’s like having multiple appliances without the extra hardware. Always-Up-to-Date Threat Feeds. Daily signature updates and AI-driven threat sensing mean we’re blocking the latest vulnerabilities almost as soon as they’re announced.
Nitin Yadav - PeerSpot reviewer
Network & Security Engineer at Arrow PC Network Pvt.Ltd.
Strong threat prevention has reduced phishing and malware while I monitor traffic in depth
Palo Alto Networks NG Firewalls offers application and user awareness, which allow me to control traffic based on threats. The product includes threat prevention, advanced threat prevention, and deep packet inspection that really helps prevent issues in our network. Deep packet inspection inspects full traffic content, even inside applications and encrypted sessions. Deep packet inspection makes a very practical difference day to day because it lets me see and control what is actually inside the traffic, not just the open port or IP. I have real visibility of which application is running instead of just seeing HTTPS. Palo Alto Networks NG Firewalls WildFire sandboxing is really good at detecting and blocking zero-day malware automatically, along with its GlobalProtect and DNS security features. Using Palo Alto Networks NG Firewalls positively impacts my organization by providing strong security, better visibility, faster response, and simplified operations. After deploying Palo Alto Networks NG Firewalls in our network, it blocks malicious traffic and prevents compromises that occurred before Palo Alto Networks NG Firewalls. I can now block outside IPs to prevent issues. After Palo Alto Networks NG Firewalls installation, I reduced 60 to 70 percent of malware and phishing attacks. Its threat prevention and DNS security features detect these attacks, block malicious domains, and reduce manual efforts for the security team.
Zsolt Jónás - PeerSpot reviewer
System Administrator at NaxoNet
Advanced GUI and layered security have supported compliance and simplified intrusion prevention
I haven't had a task that I couldn't solve with Stormshield Network Security. The active-active high availability solution would be beneficial because currently, if you build a high availability solution with Stormshield Network Security, you have a main device and another one is a backup device. The HA can switch between them, but it would be good to have a master-master solution, not just a master-slave one. I could set a URL that I can call to update the DNS record. Currently, Stormshield Network Security devices support DynDNS, which is not a usual feature request from a server environment. I have my own solution instead of DynDNS because I don't prefer it, so I have my own service for that. However, the GUI does not support using a custom service instead of DynDNS. I had to solve it in the console on Stormshield Network Security device, but it would be much better if it was reachable on the GUI. I had to figure out a trick for the IPsec configuration. In the IPsec config, we have to provide the remote side's IP address, but it's always changing. This means that an office, for example a company that has an office but without a fixed IP address, cannot be used with IPsec VPN.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The solution effectively controls browsing traffic."
"Fortinet FortiGate IPS has helped increase the efficiency of our network operations and we are experiencing fewer queries in the network and security domain."
"The web controls are what I appreciate about Fortinet FortiGate. We have extensive controls over areas where we could block external-facing IPs, external URLs. We can do geo-fencing with the firewalls, which is a good feature."
"It's an easy solution to set up."
"On a scale of one to ten, I rate this solution 10 out of 10."
"We are very well satisfied with the Fortinet technical support."
"The customers have seen an ROI from using Fortinet FortiGate and they are satisfied with the solution."
"You don't need to reinvent the wheel, as FortiGate is the best solution."
"In general, its performance and ease of use are the most valuable; its performance is good, stable, and reliable, and the user interface is friendly and easy to use, so customers find it easy to work with and easy to learn."
"The trackability is most valuable. When a port is open for a protocol, such as port 443 for HTTPS, it can look inside the traffic and identify or verify the applications that are using the port, which was previously not possible with traditional firewalls."
"The most valuable features of this solution are all of the services it provides."
"One of the things I really like about it is that we have the same features and functions available on the entry-level device (PA-220), as do large corporations with much more costly appliances."
"The most important feature is the firewall. We can make rules to filter the application layer of traffic. It's a very helpful feature."
"The stability is fire and forget; you don't have to worry about it."
"The most valuable feature of Palo Alto Networks NG Firewalls is its application visibility, which allows us to see all users and their accessed resources."
"We reduced access to unwanted websites by 80%, optimized user efficiency by restricting nonessential social media features, and now get all the security, monitoring, and wireless detection we need from a single Palo Alto platform instead of managing five to seven separate tools."
"The StormShield solution has enabled us to fully implement best practices from Microsoft in the cloud : the hub and spoke architecture."
"Fortinet, Dell SonicWall and Check Point because these products offer a wide range of features that are not available with Netasq."
"The scalability of the solution is good."
"The most valuable features are the IPS, the firewall function, and the price."
"I like that it works fine. Stormshield is a very good solution."
"The solution has improved my organization because I can see what traffic is happening and I can use it to block and prevent attacks."
"A very robust product."
"The multi-layered security approach of Stormshield Network Security is a good one and has helped with compliance."
 

Cons

"There should be some open-source training or free training for decision makers, or some webinars should be available. These would help understand the new product line and the existing product line features."
"Its reporting can be improved. Sometimes, I don't get proper reports."
"The things we require are already sorted out, so there isn't any scope for improvement as far as our requirements go. However, its price can be better."
"The web process often has a memory leak."
"Two-way inspections are not possible in FortiGate."
"Monitoring could be improved."
"Fortinet renewal prices for all models are too high, so they should offer discounts for customers on renewal."
"There are no areas that need improvement at this point in time."
"There is a tradeoff between security and network performance, as security is always top-notch, but performance can sometimes lag and has room for improvement."
"The pricing of the solution is quite high. It's one of the most expensive firewall solutions on the market."
"It would be better to have more tools to control Palo Alto Networks NG Firewalls. We don't have too many tools to access Palo Alto. For example, the IT team doesn't have access to it. We can see it physically and see if it's running or not. We need to contact a special team to receive that information. I would also like to see more reporting in the next release."
"The configuration framework for Palo Alto Networks Next-Generation firewalls should be simplified, particularly for applications like ASG authentication. Technical support needs improvement, as issue resolution takes a significant amount of time."
"The biggest thing that needs to be improved with them is their training."
"In the last three years at least, they have been lagging behind their competitors. The main issue is the support that we can get... You have to wait for them to get back to you and sometimes it's random. And the biggest problem I have is that you have to wait hours on the line when you're calling them to get a hold of the next available engineer."
"Currently, they don't have email protection. They can maybe add it in the future. Currently, if you want to do so, you need to go with another solution."
"When you delete and add a new rule, because of the one hundred rule limit, if the new rule has an ID that is greater than one hundred, even though you have fewer than that, it will not work."
"A more user-friendly interface would be helpful."
"It could be better if it were more user-friendly. It's too complicated for us to use it. The price could be better as well."
"An application firewall like other next generation firewalls have."
"The product must improve its pricing."
"The filtering configuration could be better. We have some difficulties with the filtering configuration and the filter extension."
"It could be better if it were more user-friendly for us as we dont use it very often even if we never had problems to modify setup when needed."
"Being more cost effective. I went with a pair of Watchguard M300 recently when buying a new firewall cluster for our own use because it was way cheaper than NetASQ/Stormshield N700 while being faster, and it offers true multi-master firewall clustering if needed."
"This is not a next-generation firewall."
 

Pricing and Cost Advice

"It is very cost-effective. You get features similar to other firewalls, such as Palo Alto, but at a lower price."
"It is less expensive than a Cisco solution."
"As far as I'm aware, in our case, it's just a yearly pricing arrangement with no additional licensing costs."
"The price of Fortinet FortiGate is better than Cisco, Check Point, and Palo Alto. In terms of pricing, it's probably a better-priced firewall solution overall."
"The setup cost was good. The Egyptian pound is declining, and upgrading Fortinet FortiGate yearly costs about $2000 USD, which equals one hundred Egyptian pounds. I maintain a business relationship with the vendor and receive support from them."
"Fortinet FortiGate is reasonably priced."
"The pricing is flexible."
"The product is expensive."
"Palo Alto Networks NG Firewalls are expensive compared to WatchGuard XTM firewalls."
"It can be quite expensive, but there's a good incentive for the three-year contracts. The part that is especially confusing is for the virtual environment. The credits or the licensing system can be very confusing."
"Palo Alto is a more expensive firewall solution than others."
"The licensing leaves a lot to be desired. We buy the license and then we can't transfer the license without paying an exorbitant fee to our client if they leave us, and that just seems to be a bit of a pain point for us, and there's really no way to partner effectively to make that more reasonable."
"It is a little bit expensive than other firewalls, but it is worth every penny. There are different licenses for the kinds of services you want to use. When we buy a new product, we go for a three-year subscription."
"The pricing is straightforward with no hidden costs."
"Palo Alto Networks NG Firewalls are overpriced."
"Its price is comparable to other companies. The license is on a one-year or three-year basis. It depends on the customers what they want to go for. There are some features that require an additional license, and there is also the cost of the support."
"The pricing could be better."
"For mid-sized companies, they sell their appliances for good prices."
"The price of this solution and the price of support are ok."
"We chose Stormshield for its price, as the Azure firewall was too expensive."
"We bought a three-year license, and we renew it whenever it expires. The price could be better. It's always very expensive."
"The SN200 series costs between $500 USD and $600 USD per year, whereas the SN700 series costs approximately $1,000 annually."
"I think the price is good."
report
Use our free recommendation engine to learn which Firewalls solutions are best for your needs.
902,495 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Comms Service Provider
10%
Computer Software Company
9%
Manufacturing Company
9%
Financial Services Firm
7%
Manufacturing Company
10%
Computer Software Company
9%
Financial Services Firm
9%
Comms Service Provider
6%
Comms Service Provider
16%
Manufacturing Company
12%
Computer Software Company
9%
Construction Company
9%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business369
Midsize Enterprise139
Large Enterprise195
By reviewers
Company SizeCount
Small Business77
Midsize Enterprise57
Large Enterprise87
By reviewers
Company SizeCount
Small Business11
Midsize Enterprise5
Large Enterprise2
 

Questions from the Community

Which is the better NGFW: Fortinet Fortigate or Cisco Firepower?
When you compare these firewalls you can identify them with different features, advantages, practices and usage a...
What is the biggest difference between Sophos XG and FortiGate?
From my experience regarding both the Sophos and FortiGate firewalls, I personally would rather use FortiGate. I know...
What are the biggest technical differences between Sophos UTM and Fortinet FortiGate?
As a solution, Sophos UTM offers a lot of functionality, it scales well, and the stability and performance are quite ...
What is a better choice, Azure Firewall or Palo Alto Networks NG Firewalls?
Azure Firewall Vs. Palo Alto Network NG Firewalls Both solutions provide stellar stability and security. Azure Firew...
Features comparison between Palo Alto and Fortinet firewalls
In the best tradition of these questions, Feature-wise both are quite similar, but each has things it's better at, it...
Which is better - Palo Alto Networks NG Firewalls or Sophos XG?
Palo Alto Networks NG Firewalls have both great features and performance. I like that Palo Alto has regular threat si...
What needs improvement with Stormshield Network Security?
I haven't had a task that I couldn't solve with Stormshield Network Security. The active-active high availability sol...
What is your primary use case for Stormshield Network Security?
I already use Stormshield Network Security, and I am now looking for a new solution. I am already working with Storms...
What advice do you have for others considering Stormshield Network Security?
The pricing is increasing, and I would say it is a bit expensive. Palo Alto and others are much more expensive, but S...
 

Also Known As

Fortinet FortiGate Next-Generation Firewall
Palo Alto NGFW, Palo Alto Networks Next-Generation Firewall
NETASQ Firewalls
 

Overview

 

Sample Customers

Amazon Web Services, Microsoft, IBM, Cisco, Dell, HP, Oracle, Verizon, AT&T, T-Mobile, Sprint, Vodafone, Orange, BT Group, Telstra, Deutsche Telekom, Comcast, Time Warner Cable, CenturyLink, NTT Communications, Tata Communications, SoftBank, China Mobile, Singtel, Telus, Rogers Communications, Bell Canada, Telkom Indonesia, Telkom South Africa, Telmex, Telia Company, Telkom Kenya
SkiStar AB, Ada County, Global IT Services PSF, Southern Cross Hospitals, Verge Health, University of Portsmouth, Austrian Airlines, The Heinz Endowments
ACESUR group, Ministry of Education Oman, Anios Laboratories, Zain, DLM Location
Find out what your peers are saying about Fortinet, Netgate, Sophos and others in Firewalls. Updated: May 2026.
902,495 professionals have used our research since 2012.