No more typing reviews! Try our Samantha, our new voice AI agent.

Palo Alto Networks PA-Series vs Stormshield Network Security comparison

Sponsored
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Fortinet FortiGate
Sponsored
Average Rating
8.4
Reviews Sentiment
6.9
Number of Reviews
592
Ranking in other categories
Secure Web Gateways (SWG) (2nd), Firewalls (1st), Intrusion Detection and Prevention Software (IDPS) (1st), Software Defined WAN (SD-WAN) Solutions (1st), WAN Edge (1st), ZTNA (1st), Unified Threat Management (UTM) (1st)
Palo Alto Networks PA-Series
Average Rating
8.6
Reviews Sentiment
7.0
Number of Reviews
37
Ranking in other categories
Firewalls (20th)
Stormshield Network Security
Average Rating
7.8
Reviews Sentiment
5.4
Number of Reviews
18
Ranking in other categories
Unified Threat Management (UTM) (14th)
 

Featured Reviews

JK
IP Network Security Specialist at MTN Ghana
Process-Level CPU Visibility: Introduce detailed CPU-usage metrics per subsystem (e.g., IPS engine, logging) so administrators can quickly identify and address performance spikes.
Analytics with FortiAnalyzer. Being able to pull in logs not just from our FortiGates but from all our other firewalls and then get them in one view has been a game changer. Whether I’m building an executive dashboard or doing a deep dive forensics session, I get everything I need without navigating consoles.Straightforward Application Control. FortiGate spots and blocks unwanted apps (eq. like BitTorrent or streaming services) with accuracy. Segmentation with VDOMs. We’ve carved our data center into four logical ‘mini-firewalls’ enterprise, core, billing, and WAF—all on one box. Each has its own rules and logs, and any traffic between them still gets inspected. It’s like having multiple appliances without the extra hardware. Always-Up-to-Date Threat Feeds. Daily signature updates and AI-driven threat sensing mean we’re blocking the latest vulnerabilities almost as soon as they’re announced.
Rohit Ghorpade - PeerSpot reviewer
Cloud Network Engineer at a insurance company with 5,001-10,000 employees
Identity-based perimeter control has improved security and supports reliable remote access
Currently, we are working with vendors such as Palo Alto Networks PA-Series, Cisco, Check Point, and Citrix. Palo Alto Networks PA-Series is a better firewall. Deep packet inspection and threat prevention basically comply with whatever traffic is incoming and outgoing through the firewall. I do not think anything improvement is required. The thing is that Palo Alto Networks PA-Series works mostly on a license-based model. If you want to utilize any feature, you have to purchase the license. For example, URL filtering requires a license purchase. It simplifies the implementation because LDAP server profile can be integrated. Basically, that simplifies the implementation of access rule or security policy.
Zsolt Jónás - PeerSpot reviewer
System Administrator at NaxoNet
Advanced GUI and layered security have supported compliance and simplified intrusion prevention
I haven't had a task that I couldn't solve with Stormshield Network Security. The active-active high availability solution would be beneficial because currently, if you build a high availability solution with Stormshield Network Security, you have a main device and another one is a backup device. The HA can switch between them, but it would be good to have a master-master solution, not just a master-slave one. I could set a URL that I can call to update the DNS record. Currently, Stormshield Network Security devices support DynDNS, which is not a usual feature request from a server environment. I have my own solution instead of DynDNS because I don't prefer it, so I have my own service for that. However, the GUI does not support using a custom service instead of DynDNS. I had to solve it in the console on Stormshield Network Security device, but it would be much better if it was reachable on the GUI. I had to figure out a trick for the IPsec configuration. In the IPsec config, we have to provide the remote side's IP address, but it's always changing. This means that an office, for example a company that has an office but without a fixed IP address, cannot be used with IPsec VPN.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The low cost of ownership was a benefit with all of the features we wanted."
"User identification and application identification are valuable features."
"The best features of Fortinet FortiGate are the integration of SD-WAN capabilities with Fortinet Unified SASE."
"Customers are more inclined towards FortiGate because of application control, web filtering, and anti-spam features. The support from the FortiGate team is good, and price-wise, it is affordable."
"It is a good source for firewall protection."
"User-friendly and affordable security solution that's recommended for SMB customers. This solution has good technical support."
"Fortinet FortiGate is the best option on the market when it comes to firewalls."
"This firewall is an antivirus, protects against spam, and is an IPS."
"A valuable feature that we can consider is the deployment time, which is significantly reduced. It is almost 90% faster compared to other solutions."
"Palo Alto Networks PA-Series is basically integrated with LDAP to fetch the identity of the users and we provide access based on the identity."
"The solution is easy to manage."
"The documentation is great."
"When I compare the tool with other firewalls, it’s the most powerful. It's the most powerful security engine. All the traffic going to the Internet passes through it as the first layer of protection. Because of its good performance, we also use it for decryption."
"A valuable feature that we can consider is the deployment time, which is significantly reduced, almost 90% faster compared to other solutions. This leads to quicker deployment and less downtime."
"The cloud-based aspect helps significantly. It integrates seamlessly with other Palo products like Prisma Cloud, offers robust VPN protection, and it's all in one convenient package."
"The best features of the Palo Alto Networks PA-Series firewall include Global protector VPN workings, and content filtering is easy to manage and operate."
"The multi-layered security approach of Stormshield Network Security is a good one and has helped with compliance."
"Ease of use is the best feature of the product."
"The scalability of the solution is good."
"The features I find most valuable is the backup inspection, the filtering, and the load balancing, and I am also impressed by the antivirus feature that gives us two controls over the viruses - one is from the parameter and one on the endpoint."
"It's an easy, straightforward management platform to use."
"Easily manageable in a variety of environments."
"Stormshield Network Security is a very stable solution and the solution works perfectly so we never had to contact technical support."
"The most valuable features are the IPS, the firewall function, and the price."
 

Cons

"Palo Alto has a feature called WildFire Analysis that is unavailable in FortiGate. WildFire is better than a sandbox because it can address zero-day threats and vulnerabilities. It can immediately identify zero-day threats from the cloud."
"The configuration option availability is not 100% from the website of the FortiGate web management site."
"I could not configure sFlow from the FortiGate graphical user interface. I realized that the sFlow configuration is available only from the CLI, and discovered that sFlow is not supported on virtual interfaces, such as VDOM links, IPsec, or GRE."
"The cloud features can be improved."
"They have recently acquired a CNAP solution which should be integrated into FortiGate boxes natively for protection at any application layer. Since Fortinet FortiGate has Layer 7 protection, they should integrate that as soon as they can for threat detection and network detection."
"There are mainly two areas of improvement in Fortinet FortiGate— the licensing cost and the timing of upgrading licenses for boxes."
"It is somewhat expensive compared to other solutions such as Sophos."
"FortiGate is a complete solution, but it is very expensive compared with other solutions."
"The SD-WAN feature of Palo Alto Networks is not good compared to FortiGate."
"There seem to be some issues with TAC (Technical Assistance Center) or Palo Alto support. Anytime you open a case, a level one engineer joins, and then you have to escalate it to level two or three. The support system has changed in the past few years, and that's something they need to look into."
"Compared to other vendors, the solution's community should be strong enough to solve the problems engineers face."
"Pricing flexibility could be an aspect worth considering, as it has been a concern for some of our clients."
"With Palo Alto Networks PA-Series, I find that the support team takes a long time to resolve the issues that a user may face during the use of the product."
"The solution's licensing price could be improved."
"Currently, they are not protected with any data security when they work from home or outside the network. They surf the Internet directly and should implement a proxy or firewall to monitor the data between the endpoint and the internet."
"The interface is complex."
"This solution has a big problem with web filtering and it needs to be improved."
"I don’t recommend this product at all."
"The biggest issue was their support department was not able to help us, then everything stops. This is a no-go area for me."
"The technical support for this solution in Poland is not good."
"The pricing is increasing, and I would say it is a bit expensive."
"The pricing of this solution needs to be decreased."
"The filtering configuration could be better. We have some difficulties with the filtering configuration and the filter extension."
"Support is always an issue because they're constantly busy."
 

Pricing and Cost Advice

"The price is relatively expensive compared to other solutions which are providing similar features."
"FortiGate Next Generation Firewall is a very cheap solution."
"The pricing is based on a licensing model for each IPS in your environment."
"In the Asian economy in which we operate, FortiGate is expensive."
"When comparing this solution to others, I would rate it a ten out of ten in terms of pricing. However, the issue of requiring a separate license for redundancy is a drawback, and I would rate it a nine out of ten."
"The license of Fortinet FortiGate should be reduced."
"There is an annual license to use this solution. The prices have been increasing over the years."
"The price is highly competitive when compared to other brands that offer similar functionality."
"From my perspective, managing the price is important, especially because we're a small business. For larger organizations like Barclays, we provide our requirements to the client, and they place the order on BigFix. It's their responsibility to consider their budget and make decisions accordingly. We appreciate the features we get, but the cost-sharing still depends on the client."
"The tool's pricing was reasonable when we bought the product. We pay around 60,000 dollars per year."
"From my perspective, managing the price is important, especially because we're a small business. For larger organizations like Barclays, we provide our requirements to the client, and they place the order on BigFix. It's their responsibility to consider their budget and make decisions accordingly. We appreciate the features we get, but the cost-sharing still depends on the client."
"The product is offered to users at high prices compared to the pricing model of the other vendors in the market."
"The cost varies depending on the device model, with entry-level firewalls priced around $1,300 to $1,500, while higher-end models can reach prices of several hundred thousand dollars."
"It is a very expensive solution."
"Compared to other vendors, Palo Alto Networks PA-Series is expensive."
"The pricing is a bit on the higher side."
"For mid-sized companies, they sell their appliances for good prices."
"The price of this solution and the price of support are ok."
"The pricing could be better."
"The SN200 series costs between $500 USD and $600 USD per year, whereas the SN700 series costs approximately $1,000 annually."
"We chose Stormshield for its price, as the Azure firewall was too expensive."
"We bought a three-year license, and we renew it whenever it expires. The price could be better. It's always very expensive."
"I think the price is good."
report
Use our free recommendation engine to learn which Firewalls solutions are best for your needs.
902,495 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Comms Service Provider
10%
Computer Software Company
9%
Manufacturing Company
9%
Financial Services Firm
7%
Comms Service Provider
9%
Computer Software Company
8%
Government
8%
Manufacturing Company
8%
Comms Service Provider
16%
Manufacturing Company
12%
Computer Software Company
9%
Construction Company
9%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business369
Midsize Enterprise139
Large Enterprise195
By reviewers
Company SizeCount
Small Business14
Midsize Enterprise6
Large Enterprise17
By reviewers
Company SizeCount
Small Business11
Midsize Enterprise5
Large Enterprise2
 

Questions from the Community

Which is the better NGFW: Fortinet Fortigate or Cisco Firepower?
When you compare these firewalls you can identify them with different features, advantages, practices and usage a...
What is the biggest difference between Sophos XG and FortiGate?
From my experience regarding both the Sophos and FortiGate firewalls, I personally would rather use FortiGate. I know...
What are the biggest technical differences between Sophos UTM and Fortinet FortiGate?
As a solution, Sophos UTM offers a lot of functionality, it scales well, and the stability and performance are quite ...
What is your experience regarding pricing and costs for Palo Alto Networks PA-Series?
If we look at the features, then the price is good, but they do charge for the GlobalProtect VPNs. Overall, the prici...
What needs improvement with Palo Alto Networks PA-Series?
There is room for improvement in Palo Alto Networks PA-Series in the areas where they can minimize applications and i...
What is your primary use case for Palo Alto Networks PA-Series?
I am using Palo Alto Networks PA-Series to ensure protection and cybersecurity by preventing and implementing network...
What needs improvement with Stormshield Network Security?
I haven't had a task that I couldn't solve with Stormshield Network Security. The active-active high availability sol...
What is your primary use case for Stormshield Network Security?
I already use Stormshield Network Security, and I am now looking for a new solution. I am already working with Storms...
What advice do you have for others considering Stormshield Network Security?
The pricing is increasing, and I would say it is a bit expensive. Palo Alto and others are much more expensive, but S...
 

Also Known As

Fortinet FortiGate Next-Generation Firewall
No data available
NETASQ Firewalls
 

Overview

 

Sample Customers

Amazon Web Services, Microsoft, IBM, Cisco, Dell, HP, Oracle, Verizon, AT&T, T-Mobile, Sprint, Vodafone, Orange, BT Group, Telstra, Deutsche Telekom, Comcast, Time Warner Cable, CenturyLink, NTT Communications, Tata Communications, SoftBank, China Mobile, Singtel, Telus, Rogers Communications, Bell Canada, Telkom Indonesia, Telkom South Africa, Telmex, Telia Company, Telkom Kenya
Information Not Available
ACESUR group, Ministry of Education Oman, Anios Laboratories, Zain, DLM Location
Find out what your peers are saying about Fortinet, Netgate, Sophos and others in Firewalls. Updated: May 2026.
902,495 professionals have used our research since 2012.