Erik Flores - PeerSpot reviewer
  • 10
  • 114

How do I convince a client that the most expensive firewall is not necessarily the best?

Hi community,

What can I do to show a client that buying the most important doesn't mean that it's the best option? 

For example, how do I demonstrate this with Fortinet FortiGate vs Cisco ASA Firewall?

PeerSpot user
11 Answers
Business Owner at Anyshape
Real User
Sep 14, 2021

Meh... Both of them are very VERY overrated!!!... Nothing more frustrating than a client with Google.... 

Product comparison that may be of interest to you
Networking Specialist at a healthcare company with 1,001-5,000 employees
Real User
Top 5
Sep 15, 2021

A firewall is something very personal, depend on the company, the kind of traffic, for example, a hospital doesn't need the same features as a university. One needs to implement DLP and another organization doesn't have this need. 

The same with web filtering, AV, ...

IT Manager at a legal firm with 11-50 employees
Real User
Top 10
Sep 15, 2021

You have to fetch case studies to convince the client technically (bitter truth, whatever is successful has its cost).  

Now the new era began - NGFW comes to the picture AI/ML-based only data sheets, then case studies only the key  

Every security appliance has its own cons and pros  (my observations only. 

Advanced Technology Executive with 1,001-5,000 employees
Sep 14, 2021

I'd use Gartner Magic Quadrant's leaders, other competitve data, references. 

Look at attack data. Leaders are Palo Alto, Fortinet, Checkpoint... some things to look at.

CEO at a computer software company with 1-10 employees
Real User
Sep 14, 2021

Unfortunately, many clients today are of that opinion, and much of it is due to Marketing strategies and the stories provided by each of the product's manufacturers. 

However, that said, often, the most expensive product sometimes is the better product, but not necessarily the best to meet the requirements of the customer. 

Do your proper analysis and be prepared to show your customer why you are choosing the option you have. Explain why your team has chosen the one you have, and not the more expensive option. Far too often, we find that the customer feels the option we are presenting is too high a cost, even if it is not close to the price of the most expensive, and we simply remind them, they are not buying a router, they are purchasing a security appliance, and therefore it is a very good investment in their system's security, they do not require some of the features or benefits offered by the most expensive product, so you have made the best suggestion to take care of them at a fair price.    

If you can honestly recommend a product, you probably use it in your own operation, so remember to advise the customer of that.

SE at a comms service provider with 11-50 employees
Real User
Top 10
Sep 13, 2021

How do I convince a client that the most expensive firewall is not necessarily the best? --> don't waste your time. 

In the client's eyes, you are not a trusted advisor. If you can manage both, just let them take the risk.

Find out what your peers are saying about Cisco Secure Firewall vs. Fortinet FortiGate and other solutions. Updated: January 2023.
670,331 professionals have used our research since 2012.
Supervisor of IT Infrastructure & Cybersecurity at a comms service provider with 51-200 employees
Top 5Leaderboard
Jan 14, 2021

If you have a client that knows what a Fortigate and an ASA are you have a good client.

There are a couple strategies I would recommend. First show them market share of each product. Then explain the origin story of Fortinet. Then I would explain the fact that the security of any device is greatly dependent on the skills of the team managing it and that Fortigate is your teams security stack leader for security appliances and they are most familiar with them and find them a better overall solution.

Of course at the end of the day the final decision is the clients but price margin is all your decision. I've managed both devices and while I agree that Fortigate is a better solution I would be fine deploying either if a client felt strong about it. Hope that helps.

Principal at a tech services company with 1-10 employees
Real User
Jan 15, 2021

My clients are all very small, and pfSense works great for them. Other than past experience with ASA being difficult to configure without deep knowledge of the product, I don't know these products. Google Fortinet FortiGate and Cisco ASA came up with some interesting articles. The first on that list https://info.pivitglobal.com/r... makes FortiGate look pretty good.

Solutions Architect at Controles Empresariales
Top 10
Jan 13, 2021

Although it may seem simple to say, quality is price-related, but an expensive product is an expensive product and a quality product is a quality product.

Quality products are usually more expensive because they are related to the one who produces them, they are few people, more exclusive.

Expensive products are those for which a price is charged that does not meet the quality offered by some of the others for a lower price.

In short, there is no expensive or quality product, this is reflected in the needs they cover, if it is good product, because it covers my needs, it is an expensive product, even if its price is low.

You won't believe it, but this doesn't always happen, the cheap comes out expensive in the end.

‎Director Of Information Technology with 201-500 employees
Jan 13, 2021

Cisco makes great gear, but I hate Smartnet costs as a budget manager. Cisco is actively abandoning the ASA line of hardware. It was not their most successful product with an assortment of issues. 

We gave up on our 5510 and 12's long ago after bad updates and hardware failures forced us to change. 

We are now using Fortigate 200F's with no issues whatsoever. This was not a difficult choice for us.

Principal Network Engineer at a manufacturing company with 501-1,000 employees
Real User
Jan 15, 2021

Netsecopen.org and gartner quadrant

Related Questions
User at PT. Manunggal Integrasi Sejahtera
Jan 27, 2023
Hello peers,  I work at a small tech company and am researching firewalls. Which solution do you prefer: Juniper SRX4200 or FortiGate 1800? Can you please compare the two solutions? Thank you for your help.
See 1 answer
Technical Specialist - Head of Presales at Artha Mitra Interdata
Jan 27, 2023
Hi Fahrorozi,If I have to choose between these two, I will choose FG 1800Reasons:1. More flexible ports to use from 1G to 40G2. Include SSL VPN / client VPN for users3. Have better Web management than SRX.4. From datasheet some of the throughput also larger (IPv4 FW throughput, Max Session, Max Policies, etc)But you need to know what you need for your company.- Maybe you only need 10G interface instead of 1G- Maybe you dont need the SSL VPN / Client VPN- You also don't need a large throughput.Hope this help.
Guillermo Read - PeerSpot reviewer
Advisory Engineer - Telecommunications Solution Design at Claro RD
Jan 20, 2023
Hello community, I am an Advisory Engineer at a large comms services company. I am currently researching Fortinet's firewall solutions. Which Fortinet firewall model is the equivalent of Sophos XG 450? Thank you for your help.
2 out of 3 answers
Director at REDCO
Jan 20, 2023
According to the datasheet, it can be the 400F, but I almost think that with 200F it can work without a problem, the detail is that XG is the previous generation. At the moment, they are the XGS of SOPHOS.
William Yragui - PeerSpot reviewer
President at infobond
Jan 20, 2023
The XG 450 supports 2 10Gb SFP+ slots and 8 GE ports. A Fortinet FG200F supports 4 10Gb SFP+ slots, 8 GE SFP slots, and 18 GE ports. A Fortinet FG400F supports 8 10Gb SFP+ slots, 8 GE SFP slots, and 18 GE ports. Barebones the Sophos XV 450 carries a list price of $11,823, whereas an FG200F costs $5,544, and the FG400F, $11,523.  What I look for is the ability of a firewall to decrypt SSL sessions. Given that 80% or more of your network traffic will be encrypted, the firewall has to be able to decrypt packets to find malware. The Sophos XG 450 can inspect 770 Mbps of SSL traffic. The FG200F will inspect 4 Gbps and the FG400F will inspect 8 Gbps of SSL traffic. The Sophos XG 450 has a threat protection throughput of 3.4 Gbps whereas the FG200F datasheet states 3.5 Gbps and the FG400F,  has 9 Gbps of threat protection throughput.
Product Comparisons
Download Free Report
Download our FREE report comparing Cisco Secure Firewall and Fortinet FortiGate based on reviews, features, and more! Updated: January 2023.
670,331 professionals have used our research since 2012.