Try our new research platform with insights from 80,000+ expert users

Check Point NGFW vs Cisco Secure Firewall comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Sep 2, 2024
 

Categories and Ranking

Fortinet FortiGate
Sponsored
Ranking in Firewalls
2nd
Average Rating
8.4
Reviews Sentiment
7.2
Number of Reviews
317
Ranking in other categories
Software Defined WAN (SD-WAN) Solutions (1st), WAN Edge (1st)
Check Point NGFW
Ranking in Firewalls
5th
Average Rating
8.8
Reviews Sentiment
7.3
Number of Reviews
306
Ranking in other categories
Unified Threat Management (UTM) (1st)
Cisco Secure Firewall
Ranking in Firewalls
6th
Average Rating
8.2
Reviews Sentiment
7.5
Number of Reviews
406
Ranking in other categories
Cisco Security Portfolio (4th)
 

Mindshare comparison

As of December 2024, in the Firewalls category, the mindshare of Fortinet FortiGate is 20.5%, up from 17.3% compared to the previous year. The mindshare of Check Point NGFW is 3.2%, down from 3.4% compared to the previous year. The mindshare of Cisco Secure Firewall is 5.8%, down from 5.9% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Firewalls
 

Featured Reviews

DineshKumar28 - PeerSpot reviewer
Effective threat prevention with responsive customer support
We are using Fortinet FortiGate as a firewall Fortinet FortiGate has been invaluable. It has helped save costs due to its various features, reliable performance, very good UI, low latency, and stability. The Threat Intel engine in Fortinet FortiGate is highly rated for its effectiveness in…
Pratik-Savla - PeerSpot reviewer
Filters internet access and controls applications
Before choosing Check Point NGFW, we used Palo Alto Networks. We switched because of issues with Palo Alto. Their customer support wasn't very responsive. Some policies weren't working right, letting things through that should've been blocked. We compared different pricing options and features before deciding on Check Point NGFW. The main differences between Palo Alto and Check Point NGFW were mostly in how they worked for us. They both offer good next-gen firewalls, but we had some problems with Palo Alto. Sometimes it wouldn't notify us quickly when something got through. Its prevention wasn't always as strong as we wanted. We felt Palo Alto's traffic inspection was only partial, not checking everything thoroughly. Check Point NGFW seemed to offer better inspection. Check Point NGFW also had better threat intel and application control. With Palo Alto, we couldn't see all our applications, only some of them. This caused shadow IT problems. Cost was also a factor in our decision.
Daniel Going - PeerSpot reviewer
Is intuitive in terms of troubleshooting, easy to consume, and stable
Licensing is complex, and I'd like it to be simplified. This is an area for improvement. If we could create a Firepower solution that became like an SD-WAN or a SASE solution in a box, then perhaps we could exploit that on remote sites. We've already kind of got that with Meraki, but if we could pull out some of the features from ASA Firepower and make those available in SD-WAN in SASE, then it would be pretty cool.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"It's great for capturing the traffic and troubleshooting it."
"The most valuable features are the policies, filtering, and configuration."
"I like Fortinet's cloud management. It allows me to manage all my devices in different branches for three cloud accounts. Even though I use on-prem devices, I can manage everything on the cloud."
"The solution is scalable."
"UTM/NGFW features and FortiCloud for logs and backups are awesome."
"The user interface (UI) is very, very good."
"Anti-Spam web content filterinG."
"The FortiGate controls the user's activities and maximizes my bandwidth use overall."
"The ability to split single hardware into multiple virtuals along with support for dynamic routing using BGP is very useful for our environment."
"In R80.10 and above, you can view logs in SmartConsole. You don't have to open another smart tracker to view logs. That is the improvement Check Point has done which makes it better because it is much easier to find logs. This saves time, approximately 40 to 50 a day in one shift."
"Its functionality is highly satisfactory."
"Check Point NGFW is popular because of the protection it offers."
"The fact that these can be separated and made in different layers provides excellent convenience for the administrators who regulate the rules."
"The most valuable feature is the powerful, deep packet inspection engine."
"It is easy to control from the central management system. For example, if we have 10 firewalls, and we want to push that same configuration among them, we can use this solution's central management system to do that simultaneously. So, there is time saving in that way. The time savings does depend on the situation. For example, if I am running half an hour of work on each firewall, that will take around 300 minutes. However, if I do this work from the central management system, then it will only take 30 minutes to push the same configuration to those same 10 devices."
"There is modern protection against current threats."
"Basic firewalling is obviously the most valuable. In addition to that, secure access and remote access are also very useful for us."
"Because of the deeper inspection it provides we have better security and sections that allow users broader access."
"The ASA 55-x range is a solid and reliable firewall. It secures the traffic for normal purposes."
"The setup was straightforward. I was happy with the configuration and deployment of the solution, as it was quick."
"I like the user interface because the navigation is very easy, straightforward on your left side pane you have all the sites that you need to browse. Unlike any other firewalls, it's pretty straightforward."
"Feature-wise, we mostly use IPS because it is a security requirement to protect against attacks from outside and inside. This is where IPS helps us out a bunch."
"We have been using a 5520 for seven years in our datacenter and we are satisfied by this version."
"The initial setup was not complex."
 

Cons

"The customization could be improved. Cisco, for example, is much better at this. They need to work to be at least as good as they are."
"FortiOS is not simple."
"They need to improve their technical support."
"It would be nice if backups could more easily migrate between different models."
"It's my understanding that more of the current generation features could be brought in. There could be more integration with EDRs, for example."
"One of the problems I was having was with user mapping, and it is an issue for which I have escalated tickets with Fortinet support."
"One issue that I have had is that sometimes I need to monitor the traffic, so I need to filter it according to the user and which user is using it the most. I experience a bottleneck most of the time, particularly at the peak time when the number of contracts and users are at maximum."
"Stability and technical support are the two major issues I have found with Fortinet."
"There needs to be advanced troubleshooting."
"One feature I have yet to see implemented is authenticated email support for alerts generated via the GW or SMS."
"One area which is still lacking is the site-to-site VPN solution."
"The interface can be more user-friendly in terms of design and the location of critical and commonly used icons."
"The solution could improve by keeping more up-to-date with technology. For example, if Amazon releases something in the security field, Check Point should have integration or adoption of this feature a bit faster than it is today. Sometimes we can hear a lot of the marketing information about an attractive feature, which we would like to have, but the feature will be released in two years. This timeframe should decrease."
"It would be great if the access management, the user management features, were improved in terms of the number of users that can be connected, and how users can access the various resources with the help of firewall authentication."
"We looked very closely at ArcSight's solution because it's a multi-vendor solution. With ArcSight we could have Check Point, we could have RSA, we could have any brand and integrate several brands, from a security point of view. With Check Point, you cannot do so, you can integrate with Check Point products."
"Pricing needs to be lowered from start, this would be more effective than lowering it during negotiations."
"Cisco Firepower NGFW Firewall can be more secure."
"It would be great to have all the data correlated to have an overview and one point of administration."
"The scalability is a bit limiting, to be honest. In terms of when you look to changing landscape in terms of threats, I think to me, my personal it's a bit limiting."
"The cloud does not precisely mimic what is on-premises."
"The throughput highlighted on the datasheet (10Gbps) should be reviewed. This throughput is only for a UDP running environment, which you will never find in the real world. Rather consider a multiprotocol throughput."
"Cisco Secure Firewall's integration with cloud providers has room for improvement. We could do more in terms of integration, for example, if we had a tag on an instance."
"The content filtering on an application level is not as good as other solutions such as Palo Alto."
"It should have packets, deep level inspections and controls, like the features which other IPS solutions used to have."
 

Pricing and Cost Advice

"Fortinet is competitive price-wise."
"It was probably about $2,500 per firewall. It was all included. It included support, services, threat management software, and 24/7 FortiCare on it. Cisco products are more expensive."
"Fortinet is reasonable in pricing and licensing. Overall, FortiGate is affordable. The licensing fee can be a little high, depending on the budget for your project."
"There is a license to use Fortinet FortiGate."
"Fortinet FortiGate as a less expensive solution than Palo Alto."
"It is affordable. Palo Alto is much more expensive than Fortinet."
"The solution requires a license annually, it is not a user license, you can have as many users as your want. I must renew the license regularly per device."
"For our organization, the licensing costs are approximately $7,000 per year."
"The pricing is high compared to competitors."
"Check Point NGFW is not a cheap solution."
"Check Point should provide some basic license for mobile access VPN by default, for at least five to ten users."
"I don't think the product's pricing is a good value. I feel it's very overpriced. I feel a lot of the features for a next gen firewall are there. But I feel it's overpriced, because of the stability issues. As far as support goes, I really can't speak to direct Check Point support, but the third-party was pretty terrible... As far as the licensing goes, it's pretty complex. If anybody was to purchase the Check Point product, definitely make sure they have an account rep come on site, and explain it line by line, what each thing is. It's not straightforward. It's very convoluted. There's no way you could just figure it out by looking at it."
"Before you buy, check which features you need, and if possible, I recommend signing up for at least a three-year license."
"They offered more features for a lower cost than competitors, and the licensing model was easy to understand."
"Check Point is a little more expensive than FortiGate."
"Check Point solutions are very expensive here. They're good, but they're expensive... Check Point is only useful for customers that have a big IT budget."
"Pricing is the same as other competitors. It is comparable. The licensing has gotten better. It has been easier with Smart Licensing."
"The pricing and licensing structure of the firewall is fair and reasonable."
"Pricing varies on the model and the features we are using. It could be anywhere from $600 to $1000 to up to $7,000 per year, depending on what model and what feature sets are available to us."
"The ROI is good. Using ASA, we have saved 10% to 20% on our costs."
"It requires additional licensing to enable 10G ports."
"The pricing for Cisco products is higher than others, but Cisco is a very good, strong, and stable technology."
"I like its licensing because you buy the license once, and it is yours. We don't have to go for a subscription. So, I liked how they licensed Cisco ASA. Our clients are also very satisfied with its licensing model."
"We bought a three-year license as a part of the enterprise agreement, which includes help with implementation and troubleshooting. We have a big data center with many applications, so implementation was not straightforward. We had to put effort into it. It wasn't an easy or straightforward implementation. The support that we got from Cisco engineers with the three-year premium license was helpful. The enterprise agreement helped to consume the licenses in a practical and faster way and streamline the implementation."
report
Use our free recommendation engine to learn which Firewalls solutions are best for your needs.
823,795 professionals have used our research since 2012.
 

Comparison Review

it_user206346 - PeerSpot reviewer
Mar 11, 2015
Cisco ASA vs. Palo Alto Networks
Cisco ASA vs. Palo Alto: Management Goodies You often have comparisons of both firewalls concerning security components. Of course, a firewall must block attacks, scan for viruses, build VPNs, etc. However, in this post I am discussing the advantages and disadvantages from both vendors concerning…
 

Top Industries

By visitors reading reviews
Educational Organization
22%
Computer Software Company
14%
Comms Service Provider
6%
Manufacturing Company
6%
Educational Organization
58%
Computer Software Company
7%
Financial Services Firm
4%
Government
3%
Educational Organization
35%
Computer Software Company
15%
Government
5%
Manufacturing Company
5%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

Which is the better NGFW: Fortinet Fortigate or Cisco Firepower?
When you compare these firewalls you can identify them with different features, advantages, practices and usage a...
What is the biggest difference between Sophos XG and FortiGate?
From my experience regarding both the Sophos and FortiGate firewalls, I personally would rather use FortiGate. I know...
What are the biggest technical differences between Sophos UTM and Fortinet FortiGate?
As a solution, Sophos UTM offers a lot of functionality, it scales well, and the stability and performance are quite ...
How does Check Point NGFW compare with Fortinet Fortigate?
I have experience on both from Disti and channel experience. Please find below my comments (nothing new as such). -Ch...
Which would you recommend - Azure Firewall or Check Point NGFW?
Azure Firewall is easy to use and provides excellent support. Valuable features include integration into the overall ...
What do you like most about Check Point NGFW?
Check Point NGFW provides essential security, featuring no-obligation access for secure connections, strong intrusion...
Which is better - Fortinet FortiGate or Cisco ASA Firewall?
One of our favorite things about Fortinet Fortigate is that you can deploy on the cloud or on premises. Fortinet Fort...
How does Cisco's ASA firewall compare with the Firepower NGFW?
It is easy to integrate Cisco ASA with other Cisco products and also other NAC solutions. When you understand the Cis...
Which is better - Meraki MX or Cisco ASA Firewall?
Cisco Adaptive Security Appliance (ASA) software is the operating software for the Cisco ASA suite. It supports netw...
 

Also Known As

FortiGate 60b, FortiGate 60c, FortiGate 80c, FortiGate 50b, FortiGate 200b, FortiGate 110c, FortiGate, Fortinet Firewall
Check Point NG Firewall, Check Point Next Generation Firewall
Cisco ASA Firewall, Cisco Adaptive Security Appliance (ASA) Firewall, Cisco ASA NGFW, Cisco ASA, Adaptive Security Appliance, ASA, Cisco Sourcefire Firewalls, Cisco ASAv, Cisco Firepower NGFW Firewall
 

Overview

 

Sample Customers

Amazon Web Services, Microsoft, IBM, Cisco, Dell, HP, Oracle, Verizon, AT&T, T-Mobile, Sprint, Vodafone, Orange, BT Group, Telstra, Deutsche Telekom, Comcast, Time Warner Cable, CenturyLink, NTT Communications, Tata Communications, SoftBank, China Mobile, Singtel, Telus, Rogers Communications, Bell Canada, Telkom Indonesia, Telkom South Africa, Telmex, Telia Company, Telkom Kenya
Control Southern, Optimal Media
There are more than one million Adaptive Security Appliances deployed globally. Top customers include First American Financial Corp., Genzyme, Frankfurt Airport, Hansgrohe SE, Rio Olympics, The French Laundry, Rackspace, and City of Tomorrow.
Find out what your peers are saying about Check Point NGFW vs. Cisco Secure Firewall and other solutions. Updated: December 2024.
823,795 professionals have used our research since 2012.