Try our new research platform with insights from 80,000+ expert users

Check Point NGFW vs Zscaler Cloud Firewall comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Jul 13, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Fortinet FortiGate
Sponsored
Ranking in Firewalls
2nd
Average Rating
8.4
Reviews Sentiment
7.0
Number of Reviews
396
Ranking in other categories
Software Defined WAN (SD-WAN) Solutions (1st), WAN Edge (1st)
Check Point NGFW
Ranking in Firewalls
5th
Average Rating
8.8
Reviews Sentiment
7.4
Number of Reviews
324
Ranking in other categories
Unified Threat Management (UTM) (1st)
Zscaler Cloud Firewall
Ranking in Firewalls
25th
Average Rating
8.2
Reviews Sentiment
8.0
Number of Reviews
18
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of July 2025, in the Firewalls category, the mindshare of Fortinet FortiGate is 21.2%, up from 17.7% compared to the previous year. The mindshare of Check Point NGFW is 3.0%, down from 3.2% compared to the previous year. The mindshare of Zscaler Cloud Firewall is 0.4%, up from 0.3% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Firewalls
 

Featured Reviews

Vasu Gala - PeerSpot reviewer
A stable solution with an intuitive interface and quick customer service
I have been working with Fortinet FortiGate, WatchGuard, Sophos, and SonicWall. I'm not as comfortable with SonicWall because of their UI and limitations. I prefer Fortinet above all other options. When it comes to configuration, I am confident in my ability to handle various tasks, including creating policies such as firewall rules, web policies, and application policies. Additionally, I can configure VPNs and implement load balancing, among other tasks. Overall, I feel much more comfortable working with Fortinet. Fortinet has made significant improvements by integrating AI with firewalls for threat analysis and prevention. In the past 2-3 years, they have launched FortiSASE and SIEM, and they also provide SOC services. Both Palo Alto and Fortinet FortiGate are excellent. While Fortinet FortiGate comes at higher prices, the functionality and support justify the cost. They promptly resolve firmware issues and inform all support providers about configuration changes.
Hailemichael Yigrem - PeerSpot reviewer
Advanced security features enhance threat detection and prevention
Check Point NGFW provides granular application control and detailed visibility over application and user activity. It integrates with the ThreatCloud ecosystem, enabling real-time threat detection and prevention. The User Identity Awareness blade integrates with Active Directory, identifying user traffic sources. Check Point NGFW is highly scalable and has centralized management through SmartConsole, which manages policies, logs, and threat data. It reduced our incidents and decreased the time to analyze cyber threats by 70 percent.
Bhaskar Rao - PeerSpot reviewer
Though it helps deal with web traffic or any malicious traffic, it needs to work on its DC performance issues
The product's initial setup phase is moderate in level, so it is neither very complex nor very easy. For the deployment, my company first needs to gather all the requirements of the users and the domain names and consider how many users there are in the company. In the implementation and planning part, my company needs to consider what kind of policies we will create while ensuring that the policies are created based on the requirements of the users. There is a need to segregate the users' requirements since there are separate departments in the company, like the HR department, sales department, IT department, and manufacturing department, so that our company can create policies depending on their requirements. On-site, if you want a GRE tunnel, our company can handle GRE tunnel traffic routing and Zscaler Cloud Firewall, after which Zscaler will take action based on the policies created by our organization. For the deployments and maintenance, a team of five members consisting of two managers and three engineers is required.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The dynamic segmentation feature in Fortinet FortiGate is pretty good."
"It has upscaled our security posture, especially regarding external connectivity, because any access or connection from the company has to go through the Fortinet FortiGate firewall."
"We can detect any attack of viruses or malware at the first point of contact."
"The strengths of Fortinet FortiGate include network security, VPN, site-to-site tunnels, client VPN solutions, two-factor authentication for VPN clients, and SD-WAN for branch level. We have implemented these solutions for various customers."
"It has improved our organization with control data."
"The reporting and monitoring are very good."
"In terms of security, we have not experienced any security flaws or loopholes, and it has proven to be quite stable."
"The features I find most useful in Fortinet FortiGate are its simplicity of utilization, which is very important, and its provision of interfaces to see the alerts and other things."
"The sales, pre-sales, professional services, and tech support are all very nice."
"The security posture assessment with two-factor authentication has saved more time and commercial costs by avoiding deploying having to deploy another solution."
"I like the dashboard, redundancy, log analysis, threat prevention and ISP, and VPN."
"The interface allows us to quickly adapt to new security requirements and maintain compliance with organizational policies."
"The scalability is very good."
"The initial setup is very straightforward."
"The product is very scalable."
"The tool provides great security."
"Zscaler provides effective protection against various cyber threats ensuring a safe environment"
"The technical support from Zscaler was excellent."
"The visibility and log availability offered are highly valued for troubleshooting purposes, and this is a key factor driving customer interest in the firewall module."
"The solution offers good sandboxing."
"The scalability is okay. We have around 2200 people using this solution."
"It helps a lot of companies to reduce their downtime. Also, It helps businesses in terms of being secured and protected from any threats."
"The product’s firewall and VPN package are fantastic compared to any other solution."
"I like the ease of deployment and its flexibility. We don't need to deal with license, quotes, procurement, delivery, and installation. Everything is software-based, and it's very easy to operate."
 

Cons

"I find the management console not very straightforward, so that's an area where Fortinet FortiGate can improve. They should simplify it and make it more user-friendly."
"The biggest "gotcha" is that if the client purchases what they call the UTM shared bundle, which has unified threat management on both, it's not as easy to manage if you have more than one firewall."
"Its reporting can be improved. Sometimes, I don't get proper reports."
"I believe there is room for improvement in machine learning and AI in Fortinet FortiGate."
"I would like Fortinet to add more automation to FortiGate."
"It can be a little bit more user-friendly in terms of policy definition and implementation. It seems a little bit complicated, and it could be simplified."
"We had some issues in the beginning while setting it up, but after doing the firmware update, it is working fine."
"WAN load-balancing could be a lot better at detecting when a link is poor or inconsistent, and not just flat out dead."
"The distributor support capability is quite lacking as the problem/incident is rarely solved on the distributor level and instead escalated to the principal."
"Check Point should quickly update and expand its application database to have what Palo Alto has."
"The Check Point support needs a lot of improvement."
"It could be easier to access the installation of the Hostfix for VSX solutions. The CLI commands help us understand how virtual firewalls behave in terms of processor, memory, and other aspects. More graphic visualizations of CPUSE commands would be a welcome improvement, and Check Point could expand scripts to run within the solution for multiple tasks."
"You need to merge all the old consoles into one new one and make the interface more convenient for the novice administrator."
"The pricing could be better."
"I'd like to see more use of applications and URLs in security policies moving forwards."
"I would like to see better Data Leakage protection options and easier-to-understand deployment models for this."
"They do not provide a few components that are fundamental to differentiate the products"
"Instead of the standard license, they should certainly provide customers with the visibility to access and view the logs."
"It would be better if they improved their policy, package visibility, and flexibility while we're creating rules for inspection. It could also be cheaper or more things could be included in the basic package. In the next release, I would like better coverage in the Asia Pacific region and better quality of service."
"There are some areas it could improve when it comes to blocking, we have to block some things manually. For example, if we block a top-level domain we have seen that the new IPs come through, the IPs are not blocked. There should be some more granular way of doing it. My only request is if you're blocking something at a top level, the sub-level sub-domains and all those other IPs should be blocked too automatically."
"The issue right now is probably that Zscaler is not providing web browser isolation. Another solution, Menlo, offers this. For one customer, we had to send traffic to Menlo to do the isolation for us. It was requested by the customer so that they could integrate any iframe. Zscaler needs to add this type of feature in their next release."
"When it comes to customer support, there is room for improvement in Zscaler's service."
"Certain criteria need to be met if you want to scale this solution."
"Apart from the issues associated with the product in areas like the DC performance issues and DC failover, Zscaler Cloud Firewall's IP should not have a proxy IP."
 

Pricing and Cost Advice

"The price of Fortinet FortiGate is better than Cisco, Check Point, and Palo Alto. In terms of pricing, it's probably a better-priced firewall solution overall."
"It is cost-effective, and provides a good value for your money. The pricing, and license renewal, is very reasonable for us."
"It is not the cheapest one, but its price is very competitive."
"The value is the capability of having multiple services with one unique license, not having the limitation per user licensing schema, like other vendors."
"Fortinet FortiGate's price can be reduced."
"We have the full license that included all of the features and support."
"It's very affordable."
"The pricing is justified. It's a little pricey, but what you pay for is what you get."
"This product is not cheap and there are additional costs that depend on what model or package that you buy."
"The pricing and licensing part is something that could be improved. Check Point license and pricing are a bit higher compared to competing firewalls. I think they can work on that."
"When comparing the price of Check Point NGFW to other solutions it's difficult to compare because even though everything is included in the Fortinet price, there are large differences between the models. You need to go to a quite expensive Fortinet firewall to receive the same throughput and functionality as in a Check Point firewall. In the end, they are quite similar in price, Fortinet might be a bit cheaper."
"The pricing and licensing are pretty steep. They know that they are good, so they are pricey."
"The product provides value for pricing in terms of performance and technical features compared to other firewalls."
"Check Point solutions are very expensive here. They're good, but they're expensive... Check Point is only useful for customers that have a big IT budget."
"It's an expensive solution"
"The pricing is high compared to competitors."
"The product is a bit expensive compared to the solutions offered by its competitors, like Palo Alto. There is a need to make yearly payments towards the license in charges associated with the product."
"Zscaler is priced too high compared to the cost of Fortinet."
"On a scale from one to ten, where one is cheap, and ten is expensive, I rate the solution's pricing an eight out of ten."
"There are licensing costs, and I would not say that it's a cheap vendor."
"The licensing is on a yearly basis. It is somewhere around 30 or 40 pounds per user for our organization."
"There are different subscription models available."
"It comes at a significantly reduced cost while ensuring control and effectiveness."
"There is an annual license required for the use of the Zscaler Cloud Firewall."
report
Use our free recommendation engine to learn which Firewalls solutions are best for your needs.
863,679 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
16%
Comms Service Provider
8%
Manufacturing Company
7%
Financial Services Firm
6%
Computer Software Company
15%
Financial Services Firm
10%
Comms Service Provider
6%
Manufacturing Company
6%
Computer Software Company
13%
Manufacturing Company
9%
Financial Services Firm
8%
Retailer
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

Which is the better NGFW: Fortinet Fortigate or Cisco Firepower?
When you compare these firewalls you can identify them with different features, advantages, practices and usage a...
What is the biggest difference between Sophos XG and FortiGate?
From my experience regarding both the Sophos and FortiGate firewalls, I personally would rather use FortiGate. I know...
What are the biggest technical differences between Sophos UTM and Fortinet FortiGate?
As a solution, Sophos UTM offers a lot of functionality, it scales well, and the stability and performance are quite ...
How does Check Point NGFW compare with Fortinet Fortigate?
I have experience on both from Disti and channel experience. Please find below my comments (nothing new as such). -Ch...
Which would you recommend - Azure Firewall or Check Point NGFW?
Azure Firewall is easy to use and provides excellent support. Valuable features include integration into the overall ...
What do you like most about Check Point NGFW?
Check Point NGFW provides essential security, featuring no-obligation access for secure connections, strong intrusion...
Which lesser known firewall product has the best chance at unseating the market leaders?
Netscope, Zscaler if they continue route they are on now. FIrewalls needs great deal of automation on each end, datac...
What do you like most about Zscaler Cloud Firewall?
The product’s firewall and VPN package are fantastic compared to any other solution.
What is your experience regarding pricing and costs for Zscaler Cloud Firewall?
Zscaler Cloud Firewall is quite expensive compared to competitors. However, it offered moderate value for money.
 

Also Known As

FortiGate 60b, FortiGate 60c, FortiGate 80c, FortiGate 50b, FortiGate 200b, FortiGate 110c, FortiGate, Fortinet Firewall
Check Point NG Firewall, Check Point Next Generation Firewall
No data available
 

Overview

 

Sample Customers

Amazon Web Services, Microsoft, IBM, Cisco, Dell, HP, Oracle, Verizon, AT&T, T-Mobile, Sprint, Vodafone, Orange, BT Group, Telstra, Deutsche Telekom, Comcast, Time Warner Cable, CenturyLink, NTT Communications, Tata Communications, SoftBank, China Mobile, Singtel, Telus, Rogers Communications, Bell Canada, Telkom Indonesia, Telkom South Africa, Telmex, Telia Company, Telkom Kenya
Control Southern, Optimal Media
Zenith Live, Azure, Carlsberg Group
Find out what your peers are saying about Check Point NGFW vs. Zscaler Cloud Firewall and other solutions. Updated: July 2025.
863,679 professionals have used our research since 2012.