Try our new research platform with insights from 80,000+ expert users

Cisco Secure Firewall vs FortiGate Next Generation Firewall (NGFW) comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Sep 16, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Fortinet FortiGate
Sponsored
Ranking in Firewalls
2nd
Average Rating
8.4
Reviews Sentiment
7.2
Number of Reviews
319
Ranking in other categories
Software Defined WAN (SD-WAN) Solutions (1st), WAN Edge (1st)
Cisco Secure Firewall
Ranking in Firewalls
7th
Average Rating
8.2
Reviews Sentiment
7.1
Number of Reviews
409
Ranking in other categories
Cisco Security Portfolio (4th)
FortiGate Next Generation F...
Ranking in Firewalls
10th
Average Rating
8.4
Reviews Sentiment
7.4
Number of Reviews
48
Ranking in other categories
ZTNA (5th), Unified Threat Management (UTM) (9th)
 

Mindshare comparison

As of April 2025, in the Firewalls category, the mindshare of Fortinet FortiGate is 21.1%, up from 17.7% compared to the previous year. The mindshare of Cisco Secure Firewall is 5.8%, up from 5.5% compared to the previous year. The mindshare of FortiGate Next Generation Firewall (NGFW) is 0.4%, up from 0.2% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Firewalls
 

Featured Reviews

EhabAli - PeerSpot reviewer
Efficient, user-friendly, and affordable
In the past, NSS Labs was utilized to test files and verify the numbers and datasheets. It would be beneficial to have an organization or testing lab that can verify the numbers in our datasheets since changes are frequently made, which can be inconvenient for review. For instance, when comparing different competitors such as Forcepoint, Palo Alto, and Check Point, the throughput or numbers in the datasheet may be lower than the actual numbers. Conversely, Fortinet typically reports very high numbers, but they cannot be replicated in the real world. Therefore, it would be advantageous for them to partner with a neutral testing organization such as NSS Labs to validate these numbers, thus providing more credibility and comfort to everyone regarding the accuracy of the datasheets. For the migration, everyone has a firewall in use and I am selling Fortinet. Typically, I am replacing another firewall. Previously, there was a tool available to convert configurations from one firewall, such as Palo Alto, to Fortinet, but this tool is no longer free. If it could be made free again, it would be very beneficial. This tool shows a lot of promise and is very good. Making it free would help many companies deliver their products in a more efficient and integrated way. It would also be more valuable to include the tool with the firewall package or license instead of having to pay extra for it. Paying extra puts more pressure on small companies to deliver the firewall and complete the configuration, especially if they have hundreds or thousands of policies. It's very painful to move through these policies line by line. The stability has room for improvement. When it comes to Secure SD-WAN, everything is fine. They are going the right way. SD-WAN is very promising. They can provide the SD-WAN solution separately, but they will not take this approach because even the smallest firewall can support the features, so there is no need to have a separate service or appliance. They are following the right steps, and there is nothing to be improved. Feature-wise, I'm really satisfied with the new release, and the features they have added. For now, it's fine.
Maharajan S - PeerSpot reviewer
Enhances security with precise access control but has integration challenges
Overall, I would rate the product six out of ten. Because of the support and cost, I moved away from Cisco, but otherwise, it is a good product. Recommendation depends on the requirement. If lacking a proper team and being dependent on the OEM and partner, Cisco is not suitable. However, if the team is qualified with Cisco-certified people and the requirement is a big network, it can be considered. In today's hybrid work world, having an expanded gateway is more typical than having a single one. Thus, Cisco is unlikely to be recommended for a hybrid requirement unless in-house skills align. Otherwise, depending on partners and Cisco, it can be a risk. I rate the overall solution six out of ten.
MOHAN SUKUMAR - PeerSpot reviewer
User-based policies improve network security but integration complexity persists
The main area needing improvement is the user-friendliness of FortiGate's integration with other Fortinet tools like FortiAuthenticator and VPN services. Configuring these services is quite complex and not very user-friendly, requiring technical steps that are difficult for normal users to understand. Fortinet support's resolution of issues is slow, and the research on making the solution user-friendly needs to progress further.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The most valuable features of Fortinet FortiGate are the APIs. They are the most widely known."
"Some of the key features of the solution is that it has good reporting, you can receive many details from the connection, for example, clients and website information."
"The most valuable features are simplicity, management, and that it's constantly evolving."
"The solution is highly scalable because they have devices that can handle a large amount of traffic."
"FortiGate Secure SD-WAN includes best-of-breed next-generation firewall (NGFW) security, SD-WAN, advanced routing, and WAN optimization capabilities, delivering a security-driven networking WAN edge transformation in a unified offering."
"The response is very quick and they can visually resolve our problems in a short period."
"I like Fortinet's cloud management. It allows me to manage all my devices in different branches for three cloud accounts. Even though I use on-prem devices, I can manage everything on the cloud."
"We use a southern institution that's audited for IT security and the reporting that automatically comes off the unit makes it much easier to meet compliance standards and makes it easier as far as the amount of time that has to be spent to compile that information. If you get your reporting set up correctly when you initially set it up, you just select the one you want and hit print. The auditing trail on it is the best feature."
"The SLA is great, and the escalation process is also great."
"The user interface is very easy to manage and find rules. You can do object searches, which are very easy. Also, the logging is very simple to use. So, it is a lot easier to troubleshoot and find items inside the firewall."
"VPN, firewall, and IDS/IPS allow us to deliver services to meet client needs across various industry verticals."
"The most valuable feature would be the IP blocking. It gets rid of things that you don't need in your environment."
"The traffic inspection and the Firepower engine are the most valuable features. It gives you full details, application details, traffic monitoring, and the threats. It gives you all the containers the user is using, especially at the application level. The solution also provides application visibility and control."
"The most valuable feature is that it has the ability to divide the network into three parts; internal, external, and DMZ."
"I am used to the ASA syntax, therefore it is quite easy to make up new rules. I have found that DNS doctoring rules are useful."
"There is a good relationship between real throughput, meaning the root performance, and the data sheet performance."
"The solution has helped our organization secure our network and connect remote sites."
"The most valuable features of the FortiGate firewall include SSL inspection, VPN functionality, and threat intelligence features for preventing threats."
"FortiGate Next Generation Firewall has a stateless balance proposition"
"The IPS and the application control feature are the most valuable."
"The product is easy to configure."
"User identification and application identification are valuable features."
"FortiGate Next Generation Firewall is a good solution because it has a range of options and a clear ecosystem."
"You can integrate certain other services with FortiGate and use additional threat intelligence services because they allow you to combine various solutions, enhancing your overall security."
 

Cons

"There is a lot of improvement needed with SSL-VPN."
"I would like to see improvements with the antivirus and IPS as they are not working properly all the time."
"Usually, we sell the bundle with the UTM or threat management piece with IPS, IDS. Other providers, such as Palo Alto, are ahead in terms of safe functionality. So, for me, delivering truly safe service is probably something that still needs to be improved."
"The support system could be improved."
"To the best of my knowledge, Fortinet does not have a CASB solution and Fortinet does not have a Zero trust solution."
"The cloud management and automation capability could be improved."
"The setup is pretty complex and not easy to implement."
"Lacks training for new features."
"Licensing is complex, and I'd like it to be simplified. This is an area for improvement."
"I would like to see more configurable feature parity with Cisco ASA, which is the legacy product that Cisco is moving away from. When configuring remote access VPN, not all of the options are there. You have to download another tool, which means that the configuration takes a little bit longer with Cisco Secure Firewall. Though it's getting there, there are still some features lagging behind."
"We have to rely on Cisco ASDM to access the firewall interface. This needs improvement. Because we have a web-based interface, and it is a lot more user-friendly."
"It would be great to have all the data correlated to have an overview and one point of administration."
"Usually, the customers are satisfied, but I am going to recommend that all clients upgrade to FirePOWER management. I want Cisco to improve the feature called anti-spam. We use a Cisco only email solution, that's why we need the anti-spam on email facility."
"It integrates with other security products from Cisco, but sometimes, there can be glitches or errors."
"You shouldn't have to use the ASDM to help manage the client."
"The ASA needs to incorporate the different modules you have to integrate to achieve UTM functions, especially for small businesses."
"There's a limitation wherein you can only have about 30 virtual or secondary IPs on a particular interface."
"There have been several vulnerabilities in the firewall. It is hackable, some of the images are hackable."
"I see room to explore its integration with Secure Service Automation for a more comprehensive security view."
"Being a great product, some changes in the pricing would make it a great choice for even more organizations."
"Improvements could be made when companies expand and need better equipment and more licenses."
"Someone without certification and experience with other firewalls might find it a bit more challenging to grasp the FortiGate format and its platform layout."
"FortiGate Next Generation Firewall could be made a little less expensive."
"There should be better customization in the IPS."
 

Pricing and Cost Advice

"Setup costs and pricing depends on many variables, but it's mostly affordable."
"The license is too expensive to renew. The license renewal process is also complex."
"Pricing for this product is comparatively lower than other products. It's an affordable solution, but when expanding the number of users, they'll ask you to replace the model, so that's an added cost."
"Fortinet Secure SD-WAN delivered the lowest total cost of ownership (TCO) per Mbps among all other vendors."
"It is cost-effective, and provides a good value for your money. The pricing, and license renewal, is very reasonable for us."
"The solution requires a license annually, it is not a user license, you can have as many users as your want. I must renew the license regularly per device."
"I would say that all things considered, the pricing is pretty good."
"I think that the pricing is fair."
"We are partners with Cisco. They are always one call away, which is good. They know how to keep their customers happy."
"​Price point is too high for features and throughput available.​"
"Watch out for hidden licensing and incredibly high annual maintenance costs."
"It has a great performance-to-price value, compared to competitive solutions."
"It would be nice if pricing could do more to reflect the economy of the country where the product is being implemented."
"Licensing, recently, has been getting more complicated. In particular, the Smart Licensing that came out is quite complicated. I don't know what's going on.... They call it Smart, but it's complicated. I prefer the traditional license where you buy it once."
"The prices of Cisco Secure Firewall are competitive, especially for us as Cisco partners. We purchase the products directly from Cisco as a gold partner, which allows us to obtain better pricing than we would get from normal distributors or the local market."
"We normally license on a yearly basis. The hardware procurement cost should be considered. If you're virtual maybe that cost is eradicated and just the licensing cost is applied. If you have hardware the cost must be covered by you. All the shipping charges will be paid by you also. I don't thing there are any other hidden charges though."
"Although the solution's pricing is high, compared with other products, it may be cheap."
"It is an expensive solution."
"In my opinion, the pricing of the product is reasonable."
"There is a licensing fee; it is on a yearly basis."
"The tool's pricing is neither cheap nor expensive. Overall, I find it to be competitive in the market."
"The pricing is better compared to other solutions like Check Point, Arista, or Cisco."
"FortiGate Next Generation Firewall is an expensive solution."
"I would rate the pricing a seven out of ten"
report
Use our free recommendation engine to learn which Firewalls solutions are best for your needs.
845,849 professionals have used our research since 2012.
 

Comparison Review

it_user206346 - PeerSpot reviewer
Mar 11, 2015
Cisco ASA vs. Palo Alto Networks
Cisco ASA vs. Palo Alto: Management Goodies You often have comparisons of both firewalls concerning security components. Of course, a firewall must block attacks, scan for viruses, build VPNs, etc. However, in this post I am discussing the advantages and disadvantages from both vendors concerning…
 

Top Industries

By visitors reading reviews
Educational Organization
22%
Computer Software Company
14%
Comms Service Provider
7%
Manufacturing Company
6%
Educational Organization
41%
Computer Software Company
13%
Manufacturing Company
4%
Government
4%
Computer Software Company
20%
Comms Service Provider
12%
Financial Services Firm
8%
Manufacturing Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

Which is the better NGFW: Fortinet Fortigate or Cisco Firepower?
When you compare these firewalls you can identify them with different features, advantages, practices and usage a...
What is the biggest difference between Sophos XG and FortiGate?
From my experience regarding both the Sophos and FortiGate firewalls, I personally would rather use FortiGate. I know...
What are the biggest technical differences between Sophos UTM and Fortinet FortiGate?
As a solution, Sophos UTM offers a lot of functionality, it scales well, and the stability and performance are quite ...
Which is better - Fortinet FortiGate or Cisco ASA Firewall?
One of our favorite things about Fortinet Fortigate is that you can deploy on the cloud or on premises. Fortinet Fort...
How does Cisco's ASA firewall compare with the Firepower NGFW?
It is easy to integrate Cisco ASA with other Cisco products and also other NAC solutions. When you understand the Cis...
Which is better - Meraki MX or Cisco ASA Firewall?
Cisco Adaptive Security Appliance (ASA) software is the operating software for the Cisco ASA suite. It supports netw...
What do you like most about FortiGate Next Generation Firewall (NGFW)?
The tool's most valuable feature is IPS. In my experience, I haven't encountered any issues with integration. It easi...
What is your experience regarding pricing and costs for FortiGate Next Generation Firewall (NGFW)?
The pricing of the FortiGate firewall is good. It offers cost savings as it is generally cheaper than the competition.
What needs improvement with FortiGate Next Generation Firewall (NGFW)?
There should be more testing before releasing software since it can be a little buggy sometimes when new features com...
 

Also Known As

FortiGate 60b, FortiGate 60c, FortiGate 80c, FortiGate 50b, FortiGate 200b, FortiGate 110c, FortiGate, Fortinet Firewall
Cisco Adaptive Security Appliance (ASA) Firewall, Cisco ASA NGFW, Adaptive Security Appliance, Cisco Sourcefire Firewalls, Cisco ASAv, Cisco Firepower NGFW Firewall
No data available
 

Overview

 

Sample Customers

Amazon Web Services, Microsoft, IBM, Cisco, Dell, HP, Oracle, Verizon, AT&T, T-Mobile, Sprint, Vodafone, Orange, BT Group, Telstra, Deutsche Telekom, Comcast, Time Warner Cable, CenturyLink, NTT Communications, Tata Communications, SoftBank, China Mobile, Singtel, Telus, Rogers Communications, Bell Canada, Telkom Indonesia, Telkom South Africa, Telmex, Telia Company, Telkom Kenya
There are more than one million Adaptive Security Appliances deployed globally. Top customers include First American Financial Corp., Genzyme, Frankfurt Airport, Hansgrohe SE, Rio Olympics, The French Laundry, Rackspace, and City of Tomorrow.
Information Not Available
Find out what your peers are saying about Cisco Secure Firewall vs. FortiGate Next Generation Firewall (NGFW) and other solutions. Updated: April 2025.
845,849 professionals have used our research since 2012.