Try our new research platform with insights from 80,000+ expert users

Cisco Secure Firewall vs Palo Alto Networks PA-Series comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Sep 16, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Fortinet FortiGate
Sponsored
Ranking in Firewalls
2nd
Average Rating
8.4
Reviews Sentiment
7.2
Number of Reviews
319
Ranking in other categories
Software Defined WAN (SD-WAN) Solutions (1st), WAN Edge (1st)
Cisco Secure Firewall
Ranking in Firewalls
7th
Average Rating
8.2
Reviews Sentiment
7.1
Number of Reviews
409
Ranking in other categories
Cisco Security Portfolio (4th)
Palo Alto Networks PA-Series
Ranking in Firewalls
15th
Average Rating
8.6
Reviews Sentiment
7.3
Number of Reviews
32
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of April 2025, in the Firewalls category, the mindshare of Fortinet FortiGate is 21.1%, up from 17.7% compared to the previous year. The mindshare of Cisco Secure Firewall is 5.8%, up from 5.5% compared to the previous year. The mindshare of Palo Alto Networks PA-Series is 0.5%, up from 0.1% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Firewalls
 

Featured Reviews

EhabAli - PeerSpot reviewer
Efficient, user-friendly, and affordable
In the past, NSS Labs was utilized to test files and verify the numbers and datasheets. It would be beneficial to have an organization or testing lab that can verify the numbers in our datasheets since changes are frequently made, which can be inconvenient for review. For instance, when comparing different competitors such as Forcepoint, Palo Alto, and Check Point, the throughput or numbers in the datasheet may be lower than the actual numbers. Conversely, Fortinet typically reports very high numbers, but they cannot be replicated in the real world. Therefore, it would be advantageous for them to partner with a neutral testing organization such as NSS Labs to validate these numbers, thus providing more credibility and comfort to everyone regarding the accuracy of the datasheets. For the migration, everyone has a firewall in use and I am selling Fortinet. Typically, I am replacing another firewall. Previously, there was a tool available to convert configurations from one firewall, such as Palo Alto, to Fortinet, but this tool is no longer free. If it could be made free again, it would be very beneficial. This tool shows a lot of promise and is very good. Making it free would help many companies deliver their products in a more efficient and integrated way. It would also be more valuable to include the tool with the firewall package or license instead of having to pay extra for it. Paying extra puts more pressure on small companies to deliver the firewall and complete the configuration, especially if they have hundreds or thousands of policies. It's very painful to move through these policies line by line. The stability has room for improvement. When it comes to Secure SD-WAN, everything is fine. They are going the right way. SD-WAN is very promising. They can provide the SD-WAN solution separately, but they will not take this approach because even the smallest firewall can support the features, so there is no need to have a separate service or appliance. They are following the right steps, and there is nothing to be improved. Feature-wise, I'm really satisfied with the new release, and the features they have added. For now, it's fine.
Maharajan S - PeerSpot reviewer
Enhances security with precise access control but has integration challenges
Overall, I would rate the product six out of ten. Because of the support and cost, I moved away from Cisco, but otherwise, it is a good product. Recommendation depends on the requirement. If lacking a proper team and being dependent on the OEM and partner, Cisco is not suitable. However, if the team is qualified with Cisco-certified people and the requirement is a big network, it can be considered. In today's hybrid work world, having an expanded gateway is more typical than having a single one. Thus, Cisco is unlikely to be recommended for a hybrid requirement unless in-house skills align. Otherwise, depending on partners and Cisco, it can be a risk. I rate the overall solution six out of ten.
Deminda Dilan - PeerSpot reviewer
Good for enterprise-level businesses and offers many features like URL filtering and antivirus capabilities
Palo Alto can improve the web application firewall (WAF) feature at layer 7. Currently, I don't think it's available. If they can improve that, it would be better. We wouldn't need to purchase a separate WAF solution because they already have advanced URL filtering. But I don't think that advanced URL filtering has the same features as a dedicated WAF, like F5 or other solutions. That is an area for improvement. If they can improve the WAF feature, customers won't have to buy a separate WAF solution. They could do it with the same Palo Alto firewall, perhaps through a subscription-based model. So the web application firewall feature has to be improved.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The solution is very user friendly. The user interface in particular is quite nice."
"The most valuable feature is the bundled subscription, which is IPS, TV and web filtering."
"The most important feature, normally for small business customers, is link load balancing."
"Initial setup is straightforward. There weren't too many issues with setting it up. It takes one hour or so."
"The secure web gateway module and the application control module are valuable. HA operations are very easy."
"The email protection and VPN features are the most valuable."
"The solution can scale well."
"The most valuable feature of Fortinet FortiGate is the simple configuration."
"I have found the stability of this solution really good. This is why I use it."
"Web filtering is a big improvement for us. The previous version we used, the AC520, did not have that feature included. It was not very easy for us, especially because the environment had to be isolated and we needed to get updates from outside, such as Windows patches. That feature has really helped us when we are going outside to pull those patches."
"The greatest benefit that this has provided to our organization is that we've been able to adjust the time that it takes to implement firewall changes. It's gone from a week to less than half a day to implement a change, which means that our DevOps team can be much more agile, and there is much less overhead on the firewall team."
"It is a secure product."
"The ASA has seen significant improvement due to the IPS."
"The IPS, as well as the malware features, are the two things that we use the most and they're very valuable."
"The most important feature is its categorization because on the site and social media you are unified in the way they are there."
"The transparency of the single UI to ensure security. A product has to be simple so that an administrator can use it."
"A valuable feature that we can consider is the deployment time, which is significantly reduced. It is almost 90% faster compared to other solutions."
"The tool's most valuable feature is WildFire."
"Palo Alto Networks firewalls offer single-mode panel processing with live scanning."
"The solution has a three-layer architecture, and it helps customers to deploy the solution quickly."
"The most valuable feature of Palo Alto Networks PA-Series is that it is highly customizable."
"A valuable feature that we can consider is the deployment time, which is significantly reduced, almost 90% faster compared to other solutions. This leads to quicker deployment and less downtime."
"The reporting feature and application ID functionality within Palo Alto Networks PA-Series are incredibly valuable to us."
"I rate the stability as ten out of ten."
 

Cons

"While FortiGate is cheaper than most other solutions, we're seeing increased license renewal costs. Most of our clients are asking for more significant discounts because the price is going up."
"Regarding challenges, customers initially faced issues like internet dropping, but after firmware upgrades, everything worked well."
"Vulnerability scanning could be improved."
"In the balance between links feature normally you can just choose one option to balance. It would be better for the solution to have more than one option, preferably three."
"I would like to see improvements made to the dashboard and UI, as well as to the reporting."
"One of the features that I would like to have is to do with endpoint production, it should be integrated. For example, the firewall gets notified of any kind of forensic event that needs to be done, such as if there is a ransomware attack and how it originated, all those records have to be available from the firewall, which is not."
"The improvement is related to logs. Instead of the CLI, we should be able to have more insights into the logs of the firewall in the GUI."
"The user interface could be improved to make it less confusing and easier to set up."
"We are replacing ASA with FTD which offers many new features not available using ASA."
"They should improve their interface."
"One thing that Cisco could improve is the GUI. The graphic user interface should be more user-friendly."
"UTM features would be nice or some NextGen features."
"I see room for improvement when it comes to integrating all the devices into a central management system. Cisco doesn't provide this, but there are some good products in the market that can provide it."
"The user interface for the Firepower management console is a little bit different from traditional Cisco management tools. If you look at products we already use, like Cisco Prime or other products that are cloud-based, they have a more modern user interface for managing the products. For Firepower, the user interface is not very user-friendly. It's a little bit confusing sometimes."
"It is not the newest, cutting-edge technology"
"There are always vulnerabilities that come up and there was one in early 2018 but this was patched with software updates."
"Palo Alto Networks PA-Series is complicated to configure compared to one of its competitors."
"There is room for improvement in streamlining this process for smoother transitions."
"The support provided by the solution is not that good."
"The technical support offered by Palo Alto is an area of concern where improvements are required."
"The SD-WAN feature of Palo Alto Networks is not good compared to FortiGate."
"I encountered a slight issue with the application portal, which was not functioning correctly."
"I experienced some problems with AWS cloud parameters connected to Palo Alto firewall."
"The initial setup of Palo Alto Networks PA-Series is very complicated."
 

Pricing and Cost Advice

"The price of Fortinet FortiGate is better than Cisco, Check Point, and Palo Alto. In terms of pricing, it's probably a better-priced firewall solution overall."
"Compared to other firewall products, it's a little cheaper in terms of pricing."
"We have the full license that included all of the features and support."
"FortiGate's pricing falls within the mid-range when compared to other leading firewall solutions."
"It is a good product from a price perspective versus functionality."
"Fortinet FortiGate is expensive."
"The price of FortiGate is reasonable as I plan to buy new switches. The initial gadgets are already booted, and the pricing seems normal on the market. As for additional costs, I haven't subscribed to many extra features, so I'm only using what I need. Last year, I renewed the support for three years, which can sometimes be expensive but depends on the security benefits and how it helps us."
"It is affordable. Palo Alto is much more expensive than Fortinet."
"They're not too expensive. They're a little more expensive than other products, but you are getting the name, the company, and the support."
"It requires additional licensing to enable 10G ports."
"The cost of keeping the licensing up on the ASA is very expensive. It has a lot of positives, but the cost of going with it is really starting to be a major negative right now."
"The pricing was pretty comparable to other solutions when we purchased it."
"We pay a lot of money for it."
"This solution is expensive and other solutions, such as FortiGate, are cheaper."
"We're using the smart license for this firewall. The models that we have require licensing for remote access."
"The price of this solution is not good or bad."
"From my perspective, managing the price is important, especially because we're a small business. For larger organizations like Barclays, we provide our requirements to the client, and they place the order on BigFix. It's their responsibility to consider their budget and make decisions accordingly. We appreciate the features we get, but the cost-sharing still depends on the client."
"The solution's pricing is high compared to that of Cisco and Fortinet."
"The product is expensive."
"The pricing is a bit on the higher side."
"It is a very expensive solution."
"While other firewalls may come with a higher cost, when you consider the cost in relation to the services and features that Palo Alto offers, it is clear that Palo Alto is delivering excellent value."
"The cost varies depending on the device model, with entry-level firewalls priced around $1,300 to $1,500, while higher-end models can reach prices of several hundred thousand dollars."
"From my perspective, managing the price is important, especially because we're a small business. For larger organizations like Barclays, we provide our requirements to the client, and they place the order on BigFix. It's their responsibility to consider their budget and make decisions accordingly. We appreciate the features we get, but the cost-sharing still depends on the client."
report
Use our free recommendation engine to learn which Firewalls solutions are best for your needs.
845,849 professionals have used our research since 2012.
 

Comparison Review

it_user206346 - PeerSpot reviewer
Mar 11, 2015
Cisco ASA vs. Palo Alto Networks
Cisco ASA vs. Palo Alto: Management Goodies You often have comparisons of both firewalls concerning security components. Of course, a firewall must block attacks, scan for viruses, build VPNs, etc. However, in this post I am discussing the advantages and disadvantages from both vendors concerning…
 

Top Industries

By visitors reading reviews
Educational Organization
22%
Computer Software Company
14%
Comms Service Provider
7%
Manufacturing Company
6%
Educational Organization
41%
Computer Software Company
13%
Manufacturing Company
4%
Government
4%
Computer Software Company
17%
Manufacturing Company
13%
University
8%
Comms Service Provider
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

Which is the better NGFW: Fortinet Fortigate or Cisco Firepower?
When you compare these firewalls you can identify them with different features, advantages, practices and usage a...
What is the biggest difference between Sophos XG and FortiGate?
From my experience regarding both the Sophos and FortiGate firewalls, I personally would rather use FortiGate. I know...
What are the biggest technical differences between Sophos UTM and Fortinet FortiGate?
As a solution, Sophos UTM offers a lot of functionality, it scales well, and the stability and performance are quite ...
Which is better - Fortinet FortiGate or Cisco ASA Firewall?
One of our favorite things about Fortinet Fortigate is that you can deploy on the cloud or on premises. Fortinet Fort...
How does Cisco's ASA firewall compare with the Firepower NGFW?
It is easy to integrate Cisco ASA with other Cisco products and also other NAC solutions. When you understand the Cis...
Which is better - Meraki MX or Cisco ASA Firewall?
Cisco Adaptive Security Appliance (ASA) software is the operating software for the Cisco ASA suite. It supports netw...
What do you like most about Palo Alto Networks PA-Series?
The reporting feature and application ID functionality within Palo Alto Networks PA-Series are incredibly valuable to...
What needs improvement with Palo Alto Networks PA-Series?
The interface of Palo Alto Networks PA-Series should be made much more user-friendly.
 

Also Known As

FortiGate 60b, FortiGate 60c, FortiGate 80c, FortiGate 50b, FortiGate 200b, FortiGate 110c, FortiGate, Fortinet Firewall
Cisco Adaptive Security Appliance (ASA) Firewall, Cisco ASA NGFW, Adaptive Security Appliance, Cisco Sourcefire Firewalls, Cisco ASAv, Cisco Firepower NGFW Firewall
No data available
 

Overview

 

Sample Customers

Amazon Web Services, Microsoft, IBM, Cisco, Dell, HP, Oracle, Verizon, AT&T, T-Mobile, Sprint, Vodafone, Orange, BT Group, Telstra, Deutsche Telekom, Comcast, Time Warner Cable, CenturyLink, NTT Communications, Tata Communications, SoftBank, China Mobile, Singtel, Telus, Rogers Communications, Bell Canada, Telkom Indonesia, Telkom South Africa, Telmex, Telia Company, Telkom Kenya
There are more than one million Adaptive Security Appliances deployed globally. Top customers include First American Financial Corp., Genzyme, Frankfurt Airport, Hansgrohe SE, Rio Olympics, The French Laundry, Rackspace, and City of Tomorrow.
Information Not Available
Find out what your peers are saying about Cisco Secure Firewall vs. Palo Alto Networks PA-Series and other solutions. Updated: April 2025.
845,849 professionals have used our research since 2012.