Try our new research platform with insights from 80,000+ expert users

Forcepoint Next Generation Firewall vs Palo Alto Networks Advanced Threat Prevention comparison

Sponsored
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Fortinet FortiGate
Sponsored
Average Rating
8.4
Reviews Sentiment
7.2
Number of Reviews
318
Ranking in other categories
Firewalls (2nd), Software Defined WAN (SD-WAN) Solutions (1st), WAN Edge (1st)
Forcepoint Next Generation ...
Average Rating
7.6
Reviews Sentiment
6.6
Number of Reviews
43
Ranking in other categories
Firewalls (27th), Software Defined WAN (SD-WAN) Solutions (11th), WAN Edge (12th)
Palo Alto Networks Advanced...
Average Rating
8.6
Reviews Sentiment
6.9
Number of Reviews
26
Ranking in other categories
Intrusion Detection and Prevention Software (IDPS) (6th)
 

Mindshare comparison

Firewalls
Intrusion Detection and Prevention Software (IDPS)
 

Featured Reviews

EhabAli - PeerSpot reviewer
Efficient, user-friendly, and affordable
In the past, NSS Labs was utilized to test files and verify the numbers and datasheets. It would be beneficial to have an organization or testing lab that can verify the numbers in our datasheets since changes are frequently made, which can be inconvenient for review. For instance, when comparing different competitors such as Forcepoint, Palo Alto, and Check Point, the throughput or numbers in the datasheet may be lower than the actual numbers. Conversely, Fortinet typically reports very high numbers, but they cannot be replicated in the real world. Therefore, it would be advantageous for them to partner with a neutral testing organization such as NSS Labs to validate these numbers, thus providing more credibility and comfort to everyone regarding the accuracy of the datasheets. For the migration, everyone has a firewall in use and I am selling Fortinet. Typically, I am replacing another firewall. Previously, there was a tool available to convert configurations from one firewall, such as Palo Alto, to Fortinet, but this tool is no longer free. If it could be made free again, it would be very beneficial. This tool shows a lot of promise and is very good. Making it free would help many companies deliver their products in a more efficient and integrated way. It would also be more valuable to include the tool with the firewall package or license instead of having to pay extra for it. Paying extra puts more pressure on small companies to deliver the firewall and complete the configuration, especially if they have hundreds or thousands of policies. It's very painful to move through these policies line by line. The stability has room for improvement. When it comes to Secure SD-WAN, everything is fine. They are going the right way. SD-WAN is very promising. They can provide the SD-WAN solution separately, but they will not take this approach because even the smallest firewall can support the features, so there is no need to have a separate service or appliance. They are following the right steps, and there is nothing to be improved. Feature-wise, I'm really satisfied with the new release, and the features they have added. For now, it's fine.
OusaidAbaz - PeerSpot reviewer
Provides decent protection for the LAN but complicated interface
We had some licensing issues with its web filtering capabilities. That's why we migrated our web filtering to Cisco Umbrella. Moreover, the interface is complicated. It's difficult to locate all the necessary menus and functions. For example, one of the many issues is with SSH. Even now, we haven't successfully opened the port to connect using SSH mode when we want to change the configuration. It's like a black box—not very open to changes and customization. It's simply not easy to configure. There are other problems, too. For example regarding Forcepoint's Websense component. We had a lot of problems managing the web settings within Websense. That's why we migrated to Cisco Umbrella for cloud-based web filtering. It's not that Forcepoint is inherently bad. The issue is that it's not user-friendly. It is not easy to use. The developers need to redesign the interface (GUI) for better management. It is very difficult to manage. For example, simple actions require too many clicks compared to FortiGate or Palo Alto. That's the main problem.
Carlos Bracamonte - PeerSpot reviewer
Robust, reliable, simple to install and good technical support
We are attempting to improve the use of URL filtering beyond threat protection. I'm not sure what the remaining threat protection features are off the top of my head. But beyond that, we use URL filtering. We have three approved cases for using external dynamic lists that are stored in a bucket repository. Then, for each URL site that needs to be whitelisted, we add it to the external dynamic list in order to gain access to this email. I would like Wildfire to be implemented. We use the equivalent in Cisco is the integration policies. We have the Wildfire but we are not currently implementing it. We don't have the license to use it, but we are not currently implementing it until we present the use cases that the company gives some value to and they approve the use of it.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The CLI is robust and powerful, enabling rapid, consistent changes via SSH."
"You can create multiple Virtual Domains (VDOMs), which are treated as separate firewall instances."
"The inspection and web security features are most valuable."
"Whenever we raise a complaint with FortiGate, their response and resolution times are minimal."
"It performs very well."
"The network security and cloud security are most valuable."
"UTM/NGFW features and FortiCloud for logs and backups are awesome."
"The most valuable features are SD-WAN, application control, IPS control, and FortiSandbox."
"I found the initial setup process to be very simple and straightforward."
"Technical support has been quite helpful in the past."
"The blocking, based on the signal provided, is the solution's most valuable aspect."
"The support is great. They also have very good categorization. It's very good. It captures a lot of threats."
"It is stable and scalable. In addition, their support is great. When you ask them for something, they provide support, and if required, they also involve the R&D team to help you to resolve the issues in your configuration."
"The people we deal with is a local partner in Cambodia and we can get good support from them."
"We like the scalability of Forcepoint because with the Forcepoint NGFW solution, we can scale anything. The solution has central management, so we can manage all the branches and devices centrally in one controller."
"When our customer needs some optimization, along with performance and security. If they want everything in one package, I recommend Forcepoint because they have everything."
"The most valuable features are the simplicity, transparency, and overall ease of management."
"It's a monster, it's got so many beautiful features. We do deal with other firewalls and we've got a better idea of what other firewalls' capabilities are, any comparison with the Palo Alto I liked the quality of service on the applications that you can control the amount of bandwidth an application is allowed to consume. The best feature is the quality of the application quality of service."
"The sandboxing tools offer great prevention for cloud feeds."
"One of the most valuable features is the anti-malware protection."
"Edge protection is a valuable feature."
"The most valuable features are that it's user-friendly, has interesting features, URL filtering, and threat prevention."
"With the IP address flag, I was able to see that I was being hacked. The moment there was an interaction between somebody on my network and that IP, the solution was able to flag it, and we were able to protect ourselves."
"The most valuable feature of Palo Alto Threat Prevention for our company is the next generation firewall."
 

Cons

"The feature which gives us a lot of pain is ASIC architecture."
"There were quite a few problems with the stability of the system."
"Fortinet FortiGate can improve the integration with Active Directory. Additionally, I would like to have a Cloud Controller, such as they do in the Cisco Meraki solution."
"They should make the rule sets more understandable for the end user. When you're trying to explain to somebody how a computer network is secured, sometimes it's difficult for an end user or customer to understand. If there was a way to make the terminology more accessible to the end user, the set up could be easier. They should translate the technical jargon to an easily relatable and understandable conversation for the end user, the customer, that would be brilliant. Particularly in an environment where the IT structure is audited regularly, there's always pressure from the auditor to up the standards and up the security and you get your USCERT's that come out and there's a warning about this and the customer will want to lock out so much and when you apply it they run into issue where they can't search the internet or print to their remote office. Of course they can't print to your remote office, they just locked it up. They should make the language more understandable for the customer. If there's a product out there that made the jargon understandable to John Q. Public, I would buy that."
"This product could be improved with Active directory integration and better handling in IPsec and GRE Tunnels."
"My only complaint about FortiGate is a lack of QinQ VLAN tunneling. I haven't found this feature in any Fortinet product. You can do this on all Cisco routers, including the smaller models. However, QinQ isn't available on the biggest, most expensive Fortinet units. They still don't have that. I think now we're on software version 6.0, and they still haven't found a solution for QinQ. It isn't a dealbreaker, but that's my main complaint."
"I think they need to improve more in order to be a competitor with the leaders of the field."
"The pricing could be a bit better, especially when you consider how they have the most basic offering priced."
"The solution needs to build upon its network functionality. It needs to be a bit smarter."
"They should have a GUI on the product itself, not a separate management tool to be used on the management server or on a server to be used to manage the file. It should be all in one device. The device should be controlled through its own GUI. They also have to improve the learning center and the documents as the documents don't really help."
"Making this solution easier to use would be an improvement."
"They need to improve their alerts."
"I would like to see more sizing in the next release, and the roadmap should be clear."
"It's a complicated firewall. Until you come to know the firewall inducers, most people don't like the firewall because the components for the firewall are a little bit complex. User-friendliness is a little bit tough. It needs to be user-friendly when creating policies, and pushing policies. Committing takes more time compared to Palo Alto."
"Next Generation Firewall's configuration could be improved."
"They need to work on stability, it has not been the best in our experience."
"The technology firewall anomaly network could stand improvement."
"Palo Alto Networks Threat Prevention could improve the commercial offing. Other solutions, such as Fortinet provide better commercial features."
"I think they can use some improvement on FID."
"The solution needs to improve its local technical support services. There is no premium support offered in our market."
"It's not so easy to set up a test environment, because it's not so easy to get the test license. The vendor only gives you 90 days for a test license; it's a tough license to get."
"The pricing has improved with the newer generation of their Firewalls, but the price could always be lower. In comparison with other solutions, I believe they're quite competitive."
"The application’s pricing and dashboard need improvement. It could be user-friendly."
"There is a potential drawback with the lack of support for the ICAP protocol."
 

Pricing and Cost Advice

"The price depends on the size of the company. From the beginning, you just want to know the internet bandwidths, speed, and the number of users to be able to offer the right product and model. They have a lot of products in FortiGate according to the size of the company, like 200D and 300D."
"Pricing is good. They offer a lot of things, the most important is the support. Every time you upgrade your license, you also get insurance for the equipment. If you have any problem with equipment, they send in new equipment."
"It is affordable. Palo Alto is much more expensive than Fortinet."
"The price of FortiGate is average and I would say that based on the top five products available on the market, it is in the affordable range."
"The price of FortiGate is comparable to that of most other firewall solutions and is more affordable than Cisco."
"The cost is too high... They have to focus on more features with less cost for the customer. If you see the market, where it's going, there are a lot of players offering more features for less cost."
"The license is yearly. We pay for the top end. It's called 360."
"The price is really low. It's cheap in comparison to the cost of Cisco or CheckPoint, for example."
"It could be cheaper like Fortinet."
"Forcepoint is very expensive but it's really secure."
"I believe the licensing fee is for one year, three years, and five years, or something like that. If you wants to increase the support level from a simpler level to platinum, I think that there's a cost. There are differences between every kind of support, but I don't know the numbers."
"Forcepoint Next Generation Firewall is reasonable, it is priced the same as other firewalls."
"The big advantage of this solution is that we can select the right model for our requirements, which is not too expensive."
"We would love to take other solution from Forcepoint, but unfortunately the price is too high. That's why we are not considering using Forcepoing for our proxy and DLB. They have a very good DLB, but the matter in the end is the cost."
"The pricing of the solution is normally competitive with other products."
"It is expensive."
"The price of the solution is higher than others on the market. A price reduction would be beneficial if it does not impact their database quality."
"There is an initial, expensive investment but the return is good."
"The product’s pricing is expensive for small companies."
"The pricing has improved with the newer generation of their Firewalls, but the price could always be lower."
"The pricing and the licensing are pretty competitive at this stage. As a reseller, I would like to see the price come down a little bit so I can compete better against other firewalls because we do that all the time."
"If you want to have all of the good features then you have to pay extra for licensing."
"It is an expensive solution and I would like to see a drop in price."
"It's not too expensive."
report
Use our free recommendation engine to learn which Firewalls solutions are best for your needs.
845,040 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Educational Organization
22%
Computer Software Company
14%
Comms Service Provider
7%
Manufacturing Company
6%
Computer Software Company
17%
Manufacturing Company
10%
Financial Services Firm
10%
Government
8%
Computer Software Company
17%
Financial Services Firm
11%
Manufacturing Company
10%
Government
9%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

Which is the better NGFW: Fortinet Fortigate or Cisco Firepower?
When you compare these firewalls you can identify them with different features, advantages, practices and usage a...
What is the biggest difference between Sophos XG and FortiGate?
From my experience regarding both the Sophos and FortiGate firewalls, I personally would rather use FortiGate. I know...
What are the biggest technical differences between Sophos UTM and Fortinet FortiGate?
As a solution, Sophos UTM offers a lot of functionality, it scales well, and the stability and performance are quite ...
What is your experience regarding pricing and costs for Forcepoint Next Generation Firewall?
In terms of pricing, I would place Forcepoint in the middle when compared to other firewalls like Fortinet and Palo A...
What needs improvement with Forcepoint Next Generation Firewall?
There is a lot of technical stuff that could be improved. We've encountered scenarios that were really hard to set up...
Which is the best DDoS protection solution for a big ISP for monitoring and mitigating?
Arbor would be the best bid, apart from Arbor, Palo Alto and Fortinet have good solutions. As this is an ISP, I would...
What is your experience regarding pricing and costs for Palo Alto Networks Threat Prevention?
The pricing is competitive, and with current campaigns and discounts, it provides an excellent device for a reasonabl...
 

Also Known As

FortiGate 60b, FortiGate 60c, FortiGate 80c, FortiGate 50b, FortiGate 200b, FortiGate 110c, FortiGate, Fortinet Firewall
Forcepoint NGFW, Stonesoft Next Generation Firewall, McAfee Network Security Platform, Intel Security Network Security Platform
No data available
 

Overview

 

Sample Customers

Amazon Web Services, Microsoft, IBM, Cisco, Dell, HP, Oracle, Verizon, AT&T, T-Mobile, Sprint, Vodafone, Orange, BT Group, Telstra, Deutsche Telekom, Comcast, Time Warner Cable, CenturyLink, NTT Communications, Tata Communications, SoftBank, China Mobile, Singtel, Telus, Rogers Communications, Bell Canada, Telkom Indonesia, Telkom South Africa, Telmex, Telia Company, Telkom Kenya
California Department of Corrections and Rehabilitation (CDCR)
University of Arkansas, JBG SMITH, SkiStar AB, TRI-AD, Temple University, Telkom Indonesia
Find out what your peers are saying about Netgate, Fortinet, OPNsense and others in Firewalls. Updated: March 2025.
845,040 professionals have used our research since 2012.