Try our new research platform with insights from 80,000+ expert users

KerioControl vs Palo Alto Networks Advanced Threat Prevention comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Dec 19, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

KerioControl
Ranking in Intrusion Detection and Prevention Software (IDPS)
15th
Average Rating
8.2
Reviews Sentiment
7.0
Number of Reviews
57
Ranking in other categories
Firewalls (29th), Unified Threat Management (UTM) (11th)
Palo Alto Networks Advanced...
Ranking in Intrusion Detection and Prevention Software (IDPS)
6th
Average Rating
8.6
Reviews Sentiment
6.9
Number of Reviews
26
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of April 2025, in the Intrusion Detection and Prevention Software (IDPS) category, the mindshare of KerioControl is 1.6%, up from 1.2% compared to the previous year. The mindshare of Palo Alto Networks Advanced Threat Prevention is 7.4%, down from 8.0% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Intrusion Detection and Prevention Software (IDPS)
 

Featured Reviews

Constantnos Achilleos - PeerSpot reviewer
Leveraging geo-tagging and web filtering for enhanced network security
The solution is used for site-to-site VPN connections and it is valued for its cost efficiency and easy connectivity. It is especially beneficial for multi-site VPNs and is used in about fifteen different components KerioControl has provided a financial benefit as it allows purchasing one license…
Carlos Bracamonte - PeerSpot reviewer
Robust, reliable, simple to install and good technical support
We are attempting to improve the use of URL filtering beyond threat protection. I'm not sure what the remaining threat protection features are off the top of my head. But beyond that, we use URL filtering. We have three approved cases for using external dynamic lists that are stored in a bucket repository. Then, for each URL site that needs to be whitelisted, we add it to the external dynamic list in order to gain access to this email. I would like Wildfire to be implemented. We use the equivalent in Cisco is the integration policies. We have the Wildfire but we are not currently implementing it. We don't have the license to use it, but we are not currently implementing it until we present the use cases that the company gives some value to and they approve the use of it.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The most valuable features of Kerio Control are the IPS and traffic rules. The traffic rules are very user-friendly and the IPS is working well. Additionally, the anti-virus is effective with quick options, such as filtering."
"The ease of use in the GUI itself is the most valuable feature. The GUI is really the best part of it. We like the traffic rules so we can control who can get to what. It's easy to determine the flow of the traffic itself so we aren't having to guess through command lines and reading out basically command-driven output. It's just a very easy-to-use interface. The interface is the best part of the product."
"Compared to other solutions, accounting and live monitoring of firewall status are very good features in KerioControl."
"Kerio Control is easy to use and provides the ability to deliver customized solutions."
"It prevents people from visiting undesirable sites and ensures that they use the internet for their designated jobs."
"I am impressed with the tool's firewall filtering capacity."
"When one of the employees of my customers is using the VPN Client, I have created for them that they will always get a message. When the VPN Client connects to Kerio Control from the outside, they will get an email so they know when they are connected and when they are disconnected what is happening to their network."
"The solution provides feasibility regarding cyber privacy."
"It effectively prevents malware, ransomware, and other attacks."
"I like the solution's interface."
"One of the most valuable features is the anti-malware protection."
"The most valuable feature of Palo Alto Threat Prevention for our company is the next generation firewall."
"The application control and vulnerability protection are the most valuable features."
"The sandboxing tools offer great prevention for cloud feeds."
"It is a stable product."
"It's a monster, it's got so many beautiful features. We do deal with other firewalls and we've got a better idea of what other firewalls' capabilities are, any comparison with the Palo Alto I liked the quality of service on the applications that you can control the amount of bandwidth an application is allowed to consume. The best feature is the quality of the application quality of service."
 

Cons

"One area that confused me a bit when I was building my current network. I use VLANs to have separate functionality on the network, and the appliance I got was the WiFi model, but I discovered that you can't assign WiFi channels to the VLAN. So, you can have WiFi, but its own subnet. You can't run that over the VLAN. Effectively, I can't use the WiFi facility in the appliance and had to purchase a separate web that supports VLANs. In the end, I had to go to GFI support. They confirmed this is just a limited functionality of that device, as it is a low-end device. I don't know if any of their high-end models have a better facility or not."
"I would like to be able to inspect https packets for the purpose of virus scanning."
"I would like for there to be a difference between international and national links."
"The upgrades make the network slower."
"I would like to see them develop a bit more flexibility creating VLANs."
"I have had a few issues with HTTPS decryption. The solution also does not show the actual user's Internet usage."
"They should improve the remote connectivity feature for users."
"The logs could be improved for better clarity."
"I think they can use some improvement on FID."
"In terms of what needs improvement, the only thing I don't like is the support."
"We are attempting to improve the use of URL filtering beyond threat protection."
"The documentation needs to be improved. I need better information about how to configure it and what the best practices are."
"Sometimes when you want to group a set of ports, and communicate with Palo Alto, you cannot group TCP and UDP ports together. This needs to be adjusted."
"The initial setup is complex."
"The application’s pricing and dashboard need improvement. It could be user-friendly."
"The cost involves the price of the hardware, which is expensive. However, most of the Palo Alto solutions are expensive."
 

Pricing and Cost Advice

"It is a good fit for SMBs because of its maintainability. When you want to keep your costs low, then Kerio Control is a very good solution. It's not an expensive product that is well integrated. It has a complete set of features within it that make it a very strong product."
"We have to pay approximately EUR 175 for the product."
"I am living in Iran and we cannot buy the product from Kerio because of sanctions."
"The price of Kerio Control could be better, it is a bit overpriced compared to other solutions."
"Its licensing is yearly. You renew every year. Its price is all-inclusive."
"The price is fine."
"I pay approximately $50 for the solution on an annual basis."
"Its initial cost is less as compared to other products. It becomes a bit costly when you pay for the products that you don't use. We paid for almost all the products through subscription, but we are using only a few products. We use EndPointSecurity, Kerio Connect, WebMonitor, and LanGuard. We don't use the rest of the products."
"The pricing and the licensing are pretty competitive at this stage. As a reseller, I would like to see the price come down a little bit so I can compete better against other firewalls because we do that all the time."
"The product’s pricing is expensive for small companies."
"The pricing has improved with the newer generation of their Firewalls, but the price could always be lower."
"There is an initial, expensive investment but the return is good."
"Palo Alto Networks Threat Prevention could improve by having consistent pricing at system levels."
"It's not too expensive."
"It is an expensive solution and I would like to see a drop in price."
"If you want to have all of the good features then you have to pay extra for licensing."
report
Use our free recommendation engine to learn which Intrusion Detection and Prevention Software (IDPS) solutions are best for your needs.
849,190 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
23%
Comms Service Provider
9%
Financial Services Firm
9%
Media Company
8%
Computer Software Company
16%
Financial Services Firm
10%
Manufacturing Company
10%
Government
9%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about KerioControl?
The solution provides feasibility regarding cyber privacy.
What is your experience regarding pricing and costs for KerioControl?
KerioControl offers good pricing as one license covers all features needed without extra payment. The price for the product is rated as ten out of ten.
What needs improvement with KerioControl?
The logs could be improved for better clarity. It is difficult to understand when there is a threat attack, and handling firmware requires experience.
Which is the best DDoS protection solution for a big ISP for monitoring and mitigating?
Arbor would be the best bid, apart from Arbor, Palo Alto and Fortinet have good solutions. As this is an ISP, I would prefer Arbor.
What is your experience regarding pricing and costs for Palo Alto Networks Threat Prevention?
The pricing is competitive, and with current campaigns and discounts, it provides an excellent device for a reasonable price.
 

Overview

 

Sample Customers

Triton Technical, McDonald's
University of Arkansas, JBG SMITH, SkiStar AB, TRI-AD, Temple University, Telkom Indonesia
Find out what your peers are saying about KerioControl vs. Palo Alto Networks Advanced Threat Prevention and other solutions. Updated: April 2025.
849,190 professionals have used our research since 2012.