Try our new research platform with insights from 80,000+ expert users

OPNsense vs Palo Alto Networks PA-Series comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Sep 16, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Fortinet FortiGate
Sponsored
Ranking in Firewalls
2nd
Average Rating
8.4
Reviews Sentiment
7.2
Number of Reviews
327
Ranking in other categories
Software Defined WAN (SD-WAN) Solutions (1st), WAN Edge (1st)
OPNsense
Ranking in Firewalls
3rd
Average Rating
8.2
Reviews Sentiment
7.2
Number of Reviews
39
Ranking in other categories
No ranking in other categories
Palo Alto Networks PA-Series
Ranking in Firewalls
15th
Average Rating
8.6
Reviews Sentiment
7.3
Number of Reviews
32
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of April 2025, in the Firewalls category, the mindshare of Fortinet FortiGate is 21.1%, up from 17.7% compared to the previous year. The mindshare of OPNsense is 12.3%, down from 17.6% compared to the previous year. The mindshare of Palo Alto Networks PA-Series is 0.5%, up from 0.1% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Firewalls
 

Featured Reviews

EhabAli - PeerSpot reviewer
Efficient, user-friendly, and affordable
In the past, NSS Labs was utilized to test files and verify the numbers and datasheets. It would be beneficial to have an organization or testing lab that can verify the numbers in our datasheets since changes are frequently made, which can be inconvenient for review. For instance, when comparing different competitors such as Forcepoint, Palo Alto, and Check Point, the throughput or numbers in the datasheet may be lower than the actual numbers. Conversely, Fortinet typically reports very high numbers, but they cannot be replicated in the real world. Therefore, it would be advantageous for them to partner with a neutral testing organization such as NSS Labs to validate these numbers, thus providing more credibility and comfort to everyone regarding the accuracy of the datasheets. For the migration, everyone has a firewall in use and I am selling Fortinet. Typically, I am replacing another firewall. Previously, there was a tool available to convert configurations from one firewall, such as Palo Alto, to Fortinet, but this tool is no longer free. If it could be made free again, it would be very beneficial. This tool shows a lot of promise and is very good. Making it free would help many companies deliver their products in a more efficient and integrated way. It would also be more valuable to include the tool with the firewall package or license instead of having to pay extra for it. Paying extra puts more pressure on small companies to deliver the firewall and complete the configuration, especially if they have hundreds or thousands of policies. It's very painful to move through these policies line by line. The stability has room for improvement. When it comes to Secure SD-WAN, everything is fine. They are going the right way. SD-WAN is very promising. They can provide the SD-WAN solution separately, but they will not take this approach because even the smallest firewall can support the features, so there is no need to have a separate service or appliance. They are following the right steps, and there is nothing to be improved. Feature-wise, I'm really satisfied with the new release, and the features they have added. For now, it's fine.
Eddy Ramirez - PeerSpot reviewer
Good interface and firewall capabilities and overall easy to use
The security has improved as we can isolate the network. We can do attrition prevention via a tool that comes with the solution. We can have a VPN solution in place for those that work from home, outside the network, in a secure manner. We also like that it offers good authentication. It offers radius-based authentication, which has been useful for the company. The main platform is under the Open VPN firewall. The solution has high availability. When we have different ISPs, we can actually load balance those links or actually put some priority or even classify the traffic that might go into one ISP or another.
Deminda Dilan - PeerSpot reviewer
Good for enterprise-level businesses and offers many features like URL filtering and antivirus capabilities
Palo Alto can improve the web application firewall (WAF) feature at layer 7. Currently, I don't think it's available. If they can improve that, it would be better. We wouldn't need to purchase a separate WAF solution because they already have advanced URL filtering. But I don't think that advanced URL filtering has the same features as a dedicated WAF, like F5 or other solutions. That is an area for improvement. If they can improve the WAF feature, customers won't have to buy a separate WAF solution. They could do it with the same Palo Alto firewall, perhaps through a subscription-based model. So the web application firewall feature has to be improved.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Fortinet FortiGate meets all the security demands of my industry. It covers endpoint security, including web interface, DNS security, and ELP. I'm currently using the latest version. The features that have most improved our network security are Web Control, filtering, application control, IDS, IPS policies, and Deep SSL inspection."
"The dashboard I have found the most valuable in Fortinet FortiGate."
"The most valuable feature of this solution is Quota."
"FortiGate SD-WAN facilitated a smooth transition for our customers between their two internet service providers, ensuring uninterrupted connectivity without any downtime."
"The most valuable feature is the web filter."
"The main benefit is the grouping of our security monitoring."
"It increases security posture and is helpful for firewall reporting, intrusion protection, web filtering, and SD-WAN implementation."
"Allows for firewall rules to be programmed and named in a way that makes it “readable”"
"OPNsense is easy to use and open source."
"It is a very good solution. I like the dashboard. I can see what is going on and manage it as I like it."
"The technical support is very good."
"It has firewall and VPN capabilities, which are very valuable features."
"OPNsense is easy to scale when running on the hardware."
"The most valuable features of OPNsense are the GUI and frequent updates."
"One of the most valuable features is the network checking. Additionally, the firewall and web filtering functionalities are highly useful."
"OPNsense is highly stable."
"The solution provides good customer support."
"A valuable feature that we can consider is the deployment time, which is significantly reduced. It is almost 90% faster compared to other solutions."
"A valuable feature that we can consider is the deployment time, which is significantly reduced, almost 90% faster compared to other solutions. This leads to quicker deployment and less downtime."
"It offers a seamless transition from one option to another, making it exceptionally versatile and user-friendly in an enterprise setting."
"App-ID is a really good feature."
"Palo Alto has predefined applications that you can control at the application level."
"The tool's most valuable feature is WildFire."
"It offers application-based policy enforcement. Palo Alto Networks firewalls help us recognize protocol anomalies, contrasting with other vendors that may require policies based on port numbers. With Palo Alto Networks, the port number isn't a constraint because their devices handle protocol traffic at Layer 7, allowing for accurate identification of protocol usage and port numbers. They can identify which protocol actually uses which port."
 

Cons

"Its filtering is sometimes too precise or strict. We sometimes have to bypass and authorize some of the sites, but they get blocked. We know that they are trusted sites, but they are blocked, and we don't know why."
"FortiGate is really good. We have been using it for quite some time. Initially, when we started off, we had around 70 plus devices of FortiGate, but then Check Point and Palo Alto took over the place. From the product perspective, there are no issues, but from the account perspective, we have had issues. Fortinet's presence in our company is very less. I don't see any Fortinet account managers talking to us, and that presence has diluted in the last two and a half or three years. We have close to 1,500 firewalls. Out of these, 60% of firewalls are from Palo Alto, and a few firewalls are from Check Point. FortiGate firewalls are very less now. It is not because of the product; it is because of the relationship. I don't think they had a good relationship with us, and there was some kind of disconnect for a very long time. The relationship between their accounts team and my leadership team seems to be the reason for phasing out FortiGate."
"There are a lot of bugs I have found in the solution and it is difficult to upgrade. These areas need improvement."
"One issue that I have had is that sometimes I need to monitor the traffic, so I need to filter it according to the user and which user is using it the most. I experience a bottleneck most of the time, particularly at the peak time when the number of contracts and users are at maximum."
"The stability could be a bit better."
"The sniffing packets or packet captures, can be simplified and improved because it's a little confusing."
"I think there could be more QoS features"
"A sandbox would be good in order to be able to inspect the emails containing spam and be able to validate the emails that contain malware, prior to delivering to the customer."
"While they do have paid options that actually gives better features, for most of the clients, if they tend to take a paid option will instead opt for Fortinet."
"The reporting part could be better."
"I would like better documentation concerning the provided packages and their integration."
"There should be more technical documentation."
"OPNsense showed me some problems when using it in different environments. The problem is integration with a virtual server."
"I would like to see better SD-WAN performance."
"The only thing that I would like to see improved is the Insight or the NetFlow analysis part. It would be good to have the possibility to dig down on the Insight platform. Right now, we can easily do only a few analyses. If this page becomes more powerful, it surely will be a well-adopted platform."
"There is room for improvement in SSL inspection."
"The product must provide multiple threat detection features."
"The technical support offered by Palo Alto is an area of concern where improvements are required."
"The support provided by the solution is not that good."
"The product's gateway services can be improved."
"The pricing of the solution needs improvement."
"I had opened a case before with the tool because I could not create a wildcard for the security address. We can create wildcards for security addresses in Fortinet, but this feature doesn't exist in the product."
"The product's high prices are an area of concern where improvements are required."
"There seem to be some issues with TAC (Technical Assistance Center) or Palo Alto support. Anytime you open a case, a level one engineer joins, and then you have to escalate it to level two or three. The support system has changed in the past few years, and that's something they need to look into."
 

Pricing and Cost Advice

"You need to pay a license for this solution. Our licensing is now done in our subsidiary."
"The price for the device and software is high. However, the solution is of good quality and has a lot of features."
"The price of Fortinet FortiGate is better than Cisco, Check Point, and Palo Alto. In terms of pricing, it's probably a better-priced firewall solution overall."
"For the price, I'd rate it a ten because it's very cost-effective."
"Licensing is usually on a three-year period."
"The licensing costs are very low."
"If the customer is looking for SD-WAN, it comes free with FortiGate."
"The license of Fortinet FortiGate should be reduced."
"I would rate the pricing three out of ten."
"Its pricing is unbeatable in comparison to other firewalls. You can have a small instance that could be €80 a month with the hardware underneath. Azure Firewall and FortiGate are out of the question at this price. If you are on a public cloud, you need the underlying infrastructure. Other than that, there is no additional cost. If you have it on-prem, you have to buy the server or the appliance. The hardware cost is replaced with the infrastructure cost in the cloud. You also have costs for the public IPs and underlying VMs, but that's not related to OPNsense. It would be the same for a FortiGate deployment on Azure. You need a FortiGate license, and you need the underlying infrastructure that scales up depending on your needs."
"The solution is not expensive."
"It is free."
"OPNsense is an open-source solution and it is free to use."
"It is not an expensive product. Basically, I deployed it because it was the fastest solution to satisfy our needs in open source."
"OPNsense is a well known open-source tool."
"We are not paying any licensing fees. OPNsense is completely free for us."
"Palo Alto Networks PA-Series's price is much higher than other firewall brands."
"From my perspective, managing the price is important, especially because we're a small business. For larger organizations like Barclays, we provide our requirements to the client, and they place the order on BigFix. It's their responsibility to consider their budget and make decisions accordingly. We appreciate the features we get, but the cost-sharing still depends on the client."
"We have to pay a yearly licensing fee for the solution."
"The tool's pricing was reasonable when we bought the product. We pay around 60,000 dollars per year."
"The product is offered to users at high prices compared to the pricing model of the other vendors in the market."
"Compared to other vendors, Palo Alto Networks PA-Series is expensive."
"Price-wise, Palo Alto offers high-price products."
"The solution's pricing is high compared to that of Cisco and Fortinet."
report
Use our free recommendation engine to learn which Firewalls solutions are best for your needs.
847,862 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Educational Organization
21%
Computer Software Company
14%
Comms Service Provider
7%
Manufacturing Company
6%
Computer Software Company
16%
Comms Service Provider
13%
Government
7%
Educational Organization
6%
Computer Software Company
17%
Manufacturing Company
13%
University
8%
Comms Service Provider
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

Which is the better NGFW: Fortinet Fortigate or Cisco Firepower?
When you compare these firewalls you can identify them with different features, advantages, practices and usage a...
What is the biggest difference between Sophos XG and FortiGate?
From my experience regarding both the Sophos and FortiGate firewalls, I personally would rather use FortiGate. I know...
What are the biggest technical differences between Sophos UTM and Fortinet FortiGate?
As a solution, Sophos UTM offers a lot of functionality, it scales well, and the stability and performance are quite ...
What is the difference between PfSense and OPNsense?
Two of the most common and well recognized firewalls, PfSense and OPNsense both support site-to-site IPsec VPN and cl...
What do you like most about OPNsense?
What I like the most about OPNsense is that it offers an easy-to-use dashboard for device management and control.
What is your experience regarding pricing and costs for OPNsense?
I consider the pricing of OPNsense to be high when compared with other market products. However, as a free firewall p...
What do you like most about Palo Alto Networks PA-Series?
The reporting feature and application ID functionality within Palo Alto Networks PA-Series are incredibly valuable to...
What needs improvement with Palo Alto Networks PA-Series?
The interface of Palo Alto Networks PA-Series should be made much more user-friendly.
 

Also Known As

FortiGate 60b, FortiGate 60c, FortiGate 80c, FortiGate 50b, FortiGate 200b, FortiGate 110c, FortiGate, Fortinet Firewall
No data available
No data available
 

Overview

 

Sample Customers

Amazon Web Services, Microsoft, IBM, Cisco, Dell, HP, Oracle, Verizon, AT&T, T-Mobile, Sprint, Vodafone, Orange, BT Group, Telstra, Deutsche Telekom, Comcast, Time Warner Cable, CenturyLink, NTT Communications, Tata Communications, SoftBank, China Mobile, Singtel, Telus, Rogers Communications, Bell Canada, Telkom Indonesia, Telkom South Africa, Telmex, Telia Company, Telkom Kenya
1. Deciso B.V. 2. iXsystems, Inc.  3. EuroBSDCon  4. Netgate  5. Claranet  6. Voleatech  7. Open Systems AG  8. Securebit AG  9. Proxmox Server Solutions GmbH  10. AVM Computersysteme Vertriebs GmbH  Additional customers include: T-Systems International GmbH, Deutsche Telekom AG, Vodafone GmbH, 1&1 IONOS SE, OVHcloud, Hetzner Online GmbH, Strato AG, PlusServer GmbH, Host Europe GmbH, United Internet AG, 1&1 Versatel Deutschland GmbH, QSC AG, Bechtle AG, Cancom SE, Computacenter AG & Co. oHG, T-Systems Multimedia Solutions GmbH, Atos SE, Capgemini SE, Accenture plc, IBM Corporation, Hewlett Packard Enterprise Company, Cisco Systems, Inc.
Information Not Available
Find out what your peers are saying about OPNsense vs. Palo Alto Networks PA-Series and other solutions. Updated: April 2025.
847,862 professionals have used our research since 2012.