Try our new research platform with insights from 80,000+ expert users

Palo Alto Networks NG Firewalls vs Sophos XG comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Sep 29, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Customer Service

Sentiment score
7.0
Fortinet FortiGate's customer service is responsive and helpful, though technical support experiences vary and can be inconsistent.
Sentiment score
7.5
Palo Alto Networks support is knowledgeable but varies; users desire quicker responses and face communication challenges and mixed satisfaction.
Sentiment score
6.1
Sophos XG's support is knowledgeable but often slow and inefficient, especially during the pandemic, with mixed user experiences.
The response time for a critical priority one issue was over four hours and they only responded because we threatened legal action for them violating our support contract.
They say they will respond in 24 hours, but I have received responses in a maximum of one hour, which is impressive.
The technical support from Fortinet FortiGate is 24 hours a day seven days a week, and 365 days a year.
Their response time is within one hour.
Palo Alto offers multiple tiers of support, including basic, premium, and premium plus.
Support is a challenge as the response time is long
Sophos provides online documentation which is very user friendly.
We are also trying to keep up on how the hackers work because we are working with different associations of security worldwide.
On a scale from one to ten, I would give Sophos support a ten.
 

Room For Improvement

Sentiment score
4.6
Fortinet FortiGate needs better documentation, UI, integration, troubleshooting tools, scalability, reporting, and reduced impact on performance and fees.
Sentiment score
4.7
Palo Alto Networks NG Firewalls need improvements in pricing, support, integration, UI, reporting, VPN, and security features.
Sentiment score
4.4
Enhance network security, simplify interface, improve VPN, documentation, cloud integrations, reporting, firmware updates, user management, and vendor integration.
FortiWAN supports OSPF but does not support the BGP protocol.
Fortinet VPN and DDoS capabilities are great, yet we need to provide a solution that enables CASB and integration to the cloud.
The relationship between their accounts team and my leadership team seems to be the reason for phasing out FortiGate.
Palo Alto Networks NG Firewalls lack built-in multi-factor authentication, requiring the purchase of a third-party tool to implement this essential security feature.
Configurations related to different operating systems can be complex, and we have encountered issues with Linux systems.
Palo Alto recently introduced a security analyzer in version ten, but this feature could be enhanced.
The developers should test everything after any update to ensure that bugs don't come through with the update.
There are times that I really want to know which user or which IP is causing a problem.
If they could incorporate some user profiling and present the analytics of the login user usage patterns, or a typical proper management dashboard to take a decision on the firewall rules, that would be useful.
 

Scalability Issues

Sentiment score
7.1
Fortinet FortiGate provides effective scalability and adaptability, though careful budgeting and upgrades are needed for high-demand scenarios.
Sentiment score
7.4
Palo Alto Networks NG Firewalls offer varying scalability; effective for large organizations, but costly for smaller enterprises.
Sentiment score
7.3
Sophos XG is praised for scalable solutions suited for small to large enterprises, albeit sometimes needing new hardware for extensive scaling.
The devices will usually fail way before reaching the capacity advertised in the data sheets, especially when you activate several of the features the device can handle.
The solution is working and it is still stable even across all of these devices and servers.
We have over 10,000 users behind it.
Cloud deployments benefit from auto-scaling, allowing for automatic adjustments to firewall capacity based on demand.
In other words it doesn't have that modularity feature.
We do have plans to increase usage because we are growing our projects around the world to countries like the US, Germany, Pakistan, India, UAE (Dubai) and Egypt.
You've got to define the criteria in terms of what you're trying to protect, the number of users, the bandwidth that is going through it, the speed, etc.
 

Setup Cost

Sentiment score
7.6
Fortinet FortiGate's initial costs are high, but offers competitive pricing and value compared to Cisco and Palo Alto.
Sentiment score
7.0
Palo Alto Networks NG Firewalls offer advanced, reliable security at a high cost, but deliver strong value for enterprise needs.
Sentiment score
7.2
Sophos XG provides competitive, mid-range pricing and flexible licensing, ideal for small to medium-sized businesses with available discounts.
The cost of the original deployment fell below £5,000, and licenses are priced at around £3,000.
Every time you upgrade your license, you also get insurance for the equipment.
Overall, FortiGate is affordable.
Palo Alto Networks NG Firewalls come at a premium, exceeding the cost of most competitors by 45 percent.
While Palo Alto Networks Next-Generation Firewalls may be considered expensive, their quality justifies the cost.
Palo Alto Networks NG Firewalls are more expensive than Cisco firewalls, but slightly less expensive than Juniper firewalls.
One way they are doing this is by having an aggressive pricing policy.
There are no additional fees on top of this.
The option to get a combo with hardware means the software portion is mostly free, and then you pay upfront for the three-year license for everything.
 

Stability Issues

Sentiment score
7.9
Fortinet FortiGate is highly stable and reliable, with improved performance in newer versions, praised for its consistent robustness.
Sentiment score
8.2
Palo Alto Networks NG Firewalls offer superior stability and reliability, with high availability minimizing downtimes and ensuring performance.
Sentiment score
8.0
Sophos XG is generally stable and reliable, with occasional issues resolved quickly, receiving stability ratings of 7-10.
All of these issues were resolved in v5.2.
Stability has dramatically improved over the previous main version branch of FortiOS; 5.2.x and 5.4.x are stable enough for critical environments.
Overall, the devices have been very stable.
Palo Alto Networks NG Firewalls are stable and reliable when deployed and configured correctly.
Palo Alto Networks NG Firewalls are stable.
Sophos' support is very good to correct quickly, ASAP.
There isn't crashing or freezing.
It may be possible to implement a second device in a fail-over cluster and this would avoid such a problem as then if one device fails in the updating process, the other device could take over.
 

Valuable Features

Sentiment score
8.0
Fortinet FortiGate is valued for its robust security, ease of use, scalability, and comprehensive threat management features.
Sentiment score
8.5
Palo Alto Networks NG Firewalls offer advanced security, application visibility, and seamless integration, making them a reliable network security choice.
Sentiment score
8.2
Sophos XG offers traffic prevention, endpoint isolation, intuitive interface, detailed logs, SSL VPN, firewall integration, malware scanning, and central management.
The two most valuable features are VPN and firewalling.
WiFi network for visitors isolated from our corporate WiFi network using only one unit
Allows for firewall rules to be programmed and named in a way that makes it 'readable'
These next-generation firewalls are application-centric, identifying specific applications to provide enhanced security against a wider range of attacks.
We utilize nearly all the features of Palo Alto Networks NG Firewalls, including threat detection and anti-spyware capabilities.
The most valuable aspect of Palo Alto Networks NG Firewalls is the performance.
Anti-malware: Sophos XG comes with two anti-malware engines: its own and Avira, making the UTM more effective at catching malicious code.
If my file is getting infected, I get to know from a single pane point of view.
The user interface is very user-friendly, so it's very easy for the administrator to make any policy changes.
 

Categories and Ranking

Fortinet FortiGate
Sponsored
Ranking in Firewalls
2nd
Average Rating
8.4
Reviews Sentiment
7.2
Number of Reviews
316
Ranking in other categories
Software Defined WAN (SD-WAN) Solutions (1st), WAN Edge (1st)
Palo Alto Networks NG Firew...
Ranking in Firewalls
7th
Average Rating
8.6
Reviews Sentiment
7.4
Number of Reviews
183
Ranking in other categories
No ranking in other categories
Sophos XG
Ranking in Firewalls
4th
Average Rating
8.2
Reviews Sentiment
7.0
Number of Reviews
196
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of November 2024, in the Firewalls category, the mindshare of Fortinet FortiGate is 19.8%, up from 17.1% compared to the previous year. The mindshare of Palo Alto Networks NG Firewalls is 3.3%, up from 3.2% compared to the previous year. The mindshare of Sophos XG is 11.3%, up from 8.8% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Firewalls
 

Q&A Highlights

NC
Nov 17, 2021
 

Featured Reviews

DineshKumar28 - PeerSpot reviewer
Effective threat prevention with responsive customer support
We are using Fortinet FortiGate as a firewall Fortinet FortiGate has been invaluable. It has helped save costs due to its various features, reliable performance, very good UI, low latency, and stability. The Threat Intel engine in Fortinet FortiGate is highly rated for its effectiveness in…
Simon Webster - PeerSpot reviewer
We get reports back from WildFire on a minute-by-minute basis
The biggest thing that needs to be improved with them is their training. I took a training class for the 8.0 build, then I took it again for the 9.0 and 10 builds. They add new features every time that they do a new major release, but the training doesn't keep up. It is the same basic training that probably was with the 3.0 build, and they just change the screenshots. I would love to see them do some more work since they have all these bells and whistles, but we don't know how to use those features on a large scale. I know this little section here about the firewall, but I know there is a huge amount that still could be done with it. I am not touching enough of it because I just don't know how. It seems like the more I learn about it, the more I learn that there is to learn
Akshay Y P - PeerSpot reviewer
Has good technical support services, but the GUI needs enhancement
The product’s new variant allows for faster processing of data packets from LAN to WAN, surpassing the capabilities of an 8G firewall. It provides threat prevention features, including WAF, IPS, and AV. We have configured SSL VPN capabilities for different branches, which have been working efficiently. For our minimalistic usage, it has been performing well in transferring data from on-premise devices. It helps us generate detailed reports on the dashboard. The product’s integration with Sophos Central enhances security architecture by enabling centralized management under a single dashboard. We recommend Sophos XG as a priority as it is much more reliable and has efficient technical assistance. It is much easier for configuration, web filtering, or web extension than one of its competitors. I rate it a seven out of ten.
report
Use our free recommendation engine to learn which Firewalls solutions are best for your needs.
816,192 professionals have used our research since 2012.
 

Answers from the Community

NC
Nov 17, 2021
Nov 17, 2021
Palo Alto Networks NG Firewalls have both great features and performance. I like that Palo Alto has regular threat signatures and updates. I also appreciate that I can just import addresses and URL objects from the external server. Palo Alto has a dedicated management interface, which makes it easy to manage the device and handle the initial configuration. It has fantastic throughput and its co...
See 2 answers
CL
Oct 19, 2021
As a Sophos specialist, I can tell you that XG Firewall will cover all that you'll need with a more affordable way.Sophos XG firewall will not disappoint you with its performance, resources or features.
Janet Staver - PeerSpot reviewer
Nov 17, 2021
Palo Alto Networks NG Firewalls have both great features and performance. I like that Palo Alto has regular threat signatures and updates. I also appreciate that I can just import addresses and URL objects from the external server. Palo Alto has a dedicated management interface, which makes it easy to manage the device and handle the initial configuration. It has fantastic throughput and its connection speed is pretty fair, even when dealing with a high traffic load. With Palo Alto I can configure and manage with REST API integration. And Palo Alto provides deep visibility into your network activity via Application and Command Control. Although Palo Alto has great things going for it, there are a few things I dislike about it. For example, when the CPU is 100%, the GUI can take a very long time to respond. Booting time is also time-consuming, and committing the configuration takes more time than I would like it to. Like Palo Alto, Sophos XG is quick and easy to configure. It is compact in size, and therefore does not weigh a lot either. Similar to Palo Alto as well, it can handle heavy traffic and has a solid performance. A good thing about Sophos XG is that it supports IPsec connection with multiple vendor firewalls. However, I am not impressed with the CLI which is not so useful, and I don’t like that there is no option to import bulk address objects. Conclusion: Palo Alto Networks NG Firewalls and Sophos XG are both good products. However, Palo Alto has certain features I really like and that’s why I chose it. For me, Palo Alto’s dynamic address group option is a big advantage because it is a huge time saver instead of having to create address groups manually. Another biggie for me was its DNS Sinkhole feature because it is something I rely on a lot and it is very effective in blocking C2 command control traffic.
 

Top Industries

By visitors reading reviews
Educational Organization
22%
Computer Software Company
15%
Manufacturing Company
6%
Comms Service Provider
6%
Computer Software Company
15%
Financial Services Firm
10%
Manufacturing Company
8%
Government
7%
Computer Software Company
17%
Comms Service Provider
8%
Manufacturing Company
7%
Government
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

Which is the better NGFW: Fortinet Fortigate or Cisco Firepower?
When you compare these firewalls you can identify them with different features, advantages, practices and usage a...
What is the biggest difference between Sophos XG and FortiGate?
From my experience regarding both the Sophos and FortiGate firewalls, I personally would rather use FortiGate. I know...
What are the biggest technical differences between Sophos UTM and Fortinet FortiGate?
As a solution, Sophos UTM offers a lot of functionality, it scales well, and the stability and performance are quite ...
What is a better choice, Azure Firewall or Palo Alto Networks NG Firewalls?
Azure Firewall Vs. Palo Alto Network NG Firewalls Both solutions provide stellar stability and security. Azure Firew...
Features comparison between Palo Alto and Fortinet firewalls
In the best tradition of these questions, Feature-wise both are quite similar, but each has things it's better at, it...
Which is better - Palo Alto Networks NG Firewalls or Sophos XG?
Palo Alto Networks NG Firewalls have both great features and performance. I like that Palo Alto has regular threat si...
What are the main differences in features between Sophos XG and FortiGate 80F?
Hi Arvind P , The Sophos XG firewall has a number of models right from XG86 to XG135w under the 1U Desktop Form Fact...
What Is The Biggest Difference Between Sophos UTM and Sophos XG?
The Sophos UTM is a UTM and Sophos XG is the NGFW. First, you must know about the difference between a UTM and NGFW. ...
 

Also Known As

FortiGate 60b, FortiGate 60c, FortiGate 80c, FortiGate 50b, FortiGate 200b, FortiGate 110c, FortiGate
Palo Alto NGFW, Palo Alto Networks Next-Generation Firewall
No data available
 

Overview

 

Sample Customers

Amazon Web Services, Microsoft, IBM, Cisco, Dell, HP, Oracle, Verizon, AT&T, T-Mobile, Sprint, Vodafone, Orange, BT Group, Telstra, Deutsche Telekom, Comcast, Time Warner Cable, CenturyLink, NTT Communications, Tata Communications, SoftBank, China Mobile, Singtel, Telus, Rogers Communications, Bell Canada, Telkom Indonesia, Telkom South Africa, Telmex, Telia Company, Telkom Kenya
SkiStar AB, Ada County, Global IT Services PSF, Southern Cross Hospitals, Verge Health, University of Portsmouth, Austrian Airlines, The Heinz Endowments
Information Not Available
Find out what your peers are saying about Palo Alto Networks NG Firewalls vs. Sophos XG and other solutions. Updated: October 2024.
816,192 professionals have used our research since 2012.