Try our new research platform with insights from 80,000+ expert users

Palo Alto Networks PA-Series vs WatchGuard Firebox comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Sep 16, 2024
 

Categories and Ranking

Fortinet FortiGate
Sponsored
Ranking in Firewalls
2nd
Average Rating
8.4
Reviews Sentiment
7.2
Number of Reviews
317
Ranking in other categories
Software Defined WAN (SD-WAN) Solutions (1st), WAN Edge (1st)
Palo Alto Networks PA-Series
Ranking in Firewalls
14th
Average Rating
8.6
Reviews Sentiment
7.2
Number of Reviews
31
Ranking in other categories
No ranking in other categories
WatchGuard Firebox
Ranking in Firewalls
12th
Average Rating
8.4
Reviews Sentiment
7.5
Number of Reviews
85
Ranking in other categories
Unified Threat Management (UTM) (4th)
 

Featured Reviews

DineshKumar28 - PeerSpot reviewer
Effective threat prevention with responsive customer support
We are using Fortinet FortiGate as a firewall Fortinet FortiGate has been invaluable. It has helped save costs due to its various features, reliable performance, very good UI, low latency, and stability. The Threat Intel engine in Fortinet FortiGate is highly rated for its effectiveness in…
Deminda Dilan - PeerSpot reviewer
Good for enterprise-level businesses and offers many features like URL filtering and antivirus capabilities
Palo Alto can improve the web application firewall (WAF) feature at layer 7. Currently, I don't think it's available. If they can improve that, it would be better. We wouldn't need to purchase a separate WAF solution because they already have advanced URL filtering. But I don't think that advanced URL filtering has the same features as a dedicated WAF, like F5 or other solutions. That is an area for improvement. If they can improve the WAF feature, customers won't have to buy a separate WAF solution. They could do it with the same Palo Alto firewall, perhaps through a subscription-based model. So the web application firewall feature has to be improved.
CarlosArdila - PeerSpot reviewer
Serves as the main firewall for customers' premises and data centers
The initial setup is straightforward. You can deploy it on-premises or using the cloud. If you configure the device to connect to the cloud, you can deploy the Firebox based on templates. You can add a template for a specific client and deploy it for a particular use case. For example, if you're setting it up for a restaurant or a cafe, you can have templates tailored for those businesses. This significantly reduces deployment time, especially if you have several customers of the same type of business. One person is enough for the solution's deployment, but it will run in less than an hour. A network security engineer meets with clients to gather configuration requirements. He prepares a configuration template before the implementation. When he arrives at the site, he turns on the device, applies the template, tests everything, and then migrates the settings from the existing router or firewall to the Firebox.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Its user interface is good, and it is always working fine."
"It is easy to manage, and it doesn't need much knowledge from the team. It is a stable device, and there are many features that are included out of the box."
"It's very easy to configure."
"The tool is a nice product and easy to handle. The software's user interface is also good. You can easily implement remote access in the solution."
"The Fortinet FortiGate local partners were good. I did not have direct contact with Fortinet support."
"The solution is stable."
"The IPsec tunnels are very easily created, and quite interoperable with devices from other vendors."
"FortiGate has led to a reduction in our security budget."
"The cloud-based aspect helps significantly. It integrates seamlessly with other Palo products like Prisma Cloud, offers robust VPN protection, and it's all in one convenient package."
"It is a stable solution. Stability-wise, I rate the solution a ten out of ten."
"I rate the stability as ten out of ten."
"It has its own logging system. You can go to monitoring and check the logs to see if a connection is getting blocked. You can use multiple types of logs to check if a file or a port is getting blocked or if there are any TCP resets from the source or destination. It's easy to troubleshoot with the monitoring and logging it provides."
"It is scalable. But that depends on what model you are using."
"The solution is robust."
"The solution is used for security and IoT security."
"The solution is easy to manage."
"WatchGuard has a very easy VPN and branch office VPN setup, so we use those pretty extensively."
"The set up of the VPN is pretty straightforward. Being able to build VPNs on the fly for certain users, if need be, is also valuable."
"I like their management features a lot. Their System Manager server as well the System Manager software make managing them, and tracking changes, very easy and complete."
"Among the most valuable features is the ease of use — love the interface — of both the web interface and of the WatchGuard System Manager."
"One of my favorite features is the Geolocation service, where you can actually block specific activity or IP addresses registered to certain countries. For example, I don't want any web traffic from Russia or North Korea. I may even lock down certain policies down to 'I only want U.S. IP addresses.' I find that very useful."
"The solution simplifies my business. Normally, for administration, we are using NetApp System Manager on Window since it's easy to create new policies. In a short amount of time, you can create new policies based on new requirements. For example, in the last few months, many requirements changed due to the coronavirus, adding the use of new services, like Office 365, and eLearning tools, like Zoom."
"It's very easy to use, especially compared to similar products. A lot more users use the WatchGuard appliance now than use the SonicWall appliance because of the ease of usability."
"I like that this product has very few issues."
 

Cons

"There's always something new that can be added or fixed."
"The solution needs to improve its integration with cybersecurity."
"This product needs to have an analysis feature, rather than having the analysis done through the integration of a different product."
"The renewal price and the availability could be improved."
"I think that the infrastructure for the VPN could be improved. The way that it is bundled also made it difficult to use and sell as it is too expensive."
"One issue that I have had is that sometimes I need to monitor the traffic, so I need to filter it according to the user and which user is using it the most. I experience a bottleneck most of the time, particularly at the peak time when the number of contracts and users are at maximum."
"There are just some services that aren't available. For example, the Ethernet or point-to-point protocols. They could add these services to their product offering - especially services for ISPs."
"Lacks sufficient security options."
"The technical support offered by Palo Alto is an area of concern where improvements are required."
"The product's high prices are an area of concern where improvements are required."
"There are constant updates for the operating system. It is a nice thing also, but it has its own disadvantages. Continuous updates are there. The users face issues like, how often do I need to update that? Within a period of five months, I'm updating it two or three times. It gives them a feeling that they are not confident about their product and have to update it so frequently."
"Pricing flexibility could be an aspect worth considering, as it has been a concern for some of our clients."
"The UI definitely needs work. In my opinion, the UI could be simpler and more user-friendly for the average user."
"Palo Alto Networks PA-Series is complicated to configure compared to one of its competitors."
"There is room for improvement in streamlining this process for smoother transitions."
"Palo Alto should integrate artificial intelligence for security purposes in the background for well-known threats and new risks coming to the market."
"The software base, the management piece that goes onto a server, is not as user-friendly as I would like. There are three different pieces that you have to manage, so it's a little bit convoluted, in my opinion."
"The data loss protection works well, but it could be easier to configure. The complexity of data loss protection makes it a more difficult feature to fully leverage. Better integration with third-party, two-factor authentication would be advantageous."
"We use WatchGuard to manage our failover for internet. If a primary internet goes down, it does a failover to the secondary the internet. However, what it doesn't do so well is that if the primary internet has a lot of latency but it's not completely down, it doesn't do a failover to the backup in a timely manner."
"I'd like to have better access to workstation monitoring, connection monitoring, and the amount of time an address is being used, to better gauge proper network utilization. If I knew that something was connected to a particular external location for an extended period that seems abnormal, I'd be able to act upon it."
"Setup of this solution is complex, it's not plug and play."
"There is a slight learning curve."
"What could use some significant improvement in WatchGuard Firebox would be its interface and policy management. An additional feature I'd like to see in the next release of WatchGuard Firebox is the ability to modify an existing policy instead of having to recreate a policy when changes are necessary. At the moment, there's no possibility to modify the policy. You have to delete the policy and recreate it."
"The only downside is that it is missing an API, that you can use to easily collect information from it."
 

Pricing and Cost Advice

"Fortinet has one or two license types, and the VPN numbers are only limited by the hardware chassis make."
"Fortinet has more device options that are affordable for small businesses than Palo Alto, and its enterprise-level models are also cheaper. Palo Alto also has a separate license for VPN connections and SD-WAN, but FortiGate offers these features standard."
"Fortinet is competitive price-wise."
"The pricing is fair."
"The initial setup is super straight forward and as far as the licensing goes for the small product that we have, the pricing was pretty competitive. It wasn't as simple and as cheap as a SonicWall but for the service we would get it was a good price."
"The price of the license and warranty can be better because it is very expensive."
"Fortinet Secure SD-WAN delivered the lowest total cost of ownership (TCO) per Mbps among all other vendors."
"The price of Fortinet FortiGate is the lowest in the market."
"The cost varies depending on the device model, with entry-level firewalls priced around $1,300 to $1,500, while higher-end models can reach prices of several hundred thousand dollars."
"Palo Alto Networks PA-Series's price is much higher than other firewall brands."
"From my perspective, managing the price is important, especially because we're a small business. For larger organizations like Barclays, we provide our requirements to the client, and they place the order on BigFix. It's their responsibility to consider their budget and make decisions accordingly. We appreciate the features we get, but the cost-sharing still depends on the client."
"Compared to other vendors, Palo Alto Networks PA-Series is expensive."
"We have to pay a yearly licensing fee for the solution."
"Palo Alto is more expensive than FortiGate."
"This product has an affordable and reasonable price point."
"The pricing is a bit on the higher side."
"They license it. When we buy it, we buy it with a three-year license. That's the most cost-effective way to do it. So, if you're going to buy it, then buy it with the three-year licensing."
"Very competitive pricing regarding throughput compared to other alternatives."
"The cost was somewhere in the vicinity of $2,000 to $3,000 for each one..."
"I would rate the pricing at seven out of ten. As for the licensing costs, we typically have yearly licenses for our clients, but there are no additional costs beyond the standard licensing fees."
"There is an additional cost for support on top of licensing. When I bought my new unit, I received additional time added to my support."
"The solution is not expensive and customers pay for a yearly license."
"It's fair pricing, but it could always be reduced."
"The primary reason that we went with Firebox was its cost. It is very economical and it provided us with all the security functions that we were looking for at the time. And the throughput was more than what we required, so it was a very cost-effective device to deploy on our network."
report
Use our free recommendation engine to learn which Firewalls solutions are best for your needs.
823,875 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Educational Organization
22%
Computer Software Company
14%
Comms Service Provider
6%
Manufacturing Company
6%
Computer Software Company
20%
Manufacturing Company
10%
University
10%
Comms Service Provider
7%
Computer Software Company
18%
Comms Service Provider
10%
Hospitality Company
6%
Retailer
5%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

Which is the better NGFW: Fortinet Fortigate or Cisco Firepower?
When you compare these firewalls you can identify them with different features, advantages, practices and usage a...
What is the biggest difference between Sophos XG and FortiGate?
From my experience regarding both the Sophos and FortiGate firewalls, I personally would rather use FortiGate. I know...
What are the biggest technical differences between Sophos UTM and Fortinet FortiGate?
As a solution, Sophos UTM offers a lot of functionality, it scales well, and the stability and performance are quite ...
What do you like most about Palo Alto Networks PA-Series?
The reporting feature and application ID functionality within Palo Alto Networks PA-Series are incredibly valuable to...
What is your experience regarding pricing and costs for Palo Alto Networks PA-Series?
It's not cheap. In Sri Lanka, it's expensive compared to other firewalls. But considering the features and the potent...
What needs improvement with Palo Alto Networks PA-Series?
Palo Alto can improve the web application firewall (WAF) feature at layer 7. Currently, I don't think it's available....
What is your primary use case for WatchGuard Firebox?
We are providing our services to all WatchGuard customers in the region.
What is your primary use case for WatchGuard Firebox?
We just use it as a secondary WiFi device. We're a small office and we needed to set up a WiFi device for a few of ou...
What is your primary use case for WatchGuard Firebox?
We're a hospital and we use it for developing our incoming and outgoing policies, and we also use it for VPN.
 

Also Known As

FortiGate 60b, FortiGate 60c, FortiGate 80c, FortiGate 50b, FortiGate 200b, FortiGate 110c, FortiGate, Fortinet Firewall
No data available
No data available
 

Learn More

 

Overview

 

Sample Customers

Amazon Web Services, Microsoft, IBM, Cisco, Dell, HP, Oracle, Verizon, AT&T, T-Mobile, Sprint, Vodafone, Orange, BT Group, Telstra, Deutsche Telekom, Comcast, Time Warner Cable, CenturyLink, NTT Communications, Tata Communications, SoftBank, China Mobile, Singtel, Telus, Rogers Communications, Bell Canada, Telkom Indonesia, Telkom South Africa, Telmex, Telia Company, Telkom Kenya
Information Not Available
Ellips, Diecutstickers.com, Clarke Energy, NCR, Wrest Park, Homeslice Pizza, Fortessa Tableware Solutions, The Phoenix Residence
Find out what your peers are saying about Palo Alto Networks PA-Series vs. WatchGuard Firebox and other solutions. Updated: December 2024.
823,875 professionals have used our research since 2012.