Try our new research platform with insights from 80,000+ expert users

Palo Alto Networks VM-Series vs Zscaler Cloud Firewall comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Sep 16, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Fortinet FortiGate
Sponsored
Ranking in Firewalls
2nd
Average Rating
8.4
Reviews Sentiment
7.2
Number of Reviews
327
Ranking in other categories
Software Defined WAN (SD-WAN) Solutions (1st), WAN Edge (1st)
Palo Alto Networks VM-Series
Ranking in Firewalls
11th
Average Rating
8.6
Reviews Sentiment
7.1
Number of Reviews
62
Ranking in other categories
Advanced Threat Protection (ATP) (9th)
Zscaler Cloud Firewall
Ranking in Firewalls
24th
Average Rating
8.2
Reviews Sentiment
8.0
Number of Reviews
18
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of April 2025, in the Firewalls category, the mindshare of Fortinet FortiGate is 21.1%, up from 17.7% compared to the previous year. The mindshare of Palo Alto Networks VM-Series is 0.8%, up from 0.8% compared to the previous year. The mindshare of Zscaler Cloud Firewall is 0.4%, up from 0.3% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Firewalls
 

Featured Reviews

EhabAli - PeerSpot reviewer
Efficient, user-friendly, and affordable
In the past, NSS Labs was utilized to test files and verify the numbers and datasheets. It would be beneficial to have an organization or testing lab that can verify the numbers in our datasheets since changes are frequently made, which can be inconvenient for review. For instance, when comparing different competitors such as Forcepoint, Palo Alto, and Check Point, the throughput or numbers in the datasheet may be lower than the actual numbers. Conversely, Fortinet typically reports very high numbers, but they cannot be replicated in the real world. Therefore, it would be advantageous for them to partner with a neutral testing organization such as NSS Labs to validate these numbers, thus providing more credibility and comfort to everyone regarding the accuracy of the datasheets. For the migration, everyone has a firewall in use and I am selling Fortinet. Typically, I am replacing another firewall. Previously, there was a tool available to convert configurations from one firewall, such as Palo Alto, to Fortinet, but this tool is no longer free. If it could be made free again, it would be very beneficial. This tool shows a lot of promise and is very good. Making it free would help many companies deliver their products in a more efficient and integrated way. It would also be more valuable to include the tool with the firewall package or license instead of having to pay extra for it. Paying extra puts more pressure on small companies to deliver the firewall and complete the configuration, especially if they have hundreds or thousands of policies. It's very painful to move through these policies line by line. The stability has room for improvement. When it comes to Secure SD-WAN, everything is fine. They are going the right way. SD-WAN is very promising. They can provide the SD-WAN solution separately, but they will not take this approach because even the smallest firewall can support the features, so there is no need to have a separate service or appliance. They are following the right steps, and there is nothing to be improved. Feature-wise, I'm really satisfied with the new release, and the features they have added. For now, it's fine.
AshwaniTyagi - PeerSpot reviewer
Advanced protection and good integration capabilities with good reliability
We use Palo Alto Networks VM-Series to offer services to our customers as a managed security service provider. We provide solutions and services to our customers across the globe. For example, if I want to host a firewall in the cloud or somewhere where the physical appliance is not a possibility…
Bhaskar Rao - PeerSpot reviewer
Though it helps deal with web traffic or any malicious traffic, it needs to work on its DC performance issues
The product's initial setup phase is moderate in level, so it is neither very complex nor very easy. For the deployment, my company first needs to gather all the requirements of the users and the domain names and consider how many users there are in the company. In the implementation and planning part, my company needs to consider what kind of policies we will create while ensuring that the policies are created based on the requirements of the users. There is a need to segregate the users' requirements since there are separate departments in the company, like the HR department, sales department, IT department, and manufacturing department, so that our company can create policies depending on their requirements. On-site, if you want a GRE tunnel, our company can handle GRE tunnel traffic routing and Zscaler Cloud Firewall, after which Zscaler will take action based on the policies created by our organization. For the deployments and maintenance, a team of five members consisting of two managers and three engineers is required.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The most valuable features of Fortinet FortiGate are the ability to work in proxy mode, which other solutions, such as Palo Alto cannot. There are some features that are better that come at no extra license or subscriptions cost, such as basic SD-WAN. The DLT is useful, other solutions have the same feature too, such as Palo Alto."
"The most valuable features are SD-WAN, application control, IPS control, and FortiSandbox."
"The GUI is good."
"FortiGate is on the cheaper end, and it offers good value."
"The scalability of Fortinet FortiGate is good."
"The Fortinet FortiGate local partners were good. I did not have direct contact with Fortinet support."
"The most valuable feature is the VDOM, which allows the customer to have multiple firewalls in a single campus."
"You can purchase switches and you don't need to do anything with them. You just put in the firewall and the switches get all the policies and rules that you already have in the firewall. With Fortinet, you just connect the FortiSwitch to the Fortinet and that's it."
"In AWS, Palo Alto provides us a better view than flow logs for network traffic."
"The most valuable features are security and support."
"It has a good performance which helps you with the stability of your virtual environment."
"Embedding it into my application development lifecycle prevents data loss and business disruption, allowing the adoption to operate at the speed of my AWS Cloud."
"The technical support for the solution is very good."
"The threat prevention and WildFire features are the most valuable features. DNS is another good feature of the product."
"It allows us to see all our traffic to properly secure it and only allow what is needed through the firewall."
"Palo Alto offers excellent security, with features such as email scanning, malware protection, and efficient VPN and antivirus capabilities."
"If malicious traffic attacks our on-premises servers, then it gets blocked by Zscaler Cloud Firewall."
"Includes advanced tech protection."
"The solution offers good sandboxing."
"The product’s firewall and VPN package are fantastic compared to any other solution."
"Since it is really customizable, I can use it and avoid enabling access to the full network."
"Most of the features that Zscaler has to offer, we will deploy."
"Zscaler Cloud Firewall understands the applications in the current generation and adapts to the present generation cloud applications."
"Zscaler provides effective protection against various cyber threats ensuring a safe environment"
 

Cons

"There are some complex administration tasks in their administration portal. That needs to be improved."
"Lacks training for new features."
"They are doing good, but they can improve the distributor assignment. The availability of the product and the timeline of delivery are the main things. The distribution should be swift, and the distributor should not reach out to end customers directly. They should work as a distributor. There should also be one more local distributor. Currently, there is only one distributor in Pakistan, and the rest of them are in UAE. It is difficult to work with only one distributor. Sometimes, you don't get along with the same distributor, and that's why they should have one more distributor. Their licensing should also be improved. The activation or renewal of the product should be done from the date of renewal, not from the date on which the license expired."
"They could improve the response time and quality of support."
"Scalability is one of the disadvantages. When it comes to scalability, you have to actually change the box. If you want to upgrade it, you need to actually change the existing box and probably you take the system off to other sites."
"Some configuration elements cannot be easily altered once created."
"The cloud features and integration could be improved."
"Improvement is needed in the Web Filter quotas to restrict users with allocated quotas."
"Recently, they introduced their Prisma Cloud solution. Compared to the previous technologies, like Panorama, which is used for centralized firewall management, or even the individual firewalls, it's a bit challenging to integrate the traditional firewall policies into Prisma Cloud."
"There are various reports that come with the box or with the VMware, but you can only run them daily."
"The performance of VM instances has some limitations in terms of threshold and throughput compared to appliances."
"It can definitely improve on the performance."
"The product's AIOps process needs improvement."
"The one issue that I didn't like is that the SNMP integration with interfaces didn't record the interface counters."
"It has to be more scalable for the deployment of VMs on the cloud."
"The product could provide protection above Layer 3, which gets into the application layer and provides better visibility into those aspects of application security."
"We are having some issues with internet access being denied when organizational ID-based policies change. For example, a lower level employee ends up getting the same level of access as that of a higher level employee."
"Apart from the issues associated with the product in areas like the DC performance issues and DC failover, Zscaler Cloud Firewall's IP should not have a proxy IP."
"Data Leak Prevention is only for web filtering and there is no protection for email."
"I don't have the visibility of a control dashboard or a network management system."
"Certain criteria need to be met if you want to scale this solution."
"They do not provide a few components that are fundamental to differentiate the products"
"Instead of the standard license, they should certainly provide customers with the visibility to access and view the logs."
"If I can get rid of Jetscaler, I will use Twingate for sure."
 

Pricing and Cost Advice

"Pricing for this product is comparatively lower than other products. It's an affordable solution, but when expanding the number of users, they'll ask you to replace the model, so that's an added cost."
"If the customer is looking for SD-WAN, it comes free with FortiGate."
"The Indian market is different than the European and American markets. When you compare they need to be a bit more aggressive on pricing."
"The pricing for the product is alright."
"I do not have first-hand experience with the rice of Fortinet FortiGate, but I have heard the price was reasonable."
"The price is fair for what we get with FortiGate."
"I had to pay for the license for the firewall, but it is guaranteed to have updates. I expect a good service for it. It was about €1000 for a year, and there was no additional cost."
"It is affordable. Palo Alto is much more expensive than Fortinet."
"The price of this solution is very high for some parts of Africa, which makes it a challenge."
"For what you get, it does do what it says. It is a good value for an enterprise firewall.​"
"It is a little bit of crazy if you compare it to Vanguard, Sophos, or even Cisco. The newest version of Cisco, the Next-Generation Firewall of Cisco, is less expensive than Palo Alto. It is more comparable to Check Point."
"The pricing and licensing of this product on AWS should be from $1.28/hr or $4,500.00/yr. Then, it would be a good price for the performance that it delivers."
"The product is cheaper than the on-premise version."
"The price is not bad. They have a yearly renewal fee, and the pricing is exactly where we expect it to be."
"Do not buy larges box if you do not need them. Rightsizing is a great task to do before​hand."
"Purchasing on the AWS Marketplace was simple, effective, and easy."
"It is not the most budget-friendly solution, but it's important to consider its overall value."
"Zscaler is priced too high compared to the cost of Fortinet."
"There are different subscription models available."
"It comes at a significantly reduced cost while ensuring control and effectiveness."
"The product is a bit expensive compared to the solutions offered by its competitors, like Palo Alto. There is a need to make yearly payments towards the license in charges associated with the product."
"There is an annual license required for the use of the Zscaler Cloud Firewall."
"There are licensing costs, and I would not say that it's a cheap vendor."
"It is expensive for small businesses."
report
Use our free recommendation engine to learn which Firewalls solutions are best for your needs.
848,207 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Educational Organization
21%
Computer Software Company
14%
Comms Service Provider
7%
Manufacturing Company
6%
Computer Software Company
16%
Financial Services Firm
13%
Manufacturing Company
8%
Government
7%
Financial Services Firm
13%
Computer Software Company
13%
Manufacturing Company
8%
Government
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

Which is the better NGFW: Fortinet Fortigate or Cisco Firepower?
When you compare these firewalls you can identify them with different features, advantages, practices and usage a...
What is the biggest difference between Sophos XG and FortiGate?
From my experience regarding both the Sophos and FortiGate firewalls, I personally would rather use FortiGate. I know...
What are the biggest technical differences between Sophos UTM and Fortinet FortiGate?
As a solution, Sophos UTM offers a lot of functionality, it scales well, and the stability and performance are quite ...
Features comparison between Palo Alto and Fortinet firewalls
In the best tradition of these questions, Feature-wise both are quite similar, but each has things it's better at, it...
How does Azure Firewall compare with Palo Alto Networks VM Series?
Both products are very stable and easily scalable. The setup of Azure Firewall is easy and very user-friendly and the...
Which lesser known firewall product has the best chance at unseating the market leaders?
Netscope, Zscaler if they continue route they are on now. FIrewalls needs great deal of automation on each end, datac...
What do you like most about Zscaler Cloud Firewall?
The product’s firewall and VPN package are fantastic compared to any other solution.
What is your experience regarding pricing and costs for Zscaler Cloud Firewall?
The product is a bit expensive compared to the solutions offered by its competitors, like Palo Alto. There is a need ...
 

Also Known As

FortiGate 60b, FortiGate 60c, FortiGate 80c, FortiGate 50b, FortiGate 200b, FortiGate 110c, FortiGate, Fortinet Firewall
No data available
No data available
 

Overview

 

Sample Customers

Amazon Web Services, Microsoft, IBM, Cisco, Dell, HP, Oracle, Verizon, AT&T, T-Mobile, Sprint, Vodafone, Orange, BT Group, Telstra, Deutsche Telekom, Comcast, Time Warner Cable, CenturyLink, NTT Communications, Tata Communications, SoftBank, China Mobile, Singtel, Telus, Rogers Communications, Bell Canada, Telkom Indonesia, Telkom South Africa, Telmex, Telia Company, Telkom Kenya
Warren Rogers Associates
Zenith Live, Azure, Carlsberg Group
Find out what your peers are saying about Palo Alto Networks VM-Series vs. Zscaler Cloud Firewall and other solutions. Updated: April 2025.
848,207 professionals have used our research since 2012.