Try our new research platform with insights from 80,000+ expert users

Application Control vs WatchGuard Firebox comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Feb 15, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Fortinet FortiGate
Sponsored
Average Rating
8.4
Reviews Sentiment
6.9
Number of Reviews
587
Ranking in other categories
Secure Web Gateways (SWG) (2nd), Firewalls (1st), Intrusion Detection and Prevention Software (IDPS) (1st), Software Defined WAN (SD-WAN) Solutions (1st), WAN Edge (1st), ZTNA (1st), Unified Threat Management (UTM) (1st)
Application Control
Average Rating
8.0
Reviews Sentiment
5.2
Number of Reviews
3
Ranking in other categories
Application Control (11th)
WatchGuard Firebox
Average Rating
8.4
Reviews Sentiment
6.8
Number of Reviews
131
Ranking in other categories
Data Loss Prevention (DLP) (12th), Firewalls (10th), Intrusion Detection and Prevention Software (IDPS) (5th), Anti-Malware Tools (6th), Endpoint Detection and Response (EDR) (18th), Application Control (4th), Unified Threat Management (UTM) (4th)
 

Featured Reviews

Vasu Gala - PeerSpot reviewer
Manager, Information Technology Operation/Presales at TechMonarch
A stable solution with an intuitive interface and quick customer service
I have been working with Fortinet FortiGate, WatchGuard, Sophos, and SonicWall. I'm not as comfortable with SonicWall because of their UI and limitations. I prefer Fortinet above all other options. When it comes to configuration, I am confident in my ability to handle various tasks, including creating policies such as firewall rules, web policies, and application policies. Additionally, I can configure VPNs and implement load balancing, among other tasks. Overall, I feel much more comfortable working with Fortinet. Fortinet has made significant improvements by integrating AI with firewalls for threat analysis and prevention. In the past 2-3 years, they have launched FortiSASE and SIEM, and they also provide SOC services. Both Palo Alto and Fortinet FortiGate are excellent. While Fortinet FortiGate comes at higher prices, the functionality and support justify the cost. They promptly resolve firmware issues and inform all support providers about configuration changes.
Andre Lourens - PeerSpot reviewer
Technical at Gemini Networks
Stable performance and effective control over user access to specific applications and websites
I'm not sure about its scalability since most of my deployments are for small to medium-sized companies. I haven't faced any scalability issues so far. It runs smoothly. I don't use dedicated appliances; instead, I have it running on existing PCs. And it works fine. I haven't experienced any throughput issues or similar problems. I have around five or six different clients using Untangle Application Control.
PS
CEO at ajuntament del Prat
Network protection has improved with stronger VPN connectivity but administration remains complex
Deploying WatchGuard Firebox was quite easy, but we have had some problems regarding the VPN and the administration of the tool and the two firewalls that we have. When comparing WatchGuard Firebox with our previous solution, Palo Alto, we have had some problems in administration because of the tools. I think that they have some aspects in their system that are cloud-provided, but they also have an on-premise solution, which makes this combination good. Although I should say that when compared to Palo Alto, we have taken a step backwards. In general, I would rate WatchGuard Firebox around 6-7; it is a good firewall, but they lack good administration tools. We experience many problems with the performance and administration tools on the web, including several issues with VPNs.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Some of the valuable features are the firewall, IPS, web filter, and gateway capabilities. Additionally, it is easy to use and flexible."
"Their reliability and their policy of pre-shipping replacements when a unit has failed."
"It is simpler to configure. It is not like Cisco Firepower, where you go crazy trying to follow the Cisco documentation to figure out how to configure one little thing. Unlike Cisco Firepower, where you can't do everything through the web interface and you have got to do some command line stuff, Fortinet FortiGate SWG is simpler. There are four different things in Cisco to get in, which is not the case with Fortinet FortiGate SWG. It is one of my favorite solutions to work with. I would much rather work with it than Cisco Firepower, for example. Even though I've got 20 years of Cisco experience with different firewalls, I would much prefer this solution."
"FortiGate Next Generation Firewall can be described as the most complete solution."
"The feature I like most is the SD-WAN. It allows you to manage more than one ISP at the same time. And there is a high-availability mode, so if one of your ISPs is down, you still have a backup."
"I would advise others considering or evaluating the Fortinet FortiGate to buy it."
"The most valuable features of Fortinet FortiGate that I found are its next-generation firewall capabilities with stateful inspection and antivirus, along with features such as a reverse proxy that are missed by some other firewall products such as Palo Alto or Check Point."
"The product is easy to use and is stable. The SV1 functionality is a benefit."
"Application filter features are the most valuable for us."
"Content filtering is really easy to use. We have rules for content filtering. One of the rules that we have is that if it is not an SSL site, it should block the site. It scans, and if it finds a bad site, it is not going to allow it. We can also block based on what the company wants us to block. If the company wants us to block porn, we'll block porn. If the company wants to block social media, we're going to block social media."
"The fact that I can limit access to certain apps is the most valuable feature for me. For example, I can restrict access to specific websites or certain functions within websites."
"If we don't want specific data sent out, the tool will stop that data based on the policy we have allocated to it. It has reduced the risks of sending data where it shouldn't be. I haven't faced any issues with the tool's integration capabilities."
"The most valuable feature of WatchGuard Firebox is its ease of use."
"The pricing of the solution is okay. It's not the most expensive option."
"Their support is excellent, and the stability is very good."
"The most valuable features are the VPN and web blocker security."
"For us as an MSP, we experience a reduction in system bottlenecks after implementing WatchGuard Firebox, which translates into a more billable engineer who can do more work in the same time period."
"The initial setup was straightforward and, because we only need intrusion detection and prevention, we needed only about four hours to deploy it."
"What I found most valuable in WatchGuard Firebox is that it's a functional platform that works, and each of its features works well. The solution also has good reporting and dashboard capabilities. I also find the overall performance of WatchGuard Firebox great."
 

Cons

"The pricing of the solution should be more affordable"
"There have been several vulnerabilities in the firewall. It is hackable, some of the images are hackable."
"The support package being an additional extra, even with an enterprise package purchase, is pathetic. Though I haven't had direct experience with support, the fact that it doesn't come by default, which is very misleading compared to other brands, warrants a rating of two out of ten."
"The support from Fortinet FortiGate could improve. They are not easily accessible when we need them. They could improve their response time."
"The support structure needs to be improved because every time we contact them, there is a delay in the response."
"Improvements for Fortinet FortiGate could be made by making it easier to implement on networks and simpler to add users and accounts that utilize this solution. That's basically the only challenge that I see."
"In FortiGate Next Generation Firewall (NGFW), my concern regarding improvements is the licensing model."
"In the next release, maybe the documentation on how to use this solution could be improved."
"There is room for improvement in blocking torrents."
"Reporting functionality could be improved to provide more comprehensive insights."
"The only thing that they need to improve is that they drop sessions. Currently, if you see a session come in, such as a DHCP session or a VPN session, you don't have the ability to click on that session, hit drop, and have them re-negotiate. It would be a really nice feature, and they are working on it. This is the only feature that is missing."
"The control software is currently only available for Windows, which can be a little annoying for Linux users."
"It's very hard to get information from their website, for exactly what I need to do. Sometimes I end up having to open a lot of support tickets... It's a navigational issue which makes it hard to find what I'm looking for and it's just so broad."
"The product's technical support services need improvement."
"Due to their lack of investment in marketing, channel development, and certifications, WatchGuard faces challenges in gaining visibility and market share, especially in regions like Pakistan."
"This product needs to be fully integrated with the firewall. Currently, it only sends logs to the cloud and asks the firewall to correlate them."
"Once you start getting into proxy actions and setting up: "Okay, cool. Once this rule gets triggered, what actions have to happen?" I do know a few people who use WatchGuard and they still have to get assistance when they look at that. So I would file that as a con for WatchGuard. Proxy actions can be a little bit complicated."
"What could use some significant improvement in WatchGuard Firebox would be its interface and policy management. An additional feature I'd like to see in the next release of WatchGuard Firebox is the ability to modify an existing policy instead of having to recreate a policy when changes are necessary. At the moment, there's no possibility to modify the policy. You have to delete the policy and recreate it."
"When working with WatchGuard, specifically in configuring Panda Security on the portal for the first time, it was challenging for me."
 

Pricing and Cost Advice

"Fortinet Secure SD-WAN delivered the lowest total cost of ownership (TCO) per Mbps among all other vendors."
"It is not expensive as compared to Cisco."
"The product is not very expensive."
"I think the price of Fortinet FortiGate is very reasonable."
"Fortinet FortiGate SWG is an affordable solution."
"The price is highly competitive when compared to other brands that offer similar functionality."
"It is not a very costly product if you compare it with other products. The return on investment is also good. If you compare the return of investment and money that you are spending on this product with Palo Alto, Cisco, Check Point, and other solutions, the investment is very less. We are happy with this solution. The optional licenses are there, and you can choose which one you want and which one to avoid."
"We pay for the solution annually."
"Everything is included on the firewall at one price point, and we sell it for $70 a month, which includes the hardware."
"I use the free version of Untangle."
"It costs me about $800 a year."
"The solution's most valuable feature is its pricing."
"We don't have any other costs other than the licensing stuff."
"There is an additional cost for support on top of licensing. When I bought my new unit, I received additional time added to my support."
"I buy a three-year renewal on the main device, which is usually around $3,000 to $4,000. They usually upgrade the device when I do it. You get a big discount when you do three years."
"WatchGuard Firebox has good quality, but it is expensive."
"It's fair pricing, but it could always be reduced."
"The licensing contract we have is on a three-year basis. There aren't any costs in addition to the standard licensing fees—usually, every three years, we just purchase or renew the same license and we are okay. Every six years, we completely change the firewall, but that's the usual schema. So after three years, we just renew the licenses for another three years, and then after that particular period of time, we just purchase another firewall equivalent to the ones that we currently use."
report
Use our free recommendation engine to learn which Application Control solutions are best for your needs.
884,873 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
11%
Comms Service Provider
10%
Manufacturing Company
8%
Financial Services Firm
6%
No data available
Comms Service Provider
11%
Computer Software Company
10%
Manufacturing Company
7%
Retailer
5%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business360
Midsize Enterprise135
Large Enterprise190
No data available
By reviewers
Company SizeCount
Small Business95
Midsize Enterprise28
Large Enterprise15
 

Questions from the Community

Which is the better NGFW: Fortinet Fortigate or Cisco Firepower?
When you compare these firewalls you can identify them with different features, advantages, practices and usage a...
What is the biggest difference between Sophos XG and FortiGate?
From my experience regarding both the Sophos and FortiGate firewalls, I personally would rather use FortiGate. I know...
What are the biggest technical differences between Sophos UTM and Fortinet FortiGate?
As a solution, Sophos UTM offers a lot of functionality, it scales well, and the stability and performance are quite ...
Ask a question
Earn 20 points
What is your primary use case for WatchGuard Firebox?
We are providing our services to all WatchGuard customers in the region.
What is your primary use case for WatchGuard Firebox?
We just use it as a secondary WiFi device. We're a small office and we needed to set up a WiFi device for a few of ou...
What is your primary use case for WatchGuard Firebox?
We're a hospital and we use it for developing our incoming and outgoing policies, and we also use it for VPN.
 

Also Known As

Fortinet FortiGate Next-Generation Firewall
No data available
WatchGuard Threat Detection and Response, WatchGuard Application Control, WatchGuard Data Loss Prevention, WatchGuard Gateway AntiVirus, WatchGuard Intrusion Prevention Service
 

Overview

 

Sample Customers

Amazon Web Services, Microsoft, IBM, Cisco, Dell, HP, Oracle, Verizon, AT&T, T-Mobile, Sprint, Vodafone, Orange, BT Group, Telstra, Deutsche Telekom, Comcast, Time Warner Cable, CenturyLink, NTT Communications, Tata Communications, SoftBank, China Mobile, Singtel, Telus, Rogers Communications, Bell Canada, Telkom Indonesia, Telkom South Africa, Telmex, Telia Company, Telkom Kenya
Bridger Valley Electric, Rathbone Group, Cerebral Palsy of North Jersey (CPNJ), Brown County Schools
Ellips, Diecutstickers.com, Clarke Energy, NCR, Wrest Park, Homeslice Pizza, Fortessa Tableware Solutions, The Phoenix Residence
Find out what your peers are saying about Application Control vs. WatchGuard Firebox and other solutions. Updated: March 2026.
884,873 professionals have used our research since 2012.