Try our new research platform with insights from 80,000+ expert users

Check Point Application Control vs WatchGuard Firebox comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Aug 5, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Fortinet FortiGate
Sponsored
Average Rating
8.4
Reviews Sentiment
6.9
Number of Reviews
411
Ranking in other categories
Firewalls (2nd), Software Defined WAN (SD-WAN) Solutions (1st), WAN Edge (1st)
Check Point Application Con...
Average Rating
8.8
Reviews Sentiment
7.6
Number of Reviews
41
Ranking in other categories
Application Control (3rd)
WatchGuard Firebox
Average Rating
8.4
Reviews Sentiment
7.5
Number of Reviews
125
Ranking in other categories
Data Loss Prevention (DLP) (11th), Firewalls (14th), Intrusion Detection and Prevention Software (IDPS) (8th), Anti-Malware Tools (12th), Endpoint Detection and Response (EDR) (20th), Application Control (7th), Unified Threat Management (UTM) (2nd)
 

Featured Reviews

Vasu Gala - PeerSpot reviewer
A stable solution with an intuitive interface and quick customer service
I have been working with Fortinet FortiGate, WatchGuard, Sophos, and SonicWall. I'm not as comfortable with SonicWall because of their UI and limitations. I prefer Fortinet above all other options. When it comes to configuration, I am confident in my ability to handle various tasks, including creating policies such as firewall rules, web policies, and application policies. Additionally, I can configure VPNs and implement load balancing, among other tasks. Overall, I feel much more comfortable working with Fortinet. Fortinet has made significant improvements by integrating AI with firewalls for threat analysis and prevention. In the past 2-3 years, they have launched FortiSASE and SIEM, and they also provide SOC services. Both Palo Alto and Fortinet FortiGate are excellent. While Fortinet FortiGate comes at higher prices, the functionality and support justify the cost. They promptly resolve firmware issues and inform all support providers about configuration changes.
Jivesh Sharma - PeerSpot reviewer
Control application access and optimize bandwidth for enhanced productivity
Check Point Application Control can be improved, particularly in policy management. When we add applications in the policy, we currently have the option to select individual applications, but a feature allowing categorization of applications based on types, such as social media applications, would make it easier to add multiple or bulk applications in the policy. This feature would be very valuable if introduced. Feedback from management about how these changes improved productivity and network performance has been positive. Users were spending their time watching videos on YouTube or streaming content, wasting time on Instagram and Facebook while in the office. Managers complained about this, leading to compliance policies being defined to restrict access to these kinds of applications.
Rajesh  Makwana - PeerSpot reviewer
Efficient bandwidth management and secure network access with a strong firewall
The primary use case of the Firebox mainly revolves around bandwidth management, unnecessary web blocking, application control, and protection against brute force attacks. It is also implemented for load balancing, SD-WAN, and branch-to-branch connectivity from one location to another. We also use…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"It's quite comfortable to handle the FortiGate firewall."
"There are lots of features and most of them are deployed for internet security. Users are protected if they accidentally go to some malicious sites."
"The best feature of Fortinet FortiGate is the IPS or IDS implementation. I appreciate most the agility or the flexibility to create hashes to block incoming threats, and I can integrate with third-party threat intelligence with our FortiGate."
"The most important feature, normally for small business customers, is link load balancing."
"Initial setup is straightforward. There weren't too many issues with setting it up. It takes one hour or so."
"Fortinet FortiGate has a threat detection capacity compared to other vendors."
"Some of the best features of Fortinet FortiGate include the next-generation firewall features."
"The interface is very good."
"The most important characteristic is granularity, which allows our teams to have different security profiles depending on the department to be protected."
"They have an excellent support team. They are fast and it is easy to escalate any situation."
"We can control bandwidth and high-risk application access from our network using application control."
"The most valuable thing about the solution is that we get real-time visibility into the usage of an application and the granular control of the application."
"The most valuable feature of Check Point Application Control is VPN access and the ability to lock out sites we do not want users to have access. The reporting monitoring software in Check Point Application Control is fantastic. For example, log filtering is beneficial."
"Among the features that we have used, we like being able to identify the identity of the user who is doing transactions."
"Check Point enables us to save internet bandwidth. The administration offers good guidance. We don't want the employees to access social networking on work computers because it will distract them from their jobs, so we can block that. It also helps us to implement changes very quickly and to get people to be more focused on the job."
"Its initial setup is very simple and straightforward."
"It is a scalable solution."
"The most valuable feature is the correlation of logs from different devices."
"The most valuable features of this solution are live logging, rule setup and maintenance, and VPN creation."
"It provides us with Layer 2 and Layer 3 security."
"The solution is very easy to use."
"The most valuable feature for small and medium businesses is the support for various protocol proxies."
"Cloud integration is one of the best features."
"The analytics are important because if there is an abnormality then it provides that information to us."
 

Cons

"We had some issues in the beginning while setting it up, but after doing the firmware update, it is working fine."
"It can be a little bit more user-friendly in terms of policy definition and implementation. It seems a little bit complicated, and it could be simplified."
"Fortinet FortiGate could improve by having a frequent ask questions(FAQ) area for people to receive quick answers to popular questions. Additionally, it would be beneficial to have an SMS notification feature. For example, if you cannot access your email you could receive an SMS message."
"Areas of improvement for Fortinet FortiGate include the need for more training and certification, especially when dealing with distributors globally, which presents challenges in product availability and delivery timelines."
"Sometimes you do need to know some CLI commands, so it's a bit harder for technicians or new people that don't know it."
"In an incident, after a restart, Fortinet FortiGate did not connect to FortiGuard servers. Due to that reason, on the customer end, all websites got blocked."
"Its filtering is sometimes too precise or strict. We sometimes have to bypass and authorize some of the sites, but they get blocked. We know that they are trusted sites, but they are blocked, and we don't know why."
"They have recently acquired a CNAP solution which should be integrated into FortiGate boxes natively for protection at any application layer. Since Fortinet FortiGate has Layer 7 protection, they should integrate that as soon as they can for threat detection and network detection."
"The blocking characteristics for filtering content currently are not so customizable."
"Configuration and deployment are a little bit difficult."
"I recommend network upgrades in the next release to meet most company demands and daily changes."
"Check Point Application Control needs to ensure that they release up-to-date security patches regularly. It should release better documentation so end-users can use the product without depending on the support team."
"Seeing the capabilities and features that we are using today, we can say that we could expect an additional feature that could allow us to integrate this management and even security with APIs."
"The initial setup was a bit difficult."
"The one feature that could be improved would be the ability to see implicit rules that are defaulted on the policy."
"There are many aspects we do not like about the solution and there are a lot of alternatives available on the market. Some of the settings are buried deep within the solution making it a challenge to navigate. It would be helpful if it was more intuitive. Additionally, there can be some settings that are in multiple places, this leaves the user not knowing what settings are needed to be modified for the wanted result. I have lost confidence because I do not know if I change a setting or if it is going to have the desired result I intended it to do."
"If they could make the traffic monitoring easier that would be great. I don't use it that frequently, but I would like to see some improvements in the ease of use of that component, so it makes more sense. I know it's a technical component so there's going to be some difficulty trying to make that easier."
"I don't think I can get a full-blown DNS client from it. I've been trying to have DNS services. It has forwarding, but I don't get the services of a full DNS client. My main difficulty with it is that I can't run a complete service. I need NTP. I need DNS. I need DHCP for my domain, but I only get forwarding. As far as I can tell, I don't get caching and the kinds of reporting and registration needed to host a DNS for a domain. I have to have a separate solution for that."
"Some of the configuration options are somewhat confusing."
"Particularly in India, the cost for renewal after three years is 75% of the hardware cost, which is a significant problem."
"The product's technical support services need improvement."
"The solution is a bit confusing and there are unusual complications with setup."
"The level of support from WatchGuard is not as good."
"I believe there is a need for additional measures to connect mobile devices securely to the Firebox router."
 

Pricing and Cost Advice

"If you are looking for a quality product, it will come at a higher price. Expecting them to be significantly cheaper is unrealistic. In terms of pricing, it is a bit costly. However, the functionality and support offered are worth it."
"The price of FortiGate is average and I would say that based on the top five products available on the market, it is in the affordable range."
"It is not a very costly product if you compare it with other products. The return on investment is also good. If you compare the return of investment and money that you are spending on this product with Palo Alto, Cisco, Check Point, and other solutions, the investment is very less. We are happy with this solution. The optional licenses are there, and you can choose which one you want and which one to avoid."
"The beauty is the price performance ratio is great with FortiGate. It provides all the features we needed and the price is comparable with others' firewalls. The price is quite competitive with the firewalls with similar features."
"A year or two years back, its price was competitive and reasonable. That was one of the reasons that people easily switched to Fortinet. Over the last two years, the prices have increased drastically. However, the prices of others have also increased. An advantage is there from the price point but not as much as it was previously."
"Setup cost may be not so low, as you expect, because it depends on different factors, but TCO for 5 years may pleasantly surprise you."
"Before choosing a piece of equipment you have to take into account the cost-benefit offered by each one. Sometimes it is not worth paying a very cheap price to have a minimum level of security."
"If the customer is looking for SD-WAN, it comes free with FortiGate."
"I think application control has become a basic feature and it should be enabled automatically, without having to purchase a separate license for it."
"The price of Check Point Application Control is high. The support and ecosystem around the solution are expensive."
"The blade has its cost but you can take advantage of the license package to pay less for it."
"Check Point Application Control is expensive. The tool's licensing costs are yearly."
"It's a bit expensive and it could be cheaper, but it's part of business politics."
"I haven't seen the pricing since 2017, but it was competitive. SonicWall, Barracuda, and WatchGuard were all about the same price when we did our last pricing."
"The subscription that was purchased is for three years, but it is usually for one year at a time."
"The primary reason that we went with Firebox was its cost. It is very economical and it provided us with all the security functions that we were looking for at the time. And the throughput was more than what we required, so it was a very cost-effective device to deploy on our network."
"The two larger devices are about $1,000 each and the smaller ones are about $500 or $600 each... It's cheaper and you have more control because it's self-managed."
"I think we might be subscribed to one or two of the premium features."
"I spent $600 or $800 on this product and I'm paying a couple of hundred dollars a year in a subscription service to keep the lights on, on it... It works out to $100 or $200 a year if you buy several years at once. It's fair."
"The price of WatchGuard is very good."
"We only license our corporate one and the one we have at our DR site, we don't worry about the branches. It doesn't pay for us to license the ones at the branches. What they charge for what they call basic maintenance is extremely high for those little fireboxes."
report
Use our free recommendation engine to learn which Application Control solutions are best for your needs.
865,295 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
16%
Comms Service Provider
9%
Manufacturing Company
7%
Financial Services Firm
6%
Computer Software Company
14%
Performing Arts
11%
Financial Services Firm
11%
Manufacturing Company
8%
Computer Software Company
14%
Comms Service Provider
11%
Retailer
6%
Manufacturing Company
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

Which is the better NGFW: Fortinet Fortigate or Cisco Firepower?
When you compare these firewalls you can identify them with different features, advantages, practices and usage a...
What is the biggest difference between Sophos XG and FortiGate?
From my experience regarding both the Sophos and FortiGate firewalls, I personally would rather use FortiGate. I know...
What are the biggest technical differences between Sophos UTM and Fortinet FortiGate?
As a solution, Sophos UTM offers a lot of functionality, it scales well, and the stability and performance are quite ...
What do you like most about Check Point Application Control?
It has many important features that have greatly helped the company and the IT department.
What is your experience regarding pricing and costs for Check Point Application Control?
My experience with the pricing, setup cost, and licensing for Check Point Application Control is that the pricing is ...
What needs improvement with Check Point Application Control?
Check Point Application Control could be improved, particularly regarding the application categorization accuracy as ...
What is your primary use case for WatchGuard Firebox?
We are providing our services to all WatchGuard customers in the region.
What is your primary use case for WatchGuard Firebox?
We just use it as a secondary WiFi device. We're a small office and we needed to set up a WiFi device for a few of ou...
What is your primary use case for WatchGuard Firebox?
We're a hospital and we use it for developing our incoming and outgoing policies, and we also use it for VPN.
 

Also Known As

FortiGate 60b, FortiGate 60c, FortiGate 80c, FortiGate 50b, FortiGate 200b, FortiGate 110c, FortiGate, Fortinet Firewall
No data available
WatchGuard Threat Detection and Response, WatchGuard Application Control, WatchGuard Data Loss Prevention, WatchGuard Gateway AntiVirus, WatchGuard Intrusion Prevention Service
 

Overview

 

Sample Customers

Amazon Web Services, Microsoft, IBM, Cisco, Dell, HP, Oracle, Verizon, AT&T, T-Mobile, Sprint, Vodafone, Orange, BT Group, Telstra, Deutsche Telekom, Comcast, Time Warner Cable, CenturyLink, NTT Communications, Tata Communications, SoftBank, China Mobile, Singtel, Telus, Rogers Communications, Bell Canada, Telkom Indonesia, Telkom South Africa, Telmex, Telia Company, Telkom Kenya
SEB, Luma Arles, Terma, Aerospace, Midwest Rubber
Ellips, Diecutstickers.com, Clarke Energy, NCR, Wrest Park, Homeslice Pizza, Fortessa Tableware Solutions, The Phoenix Residence
Find out what your peers are saying about Check Point Application Control vs. WatchGuard Firebox and other solutions. Updated: August 2025.
865,295 professionals have used our research since 2012.