Try our new research platform with insights from 80,000+ expert users

Forcepoint Next Generation Firewall vs Fortra's Tripwire Enterprise comparison

Sponsored
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Fortinet FortiGate
Sponsored
Average Rating
8.4
Reviews Sentiment
6.9
Number of Reviews
581
Ranking in other categories
Secure Web Gateways (SWG) (2nd), Firewalls (1st), Intrusion Detection and Prevention Software (IDPS) (1st), Software Defined WAN (SD-WAN) Solutions (1st), WAN Edge (1st), ZTNA (1st), Unified Threat Management (UTM) (1st)
Forcepoint Next Generation ...
Average Rating
7.6
Reviews Sentiment
6.6
Number of Reviews
49
Ranking in other categories
Firewalls (20th), Software Defined WAN (SD-WAN) Solutions (8th), WAN Edge (8th)
Fortra's Tripwire Enterprise
Average Rating
8.0
Reviews Sentiment
7.2
Number of Reviews
8
Ranking in other categories
Intrusion Detection and Prevention Software (IDPS) (19th)
 

Mindshare comparison

Firewalls Market Share Distribution
ProductMarket Share (%)
Forcepoint Next Generation Firewall0.6%
Fortinet FortiGate18.7%
OPNsense10.5%
Other70.2%
Firewalls
Intrusion Detection and Prevention Software (IDPS) Market Share Distribution
ProductMarket Share (%)
Fortra's Tripwire Enterprise1.9%
Fortinet FortiGate13.2%
Darktrace11.5%
Other73.4%
Intrusion Detection and Prevention Software (IDPS)
 

Featured Reviews

Vasu Gala - PeerSpot reviewer
Manager, Information Technology Operation/Presales at TechMonarch
A stable solution with an intuitive interface and quick customer service
I have been working with Fortinet FortiGate, WatchGuard, Sophos, and SonicWall. I'm not as comfortable with SonicWall because of their UI and limitations. I prefer Fortinet above all other options. When it comes to configuration, I am confident in my ability to handle various tasks, including creating policies such as firewall rules, web policies, and application policies. Additionally, I can configure VPNs and implement load balancing, among other tasks. Overall, I feel much more comfortable working with Fortinet. Fortinet has made significant improvements by integrating AI with firewalls for threat analysis and prevention. In the past 2-3 years, they have launched FortiSASE and SIEM, and they also provide SOC services. Both Palo Alto and Fortinet FortiGate are excellent. While Fortinet FortiGate comes at higher prices, the functionality and support justify the cost. They promptly resolve firmware issues and inform all support providers about configuration changes.
reviewer2774055 - PeerSpot reviewer
Cybersecurity Engineer at a tech consulting company with 51-200 employees
Improved network segmentation has reduced lateral movement while the interface still needs modernization
For threat prevention, I noticed on another customer that there were repeated scanning and exploit attempts against some public-facing service running on HTTPS. I configured Forcepoint Next Generation Firewall to handle IPS by enabling it with critical and high severity signatures only to reduce false positives. I turned on IP reputation filtering to filter out known malicious networks, applied rate limiting on specific services in the DMZ, and logged events centrally for correlation. As a result, exploit attempts were much less than before, being blocked before reaching the back-end servers from the firewall itself, with no performance degradation on the applications. The security team received clear and actionable logs that were centralized, so they knew what was happening all the time. Strong network segmentation is my favorite feature that Forcepoint Next Generation Firewall offers. The policies are very deterministic and readable, and it has excellent east-west blocking and least privilege architecture. Application awareness identifies traffic beyond just the port itself; I can identify the application using a specific port and block risky applications even if they use allowed ports, which is great for environments with shadow IT. The integrated threat prevention is also very good, with IPS featuring well-tuned signatures and reputation-based filtering that blocks known bad actors before they can touch any applications. It supports both IPsec and SSL VPN tunnels, along with site-to-site, client-to-site, and hybrid cloud links, integrating well with Active Directory and LDAP. Additionally, centralized log management and reporting are very actionable and structured, with clarity in the policies for auditing. Overall, its stability and reliability are commendable. A real example of how Forcepoint Next Generation Firewall's readable policies and application awareness features made my work easier was fixing a flat network problem without breaking actual applications. I inherited an environment where users, application servers, and databases were loosely segmented, with port-based and messy firewall rules. Security audits flagged lateral movement risks, and application owners were scared of outages if I tightened security too much. Forcepoint Next Generation Firewall made it easy by providing very easy-to-read and logical policies. I built policies that are clear, showing communications from the user zone to the application zone to specific applications, or from the app zone to the database zone, using only required database protocols. By default, I applied a deny rule between zones unless explicitly allowed by the readable rules I implemented. The policy view clarified who talks to whom, which rules exist, why they exist, and the business function they support, effectively stopping port abuse. Security posture has definitely improved greatly since using Forcepoint Next Generation Firewall. From a flat or semi-flat network, I now have clear zone-based segmentation, with increased operational efficiency. The admins using the firewall have rules that are easy to read and intent-based, making changes easier to review and approve. There is less fear that one wrong rule could break production and fewer outages caused by security changes, without hidden matches or rule shadowing surprises. Clear hit count visibility helps me clean unused rules, leading to much fewer outages caused by changes on the firewalls. The centralized log management with supported log types provides better visibility for the SOC team and the SIEM team, as Forcepoint Next Generation Firewall sends very easy-to-parse and search clear logs to the SOC team. I did see measurable, defensible results after using Forcepoint Next Generation Firewall, including fewer security incidents reaching the back-end servers. This reduction is due to strong segmentation, application awareness, and IPS features, leading to a 60 to 70 percent reduction in security alerts that actually reach the servers. DMZ exploit attempts dropped to near zero, and no lateral movement incidents were detected post network segmentation. Additionally, overall SOC efficiency improved due to well-structured and contextual logs reflecting clear policy intent, resulting in a 35 to 40 percent reduction in mean time to triage. SOC analysts stopped chasing noise and false positives, as they had much clearer logs to use confidently.
reviewer2093205 - PeerSpot reviewer
Senior Cybersecurity Analyst at a energy/utilities company with 1,001-5,000 employees
It has excellent scalability and allows you to execute custom COCR rules, letting you fine-tune agent monitoring
I'm using Tripwire Enterprise version 9.0. In my company, thirty to forty people use Tripwire Enterprise, mainly different types of engineers, governance, risk, compliance, and cybersecurity personnel. I advise people planning to use Tripwire Enterprise to take the training because the solution has a fairly complex interface. You can do a lot of work with it, but it isn't very easy. Tripwire Enterprise is a sophisticated tool. I rate the tool an eight on a scale of one to ten because it does an excellent job of handling the unique challenges of maintaining NERC CIP compliance and monitoring industrial controls.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The product has the most valuable configuration, offloading, and security features."
"The most valuable features of Fortinet FortiGate that I found are its next-generation firewall capabilities with stateful inspection and antivirus, along with features such as a reverse proxy that are missed by some other firewall products such as Palo Alto or Check Point."
"It's a user-friendly firewall. Most of the tasks are very simple. It's simple to configure and troubleshoot this firewall."
"The most valuable features are SD-WAN, application control, IPS control, and FortiSandbox."
"FortiGate firewalls are easy to manage through a user-friendly web interface. They also have advanced features like DDoS and DLP. However, I wouldn't recommend enabling all of these features on one device because it can cause performance issues."
"We purchased Fortinet because of the pricing, its functionality, because it met our requirements, and the total cost of ownership over five years was quite reasonable. In the market, Fortinet is rated quite well."
"Fortinet FortiGate's ease of management is the most valuable feature."
"The best feature of Fortinet FortiGate is its SD-WAN capability, which is included and differs from other products that require an additional license."
"Overall, it is an excellent product, highly reliable, and among the top contenders; Forcepoint Next Generation Firewall is well known."
"I don't have anything bad to say about the product. I absolutely love it."
"The VPN is great."
"The solution offers sandboxing, which can be integrated at any time."
"One of the most valuable features is having the ability to cluster multiple firewalls even if they are different versions."
"They offer templates that provide detailed reports categorized by user, device, and internal network access."
"I have two offices, and I can route the internet of both offices using the same product. The connectivity is great."
"It is a scalable product. I know a customer who has deployed more than 4,000 firewalls in a single deployment."
"Its reporting features are great. It gives you an in-depth report. Its customization is also great, and it is working fine."
"File monitoring is the most valuable feature of the solution."
"The product supports different platforms."
"The most valuable feature is integrity management. I had some discussions with service providers, and they also agreed."
"What's most valuable in Tripwire Enterprise is the ability to execute custom COCR rules that lets me fine-tune how I monitor Linux and Windows agents."
"The most valuable feature is the integrity."
"Even if you change a single word in Notepad, it will let you know whether it was added, removed, or modified."
"We use Tripwire Enterprise as a tool to test the vulnerability of a network. That is the most valuable feature of the product for us."
 

Cons

"One area of improvement I've noticed is the lack of built-in monitoring capabilities in the firewall. Currently, we rely on third-party solutions for monitoring purposes. However, I believe the firewall itself has the potential to do a better job in this aspect. Another aspect of Fortinet that concerns me is related to redundancy. We have a setup with two firewalls working in parallel, which requires a highly adaptable configuration. However, it feels unfair that clients need to purchase two licenses, especially when one of the firewalls serves as a backup. We have noticed that other manufacturers have different policies on this matter."
"Deploying FortiGate is hard."
"I would like to be able to generate reports about the protections that we have. I would like a report feature."
"You do need some IT knowledge in order to effectively work with the solution."
"Some configuration elements cannot be easily altered once created."
"With the reports, you can see it, and you can get good feelings so upper management can go, "Oh, wow. That looks pretty." However, it's very basic."
"The firmware updates are sometimes not stable. The stability issues can vary, sometimes happening once a month or quarterly. New firmware updates can occasionally introduce bugs, causing some policies to fail. We then have to raise a ticket, and Fortinet usually provides a fix within a few days."
"Areas of improvement for Fortinet FortiGate include the need for more training and certification, especially when dealing with distributors globally, which presents challenges in product availability and delivery timelines."
"The company should update the URL filtering database. They need to enhance the URL filtering and make it easier to customize."
"In larger companies with extensive infrastructure, retrieving logs for a longer period of time can sometimes take a bit longer than desired."
"You do need knowledge of the solution in order to set the product up properly."
"They should have a local vendor who can provide support. Most of the support is overseas, so the time zones can be a problem."
"A VPN client feature is missing in our region, which we hope Forcepoint will address in future updates."
"The solution's support could use improvement."
"Configuration is not easy because it has an old-fashioned interface. The configuration interface is highly complex, and it's been the same for years. They have to change the interface."
"The security features need to be improved."
"The main way that it can be improved is through better reporting."
"A lot of network devices need a custom integration."
"An area for improvement in Tripwire Enterprise is stability, as my company had stability issues with the last few versions of the solution. Tripwire Enterprise has been a bit buggy."
"The Windows online integration license needs to be improved."
"Cloud monitoring could be better. It would also be better if the company followed a pay-as-you-use model."
"The deployment with certain systems can be difficult and it needs to be simplified."
"The initial setup is complex."
"It needs more local support from the OEM side. It would be great if this can be improved."
 

Pricing and Cost Advice

"The platform offers a reasonable price point compared to its competitors."
"When you look at these end security systems and firewalls, these firewalls even five years ago were $50,000 or perhaps $25,000 to implement in some types of customer sites. Now we're talking about tools that are $1,000. In this case, it might have been $500 or something like that."
"Fortinet FortiGate's price can be reduced."
"The value is the capability of having multiple services with one unique license, not having the limitation per user licensing schema, like other vendors."
"Its price is good."
"I think price-wise, the solution is totally reasonable since it has many products to serve, starting from small homes to massive scale sites."
"It is quite affordable for our customers. There is a separate cost for IPS, antivirus, web filtering, and other features. They have a great choice of licenses. You can go for the license that you want, which is quite useful."
"The price for the device and software is high. However, the solution is of good quality and has a lot of features."
"The cost is fair, but it could be improved."
"There is a need to make payments towards the licensing charges attached to the product. The product is not expensive."
"It requires a yearly subscription."
"The solution is expensive."
"There is a license required to use this solution and we can purchase it for one, two, three, or five years."
"Forcepoint is very expensive but it's really secure."
"It is expensive."
"The pricing should be more competitive against other vendors in the market."
"Cloud monitoring could be better. It could also be cheaper. It would be better if the company followed a pay-as-you-use model."
"Tripwire is more expensive than Netwrix."
"The licensing depends on the equipment, how many devices and the types of devices."
report
Use our free recommendation engine to learn which Firewalls solutions are best for your needs.
881,757 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
12%
Comms Service Provider
9%
Manufacturing Company
8%
Financial Services Firm
6%
Manufacturing Company
10%
Financial Services Firm
8%
Government
7%
Computer Software Company
7%
Manufacturing Company
11%
University
9%
Computer Software Company
8%
Real Estate/Law Firm
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business357
Midsize Enterprise133
Large Enterprise189
By reviewers
Company SizeCount
Small Business28
Midsize Enterprise10
Large Enterprise11
By reviewers
Company SizeCount
Small Business5
Large Enterprise3
 

Questions from the Community

Which is the better NGFW: Fortinet Fortigate or Cisco Firepower?
When you compare these firewalls you can identify them with different features, advantages, practices and usage a...
What is the biggest difference between Sophos XG and FortiGate?
From my experience regarding both the Sophos and FortiGate firewalls, I personally would rather use FortiGate. I know...
What are the biggest technical differences between Sophos UTM and Fortinet FortiGate?
As a solution, Sophos UTM offers a lot of functionality, it scales well, and the stability and performance are quite ...
What is your experience regarding pricing and costs for Forcepoint Next Generation Firewall?
My experience with pricing, setup cost, and licensing is limited because I do not work with pricing, but I have exper...
What needs improvement with Forcepoint Next Generation Firewall?
Forcepoint Next Generation Firewall can be improved, perhaps in the user interface and policy management. While the p...
Ask a question
Earn 20 points
 

Also Known As

Fortinet FortiGate Next-Generation Firewall
Forcepoint NGFW, Stonesoft Next Generation Firewall, McAfee Network Security Platform, Intel Security Network Security Platform
No data available
 

Overview

 

Sample Customers

Amazon Web Services, Microsoft, IBM, Cisco, Dell, HP, Oracle, Verizon, AT&T, T-Mobile, Sprint, Vodafone, Orange, BT Group, Telstra, Deutsche Telekom, Comcast, Time Warner Cable, CenturyLink, NTT Communications, Tata Communications, SoftBank, China Mobile, Singtel, Telus, Rogers Communications, Bell Canada, Telkom Indonesia, Telkom South Africa, Telmex, Telia Company, Telkom Kenya
California Department of Corrections and Rehabilitation (CDCR)
1. Aetna 2. Adobe 3. ADP 4. Airbus 5. Amazon 6. American Express 7. Aon 8. ATT 9. Bank of America 10. Barclays 11. Baxter International 12. Bechtel 13. Boeing 14. Cisco Systems 15. CocaCola 16. Comcast 17. Dell 18. ETRADE 19. ExxonMobil 20. Ford Motor Company 21. General Electric 22. General Motors 23. Google 24. JPMorgan Chase 25. Kraft Foods 26. Lockheed Martin 27. McDonald's 28. Merck 29. Microsoft 30. Morgan Stanley 31. Nike 32. Oracle
Find out what your peers are saying about Fortinet, Netgate, Sophos and others in Firewalls. Updated: January 2026.
881,757 professionals have used our research since 2012.