No more typing reviews! Try our Samantha, our new voice AI agent.

Forcepoint Next Generation Firewall vs Palo Alto Networks URL Filtering with PAN-DB comparison

Sponsored
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Fortinet FortiGate
Sponsored
Average Rating
8.4
Reviews Sentiment
6.9
Number of Reviews
588
Ranking in other categories
Secure Web Gateways (SWG) (2nd), Firewalls (1st), Intrusion Detection and Prevention Software (IDPS) (1st), Software Defined WAN (SD-WAN) Solutions (1st), WAN Edge (1st), ZTNA (1st), Unified Threat Management (UTM) (1st)
Forcepoint Next Generation ...
Average Rating
7.6
Reviews Sentiment
6.4
Number of Reviews
51
Ranking in other categories
Firewalls (19th), Software Defined WAN (SD-WAN) Solutions (8th), WAN Edge (8th)
Palo Alto Networks URL Filt...
Average Rating
8.6
Reviews Sentiment
6.7
Number of Reviews
13
Ranking in other categories
Intrusion Detection and Prevention Software (IDPS) (8th)
 

Mindshare comparison

Firewalls Mindshare Distribution
ProductMindshare (%)
Forcepoint Next Generation Firewall0.6%
Fortinet FortiGate18.3%
OPNsense10.3%
Other70.8%
Firewalls
Intrusion Detection and Prevention Software (IDPS) Mindshare Distribution
ProductMindshare (%)
Palo Alto Networks URL Filtering with PAN-DB2.3%
Fortinet FortiGate12.6%
Darktrace11.2%
Other73.9%
Intrusion Detection and Prevention Software (IDPS)
 

Featured Reviews

Vasu Gala - PeerSpot reviewer
Manager, Information Technology Operation/Presales at TechMonarch
A stable solution with an intuitive interface and quick customer service
I have been working with Fortinet FortiGate, WatchGuard, Sophos, and SonicWall. I'm not as comfortable with SonicWall because of their UI and limitations. I prefer Fortinet above all other options. When it comes to configuration, I am confident in my ability to handle various tasks, including creating policies such as firewall rules, web policies, and application policies. Additionally, I can configure VPNs and implement load balancing, among other tasks. Overall, I feel much more comfortable working with Fortinet. Fortinet has made significant improvements by integrating AI with firewalls for threat analysis and prevention. In the past 2-3 years, they have launched FortiSASE and SIEM, and they also provide SOC services. Both Palo Alto and Fortinet FortiGate are excellent. While Fortinet FortiGate comes at higher prices, the functionality and support justify the cost. They promptly resolve firmware issues and inform all support providers about configuration changes.
reviewer2774055 - PeerSpot reviewer
Cybersecurity Engineer at a tech consulting company with 51-200 employees
Improved network segmentation has reduced lateral movement while the interface still needs modernization
For threat prevention, I noticed on another customer that there were repeated scanning and exploit attempts against some public-facing service running on HTTPS. I configured Forcepoint Next Generation Firewall to handle IPS by enabling it with critical and high severity signatures only to reduce false positives. I turned on IP reputation filtering to filter out known malicious networks, applied rate limiting on specific services in the DMZ, and logged events centrally for correlation. As a result, exploit attempts were much less than before, being blocked before reaching the back-end servers from the firewall itself, with no performance degradation on the applications. The security team received clear and actionable logs that were centralized, so they knew what was happening all the time. Strong network segmentation is my favorite feature that Forcepoint Next Generation Firewall offers. The policies are very deterministic and readable, and it has excellent east-west blocking and least privilege architecture. Application awareness identifies traffic beyond just the port itself; I can identify the application using a specific port and block risky applications even if they use allowed ports, which is great for environments with shadow IT. The integrated threat prevention is also very good, with IPS featuring well-tuned signatures and reputation-based filtering that blocks known bad actors before they can touch any applications. It supports both IPsec and SSL VPN tunnels, along with site-to-site, client-to-site, and hybrid cloud links, integrating well with Active Directory and LDAP. Additionally, centralized log management and reporting are very actionable and structured, with clarity in the policies for auditing. Overall, its stability and reliability are commendable. A real example of how Forcepoint Next Generation Firewall's readable policies and application awareness features made my work easier was fixing a flat network problem without breaking actual applications. I inherited an environment where users, application servers, and databases were loosely segmented, with port-based and messy firewall rules. Security audits flagged lateral movement risks, and application owners were scared of outages if I tightened security too much. Forcepoint Next Generation Firewall made it easy by providing very easy-to-read and logical policies. I built policies that are clear, showing communications from the user zone to the application zone to specific applications, or from the app zone to the database zone, using only required database protocols. By default, I applied a deny rule between zones unless explicitly allowed by the readable rules I implemented. The policy view clarified who talks to whom, which rules exist, why they exist, and the business function they support, effectively stopping port abuse. Security posture has definitely improved greatly since using Forcepoint Next Generation Firewall. From a flat or semi-flat network, I now have clear zone-based segmentation, with increased operational efficiency. The admins using the firewall have rules that are easy to read and intent-based, making changes easier to review and approve. There is less fear that one wrong rule could break production and fewer outages caused by security changes, without hidden matches or rule shadowing surprises. Clear hit count visibility helps me clean unused rules, leading to much fewer outages caused by changes on the firewalls. The centralized log management with supported log types provides better visibility for the SOC team and the SIEM team, as Forcepoint Next Generation Firewall sends very easy-to-parse and search clear logs to the SOC team. I did see measurable, defensible results after using Forcepoint Next Generation Firewall, including fewer security incidents reaching the back-end servers. This reduction is due to strong segmentation, application awareness, and IPS features, leading to a 60 to 70 percent reduction in security alerts that actually reach the servers. DMZ exploit attempts dropped to near zero, and no lateral movement incidents were detected post network segmentation. Additionally, overall SOC efficiency improved due to well-structured and contextual logs reflecting clear policy intent, resulting in a 35 to 40 percent reduction in mean time to triage. SOC analysts stopped chasing noise and false positives, as they had much clearer logs to use confidently.
Abdul  Basit - PeerSpot reviewer
Deputy Manager IT at Asia Petroleum Limited
Advanced features and robust support elevate overall network management experience
I think URL filtering could be better to some extent. Improvements could be made in Palo Alto Networks URL Filtering with PAN-DB compared to Sophos. The URL filtering option in Palo Alto gives a very clear vision of the network and the applications using URL filtering. If you assign a user in a group not to access certain URLs, that user should only be allowed to access LinkedIn without running videos. However, deep URL filtering in Palo Alto is not configurable. One user can have access to LinkedIn with video running, while another cannot. They should improve this deep analysis of URL filtering options.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"On a scale of one to ten, I rate this solution 10 out of 10."
"The common valuable feature for FortiGate is its UTM functionality, which includes various features under a license that is commonly implemented."
"Better visibility into traffic patterns Lightening fast troubleshooting and reduced management complexity overall."
"The security for endpoints is the most valuable. It is very secure for our workers. It allows us to secure a transaction and enable security for a specific segment in the workflow."
"The security features are about the best that I've seen anywhere."
"I've found the solution to be very good."
"Layer-3 firewall and routing are the most valuable features."
"The Fortinet FortiGate local partners were good. I did not have direct contact with Fortinet support."
"Forcepoint is a complete package because it has network and systems applications. Other firewalls are only for the network."
"This solution is very reliable."
"I don't have anything bad to say about the product. I absolutely love it."
"The Forcepoint Next Generation Firewall is a scalable product."
"The most valuable feature is the console management."
"The initial setup is very easy."
"I like the IPS. IPS is the master feature. I depend on the firewall and sandbox."
"It is stable and scalable. In addition, their support is great. When you ask them for something, they provide support, and if required, they also involve the R&D team to help you to resolve the issues in your configuration."
"The stability of the solution is perfect and totally useful."
"The tool blocks URLs."
"The most valuable feature is that the product can do everything in a single device, including the firewall, rules, and the PBL, and it also has good routing and switching."
"I would rate Palo Alto Networks URL Filtering with PAN-DB a perfect 10 out of 10."
"It provides visibility and control over where people are web browsing and protects them from going to malicious sites."
"Prohibited URLs can be listed by category."
"It's allowed us to have better visibility and protection from threats."
"The Palo Alto solution has improved our organization by providing threat protection across a variety of internet connections. Our company also gets valuable insights regarding threat analysis."
 

Cons

"There are a lot of bugs I have found in the solution and it is difficult to upgrade. These areas need improvement."
"With the standard support subscription, if the device goes down, the customer has to first ship the box, and then Fortinet sends the replacement. With the higher support, the customer has to ship the device after they have the replacement. It would be better for customers to get immediate replacements even with a standard subscription."
"The command line is complicated, and the interface could be better."
"As far as wanting more scalability or things in the network diagram, it's going to cost you."
"The IPS monitoring can be improved."
"We are not utilizing Fortinet FortiGate to its full capacity because we have to pay for every small feature."
"One of the most important areas for improvement for Fortinet FortiGate is the limited resources for tests. I was limited to a few interfaces for one month, and it would be great if Fortinet could improve these features in their test versions."
"It is very expensive, and their support is not very good. I hope that their technical support will be better in the future."
"Sometimes Forcepoint Next Generation Firewall is not really stable at all. It has many freezes for no reason, and local support needs to reboot it physically by unplugging the power cable and plugging it back in."
"My team is looking for more throughput and better integration with our security framework."
"The solution needs to build upon its network functionality. It needs to be a bit smarter."
"The security features need to be improved."
"We would love to take another solution from Forcepoint, but unfortunately, the price is too high."
"This solution would be improved with the inclusion of custom reporting."
"If you have Cisco integration, then I wouldn't recommend this solution — it won't integrate."
"They need to increase the local support here. There are also some bugs or fixes on which they need to work. They very well know about these bugs. In terms of licensing, I would like them to either increase the number of features in a single license or make licensing more flexible."
"The licensing costs and setup costs are very expensive for us. The price is significantly higher compared to other competitive products."
"Support needs to be enhanced."
"Performance monitoring could use improvement."
"The main limitation is that it needs a live Internet connection for ongoing updates."
"Customer service is sometimes inconsistent. Some engineers are very knowledgeable, while others cannot answer questions and delay solutions."
"One way Palo Alto can improve is by offering sandboxing. I don't know if they currently offer a sandboxing feature together with the firewall or not. They should provide secure sandboxing with the firewalls."
"For hosting sites like Blogspot, they host sites that should be in different categories, but get lumped together in general. There needs to be more granularity or multiple categorizations."
"I cannot say that PAN-DB has provided any significant improvements, since we are using it primarily as a white list."
 

Pricing and Cost Advice

"The pricing is fair."
"Fortinet Secure SD-WAN delivered the lowest total cost of ownership (TCO) per Mbps among all other vendors."
"In my opinion, the pricing of the product is reasonable."
"Fortinet FortiGate is reasonably priced."
"We just pay a flat monthly fee to the vendor for the support."
"This is not a cheap solution but it isn't expensive, either. It's a good solution for the right price."
"The price for the Fortinet FortiGate is reasonable. Secure SD-WAN is free of charge. If you have their firewall, it's free of charge. It's very tempting."
"It's an expensive solution"
"We have found the price could be reduced. It is a little expensive."
"Everything in Forcepoint comes with an individual license, which is kind of a problem. In our last meeting, they said that it may change at the beginning of 2021, and they will try to merge some licenses together. Customers will get more features than what they got previously. We will wait and see."
"We have just a subscription for the cloud, and this license is great. The license is so good."
"The pricing should be more competitive against other vendors in the market."
"The pricing of the solution is normally competitive with other products."
"The cost is fair, but it could be improved."
"Forcepoint is very expensive but it's really secure."
"It is an affordable product. We purchase its yearly license."
"It is more expensive than ASA but is far cheaper than Checkpoint. So, pricing wise, it is right in the middle."
"Expensive, but that's because it provides everything."
report
Use our free recommendation engine to learn which Firewalls solutions are best for your needs.
885,789 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
11%
Comms Service Provider
10%
Manufacturing Company
8%
Financial Services Firm
7%
Construction Company
10%
Financial Services Firm
9%
Manufacturing Company
9%
Computer Software Company
8%
Performing Arts
14%
Financial Services Firm
10%
University
9%
Manufacturing Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business364
Midsize Enterprise135
Large Enterprise191
By reviewers
Company SizeCount
Small Business29
Midsize Enterprise10
Large Enterprise12
By reviewers
Company SizeCount
Small Business5
Midsize Enterprise3
Large Enterprise5
 

Questions from the Community

Which is the better NGFW: Fortinet Fortigate or Cisco Firepower?
When you compare these firewalls you can identify them with different features, advantages, practices and usage a...
What is the biggest difference between Sophos XG and FortiGate?
From my experience regarding both the Sophos and FortiGate firewalls, I personally would rather use FortiGate. I know...
What are the biggest technical differences between Sophos UTM and Fortinet FortiGate?
As a solution, Sophos UTM offers a lot of functionality, it scales well, and the stability and performance are quite ...
What is your experience regarding pricing and costs for Forcepoint Next Generation Firewall?
My experience with pricing, setup cost, and licensing is limited because I do not work with pricing, but I have exper...
What needs improvement with Forcepoint Next Generation Firewall?
I found one problem with Forcepoint Next Generation Firewall. They still do not have any VPN clients for Windows comp...
What is your experience regarding pricing and costs for Palo Alto Networks URL Filtering with PAN-DB?
The licensing costs and setup costs are very expensive for us. The price is significantly higher compared to other co...
What needs improvement with Palo Alto Networks URL Filtering with PAN-DB?
I think URL filtering could be better to some extent. Improvements could be made in Palo Alto Networks URL Filtering ...
What is your primary use case for Palo Alto Networks URL Filtering with PAN-DB?
We previously discussed Palo Alto Networks WildFire, and we are currently using it for our firewalls with the WildFir...
 

Also Known As

Fortinet FortiGate Next-Generation Firewall
Forcepoint NGFW, Stonesoft Next Generation Firewall, McAfee Network Security Platform, Intel Security Network Security Platform
Palo Alto Networks URL Filtering PAN-DB
 

Overview

 

Sample Customers

Amazon Web Services, Microsoft, IBM, Cisco, Dell, HP, Oracle, Verizon, AT&T, T-Mobile, Sprint, Vodafone, Orange, BT Group, Telstra, Deutsche Telekom, Comcast, Time Warner Cable, CenturyLink, NTT Communications, Tata Communications, SoftBank, China Mobile, Singtel, Telus, Rogers Communications, Bell Canada, Telkom Indonesia, Telkom South Africa, Telmex, Telia Company, Telkom Kenya
California Department of Corrections and Rehabilitation (CDCR)
TRI-AD, Telkom Indonesia
Find out what your peers are saying about Fortinet, Netgate, Sophos and others in Firewalls. Updated: March 2026.
885,789 professionals have used our research since 2012.