No more typing reviews! Try our Samantha, our new voice AI agent.

IPFire vs Palo Alto Networks NG Firewalls comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Jan 25, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Fortinet FortiGate
Sponsored
Ranking in Firewalls
1st
Average Rating
8.4
Reviews Sentiment
6.9
Number of Reviews
592
Ranking in other categories
Secure Web Gateways (SWG) (2nd), Intrusion Detection and Prevention Software (IDPS) (1st), Software Defined WAN (SD-WAN) Solutions (1st), WAN Edge (1st), ZTNA (1st), Unified Threat Management (UTM) (1st)
IPFire
Ranking in Firewalls
35th
Average Rating
8.0
Reviews Sentiment
8.3
Number of Reviews
3
Ranking in other categories
No ranking in other categories
Palo Alto Networks NG Firew...
Ranking in Firewalls
6th
Average Rating
8.6
Reviews Sentiment
7.1
Number of Reviews
199
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of June 2026, in the Firewalls category, the mindshare of Fortinet FortiGate is 15.1%, down from 21.7% compared to the previous year. The mindshare of IPFire is 1.1%, down from 1.8% compared to the previous year. The mindshare of Palo Alto Networks NG Firewalls is 5.1%, up from 3.7% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Firewalls Mindshare Distribution
ProductMindshare (%)
Fortinet FortiGate15.1%
Palo Alto Networks NG Firewalls5.1%
IPFire1.1%
Other78.7%
Firewalls
 

Featured Reviews

JK
IP Network Security Specialist at MTN Ghana
Process-Level CPU Visibility: Introduce detailed CPU-usage metrics per subsystem (e.g., IPS engine, logging) so administrators can quickly identify and address performance spikes.
Analytics with FortiAnalyzer. Being able to pull in logs not just from our FortiGates but from all our other firewalls and then get them in one view has been a game changer. Whether I’m building an executive dashboard or doing a deep dive forensics session, I get everything I need without navigating consoles.Straightforward Application Control. FortiGate spots and blocks unwanted apps (eq. like BitTorrent or streaming services) with accuracy. Segmentation with VDOMs. We’ve carved our data center into four logical ‘mini-firewalls’ enterprise, core, billing, and WAF—all on one box. Each has its own rules and logs, and any traffic between them still gets inspected. It’s like having multiple appliances without the extra hardware. Always-Up-to-Date Threat Feeds. Daily signature updates and AI-driven threat sensing mean we’re blocking the latest vulnerabilities almost as soon as they’re announced.
AE
Chief Technology Officer at Agileware Limited
Firewall deployment has secured mission-critical public apps and simplifies Linux-based management
The best features IPFire offers include its very intuitive nature because, even though it has a Linux back-end, in terms of configuration, it has a very rich GUI interface. The GUI and configuration features of IPFire have made my work easier and more efficient because their positioning and the sequence with which I follow is easy. In terms of all the processes, what you need to do at first and the next thing that you need to do is clear. The GUI is well arranged in sequential order, so you can follow that from whatever you want to do until you get the target objective. IPFire includes features with a very robust and rich community that is very much valid in terms of content. IPFire has positively impacted my organization by giving us some mileage. At least, a lot of organizations now know that we have a solution that can deliver the same value.
Nitin Yadav - PeerSpot reviewer
Network & Security Engineer at Arrow PC Network Pvt.Ltd.
Strong threat prevention has reduced phishing and malware while I monitor traffic in depth
Palo Alto Networks NG Firewalls offers application and user awareness, which allow me to control traffic based on threats. The product includes threat prevention, advanced threat prevention, and deep packet inspection that really helps prevent issues in our network. Deep packet inspection inspects full traffic content, even inside applications and encrypted sessions. Deep packet inspection makes a very practical difference day to day because it lets me see and control what is actually inside the traffic, not just the open port or IP. I have real visibility of which application is running instead of just seeing HTTPS. Palo Alto Networks NG Firewalls WildFire sandboxing is really good at detecting and blocking zero-day malware automatically, along with its GlobalProtect and DNS security features. Using Palo Alto Networks NG Firewalls positively impacts my organization by providing strong security, better visibility, faster response, and simplified operations. After deploying Palo Alto Networks NG Firewalls in our network, it blocks malicious traffic and prevents compromises that occurred before Palo Alto Networks NG Firewalls. I can now block outside IPs to prevent issues. After Palo Alto Networks NG Firewalls installation, I reduced 60 to 70 percent of malware and phishing attacks. Its threat prevention and DNS security features detect these attacks, block malicious domains, and reduce manual efforts for the security team.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"This solution has helped us have control over our network."
"The scalability is good in Fortinet FortiGate."
"Anti-Spam web content filterinG."
"We have peace of mind; we do work in a very dangerous environment, the internet, and this device gives us alerts and the opportunity to know what is going on."
"With Fortinet FortiGate, we improved security significantly."
"Fortinet FortiGate is used to prevent security failures. Since implementing the solution, we have seen improvements in security and in the distribution of our network."
"The best feature of Fortinet FortiGate is the IPS or IDS implementation. I appreciate most the agility or the flexibility to create hashes to block incoming threats, and I can integrate with third-party threat intelligence with our FortiGate."
"It has improved our productivity because we can control the people who go on the internet, and we control their access to social networks."
"IPFire has prevented any kind of hacking and enables us to comply with customer requirements."
"Regarding IPFire's AI capabilities, I think they are quite focused; in all the deployments I have done, I have not had any incidents or breaches."
"I would rate the stability as ten out of ten for IPFire."
"The most valuable feature is advanced URL filtering. Its prevention capabilities and DNS security are also valuable. It pinpoints any suspicious activities and also prevents the users from doing certain things."
"The most valuable features are Wildfire, URL filtering, and IPS."
"Operationally, it is easier, and the manageability and their security features are good."
"The user experience is good and the configuration is very easy."
"I would rate Palo Alto Networks NG Firewalls a nine out of ten, as it is a very good and stable solution, and I recommend it over Check Point, Fortinet, and Cisco; it stands out as the leader."
"In addition to our environment being secure, we can monitor compliance of VPN users."
"Innovative, advanced threat protection is the most valuable feature."
"The DNS sync code in your filtering is the most valuable feature of the Palo Alto Networks NG Firewalls."
 

Cons

"The solution is quite expensive and I'd like to see the cost reduced."
"I don't like that anything more than very basic reporting is not included. You have to buy their cloud module that's an add-on for getting more customized reporting."
"Due to its higher cost, Fortinet FortiGate can lead to increased operational expenses."
"There are some complex administration tasks in their administration portal. That needs to be improved."
"The web interface could be made better."
"It should have a better pricing plan. It is too expensive. It should also have a more granular view of the attack. I don't have FortiAnalyzer, and it is difficult for me to have a complete view when there is an attack on my server."
"Fortinet FortiGate IPS could improve the configuration. In some use cases, there can be some configuration conflicts."
"I would like reporting to be improved and should offer a lot more tools to monitor the products."
"The graphical interface could be much better."
"Accessing the internet was a bit complicated."
"I would rate IPFire 8 out of 10 because I do not think there is any solution anywhere in the world that is 100 percent efficient."
"It is a complete product, but the SSL inspection feature requires some improvements. We need to deploy certificates at each end point to completely work out the UTM solutions. If you enable SSL encryption, it is a tedious process. It takes a lot of time to deploy the certificates to all endpoints. Without SSL inspection, UTM features will not work properly. So, we are forced to enable this SSL inspection feature."
"I would like to see better third-party orchestration so that it is easier for the team to work with different products."
"The price is expensive and should be reduced to make it more competitive."
"Palo Alto could do better with integrating the Palo Alto Next-Gen Firewall with SD-WAN. The biggest issue with Palo Alto is that they are expensive. They are very expensive for what they offer. They should improve their pricing."
"Configurations related to different operating systems can be complex, and we have encountered issues with Linux systems."
"The solution could offer better pricing. We'd like it if it could be a bit more affordable for us."
"Personally, I feel that their dashboards for reporting and things like that need some improvement."
"The advanced manual protection needs to be improved a little bit because they used to make a cloud manual analysis for the cloud."
 

Pricing and Cost Advice

"It is an expensive solution."
"It is very cost-effective. You get features similar to other firewalls, such as Palo Alto, but at a lower price."
"The pricing is very reasonable."
"I give the pricing of the solution a six out of ten."
"FortiGate's pricing falls within the mid-range when compared to other leading firewall solutions."
"The solution is more expensive than Sophos. It could be cheaper. The licensing is on a yearly basis. We have had it for about three years. We must only pay extra for the license, additional requirements, and the hardware box."
"If you are looking for a quality product, it will come at a higher price. Expecting them to be significantly cheaper is unrealistic. In terms of pricing, it is a bit costly. However, the functionality and support offered are worth it."
"The pricing for this solution is reasonable."
Information not available
"Its price should be improved."
"You pay based on the kind of license you require, but comparatively, it is not very expensive."
"Paul Alto is the most expensive solution in this category."
"The price of the solution is on the higher side compared to competitors."
"After the hardware and software are procured, it is the AMC support that has to be renewed yearly."
"Palo Alto Networks NG Firewalls are very expensive compared to other firewalls such as Fortinet. As a result, Palo Alto is losing some of its market share."
"While Palo Alto Networks Next-Generation Firewalls may be considered expensive, their quality justifies the cost."
"Palo Alto Networks NG Firewalls are the Cadillac standard, and you do pay Cadillac pricing. However, the protection is worth the steep price."
report
Use our free recommendation engine to learn which Firewalls solutions are best for your needs.
902,417 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Comms Service Provider
10%
Computer Software Company
9%
Manufacturing Company
9%
Financial Services Firm
7%
Comms Service Provider
21%
Computer Software Company
10%
University
8%
Government
7%
Manufacturing Company
10%
Computer Software Company
9%
Financial Services Firm
9%
Comms Service Provider
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business369
Midsize Enterprise139
Large Enterprise195
No data available
By reviewers
Company SizeCount
Small Business77
Midsize Enterprise57
Large Enterprise87
 

Questions from the Community

Which is the better NGFW: Fortinet Fortigate or Cisco Firepower?
When you compare these firewalls you can identify them with different features, advantages, practices and usage a...
What is the biggest difference between Sophos XG and FortiGate?
From my experience regarding both the Sophos and FortiGate firewalls, I personally would rather use FortiGate. I know...
What are the biggest technical differences between Sophos UTM and Fortinet FortiGate?
As a solution, Sophos UTM offers a lot of functionality, it scales well, and the stability and performance are quite ...
What needs improvement with IPFire?
The graphical interface could be much better.
What is your primary use case for IPFire?
I use IPFire ( /products/ipfire-reviews ) to protect my home.
What advice do you have for others considering IPFire?
Sometimes configuring IPFire is challenging. Overall, I would rate this solution as eight out of ten.
What is a better choice, Azure Firewall or Palo Alto Networks NG Firewalls?
Azure Firewall Vs. Palo Alto Network NG Firewalls Both solutions provide stellar stability and security. Azure Firew...
Features comparison between Palo Alto and Fortinet firewalls
In the best tradition of these questions, Feature-wise both are quite similar, but each has things it's better at, it...
Which is better - Palo Alto Networks NG Firewalls or Sophos XG?
Palo Alto Networks NG Firewalls have both great features and performance. I like that Palo Alto has regular threat si...
 

Also Known As

Fortinet FortiGate Next-Generation Firewall
No data available
Palo Alto NGFW, Palo Alto Networks Next-Generation Firewall
 

Overview

 

Sample Customers

Amazon Web Services, Microsoft, IBM, Cisco, Dell, HP, Oracle, Verizon, AT&T, T-Mobile, Sprint, Vodafone, Orange, BT Group, Telstra, Deutsche Telekom, Comcast, Time Warner Cable, CenturyLink, NTT Communications, Tata Communications, SoftBank, China Mobile, Singtel, Telus, Rogers Communications, Bell Canada, Telkom Indonesia, Telkom South Africa, Telmex, Telia Company, Telkom Kenya
1. Siemens 2. IBM 3. Cisco 4. Dell 5. HP 6. Intel 7. Oracle 8. Google 9. Microsoft 10. Amazon 11. Apple 12. Facebook 13. Twitter 14. Netflix 15. Adobe 16. SAP 17. VMware 18. Juniper Networks 19. Ericsson 20. Nokia 21. AT&T 22. Verizon 23. T-Mobile 24. Vodafone 25. Orange 26. Deutsche Telekom 27. British Telecom 28. Comcast 29. Time Warner 30. Sony 31. Samsung 32. LG
SkiStar AB, Ada County, Global IT Services PSF, Southern Cross Hospitals, Verge Health, University of Portsmouth, Austrian Airlines, The Heinz Endowments
Find out what your peers are saying about IPFire vs. Palo Alto Networks NG Firewalls and other solutions. Updated: June 2026.
902,417 professionals have used our research since 2012.