No more typing reviews! Try our Samantha, our new voice AI agent.

IPFire vs Palo Alto Networks NG Firewalls comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Jan 25, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Fortinet FortiGate
Sponsored
Ranking in Firewalls
1st
Average Rating
8.4
Reviews Sentiment
6.8
Number of Reviews
591
Ranking in other categories
Secure Web Gateways (SWG) (2nd), Intrusion Detection and Prevention Software (IDPS) (1st), Software Defined WAN (SD-WAN) Solutions (1st), WAN Edge (1st), ZTNA (1st), Unified Threat Management (UTM) (1st)
IPFire
Ranking in Firewalls
35th
Average Rating
8.0
Reviews Sentiment
8.5
Number of Reviews
2
Ranking in other categories
No ranking in other categories
Palo Alto Networks NG Firew...
Ranking in Firewalls
6th
Average Rating
8.6
Reviews Sentiment
7.2
Number of Reviews
199
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of May 2026, in the Firewalls category, the mindshare of Fortinet FortiGate is 16.0%, down from 21.6% compared to the previous year. The mindshare of IPFire is 1.2%, down from 1.7% compared to the previous year. The mindshare of Palo Alto Networks NG Firewalls is 5.1%, up from 3.6% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Firewalls Mindshare Distribution
ProductMindshare (%)
Fortinet FortiGate16.0%
Palo Alto Networks NG Firewalls5.1%
IPFire1.2%
Other77.7%
Firewalls
 

Featured Reviews

Abhinandan Yadav - PeerSpot reviewer
Network Security Engineer at a retailer with 11-50 employees
Unified security and sd-wan have improved uptime and cut wan costs for multi-site branches
Users report stability issues in certain versions, which requires regular updates. Real-world attacks have also highlighted the need for urgent patching of vulnerabilities.Fortinet FortiGate, while a powerful and feature-rich web firewall, could improve in areas like firmware stability, documentation, and ease of use. The learning curve can be steep for some users. For beginners, support quality can vary, and frequent updates with occasional vulnerabilities call for careful patch management. However, once Fortinet FortiGate is configured, it remains highly reliable and efficient. Customer support needs improvement, as I find it very slow, with reports from other users reflecting that customer support is inadequate.
DS
Head Competence Team IT at Duktig Brand
Blocking access from specific countries and ensuring robust security have been effortlessly achieved
I use IPFire to protect my home The best feature of IPFire is the location block functionality. It allows me to block certain countries from accessing my site. Additionally, it is a solution that is available for free, which is perfect. The graphical interface could be much better. I have…
Abhinandan Yadav - PeerSpot reviewer
Network Security Engineer at a retailer with 11-50 employees
Advanced visibility has transformed security policies and provides proactive threat prevention
Palo Alto Networks NG Firewalls are powerful, but there are areas for improvement that could enhance their effectiveness, such as cost and licensing models. One of the main challenges we face is the high cost, especially for small to mid-sized businesses (SMBs), with licensing for features such as threat prevention, URL filtering, and WildFire being quite expensive. Additionally, centralized management with Panorama is a dependency for managing multiple firewalls, leading to added costs and complexity, and the built-in centralized management features could be made more user-friendly. Moreover, the learning curve associated with the initial setup and advanced configuration including NAT, decryption, and routing can be complex for new users, and enhancements in logging and reporting could also improve the user experience. There are a few more areas where improvements could streamline operations, such as optimizing commit times. Sometimes committing changes takes a noticeable amount of time, particularly for larger configurations, so a faster commit option would significantly help during urgent troubleshooting. Easier policy troubleshooting is necessary as well. Even though logs are detailed, finding the exact rule match and issue can still be time-consuming in complex environments, so having automated policy simulation and a recommendation tool would expedite troubleshooting. Additionally, better default templates and best practices for SMB data centers and branch offices would speed up deployment and reduce errors. Enhancing integration visibility through a unified dashboard would simplify monitoring, and improving the firmware upgrade process to allow for a more seamless zero downtime upgrade would also enhance operations, as upgrades are stable but typically require careful planning and downtime.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"SD-WAN has had a positive impact by reducing the operational costs in terms of headcount and management."
"Fortinet FortiGate saves a lot of time in expert hours from an expert engineer because the administration of the Fortinet FortiGate solution is easy, which may lead to fewer hours of an engineer spent on Fortinet FortiGate."
"What I like the most is the configuration and that it's simple, and straightforward to maintain."
"The response is very quick and they can visually resolve our problems in a short period."
"The stability is great; there are no issues with crashing or freezing, and there are no bugs or glitches."
"The flexibility and ease of configuration are the most valuable features."
"The most important features with FortiGate are the web filter and application controls. We can control our internet usage and use the web filter for application purposes."
"The interest of the Fortinet FortiGate appliance is the ability to manage quickly and easily the different functionalities."
"IPFire has prevented any kind of hacking and enables us to comply with customer requirements."
"I would rate the stability as ten out of ten for IPFire."
"This solution not only provides better security than flat VLAN segments but allows easy movement through the lifecycle of the server."
"The most valuable aspect of this solution is pre-sales and post-sales because of the support and relationship building."
"Good functionality and features."
"I have experience with multiple firewall vendors and I have seen that products from other vendors have bugs."
"Palos Alto's firewalls have machine learning software and sandboxing, and everything is one step ahead of all the competitors."
"Palo Alto Networks NG Firewalls have reduced downtime in my customers' environments."
"Decryption is one of Palo Alto Networks NG Firewalls' best features because we can decrypt by category. For instance, we can decrypt everything except for bank traffic so that we don't interfere with the passwords and two-factor authentication of those checking their bank accounts at work. We can still monitor for malware and other threats that come through a secure channel. It's seamless for users. The URL filtering and IPS are both great as well."
"The product's most valuable features are the ease of deployment, regularly updated security information, and robust hardware."
 

Cons

"Being a great product, some changes in the pricing would make it a great choice for even more organizations."
"Some configuration elements cannot be easily altered once created."
"The configuration part was challenging, especially converting configurations from another OEM to FortiGate."
"Its performance can be better. We have had performance issues in the past, but we sometimes tend to find that it is more related to what we do in our network than anything else. It is quite a good product, and there isn't much to improve."
"At the moment, the main concern is the pricing and the type of licensing."
"The one concern I have with Fortinet FortiGate is the firmware versions, which often have many bugs when upgraded, leading us to revert back to older versions multiple times in my lifecycle."
"The support is very poor with FortiGate IPS and they need to look into fixing it. The senior support agent does not honor their commitments when ordering products."
"If you have the firmware version 6.4.3 and are using FortiLink in VLAN, it has trouble with tunneling networks for a wireless network; it won't give it a route to the internet."
"The graphical interface could be much better."
"Accessing the internet was a bit complicated."
"The stability, scalability for enterprise-level organizations, and technical documentation have room for improvement."
"Based on the features that I have seen so far, I do not see any room for improvement, but they can improve their CLI documentation. I haven't really seen much when it comes to CLI documentation."
"Understanding the flow and application of securities can be complex, requiring navigation across different sections."
"I am in GCC in the Middle East. The support that we are getting from Palo Alto is disastrous. The problem is that the support ticket is opened through the distributor channel. Before opening a ticket, we already do a lot of troubleshooting, and when we open a ticket, it goes to a distributor channel. They end up wasting our time again doing what we have already done. They execute the same things and waste time. The distributor channel's engineer tries to troubleshoot, and after spending hours, they forward the ticket to Palo Alto. It is a very time-consuming process. The distributor channels also do not operate 24/7, and they are very lazy in responding to the calls."
"The pricing could be improved upon."
"I would like to see more in terms of reporting tools and the threat analysis capabilities."
"These are not the cheapest firewalls; they are quite expensive."
"Most of the time, they were pretty good, but sometimes technical support couldn't resolve the issue, and they don't know what to do."
 

Pricing and Cost Advice

"The Indian market is different than the European and American markets. When you compare they need to be a bit more aggressive on pricing."
"While slightly more affordable than competitors, it remains relatively expensive due to its inclusive subscription."
"The pricing is better compared to other solutions like Check Point, Arista, or Cisco."
"It was probably about $2,500 per firewall. It was all included. It included support, services, threat management software, and 24/7 FortiCare on it. Cisco products are more expensive."
"The cost of Fortinet FortiGate is competitive and not expensive compared to other enterprise- grade solutions. On average, the license cost per year is around seventy percent of the firewall's purchase price."
"It's an expensive solution."
"As far as I'm aware, in our case, it's just a yearly pricing arrangement with no additional licensing costs."
"Pricing and licensing is a little bit complicated in FortiGate. They are always on the higher side. This is one issue that we always raise with the company that they should reduce the price according to Indian market requirements. There are no costs in addition to the standard licensing fees."
Information not available
"Compared to other products, the pricing is flexible and reasonable."
"It's an expensive product."
"Palo Alto Networks NG Firewalls are expensive compared to other solutions."
"That solution's pricing and/or licensing are very convoluted."
"The cost is steep, but most firewalls cost a lot."
"I would assume that it's still within mid-range given its company structure and everything else. My guess is it's still okay."
"Pricing is yearly, but it depends. You could pay on a yearly basis, or every three years. If you want to add a device or two, there would be an additional cost. Also, if you want to do an assessment, or other similar add-on, you have to pay accordingly for the additional service."
"The product is expensive compared to competing products but uses a similar type of pricing model based on hardware, software and maintenance."
report
Use our free recommendation engine to learn which Firewalls solutions are best for your needs.
893,915 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
10%
Comms Service Provider
10%
Manufacturing Company
9%
Financial Services Firm
7%
Comms Service Provider
21%
Computer Software Company
10%
Manufacturing Company
8%
University
7%
Computer Software Company
10%
Manufacturing Company
9%
Financial Services Firm
8%
Comms Service Provider
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business367
Midsize Enterprise135
Large Enterprise193
No data available
By reviewers
Company SizeCount
Small Business77
Midsize Enterprise56
Large Enterprise85
 

Questions from the Community

Which is the better NGFW: Fortinet Fortigate or Cisco Firepower?
When you compare these firewalls you can identify them with different features, advantages, practices and usage a...
What is the biggest difference between Sophos XG and FortiGate?
From my experience regarding both the Sophos and FortiGate firewalls, I personally would rather use FortiGate. I know...
What are the biggest technical differences between Sophos UTM and Fortinet FortiGate?
As a solution, Sophos UTM offers a lot of functionality, it scales well, and the stability and performance are quite ...
What needs improvement with IPFire?
The graphical interface could be much better.
What is your primary use case for IPFire?
I use IPFire ( /products/ipfire-reviews ) to protect my home.
What advice do you have for others considering IPFire?
Sometimes configuring IPFire is challenging. Overall, I would rate this solution as eight out of ten.
What is a better choice, Azure Firewall or Palo Alto Networks NG Firewalls?
Azure Firewall Vs. Palo Alto Network NG Firewalls Both solutions provide stellar stability and security. Azure Firew...
Features comparison between Palo Alto and Fortinet firewalls
In the best tradition of these questions, Feature-wise both are quite similar, but each has things it's better at, it...
Which is better - Palo Alto Networks NG Firewalls or Sophos XG?
Palo Alto Networks NG Firewalls have both great features and performance. I like that Palo Alto has regular threat si...
 

Also Known As

Fortinet FortiGate Next-Generation Firewall
No data available
Palo Alto NGFW, Palo Alto Networks Next-Generation Firewall
 

Overview

 

Sample Customers

Amazon Web Services, Microsoft, IBM, Cisco, Dell, HP, Oracle, Verizon, AT&T, T-Mobile, Sprint, Vodafone, Orange, BT Group, Telstra, Deutsche Telekom, Comcast, Time Warner Cable, CenturyLink, NTT Communications, Tata Communications, SoftBank, China Mobile, Singtel, Telus, Rogers Communications, Bell Canada, Telkom Indonesia, Telkom South Africa, Telmex, Telia Company, Telkom Kenya
1. Siemens 2. IBM 3. Cisco 4. Dell 5. HP 6. Intel 7. Oracle 8. Google 9. Microsoft 10. Amazon 11. Apple 12. Facebook 13. Twitter 14. Netflix 15. Adobe 16. SAP 17. VMware 18. Juniper Networks 19. Ericsson 20. Nokia 21. AT&T 22. Verizon 23. T-Mobile 24. Vodafone 25. Orange 26. Deutsche Telekom 27. British Telecom 28. Comcast 29. Time Warner 30. Sony 31. Samsung 32. LG
SkiStar AB, Ada County, Global IT Services PSF, Southern Cross Hospitals, Verge Health, University of Portsmouth, Austrian Airlines, The Heinz Endowments
Find out what your peers are saying about IPFire vs. Palo Alto Networks NG Firewalls and other solutions. Updated: April 2026.
893,915 professionals have used our research since 2012.