No more typing reviews! Try our Samantha, our new voice AI agent.

Palo Alto Networks NG Firewalls vs Stormshield Network Security comparison

Sponsored
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Fortinet FortiGate
Sponsored
Average Rating
8.4
Reviews Sentiment
6.9
Number of Reviews
592
Ranking in other categories
Secure Web Gateways (SWG) (2nd), Firewalls (1st), Intrusion Detection and Prevention Software (IDPS) (1st), Software Defined WAN (SD-WAN) Solutions (1st), WAN Edge (1st), ZTNA (1st), Unified Threat Management (UTM) (1st)
Palo Alto Networks NG Firew...
Average Rating
8.6
Reviews Sentiment
7.1
Number of Reviews
199
Ranking in other categories
Firewalls (6th)
Stormshield Network Security
Average Rating
7.8
Reviews Sentiment
5.4
Number of Reviews
18
Ranking in other categories
Unified Threat Management (UTM) (14th)
 

Featured Reviews

Mageshwaran S - PeerSpot reviewer
Solution Architect at airtel
Enables customers to manage security effortlessly with intuitive features and easy integration
In terms of improvements for Fortinet FortiGate, they could offer evaluation licenses, as compared to Meraki, which provides a 90-day evaluation. In Fortinet FortiGate, they do not provide standard evaluation licenses; instead, we need to request them from the OEM through the account manager for POCs. If we want to conduct a demo, we need to work with real hardware. In comparison to Cisco, we have DCloud, which helps with providing demos to customers, but in Meraki, I need to reach out to them, book a lab, and they need to provide all the hardware. I need remote access and L3 engineers to program it; only then can I offer a real-time demo to the customer.
Nitin Yadav - PeerSpot reviewer
Network & Security Engineer at Arrow PC Network Pvt.Ltd.
Strong threat prevention has reduced phishing and malware while I monitor traffic in depth
Palo Alto Networks NG Firewalls offers application and user awareness, which allow me to control traffic based on threats. The product includes threat prevention, advanced threat prevention, and deep packet inspection that really helps prevent issues in our network. Deep packet inspection inspects full traffic content, even inside applications and encrypted sessions. Deep packet inspection makes a very practical difference day to day because it lets me see and control what is actually inside the traffic, not just the open port or IP. I have real visibility of which application is running instead of just seeing HTTPS. Palo Alto Networks NG Firewalls WildFire sandboxing is really good at detecting and blocking zero-day malware automatically, along with its GlobalProtect and DNS security features. Using Palo Alto Networks NG Firewalls positively impacts my organization by providing strong security, better visibility, faster response, and simplified operations. After deploying Palo Alto Networks NG Firewalls in our network, it blocks malicious traffic and prevents compromises that occurred before Palo Alto Networks NG Firewalls. I can now block outside IPs to prevent issues. After Palo Alto Networks NG Firewalls installation, I reduced 60 to 70 percent of malware and phishing attacks. Its threat prevention and DNS security features detect these attacks, block malicious domains, and reduce manual efforts for the security team.
Zsolt Jónás - PeerSpot reviewer
System Administrator at NaxoNet
Advanced GUI and layered security have supported compliance and simplified intrusion prevention
I haven't had a task that I couldn't solve with Stormshield Network Security. The active-active high availability solution would be beneficial because currently, if you build a high availability solution with Stormshield Network Security, you have a main device and another one is a backup device. The HA can switch between them, but it would be good to have a master-master solution, not just a master-slave one. I could set a URL that I can call to update the DNS record. Currently, Stormshield Network Security devices support DynDNS, which is not a usual feature request from a server environment. I have my own solution instead of DynDNS because I don't prefer it, so I have my own service for that. However, the GUI does not support using a custom service instead of DynDNS. I had to solve it in the console on Stormshield Network Security device, but it would be much better if it was reachable on the GUI. I had to figure out a trick for the IPsec configuration. In the IPsec config, we have to provide the remote side's IP address, but it's always changing. This means that an office, for example a company that has an office but without a fixed IP address, cannot be used with IPsec VPN.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"It is very flexible to use."
"The solution is very user friendly. The user interface in particular is quite nice."
"FortiGate has threat protection, antivirus, and even SSL encryption and decryption, and a few customers also use this firewall for web filtering and application control."
"It's quite comfortable to handle the FortiGate firewall."
"The solution is stable and quite reliable; there are no bugs or glitches and it doesn't crash or freeze."
"It's a user-friendly firewall. Most of the tasks are very simple. It's simple to configure and troubleshoot this firewall."
"The most valuable features of Fortinet FortiGate IPS are firewall and filtering."
"Because of the flexibility, the advanced user features, the high level of security controls, and the tweaks that are available for the user, I would rate this solution an eight out of ten."
"I have experience with multiple firewall vendors and I have seen that products from other vendors have bugs."
"We chose Palo Alto for its security features; it's quite nice, very user-friendly, powerful, and there are barely any bugs."
"With App-ID, we can identify exact traffic. Even if someone tries to fool the firewall with a different port number, or with the correct port number, Palo Alto is able to identify what kind of traffic it is."
"The Palo Alto Networks NG Firewalls excel in their integration capabilities."
"Palo Alto Networks NG Firewalls' IPS is more complete and is very good. This is a user-friendly solution that is easy to install, and it provides the best protection."
"They are regularly releasing new versions that include more integration with third-party services."
"The interface and dashboards are good."
"Palos Alto's firewalls have machine learning software and sandboxing, and everything is one step ahead of all the competitors."
"I like that it works fine. Stormshield is a very good solution."
"This solution is quick and easy to configure."
"Filters and URL filtering helped us to optimize our bandwidth."
"I can see what traffic is going on. I can easily block any programs from attacks."
"The most valuable features of this solution are the URL filtering database, which is great and contains all internet categories, the highly scalable interface that I can turn into what I want including hybrid, bridge, or router mode, the security with no back doors that is more secure than other solutions, and the hardware performance that is also better than others."
"This product has improved the way our organization functions."
"Our organization's main concern is stability, and this is a stable solution."
"The StormShield solution has enabled us to fully implement best practices from Microsoft in the cloud : the hub and spoke architecture."
 

Cons

"Performance on the box and technical support are areas where Fortinet FortiGate can be improved."
"The solution could maybe use more integration with artificial intelligence to be more proactive."
"Some configuration elements cannot be easily altered once created."
"The FortiGate reporting system needs to be more detailed about files."
"I have to say that the initial setup was complex. The deployment took a few days to get set up. Initially, we were using an IPVanish. We switched to this tool since we thought it would be easier. But it turns out it wasn't easier to set up and run."
"I have an issue with NAT only, in that I can't allow traffic from outside to inside using a NAT pool."
"There are too many updates coming for VPN, and the VPN keeps disconnecting frequently, which I find problematic. It does what it's supposed to do, but I practically face reconnection issues with the VPN."
"I think the only issue that needs improvement is the interface."
"Palo Alto can do a little bit better when it comes to the User-ID part. I've been facing problems related to double authentication. You have a computer user, but you also have a VPN user, and when you do a single sign-on to another page, these logs can sometimes generate a problem notification. It doesn't happen a lot, but in some networks, it could be a problem. It would be very helpful to have the ability to restrict the connections that you can have in your VPN. For example, if you have the credentials, you can connect with the same user account from different computers or devices. If you have the domain information, you can connect from different devices. That's a problem that they need to address and resolve. They should ensure that at any moment, only one person is connected through a specific user account."
"Its price can be better."
"In my opinion, the training provided is satisfactory, but there is certainly room for improvement. It would be great to have more comprehensive training at a lower cost, or even for free."
"I would like the option to be able to block the traffic from a specific country in a few clicks."
"We are not happy with Palo Alto at all."
"PA-220 Next-Generation Firewall would be perfect if it has spam filtering."
"The tech support was once great, but now it is poor. The tech support has gone south."
"The customer-facing side needs to be improved in terms of the engagement and involvement of support staff."
"With Stormshield, there are difficulties joining things, and it can be complex depending on the architecture."
"One thing, though, is that not all the fields are activated yet and we were informed that it will take at least one month."
"Stormshield Network Security is quite expensive."
"The filtering configuration could be better. We have some difficulties with the filtering configuration and the filter extension."
"This is not a next-generation firewall."
"The SD card could be more secure."
"An application firewall like other next generation firewalls have."
"The stability is not that good based on my experience. We have a lot of disruptions when it comes to Stormshield."
 

Pricing and Cost Advice

"I rate the pricing an eight and a half on a scale of one to ten, where one is low, and ten is high."
"I would rate the pricing a seven out of ten"
"It scales well if you know what to buy from a physical box standpoint. They seem to offer something for every level."
"It is an inexpensive solution."
"Setup cost may be not so low, as you expect, because it depends on different factors, but TCO for 5 years may pleasantly surprise you."
"I rate the product's pricing a seven out of ten. Its one-year license cost is competitive with three and five-year licenses offered by other products."
"Licensing for Fortinet FortiGate is on a yearly basis. Pricing for it is a bit high. It could be cheaper."
"Fortinet FortiGate's price can be reduced."
"Palo Alto Networks NG Firewalls are more expensive than Cisco firewalls, but slightly less expensive than Juniper firewalls."
"I don't know about the price of the platform or the license fees, as the finance department deals with that. I only bill for the materials involved in the design."
"Active/Passive mode is very redundant, but they require you to buy all the associated licensing for both firewalls, which is kind of a waste of money because you are really only using the services on one firewall at a time."
"Its price is comparable to other companies. The license is on a one-year or three-year basis. It depends on the customers what they want to go for. There are some features that require an additional license, and there is also the cost of the support."
"Cost-wise, I don't see much difference in network-related costs, but this is a premium-grade firewall. There is a cost involved, and you must pay for that to get the most out of it. Its licensing costs are straightforward. There aren't any hidden costs."
"That solution's pricing and/or licensing are very convoluted."
"Palo Alto Networks NG Firewalls' price is expensive."
"If someone doesn't have a security platform in their network, then the following licenses will be required: antivirus, anti-spyware, vulnerability, and Wildfire analysis. There are also licenses for GlobalProtect and support."
"We chose Stormshield for its price, as the Azure firewall was too expensive."
"I think the price is good."
"The pricing could be better."
"For mid-sized companies, they sell their appliances for good prices."
"The SN200 series costs between $500 USD and $600 USD per year, whereas the SN700 series costs approximately $1,000 annually."
"The price of this solution and the price of support are ok."
"We bought a three-year license, and we renew it whenever it expires. The price could be better. It's always very expensive."
report
Use our free recommendation engine to learn which Firewalls solutions are best for your needs.
900,747 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Comms Service Provider
10%
Computer Software Company
10%
Manufacturing Company
9%
Financial Services Firm
7%
Manufacturing Company
10%
Computer Software Company
9%
Financial Services Firm
9%
Comms Service Provider
6%
Comms Service Provider
16%
Manufacturing Company
12%
Computer Software Company
10%
Construction Company
10%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business370
Midsize Enterprise138
Large Enterprise195
By reviewers
Company SizeCount
Small Business77
Midsize Enterprise57
Large Enterprise87
By reviewers
Company SizeCount
Small Business11
Midsize Enterprise5
Large Enterprise2
 

Questions from the Community

Which is the better NGFW: Fortinet Fortigate or Cisco Firepower?
When you compare these firewalls you can identify them with different features, advantages, practices and usage a...
What is the biggest difference between Sophos XG and FortiGate?
From my experience regarding both the Sophos and FortiGate firewalls, I personally would rather use FortiGate. I know...
What are the biggest technical differences between Sophos UTM and Fortinet FortiGate?
As a solution, Sophos UTM offers a lot of functionality, it scales well, and the stability and performance are quite ...
What is a better choice, Azure Firewall or Palo Alto Networks NG Firewalls?
Azure Firewall Vs. Palo Alto Network NG Firewalls Both solutions provide stellar stability and security. Azure Firew...
Features comparison between Palo Alto and Fortinet firewalls
In the best tradition of these questions, Feature-wise both are quite similar, but each has things it's better at, it...
Which is better - Palo Alto Networks NG Firewalls or Sophos XG?
Palo Alto Networks NG Firewalls have both great features and performance. I like that Palo Alto has regular threat si...
What needs improvement with Stormshield Network Security?
I haven't had a task that I couldn't solve with Stormshield Network Security. The active-active high availability sol...
What is your primary use case for Stormshield Network Security?
I already use Stormshield Network Security, and I am now looking for a new solution. I am already working with Storms...
What advice do you have for others considering Stormshield Network Security?
The pricing is increasing, and I would say it is a bit expensive. Palo Alto and others are much more expensive, but S...
 

Also Known As

Fortinet FortiGate Next-Generation Firewall
Palo Alto NGFW, Palo Alto Networks Next-Generation Firewall
NETASQ Firewalls
 

Overview

 

Sample Customers

Amazon Web Services, Microsoft, IBM, Cisco, Dell, HP, Oracle, Verizon, AT&T, T-Mobile, Sprint, Vodafone, Orange, BT Group, Telstra, Deutsche Telekom, Comcast, Time Warner Cable, CenturyLink, NTT Communications, Tata Communications, SoftBank, China Mobile, Singtel, Telus, Rogers Communications, Bell Canada, Telkom Indonesia, Telkom South Africa, Telmex, Telia Company, Telkom Kenya
SkiStar AB, Ada County, Global IT Services PSF, Southern Cross Hospitals, Verge Health, University of Portsmouth, Austrian Airlines, The Heinz Endowments
ACESUR group, Ministry of Education Oman, Anios Laboratories, Zain, DLM Location
Find out what your peers are saying about Fortinet, Netgate, Sophos and others in Firewalls. Updated: May 2026.
900,747 professionals have used our research since 2012.