Try our new research platform with insights from 80,000+ expert users

Palo Alto Networks NG Firewalls vs WatchGuard XTM [EOL] comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Oct 19, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Fortinet FortiGate
Sponsored
Average Rating
8.4
Reviews Sentiment
6.9
Number of Reviews
588
Ranking in other categories
Secure Web Gateways (SWG) (2nd), Firewalls (1st), Intrusion Detection and Prevention Software (IDPS) (1st), Software Defined WAN (SD-WAN) Solutions (1st), WAN Edge (1st), ZTNA (1st), Unified Threat Management (UTM) (1st)
Palo Alto Networks NG Firew...
Average Rating
8.6
Reviews Sentiment
7.2
Number of Reviews
197
Ranking in other categories
Firewalls (7th)
WatchGuard XTM [EOL]
Average Rating
8.0
Number of Reviews
34
Ranking in other categories
No ranking in other categories
 

Featured Reviews

Vasu Gala - PeerSpot reviewer
Manager, Information Technology Operation/Presales at TechMonarch
A stable solution with an intuitive interface and quick customer service
I have been working with Fortinet FortiGate, WatchGuard, Sophos, and SonicWall. I'm not as comfortable with SonicWall because of their UI and limitations. I prefer Fortinet above all other options. When it comes to configuration, I am confident in my ability to handle various tasks, including creating policies such as firewall rules, web policies, and application policies. Additionally, I can configure VPNs and implement load balancing, among other tasks. Overall, I feel much more comfortable working with Fortinet. Fortinet has made significant improvements by integrating AI with firewalls for threat analysis and prevention. In the past 2-3 years, they have launched FortiSASE and SIEM, and they also provide SOC services. Both Palo Alto and Fortinet FortiGate are excellent. While Fortinet FortiGate comes at higher prices, the functionality and support justify the cost. They promptly resolve firmware issues and inform all support providers about configuration changes.
SV
Solution Architect // Network Consultant at Group S
Network security has improved and allows detailed user-based control over encrypted traffic
Bandwidth usage is not something we use much, but it depends on the SD-WAN plugin because the application load balancing is based on the SD-WAN product. That functionality does not work as it should, although the App-ID is working very well. SD-WAN functionality is working, but when you compare it with other products on the market, it is very limited. Palo Alto also has ION devices, and ION devices together with Prisma Access or Strata Cloud Manager now are more the way to go than using Palo Alto Networks NG Firewalls on-premises. At the moment I have some issues, but the issues are more related to the general way of working of many vendors. They implement new things very fast and it is not always bug-free. With new releases, sometimes you still have some issues. This is the main concern. If you look back five or maybe ten years ago, the products were more stable and you had more decent releases, but that is something in general for many vendors. Palo Alto is also a factor with that. They want to bring new features to the market too fast. Features are a concern because all vendors try to compete against each other. If one vendor comes out with a new feature, then other vendors do the same. Sometimes they want to be the first on the market with it, and that sometimes introduces bugs or issues with the product.
Generalm4545 - PeerSpot reviewer
General Manager- IT & Automation - Serum at a pharma/biotech company with 1,001-5,000 employees
Protects from attack software and hacking but it doesn't provide the reports in a readable format
In my opinion, image clarity is very important, because I don't get the proper image product on reports. This means that functionality is not there. My engineer does not know how he can replace an order. We attach a log after any kind of keys using a utility instead. For the internet policies that we are implementing, the policy should be based on proper protocols. We use the default policies and there are a number of third-party protocols that appear here. Management with WatchGuard XTM means that out of policy is the problem from our side. In this way, we can not do effective services for people with this one. The policy definition with WatchGuard XTM is not proper for all use case requirements. I've got weekly business reports that I am expecting attachments with from WatchGuard XTM that display data for all kinds of consideration which should be required. Main User Functionality Level Order must adhere to using the admin functionality on the registry, or else our users publish their own name. Maybe these recommendations are irrelevant, but I say that the issue to improve most with WatchGuard XTM is the Main User Function.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"One of the most valuable features of FortiGate Next Generation Firewall (NGFW) is the ease of usability it offers."
"The most valuable feature of this solution is the analytics."
"The ROI is great, as these boxes are not that expensive compared to what they can do, their functionality, and the reporting you receive."
"It controls the traffic in the organization and the navigation of the Internet, blocks some sites, permits limited access to our information through the web, and lets us detect any attack of viruses or malware at the first point of contact."
"The most valuable features of Fortinet FortiGate are the APIs. They are the most widely known."
"For application filtration, I really appreciate many features of Fortinet FortiGate because it is more reliable, easy to use, and the reports are easy to read and understand."
"The best feature of Fortinet FortiGate is the IPS or IDS implementation."
"This firewall is an antivirus, protects against spam, and is an IPS."
"We have not had to replace hardware routers nor purchase additional hardware. So, that has provided a little bit of an ROI."
"This is arguably the best security protection that you can buy."
"The technology's very good. We have had a lot of good experience with this solution."
"The solution's most valuable feature is the robust firewall, which we can also use as a UTM device."
"The initial setup process is quite easy."
"We have seen a return on investment; some of the use cases that we have already delivered to the organization have shown that a lot of threats have been identified and have been blocked, and at the same time, the effort was significantly reduced on the deployment of new routes based on this."
"Palo Alto Networks NG Firewalls' application context, traffic flow, netting, and other features help provide protection in a more secure way."
"Palo Alto NGFW provides a unified platform that natively integrates all security capabilities, which is very useful."
"Go for it. It's a great product with many security features and offers great protection for your network."
"WatchGuard XTM2050A has enterprise class performance with the cost of an SMB class device."
"I like the HostWatch because I can see what traffic uses the most bandwidth and I can block that site."
"Flawless. I have had my firebox for 3 years now and never had an issue with it."
"For the current network demand, I think the product is worth buying as it is not too expensive and it has almost all the features that I need."
"It costs less than the SO works and others (like SonicWall, Cisco, and Barracuda) without increasing so much CPU use."
"I have found the GUI interface to be invaluable, as it is very intuitive and easy to manage."
"We use WatchGuard XTM as a privileged access management solution; I complained about another unstable product and we switched to WatchGuard, which has been good."
 

Cons

"At first glance, the interface for the device is very confusing."
"The captive portal could be improved."
"I would like to see improvements in the IPS/IDS feature to enhance protection against attacks from attackers, including ransomware protection."
"The ease of use could be improved."
"The learning curve is a bit higher."
"Some of the filtering is not robust, you can escape it with a VPN. Some of the users bypass some of the filters."
"The cloud features can be improved."
"The solution isn't exactly scalable, especially when it comes to the public cloud environment."
"I would like to see some Machine Learning because I have observed new types of attacks that are able to bypass existing security rules."
"In the cloud, the HA could be a lot better. Its price could also be better. It is very expensive."
"Palo Alto Networks NG Firewalls offer best-in-breed security but could improve by reducing their pricing."
"We use ACC which is a tool for verifying the activity or traffic within your network. Currently, in ACC, the time of the samples that they offer is about five minutes. When you try to go down to a shorter duration, you can't. You only have five minutes. They can provide samples for shorter durations, such as one minute."
"On the entry-level models I would say commit speeds need to be improved; if I make changes on the firewall and I want to commit changes, that can take two or three minutes to commit those changes."
"This solution cannot be implemented on-premises; it's only a cloud solution. The price is high as well."
"We haven't had any issues so far."
"The machine learning component on the firewall level requires more computing power to perform at the full production level. Therefore, the ML is currently providing partial real-time attack prevention."
"Sometimes the local firebox management tool is flaky."
"The technical support is very bad. The price is very high, the response time is very long, and technical support does not provide a general solution."
"The initial setup is neither simple nor complex. If you know the base in networking and how the firewall works, you will be able to figure it out.​"
"Expensive Requires client-server application to use some advanced features"
"The issue that we had was that the integration with Active Directory was a bit of a hassle."
"VPN tunnel lost packet."
"Licensing should be improved."
"The WatchGuard gateway wireless functionality for managing access points leaves much to be desired."
 

Pricing and Cost Advice

"Each feature costs money, so it is important to study your needs."
"The solution is very expensive so pricing is rated a one out of ten."
"I would rate the pricing a five out of ten"
"I do not have first-hand experience with the rice of Fortinet FortiGate, but I have heard the price was reasonable."
"If the price of the license in Fortinet FortiGate was less expensive it would be better."
"It's a very full-featured and it's priced well solution."
"It has a competitive price."
"The price depends on the size of the company. From the beginning, you just want to know the internet bandwidths, speed, and the number of users to be able to offer the right product and model. They have a lot of products in FortiGate according to the size of the company, like 200D and 300D."
"Palo Alto Networks offers more cost efficiency compared to Cisco, with better operational and maintenance ease."
"Palo Alto can be priced higher than some less capable firewalls. However, they are exceptional when you consider the completeness of the solution and its ability to handle threats. Palo Alto is better than other solutions, which justifies a slightly higher price point. You have other tools that are easier to deploy, reducing your total cost of ownership. The newer models are faster, making the pricing more attractive."
"The cost is steep, but most firewalls cost a lot."
"The solution is expensive."
"Definitely look into a multi-year license, as opposed to a single-year. That will definitely be more beneficial in terms of cost... Palo Alto is definitely not the cheapest, but if you scale it the right way it will be very comparable to what's out there."
"It is a little bit expensive."
"Licensing is a big issue for us because of the complexity and the lack of engagement from Palo Alto. It has been hard to talk with them as we don't get the best answers."
"The cost of the license is platform-dependent. It would be nice if they standardized that across the board to make the license a flat fee instead of based on scale and the platform you're using. Functionality shouldn't change based on the platform or the amount of data going through it. It's the same functionality on there. That's one aspect customers often raise. The platform's price is what it is, but the ongoing cost of the annual license is hard for some customers to wrap their heads around."
"It costs less than the SO works and others (like SonicWall, Cisco, and Barracuda) without increasing so much CPU use."
"The licensing and renewal is very expensive."
"Get at least a maintenance contract for the updates and take a larger WatchGuard than you need. A WatchGuard creates new ways to secure your network."
"Like all other manufacturers, there are a lot of features and different pricing. The best is to talk to a representative.​"
report
Use our free recommendation engine to learn which Firewalls solutions are best for your needs.
885,286 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
11%
Comms Service Provider
10%
Manufacturing Company
8%
Financial Services Firm
6%
Computer Software Company
10%
Manufacturing Company
9%
Financial Services Firm
8%
Educational Organization
6%
No data available
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business361
Midsize Enterprise135
Large Enterprise190
By reviewers
Company SizeCount
Small Business74
Midsize Enterprise56
Large Enterprise85
By reviewers
Company SizeCount
Small Business24
Midsize Enterprise7
Large Enterprise3
 

Questions from the Community

Which is the better NGFW: Fortinet Fortigate or Cisco Firepower?
When you compare these firewalls you can identify them with different features, advantages, practices and usage a...
What is the biggest difference between Sophos XG and FortiGate?
From my experience regarding both the Sophos and FortiGate firewalls, I personally would rather use FortiGate. I know...
What are the biggest technical differences between Sophos UTM and Fortinet FortiGate?
As a solution, Sophos UTM offers a lot of functionality, it scales well, and the stability and performance are quite ...
What is a better choice, Azure Firewall or Palo Alto Networks NG Firewalls?
Azure Firewall Vs. Palo Alto Network NG Firewalls Both solutions provide stellar stability and security. Azure Firew...
Features comparison between Palo Alto and Fortinet firewalls
In the best tradition of these questions, Feature-wise both are quite similar, but each has things it's better at, it...
Which is better - Palo Alto Networks NG Firewalls or Sophos XG?
Palo Alto Networks NG Firewalls have both great features and performance. I like that Palo Alto has regular threat si...
Ask a question
Earn 20 points
 

Also Known As

Fortinet FortiGate Next-Generation Firewall
Palo Alto NGFW, Palo Alto Networks Next-Generation Firewall
No data available
 

Overview

 

Sample Customers

Amazon Web Services, Microsoft, IBM, Cisco, Dell, HP, Oracle, Verizon, AT&T, T-Mobile, Sprint, Vodafone, Orange, BT Group, Telstra, Deutsche Telekom, Comcast, Time Warner Cable, CenturyLink, NTT Communications, Tata Communications, SoftBank, China Mobile, Singtel, Telus, Rogers Communications, Bell Canada, Telkom Indonesia, Telkom South Africa, Telmex, Telia Company, Telkom Kenya
SkiStar AB, Ada County, Global IT Services PSF, Southern Cross Hospitals, Verge Health, University of Portsmouth, Austrian Airlines, The Heinz Endowments
AVG, Cyren, Kaspersky Lab, Lastline, NCP engineering, Trend Micro, Websense
Find out what your peers are saying about Fortinet, Netgate, Sophos and others in Firewalls. Updated: March 2026.
885,286 professionals have used our research since 2012.