No more typing reviews! Try our Samantha, our new voice AI agent.

Palo Alto Networks NG Firewalls vs WatchGuard XTM [EOL] comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Oct 19, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Fortinet FortiGate
Sponsored
Average Rating
8.4
Reviews Sentiment
6.8
Number of Reviews
591
Ranking in other categories
Secure Web Gateways (SWG) (2nd), Firewalls (1st), Intrusion Detection and Prevention Software (IDPS) (1st), Software Defined WAN (SD-WAN) Solutions (1st), WAN Edge (1st), ZTNA (1st), Unified Threat Management (UTM) (1st)
Palo Alto Networks NG Firew...
Average Rating
8.6
Reviews Sentiment
7.2
Number of Reviews
199
Ranking in other categories
Firewalls (6th)
WatchGuard XTM [EOL]
Average Rating
8.0
Number of Reviews
34
Ranking in other categories
No ranking in other categories
 

Featured Reviews

Abhinandan Yadav - PeerSpot reviewer
Network Security Engineer at a retailer with 11-50 employees
Unified security and sd-wan have improved uptime and cut wan costs for multi-site branches
Users report stability issues in certain versions, which requires regular updates. Real-world attacks have also highlighted the need for urgent patching of vulnerabilities.Fortinet FortiGate, while a powerful and feature-rich web firewall, could improve in areas like firmware stability, documentation, and ease of use. The learning curve can be steep for some users. For beginners, support quality can vary, and frequent updates with occasional vulnerabilities call for careful patch management. However, once Fortinet FortiGate is configured, it remains highly reliable and efficient. Customer support needs improvement, as I find it very slow, with reports from other users reflecting that customer support is inadequate.
Abhinandan Yadav - PeerSpot reviewer
Network Security Engineer at a retailer with 11-50 employees
Advanced visibility has transformed security policies and provides proactive threat prevention
Palo Alto Networks NG Firewalls are powerful, but there are areas for improvement that could enhance their effectiveness, such as cost and licensing models. One of the main challenges we face is the high cost, especially for small to mid-sized businesses (SMBs), with licensing for features such as threat prevention, URL filtering, and WildFire being quite expensive. Additionally, centralized management with Panorama is a dependency for managing multiple firewalls, leading to added costs and complexity, and the built-in centralized management features could be made more user-friendly. Moreover, the learning curve associated with the initial setup and advanced configuration including NAT, decryption, and routing can be complex for new users, and enhancements in logging and reporting could also improve the user experience. There are a few more areas where improvements could streamline operations, such as optimizing commit times. Sometimes committing changes takes a noticeable amount of time, particularly for larger configurations, so a faster commit option would significantly help during urgent troubleshooting. Easier policy troubleshooting is necessary as well. Even though logs are detailed, finding the exact rule match and issue can still be time-consuming in complex environments, so having automated policy simulation and a recommendation tool would expedite troubleshooting. Additionally, better default templates and best practices for SMB data centers and branch offices would speed up deployment and reduce errors. Enhancing integration visibility through a unified dashboard would simplify monitoring, and improving the firmware upgrade process to allow for a more seamless zero downtime upgrade would also enhance operations, as upgrades are stable but typically require careful planning and downtime.
Generalm4545 - PeerSpot reviewer
General Manager- IT & Automation - Serum at a pharma/biotech company with 1,001-5,000 employees
Protects from attack software and hacking but it doesn't provide the reports in a readable format
In my opinion, image clarity is very important, because I don't get the proper image product on reports. This means that functionality is not there. My engineer does not know how he can replace an order. We attach a log after any kind of keys using a utility instead. For the internet policies that we are implementing, the policy should be based on proper protocols. We use the default policies and there are a number of third-party protocols that appear here. Management with WatchGuard XTM means that out of policy is the problem from our side. In this way, we can not do effective services for people with this one. The policy definition with WatchGuard XTM is not proper for all use case requirements. I've got weekly business reports that I am expecting attachments with from WatchGuard XTM that display data for all kinds of consideration which should be required. Main User Functionality Level Order must adhere to using the admin functionality on the registry, or else our users publish their own name. Maybe these recommendations are irrelevant, but I say that the issue to improve most with WatchGuard XTM is the Main User Function.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"It's a firewall that secures our internal network. I have been using it since 2013, and I find that most of the features are advanced, and very user friendly."
"The most useful features of Fortinet FortiGate IPS are you can create a virtual firewall within it, most other firewalls do not have this feature. You are able to manage your network and have network segmentation within your firewall. Additionally, you can create virtual switches within the firewall and have policy management, such as firewall and access policy."
"The price of Fortinet FortiGate is better than Cisco, Check Point, and Palo Alto."
"In terms of ROI, they're inexpensive, and because they're inexpensive, they're just everywhere, in the Federal Government, schools, everywhere where budgets are fairly tight, and it is a very good product."
"The antivirus, malware, anti-malware, anti-spam, IP VPN connections, and firewall rules bring the most value for me and my clients."
"The stability is great; there are no issues with crashing or freezing, and there are no bugs or glitches."
"Fortinet FortiGate has been a Perimeter Security which defends our network from Internet attackers, armed with zero-day exploits of common Internet services like HTTP and SMTP."
"We like signature-based anomaly detection and zero-day protection features."
"URL filtering and WildFire features are most valuable. It is very user-friendly. It is a very solid product, and it definitely works."
"Decryption is one of Palo Alto Networks NG Firewalls' best features because we can decrypt by category. For instance, we can decrypt everything except for bank traffic so that we don't interfere with the passwords and two-factor authentication of those checking their bank accounts at work. We can still monitor for malware and other threats that come through a secure channel. It's seamless for users. The URL filtering and IPS are both great as well."
"I find Palo Alto Networks NG Firewalls to be a stable product and very easy to manage from layer 4 to layer 7. They are also seamless for environments with high availability."
"Flexible and integrates well with apps and other security tools."
"The interface is very nice. We generally like the UI the product offers."
"The GUI is very simple in Palo Alto and I like that."
"The most valuable aspect of this solution is pre-sales and post-sales because of the support and relationship building."
"Everything is easy in Palo Alto Networks NG Firewall. It is very stable, easy to configure, and easy to upgrade. It is also very easy to create custom policies and applications. Everything can be done with the click of a button. It is also good for the protection of web services. Nowadays, they have a rather new DNS security feature, which is pretty good and functional. We did a one-month trial, and it is the best product for the firewall network."
"Application Control is fantastic with over 2,500 applications and the granularity that we can either allow people to view but not be able to log on to Facebook; or view it and log onto it if they're in the marketing department, but not play Facebook games. There are all sorts of different options like that. So it's highly granular."
"Setup and configuration is straightforward with excellent management interface."
"I would recommend this product, as it is a very flexible one with probably the most intuitive configuration."
"After installing the product, we achieved awareness of our data protection needs and email misuse."
"Simply, give this tool a try; it will generate great benefits in terms of the scalability and environment."
"The multi-WAN feature allows us to configure multiple external interfaces."
"They have a reporting system which can store data over a very long period of time. Not many other firewall vendors provide a reporting system, but if they do, like Fortinet does, then you've got buy that as an additional product and that can be more than twice as expensive as the initial investment in the firewall. And without reporting over a long-term period, you're just about wasting your time."
"Flawless. I have had my firebox for 3 years now and never had an issue with it."
 

Cons

"Fortinet currently has many products bundled with FortiGate including the basic firewall and load balancer, and I think that that they need to have separate product portfolios for each of these specialized services."
"I find the management console not very straightforward, so that's an area where Fortinet FortiGate can improve. They should simplify it and make it more user-friendly."
"There are a lot of bugs I have found in the solution and it is difficult to upgrade. These areas need improvement."
"The solution needs to improve its support."
"It's difficult to add or define, and it's not that easy to configure and manage."
"For improving sectors, they need to focus on technical support and work on the technical part."
"The user interface needs a bit of upgrading."
"They really need to work on their support."
"We're working with the entry-level appliances, so I don't know what the higher-end ones are like, however, on the entry-level models I would say commit speeds need to be improved."
"This solution is definitely not scalable."
"Need improvement with their logs, especially the command line interface."
"The price is expensive and should be reduced to make it more competitive."
"The price could be more friendly, which would be good for Palo Alto and us. If the price were a little lower, then it would be a viable option for mid-level businesses, who may not be able to deploy at the current price point."
"The manufacturer can improve the product by improving the configuration."
"Palo Alto is like Microsoft. It has varied features, but it's too technical."
"PA-220 Next-Generation Firewall would be perfect if it has spam filtering."
"The problem is the high cost."
"The WatchGuard gateway wireless functionality for managing access points leaves much to be desired."
"The initial setup is neither simple nor complex. If you know the base in networking and how the firewall works, you will be able to figure it out."
"The technical support is very bad. The price is very high, the response time is very long, and technical support does not provide a general solution."
"I would like them to improve the product's overall protections. This would be good for all product users."
"Sometimes we have had issues with stability of the product."
"The support is poor and lazy."
"We had some problems of instability with older versions of the software."
 

Pricing and Cost Advice

"When I look around at other products, such as Sophos, Fortinet FortiGate is 20% to 30% more expensive with our current cost."
"They are more expensive than others."
"By default, they give SD-WAN along with the firewall. They don't have separate licensing for the SD-WAN functionality. However, they have security licenses that are sold separately on a subscription basis. Customers can consume these security features to protect their users from internet traffic."
"The product pricing is reasonable."
"I would rate the pricing a seven out of ten"
"I do not have first-hand experience with the rice of Fortinet FortiGate, but I have heard the price was reasonable."
"FortiGate SWG is a cost-effective solution well-suited for organisations of all sizes."
"I rate the pricing an eight and a half on a scale of one to ten, where one is low, and ten is high."
"The pricing is straightforward with no hidden costs."
"We were very happy when they released the PA-440s. Previously, we had been looking at the PA-820s, which were a bit of overkill for us. Price-wise and capability-wise, the PA-820s hit the nail on the head for us."
"I am not sure about the specific licensing costs of Palo Alto Networks NG Firewalls, but FortiGate and Palo Alto are generally cheaper than some high-end Cisco devices."
"I don't know about the price of the platform or the license fees, as the finance department deals with that. I only bill for the materials involved in the design."
"Don't buy a device with more power than you really need, because licensing depends on the cost of the box you have."
"The cost of the license is platform-dependent. It would be nice if they standardized that across the board to make the license a flat fee instead of based on scale and the platform you're using. Functionality shouldn't change based on the platform or the amount of data going through it. It's the same functionality on there. That's one aspect customers often raise. The platform's price is what it is, but the ongoing cost of the annual license is hard for some customers to wrap their heads around."
"It's too expensive."
"The pricing is competitive in the market."
"Get at least a maintenance contract for the updates and take a larger WatchGuard than you need. A WatchGuard creates new ways to secure your network."
"It costs less than the SO works and others (like SonicWall, Cisco, and Barracuda) without increasing so much CPU use."
"Like all other manufacturers, there are a lot of features and different pricing. The best is to talk to a representative.​"
"The licensing and renewal is very expensive."
report
Use our free recommendation engine to learn which Firewalls solutions are best for your needs.
893,915 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
10%
Comms Service Provider
10%
Manufacturing Company
9%
Financial Services Firm
7%
Computer Software Company
10%
Manufacturing Company
9%
Financial Services Firm
8%
Comms Service Provider
6%
Marketing Services Firm
14%
Financial Services Firm
14%
Performing Arts
13%
Manufacturing Company
11%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business367
Midsize Enterprise135
Large Enterprise193
By reviewers
Company SizeCount
Small Business77
Midsize Enterprise56
Large Enterprise85
By reviewers
Company SizeCount
Small Business24
Midsize Enterprise7
Large Enterprise3
 

Questions from the Community

Which is the better NGFW: Fortinet Fortigate or Cisco Firepower?
When you compare these firewalls you can identify them with different features, advantages, practices and usage a...
What is the biggest difference between Sophos XG and FortiGate?
From my experience regarding both the Sophos and FortiGate firewalls, I personally would rather use FortiGate. I know...
What are the biggest technical differences between Sophos UTM and Fortinet FortiGate?
As a solution, Sophos UTM offers a lot of functionality, it scales well, and the stability and performance are quite ...
What is a better choice, Azure Firewall or Palo Alto Networks NG Firewalls?
Azure Firewall Vs. Palo Alto Network NG Firewalls Both solutions provide stellar stability and security. Azure Firew...
Features comparison between Palo Alto and Fortinet firewalls
In the best tradition of these questions, Feature-wise both are quite similar, but each has things it's better at, it...
Which is better - Palo Alto Networks NG Firewalls or Sophos XG?
Palo Alto Networks NG Firewalls have both great features and performance. I like that Palo Alto has regular threat si...
Ask a question
Earn 20 points
 

Also Known As

Fortinet FortiGate Next-Generation Firewall
Palo Alto NGFW, Palo Alto Networks Next-Generation Firewall
No data available
 

Overview

 

Sample Customers

Amazon Web Services, Microsoft, IBM, Cisco, Dell, HP, Oracle, Verizon, AT&T, T-Mobile, Sprint, Vodafone, Orange, BT Group, Telstra, Deutsche Telekom, Comcast, Time Warner Cable, CenturyLink, NTT Communications, Tata Communications, SoftBank, China Mobile, Singtel, Telus, Rogers Communications, Bell Canada, Telkom Indonesia, Telkom South Africa, Telmex, Telia Company, Telkom Kenya
SkiStar AB, Ada County, Global IT Services PSF, Southern Cross Hospitals, Verge Health, University of Portsmouth, Austrian Airlines, The Heinz Endowments
AVG, Cyren, Kaspersky Lab, Lastline, NCP engineering, Trend Micro, Websense
Find out what your peers are saying about Fortinet, Netgate, Sophos and others in Firewalls. Updated: April 2026.
893,915 professionals have used our research since 2012.