No more typing reviews! Try our Samantha, our new voice AI agent.

Tanium vs WatchGuard Firebox comparison

Why PeerSpot?
Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Jun 3, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cortex XDR by Palo Alto Net...
Sponsored
Ranking in Endpoint Detection and Response (EDR)
5th
Average Rating
8.4
Reviews Sentiment
6.7
Number of Reviews
118
Ranking in other categories
Endpoint Protection Platform (EPP) (4th), Extended Detection and Response (XDR) (4th), Ransomware Protection (2nd), AI-Powered Cybersecurity Platforms (1st)
Tanium
Ranking in Endpoint Detection and Response (EDR)
20th
Average Rating
7.8
Reviews Sentiment
6.2
Number of Reviews
23
Ranking in other categories
Vulnerability Management (26th), Endpoint Protection Platform (EPP) (12th), Unified Endpoint Management (UEM) (8th), Autonomous Endpoint Management (3rd)
WatchGuard Firebox
Ranking in Endpoint Detection and Response (EDR)
10th
Average Rating
8.4
Reviews Sentiment
6.8
Number of Reviews
143
Ranking in other categories
Data Loss Prevention (DLP) (10th), Firewalls (12th), Intrusion Detection and Prevention Software (IDPS) (4th), Anti-Malware Tools (7th), Application Control (4th), Unified Threat Management (UTM) (3rd)
 

Mindshare comparison

As of September 2026, in the Endpoint Detection and Response (EDR) category, the mindshare of Cortex XDR by Palo Alto Networks is 3.6%, down from 3.9% compared to the previous year. The mindshare of Tanium is 2.1%, down from 2.2% compared to the previous year. The mindshare of WatchGuard Firebox is 1.3%, up from 0.6% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Endpoint Detection and Response (EDR) Mindshare Distribution
ProductMindshare (%)
Cortex XDR by Palo Alto Networks3.6%
WatchGuard Firebox1.3%
Tanium2.1%
Other93.0%
Endpoint Detection and Response (EDR)
 

Featured Reviews

ABHISHEK_SINGH - PeerSpot reviewer
Senior Process Expert at A.P. Moller - Maersk
Gained full visibility and streamlined threat detection through behavior-based insights and AI integration
Initially, we got to have a lot of false positives when we onboarded, but nowadays it's quite smooth. We have fine-tuned our security policies and allowed different levels of policies to get rid of those false positives. Currently, we are getting a fairly good amount of incidents that are not false positives or benign, but actionable items. The process is streamlined. In the initial days, the operations used to get involved in a lot of benign and other activities, but now the process is streamlined. We are leveraging the auto-detection and remediation plans. The operations teams are now more involved in other business roles as well, not just looking into the logs and fetching out what's happening there. They have fixed a lot of things. Initially, they didn't have IAC code drift detection, cloud posture management, or security posture management, but they have those now. They purchased different vendors and did a merger with that. They have now Prisma Cloud that gets integrated and now they are working with Cortex Cloud. Everything that was negative has now been addressed, and the product altogether looks to be in a very better and mature shape now. Currently, it's more or less detecting the workloads with AI-based best practices. Since most organizations are consuming AI agents and other things, we are looking forward to seeing what other feature enhancements Palo Alto can support in that.
Sandeepraj Gatla - PeerSpot reviewer
Dfir Analyst at a tech services company with 201-500 employees
Endpoint monitoring has strengthened incident response and provides rapid isolation and forensics
Tanium provides an endpoint which is isolated from the network and environment. We can easily search its logs and history and connect remotely directly to that particular device which has been isolated from the network. We can search for the history and logs, including audit logs and event logs. The complete activity of the user or owner of the device is visible to us. We can see the artifacts of particular USB transfers internally for official use. We can not only connect remotely but also see the device status and how many failures have occurred within the network so far. We can see the IP address, how many times it has changed its IP address, and how many times it was connected to VPN or external VPN or internal VPN and what has been searched while on VPN. We can block the IOCs or IP addresses as well. We can block domains, hashes, SHA values, SHA-256, SHA-1, SHA-5 and MD5. Although I am not completely involved in the automation team, we do have that team and I have worked in some CERT recently. Tanium is more useful while we are in the CERT because most of the times when we are on high alert, Tanium does play a main role for that particular incident or any high case. Tanium is a simple tool and we can easily integrate it to many devices and it is a mandatory tool to secure an endpoint. It is mandatory to give any RDP connection and the tool should be present in the particular device. It is completely mandatory and it is in the policy as well.
Abhishek Saini - PeerSpot reviewer
Professional Services Engineer at Next7 IT
Centralized security management has improved VPN reliability and simplified daily operations
WatchGuard Firebox is a strong and reliable platform overall, but there are a few areas where improvements could make the experience even better. One area is the user interface and navigation in some management tools. While the platform is powerful, certain configurations and troubleshooting workflows can feel less intuitive compared to some newer cloud-native firewall platforms. Another point is reporting and log analysis. Although the logging features are very useful, deeper analytics and more customizable reporting dashboards would make security monitoring much more effective. Firmware upgrades and policy synchronization can sometimes require careful planning to avoid security interruptions. Overall, the core security and VPN functionality are very solid, but improving usability, reporting, and automation would make the platform even stronger. One area that could be improved is the learning curve for new administrators. While experienced engineers can work with the platform effectively, some advanced networking and security configurations can be a bit complex for junior technicians. More guided configuration workflows, smarter recommendations, and simplified troubleshooting tools would make onboarding easier. Another improvement would be more flexible reporting customization for executive-level and client-facing reports.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The product is mostly automated, and we do not have to make decisions, because all the decisions are made by the product itself and we are not required to create any custom policies since the policies that are created are well defined in the product itself."
"Palo Alto is one of the tech vendors that always provides top-of-the-line products."
"The most valuable feature of Cortex XDR by Palo Alto Networks is its machine-learning capabilities. Additionally, there is full integration with other solutions."
"Since they've done their most recent update, the ease to isolate endpoints is valuable. If we find one where there is a virus on it, we can easily isolate it. We don't even have to contact the user. We don't have to manually take them off the network. We can easily isolate them."
"We switched because there were a lot of added features with Palo Alto that Check Point didn't have, and it was an upgrade for us."
"The solution helps find bugs, and it is safe to use to prevent attacks by hackers."
"Cortex XDR lets us manage several clients from the same console, and its endpoint defense is more advanced than traditional antivirus."
"The multi-layered approach to the product gives you confidence that it will stop exploits, ransomware, worms, or viruses from compromising endpoints, essentially providing peace of mind."
"Tanium's most valuable feature is its instant discovery aspect."
"I like the fact that you can create patching campaigns depending on the area of your network that you want to address first. I like the ability it has to make several campaigns that work in parallel."
"The security features are very valuable."
"The most valuable features of this solution are the consolidation of all historical data on device endpoints, security drivers, firmware, and Software version gaps."
"The solution's technical support is very responsive."
"Tanium's most valuable features are patch management, inventory, and distribution software."
"For incident response tasks, all these tasks can get done in minutes with minimal disruption to the end-user."
"For inventory purposes, it's from one of the best things on the scene, as you can get live inventory."
"I like intrusion detection the most."
"The controllability is phenomenal; I can control everything with it, anything coming in or out of my network."
"The fact that it just works is one of the most valuable features."
"I find WatchGuard Firebox provides very good value, with configuration migration between boxes, more flexible traffic management, best performance, strong security layers and dependencies, protocol-oriented design, rapid deploy for remote configuration, total protection for inbound and outbound traffic with deep understanding of the traffic, powerful DNS security for both network and mobile users, SD-WAN features that manage line quality, extensive exception handling, and a rich set of integrated security services like Access Portal, Application Control, APT Blocker, Botnet Detection, DLP, Gateway AntiVirus, DNSWatch, Geolocation, IntelligentAV, IPS, Reputation Enabled Defense, spamBlocker, Threat Detection and Response, and WebBlocker."
"It's very easy to use, especially compared to similar products. A lot more users use the WatchGuard appliance now than use the SonicWall appliance because of the ease of usability."
"For the price point, what we do with it, and the time that the last one lived for on our network, we have gotten our money's worth from it."
"WatchGuard Firebox provides benefits in terms of security, time saving, resource saving, and cost savings."
"The price of the solution is not expensive, it is less than FortiGate."
 

Cons

"Every 30 or 40 days, there's a new version and we need to go and make sure our customer's laptops are upgraded."
"Cortex XDR by Palo Alto Networks could improve by adding a sandbox feature to better compete with their competitors which have it."
"When it comes to core analysis, and security analysis, Cortex needs to provide more information."
"There's an overall lack of features."
"In the next release, I would like to see more UI improvements. Their UI is a bit basic. When we are speaking about Palo Alto Networks they are the big company, so they can improve the UI a little bit. The UI, the reports, the log system can all be improved."
"One thing that was missing was the integration part. Currently, they don't have out-of-box integration with IBM QRadar, or if they have the integration, the integration doesn't work well."
"There is a severe gap in functionality between Windows, Linux, and Mac versions. For example all folder restriction settings are Windows only. Traps 5.0+ does not have SAML / LDAP integration."
"To jump from the partner to Palo Alto directly was challenging."
"Tanium’s scalability could be improved."
"I would like to have more integrations and custom plugins to input. Integration is always a big deal in a lot of different environments."
"It is not really additional functions, or the features that are needed, rather the complexity would be reduced based on the number of modules required to put together a comprehensive operational security and risk compliance model."
"The most painful thing is the interface. It's a bit unclear sometimes."
"We had some issues with the solution's OS upgrade."
"The problem or challenge is a pre-sales and go-to strategy for the SMB market delivered through a channel or model. It's very convoluted and vague, which leads to some confusion about the various types of modules, and the device-to-seat cost is extremely difficult to calculate."
"There are downsides and drawbacks in Tanium, and there is room for improvement from my perspective."
"The performance could improve in future releases. We have had performance issues in specialized web environments, but overall I think the problems are less than 2% of the computer systems being used."
"Last year, I had an issue with one of the Fireboxes going down. It was overheated, because my server room became overheated and this fried it."
"Customer support is awful, as there is no customer support in Greece, which is why I changed vendors."
"I'd like a few extra features, especially around threat severity assessment."
"Websense is an application that monitors and filters internet traffic. Websense was derived from WatchGuard. But when you go to WatchGuard to actually implement that particular feature, you have to use some type of additional feature and you have to pay for it, unfortunately. I think it should be free or free in the WatchGuard box itself, as an option. It would be nice if they didn't charge us for that."
"My impression of WatchGuard's spam-blocking capabilities is that this might be the weakest point of the product, as it does not have great spam management compared to other competitors in the market, but it has not affected us excessively."
"The reporting could use improvement, because most of the firewalls available in the market come with the reporting built-in, with the memory and the hard disk capacity and all."
"I believe there is room for improvement in policies, with the potential to enhance the margins further."
"Once you start getting into proxy actions and setting up: "Okay, cool. Once this rule gets triggered, what actions have to happen?" I do know a few people who use WatchGuard and they still have to get assistance when they look at that. So I would file that as a con for WatchGuard. Proxy actions can be a little bit complicated."
 

Pricing and Cost Advice

"The solution is expensive. It's pricing is on a yearly-basis."
"This is an expensive solution."
"Very costly product."
"It has a yearly renewal."
"The tool's price is moderate."
"Cortex XDR by Palo Alto Networks is an expensive solution."
"I don't like that they have different types of licenses."
"It's about $55 per license on a yearly basis."
"It is higher than some competitors in the market."
"It's an expensive solution. It would be nice if the cost were lower."
"There is an annual license required to use this solution."
"The solution offers value for money."
"The solution is expensive but it's a good investment."
"Tanium is a more expensive solution in Latin America than some of the competitors, such as BigFix."
"The product's pricing differs from region to region depending on negotiations and the number of endpoints."
"The two larger devices are about $1,000 each and the smaller ones are about $500 or $600 each... It's cheaper and you have more control because it's self-managed."
"The licensing model for WatchGuard Application Control is based on the number of users. WatchGuard Application Control also has licensing models with several features."
"Each one, for the primary unit, was $8,600 and the High Availability unit was $2,000. That's with three years of subscription and support and the Total Security Suite."
"I buy a three-year renewal on the main device, which is usually around $3,000 to $4,000. They usually upgrade the device when I do it. You get a big discount when you do three years."
"The price of the solution is not expensive, it is less than FortiGate."
"The pricing is competitive."
"The cheapest configuration, for maybe five people, is approximately $500."
"I find the solution to be very affordable."
report
Use our free recommendation engine to learn which Endpoint Detection and Response (EDR) solutions are best for your needs.
913,806 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Outsourcing Company
12%
Comms Service Provider
12%
Construction Company
11%
Financial Services Firm
9%
Financial Services Firm
13%
Government
9%
Manufacturing Company
9%
Healthcare Company
7%
Outsourcing Company
13%
Comms Service Provider
12%
Construction Company
8%
Manufacturing Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business47
Midsize Enterprise21
Large Enterprise55
By reviewers
Company SizeCount
Small Business8
Midsize Enterprise4
Large Enterprise12
By reviewers
Company SizeCount
Small Business104
Midsize Enterprise30
Large Enterprise17
 

Questions from the Community

Cortex XDR by Palo Alto vs. Sentinel One
Cortex XDR by Palo Alto vs. SentinelOne SentinelOne offers very detailed specifics with regard to risks or attacks. ...
Comparing CrowdStrike Falcon to Cortex XDR (Palo Alto)
Cortex XDR by Palo Alto vs. CrowdStrike Falcon Both Cortex XDR and Crowd Strike Falcon offer cloud-based solutions th...
How is Cortex XDR compared with Microsoft Defender?
Microsoft Defender for Endpoint is a cloud-delivered endpoint security solution. The tool reduces the attack surface,...
What needs improvement with Tanium?
While there is always room for improvement, I am pleased with Tanium.
What is your primary use case for Tanium?
The primary use case for Tanium ( /products/tanium-reviews ) is compliance, patching, and inventory as part of the co...
What advice do you have for others considering Tanium?
For smaller companies, Tanium is quite a big investment, and one needs to have a considerable setup to make it econom...
What is your primary use case for WatchGuard Firebox?
We are providing our services to all WatchGuard customers in the region.
What is your primary use case for WatchGuard Firebox?
We just use it as a secondary WiFi device. We're a small office and we needed to set up a WiFi device for a few of ou...
What is your primary use case for WatchGuard Firebox?
We're a hospital and we use it for developing our incoming and outgoing policies, and we also use it for VPN.
 

Also Known As

Cyvera, Cortex XDR, Palo Alto Networks Traps
Tanium Inc Cloud, Tanium XEM
WatchGuard Threat Detection and Response, WatchGuard Application Control, WatchGuard Data Loss Prevention, WatchGuard Gateway AntiVirus, WatchGuard Intrusion Prevention Service
 

Overview

 

Sample Customers

CBI Health Group, University Honda, VakifBank
JPMorgan Chase, eBay, Amazon, US Bank, MetLife, pwc, Cerner, Delphi, MGM Grand, New York Life
Ellips, Diecutstickers.com, Clarke Energy, NCR, Wrest Park, Homeslice Pizza, Fortessa Tableware Solutions, The Phoenix Residence
Find out what your peers are saying about Tanium vs. WatchGuard Firebox and other solutions. Updated: September 2026.
913,806 professionals have used our research since 2012.