We just raised a $30M Series A: Read our story

Compare Palo Alto Networks NG Firewalls vs. Palo Alto Networks VM-Series

Cancel
You must select at least 2 products to compare!
Comparison Summary
Question: Features comparison between Palo Alto and Fortinet firewalls
Answer: Hi PaloAlto is better when working on app control feature and special virtual wire links. Execpt that specific point, Fortinet is above. Best Regards, Damien
Featured Review
Find out what your peers are saying about Palo Alto Networks NG Firewalls vs. Palo Alto Networks VM-Series and other solutions. Updated: November 2021.
552,695 professionals have used our research since 2012.
Quotes From Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:

Pros
"Feature-wise, we mostly use IPS because it is a security requirement to protect against attacks from outside and inside. This is where IPS helps us out a bunch.""A good intrusion prevention system and filtering.""You do not have to do everything through a command line which makes it a lot easier to apply rules.""We have not had to deal with stability issues.""The most valuable features of this solution are the integrations and IPS throughput.""Its Snort 3 IPS has better flexibility as far as being able to write rules. This gives me better granularity.""The Firepower+ISE+AMP for endpoint integration is something that really stands it out with other vendor solutions. They have something called pxGrid and i think it is already endorsed by IETF. This allows all devices on the network to communicate.""It is one of the fastest solutions, if not the fastest, in the security technology space. This gives us peace of mind knowing that as soon as a new attack comes online that we will be protected in short order. From that perspective, no one really comes close now to Firepower, which is hugely valuable to us from an upcoming new attack prevention perspective."

More Cisco Firepower NGFW Firewall Pros »

"I have found it to be reliable and very easy to use. I haven't really encountered many problems with it because its documentation is clear and readily available on their website.""It worked fine normally.""The most valuable features are the IPS/IDS subscriptions.""The configuration is very simple.""The most valuable features are web filtering and application filtering.""Innovative, advanced threat protection is the most valuable feature.""It's a next-generation firewall and it's pretty stable. You don't have to worry about if you restart it for some maintenance. It will just come back.""The management options are good."

More Palo Alto Networks NG Firewalls Pros »

"The Palo Alto VM-Series is nice because I can move the firewalls easily.""What I like about the VM-Series is that you can launch them in a very short time.""In Palo Alto the most important feature is the App-ID.""It has excellent scalability.""The feature that I have found the most useful is that it meets all our requirements technically.""The most valuable features are web control and IPS/IDS.""Palo Alto Networks VM-Series is very easy to use.""The most valuable features are security and support."

More Palo Alto Networks VM-Series Pros »

Cons
"The performance should be improved.""My team tells me that other solutions such as Fortinet and Palo Alto are easier to implement.""Cisco Firepower NGFW Firewall can be more secure.""One of the few things that are brought up is that for the overall management, it would be great to have a cloud instance of that. And not only just a cloud instance, but one of the areas that we've looked at is using an HA type of cloud. To have the ability to have a device file within a cloud. If we had an issue with one, the other one would pick up automatically.""They need a VTI. I know it's going to be available in the next software version, which is the 6.7 version. However, the problem with that is that the 6.7 is going to deprecate all the older IKEv1 deployment tunnels. Therefore, the problem is that we have a lot of customers which are using older encryptions. If I do that, update it, it's not going to work for me.""I would like it to have faster deployment times. A typical deployment could take two to three minutes. Sometimes, it depends on the situation. It is better than it was in the past, but it could always use improvement.""The price and SD-WAN capabilities are the areas that need improvement.""One issue with Firepower Management Center is deployment time. It takes seven to 10 minutes and that's a long time for deployment. In that amount of time, management or someone else can ask me to change something or to provide permissions, but during that time, doing so is not possible. It's a drawback with Cisco. Other vendors, like Palo Alto or Fortinet do not have this deployment time issue."

More Cisco Firepower NGFW Firewall Cons »

"The SD-WAN product is fairly new. They could probably improve that in terms of customizing it and making the configuration a little bit easier.""I would like to see better integration with IoT technologies.""They can work on the price. They are a little bit expensive, and not all customers are able to afford this solution. Taking into consideration that there is huge competition in the market and there are multiple firewall companies that are much cheaper than them and offer almost the same features, it would be good to improve the price.""The solution could offer better pricing. We'd like it if it could be a bit more affordable for us.""Its stability can be better. Their technical response from the support side can also be better.""The scalability of the firewalls could be improved.""The pricing of the solution is quite high. It's one of the most expensive firewall solutions on the market.""I think automation and machine learning can be improved to make bulk configurations simpler, easier, and faster"

More Palo Alto Networks NG Firewalls Cons »

"In the next release, I would like to see better integration between the endpoints and the firewalls.""The one issue that I didn't like is that the SNMP integration with interfaces didn't record the interface counters.""At the beginning of the implementation, we had some difficulties with the scripts, but Palo Alto Networks support together with a local partner finally fixed it.""They made only a halfhearted attempt to put in DLP (Data Loss Prevention).""The implementation should be simplified.""It'll help if Palo Alto Networks provided better documentation.""The command-line interface is something that some people struggle with and I think that they should have an option to go straight to the GUI.""The user interface could use some improvement."

More Palo Alto Networks VM-Series Cons »

Pricing and Cost Advice
"Cisco pricing is premium. However, they gave us a 50 to 60 percent discount.""Its pricing is good and competitive. There is a maintenance cost. It includes SecureX that makes it cost-effective as compared to the other solutions where you have to pay for XDR and SOAR capabilities.""When we are fighting against other competitors for customers, whether it is a small or big business, we feel very comfortable with the price that Firepower has today.""This product requires licenses for advanced features including Snort, IPS, and malware detection.""I am happy with the product in general, including the pricing.""Cisco is not for a small mom-and-pop shop because of the cost, but if you're in a regulated industry where a breach could cost you a million dollars, it's a bargain.""I know that licensing for some of the advanced solutions, like Intrusion Prevention and Secure Malware Analytics, are nominal costs.""The solution was chosen because of its price compared to other similar solutions."

More Cisco Firepower NGFW Firewall Pricing and Cost Advice »

"Palo Alto is not a cheap solution but it is competitive when it comes to subscriptions.""I am not involved in the commercial side, but I believe that Palo Alto is quite expensive compared to others.""It is an expensive solution.""It's an expensive product.""It has a yearly subscription.""The NG firewall is an expensive solution.""Definitely look into a multi-year license, as opposed to a single-year. That will definitely be more beneficial in terms of cost... Palo Alto is definitely not the cheapest, but if you scale it the right way it will be very comparable to what's out there.""The price of the solution is on the higher side compared to competitors."

More Palo Alto Networks NG Firewalls Pricing and Cost Advice »

"The cost of this product varies from customer to customer and the relationship with IBM, including how many offerings from IBM are already being used.""The price of this solution is very high for some parts of Africa, which makes it a challenge.""It is not the cheapest on the market. The total cost for two firewall instances is $75,000. This includes licenses, deployment fees, and support for two years.""The VM series is licensed annually.""Palo Alto can be as much as two times the price of competing products that have twice the capabilities.""Because I work for a university and the URL is for the institution, it's a free license for us."

More Palo Alto Networks VM-Series Pricing and Cost Advice »

report
Use our free recommendation engine to learn which Firewalls solutions are best for your needs.
552,695 professionals have used our research since 2012.
Answers from the Community
Donny Lee
author avatarABHILASH TH
Reseller

Hi,


Both FT and PA have compelling features for large Enterprises. I would like to add a few good points about Fortinetwhich might be helpful ( from my 13 years of engagement with them as Distributor and Partner)


Fortinet: 


Have higher throughput; which comes with competitive rates


Wide range of models to select to meet your requirement, without spending heavliy


Outstanding customer support and very active customer care team


Easly available skilled resources from the channel for deployment and post-implementation support 


Regards


Abhilash



author avatarAlexander Denisenko
User

Hello. The question is what you are going to have as a result of application

Questions from the Community
Top Answer:  When you compare these firewalls you can identify them with different features, advantages, practices and… more »
Top Answer:  The Cisco Firepower NGFW Firewall is a very powerful and very complex piece of anti-viral software. When one considers… more »
Top Answer: It is easy to integrate Cisco ASA with other Cisco products and also other NAC solutions. When you understand the Cisco… more »
Top Answer: Azure Firewall Vs. Palo Alto Network NG Firewalls Both solutions provide stellar stability and security. Azure… more »
Top Answer: In the best tradition of these questions, Feature-wise both are quite similar, but each has things it's better at, it… more »
Top Answer: Palo Alto Networks NG Firewalls have both great features and performance. I like that Palo Alto has regular threat… more »
Top Answer: Both products are very stable and easily scalable. The setup of Azure Firewall is easy and very user-friendly and the… more »
Top Answer: The initial setup was straightforward.
Top Answer: The VM series is licensed annually. The option exists to procure a basic license. With this, the firewall feature comes… more »
Comparisons
Also Known As
Cisco Firepower NGFW, Cisco Firepower Next-Generation Firewall, FirePOWER, Cisco NGFWv
Palo Alto NGFW, Palo Alto Networks Next-Generation Firewall, Palo Alto Networks PA-Series
Learn More
Overview

Cisco NGFW firewalls deliver advanced threat defense capabilities to meet diverse needs, from
small/branch offices to high performance data centers and service providers. Available in a wide
range of models, Cisco NGFW can be deployed as a physical or virtual appliance. Advanced threat
defense capabilities include Next-generation IPS (NGIPS), Security Intelligence (SI), Advanced
Malware Protection (AMP), URL filtering, Application Visibility and Control (AVC), and flexible VPN
features. Inspect encrypted traffic and enjoy automated risk ranking and impact flags to reduce event
volume so you can quickly prioritize threats. Cisco NGFW firewalls are also available with clustering
for increased performance, high availability configurations, and more.
Cisco Firepower NGFWv is the virtualized version of Cisco's Firepower NGFW firewall. Widely
deployed in leading private and public clouds, Cisco NGFWv automatically scales up/down to meet
the needs of dynamic cloud environments and high availability provides resilience. Also, Cisco NGFWv
can deliver micro-segmentation to protect east-west network traffic.
Cisco firewalls provide consistent security policies, enforcement, and protection across all your
environments. Unified management for Cisco ASA and FTD/NGFW physical and virtual firewalls is
delivered by Cisco Defense Orchestrator (CDO), with cloud logging also available. And with Cisco
SecureX included with every Cisco firewall, you gain a cloud-native platform experience that enables
greater simplicity, visibility, and efficiency.
Learn more about Cisco’s firewall solutions, including virtual appliances for public and private cloud.

Palo Alto Networks' next-generation firewalls secure your business with a prevention-focused architecture and integrated innovations that are easy to deploy and use. Now, you can accelerate growth and eliminate risks at the same time.

The VM-Series is a virtualized form factor of our next-generation firewall that can be deployed in a range of private and public cloud computing environments based on technologies from VMware, Amazon Web Services, Microsoft, Citrix and KVM.

The VM-Series natively analyzes all traffic in a single pass to determine the application identity, the content within, and the user identity. These core elements of your business can then be used as integral components of your security policy, enabling you to improve your security efficacy through a positive control model and reduce your incident response time though complete visibility into applications across all ports.

In both private and public cloud environments, the VM-Series can be deployed as a perimeter gateway, an IPsec VPN termination point, and a segmentation gateway, protecting your workloads with application enablement and threat prevention policies.

Offer
Learn more about Cisco Firepower NGFW Firewall
Learn more about Palo Alto Networks NG Firewalls
Learn more about Palo Alto Networks VM-Series
Sample Customers
Rackspace, The French Laundry, Downer Group, Lewisville School District, Shawnee Mission School District, Lower Austria Firefighters Administration, Oxford Hospital, SugarCreek, Westfield
SkiStar AB, Ada County, Global IT Services PSF, Southern Cross Hospitals, Verge Health, University of Portsmouth, Austrian Airlines, The Heinz Endowments
Warren Rogers Associates
Top Industries
REVIEWERS
Comms Service Provider22%
Financial Services Firm16%
Manufacturing Company8%
Non Profit8%
VISITORS READING REVIEWS
Comms Service Provider32%
Computer Software Company21%
Government7%
Manufacturing Company4%
REVIEWERS
Comms Service Provider21%
Computer Software Company19%
Financial Services Firm12%
Healthcare Company7%
VISITORS READING REVIEWS
Comms Service Provider26%
Computer Software Company24%
Government6%
Energy/Utilities Company4%
REVIEWERS
Financial Services Firm23%
Manufacturing Company15%
Government15%
Retailer8%
VISITORS READING REVIEWS
Computer Software Company30%
Comms Service Provider19%
Financial Services Firm5%
Government5%
Company Size
REVIEWERS
Small Business43%
Midsize Enterprise28%
Large Enterprise29%
VISITORS READING REVIEWS
Small Business21%
Midsize Enterprise13%
Large Enterprise66%
REVIEWERS
Small Business40%
Midsize Enterprise31%
Large Enterprise29%
VISITORS READING REVIEWS
Small Business35%
Midsize Enterprise15%
Large Enterprise50%
REVIEWERS
Small Business38%
Midsize Enterprise31%
Large Enterprise31%
Find out what your peers are saying about Palo Alto Networks NG Firewalls vs. Palo Alto Networks VM-Series and other solutions. Updated: November 2021.
552,695 professionals have used our research since 2012.

Palo Alto Networks NG Firewalls is ranked 7th in Firewalls with 67 reviews while Palo Alto Networks VM-Series is ranked 11th in Firewalls with 16 reviews. Palo Alto Networks NG Firewalls is rated 8.4, while Palo Alto Networks VM-Series is rated 8.6. The top reviewer of Palo Alto Networks NG Firewalls writes "The product stability and level of security are second to none in the industry". On the other hand, the top reviewer of Palo Alto Networks VM-Series writes "An excellent solution for the right situations and businesses". Palo Alto Networks NG Firewalls is most compared with Fortinet FortiGate, Azure Firewall, Sophos XG and Meraki MX, whereas Palo Alto Networks VM-Series is most compared with Azure Firewall, Fortinet FortiGate, Cisco ASA Firewall, Juniper SRX and Check Point NGFW. See our Palo Alto Networks NG Firewalls vs. Palo Alto Networks VM-Series report.

See our list of best Firewalls vendors.

We monitor all Firewalls reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.