We just raised a $30M Series A: Read our story

Compare Palo Alto Networks NG Firewalls vs. Sophos XG

Cancel
You must select at least 2 products to compare!
Comparison Summary
Question: Which is better - Palo Alto Networks NG Firewalls or Sophos XG?
Answer: As a Sophos specialist, I can tell you that XG Firewall will cover all that you'll need with a more affordable way.Sophos XG firewall will not disappoint you with its performance, resources or features.
Featured Review
Find out what your peers are saying about Palo Alto Networks NG Firewalls vs. Sophos XG and other solutions. Updated: November 2021.
553,954 professionals have used our research since 2012.
Quotes From Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:

Pros
"When it comes to the integration among Cisco tools, we find it easy. It's a very practical integration with other components as well.""Firepower NGFW has improved my organization in several ways. Before, we were trying to stamp out security threats and issues, it was a one-off type of way to attack it. I spent a lot of manpower trying to track down the individual issues or flare-ups that we would see. With Cisco's Firepower Management, we're able to have that push up to basically one monitor and one UI and be able to track that and stop threats immediately. It also gives us a little more granularity on what those threats might be.""The most valuable feature is the access control list (ACL).""The Firepower+ISE+AMP for endpoint integration is something that really stands it out with other vendor solutions. They have something called pxGrid and i think it is already endorsed by IETF. This allows all devices on the network to communicate.""The customer service/technical support is very good with this solution.""There are no issues that we are aware of. It does its job silently in the background.""We have not had to deal with stability issues.""Feature-wise, we mostly use IPS because it is a security requirement to protect against attacks from outside and inside. This is where IPS helps us out a bunch."

More Cisco Firepower NGFW Firewall Pros »

"I like the architecture because it separates the management plan process and the data plan process.""When we put it on the border, it was blocking everything that we were getting ahead of time, and we weren't getting any hits. This includes URL filtering, spam prevention, and anti-virus.""There are plenty of features available in this solution, such as attack blocker and spam blocker. Additionally, it is very robust and in-depth.""The machine learning in the core of the firewalls, for inline, real-time attack prevention, is very important to us. With the malware and ransomware threats that are out there, to keep abreast of and ahead of those types of attacks, it's important for our devices to be able to use AI to distinguish when there is malicious traffic or abnormal traffic within our environment, and then notify us.""Protection from a single packet and ease of making security rules.""Palo Alto NGFW’s unified platform has helped our customers eliminate security holes. With a unified platform, customers can deploy the NG Firewall both in the data center edge, inside the data center, and in the product/public cloud environments. They have the same user interfaces and platform, so they can be maintained by a single unified platform called Panorama. Customers can use Palo Alto Network NG Firewalls in all the places where they need to protect their environments. This helps to decrease security holes.""This solution not only provides better security than flat VLAN segments but allows easy movement through the lifecycle of the server.""Some of the valuable features in this solution are traffic monitoring, GUI functionality, and it very easy to troubleshoot if there is any problem that happens."

More Palo Alto Networks NG Firewalls Pros »

"Each user has the ability to manage the solution.""We get good usage out of the features. It has enabled us to gain popularity. It has great features.""The most valuable feature is the intrusion prevention system.""The solution is scalable.""it's user-friendly, not complex.""So far, I'm happy that they have recently added a firewall role, so I feel a little more comfortable with the security. The threat management is good.""The product has a console that is based in the cloud for all their products. In this console, they have email security, firewall security, endpoint security, et cetera. All of the products on offer in the console are very useful for us.""The most valuable features are the central management, the user VPN, and communications."

More Sophos XG Pros »

Cons
"The solution could offer better control that would allow the ability to restrictions certain features from a website.""An area of improvement for this solution is the console visualization.""Deploying configurations takes longer than it should.""There is limited data storage on the appliance itself. So, you need to ship it out elsewhere in order for you to store it. The only point of consideration is around that area, basically limited storage on the machine and appliance. Consider logging it elsewhere or pushing it out to a SIEM to get better controls and manipulation over the data to generate additional metrics and visibility.""The intelligence has room for improvement. There are some hackers that we haven't seen before and its ability to detect those types of attacks needs to be improved.""Its interface is sometimes is a little bit slow, and it can be improved. When you need to put your appliance in failover mode, it is a little difficult to do it remotely because you need to turn off the appliance in Cisco mode. In terms of new features, it would be good to have AnyConnect VPN with Firepower. I am not sure if it is available at the moment.""Web filtering needs improvement because sometimes the URL is miscategorized.""In a future release, it would be ideal if they could offer an open interface to other security products so that we could easily connect to our own open industry standard."

More Cisco Firepower NGFW Firewall Cons »

"The solution could be simplified.""The cost of the device is very high.""Its reporting can definitely be improved. I would like to have better graphical dashboards and more widgets for more clarity in the reporting area. In a third-generation firewall, you can generate some dashboards. It provides the information that we need, but from the C-level or a higher-level perspective, it is kind of rough and incomplete. Its data loss prevention (DLP) feature is not good enough. Currently, this feature is very basic and not suitable for enterprises. It would be nice if they can include a better DLP feature like Fortinet. We would like to have a local depot of Palo Alto in Latin America. Competitors such as Cisco and Check Point have a local depot here. If there is an issue with their hardware, you can go to the depot, and in about four hours, you can get a replacement device, but that's not the case with Palo Alto Networks because we need to import from Miami. It takes about two to three weeks.""When we looked at it originally, we needed to host the Panorama environment ourselves. I would prefer it if we could take this as a service. It might be that it is available, but for some reason we didn't choose it. The downsides of hosting are that we need to feed and water the machines. We are trying to move to a more SaaS environment where we have less things in our data centers, whether they be in our cloud data centers or physical data centers, which can reduce our physical data center footprint.""I would like to see better third-party orchestration so that it is easier for the team to work with different products.""The price of the solution is very high.""They can work on the price. They are a little bit expensive, and not all customers are able to afford this solution. Taking into consideration that there is huge competition in the market and there are multiple firewall companies that are much cheaper than them and offer almost the same features, it would be good to improve the price.""Lacks mobility between on-prem and cloud based."

More Palo Alto Networks NG Firewalls Cons »

"The number of ports, especially on the entry-level appliances, should be increased.""I need to open the email to see what it contains and the value of it before I know whether to access it or not.""There have been some issues when upgrading. For some reason, parts of the configuration become unconfigured, I then have to reconfigure it. I should not need to keep reconfiguring it after upgrades.""It would be better if they made their own hardware like Palo Alto and Fortinet. They use their own ASICs and claim it is more secure.""The solution could improve by making the graphical interface better and increasing the performance.""Our clients use Karios, and while it integrates well with it, the integration could be improved.""It would be great if the user can have a portal to check on activities related to their account.""The UI needs improvement because it can be a little weird at times."

More Sophos XG Cons »

Pricing and Cost Advice
"The price for Firepower is more expensive than FortiGate. The licensing is very complex. We usually ask for help from Solutel because of its complexity. I have a Cisco account where I can download the VPN client, then connect. Instead, I create an issue with Solutel, then Solutel solves the case.""When we are fighting against other competitors for customers, whether it is a small or big business, we feel very comfortable with the price that Firepower has today.""It definitely competes with the other vendors in the market.""This product is expensive.""The price is comparable.""Cisco is not for a small mom-and-pop shop because of the cost, but if you're in a regulated industry where a breach could cost you a million dollars, it's a bargain.""Its price is in the middle range. Both Firepower and FortiGate are not cheap. Palo Alto and Check Point are the cheapest ones. I don't remember any costs in addition to the standard licensing fees.""This solution is expensive and other solutions, such as FortiGate, are cheaper."

More Cisco Firepower NGFW Firewall Pricing and Cost Advice »

"The price of the solution is on the higher side compared to competitors.""It is expensive.""The NG firewall is an expensive solution.""I am not involved in the commercial side, but I believe that Palo Alto is quite expensive compared to others.""Palo Alto is not a cheap solution but it is competitive when it comes to subscriptions.""This solution is quite expensive.""The pricing is very high.""The price of this product should be reduced."

More Palo Alto Networks NG Firewalls Pricing and Cost Advice »

"The price is reasonable""The price of the solution is reasonable when comparing it to other solutions.""The pricing is economical.""For our company, the price was reasonable.""Its price is fair. It is cheaper and way better than others.""The issue of a recurring license is a hassle because every year, we have to subscribe.""We have a three-year license.""The price is fair."

More Sophos XG Pricing and Cost Advice »

report
Use our free recommendation engine to learn which Firewalls solutions are best for your needs.
553,954 professionals have used our research since 2012.
Answers from the Community
Netanya Carmi
Questions from the Community
Top Answer:  When you compare these firewalls you can identify them with different features, advantages, practices and… more »
Top Answer:  The Cisco Firepower NGFW Firewall is a very powerful and very complex piece of anti-viral software. When one considers… more »
Top Answer: It is easy to integrate Cisco ASA with other Cisco products and also other NAC solutions. When you understand the Cisco… more »
Top Answer: Azure Firewall Vs. Palo Alto Network NG Firewalls Both solutions provide stellar stability and security. Azure… more »
Top Answer: In the best tradition of these questions, Feature-wise both are quite similar, but each has things it's better at, it… more »
Top Answer: Palo Alto Networks NG Firewalls have both great features and performance. I like that Palo Alto has regular threat… more »
Top Answer: Sophos UTM is no longer being developed, according to our reseller. All the development effort is going into XG. So XG… more »
Top Answer: Compared to other firewalls that I had looked at, I thought Sophos was the better solution. It just seems to be easier… more »
Top Answer: The pricing was reasonable. VPN licensing is included.
Comparisons
Also Known As
Cisco Firepower NGFW, Cisco Firepower Next-Generation Firewall, FirePOWER, Cisco NGFWv
Palo Alto NGFW, Palo Alto Networks Next-Generation Firewall, Palo Alto Networks PA-Series
Learn More
Overview

Cisco NGFW firewalls deliver advanced threat defense capabilities to meet diverse needs, from
small/branch offices to high performance data centers and service providers. Available in a wide
range of models, Cisco NGFW can be deployed as a physical or virtual appliance. Advanced threat
defense capabilities include Next-generation IPS (NGIPS), Security Intelligence (SI), Advanced
Malware Protection (AMP), URL filtering, Application Visibility and Control (AVC), and flexible VPN
features. Inspect encrypted traffic and enjoy automated risk ranking and impact flags to reduce event
volume so you can quickly prioritize threats. Cisco NGFW firewalls are also available with clustering
for increased performance, high availability configurations, and more.
Cisco Firepower NGFWv is the virtualized version of Cisco's Firepower NGFW firewall. Widely
deployed in leading private and public clouds, Cisco NGFWv automatically scales up/down to meet
the needs of dynamic cloud environments and high availability provides resilience. Also, Cisco NGFWv
can deliver micro-segmentation to protect east-west network traffic.
Cisco firewalls provide consistent security policies, enforcement, and protection across all your
environments. Unified management for Cisco ASA and FTD/NGFW physical and virtual firewalls is
delivered by Cisco Defense Orchestrator (CDO), with cloud logging also available. And with Cisco
SecureX included with every Cisco firewall, you gain a cloud-native platform experience that enables
greater simplicity, visibility, and efficiency.
Learn more about Cisco’s firewall solutions, including virtual appliances for public and private cloud.

Palo Alto Networks' next-generation firewalls secure your business with a prevention-focused architecture and integrated innovations that are easy to deploy and use. Now, you can accelerate growth and eliminate risks at the same time.

Sophos XG Firewall is next gen firewall that is optimized for today’s business, delivering all the protection and insights you need in a single, powerful appliance that’s easy to manage.

Offer
Learn more about Cisco Firepower NGFW Firewall
Learn more about Palo Alto Networks NG Firewalls
Learn more about Sophos XG
Sample Customers
Rackspace, The French Laundry, Downer Group, Lewisville School District, Shawnee Mission School District, Lower Austria Firefighters Administration, Oxford Hospital, SugarCreek, Westfield
SkiStar AB, Ada County, Global IT Services PSF, Southern Cross Hospitals, Verge Health, University of Portsmouth, Austrian Airlines, The Heinz Endowments
Information Not Available
Top Industries
REVIEWERS
Comms Service Provider22%
Financial Services Firm16%
Non Profit8%
Government8%
VISITORS READING REVIEWS
Comms Service Provider32%
Computer Software Company21%
Government7%
Manufacturing Company4%
REVIEWERS
Comms Service Provider21%
Computer Software Company19%
Financial Services Firm12%
Healthcare Company7%
VISITORS READING REVIEWS
Comms Service Provider26%
Computer Software Company24%
Government6%
Energy/Utilities Company4%
REVIEWERS
Financial Services Firm11%
Manufacturing Company10%
Comms Service Provider9%
Healthcare Company9%
VISITORS READING REVIEWS
Comms Service Provider40%
Computer Software Company18%
Government6%
Media Company4%
Company Size
REVIEWERS
Small Business43%
Midsize Enterprise28%
Large Enterprise29%
VISITORS READING REVIEWS
Small Business21%
Midsize Enterprise13%
Large Enterprise66%
REVIEWERS
Small Business40%
Midsize Enterprise31%
Large Enterprise29%
VISITORS READING REVIEWS
Small Business36%
Midsize Enterprise15%
Large Enterprise49%
REVIEWERS
Small Business65%
Midsize Enterprise23%
Large Enterprise12%
VISITORS READING REVIEWS
Small Business50%
Midsize Enterprise25%
Large Enterprise25%
Find out what your peers are saying about Palo Alto Networks NG Firewalls vs. Sophos XG and other solutions. Updated: November 2021.
553,954 professionals have used our research since 2012.

Palo Alto Networks NG Firewalls is ranked 8th in Firewalls with 67 reviews while Sophos XG is ranked 5th in Firewalls with 118 reviews. Palo Alto Networks NG Firewalls is rated 8.4, while Sophos XG is rated 8.0. The top reviewer of Palo Alto Networks NG Firewalls writes "The product stability and level of security are second to none in the industry". On the other hand, the top reviewer of Sophos XG writes "Light and stable with excellent real-time control ". Palo Alto Networks NG Firewalls is most compared with Fortinet FortiGate, Azure Firewall, Meraki MX, pfSense and Check Point CloudGuard Network Security, whereas Sophos XG is most compared with Fortinet FortiGate, pfSense, Meraki MX, Sophos UTM and Sophos Cyberoam UTM. See our Palo Alto Networks NG Firewalls vs. Sophos XG report.

See our list of best Firewalls vendors.

We monitor all Firewalls reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.