Home Resources

Firewall guides for the MSP in the room

Your customer asks which firewall to buy, how big it needs to be, and who watches it at 3am. These pages are written for those three conversations. They are vendor-neutral, specific about what the datasheets omit, and direct about what each platform costs to run once it is in production.

Choosing a platform

Comparisons you can take into a customer meeting.

Start here

FortiGate vs Palo Alto: what to tell your customer

Most comparisons compare the wrong numbers. Firewall throughput and threat protection throughput measure different things, list price and five-year cost diverge, and an available feature still needs a license. Includes a side-by-side matrix, the cases where each platform wins, and a decision path you can run in a meeting.

Read the comparison
Pricing

The five-year number

Why no published figure describes the price gap, what actually drives it, and the ten questions that make two quotes comparable. Includes a five-year cost model to complete from your own quotes.

Work out your number
Licensing

What needs a subscription

Fortinet bundles in nested tiers and Palo Alto names a subscription per capability, so the comparison only holds capability by capability. Includes the matrix, and what stops working on each platform when a subscription lapses.

Check the quote
Performance

How to size it

What each published throughput figure actually measures, why decryption is the largest variable, and a sizing worksheet you complete from the customer's own environment. No model equivalency table, on purpose.

Size it properly
Security

The real difference

Both platforms detect well. The durable difference is how easily each one lets an engineer build a policy that inspects less than intended. App-ID against application control, and the failure modes each platform invites.

Read the argument
SD-WAN

The branch decision

SD-WAN is included in FortiOS and licensed separately by Palo Alto, which moves the per-site number at scale. Includes the architectural case against putting the WAN and the firewall in one failure domain.

Scope the estate
Remote access

Clients, posture and interop

What GlobalProtect and FortiClient include and what each needs a license for, plus the parameter-by-parameter checklist for a FortiGate to Palo Alto IPsec tunnel that will not come up.

Get the checklist
Central management

FortiManager vs Panorama

Written for a multi-tenant estate rather than a single enterprise. Customer separation, delegated administration, where the logs land, how each licenses growth, and what happens when a device and its manager disagree.

Compare the models
Migration

Palo Alto to FortiGate, without losing policy intent

Addresses, services and NAT convert with high confidence. Application-based rules convert into something that loads and enforces a different policy. Includes the concept mapping across both FortiGate NGFW modes, the manual cleanup pass in order, how to prove intent survived, and the reverse direction now that Palo Alto has retired its free migration tool.

Plan the project

Sizing and architecture

Vendor-neutral. The questions that arrive after the platform is chosen and before the purchase order is signed.

Why a firewall operator publishes vendor-neutral comparisons

We sell operations. We run firewalls that MSPs have already sold, under the MSP's own brand, across Fortinet, Palo Alto, Cisco, SonicWall, Sophos, Meraki, Check Point and Juniper. Our side of the arrangement stays the same whichever platform your customer selects. We have no commercial reason to favor either answer.

We bring the part most comparison content omits. These pages describe what each platform is like to operate at 2am, months after the sale, once the person who configured it has moved on. That perspective separates a page written from datasheets from a page written by the team carrying the pager.

Every claim here follows the standards we set ourselves. We cite vendor figures with the vendor's own test conditions, mark our own observations as ours, and put a visible checked date on anything that can go out of date.

You advise. We operate.

Once the platform decision is made, someone has to run it 24/7. That part can be ours, under your brand, from $29 per firewall per month.

Become a partner See what we cover