Home Resources
Firewall guides for the MSP in the room
Your customer asks which firewall to buy, how big it needs to be, and who watches it at 3am. These pages are written for those three conversations. They are vendor-neutral, specific about what the datasheets omit, and direct about what each platform costs to run once it is in production.
Choosing a platform
Comparisons you can take into a customer meeting.
FortiGate vs Palo Alto: what to tell your customer
Most comparisons compare the wrong numbers. Firewall throughput and threat protection throughput measure different things, list price and five-year cost diverge, and an available feature still needs a license. Includes a side-by-side matrix, the cases where each platform wins, and a decision path you can run in a meeting.
Read the comparison PricingThe five-year number
Why no published figure describes the price gap, what actually drives it, and the ten questions that make two quotes comparable. Includes a five-year cost model to complete from your own quotes.
Work out your number LicensingWhat needs a subscription
Fortinet bundles in nested tiers and Palo Alto names a subscription per capability, so the comparison only holds capability by capability. Includes the matrix, and what stops working on each platform when a subscription lapses.
Check the quote PerformanceHow to size it
What each published throughput figure actually measures, why decryption is the largest variable, and a sizing worksheet you complete from the customer's own environment. No model equivalency table, on purpose.
Size it properly SecurityThe real difference
Both platforms detect well. The durable difference is how easily each one lets an engineer build a policy that inspects less than intended. App-ID against application control, and the failure modes each platform invites.
Read the argument SD-WANThe branch decision
SD-WAN is included in FortiOS and licensed separately by Palo Alto, which moves the per-site number at scale. Includes the architectural case against putting the WAN and the firewall in one failure domain.
Scope the estate Remote accessClients, posture and interop
What GlobalProtect and FortiClient include and what each needs a license for, plus the parameter-by-parameter checklist for a FortiGate to Palo Alto IPsec tunnel that will not come up.
Get the checklist Central managementFortiManager vs Panorama
Written for a multi-tenant estate rather than a single enterprise. Customer separation, delegated administration, where the logs land, how each licenses growth, and what happens when a device and its manager disagree.
Compare the models MigrationPalo Alto to FortiGate, without losing policy intent
Addresses, services and NAT convert with high confidence. Application-based rules convert into something that loads and enforces a different policy. Includes the concept mapping across both FortiGate NGFW modes, the manual cleanup pass in order, how to prove intent survived, and the reverse direction now that Palo Alto has retired its free migration tool.
Plan the projectSizing and architecture
Vendor-neutral. The questions that arrive after the platform is chosen and before the purchase order is signed.
Firewall sizing: how to size a firewall properly
Eleven inputs, every one of them measurable on the firewall the customer already runs. Covers where each measurement comes from, how to itemize headroom so a customer can see what they are buying, why a high-availability pair does not double the capacity, and the six questions that turn a reseller's sizing tool output into something you can put your name to.
Run the method ThroughputWhich number to trust
Six figures on one datasheet, all honest, all measuring different work. What each test does, where the standard methodologies sit, and the six properties of production traffic that consume the difference.
Read the footnote TLS inspectionWhat it costs and what it breaks
The largest variable in any sizing model and the largest source of tickets after rollout. Eight classes of traffic that fail by design, why exemptions are a measurement rather than a list, and a staged rollout order.
Plan the rollout ResilienceHigh availability: what actually survives a failover
Active-passive against active-active, and the arithmetic that decides it. Which state synchronizes between members and which does not, why an inspected session rarely survives, split brain and the heartbeat path, and the failure classes a second appliance does nothing about. Includes the checklist to confirm before go-live and a failover test worth attaching to the customer record.
Check the designDelivering the service
The half of the job that starts after the appliance is racked. We sell into this part, and the pages say so.
Why a firewall operator publishes vendor-neutral comparisons
We sell operations. We run firewalls that MSPs have already sold, under the MSP's own brand, across Fortinet, Palo Alto, Cisco, SonicWall, Sophos, Meraki, Check Point and Juniper. Our side of the arrangement stays the same whichever platform your customer selects. We have no commercial reason to favor either answer.
We bring the part most comparison content omits. These pages describe what each platform is like to operate at 2am, months after the sale, once the person who configured it has moved on. That perspective separates a page written from datasheets from a page written by the team carrying the pager.
Every claim here follows the standards we set ourselves. We cite vendor figures with the vendor's own test conditions, mark our own observations as ours, and put a visible checked date on anything that can go out of date.
You advise. We operate.
Once the platform decision is made, someone has to run it 24/7. That part can be ours, under your brand, from $29 per firewall per month.