Home Resources FortiGate vs Palo Alto Licensing

FortiGate vs Palo Alto licensing: what needs a subscription

Your customer believes they bought a capability. The quote decides whether they did. This page compares the two licensing models capability by capability, which is the only level at which they are comparable at all.

Checked 8 August 2026 9 minute read No prices published

The short answer

Neither vendor bundles categorically more than the other. They bundle along different seams, which makes any statement about who "includes more" a claim about the specific configuration in front of you.

Fortinet groups services into nested bundle tiers. Palo Alto names a subscription per capability. Comparison is valid at the capability level and misleading at the bundle level.

The matrix below gives you the capability list. Take it into the quote review and make the reseller answer it line by line.

Two different seams

Both vendors sell an appliance that does little on its own and subscriptions that make it useful. The structure of those subscriptions differs.

Fortinet sells nested tiers

Fortinet groups FortiGuard security services into bundles that build on each other. The ATP tier covers the core intrusion prevention and malware services. The UTP tier adds the web-facing services, including URL and DNS filtering, video filtering and anti-botnet protection. The Enterprise tier adds broader attack-surface services such as data loss prevention, attack surface risk scoring, inline malware prevention and IoT detection. All three include FortiCare premium support.

A customer who wants exactly two capabilities buys the tier that contains both. Where those two capabilities sit in different tiers, they buy the higher tier and receive services they will never enable. Moving between tiers at renewal is a step rather than an increment.

Palo Alto sells named capabilities

Palo Alto names a subscription per capability. The cloud-delivered services currently include Advanced Threat Prevention, Advanced WildFire, Advanced URL Filtering, Advanced DNS Security, IoT Security, SaaS Security and SD-WAN.

A customer who wants exactly two capabilities buys exactly two subscriptions. The cost of that precision is that the security posture they believe they bought is several separate line items. Dependencies exist between them, and DNS Security requires a valid Threat Prevention license. A missing subscription is straightforward to overlook until the day it matters.

Bundle and subscription structure taken from each vendor's current Fortinet ordering guide and Palo Alto Networks subscription documentation, checked 8 August 2026. Names and membership change between revisions on both sides, so confirm against the document your reseller is quoting from rather than against this page.

The capability matrix

Read this as a description of how each capability is licensed rather than as a scorecard. The rows where the two vendors differ structurally are the rows worth arguing about in a quote review.

How each capability is licensed on each platform
Capability FortiGate Palo Alto
Intrusion preventionFortiGuard bundle, from the ATP tierAdvanced Threat Prevention subscription
Antivirus and malwareFortiGuard bundle, from the ATP tierAdvanced Threat Prevention, with Advanced WildFire for unknown files
Web and URL filteringFortiGuard bundle, from the UTP tierAdvanced URL Filtering subscription
DNS filteringFortiGuard bundle, from the UTP tierAdvanced DNS Security, which requires Threat Prevention
SandboxingFortiSandbox, as a cloud service or an applianceAdvanced WildFire, with a private-cloud appliance option
Application controlIncluded in FortiOSApp-ID, included in PAN-OS
SD-WANIncluded in FortiOSSeparate SD-WAN subscription per firewall
Remote-access VPN, basicIncluded in FortiOS, with the free clientIncluded in PAN-OS, no GlobalProtect license required
Remote access, advanced client featuresFortiClient EMS server plus per-endpoint subscriptionsGlobalProtect gateway license
Endpoint posture checkingFortiClient EMS licensingGlobalProtect gateway license, for HIP checks
Central managementFortiManager, licensed by managed device or VDOM countPanorama, licensed in device-count tiers
Log retention beyond the applianceFortiAnalyzer, or a cloud logging subscriptionPanorama log collectors, or the cloud logging service
High availabilityIncluded in FortiOS, each unit licensed separatelyIncluded in PAN-OS, each unit licensed separately

Compiled from Fortinet's FortiGuard bundle and FortiClient ordering documentation, Palo Alto Networks subscription documentation, and the GlobalProtect licensing documentation. Checked 8 August 2026. This is the fastest-aging page in this library and carries a hard quarterly review.

Remote access is the row that surprises people most often, because both vendors ship a usable client for free and license the features an MSP actually needs on top of it. What each client includes without a license, and what the managed deployment costs, is set out on the remote access page.

Where MSPs get caught

Four patterns account for most of the licensing surprises we see after a sale.

The capability that is visible and inert

Both platforms show configuration for capabilities the customer has not licensed. The setting accepts input, the policy references it, and the enforcement depends on a subscription that is absent. An engineer who configures from the interface rather than from the order can build a policy that looks complete and inspects less than it appears to.

Verify licensed capabilities from the license status page rather than from the presence of a configuration tab.

The feature that needs the management platform

Some capabilities exist on a single appliance and become impractical across an estate without central management. Both vendors license central management by device count, so growth in the estate carries a licensing consequence that first appears about a year after the original purchase.

The endpoint license behind the firewall feature

Endpoint posture checking is a firewall feature that depends on client-side licensing on both platforms. On Palo Alto, HIP checks require a GlobalProtect gateway license. On Fortinet, managed endpoint capability requires a FortiClient EMS server license plus per-endpoint subscriptions, and the free standalone client covers basic VPN connectivity only.

A customer promised conditional access based on device health has been promised endpoint licensing whether or not the quote mentions it.

The dependency between subscriptions

Subscriptions that depend on other subscriptions produce quotes that are internally incomplete. The DNS Security dependency on Threat Prevention is the documented example, and it is unlikely to be the only one by the time you read this. Ask the reseller which items on the quote have prerequisites.

From the operations side

The licensing question that generates real incidents is rarely "what did we buy". It is "what expires, and who is watching the date". Estates arrive on us with subscriptions that lapsed months earlier, discovered because a customer reported that a category of websites stopped resolving. Put every subscription expiry date in the same system that holds the rest of the estate's calendar, and alert on it at ninety days.

The one clear divergence

SD-WAN is the row where the two licensing models produce a genuinely different answer.

Fortinet includes Secure SD-WAN in FortiOS. It is configurable on a FortiGate without a separate SD-WAN license or an additional orchestrator product. Palo Alto licenses SD-WAN as a subscription, required on each physical appliance that participates in the deployment.

At one site this difference is a line item. At two hundred sites it is a material share of the program. The licensing difference is a fact about cost, and whether it should decide the architecture is a separate question with real arguments on both sides.

Those arguments are the subject of the SD-WAN page, including the case against putting WAN and security in the same failure domain.

What happens on expiry

This section matters more operationally than the purchase question and almost nobody writes it down.

Both platforms keep forwarding traffic when a subscription lapses. The appliance does not stop. What degrades is everything that depends on live lookups or content updates, and the two platforms carry different default behaviour when that happens.

Behaviour when a subscription lapses, by service
Service What stops What continues
Intrusion prevention, both vendorsNew signature and content updatesEnforcement using the last content loaded
Antivirus, both vendorsDefinition updatesScanning against the last definitions
Sandboxing, both vendorsSubmission and verdicts for unknown filesSignature-based detection of known files
FortiGuard web filteringCategory lookups, which return a rating errorTraffic handling per the fail-open setting, which blocks by default
Palo Alto URL filteringCloud categorization, so URLs report as unresolvedTraffic handling per the configured action, which commonly permits
Support entitlement, both vendorsSoftware downloads, TAC access, hardware replacementThe appliance, running the software already on it

Expiry behaviour compiled from vendor documentation and vendor community guidance, checked 8 August 2026. Behaviour is configurable and version dependent on both platforms. Test it on the customer's own configuration in a maintenance window rather than taking a default from this page into a production incident.

The practical difference is the direction each platform fails in by default. A FortiGate whose web filtering subscription lapses tends toward blocking, so the customer notices within minutes and calls. A Palo Alto whose URL filtering lapses tends toward permitting, so the customer notices nothing and the protection they are paying for is absent.

Both directions have a cost. Set the behaviour deliberately on both platforms, and tell the customer which one you selected for them.

Confirm before signature

Send these in writing and keep the answers with the order.

  1. List every capability included in this quote, by capability rather than by bundle name.
  2. Which capabilities in your product line are absent from this quote?
  3. Which items on this quote require another subscription to function?
  4. Does this quote include central management, and at what device count does it become necessary?
  5. Does the remote access described here require any client, endpoint or posture licensing beyond the firewall?
  6. Where do logs land, how long are they retained, and what does extending that cost?
  7. What is the expiry date of each subscription, and are they co-terminated?
  8. If a subscription lapses, what stops working, what keeps working, and what is the default traffic behaviour?
  9. What does each subscription cost to renew in each year after the initial term?
  10. For a high-availability pair, which items are required on both units?

Question eight is the one that separates a quote review from a quote comparison. Question ten changes the total on roughly every high-availability deal we see.

Someone has to watch the dates

Subscription expiry, content update health and license state are part of the estate we monitor for MSPs, on Fortinet, Palo Alto and six other platforms, under your brand, from $29 per firewall per month. Your customer keeps the relationship and you stop discovering lapsed licenses through a support ticket.

Get your rate

Common questions

The licensing questions that come up during a quote review. Something missing? Tell us and we will add it.

Does FortiGate include more in the box than Palo Alto?

The two vendors license along different seams, so the comparison holds only per capability. SD-WAN is included in FortiOS and licensed separately by Palo Alto. Basic remote-access VPN needs no subscription on either platform, and the advanced client features need one on both. Threat and content services are subscriptions on both. Assemble matched capability lists from the two quotes before drawing any conclusion about inclusion.

What is the difference between the FortiGuard ATP, UTP and Enterprise bundles?

Fortinet structures them as nested tiers. ATP covers the core intrusion prevention and malware services. UTP adds the web-facing services, including URL and DNS filtering, video filtering and anti-botnet protection. Enterprise adds the broader attack-surface services such as data loss prevention, attack surface risk scoring, inline malware prevention and IoT detection. All three include FortiCare premium support. Confirm the current contents against Fortinet's ordering guide, because bundle membership changes between revisions.

Which Palo Alto subscriptions does a typical firewall need?

Palo Alto names a subscription per capability rather than grouping them. The cloud-delivered services currently include Advanced Threat Prevention, Advanced WildFire, Advanced URL Filtering, Advanced DNS Security, IoT Security, SaaS Security and SD-WAN. Dependencies exist between them, and DNS Security requires a valid Threat Prevention license. Ask the reseller to list which of these are on the quote and which are absent.

What stops working when a firewall subscription expires?

Traffic keeps flowing and the platform keeps enforcing policy on both vendors. The services that depend on live lookups or content updates degrade, and the two platforms have different defaults about what happens next. A FortiGate with expired FortiGuard web filtering returns a rating error for every site, and the default behaviour blocks the traffic unless fail-open is configured. Palo Alto URL filtering more commonly fails open when categorization is unavailable. Test the behaviour on the customer's own configuration rather than relying on the default.

Is central management licensed separately on both platforms?

Yes, on both, and the counting rules differ. FortiManager counts managed devices, and with VDOMs enabled each VDOM counts as one license. Panorama uses a device management license sized in tiers, currently up to 25, 100, 1,000 or 5,000 firewalls, counted by serial number rather than by virtual system. Log retention is a further purchase on both platforms.