Home Resources FortiGate vs Palo Alto Licensing
FortiGate vs Palo Alto licensing: what needs a subscription
Your customer believes they bought a capability. The quote decides whether they did. This page compares the two licensing models capability by capability, which is the only level at which they are comparable at all.
The short answer
Neither vendor bundles categorically more than the other. They bundle along different seams, which makes any statement about who "includes more" a claim about the specific configuration in front of you.
Fortinet groups services into nested bundle tiers. Palo Alto names a subscription per capability. Comparison is valid at the capability level and misleading at the bundle level.
The matrix below gives you the capability list. Take it into the quote review and make the reseller answer it line by line.
Two different seams
Both vendors sell an appliance that does little on its own and subscriptions that make it useful. The structure of those subscriptions differs.
Fortinet sells nested tiers
Fortinet groups FortiGuard security services into bundles that build on each other. The ATP tier covers the core intrusion prevention and malware services. The UTP tier adds the web-facing services, including URL and DNS filtering, video filtering and anti-botnet protection. The Enterprise tier adds broader attack-surface services such as data loss prevention, attack surface risk scoring, inline malware prevention and IoT detection. All three include FortiCare premium support.
A customer who wants exactly two capabilities buys the tier that contains both. Where those two capabilities sit in different tiers, they buy the higher tier and receive services they will never enable. Moving between tiers at renewal is a step rather than an increment.
Palo Alto sells named capabilities
Palo Alto names a subscription per capability. The cloud-delivered services currently include Advanced Threat Prevention, Advanced WildFire, Advanced URL Filtering, Advanced DNS Security, IoT Security, SaaS Security and SD-WAN.
A customer who wants exactly two capabilities buys exactly two subscriptions. The cost of that precision is that the security posture they believe they bought is several separate line items. Dependencies exist between them, and DNS Security requires a valid Threat Prevention license. A missing subscription is straightforward to overlook until the day it matters.
Bundle and subscription structure taken from each vendor's current Fortinet ordering guide and Palo Alto Networks subscription documentation, checked 8 August 2026. Names and membership change between revisions on both sides, so confirm against the document your reseller is quoting from rather than against this page.
The capability matrix
Read this as a description of how each capability is licensed rather than as a scorecard. The rows where the two vendors differ structurally are the rows worth arguing about in a quote review.
| Capability | FortiGate | Palo Alto |
|---|---|---|
| Intrusion prevention | FortiGuard bundle, from the ATP tier | Advanced Threat Prevention subscription |
| Antivirus and malware | FortiGuard bundle, from the ATP tier | Advanced Threat Prevention, with Advanced WildFire for unknown files |
| Web and URL filtering | FortiGuard bundle, from the UTP tier | Advanced URL Filtering subscription |
| DNS filtering | FortiGuard bundle, from the UTP tier | Advanced DNS Security, which requires Threat Prevention |
| Sandboxing | FortiSandbox, as a cloud service or an appliance | Advanced WildFire, with a private-cloud appliance option |
| Application control | Included in FortiOS | App-ID, included in PAN-OS |
| SD-WAN | Included in FortiOS | Separate SD-WAN subscription per firewall |
| Remote-access VPN, basic | Included in FortiOS, with the free client | Included in PAN-OS, no GlobalProtect license required |
| Remote access, advanced client features | FortiClient EMS server plus per-endpoint subscriptions | GlobalProtect gateway license |
| Endpoint posture checking | FortiClient EMS licensing | GlobalProtect gateway license, for HIP checks |
| Central management | FortiManager, licensed by managed device or VDOM count | Panorama, licensed in device-count tiers |
| Log retention beyond the appliance | FortiAnalyzer, or a cloud logging subscription | Panorama log collectors, or the cloud logging service |
| High availability | Included in FortiOS, each unit licensed separately | Included in PAN-OS, each unit licensed separately |
Compiled from Fortinet's FortiGuard bundle and FortiClient ordering documentation, Palo Alto Networks subscription documentation, and the GlobalProtect licensing documentation. Checked 8 August 2026. This is the fastest-aging page in this library and carries a hard quarterly review.
Remote access is the row that surprises people most often, because both vendors ship a usable client for free and license the features an MSP actually needs on top of it. What each client includes without a license, and what the managed deployment costs, is set out on the remote access page.
Where MSPs get caught
Four patterns account for most of the licensing surprises we see after a sale.
The capability that is visible and inert
Both platforms show configuration for capabilities the customer has not licensed. The setting accepts input, the policy references it, and the enforcement depends on a subscription that is absent. An engineer who configures from the interface rather than from the order can build a policy that looks complete and inspects less than it appears to.
Verify licensed capabilities from the license status page rather than from the presence of a configuration tab.
The feature that needs the management platform
Some capabilities exist on a single appliance and become impractical across an estate without central management. Both vendors license central management by device count, so growth in the estate carries a licensing consequence that first appears about a year after the original purchase.
The endpoint license behind the firewall feature
Endpoint posture checking is a firewall feature that depends on client-side licensing on both platforms. On Palo Alto, HIP checks require a GlobalProtect gateway license. On Fortinet, managed endpoint capability requires a FortiClient EMS server license plus per-endpoint subscriptions, and the free standalone client covers basic VPN connectivity only.
A customer promised conditional access based on device health has been promised endpoint licensing whether or not the quote mentions it.
The dependency between subscriptions
Subscriptions that depend on other subscriptions produce quotes that are internally incomplete. The DNS Security dependency on Threat Prevention is the documented example, and it is unlikely to be the only one by the time you read this. Ask the reseller which items on the quote have prerequisites.
From the operations side
The licensing question that generates real incidents is rarely "what did we buy". It is "what expires, and who is watching the date". Estates arrive on us with subscriptions that lapsed months earlier, discovered because a customer reported that a category of websites stopped resolving. Put every subscription expiry date in the same system that holds the rest of the estate's calendar, and alert on it at ninety days.
The one clear divergence
SD-WAN is the row where the two licensing models produce a genuinely different answer.
Fortinet includes Secure SD-WAN in FortiOS. It is configurable on a FortiGate without a separate SD-WAN license or an additional orchestrator product. Palo Alto licenses SD-WAN as a subscription, required on each physical appliance that participates in the deployment.
At one site this difference is a line item. At two hundred sites it is a material share of the program. The licensing difference is a fact about cost, and whether it should decide the architecture is a separate question with real arguments on both sides.
Those arguments are the subject of the SD-WAN page, including the case against putting WAN and security in the same failure domain.
What happens on expiry
This section matters more operationally than the purchase question and almost nobody writes it down.
Both platforms keep forwarding traffic when a subscription lapses. The appliance does not stop. What degrades is everything that depends on live lookups or content updates, and the two platforms carry different default behaviour when that happens.
| Service | What stops | What continues |
|---|---|---|
| Intrusion prevention, both vendors | New signature and content updates | Enforcement using the last content loaded |
| Antivirus, both vendors | Definition updates | Scanning against the last definitions |
| Sandboxing, both vendors | Submission and verdicts for unknown files | Signature-based detection of known files |
| FortiGuard web filtering | Category lookups, which return a rating error | Traffic handling per the fail-open setting, which blocks by default |
| Palo Alto URL filtering | Cloud categorization, so URLs report as unresolved | Traffic handling per the configured action, which commonly permits |
| Support entitlement, both vendors | Software downloads, TAC access, hardware replacement | The appliance, running the software already on it |
Expiry behaviour compiled from vendor documentation and vendor community guidance, checked 8 August 2026. Behaviour is configurable and version dependent on both platforms. Test it on the customer's own configuration in a maintenance window rather than taking a default from this page into a production incident.
The practical difference is the direction each platform fails in by default. A FortiGate whose web filtering subscription lapses tends toward blocking, so the customer notices within minutes and calls. A Palo Alto whose URL filtering lapses tends toward permitting, so the customer notices nothing and the protection they are paying for is absent.
Both directions have a cost. Set the behaviour deliberately on both platforms, and tell the customer which one you selected for them.
Confirm before signature
Send these in writing and keep the answers with the order.
- List every capability included in this quote, by capability rather than by bundle name.
- Which capabilities in your product line are absent from this quote?
- Which items on this quote require another subscription to function?
- Does this quote include central management, and at what device count does it become necessary?
- Does the remote access described here require any client, endpoint or posture licensing beyond the firewall?
- Where do logs land, how long are they retained, and what does extending that cost?
- What is the expiry date of each subscription, and are they co-terminated?
- If a subscription lapses, what stops working, what keeps working, and what is the default traffic behaviour?
- What does each subscription cost to renew in each year after the initial term?
- For a high-availability pair, which items are required on both units?
Question eight is the one that separates a quote review from a quote comparison. Question ten changes the total on roughly every high-availability deal we see.
Someone has to watch the dates
Subscription expiry, content update health and license state are part of the estate we monitor for MSPs, on Fortinet, Palo Alto and six other platforms, under your brand, from $29 per firewall per month. Your customer keeps the relationship and you stop discovering lapsed licenses through a support ticket.
Get your rateCommon questions
The licensing questions that come up during a quote review. Something missing? Tell us and we will add it.
Does FortiGate include more in the box than Palo Alto?
The two vendors license along different seams, so the comparison holds only per capability. SD-WAN is included in FortiOS and licensed separately by Palo Alto. Basic remote-access VPN needs no subscription on either platform, and the advanced client features need one on both. Threat and content services are subscriptions on both. Assemble matched capability lists from the two quotes before drawing any conclusion about inclusion.
What is the difference between the FortiGuard ATP, UTP and Enterprise bundles?
Fortinet structures them as nested tiers. ATP covers the core intrusion prevention and malware services. UTP adds the web-facing services, including URL and DNS filtering, video filtering and anti-botnet protection. Enterprise adds the broader attack-surface services such as data loss prevention, attack surface risk scoring, inline malware prevention and IoT detection. All three include FortiCare premium support. Confirm the current contents against Fortinet's ordering guide, because bundle membership changes between revisions.
Which Palo Alto subscriptions does a typical firewall need?
Palo Alto names a subscription per capability rather than grouping them. The cloud-delivered services currently include Advanced Threat Prevention, Advanced WildFire, Advanced URL Filtering, Advanced DNS Security, IoT Security, SaaS Security and SD-WAN. Dependencies exist between them, and DNS Security requires a valid Threat Prevention license. Ask the reseller to list which of these are on the quote and which are absent.
What stops working when a firewall subscription expires?
Traffic keeps flowing and the platform keeps enforcing policy on both vendors. The services that depend on live lookups or content updates degrade, and the two platforms have different defaults about what happens next. A FortiGate with expired FortiGuard web filtering returns a rating error for every site, and the default behaviour blocks the traffic unless fail-open is configured. Palo Alto URL filtering more commonly fails open when categorization is unavailable. Test the behaviour on the customer's own configuration rather than relying on the default.
Is central management licensed separately on both platforms?
Yes, on both, and the counting rules differ. FortiManager counts managed devices, and with VDOMs enabled each VDOM counts as one license. Panorama uses a device management license sized in tiers, currently up to 25, 100, 1,000 or 5,000 firewalls, counted by serial number rather than by virtual system. Log retention is a further purchase on both platforms.