Home Resources FortiGate vs Palo Alto

FortiGate vs Palo Alto: what to tell your customer

Most comparisons compare the wrong numbers. This one is written for the MSP in the room, by a team that operates both platforms for other people's customers and has no stake in which one gets bought.

Checked 31 July 2026 12 minute read Vendor-neutral

The short answer

Both platforms will secure your customer's network competently. Palo Alto suits an organization with a dedicated security function that will use consistent application-based policy and enable decryption; FortiGate suits distributed, branch-heavy or cost-sensitive estates, particularly where SD-WAN and security should live on the same appliance.

The condition that flips the decision is not a feature. It is whether anyone will operate the thing properly after go-live. A well-run FortiGate beats a neglected Palo Alto every time, and the reverse is equally true.

How to read any comparison, including this one

Before the side-by-side, six distinctions. Every one of them is a place where vendor material, reseller decks and most comparison articles quietly compare things that are not comparable. If your customer has arrived with a printout, these are the six questions to ask about it.

1. Firewall throughput is not threat protection throughput

Both vendors publish several throughput figures per model, and they are measured under conditions that have almost nothing in common. A headline "firewall throughput" number is generally produced with large packets and inspection disabled. A "threat protection" or "NGFW" number is produced with a mixed traffic profile and security services running, and it is routinely a fraction of the headline. Comparing one vendor's headline against the other's inspection figure is the single most common error in this category, and it is usually the reason a box that looked oversized on paper is saturated in production.

Read the footnotes on the datasheet. They state the test conditions, and the test conditions are the comparison.

2. List price is not five-year cost

Appliance list price is the smallest and least stable input. What actually determines the number your customer pays over five years is the subscription bundle attached to the box, the support tier, the renewal uplift at year three, and the discount the reseller negotiated on the initial order but not necessarily on the renewal. Two quotes with the same appliance price can diverge substantially by year five.

Insist on a five-year total, not a first-year total, from both vendors, on the same term, including renewals and support. If a reseller will not produce one, that is information too.

3. A feature existing is not a feature being licensed

Both platforms will show a capability in the interface that is inert without the matching subscription. This cuts in both directions and it changes real quotes. SD-WAN is the clearest case: it is part of FortiOS with no additional subscription, whereas Palo Alto licenses SD-WAN separately. Advanced remote-access capability, such as posture checking on the endpoint, similarly sits behind a subscription on both platforms rather than being included with the appliance.

Build the licensing matrix from current ordering guides at quote time. Bundle names and contents change more often than the hardware does.

4. Application detection is not policy enforcement

This is the most misunderstood technical difference between the two, and it matters far more than the marketing comparison of App-ID against Application Control.

Palo Alto identifies the application on all traffic as a matter of architecture, and applications are first-class match criteria in the security policy. On FortiGate in its default profile mode, application control is a security profile attached to a policy — the policy still matches on addresses, ports and services, and the profile inspects what passes. FortiGate's policy mode changes this, allowing applications and URL categories to be matching criteria in the policy itself, which is structurally much closer to the PAN-OS model.

Both platforms can express an application-aware policy. They express it differently enough that a rule set does not survive translation between them intact, which is why this distinction reappears as the hardest part of any migration.

5. A marketing claim is not an operational outcome

Every vendor's material describes the platform running well. Neither describes what happens at 2am eighteen months later, when the engineer who designed the policy has left, the rule base has accumulated exceptions nobody can justify, and a firmware upgrade is overdue because the last one caused an outage.

That gap is where managed firewall estates actually succeed or fail, and it is not visible in any feature comparison.

6. Greenfield selection is not migration

"Which platform is better" and "should we move from the one we have" are different questions with different answers. A migration carries conversion effort, a validation burden, a period of elevated risk and the cost of retraining whoever operates it. A platform that would have won a greenfield evaluation can still be the wrong answer for an estate already running competently on the other one.

From the operations side

The most expensive firewall decisions we see are not wrong-platform decisions. They are right-platform decisions sized against the headline throughput figure, bought without the subscription that makes the feature the customer was sold actually work, or migrated on a timeline that left no room to validate the converted policy.

Side by side

Structural differences rather than a scorecard. Nothing here is a winner-takes-all row, which is why there is no highlighted column.

Structural comparison of FortiGate and Palo Alto Networks firewalls
Dimension FortiGate Palo Alto
Acceleration approach Purpose-built ASICs for network and content processing Single-pass architecture with dedicated function-specific hardware
Application identification Security profile in default profile mode; policy match criterion in policy mode Identified on all traffic; a first-class policy match criterion
SD-WAN licensing Included in the operating system Separate subscription
Remote access client FortiClient; posture and ZTNA require an EMS license GlobalProtect; posture checking requires a subscription
Malware analysis FortiSandbox, on-premises or cloud WildFire, cloud-delivered
Central management FortiManager, appliance or virtual Panorama, appliance or virtual
Subscription structure Bundled tiers covering most services together Individually named subscriptions per capability
Headline throughput basis Large-packet test with inspection disabled Application identification enabled on the headline figure
Feature surface Broad; switching, wireless, WAN and security in one OS Narrower and more opinionated; security-focused
Automation REST API, Terraform provider, Ansible collection REST and XML API, Terraform provider, Ansible collection
Migration tooling FortiConverter Vendor migration tooling; confirm current product before planning
Skills availability Larger installed base in the mid-market and channel Deeper specialization, smaller pool, higher rates
Typical strong fit Distributed, branch-heavy, cost-sensitive, mixed WAN Security-led estates with staff to operate them
Typical weak fit Customers who will leave profiles at defaults and never tune them Customers without the budget or headcount to use what they bought

Structural characteristics compiled from current vendor product and ordering documentation, checked 31 July 2026. Fit and skills rows are our judgement from operating both platforms, not vendor claims. Licensing structures change; re-check against a live quote before advising a customer.

Where FortiGate genuinely wins

Branch and SD-WAN economics. When routing, WAN path selection and security can converge on one appliance with no additional subscription, the per-site cost of a distributed estate drops in a way that is difficult to argue with. For a customer with sixty sites, this is frequently the whole decision.

Capability per dollar. The bundled subscription model puts a broad set of security services on the box for one line item. For a mid-market customer who wants reasonable coverage across many functions rather than depth in a few, this fits how they actually buy.

Breadth of the ecosystem. Switching, access points, endpoint and management under one operating vendor is genuinely simpler to procure and support than assembling the same from several.

The weakness, stated plainly. That breadth is also the risk. A FortiGate has more places where a setting can be wrong, and the default profile-mode model makes it entirely possible to deploy one that inspects far less than the customer believes. Security profiles left at defaults, application control attached to nothing meaningful, and SSL inspection never enabled is a configuration we encounter regularly, and the box reports itself as healthy throughout.

Where Palo Alto genuinely wins

Policy consistency. Application identity applied to all traffic as a matter of architecture, rather than as a profile someone has to remember to attach, produces a rule base that means what it appears to mean. Over years, and across staff turnover, that is worth more than most feature comparisons credit.

Investigation quality. When a customer needs to answer what happened, not just what was blocked, the log detail and the tooling around it are strong. For regulated customers and anyone with a real incident response obligation, this is a material difference.

Operational opinionatedness. Fewer ways to do a thing means fewer ways to do it wrong. A Palo Alto configured by an average engineer tends to land closer to the intended design than a FortiGate configured by the same engineer.

The weakness, stated plainly. Cost is the obvious one, but the real one is that the platform assumes competent operation and degrades badly without it. Separate subscriptions per capability mean a customer can arrive believing they bought a security outcome and find they bought part of it. And a Palo Alto running permissive rules with decryption disabled — which is common, because decryption is politically and technically hard — is an expensive appliance delivering a fraction of what it can do.

From the operations side

Ask any customer considering Palo Alto one question before the quote: will you enable TLS decryption? If the answer is no, or "eventually", a large part of the premium they are about to pay buys inspection of traffic they will never inspect. That conversation is uncomfortable and it is the single most useful thing an advising MSP can raise.

What they actually cost to operate

This is the section vendor material cannot write, and it is usually the part that determines whether the customer is happy in year three.

Upgrade risk is the dominant operational cost on both

On either platform, the recurring source of unplanned work is firmware. Neither vendor has a spotless record — both have shipped releases that introduced regressions, and both have shipped critical, actively exploited vulnerabilities in their remote-access components within the last few years. What separates a well-run estate from a badly run one is not the vendor; it is whether somebody owns a patch cadence, tests before production, and keeps a rollback path.

If your customer has no answer to "who upgrades this and when", the platform choice is the less urgent problem.

Skills cost differs more than license cost

Palo Alto expertise is scarcer and priced accordingly. FortiGate skills are more widely available, but the surface area is larger, so competence takes a similar amount of time to develop — it is simply cheaper to hire. For an MSP, the practical question is not which platform is easier but whether the coverage rota has enough depth on the chosen platform to handle an incident at 3am on a Sunday without escalating to one specific person who may be asleep, on leave, or gone.

Ticket volume follows configuration quality, not brand

Across the estates we run, the variance in operational load between two customers on the same platform is far wider than the variance between the two platforms. A tuned FortiGate with sensible profiles and a maintained rule base is quiet. An untuned one generates steady noise. The same is true of Palo Alto. Anyone claiming one brand is categorically lower-maintenance is describing their sample, not the products.

A decision path you can run in a meeting

Six questions, in order. The first one that produces a clear answer usually settles it.

  1. Will they enable TLS decryption? If no, the security-depth argument for the premium platform weakens considerably, and sizing changes too.
  2. How many sites, and does WAN path selection matter? A branch-heavy estate that needs SD-WAN pushes hard toward the platform that does not license it separately.
  3. Who operates it, and at what hours? No dedicated security function and no 24/7 coverage means favour the platform their team can actually run — or resolve the coverage gap before the platform question.
  4. What is the compliance and investigation obligation? A real forensic requirement justifies paying for log depth and investigation tooling.
  5. What is the five-year budget, including renewals? Not the capital budget for the appliance. The five-year total, with the year-three renewal in it.
  6. What is already there, and is it working? If the incumbent estate is competently run, the burden of proof for migrating is high and should be treated that way.

If the answers pull in different directions, that is a genuine result, not a failure of the process. It usually means the platform is not the binding constraint — operating capacity is.

You advise. We operate.

Bonsai Security runs firewalls that MSPs have already sold, under the MSP's own brand, on Fortinet, Palo Alto and six other platforms. Which one your customer picks changes nothing about our side — which is exactly why the comparison above has no thumb on the scale. If the honest answer to question three was "nobody, really", that is the part we can fix.

Become a partner

Common questions

The questions customers actually ask, answered the way we would answer them if you put us on the call. Something missing? Tell us and we will add it.

Which is better, FortiGate or Palo Alto?

Neither, in the abstract. Palo Alto suits customers with a dedicated security function who will use consistent application-based policy and are willing to pay for it. FortiGate suits distributed, branch-heavy or cost-sensitive estates, especially where SD-WAN and security belong on the same appliance. The decision is usually settled by the operating model rather than the feature list.

Is Palo Alto worth the additional cost over FortiGate?

It is worth it when the customer will actually operate it well: consistent policy, decryption enabled, alerts acted on. A Palo Alto run with permissive rules and no decryption delivers less security than a properly configured FortiGate at a fraction of the price. The premium buys capability, not outcomes.

How much more expensive is Palo Alto than FortiGate?

There is no reliable general figure, and any page quoting one is guessing. Real cost depends on appliance sizing, which subscription bundle is attached, support tier, contract length and the discount the reseller negotiates. Compare quotes for equivalent inspection throughput over the same term, not list prices for models with similar-sounding names.

Does FortiGate include features that require separate Palo Alto licenses?

SD-WAN is the clearest example: it is part of FortiOS at no additional subscription, whereas Palo Alto licenses SD-WAN separately. Advanced remote-access capabilities such as endpoint posture checks also sit behind a subscription. The comparison works in both directions, so build the matrix from current ordering guides rather than assuming either vendor bundles more.

Which firewall has better real-world throughput?

Not answerable from headline datasheet numbers, because the vendors measure them differently. Firewall throughput is typically measured with large packets and no inspection; threat protection throughput uses a mixed traffic profile with security services enabled, and it is often a small fraction of the headline. Compare threat protection throughput with decryption accounted for, and size against the customer's encrypted traffic volume.

How difficult is migrating from Palo Alto to FortiGate?

Conversion tools translate addresses, services, NAT and most rules, but they cannot translate policy intent between two different policy models. Expect meaningful manual cleanup, particularly around application-based rules, and plan validation time rather than assuming a one-to-one conversion. Choosing FortiGate policy mode instead of profile mode keeps the result structurally closer to the PAN-OS original.