Home Resources FortiGate vs Palo Alto

FortiGate vs Palo Alto: what to tell your customer

Most comparisons compare the wrong numbers. This one is written for the MSP advising the customer, by a team that operates both platforms under other companies' brands and has no commercial stake in the outcome.

Checked 8 August 2026 12 minute read Vendor-neutral

The short answer

Both platforms secure a network competently. Palo Alto suits an organization with a dedicated security function that will apply consistent application-based policy and enable decryption. FortiGate suits distributed, branch-heavy, or cost-sensitive estates, particularly where SD-WAN and security belong on the same appliance.

The deciding factor is whether the platform will be operated properly after go-live. A well-run FortiGate outperforms a neglected Palo Alto, and the reverse holds equally.

How to read any comparison, including this one

Six distinctions come before the side-by-side. Each marks a place where vendor material, reseller decks, and most comparison articles compare things that are not comparable. Where a customer arrives with a printout, these are the six questions to ask about it.

1. Firewall throughput and threat protection throughput measure different things

Both vendors publish several throughput figures per model, and they are measured under conditions that have almost nothing in common. A headline "firewall throughput" number is generally produced with large packets and inspection disabled. A "threat protection" or NGFW number is produced with a mixed traffic profile and security services running, and it is routinely a fraction of the headline.

Comparing one vendor's headline against the other's inspection figure is the most common error in this category. It explains most cases where an appliance that looked oversized on paper saturates in production.

Read the footnotes on the datasheet. They state the test conditions, and the test conditions are the comparison.

What each published figure measures, and the sizing method that produces a defensible model choice →

2. List price and five-year cost diverge

Appliance list price is the smallest and least stable input. The number your customer pays over five years is determined by the subscription attached to the appliance, the support tier, renewal pricing from year three, and the discount negotiated on the initial order. Two quotes with the same appliance price can diverge substantially by year five.

Request a five-year total from both vendors, on the same term, including renewals and support. A reseller's willingness to produce one is itself informative.

The five-year cost model, and the ten questions that make two quotes comparable →

3. An available feature still needs a license

Both platforms will show a capability in the interface that is inert without the matching subscription. This applies in both directions and it changes real quotes. SD-WAN is the clearest case. It is part of FortiOS with no additional subscription, while Palo Alto licenses SD-WAN separately. Advanced remote-access capability such as endpoint posture checking sits behind a subscription on both platforms.

Build the licensing matrix from current ordering guides at quote time. Bundle names and contents change more often than the hardware does.

The capability-level licensing matrix, and what stops working when a subscription lapses →

4. Detection and enforcement are separate

This is the most misunderstood technical difference between the two platforms. It matters more than the marketing comparison of App-ID against Application Control.

Palo Alto identifies the application on all traffic as a matter of architecture. Applications are first-class match criteria in the security policy. On FortiGate in its default profile mode, application control is a security profile attached to a policy. The policy matches on addresses, ports, and services, and the profile inspects what passes.

FortiGate's policy mode changes this. Applications and URL categories become matching criteria in the policy itself, which is structurally much closer to the PAN-OS model.

Both platforms express application-aware policy. They express it differently enough that a rule set resists translation between them, which is why this distinction returns as the hardest part of any migration.

App-ID against application control in full, and the misconfigurations each platform invites →

5. Marketing claims describe the platform running well

Every vendor's material describes the platform running well. The material stops there. It leaves out what happens at 2am eighteen months later, once the engineer who designed the policy has left, the rule base has accumulated unexplained exceptions, and a firmware upgrade is overdue because the last one caused an outage.

Managed firewall estates succeed or fail in that gap. A feature comparison cannot show it.

6. Selection and migration are different decisions

"Which platform is better" and "should we move from the one we have" are different questions with different answers. A migration carries conversion effort, a validation burden, a period of elevated risk, and the cost of retraining whoever operates it. A platform that would win a greenfield evaluation can still be the wrong choice for an estate already running competently on the alternative.

What a conversion tool cannot do, and how to prove policy intent survived →

From the operations side

The most expensive firewall decisions we see involve the right platform. They are appliances sized against the headline throughput figure, deployments missing the subscription that activates the capability the customer was sold, and migrations run on a timeline that left no room to validate the converted policy.

Side by side

Structural differences rather than a scorecard. Every row describes a trade-off, which is why no column is highlighted.

Structural comparison of FortiGate and Palo Alto Networks firewalls
Dimension FortiGate Palo Alto
Acceleration approach Purpose-built ASICs for network and content processing Single-pass architecture with dedicated function-specific hardware
Application identification Security profile in default profile mode; policy match criterion in policy mode Identified on all traffic; a first-class policy match criterion
SD-WAN licensing Included in the operating system Separate subscription
Remote access client FortiClient; posture and ZTNA require an EMS license GlobalProtect; posture checking requires a subscription
Malware analysis FortiSandbox, on-premises or cloud WildFire, cloud-delivered
Central management FortiManager, appliance or virtual Panorama, appliance or virtual
Subscription structure Bundled tiers covering most services together Individually named subscriptions per capability
Headline throughput basis Large-packet test with inspection disabled Application identification enabled on the headline figure
Feature surface Broad; switching, wireless, WAN and security in one OS Narrower and more opinionated; security-focused
Automation REST API, Terraform provider, Ansible collection REST and XML API, Terraform provider, Ansible collection
Migration tooling FortiConverter Vendor migration tooling; confirm current product before planning
Skills availability Larger installed base in the mid-market and channel Deeper specialization, smaller pool, higher rates
Typical strong fit Distributed, branch-heavy, cost-sensitive, mixed WAN Security-led estates with staff to operate them
Typical weak fit Customers who will leave profiles at defaults and never tune them Customers without the budget or headcount to use what they bought

Structural characteristics compiled from current vendor product and ordering documentation (Fortinet, Palo Alto Networks), checked 31 July 2026. The fit and skills rows are our judgement from operating both platforms rather than vendor claims. Licensing structures change. Re-check against a live quote before advising a customer.

Where FortiGate genuinely wins

Branch and SD-WAN economics. Routing, WAN path selection, and security converge on one appliance with no additional subscription. This lowers the per-site cost of a distributed estate substantially. For a customer with sixty sites it is frequently the whole decision.

Capability per dollar. The bundled subscription model puts a broad set of security services on the appliance for one line item. This matches how a mid-market customer buys when they want reasonable coverage across many functions rather than depth in a few.

Breadth of the ecosystem. Switching, access points, endpoint, and management under one vendor is simpler to procure and support than assembling the equivalent from several.

The weakness. That breadth is also the risk. A FortiGate has more places where a setting can be wrong, and the default profile-mode model allows a deployment that inspects far less than the customer believes. We regularly encounter security profiles left at defaults, application control attached to nothing meaningful, and SSL inspection disabled. The appliance reports itself as healthy throughout.

Where Palo Alto genuinely wins

Policy consistency. Application identity is applied to all traffic as a matter of architecture rather than through a profile someone has to remember to attach. The resulting rule base means what it appears to mean. Across years and staff turnover, that is worth more than most feature comparisons credit.

Investigation quality. The log detail and the tooling around it are strong when a customer needs to establish what happened rather than what was blocked. For regulated customers and anyone carrying an incident response obligation, this is a material difference.

A narrower set of options. Fewer ways to configure a thing means fewer ways to configure it wrong. A Palo Alto configured by an average engineer tends to land closer to the intended design than a FortiGate configured by the same engineer.

The weakness. Cost is the obvious one. The more significant one is that the platform assumes competent operation and degrades sharply without it. Separate subscriptions per capability mean a customer can arrive believing they bought a security outcome and find they bought part of it. A Palo Alto running permissive rules with decryption disabled is an expensive appliance delivering a fraction of its capability, and that configuration is common, because decryption is politically and technically hard.

From the operations side

Ask any customer considering Palo Alto one question before the quote. Will you enable TLS decryption? Where the answer is no, or "eventually", a large part of the premium buys inspection of traffic that will stay uninspected. This is the most useful question an advising MSP can raise.

What they actually cost to operate

Vendor material cannot cover this section. It usually determines whether the customer is satisfied in year three.

Whichever platform is chosen, somebody has to carry the pager for it. What that costs in headcount is set out on the build or buy page, and it is frequently larger than the difference between these two vendors.

Upgrade risk is the dominant operational cost on both

On either platform, the recurring source of unplanned work is firmware. Both vendors have shipped releases that introduced regressions, and both have shipped critical, actively exploited vulnerabilities in their remote-access components within the last few years.

A well-run estate is separated from a badly run one by process rather than by vendor. Somebody owns a patch cadence, tests before production, and keeps a rollback path. Where a customer has no answer to "who upgrades this and when", that gap outranks the platform choice.

Skills cost differs more than license cost

Palo Alto expertise is scarcer and priced accordingly. FortiGate skills are more widely available and cheaper to hire, though the larger surface area means competence takes a similar amount of time to develop.

For an MSP the practical question is depth of cover. A week contains 168 hours and a full-time schedule covers 40, so one seat staffed around the clock requires 4.2 full-time engineers before any allowance for leave or training. The question is whether the rota carries that depth on the chosen platform, rather than which platform is easier.

Ticket volume follows configuration quality

Across the estates we run, operational load varies more between two customers on the same platform than it does between the two platforms. A tuned FortiGate with sensible profiles and a maintained rule base is quiet. An untuned one generates steady noise. Palo Alto behaves the same way. A claim that one brand is categorically lower-maintenance describes the sample rather than the products.

A decision path you can run in a meeting

Six questions, in order. The first one that produces a clear answer usually settles the decision.

  1. Will they enable TLS decryption? A negative answer weakens the security-depth argument for the premium platform considerably and changes the sizing.
  2. How many sites, and does WAN path selection matter? A branch-heavy estate requiring SD-WAN points firmly toward the platform that includes it.
  3. Who operates it, and at what hours? A customer without a dedicated security function or 24/7 coverage should favor the platform their team can run, or resolve the coverage gap before selecting a platform.
  4. What is the compliance and investigation obligation? A genuine forensic requirement justifies paying for log depth and investigation tooling.
  5. What is the five-year budget, including renewals? The five-year total with year-three renewal included, rather than the capital budget for the appliance.
  6. What is already there, and is it working? A competently run incumbent estate sets a high burden of proof for migrating.

Answers that pull in different directions are a genuine result. They usually indicate that operating capacity is the binding constraint rather than the platform.

You advise. We operate.

We run firewalls that MSPs have already sold, under the MSP's own brand, on Fortinet, Palo Alto and six other platforms. Our side of the arrangement stays the same whichever platform your customer selects, which is why the comparison above has no thumb on the scale. Where question three has no good answer, that is the part we can supply.

Become a partner

Common questions

The questions customers actually ask, answered the way we would answer them if you put us on the call. Something missing? Tell us and we will add it.

Which is better, FortiGate or Palo Alto?

Each suits a different customer. Palo Alto suits organizations with a dedicated security function that will apply consistent application-based policy and pay for it. FortiGate suits distributed, branch-heavy, or cost-sensitive estates, particularly where SD-WAN and security belong on the same appliance. The operating model usually settles the decision ahead of the feature list.

Is Palo Alto worth the additional cost over FortiGate?

It is worth it where the customer will operate it well, with consistent policy, decryption enabled, and alerts acted on. A Palo Alto running permissive rules without decryption delivers less security than a properly configured FortiGate at a fraction of the price. The premium buys capability, and the customer supplies the outcome.

How much more expensive is Palo Alto than FortiGate?

No published figure answers this. Real cost depends on appliance sizing, the subscription attached, the support tier, the contract length, and the discount the reseller negotiates. Compare quotes for equivalent inspection throughput over the same term rather than list prices for models with similar-sounding names.

Does FortiGate include features that require separate Palo Alto licenses?

SD-WAN is the clearest example. It is part of FortiOS at no additional subscription, while Palo Alto licenses SD-WAN separately. Advanced remote-access capabilities such as endpoint posture checks sit behind a subscription on both platforms. The comparison runs in both directions, so build the matrix from current ordering guides.

Which firewall has better real-world throughput?

Headline datasheet numbers cannot answer this, because the vendors measure them differently. Firewall throughput is typically measured with large packets and no inspection. Threat protection throughput uses a mixed traffic profile with security services enabled, and it is often a small fraction of the headline. Compare threat protection throughput with decryption accounted for, and size against the customer's encrypted traffic volume.

How difficult is migrating from Palo Alto to FortiGate?

Conversion tools translate addresses, services, NAT, and most rules. Policy intent resists translation between two different policy models. Expect meaningful manual cleanup around application-based rules, and plan validation time rather than assuming a one-to-one conversion. Choosing FortiGate policy mode over profile mode keeps the result structurally closer to the PAN-OS original.