Fortinet vs Sophos vs Palo Alto vs SonicWall vs Juniper
All five make firewalls that protect a business well when they are configured properly and kept up to date. They differ in where they put their effort.
Fortinet
FortiGate units run on Fortinet's own security processors, which gives high throughput for the size and price. The range is the widest of the five, SD-WAN is included, and the same operating system runs on every model. The interface offers a great deal, so there is more to learn.
Choose Fortinet when throughput for the money matters, or when you want firewalls, switches and Wi-Fi from one vendor.
Sophos
Sophos XGS firewalls are managed from Sophos Central, alongside Sophos endpoint protection, and the two share information: an infected PC can be cut off by the firewall automatically. The interface is among the easier ones to work with.
Choose Sophos when you already use, or plan to use, Sophos on your PCs and servers, or when a small IT team wants one console.
Palo Alto Networks
Palo Alto Networks built its firewall around identifying applications and users, and its policy model is consistent from the smallest unit to the largest. Its threat research and subscriptions are highly regarded. Hardware and subscriptions tend to cost more than the others.
Choose Palo Alto Networks when security policy is the priority and the budget allows, or when an auditor or parent company asks for it.
SonicWall
SonicWall concentrates on small and mid-size businesses and branch networks. The TZ series is compact and available with wireless and PoE built in, and licensing is simple to follow.
Choose SonicWall for small offices and multi-branch businesses that want capable protection without enterprise complexity.
Juniper
Juniper SRX firewalls run Junos, with routing as strong as the firewalling. They are common in service-provider and large enterprise networks, and in organisations whose engineers already know Junos.
Choose Juniper when the firewall also has to be a serious router, or when the rest of the network is Juniper.
How we help you decide
We supply all five, so we have no reason to push one. We start from your line speed, your sites, your existing systems and your budget, and recommend the model that fits.
Common questions
Which firewall brand is best?
There is no single best. Each of the five is a sound choice, and a well-configured, up-to-date unit of any brand protects better than a neglected unit of another.
Can I compare throughput figures between brands?
Only roughly. Each manufacturer tests with its own traffic mix, so use the figures to shortlist and leave headroom.
Which brand is cheapest to run?
It depends on the model and the licence bundle. Compare the total for hardware and licence over three or five years. We quote that total for any model on this site.