TrustRadius: an HG Insights company

Cisco IPS Sensor (Discontinued) vs. Fortinet FortiGate vs. Juniper SRX Series Firewalls

Save this comparison

Save this comparison

Add Product

Recommended Comparisons

    Overview
    ProductRatingMost Used ByProduct SummaryStarting Price

    Cisco IPS Sensor (Discontinued)

    Score8.9 out of 10
    N/ACisco IPS Sensors have reached EOL, and EOS.N/A

    FortiGate

    Score8.5 out of 10
    N/AFortiNet FortiGate is a firewall option with high integrability. It offers a variety of deployment options and next-gen firewall capabilities, including integration with IaaS cloud platforms and public cloud environments.N/A

    Juniper SRX Series Firewalls

    Score7.3 out of 10
    N/AJuniper SRX is a firewall offering. It provides a variety of modular features, scaled for enterprise-level use, based on a 3-in-1 OS that enables routing, switching, and security in each product.N/A
    Pricing
    Cisco IPS Sensor (Discontinued)FortiGateJuniper SRX Series Firewalls
    Editions & Modules
    No answers on this topic
    No answers on this topic
    No answers on this topic
    Offerings
    Pricing Offerings
    Cisco IPS Sensor (Discontinued)FortiGateJuniper SRX Series Firewalls
    Free Trial
    NoYesNo
    Free/Freemium Version
    NoNoNo
    Premium Consulting/Integration Services
    NoNoNo
    Entry-level Setup FeeNo setup feeNo setup feeNo setup fee
    Additional DetailsFortiGate pricing starts at $250 for home office use, up to $300,000 for large enterprise appliances. Must contact sales team for pricing.
    More Pricing Information
    Community Pulse
    Cisco IPS Sensor (Discontinued)FortiGateJuniper SRX Series Firewalls
    Considered Multiple Products
    Cisco
    No answer on this topic
    Fortinet
    Chose FortiGate
    Better than Juniper, and CheckPoint. Not as good as the Palo Alto although it cost less so I would still make the choice to go with Fortinet
    Incentivized
    Chose FortiGate
    [Fortinet] Fortigate saved us with raising our availability a lot.
    Incentivized
    Chose FortiGate
    Fortinet code configuration is a little bit cleaner, it has sub-modules for different components. One of the nice things about Juniper and pitfalls is that you drop out to the FreeBSD command line if there are any issues. Fortinet and Cisco do not have that capability. …
    Incentivized
    Chose FortiGate
    Same functionality (in some cases even greater) at a fraction of the cost, with a much more intuitive management interface and a constantly evolving OS that adapts to the needs of the clients.
    Incentivized
    Chose FortiGate
    We considered/evaluated Juniper SRX and Palo Alto Networks products to replace FortiGates. But they either had much fewer features or were far more expensive than FortiGate.
    Incentivized
    Hewlett Packard Enterprise (HPE)
    Chose Juniper SRX Series Firewalls
    The SRX Stacks up well to the ASA and Sonic wall but I feel the features provided by FortiGate/Palo Alto and Checkpoint far exceed that of the competitors.
    Incentivized
    Chose Juniper SRX Series Firewalls
    Juniper SRX stands tall compared to all these products for Large Service Provider Networks, where traffic volume is larger. Also, cost comparison with SRX's few other products can also be another contributing factor while selecting this. As well as Juniper Routers, Switches, …
    Incentivized
    Chose Juniper SRX Series Firewalls
    The juniper is very versatile router/firewall box. it is an excellent router/edge device with zone based firewall.

    Incentivized
    Key User Insights
    Would buy again
    No answers on this topic
    100%
    Would buy again
    49 Answers
    100%
    Would buy again
    5 Answers
    Delivers good value for the price
    No answers on this topic
    100%
    Delivers good value for the price
    48 Answers
    100%
    Delivers good value for the price
    5 Answers
    Happy with the feature set
    No answers on this topic
    100%
    Happy with the feature set
    49 Answers
    100%
    Happy with the feature set
    5 Answers
    Lived up to sales and marketing promises
    No answers on this topic
    100%
    Lived up to sales and marketing promises
    44 Answers
    100%
    Lived up to sales and marketing promises
    5 Answers
    Implementation went as expected
    No answers on this topic
    98%
    Implementation went as expected
    47 Answers
    100%
    Implementation went as expected
    5 Answers
    Features
    Cisco IPS Sensor (Discontinued)FortiGateJuniper SRX Series Firewalls
    Firewall
    Comparison of Firewall features of Cisco IPS Sensor (Discontinued) and Fortinet FortiGate and Juniper SRX Series Firewalls
    Feature
    Cisco IPS Sensor (Discontinued)
    -
    Ratings
    Fortinet FortiGate
    8.7
    53 Ratings
    1% above category average
    Juniper SRX Series Firewalls
    8.7
    5 Ratings
    1% above category average
    Identification Technologies00 Ratings8.951 Ratings9.03 Ratings
    Visualization Tools00 Ratings8.351 Ratings7.03 Ratings
    Content Inspection00 Ratings8.852 Ratings8.04 Ratings
    Policy-based Controls00 Ratings8.953 Ratings10.04 Ratings
    Active Directory and LDAP00 Ratings8.750 Ratings8.03 Ratings
    Firewall Management Console00 Ratings7.752 Ratings7.05 Ratings
    Reporting and Logging00 Ratings8.353 Ratings8.05 Ratings
    VPN00 Ratings9.152 Ratings10.04 Ratings
    High Availability00 Ratings9.348 Ratings10.05 Ratings
    Stateful Inspection00 Ratings9.251 Ratings10.04 Ratings
    Proxy Server00 Ratings8.539 Ratings9.03 Ratings
    Best Alternatives
    Cisco IPS Sensor (Discontinued)FortiGateJuniper SRX Series Firewalls
    Small Businesses
    No answers on this topic
    SonicWall NSA Series
    Score8.4 out of 10
    SonicWall NSA Series
    Score8.4 out of 10
    Medium-sized Companies
    Snort
    Score9 out of 10
    Barracuda CloudGen Firewall
    Score9.6 out of 10
    Barracuda CloudGen Firewall
    Score9.6 out of 10
    Enterprises
    Proofpoint Advanced Threat Protection
    Score8.4 out of 10
    Cisco Adaptive Security Appliance (ASA) Software
    Score9 out of 10
    Cisco Adaptive Security Appliance (ASA) Software
    Score9 out of 10
    All AlternativesView all alternativesView all alternativesView all alternatives
    User Ratings
    Cisco IPS Sensor (Discontinued)FortiGateJuniper SRX Series Firewalls
    Likelihood to Recommend
    9.0
    (1 ratings)
    8.7
    (79 ratings)
    8.0
    (8 ratings)
    Likelihood to Renew
    -
    (0 ratings)
    7.0
    (5 ratings)
    8.0
    (2 ratings)
    Usability
    -
    (0 ratings)
    8.7
    (21 ratings)
    -
    (0 ratings)
    Availability
    -
    (0 ratings)
    8.0
    (3 ratings)
    -
    (0 ratings)
    Performance
    -
    (0 ratings)
    9.0
    (2 ratings)
    -
    (0 ratings)
    Support Rating
    9.0
    (1 ratings)
    9.0
    (27 ratings)
    6.4
    (3 ratings)
    In-Person Training
    -
    (0 ratings)
    10.0
    (1 ratings)
    -
    (0 ratings)
    Implementation Rating
    -
    (0 ratings)
    5.0
    (5 ratings)
    -
    (0 ratings)
    Configurability
    -
    (0 ratings)
    7.0
    (2 ratings)
    -
    (0 ratings)
    Contract Terms and Pricing Model
    -
    (0 ratings)
    8.0
    (1 ratings)
    -
    (0 ratings)
    Ease of integration
    -
    (0 ratings)
    7.0
    (2 ratings)
    -
    (0 ratings)
    Product Scalability
    -
    (0 ratings)
    7.0
    (3 ratings)
    -
    (0 ratings)
    Vendor post-sale
    -
    (0 ratings)
    8.0
    (2 ratings)
    -
    (0 ratings)
    Vendor pre-sale
    -
    (0 ratings)
    8.0
    (2 ratings)
    -
    (0 ratings)
    User Testimonials
    Cisco IPS Sensor (Discontinued)FortiGateJuniper SRX Series Firewalls
    Likelihood to Recommend
    Cisco
    IPS sensors are more suited for companies that do not have visibility into their network with third-party analyzing tools. Scenarios would be to place IPS sensors at the perimeter firewalls mainly. IPS sensors are less appropriate for companies that have third-party analyzing tools that will mitigate vulnerabilities and malicious traffic and activities already.
    Incentivized
    Read full review
    Fortinet
    Fortinet FortiGate addressed an immediate security issue we had a few years ago. The device gave us a much clearer picture of the activities on our network and also more importantly, increased our awareness of threats from the internet as a whole. Fortinet FortiGate helps us to mitigate these threats with regular signature updates from Fortiguard labs, identifying certain characteristics which, once recognised by Fortinet FortiGate, can be harnessed to deploy powerful 'playbooks'.
    Incentivized
    Read full review
    Hewlett Packard Enterprise (HPE)
    SRXs seem to be well suited at the enterprise level for plain routers, firewalls, and IDP/IDS. They work well on MPLS and Ethernet, including Internet. I have 3 SRXs also performing edge duty, with 2 in a high availability (HA) cluster. The Juniper line of SRXs provides a good range of scaling from small business to extremely large enterprise. Wire speed is a common comparison factor and Juniper shines in that area.
    Incentivized
    Read full review
    Pros
    Cisco
    • Identifies and blocks malicious traffic.
    • Detects unwanted traffic and allows your company to be proactive, let alone reactive.
    • Comprehensive Threat protection allows companies to adjust thresholds and policies at will.
    Incentivized
    Read full review
    Fortinet
    • SD-WAN - Load balancing of Internet traffic is a USP of Fortigate and makes it stand tall in the competition. Be it 3 or more Internet Links, multiple Subnets/segments of users to distribute and bandwidth load balancing for links and users. SLA based monitoring of Internet Links / MPLS links, makes it even better to choose the links on the basis of performance (Latency, packet loss, Jitter etc).
    • SSL VPN configuration - As we all have WFH force (to some extend or all employee) during Covid-19, it is impossible to plan BCP without having a SSL VPN. In Fortigate, the SSL VPN configuration is very easy with the help of wizard. The deep CLI-level debugging is also very helpful in troubleshooting. Type of tunnel can be easily configured - Full Tunnel or Split Tunnel for SSL.
    • Explicit Proxy - This is also a great feature to shape and re-route the traffic, configuring the Proxy on the Firewall itself. We are using this feature in Pilot for now, and planned to rollout in few weeks looking at the success rate of the POC.
    Read full review
    Hewlett Packard Enterprise (HPE)
    • Edge Device (Tunneling & Routing)
    • Routing Instances
    • Zone Based Firewall
    • L3 Gateway/Vlan termination
    • DHCP Server & DHCP Relay
    • Good support community & Good available documentation
    • Good support by the Vendor
    Incentivized
    Read full review
    Cons
    Cisco
    • The web GUI is somewhat slow.
    • Sometimes difficult to adjust policies.
    • Fail open feature may not work properly all the time.
    Incentivized
    Read full review
    Fortinet
    • Documentation is missing a great deal of detail and assumes the customer and just guess and fill in the blanks themselves
    • Fortinet has lots and lots of video guides on topics that only a small percentage of customers would ever need
    • The documentation and video guides do not get updated so most is only relevant to older software versions
    Incentivized
    Read full review
    Hewlett Packard Enterprise (HPE)
    • My only real criticism of the product is that it's hard to figure out how to upgrade the firmware from the CLI via TFTP via the docs, but it works great once you get it sorted.
    Incentivized
    Read full review
    Likelihood to Renew
    Cisco
    No answers on this topic
    Fortinet
    Fortinet's products have kept improving with new software releases and they continue to deliver great value. Their support is also very good. I believe that as a small enterprise, their products have given us competitive advantage delivering features and functionality that enable us to innovate and do things better. They also continue to be a leader in the markets they serve.
    Incentivized
    Read full review
    Hewlett Packard Enterprise (HPE)
    No answers on this topic
    Usability
    Cisco
    No answers on this topic
    Fortinet
    The firewall runs very well, firmware updates are fairly quick but you must follow the upgrade path. Neglecting this step will cause a lot of pain. If you decide to go with Fortinet FortiGate switches and/or access points, they can be managed within the firewall which is great. We're also using the FortiAnalyzer which easily plugs into the firewall for any reporting you may require.
    Incentivized
    Read full review
    Hewlett Packard Enterprise (HPE)
    No answers on this topic
    Reliability and Availability
    Cisco
    No answers on this topic
    Fortinet
    We had didn't any hardware failures at our two main office locations and upgraded our units last year after using them for about 5-6 years
    Incentivized
    Read full review
    Hewlett Packard Enterprise (HPE)
    No answers on this topic
    Performance
    Cisco
    No answers on this topic
    Fortinet
    Good performance and really good integration. We have integration with Microsoft AD.
    Incentivized
    Read full review
    Hewlett Packard Enterprise (HPE)
    No answers on this topic
    Support Rating
    Cisco
    Cisco TAC has been great at helping with configurations and issues that may arise
    Incentivized
    Read full review
    Fortinet
    The Support team at Fortinet is excellent. They can not only help you configure the device for what you are trying to do, they offer suggestions on improving rules, and troubleshooting issues. Their response time is fast, ensuring you are up and running immediately with no questions asked. We had a hard drive failure in one of our Fortinet Fortigate appliances. The tech answered immediately, and started rebuilding the drive after some preliminary investigations. After rebuilding, there were still errors and issues, so they dispatched a brand new Fortinet Fortigate appliance. The tech then backed up the configurations for when the new device came in, which showed up in a few hours. A restore of the configuration took less than a minute, and there were no more errors or issues.
    Incentivized
    Read full review
    Hewlett Packard Enterprise (HPE)
    This is the one area where I have a beef with Juniper. When I called into Cisco TAC, 90% of the time, the first person I spoke with was able to resolve my issue. With Juniper TAC, 90% of the time, the first person I speak with is not able to resolve my issue, seems to almost be reading from a script, and must escalate my ticket. All of which takes time.
    Incentivized
    Read full review
    In-Person Training
    Cisco
    No answers on this topic
    Fortinet
    I received it a couple years afters use it and it was just to confirm my knowledge about the tool.
    Incentivized
    Read full review
    Hewlett Packard Enterprise (HPE)
    No answers on this topic
    Implementation Rating
    Cisco
    No answers on this topic
    Fortinet
    Make sure that you have the most current version of FortiOS. Make sure all Fortigates are on the same version
    Incentivized
    Read full review
    Hewlett Packard Enterprise (HPE)
    No answers on this topic
    Alternatives Considered
    Cisco
    IPS sensors provides the necessary network visibility my company needs to satisfy its security appetite. By doing so, we have been able to stay compliant and up to date with today's network security requirements and procedures. We are able to be proactive with vulnerabilities and reactive to malicious traffic and intrusions in our day to day operations.
    Incentivized
    Read full review
    Fortinet
    [Fortinet] FortiGate is not only cost effective but it gives the comprehensive security against the APT attacks and gives the complete traffic visibility and granular control. You can easily create the VDOMs (Virtual firewall) within a Fortigate firewall and customize the dashboard as per your requirement if you have multiple VDOMs within a single firewall.
    Incentivized
    Read full review
    Hewlett Packard Enterprise (HPE)
    Juniper SRX stands tall compared to all these products for Large Service Provider Networks, where traffic volume is larger. Also, cost comparison with SRX's few other products can also be another contributing factor while selecting this. As well as Juniper Routers, Switches, and multiple products from the same vendor to maintain one single vendor environment. As well as Juniper Support is also really good.
    Read full review
    Contract Terms and Pricing Model
    Cisco
    No answers on this topic
    Fortinet
    No changes needed to terms and conditions.
    Incentivized
    Read full review
    Hewlett Packard Enterprise (HPE)
    No answers on this topic
    Scalability
    Cisco
    No answers on this topic
    Fortinet
    My environments are pretty small (less than 100 users per location) so no issues here.
    Incentivized
    Read full review
    Hewlett Packard Enterprise (HPE)
    No answers on this topic
    Return on Investment
    Cisco
    • Provided less need to purchase third party analyzing tools.
    • Needed more dedicated staff to build/review/and maintain policies and such.
    • Answers companies need for network security.
    Incentivized
    Read full review
    Fortinet
    • The pricing given to us for our firewall was well within what we were already spending for other vendors solutions and had the added value of eliminating a separate expense for a dedicated web filtering appliance.
    • We have also adopted Fortinet's security fabric approach and thus changed vendors for our switch and AP devices. These devices have come at reduced prices as compared to another previous vendor we were using, particularly in relation to ongoing annual maintenance costs.
    Incentivized
    Read full review
    Hewlett Packard Enterprise (HPE)
    • It is a workhorse for our field operations. It provides the last touch for an ISP to the customer. The customer has no view of the device, but with the repeatability of the device, they do not need to.
    • The ability to roll out a dynamic routing protocol attached to a security zone allows elasticity to the environment that supports growth.
    • VLAN support on the inside interfaces allow this to be the only device in some smaller deployments we install these in.
    Incentivized
    Read full review
    ScreenShots