FortiNet FortiGate is a firewall option with high integrability. It offers a variety of deployment options and next-gen firewall capabilities, including integration with IaaS cloud platforms and public cloud environments.
N/A
SonicWall TZ
Score 8.3 out of 10
N/A
SonicWall TZ is an entry to mid-tier NGFW for small to mid-sized companies. It is a Unified Threat Management solution, with additional native decryption and deep-packet inspection capabilities.
We choose Fortinet FortiGate because it provides AI-powered security services and offers more advanced threat protection and response capabilities than SonicWall TZ
Some of them are great products, but overall Fortinet gives more for less. Also it is really easy to manage for almost everyone. As you should have at least a double layer, with different manufacturers, this is a great choice
I
stick with this program because of many reasons like it is extremely robust and
scalable, as well as simple to set up. Protecting an organization's data is one
The cost was comparable to the SonicWall we were looking at but feature wise, they are in a different league. The Fortigate offered far more next generation firewall features and they were bundled in with the license we chose. The interface is much easier to use and we spend …
Ongoing costs and licensing options - the FortiGate product line comes out a winner every time. We especially like the granularity and licensing options compared to something like Meraki that is mostly "all or nothing" or the SonicWall which is less granular and just not as …
Verified User
Administrator
Chose Fortinet FortiGate
Similar prices, but the Fortinet had a few more features and a better VPN solution for our situation.
FortiGate has a strong offering at a very competitive price point. I like that with your subscription you get access to all of the pieces, and that features aren't arbitrarily turned off unless you buy a specific license or bundle. For what you get for the price, it's really …
SonicWall TZ was a no brainer to choose over FortiGate or pfSense. We had used FortiGate units in the past and, in our experience, the interface is terrible, both on the device and the cloud side. There are constant updates that require you to jump through hoops to upgrade and …
SonicWall TZ is good at some things but overall I would pick Fortinet and UDM-Pro appliances most of the time and their VPN solution does not require paid license. Interface more modern and intuitive. Overall, better bang for your buck.
We like it is a small, portable, and has many features. I have confidence in the brand a long time. Support was also a differential to make the decision.
Costs, features and ease of use were the determining factors. The UI alone outweighs the CLI from the ASA and SRX, features were easier to understand and licenses were more easily obtained.
FortiGate, from Fortinet, and SonicWall TZ are next-gen firewalls (NGFWs). They are competing solutions, however SonicWall TZ aims more at smaller companies as an entry level NGFW, while FortiGate customers include large enterprises. Both vendors are network security specialists and provide related products and services besides their firewalls; see the respective SonicWall and Fortinet vendor pages. Fortinet will tend to be deployed at larger companies and enterprise vis-a-vis SonicWall, with a correspondingly higher price tag.
Features
Both FortiGate and SonicWall TZ present certain advantages that might make them the correct solution for some networks.
FortiGate is an established vendor and the product receives frequent feedback and across the board high ratings. For a few standout features, FortiGate users say its VPN is high performing, its GUI and administrative setup are fluid and easy to understand. Users will get great results when the firewalls are properly configured, which most users say is not hard to do with proper training. Additionally, and unusually for many appliances that can be deployed in enterprise environments, users praise FortiGate for clear and straightforward pricing.
SonicWall TZ is just as highly rated for its market. Reviewers single out its excellent traffic inspection and geolocation based traffic filtering, and highly configurable network access rules controlling who and cannot access network resources. Its antivirus is also highly praised, and users point out that the SonicWall TZ appliance cost is low.
Limitations
Though these are high rated next-gen firewalls, there are a few considerations that buyers should keep in mind before deploying either solution.
A number of users say the FortiGate GUI, while excellent, takes time getting used to. Training should help get new users up to speed and may be a necessity for many users. Also, firmware upgrades for FortiGate seem to produce an unusually high number of annoying bugs. Opposite SonicWall TZ, FortiGate users find its traffic shaping rules and setup to be less intuitive. This appears to be users’ least favorite feature.
SonicWall TZ’s weak spot appears to be its logs, alerts, and reporting. Particularly the reporting is said to be lacking in detail. And while the appliances are not terribly expensive, users find the subscription cost to be surprisingly complex. Specifically, they complain that the association of the firewall’s various potential functions to separate licenses means licenses can proliferate. The end result is that costs balloon surprisingly as each and every thing the user wants is gated behind its own little recurring fee. This a la carte approach may keep overall cost down, however. SonicWall TZ is also not liked for its interface and admin controls, which are comparatively basic.
Pricing
SonicWall’s TZ series appliances are available from the company’s former parent company Dell Technologies, among other third-party vendors. The series starts with the lower end TZ350 (available now for around $400) and rise to the TZ600 series for about $1600. To load the firewall with SonicWall Antivirus and Intrusion Prevention comes in at about $300 per year. Advanced Gateway Security, a subscription-based combo of services that adds application control & intelligence as well as content filtering among other features comes in at about $1500 yearly. Its SSL VPN license costs $375 to add.
Lower level Fortinet FortiGate firewalls come in at a meager $280 – $500 per appliance approximately, while the top of the line rack-mountable, unified threat management solution FortiGate 6500F can come in at about 250k to 1mil depending on service bundle features and duration (1-3 years). The Fortigate 2000 – 3400 series of appliances range from about 150k to half a million fully featured, with services bundled.
Features
Fortinet FortiGate
SonicWall TZ
Firewall
Comparison of Firewall features of Product A and Product B
Fortinet FortiGate
8.7
53 Ratings
0% above category average
SonicWall TZ
7.9
15 Ratings
9% below category average
Identification Technologies
8.951 Ratings
8.815 Ratings
Visualization Tools
8.351 Ratings
8.114 Ratings
Content Inspection
8.852 Ratings
8.315 Ratings
Policy-based Controls
8.953 Ratings
7.715 Ratings
Active Directory and LDAP
8.750 Ratings
6.512 Ratings
Firewall Management Console
7.752 Ratings
7.115 Ratings
Reporting and Logging
8.253 Ratings
7.314 Ratings
VPN
9.052 Ratings
8.415 Ratings
High Availability
9.348 Ratings
8.714 Ratings
Stateful Inspection
9.251 Ratings
8.014 Ratings
Proxy Server
8.539 Ratings
7.810 Ratings
Best Alternatives
Fortinet FortiGate
SonicWall TZ
Small Businesses
pfSense
Score 8.8 out of 10
pfSense
Score 8.8 out of 10
Medium-sized Companies
Quantum Firewalls and Security Gateways
Score 9.3 out of 10
Quantum Firewalls and Security Gateways
Score 9.3 out of 10
Enterprises
Palo Alto Networks Virtualized Next-Generation Firewalls - VM Series
Score 9.2 out of 10
Palo Alto Networks Virtualized Next-Generation Firewalls - VM Series
Fortinet FortiGate addressed an immediate security issue we had a few years ago. The device gave us a much clearer picture of the activities on our network and also more importantly, increased our awareness of threats from the internet as a whole. Fortinet FortiGate helps us to mitigate these threats with regular signature updates from Fortiguard labs, identifying certain characteristics which, once recognised by Fortinet FortiGate, can be harnessed to deploy powerful 'playbooks'.
Based on my experience, this is a solid platform for a small to mid sized company, especially when there is someone who has IT experience, or can get outsourced IT help. I would not recommend for someone who is a technology novice. Also, this is a competent device for someone who is looking to add VPN services for remote workers.
SD-WAN - Load balancing of Internet traffic is a USP of Fortigate and makes it stand tall in the competition. Be it 3 or more Internet Links, multiple Subnets/segments of users to distribute and bandwidth load balancing for links and users. SLA based monitoring of Internet Links / MPLS links, makes it even better to choose the links on the basis of performance (Latency, packet loss, Jitter etc).
SSL VPN configuration - As we all have WFH force (to some extend or all employee) during Covid-19, it is impossible to plan BCP without having a SSL VPN. In Fortigate, the SSL VPN configuration is very easy with the help of wizard. The deep CLI-level debugging is also very helpful in troubleshooting. Type of tunnel can be easily configured - Full Tunnel or Split Tunnel for SSL.
Explicit Proxy - This is also a great feature to shape and re-route the traffic, configuring the Proxy on the Firewall itself. We are using this feature in Pilot for now, and planned to rollout in few weeks looking at the success rate of the POC.
There are Service Bundles in SonicWall TZ that are Unlicensed and do not know why they have not be Activated - would need help to further understand benefits
Do not know why Standard Support is Unlicensed
WiFi range of TZ270W is very limited - need to add Access Points or Extended to obtain adequate coverage
Fortinet's products have kept improving with new software releases and they continue to deliver great value. Their support is also very good. I believe that as a small enterprise, their products have given us competitive advantage delivering features and functionality that enable us to innovate and do things better. They also continue to be a leader in the markets they serve.
The firewall runs very well, firmware updates are fairly quick but you must follow the upgrade path. Neglecting this step will cause a lot of pain. If you decide to go with Fortinet FortiGate switches and/or access points, they can be managed within the firewall which is great. We're also using the FortiAnalyzer which easily plugs into the firewall for any reporting you may require.
Overall the new interface is very logical and easy to navigate. We did struggle at first coming from the older interface and finding our way around the new. But our new users found it very simple to find what they were looking for. One negative we do all struggle with is packet cpature not always being clear how its set/what is being monitored. this could do with more information on teh intial page instead of having to look for it
The Support team at Fortinet is excellent. They can not only help you configure the device for what you are trying to do, they offer suggestions on improving rules, and troubleshooting issues. Their response time is fast, ensuring you are up and running immediately with no questions asked. We had a hard drive failure in one of our Fortinet Fortigate appliances. The tech answered immediately, and started rebuilding the drive after some preliminary investigations. After rebuilding, there were still errors and issues, so they dispatched a brand new Fortinet Fortigate appliance. The tech then backed up the configurations for when the new device came in, which showed up in a few hours. A restore of the configuration took less than a minute, and there were no more errors or issues.
Once you get to a competent technician the support experience is better. But I have found that the lower tiers of support are very slow to respond (like 1 email per day) and you typically have to re-explain yourself a couple times before they get it. I have not used Phone support, and that may be a better experience.
[Fortinet] FortiGate is not only cost effective but it gives the comprehensive security against the APT attacks and gives the complete traffic visibility and granular control. You can easily create the VDOMs (Virtual firewall) within a Fortigate firewall and customize the dashboard as per your requirement if you have multiple VDOMs within a single firewall.
SonicWall and WatchGuard are both fine appliances, but I am accustomed to the Barracuda NG. The Barracuda Control Center is so powerful and useful that it beats out the other two. SonicWall does a great job of dividing up firewall rules and NAT policies, but this is a preference among engineers.
The pricing given to us for our firewall was well within what we were already spending for other vendors solutions and had the added value of eliminating a separate expense for a dedicated web filtering appliance.
We have also adopted Fortinet's security fabric approach and thus changed vendors for our switch and AP devices. These devices have come at reduced prices as compared to another previous vendor we were using, particularly in relation to ongoing annual maintenance costs.