NGINX vs. Palo Alto Networks Next-Generation Firewalls - PA Series

Overview
ProductRatingMost Used ByProduct SummaryStarting Price
NGINX
Score 9.3 out of 10
Mid-Size Companies (51-1,000 employees)
NGINX, a business unit of F5 Networks, powers over 65% of the world's busiest websites and web applications. NGINX started out as an open source web server and reverse proxy, built to be faster and more efficient than Apache. Over the years, NGINX has built a suite of infrastructure software products o tackle some of the biggest challenges in managing high-transaction applications. NGINX offers a suite of products to form the core of what organizations need to create…N/A
Palo Alto Networks Next-Generation Firewalls - PA Series
Score 9.3 out of 10
N/A
Palo Alto next-generation firewalls classify all traffic, including encrypted and internal traffic, based on application, application function, user and content. Users can create security policies to enable only authorized users to run sanctioned applications.
$1.50
per hour per available zone
Pricing
NGINXPalo Alto Networks Next-Generation Firewalls - PA Series
Editions & Modules
No answers on this topic
No answers on this topic
Offerings
Pricing Offerings
NGINXPalo Alto Networks Next-Generation Firewalls - PA Series
Free Trial
YesNo
Free/Freemium Version
YesNo
Premium Consulting/Integration Services
YesNo
Entry-level Setup FeeOptionalNo setup fee
Additional DetailsUsers may also choose to pay per gigabyte of data used starting at .065/GB. Note that prices listed here reflect installations via Amazon Web Services. Pricing may differ if other service providers are used.
More Pricing Information
Community Pulse
NGINXPalo Alto Networks Next-Generation Firewalls - PA Series
Features
NGINXPalo Alto Networks Next-Generation Firewalls - PA Series
Application Servers
Comparison of Application Servers features of Product A and Product B
NGINX
7.9
23 Ratings
2% below category average
Palo Alto Networks Next-Generation Firewalls - PA Series
-
Ratings
IDE support7.111 Ratings00 Ratings
Security management7.919 Ratings00 Ratings
Administration and management7.119 Ratings00 Ratings
Application server performance8.019 Ratings00 Ratings
Installation9.920 Ratings00 Ratings
Open-source standards compliance7.117 Ratings00 Ratings
Firewall
Comparison of Firewall features of Product A and Product B
NGINX
-
Ratings
Palo Alto Networks Next-Generation Firewalls - PA Series
8.7
23 Ratings
1% above category average
Identification Technologies00 Ratings9.523 Ratings
Visualization Tools00 Ratings7.523 Ratings
Content Inspection00 Ratings10.023 Ratings
Policy-based Controls00 Ratings10.023 Ratings
Active Directory and LDAP00 Ratings9.522 Ratings
Firewall Management Console00 Ratings9.023 Ratings
Reporting and Logging00 Ratings8.023 Ratings
VPN00 Ratings9.023 Ratings
High Availability00 Ratings9.522 Ratings
Stateful Inspection00 Ratings9.022 Ratings
Proxy Server00 Ratings5.011 Ratings
Best Alternatives
NGINXPalo Alto Networks Next-Generation Firewalls - PA Series
Small Businesses
Apache HTTP Server
Apache HTTP Server
Score 8.4 out of 10
pfSense
pfSense
Score 9.4 out of 10
Medium-sized Companies
Apache Tomcat
Apache Tomcat
Score 8.1 out of 10
Quantum Firewalls and Security Gateways
Quantum Firewalls and Security Gateways
Score 9.6 out of 10
Enterprises
Apache Tomcat
Apache Tomcat
Score 8.1 out of 10
Quantum Firewalls and Security Gateways
Quantum Firewalls and Security Gateways
Score 9.6 out of 10
All AlternativesView all alternativesView all alternatives
User Ratings
NGINXPalo Alto Networks Next-Generation Firewalls - PA Series
Likelihood to Recommend
9.2
(50 ratings)
9.5
(39 ratings)
Likelihood to Renew
9.1
(1 ratings)
10.0
(1 ratings)
Usability
8.8
(3 ratings)
9.0
(4 ratings)
Support Rating
8.1
(4 ratings)
8.4
(9 ratings)
User Testimonials
NGINXPalo Alto Networks Next-Generation Firewalls - PA Series
Likelihood to Recommend
F5
[NGINX] is very well suited for high performance. I have seen it used on servers with 1k current connections with no issues. Despite seeing it used in many environments I've never seen software developers use it over apache, express, IIS in local dev environments so it may be more difficult to setup. I've also seen it used to load balance again without issues.
Read full review
Palo Alto Networks
Palo Alto Networks Next-Generation Firewalls - PA Series are extremely versatile. Whether it be a one office location or multiple sites, the Panorama interface allows centralized management. I've found Palo Alto does a great job with their updates and supporting customers. As a cybersecurity professional, I like that Palo Alto's products offer a wide range of controls to support defense in depth. It is easy for security and network infrastructure teams to use the same consoles to deliver performance with security built in.
Read full review
Pros
F5
  • Very low memory usage. Can handle many more connections than alternatives (like Apache HTTPD) due to low overhead. (event-based architecture).
  • Great at serving static content.
  • Scales very well. Easy to host multiple Nginx servers to promote high availability.
  • Open-Source (no cost)!
Read full review
Palo Alto Networks
  • The PA handles VPN connectivity without missing a beat. We have multiple VPN tunnels in use for redundancy to cloud-based services.
  • The PA has great functionality in supporting failover internet connections, again with the ability to have multiple paths out to our cloud-based services.
  • The PA is updated on the regular with various security updates, we are not concerned with the firewall's ability to see what packets are really flowing across the network. Being able to see beyond just IP and port requests lets you know things are locked down better than traditional firewalls.
  • It is a great overall kit, with URL filtering and other services that fill in the gaps between other solutions without breaking the bank.
Read full review
Cons
F5
  • Customer support can be strangely condescending, perhaps it's a language issue?
  • I find it a little weird how the release versions used for Nginx+ aren't the same as for open source version. It can be very confusing to determine the cross-compatibility of modules, etc., because of this.
  • It seems like some (most?) modules on their own site are ancient and no longer supported, so their documentation in this area needs work.
  • It's difficult to navigate between nginx.com commercial site and customer support. They need to be integrated together.
  • I'd love to see more work done on nginx+ monitoring without requiring logging every request. I understand that many statistics can only be derived from logs, but plenty should work without that. Logging is not an option in many environments.
Read full review
Palo Alto Networks
  • Our specific model is a bit slow and outdated and takes up to 10 minutes to commit a configuration change.
  • Nested security rules would be helpful instead of a linear approach. But rule creation in general is very simple.
  • Documentation gives a very straight forward answer to some items but is very vague in others.
  • Support could be a little better. An issue we had a tech was insistent it was the "other guy" and it ended up being the very latest PAN OS upgrade.
Read full review
Likelihood to Renew
F5
Great value for the product
Read full review
Palo Alto Networks
The PA5220s have far exceeded what we have expected out of them. It was a bit of a learning curve coming from another vendor, but everything falls into place now with ease. The capabilities of the solution still surprise us, allowing us to remove other costly hardware and providing a single point of management needed
Read full review
Usability
F5
Front end proxy and reverse proxy of Nginx is always useful. I always prefer to Nginx in overall usability when you have application server and database or multiple application servers and single database i.e. clustered application. Nginx provides really good features and flexibility which helps the system administrator in case of troubleshooting and also from the administration perspective. Also, Nginx doesn't delay any request because of internal performance issues.
Read full review
Palo Alto Networks
The few aspects of the Palo Alto Networks Next-Generation Firewalls - PA Series that could use improvement - such as slow commit times, which I hear they have improved on in the newest models - are vastly outshined by everything else these appliances provide. We have been using the Palo Alto Networks Next-Generation Firewalls - PA Series appliances for more than 10 years and plan to continue using them for the foreseeable future.
Read full review
Support Rating
F5
Community support is great, and they've also had a presence at conferences. Overall, there is no shortage of documentation and community support. We're currently using it to serve up some WordPress sites, and configuring NGINX for this purpose is well documented.
Read full review
Palo Alto Networks
We've run into a couple undocumented bugs, but that seems to happen with every brand and technology. Any time we've had to engage Palo Alto support they've always been professional, knowledgeable and prompt. In almost all cases we've been able to resolve our issues without having to escalate our tickets.
Read full review
Alternatives Considered
F5
We have used Traffic, Apache, Google Cloud Load Balancing and other managed cloud-based load balancers. When it comes to scale and customization nothing beats Nginx. We selected Nginx over the others because
  • we have a large number of services and we can manage a single Nginx instance for all of them
  • we have high impact services and Nginx never breaks a sweat under load
  • individual services have special considerations and Nginx lets us configure each one uniquely
Read full review
Palo Alto Networks
We are using Cisco ASA before in our environment but when it comes to deep scanning & layer 7 security it doesn't have that capability. After using Palo Alto Networks Next-Generation Firewall we are using sandboxing & advance malware protection that provides high-level end-user security. Also after implementing it we can easily monitor user-level traffic.
Read full review
Return on Investment
F5
  • Nginx has decreased the burden of web server administration and maintenance, and we are spending less time on server issues than when we were using Apache.
  • Nginx has allowed more people in our company to get involved with configuring things on the web server, so there's no longer a single point of failure ("the Apache guy").
  • Nginx has given us the ability to handle a larger number of requests without scaling up in hardware quite so quickly.
Read full review
Palo Alto Networks
  • Overall, even though the device is very expensive (both hardware and licensing), the product does produce a decent ROI, given that one (or HA pair) of devices can do so many things, such as anti-virus, anti-malware, URL filtering, SSL decryption, SSL VPN, routing, etc.
  • There will definitely be sticker shock when you're renewal comes up annually (or after 3 years), so be sure to look very carefully at the recurring costs of this product, with respect to licensing and hardware/software maintenance.
Read full review
ScreenShots

NGINX Screenshots

Screenshot of Overview of the NGINX Application PlatformScreenshot of NGINX Controller - MonitoringScreenshot of NGINX Controller - Configuration