Firewall Software
Firewall Software Overview
Top Rated Firewall Products

These products won a Top Rated award for having excellent customer satisfaction ratings. The list is based purely on reviews; there is no paid placement, and analyst opinions do not influence the rankings. Read more about the Top Rated criteria.
Firewall Software TrustMap

TrustMaps are two-dimensional charts that compare products based on trScore and research frequency by prospective buyers. Products must have 10 or more ratings to appear on this TrustMap.
Firewall Products
(1-25 of 73) Sorted by Most Reviews
The list of products below is based purely on reviews (sorted from most to least). There is no paid placement and analyst opinions do not influence their rankings. Here is our Promise to Buyers to ensure information on our site is reliable, useful, and worthy of your trust.
WatchGuard Network Security is a network security and firewall software. WatchGuard includes secure Wi-Fi, multi-factor authentication, and network intelligence products and services designed for SMB’s.
Key Features
- Policy-based Controls (211)93%9.3
- Firewall Management Console (209)89%8.9
- Content Inspection (205)89%8.9
Cisco Adaptive Security Appliance (ASA) software is the core OS for the ASA suite. It provides firewall functionality, as well as integration with context-specific Cisco security modules. It is scaled for enterprise-level traffic and connections.
Key Features
- VPN (47)91%9.1
- Reporting and Logging (47)83%8.3
- Firewall Management Console (47)82%8.2
Cisco Meraki MX Firewalls is a combined UTM and Software-Defined WAN solution. Meraki is managed via the cloud, and provides core firewall services, including site-to-site VPN, plus network monitoring.
Key Features
- Identification Technologies (48)85%8.5
- Firewall Management Console (49)82%8.2
- Reporting and Logging (50)78%7.8
FortiNet FortiGate is a firewall option with high integrability. It offers a variety of deployment options and next-gen firewall capabilities, including integration with IaaS cloud platforms and public cloud environments.
Key Features
- Firewall Management Console (36)94%9.4
- Policy-based Controls (36)90%9.0
- Reporting and Logging (36)87%8.7
Palo Alto next-generation firewalls classify all traffic, including encrypted and internal traffic, based on application, application function, user and content. Users can create security policies to enable only authorized users to run sanctioned applications.
Key Features
- Content Inspection (21)99%9.9
- Identification Technologies (21)99%9.9
- Visualization Tools (21)92%9.2
The Cisco Firepower® 1000 Series for small to medium-size businesses and branch offices is a family of four threat-focused Next-Generation Firewall (NGFW) security platforms designed to deliver business resiliency through superior threat defense. The vendor provides that they offers…
Key Features
- Policy-based Controls (31)82%8.2
- Firewall Management Console (30)73%7.3
- Reporting and Logging (31)70%7.0
Cisco offers a threat-focused next-generation firewall (NGFW), the ASA 5500-X Series. The ASA 5500 Series platforms can run either the Cisco ASA Firewall or Cisco Firepower Threat Defense (FTD). The series features appliances in a variety of form factors, including standalone options…
Key Features
- Firewall Management Console (27)87%8.7
- Reporting and Logging (27)86%8.6
- Content Inspection (27)80%8.0
pfSense is a firewall and load management product available through the open source pfSense Community Edition, as well as a the licensed edition, pfSense Plus (formerly known as pfSense Enterprise). The solution provides combined firewall, VPN, and router functionality, and can be…
Key Features
- Reporting and Logging (9)86%8.6
- Policy-based Controls (9)84%8.4
- Content Inspection (9)74%7.4
Cisco Secure Firewall (formerly Cisco Firepower NGFW) is a firewall product that integrates with other Cisco security offerings. It provides Advanced Malware protection, including sandboxing environments and DDoS mitigation. Cisco also offers a Next Generation Intrusion Prevention…
Key Features
- Content Inspection (16)94%9.4
- Policy-based Controls (16)89%8.9
- Firewall Management Console (16)89%8.9
SonicWall TZ is a NGFW for small to mid-sized companies. It is a Unified Threat Management solution, with additional native decryption and deep-packet inspection capabilities.
Key Features
- Identification Technologies (9)90%9.0
- Content Inspection (9)85%8.5
- Policy-based Controls (9)81%8.1
Barracuda CloudGen Firewalls provides a wide range of security and connectivity features, including web filtering, NAC and SSL VPN and other features for remote access, as well as protection as edge devices and IoT security.
Key Features
- Firewall Management Console (9)83%8.3
- Active Directory and LDAP (9)75%7.5
- Reporting and Logging (9)70%7.0
The VM-Series is a virtualized form of Palo Alto next-generation firewall that can be deployed in a range of cloud environments. The VM-Series natively analyzes all traffic in a single pass to determine the application identity, the content within, and the user identity.
Key Features
- Content Inspection (7)97%9.7
- Identification Technologies (7)95%9.5
- Visualization Tools (7)90%9.0
Untangle NG Firewall is an open-source firewall and gateway security platform. It offers a free core firewall platform with paid add-ons, and a cloud-based management platform with a variety of deployment options for smaller teams.
Key Features
- Content Inspection (5)99%9.9
- Visualization Tools (5)94%9.4
- Identification Technologies (5)79%7.9
Sophos XG Firewall provides comprehensive next-generation firewall protection powered by deep learning and Synchronized Security. The vendor states XG Firewall supplies unmatched insights and exposes hidden user, application, and threat risks on the network, and say the product is…
Key Features
- Content Inspection (7)90%9.0
- Identification Technologies (7)81%8.1
- Visualization Tools (7)78%7.8
RackFoundry was a firewall solution with VPN, SIEM, automated vulnerability scanning and log management features scaled for SME’s. It has been discontinued and is no longer available.
Key Features
- Event and log normalization/management (6)10%1.0
- Custom dashboards and workspaces (6)10%1.0
Learn More About Firewall Software
What are Firewall Software?
Firewall software are filters that stand between a computer or computer network and the Internet. Each firewall can be programmed to keep specific traffic in or out. All messages passing through the firewall software are examined. Those messages that do not meet pre-defined security criteria are blocked.
For example, on the outbound side, firewall software can be configured to prevent employees from transmitting sensitive data outside the network. On the inbound side, firewalls can be configured to prevent access to certain kinds of websites, like social media sites.
Types of Firewalls
Firewalls use several methods to control traffic flowing in and out of a network:
- Packet filtering: This method analyzes small pieces of data against a set of filters. Those that meet the filter criteria are allowed to pass through, while others are discarded.
- Proxy service: In this method, computers make a connection to the proxy which then initiates a new network connection based on the content of the request. In this way, there is no direct connection or packet transfer on either side of the firewall. Network addresses are effectively hidden.
- Stateful inspection: Stateful inspection is the new standard firewall security method that monitors communications packets over a period of time. Outgoing packets that request specific types of incoming packets are tracked. Only incoming packets that are an appropriate response are allowed to pass. Firewalls using this method are often referred to as next-generation firewalls (NGFW).
There are also more specific firewall software beyond network-level firewalls. For instance, Web Application Firewalls sit between externally-facing applications and the web portal that end-users connect to the application through.
Firewall Software Features & Capabilities
Firewall software should have most or all of these features:
- Application visibility and control
- Identify and control evasive app threats
- Intrusion Prevention integration
- Physical and virtual environment support
- Integration with LDAP and Active Directory
- "Sandbox," or isolated, cloud-based threat emulation
Firewall vendors are beginning to bundle firewall offerings with other security or privacy features, although this is not a universal practice. The most common example is support for Virtual Private Networks (VPN), and load-management is often featured as well.
Firewall Comparison
To compare different Firewall software, you likely want to consider evaluating these aspects of the software:
- Managed Service Provider vs. In-House Focus: Are you looking for a firewall software to sell to and manage for your clients, or do you need something for your own business? Software tailored to the former context will emphasize centralized management and customizability, while the latter will be more accessible for line of business users without IT security backgrounds.
- Physical vs. Cloud Deployments: The standard deployment method for firewalls is via hardware appliance deployed on-premise. Alternative deployments on virtual machines, or hosted in the cloud on 3rd party infrastructure, have become frequent options among leading vendors. Cloud deployments frequently operate on a subscription pricing model, while physical appliances are more likely to be a one-time purchase, with additional costs for software updates varying by product.
- Multi-Location vs. Single-Location: Providing a firewall across multiple locations will require specific features. The most relevant feature differences will be VPN support (for securely connecting to remote offices), central management support, and native SD-WAN capabilities.
- Support: Reviewers frequently mention customer support and service, both positively and negatively depending on the software. Given a convergence of capabilities towards market parity, the extra support and services vendors provide can become a key differentiator between products.
Pricing Information
The cost of firewalls can vary from free (for personal use) to significant sums of money for enterprise firewalls. Firewalls are often on-premise appliances, but can also be purchased as software which must be installed on a server, or as a cloud service. The range of pricing models is broad making it difficult to compare across vendors. However, an enterprise firewall may cost upwards of $30,000, depending on capability and type.
Cisco ASA 5500-X Starting Price: $400.00 / Maximum Price: $20,000.00
SonicWall TZ Starting Price: $300.00 / Maximum Price: $2,300.00
Fortinet Fortigate Starting Price: $250.00 / Maximum Price: $300,000.00
pfSense Starting Price: $179.00 / Maximum Price: $2,649.00
Cisco Firepower Starting Price: $500.00 / Maximum Price: $200,000.00
Cisco Meraki MX Starting Price:$595.00 / Maximum Price: $19,995.00
More Resources
Firewall Software Best Of Awards
The following firewalls offer award-winning customer relationships, feature sets, and value for price. Learn more about our Best Of Awards methodology here.

Related Categories
Frequently Asked Questions
What are the main types of firewall?
There are four major types.
- Packet Filtering: Small pieces of data are analyzed against a set of filters and are either allowed to pass through or are discarded.
- Proxy Firewall: A proxy firewall serves as the gateway from one network to another. Computers make a connection to the proxy which then initiates a new network connection based on the content of the request.
- Stateful Inspection: Stateful inspection monitors the state of active connections and uses this information to determine which network packets to allow through. Decisions on what to allow through are based on a combination of defined rules and context.
- Next-Generation Firewall (NGFW): Next-generation firewalls go beyond packet filtering and stateful inspection. They have additional capabilities in order to help combat more modern threats like malware.