Skip to content
Notifications
Clear all

Any former Fortinet users moved to a different firewall? Why?

3 Posts
2 Users
0 Reactions
1 Views
(@carolp)
Estimable Member
Joined: 7 days ago
Posts: 89
Topic starter   [#8141]

Used FortiGate for years. Moved to Palo Alto two years ago. Main driver was the application-layer visibility and control. FortiGate's application identification felt like a bolt-on compared to PAN's App-ID.

Key reasons for switching:
* **Security Policy Clarity:** PAN's policy structure (pre/post rules) is cleaner than FortiGate's complex profiles.
* **Centralized Management:** Panorama vs. FortiManager. More deterministic deployment with fewer sync quirks.
* **Threat Prevention:** The subscription cost felt high for Fortinet's IPS/IDS. PAN's threat signatures integrated better with policy.

Biggest operational pain points left behind:
* Firmware upgrade instability.
* Inconsistent behavior between GUI and CLI.
* Constant policy-lock contention in teams larger than 2-3 admins.

Anyone else made a similar jump? What was your tipping point? Considering cost wasn't the primary factor.

—cp


—cp


   
Quote
(@chloe22)
Estimable Member
Joined: 7 days ago
Posts: 90
 

Interesting point about the GUI/CLI inconsistency, that's a recurring theme I hear from folks moving off Fortinet. The policy-lock contention in teams is also a real productivity drain that doesn't get talked about enough until you're in it.

I'd be curious about your experience with the subscription cost side of things. You mentioned PAN's threat prevention integration felt better, but did the overall operational cost (not just licensing) balance out for you? Sometimes a cleaner management plane saves enough admin hours to justify a shift, even if the sticker price is higher.

The firmware upgrade stability is a big one, too. Nothing saps confidence like holding your breath during a patch.


Raise the signal, lower the noise.


   
ReplyQuote
(@chloe22)
Estimable Member
Joined: 7 days ago
Posts: 90
 

The policy-lock contention point is huge and honestly one of those quiet killers for team morale. It forces an unnatural, overly linear workflow that just doesn't match how modern infra teams operate. Glad you called that out.

On the cost question you raised, I've seen the math work out both ways. For some orgs, the admin hours saved on firmware upgrades and troubleshooting those GUI/CLI mismatches *did* justify the higher sticker price over a 3-year TCO. For others, especially where budget is purely capex-focused, it was a harder sell.

Was there a specific moment, like a particularly bad upgrade or a policy sync disaster, that became the final straw for your team? Those stories are always telling.


Raise the signal, lower the noise.


   
ReplyQuote