Hey folks! With all the talk about cloud-native security and shifting perimeters, I've been thinking about the firewall landscape. FortiGate has been a staple in so many stacks (I've managed my fair share of them 😅), but the field is getting crowded with interesting alternatives. Hereβs my take on the top competitors making waves as we look toward 2026, especially from a DevOps/Infra-as-Code perspective.
**Top of Mind Competitors:**
* **Palo Alto Networks (PA-Series & Prisma Cloud):** Still the heavyweight in many enterprise comparisons. Their integration of network and cloud security (via Prisma) is a huge draw. The API coverage is excellent, which is great for automation.
* **Cisco Secure Firewall (formerly Firepower):** A classic rival. Their shift towards more cloud-managed offerings and intent-based networking keeps them relevant, though I've found their Terraform provider a bit clunkier than I'd like.
* **Check Point Quantum:** Strong on consolidated security management and threat prevention. Their "Infinity" architecture is a direct play for the cloud-native, unified policy crowd.
* **The Cloud-Native Contenders:** This is where it gets exciting for our workflows.
* **AWS Network Firewall + Gateway Load Balancer:** For pure AWS shops, this managed combo is becoming a powerful, scalable alternative. Defining everything in Terraform is a dream.
* **Open Source (pfSense/OPNsense):** For cost-sensitive or highly customized deployments, they're unbeatable. The community-driven model and flexibility are huge pros.
**Where the Real Competition Lies (IMO):**
For teams embracing GitOps and IaC, the deciding factor is often **API-first design and automation maturity**. Can I treat my firewall rules like code? For example, managing a Palo Alto rule via a quick Terraform snippet feels clean:
```hcl
resource "panos_security_rule" "web_allow" {
rulebase = "pre-rulebase"
name = "Allow-Web-to-App"
source_zones = ["untrust"]
source_addresses = ["any"]
destination_zones = ["trust"]
destination_addresses = ["10.0.1.10"]
applications = ["http", "https"]
action = "allow"
}
```
That kind of declarative management is becoming a requirement, not a nice-to-have.
**The Big Considerations for 2026:**
* **Convergence with Kubernetes:** How do these platforms handle Ingress/Egress control for dynamic K8s workloads? Solutions like Calico's network policy (though not a traditional firewall) are eating into this space.
* **Pricing & Transparency:** FortiGate often wins on price/performance, but operational costs (including management overhead) can change the math.
* **Developer Experience:** Can my platform team offer security as a self-service, API-driven layer to developers?
I'm curiousβwhat's in your pipeline? Are you sticking with FortiGate, or piloting something new for that next-gen infrastructure project?
Keep deploying!
Your point about Palo's API coverage is key from an automation standpoint. Where I've seen them struggle, and where FortiGate often retains an edge, is in raw throughput-to-cost ratio for mid-range deployments. In the 200-series and 600-series bracket, FortiGate consistently benchmarks higher for SSL inspection throughput at a comparable price point. However, Palo's Prisma Cloud integration creates a security policy unification that's hard to match if you're heavily invested in AWS or Azure.
You mentioned Cisco's Terraform provider being clunky, and that's a real operational tax. It's worth checking out the emerging providers from vendors like Juniper (with their SRX and vSRX lines) or even open-source projects like Teraform's nascent support for OPNsense. They're not as mature, but for greenfield cloud-native deployments, they can be more agile.
Data never lies.
That throughput-to-cost point is so real. I've watched Palo quotes come in and just wince at the numbers for the same spec on paper. But you're onto something with the greenfield cloud-native angle.
We did a proof-of-concept last quarter with Juniper's vSRX on a couple of dev VPCs. Their Ansible modules were surprisingly good, actually better documented than their Terraform provider at the time. The agility was there, but the operational maturity for a full production deployment felt like a step back from Fortinet or Palo.
I'm curious if anyone's pushed the open-source route (like OPNsense) past lab environments for a distributed cloud footprint. The policy abstraction seems like it would get messy at scale.