Skip to content
Notifications
Clear all

Switched from Palo Alto Prisma Access to FortiSASE - 6 month review

2 Posts
2 Users
0 Reactions
2 Views
(@annie82)
Estimable Member
Joined: 6 days ago
Posts: 61
Topic starter   [#11145]

Hi everyone! I've been lurking here for a while, trying to absorb all the info. This community has been a lifesaver while I've been figuring out our company's security stack.

We made a pretty big switch about six months ago, moving our team of ~50 from Palo Alto Prisma Access to Fortinet FortiSASE. The decision was mostly driven by budget and our existing FortiGate firewalls, honestly. I was tasked with helping evaluate, and it was overwhelming with all the features to compare!

So far, the experience has been... mixed? The onboarding was surprisingly smooth, and tying it into our Fortinet ecosystem felt seamless. The management console is less cluttered than Prisma's, which I appreciate. The cost savings are real, which our finance folks love.

But I'm hitting some snags I didn't expect. The client connection seems less stable for our fully remote folks, and I feel like I'm constantly tweaking policies to get the same application visibility we had before. The reporting is powerful, but it feels like you need a Fortinet certification to understand some of the logs.

Has anyone else made a similar switch? I'd love to hear:
- If you've found tricks for better connection reliability.
- How you handle deep application control compared to Prisma.
- Whether the FortiSASE feature set feels complete to you, or if it's still catching up.

I'm still learning, and sometimes I wonder if we gave up too much for the cost and single-vendor simplicity. Any insights from your own journeys would be so helpful!

✌️ annie



   
Quote
(@ethanv)
Estimable Member
Joined: 1 week ago
Posts: 117
 

I'm a DevOps lead at a mid-size SaaS company (~60 people, fully remote). We run FortiSASE for our edge security alongside a couple of FortiGate boxes for on-prem break-out. I've been in the trenches with this stack for about a year now, so your six-month timing is fresh.

* **Connection reliability**: That's been our biggest pain point too. The default tunnel keepalive is too aggressive for some home ISPs. We saw 2-3 drops per user per week until we bumped the keepalive interval to 15 seconds and enabled the "persistent tunnel" setting in the FortiClient config. After that, drops went down to <1 per week. Still, if your remote folks have high-latency or packet-loss connections (e.g., satellite, cellular), FortiSASE seems more sensitive than Prisma was. We had to add a local egress point for one user on Starlink just to keep Zoom stable.

* **Application visibility**: The FortiView dashboards are powerful but you're right - they're not turnkey. I spent about 10 hours building custom filters to match the out-of-the-box application categories we had in Prisma. The trick is to use the "app control" signatures and then build a custom report with the "top talkers" widget. It's doable, but if your team doesn't have a dedicated security person, Prisma's visibility is easier to consume.

* **Pricing and hidden costs**: The base FortiSASE license is around $6-8/user/mo depending on term, but that's just the SASE part. If you want ZTNA or DLP, add another $3-5/user/mo. We also had to buy a small FortiGate VM for local management and log aggregation - that was an extra ~$2k/year. Prisma was $12-15/user/mo for equivalent features, so the savings are real, but you'll pay in hours of config time.

* **Ecosystem lock-in vs flexibility**: If you already have FortiGates, the integration is genuinely smooth - single pane of glass for policies, auto-discovery of existing rules. But if you're running a mix of vendors, FortiSASE's management console is more opinionated. You can't easily export logs to a third-party SIEM without a FortiAnalyzer license. Prisma has better API-level integration with Splunk and Datadog out of the box.

If you're already on FortiGate and can spare a few hours per month for tuning, FortiSASE is a solid cost saver. But if your remote users are scattered across different ISPs and you need zero-touch reliability, I'd lean toward Prisma (or Zscaler if budget allows). What does your typical remote user's network look like - are they on cable/fiber or do you have a few folks on crappy copper? That'll tell you whether the keepalive tweaks are enough or if you need a local POP.


Ship fast, measure faster.


   
ReplyQuote