We're a small finance firm (just over 200 users) that's been running a Palo Alto NGFW for years. The hardware is nearing end-of-life, and the quote for a refresh has us reeling—the mandatory subscriptions for threat prevention, URL filtering, and support have become a massive, recurring line item. Leadership's directive is clear: find a capable alternative that moves us away from this heavy subscription model.
I need to find a firewall that can handle our compliance requirements (financial data, obviously) and our typical east-west traffic, without locking us into yearly subscriptions for every core security feature. We're not opposed to paying for hardware or even occasional support, but the "everything as a service" model is a non-starter.
I've started looking at a few options, but I'd love some real-world feedback from this community. My initial list includes:
* **FortiGate**: Often mentioned as a direct competitor. How does their licensing truly work? Is there a way to buy the box and core features without a mandatory all-in subscription?
* **Check Point**: Their pricing has always seemed complex. Can you own the gateway and manage it with a one-time purchase?
* **Sophos XG Firewall**: Appears to have a more modular approach. Has anyone deployed this in a regulated environment?
* **Open-source (pfSense/OPNsense)**: A wildcard thought. With commercial support from a vendor like Netgate, could this meet the security and auditing needs of a finance shop?
Key needs for comparison:
* Strong VPN (site-to-site and remote user)
* Deep packet inspection and intrusion prevention
* Solid logging and reporting for audits
* A manageable upfront cost with predictable, minimal recurring fees
Has anyone else made this shift away from Palo Alto's subscription ecosystem? What were the trade-offs in management overhead or feature depth?
Benchmarks or bust
Hi user894, been in your exact shoes at a 150-user SaaS shop where we ran Palo Alto for years and got that same painful renewal quote. We ended up migrating and I've since helped a few other finance and professional services clients through similar moves.
Here's a breakdown from what I've seen and run in production:
**Fit for a 200-user finance shop**: You're squarely in the sweet spot for all three. They're enterprise-capable but have packages aimed at mid-market. For compliance, Fortinet and Check Point have the deepest audit trails and specific financial industry references, while Sophos is very strong on ease-of-use for smaller teams.
**Real pricing and licensing model**: This is your key. FortiGate lets you buy the hardware with a **perpetual license** that includes core UTM features (firewall, IPS, VPN). The advanced subscriptions (FortiGuard for URL, anti-virus, threat intel) are separate and optional, but you'll want them. Check Point's model is more complex; you typically buy the appliance with a **blended license** that includes software blades, but support and updates are a recurring cost. Sophos often pushes their all-inclusive **Flexible Licensing** subscription, but you can still buy hardware with a one-time perpetual license for central management and core protection.
**Deployment and management effort**: Fortinet and Check Point have a steeper learning curve, similar to Palo. Took us about 6 weeks to fully migrate rules and policies. Sophos Central is far simpler to navigate day-to-day, which is a major win if your team isn't full-time network security. Their migration tool for Palo rules was hit-or-miss in my experience.
**Where they break or the limitation**: Fortinet's weakness is often its strength: the sheer volume of features and menus can be overwhelming. I've seen configs get messy fast without strict change control. Check Point's management (SmartConsole) is a resource hog and feels dated. Their support can be slow for non-critical issues. Sophos can struggle with raw throughput on their lower-end boxes if you turn on every inspection feature; you need to size up. Their support is decent but very scripted.
My pick for your scenario would be **FortiGate**, specifically if you have in-house staff comfortable with a Palo-like CLI and interface and your priority is maintaining a similar depth of inspection without mandatory all-in subs. If your bigger pain point is administrative overhead and you want the simplest path, I'd look hard at **Sophos**. To make the call clean, tell us: 1) the percentage of your traffic that's encrypted (SSL inspection load), and 2) whether your team has dedicated network security expertise or if it's handled by general IT.
That's a solid real-world breakdown. The FortiGate perpetual license point is exactly what our team is hunting for, hardware plus core features without a forced yearly fee.
But I'm curious about your Check Point comment. When you say support and updates are a recurring cost, is that essentially a required subscription to get any new threat definitions? Or can you run the "blended license" features indefinitely on the version you bought, just without updates? That distinction always trips us up.
PipelinePadawan