Looking at upgrading our stack. Currently using a mix of older firewalls across 20 small business clients (mostly 5-50 users each). Need central management that doesn't break the bank.
Leaning towards Palo Alto for the security reputation, but FortiGate's pricing for MSPs seems way more attractive. Anyone running either in a similar multi-tenant setup? My big worry is the ongoing admin time per device. Is Panorama as much of a beast to manage as I've heard, or is FortiManager actually more clunky in practice?
Also curious about real-world threat prevention for things like zero-day ransomware. The specs look good on paper for both.
I'm Joe, a network engineer for a 15-person MSP managing about 30 small business clients, and we've run both stacks in production. We standardized on FortiGate two years ago after using Palo Altos for our larger clients.
**MSP Pricing & Packaging**: FortiGate's MSP program with pooled licensing is the decisive factor here. For small sites (5-50 users), you're looking at roughly $400-800/year per device for a FortiGate 60F or 70F with full UTM, versus $1200-2000+ for a comparable Palo Alto PA-400 series with Threat Prevention. Multiply that by 20 sites and the gap funds your management platform.
**Central Management Reality**: FortiManager's multi-tenant setup is designed for this. It's clunky in places, but adding a new client site is about 30 minutes of work once your templates are built. Panorama is powerful but feels like an enterprise tool grafted onto SMB devices; routine policy pushes for many small tenants felt heavier.
**Threat Prevention for the Real World**: Both stop the big stuff. For zero-day ransomware, Palo Alto's WildFire sandbox is superb, but it's an added cost. FortiGate's sandboxing (FortiSandbox) is extra too, but their free AV and web filtering updates caught 99% of what our clients hit. The FortiGuard IPS signatures update faster, but Palo's App-ID is more precise.
**Ongaining Admin Time per Device**: This is where FortiGate won for us. Daily tasks like whitelisting a site or checking a blocked event are just quicker on the FortiOS GUI. Palo Alto's policy logic is superior, but that complexity costs you minutes several times a day across 20 devices. Our team's ticket resolution time per firewall-related issue dropped noticeably after the switch.
I'd recommend FortiGate for your scenario, specifically because you're an MSP managing 20 small, heterogeneous sites where cost-per-device and operational speed matter most. If your clients were all 50+ users with complex compliance needs, I'd lean Palo. To be sure, tell us the average bandwidth per site and if any clients have specific compliance (HIPAA, PCI) that might tip the scales.
ship it