Everyone's hyping Palo Alto for retail. They're fine until you need to scale a promotion and their licensing model chokes your budget. Fortinet is cheaper upfront but their firmware updates are a gamble. Check Point's management is a full-time job.
You have 500 users and presumably a dozen stores. Have you calculated the real cost of SSL decryption across all those locations? What about the admin hours for policy management? Palo Alto's "simplicity" vanishes when you try to integrate with legacy POS systems.
Just saying.
Just saying.
I'm the IT lead for a 300-employee regional furniture retailer managing 25 stores, and I've run Palo Alto and Fortigate firewalls in production over the last five years.
1. **Real licensing and scaling cost:** Palo Alto's yearly Threat Prevention + URL Filtering subscription ran us about $12k per firewall. That's before the SSL decryption add-on, which added ~20% more. Fortinet's equivalent UTM bundle for the same throughput was roughly 40% less. The real budget killer for Palo Alto in retail is when you scale VPN users or add virtual appliances for pop-up sites; their per-user/feature licenses add up fast.
2. **Stability and update pain:** You're right about Fortinet firmware. We had a 100F model at a store that would drop IPSec tunnels after a specific update. We now lag updates by 6 months unless there's a critical CVE. Palo Alto updates were smoother for us, but their hardware had a higher DOA rate on arrival (we had to RMA 2 out of 15 units initially).
3. **Management overhead:** Central management is where they truly differ. Panorama (Palo Alto) is powerful but needs a dedicated admin to manage object hierarchies cleanly. FortiManager is clunkier but gets the job done for pushing uniform policies to 25+ devices. Check Point's management console, from my testing, felt like a 2000s Java app and required more dedicated tuning.
4. **Legacy system integration:** This is the quiet deal-breaker. Neither plays nicely with old, non-standard POS gear out of the box. Palo Alto's App-ID often mislabeled our old POS traffic as 'unknown-tcp', forcing manual ports and rules, which negates their "simplicity". Fortinet's application control was less granular but easier to bypass with a standard allow rule for the store VLAN.
My pick is Fortinet for a multi-store retail chain where budget predictability and basic centralized policy are the main goals. If your primary constraint is having a dedicated security team to manage a complex rule set and you need the deepest inspection, Palo Alto is worth the premium.
Tell us if you have an existing security team to manage this and what your most critical legacy system is (POS, inventory, scheduling).
edge cases matter
The point about legacy POS integration is critical and often overlooked. You're not just pushing generic web traffic; you're dealing with proprietary protocols and oddball ports that don't fit neatly into application-based policies. I've seen Palo Alto's App-ID struggle with some of these older systems, defaulting to a port-based rule that blows a hole in your security model. That's where the promised simplicity breaks down and you're suddenly managing a complex set of custom applications and service objects anyway.
The admin hours for policy management scale non-linearly with distributed stores if you're trying to maintain granular control. You either centralize and have overly broad policies, or you commit to managing dozens of device groups, which indeed becomes a full-time job.
- Mike