Skip to content

300,000+ products in stockAI infrastructure + enterprise IT hardware. Genuine product, full manufacturer warranty.

Networking hardware: Enterprise Firewall Buying Guide: FortiGate, Palo Alto, and Cisco Compared
Networking
Back to Resources
Networking 10 min read 23 September 2026

Enterprise Firewall Buying Guide: FortiGate, Palo Alto, and Cisco Compared

Throughput numbers on a spec sheet rarely survive contact with a real security policy. How to size a next-generation firewall honestly, and where FortiGate, Palo Alto Networks, and Cisco actually differ.

Every next-generation firewall vendor publishes a firewall-throughput number on the front of the data sheet, and that number is the single least useful figure for sizing a real deployment. It's measured with security features largely disabled, on traffic patterns that don't resemble a real network. Buy to that number and the appliance you receive will be undersized the day you turn on the inspection features you bought it for in the first place.

Why the headline throughput number misleads

"Firewall throughput" on most data sheets is measured with large packet sizes and stateful inspection only: no intrusion prevention, no deep packet inspection of encrypted traffic, no application identification. Enable NGFW-grade inspection (IPS, application control, SSL/TLS decryption) and the effective throughput on the same appliance frequently drops by half or more, because those features are computationally expensive and run on the same control-plane and inspection hardware. Vendors publish an "NGFW throughput" or "threat protection throughput" figure specifically because it's meaningfully lower. That second, smaller number is the one to size against, not the headline.

SSL/TLS inspection deserves particular attention because it is now inspecting the large majority of enterprise traffic, and decrypting, inspecting and re-encrypting a TLS session is one of the most expensive operations a firewall performs. An appliance sized comfortably for plaintext throughput can become the bottleneck on your network the day you enable full TLS inspection across all traffic rather than a subset.

Sizing questions that actually matter

  • What share of traffic will actually be TLS-inspected? Full inspection of all encrypted traffic is a materially heavier load than inspecting only specific categories or exempting trusted destinations.
  • How many concurrent sessions and new sessions per second does your user and application population actually generate? This scales with user count, but not linearly: a site running heavy east-west application traffic or a large number of IoT/OT devices generates disproportionately more sessions than the headcount suggests.
  • How many sites, and does the architecture call for a hub appliance sized for all site traffic aggregated, or a firewall at each site with a smaller individual sizing requirement? SD-WAN-integrated deployments increasingly favor the latter.
  • What's the growth horizon? A three-to-five-year refresh cycle is standard for these appliances, and undersizing to save on the initial purchase is the single most common enterprise firewall sizing mistake. The appliance gets replaced early, at a worse price than if it had been sized correctly the first time.

Where the major vendors actually differ

By the time you're comparing FortiGate, Palo Alto Networks and Cisco at a matched throughput tier, the raw security capability across all three is broadly comparable: all three run mature threat intelligence pipelines, all three do application identification, all three handle SSL inspection at scale. The differences that should actually drive the decision are architectural and operational.

  • Fortinet FortiGate: built around Fortinet's own security processing units (SPUs), purpose-built silicon for firewall and content inspection separate from the general-purpose CPU, which is a meaningful part of why FortiGate appliances often post strong NGFW throughput per dollar at the mid-range. FortiGate is also frequently the choice for organizations already standardized on the broader Fortinet Security Fabric (switches, access points, EDR) for единой single-pane management.
  • Palo Alto Networks PA-series: widely regarded as having the deepest application-identification engine (App-ID) and one of the more mature policy models in the industry, which matters most for organizations with complex, granular application-control requirements rather than simple allow/deny-by-port policy. Panorama, its centralized management platform, is a strong multi-site management story at a cost that reflects it.
  • Cisco Firepower / Secure Firewall: the natural choice for an organization already deeply standardized on Cisco networking, where integration with the existing Cisco security and management ecosystem (and existing Cisco support contracts and personnel familiarity) outweighs any feature-level comparison with the other two.

New versus refurbished, and why it's a legitimate choice here

Unlike a server, a firewall appliance's hardware doesn't meaningfully age the way compute does, because the security value comes from the software, signatures and subscription services running on it, not from the silicon's raw generation. A well-maintained refurbished appliance from an authorized channel, running a current-generation OS with an active support and subscription contract, delivers the same security posture as new hardware at a lower capital cost. The subscription (threat intelligence, IPS signatures, URL filtering) is what needs to stay current, far more than the chassis underneath it. This makes refurbished appliances a genuinely sound choice for branch and mid-tier deployments, not just a budget compromise.

Bundle SKUs and what they actually include

Most vendors, Fortinet in particular, sell firewalls as a hardware-plus-support-term bundle rather than bare hardware: a "FortiGate 101F Hardware Plus 3-Year FortiCare Premium and FortiGuard UTP Bundle" is the hardware and three years of the subscription services that make the security features functional, sold as one SKU. Compare quotes at the same bundle term and the same subscription tier across vendors; a bare-appliance price against a bundled price from a competitor is not a comparison, it's an error.

How Nexus Compute helps

As an independent procurement partner, we help you turn a firewall refresh into a concrete, validated configuration, genuine and fully warranted, quoted within 48 business hours. Send us your actual traffic profile, TLS inspection scope, and site topology, and we'll size against NGFW throughput rather than the headline number, across whichever vendor genuinely fits your operational estate.

Systems covered in this article

Planning a hardware investment?

Tell us what you're trying to build. A procurement specialist will help you specify and quote the right configuration within 48 business hours, no obligation.

FirewallNext-Generation FirewallFortiGatePalo Alto NetworksCisco FirepowerNetwork Security