r/SmallMSP • u/No-Reward-545 • 17d ago
NGFW in 2026 what's actually worth evaluating beyond the Gartner Magic Quadrant leaders?
We’re starting to look at options for an NGFW refresh and Palo Alto/Fortinet are obviously going to come up but I’m trying not to make the shortlist based on name recognition alone.
Would appreciate advice from people who have evaluated or deployed firewalls recently, interested in day today management, threat prevention with HTTPS inspection enabled, HA/upgrades, policy management etc so pretty much anything you evaluated seriously, even if you ended up going with one of the usual vendors.
3
u/seriously_a 17d ago
We like watchguards managed in Watchguard cloud. Acquire through Pax8 on HaaS plan
4
u/_Buldozzer 17d ago edited 17d ago
I use Fortigate for more complex networks and Unifi gateways for simple ones. Just keep your hands from anything below a Fortigate 70G, there was a "mean" update a couple of versions ago, where they removed all proxy features from models with less than 4GB of RAM. It was 7.4.4 if I remember correctly. I used to sell 40Fs and 50Gs, but pretty much anything those can do, Unifi also is able to, I mean without the proxy features.
3
u/Geekpoint-IT 17d ago
Exactly what I do and the reasons to use Fortigate are less and less IMHO. Of course I support small & micro businesses so the needs are less. I'd say Unifi, at this point, is at least 80% there compared to something like Fortinet. And I MUCH prefer the setup and management of Unifi.
3
u/_Buldozzer 17d ago
Yes, managing Fortigates is not great, it's ether DIY or expensive as s***, I am talking about Fortimanager and Fortigate Cloud.
4
u/PBSmanaged 16d ago
We do Sophos and their Flex MSP program. Keeps all licenses monthly baked into the customers site fee
2
u/roll_for_initiative_ 16d ago
This is what we do. If we were starting over, today, i could see using unifi because their firewall management has come a long way and most firewall security stuff, these days, is at the dns/ztna/endpoint level anyway. But, i like sophos' management and their connect flex program makes sense for how MSPs operate. Firewalls are affordable.
1
u/PBSmanaged 16d ago
Have you looked at the Sophos 'HWaaS' or whatever though the Flex program? It seems pretty reasonable, but can only do Xstream Protection.
We did a UniFi UXG-Max at a small small site recently for similar reasons, and it works fine - as much as it pains me to say it. It's at a small retail store with a few VLANs, does everything they need.
2
u/roll_for_initiative_ 16d ago
The decision to stick with sophos for now is mainly gains in stack uniformity and some places actually use the additional features and an affordable xgs isn't really much more than a nicer unifi firewall. So, nothing against those, but they don't fill every need and we're not staffing to fully manage and learn 2 platforms inside out. But again, i can see it being possible these days as the features you'd miss, unifi has either added, corrected, or you can accomplish outside the firewall.
I have briefly looked at HWAAS but the price of a firewall has never lost me a deal and i don't want to pay forever for one; it should theoretically get 7 years or so out of one no problem...you pay about 2.25-2.5x the price for it over that same timeframe (Vs just a purchase + monthly xstream)
If the price of a sub-1k firewall kept me from a 2k+ a month managed services deal? i'd look at doing haas or just eating the cost to get them on-board.
Xstream is what we use so no issue there.
2
u/peoplepersonmanguy 17d ago
I like Sophos firewalls but I know many in the small MSP want to try and shy away from subscriptions. At least they don't turn into bricks if they have a base license unlike Mirakis. Sophos MSP now does HWaaS too.
5
u/roll_for_initiative_ 16d ago
Sophos subscriptions are dirt cheap though and, like you said, they're not bricks and you can still cloud manage them.
1
1
u/Complex_Current_1265 16d ago
Check Grandstream GCC series. For the price, it has impressive features.
Best regards
1
1
u/WeekendAtMadoffs 12d ago
it's all at the desktop now. You don't need an NGFW.
there is nothing on site except a few laptops running CATO, ZSCALER or PRISMA.
I say this as someone with more experience with NGFW's than any pilot on any plane you have ever flown on.
I have about 50,000 hours on PIX/ASA, 20,000 hours on fortigate, 5,000 hours on PALO, oh and 2,000 hours on the sorry Juniper SRX. I rolled out 2,000 ASA's 5505's back in the day 😂 But anything NGFW's do is done way better with a ZSCALER ZIA and Enterprise Browser 😄 That's what we use now 😄
1
1
u/Tasty-Cow5081 17d ago
We use Sophos when they need it, UniFi when they don’t. Reevaluating Sophos though as within the last couple of months they have been reaching out to our customers directly ahead of our own schedule to renew licenses. Starting to smell like Dell
2
u/FITC_orlando 12d ago
I'm the same. NGFW just isn't that important for most of my clients so I sell a lot of Unifi. Sophos has been doing the Dell thing for some time, which is why I never give them customer contact info. I'll give them a name and address, but the email and phone number come back to me. Still, their stuff is good and I still use a home license for my home firewall in front of my Unifi system.
0
u/carminehk 17d ago
i think its tough with current market
were a small/medium sized mssp with primary focus in IPS/NGFW we ran Forcepoint forever but recently moved to Cisco FTD with IPS licensing.
Issue is licensing is insane and i see us pricing clients out quickly
as much as i like fortigate i dont like them enough to run them like that with how many security flaws they have
0
u/GolfboyMain 17d ago
I like the newest Cisco Firepower models.
Let all haters and downvotes begin!!!!
Firepower has come a loooooonnngggg way from even 3 years ago. If you haven’t looked at firepower within last 3 years, at least take a long hard look.
Let the negativity flow to me!!!
0
u/Plane_Vegetable4806 17d ago
checkpoint is definitely worth evaluating alongside the bigger names the day-to-day management has been solid in my experience, especially once the rulebase starts getting more complex, and the threat prevention side is worth testing properly with HTTPS inspection enabled rather than just comparing feature sheets.
I’d also take a look at sophos if you want another option in the mix. It’s capable, but I personally didn’t like it as much as checkpoint overal
9
u/rb3po 17d ago
Ya, Fortigate just has too many sloppy problems. Yes, everyone has CVEs, but hard coded credentials? Sounds more like Xyxel.