Firewall Sizing Guide 2026

Firewall Sizing Guide:
FortiGate vs Palo Alto vs SonicWall

Find the right firewall for your organization in minutes — and get competitive NET pricing that beats your current quote.

Get a Competitive Quote

How to Size a Firewall

Three numbers determine the right firewall model. Here's the math:

Raw Throughput
Internet speed × 1.5
Minimum baseline with no inspection
NGFW Throughput
Internet speed × 2.5
With SSL inspection enabled — use this number
IPS Throughput
Internet speed × 2.0
With intrusion prevention active

Pro tip: Always size to NGFW throughput, not raw firewall throughput. Raw throughput is a marketing number measured with all security features disabled — it's 3–5× higher than what you'll see with SSL inspection on.

Vendor Comparison

How the major firewall vendors stack up in 2026:

Fortinet FortiGate

Recommended

Best overall value — SMB to enterprise

40F · 60F · 100F · 200F · 400F · 600F · 900G

Palo Alto Networks

Enterprise

Best-in-class threat prevention & compliance

PA-410 · PA-440 · PA-450 · PA-1410 · PA-3440

SonicWall

Budget

Best budget option — K-12 & SMB

TZ270 · TZ370 · TZ470 · NSa 2700 · NSa 3700

Check Point

Security

Best for security-first enterprises

Spark 1600 · Spark 1900 · Quantum 6200 · 6800

Sophos XGS

Unified

Best for Sophos endpoint shops

XGS 87 · 107 · 136 · 2300 · 3300 · 4300

Cisco Meraki MX

Cloud

Best cloud-managed multi-site

MX67 · MX75 · MX85 · MX95 · MX250 · MX450

Not sure which model is right?

Use the free AI sizing tool — answer a few questions and get a specific model recommendation in under 2 minutes.

The tool will ask about:

User count & locations
Internet speed
SSL inspection needs
Compliance (PCI/HIPAA)
HA requirements
Current vendor

Click the chat bubble in the bottom right → say "help me size a firewall"

Frequently Asked Questions

How do I size a firewall for my organization?
Start with your internet speed and multiply by 2.5x to get the minimum NGFW throughput you need with SSL inspection enabled. Then factor in your user count, number of sites, VPN requirements, and any compliance needs like PCI-DSS or HIPAA. Size up one tier to account for growth.
What's the difference between firewall throughput and NGFW throughput?
Raw firewall throughput is measured with all security features off — a marketing number. NGFW throughput (with IPS, App Control, and SSL inspection enabled) is what you'll actually see in production. It's typically 3–5x lower than raw throughput. Always size to NGFW throughput.
FortiGate vs Palo Alto — which is better?
FortiGate wins on price/performance for SMB and mid-market. Palo Alto leads on App-ID granularity and compliance posture for highly regulated enterprises. For most organizations under 1,000 users, FortiGate delivers 90% of the security at 40–60% of the Palo Alto cost.
Do I need HA (high availability) for my firewall?
Yes, if downtime costs money. HA means two identical firewall units in active/passive or active/active mode — if one fails, the other takes over instantly. For any business-critical environment, always quote an HA pair.
How much does a firewall cost?
SMB firewalls (FortiGate 60F, SonicWall TZ370) range from $400–$900 hardware only. Mid-market (FortiGate 200F, PA-450) run $2,000–$8,000. Enterprise (FortiGate 600F, PA-1410) are $8,000–$30,000+. Add 20–25% annually for subscription licenses (IPS, App Control, SSL). Frankly quotes NET pricing — typically 15–30% below MSRP.
What is SD-WAN and do I need it?
SD-WAN lets you use multiple internet connections (fiber + 4G/5G) intelligently — routing traffic based on application type, latency, and cost. Fortinet's built-in SD-WAN is included free with FortiGate. If you have multiple sites or want to reduce MPLS costs, SD-WAN is worth enabling.

Ready to get a better price?

Frankly quotes NET pricing — typically 15–30% below MSRP. Submit your current quote and we'll beat it within 48 hours.

Get a Competing Quote