Sizing: ignore the headline number
Every datasheet quotes a firewall throughput figure. Almost none of them are achievable in production. The headline is usually IMIX firewall throughput with no IPS, no SSL inspection, no app control, and no logging. Once you turn on the features you bought the box for, real throughput drops to 20–40% of the headline. SSL/TLS inspection in particular punches throughput down to roughly a quarter — and most internet traffic in 2026 is encrypted, so if you're not inspecting TLS, you're not getting NGFW value.
Practical sizing rule: take your aggregate WAN bandwidth, multiply by 1.5x for headroom, and choose a model whose Threat Prevention or NGFW throughput (with IPS + AV + app control + TLS inspection enabled) exceeds that. For a 1 Gbps fibre on a 50-user office, that means a box rated at 1.5 Gbps NGFW throughput minimum.
Licensing models: where the real cost lives
Hardware capex is roughly 30% of total cost of ownership over five years; subscriptions and renewals are the other 70%. Vendors structure subscriptions differently:
- Fortinet: "FortiGuard Enterprise Protection" or "Unified Threat Protection" bundles — choose UTP for SMB, Enterprise for those needing CASB/DLP
- Sophos: "Standard Protection" or "Xstream Protection" — Xstream adds TLS inspection at line rate and is required for serious use
- Cisco Meraki: "Advanced Security" or "SD-WAN Plus" license tied to the MX appliance — license expiry effectively bricks the device
- WatchGuard: "Total Security Suite" — single all-inclusive license that competes well on transparency
- Kerio Control / GFI: per-user licensing with optional anti-spam and content filter add-ons — favours small offices
Brand head-to-head
Fortinet FortiGate
The market share leader for SMB and mid-enterprise. Best raw NGFW performance per euro thanks to the custom SPU/NP ASICs, deep ecosystem (FortiSwitch, FortiAP, FortiClient, FortiAnalyzer), and the most generous SD-WAN capabilities at the entry tier. Downsides: the FortiOS UI has a steep learning curve, and the licensing matrix can be opaque for first-time buyers.
Sweet spot: 60F for 25-user offices, 80F for 50–100 users, 100F for 100–200 users, 200F/201F for 200+ users with heavy TLS inspection.
Sophos XGS
Best-in-class management UI and reporting. Xstream Protection includes TLS 1.3 decryption at line rate and DPI-based app identification. Tight integration with Sophos Central for unified endpoint + firewall management — a real differentiator for MSPs.
Sweet spot: XGS 116 for 25-user offices, XGS 136/146 for 50–100, XGS 166/2100 for 100–250.
Cisco Meraki MX
The cloud-managed dashboard is unmatched for multi-site SMBs and MSP-managed customers. Auto-VPN spins up a mesh between sites in literally minutes. SD-WAN is included in the Advanced Security license. The downside is the throughput-per-euro: Meraki costs more than the equivalent FortiGate or Sophos at every tier, and license expiry effectively disables the appliance.
Sweet spot: MX67/MX68 for branch offices, MX85 for headquarters, MX95/MX105 for larger sites or hub-and-spoke.
WatchGuard Firebox
Underrated. The Total Security Suite license is the most transparent in the market — one SKU, all the features. Strong reporting via WatchGuard Dimension and good multi-WAN failover. The recent T-series and M-series refresh has restored hardware-throughput competitiveness with Fortinet and Sophos.
Sweet spot: T25 for 10-user offices, T45 for 25-user, T85-PoE for branch with integrated switching, M290/M390 for HQ.
GFI Kerio Control
Per-user-licensed firewall popular in EU SMB, hospitality, and marine. The NG-series appliances (NG100, NG300, NG500, NG520) compete on simplicity rather than feature breadth — easier to deploy than FortiGate, cheaper to run than Meraki. Includes site-to-site VPN, IPS via Snort, content filtering, and bandwidth management.
Sweet spot: NG100/NG300 for 10–50 users, NG500/NG520 for 50–200 users including hospitality and small marine deployments.
Features that matter (and ones that don't)
Features worth paying for in 2026: IPS/IDS with hourly signature updates, TLS 1.3 inspection at line rate, DPI-based application control, geo-blocking, DNS filtering, IPv6 dual-stack support, and SD-WAN with multi-WAN failover and active-active load balancing.
Features oversold by marketing: "AI-powered" threat detection (most are heuristics rebranded), "zero-trust" rebranded VPN clients (your endpoint posture is what matters, not the firewall), and "sandbox" detonation (genuinely useful but usually a separate paid product).
Deployment considerations
High availability: active-passive HA pairs are now table stakes for businesses where the internet outage costs money. Every brand listed above supports it at the SMB tier — but you must order two units and the appropriate licensing.
Cabling and SFP modules: many SMB buyers order the firewall and forget the optics. If you have a 10G fibre handoff from the ISP, you need 10G SFP+ modules in the firewall — check compatibility (Cisco-coded vs FortiNet-coded vs generic) before ordering.
Rack vs desktop: anything above the smallest tier ships rack-mountable. Specify the rack ears if you need them; some come standard, some are an extra SKU.
Where to buy in the EU
Firewall procurement in the EU has three failure modes: grey-market US-spec units shipped without ETSI radio firmware (a problem with FortiGate-AP combos), expired or in-transit licenses (a Meraki box without an Advanced Security license is a paperweight), and out-of-stock during the September refresh cycle when every IT department renews at once.
FUSE stocks the full SMB firewall range from Fortinet, Sophos, Cisco Meraki, WatchGuard, and GFI Kerio across EU warehouses in Malta, Poland, Netherlands, and Germany — with multi-warehouse stock visibility before you place the order.
Frequently asked questions
How do I size a firewall for my office?
+
Multiply your aggregate WAN bandwidth by 1.5x for headroom. Choose a model whose NGFW or Threat Prevention throughput (measured with IPS + AV + app control + TLS inspection enabled) exceeds that. For a 1 Gbps fibre on a 50-user office, look for a box rated at 1.5 Gbps NGFW throughput minimum — for example FortiGate 80F, Sophos XGS 136, Meraki MX85, WatchGuard M290, or Kerio NG500.
Is FortiGate or Sophos better for SMB?
+
FortiGate wins on raw NGFW performance per euro and SD-WAN capability. Sophos XGS wins on management UI, Xstream TLS inspection, and tight Sophos Central integration with endpoint products. For an MSP managing multiple customers, Sophos is often the simpler choice. For an in-house IT team that wants maximum capability per euro, FortiGate is usually the answer.
Why is Cisco Meraki more expensive?
+
The Meraki dashboard, Auto-VPN, and unified Catalyst+Meraki cloud management are real differentiators that justify a premium for multi-site or MSP-managed customers. For single-site businesses with in-house IT, FortiGate or Sophos delivers more raw capability per euro.
What is WatchGuard Total Security Suite?
+
WatchGuard's Total Security Suite is an all-inclusive subscription license bundled with the Firebox appliance. It covers IPS, gateway antivirus, application control, web blocker, spamBlocker, reputation defense, APT blocker, DNSWatch, and ThreatSync — eliminating the per-feature licensing complexity that's typical of competitors.
Does the Kerio NG520 support TLS inspection?
+
Yes, Kerio Control on the NG-series appliances supports HTTPS/TLS content filtering with a deployed CA certificate. Performance varies by model — the NG520 handles TLS inspection at line rate for typical SMB workloads up to several hundred users.
Do I need high availability?
+
If an internet outage costs your business meaningful revenue or productivity, yes. Active-passive HA pairs are now standard at the SMB tier across all major vendors — but you must order two appliances and the appropriate HA license, which doubles capex.
Where do I buy SMB firewalls in the EU?
+
FUSE stocks the full SMB firewall range from Fortinet, Sophos, Cisco Meraki, WatchGuard, and GFI Kerio across EU warehouses in Malta, Poland, Netherlands, and Germany — with multi-warehouse stock visibility, EU radio compliance (ETSI), and EU-resident technical support.
Browse Kerio Software on FUSE
Multi-warehouse EU stock from Malta, Poland, Netherlands, and Germany — with EU-resident technical support and ETSI-compliant regulatory-domain hardware.
Primary sources
Technical and regulatory claims in this guide are checked against these first-party references. Product availability and regional variants should still be confirmed before ordering.
