Try our new research platform with insights from 80,000+ expert users

Cato SASE Cloud Platform vs Juniper Contrail SD-WAN comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Sep 16, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Fortinet FortiGate
Sponsored
Ranking in Software Defined WAN (SD-WAN) Solutions
1st
Ranking in WAN Edge
1st
Average Rating
8.4
Reviews Sentiment
7.2
Number of Reviews
331
Ranking in other categories
Firewalls (2nd)
Cato SASE Cloud Platform
Ranking in Software Defined WAN (SD-WAN) Solutions
5th
Ranking in WAN Edge
5th
Average Rating
8.8
Reviews Sentiment
7.7
Number of Reviews
29
Ranking in other categories
WAN Optimization (1st), Cloud Access Security Brokers (CASB) (6th), ZTNA as a Service (4th), Secure Access Service Edge (SASE) (5th)
Juniper Contrail SD-WAN
Ranking in Software Defined WAN (SD-WAN) Solutions
14th
Ranking in WAN Edge
14th
Average Rating
7.4
Reviews Sentiment
6.6
Number of Reviews
6
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of May 2025, in the Software Defined WAN (SD-WAN) Solutions category, the mindshare of Fortinet FortiGate is 21.1%, up from 20.8% compared to the previous year. The mindshare of Cato SASE Cloud Platform is 6.9%, up from 6.2% compared to the previous year. The mindshare of Juniper Contrail SD-WAN is 0.9%, up from 0.9% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Software Defined WAN (SD-WAN) Solutions
 

Featured Reviews

EhabAli - PeerSpot reviewer
Efficient, user-friendly, and affordable
In the past, NSS Labs was utilized to test files and verify the numbers and datasheets. It would be beneficial to have an organization or testing lab that can verify the numbers in our datasheets since changes are frequently made, which can be inconvenient for review. For instance, when comparing different competitors such as Forcepoint, Palo Alto, and Check Point, the throughput or numbers in the datasheet may be lower than the actual numbers. Conversely, Fortinet typically reports very high numbers, but they cannot be replicated in the real world. Therefore, it would be advantageous for them to partner with a neutral testing organization such as NSS Labs to validate these numbers, thus providing more credibility and comfort to everyone regarding the accuracy of the datasheets. For the migration, everyone has a firewall in use and I am selling Fortinet. Typically, I am replacing another firewall. Previously, there was a tool available to convert configurations from one firewall, such as Palo Alto, to Fortinet, but this tool is no longer free. If it could be made free again, it would be very beneficial. This tool shows a lot of promise and is very good. Making it free would help many companies deliver their products in a more efficient and integrated way. It would also be more valuable to include the tool with the firewall package or license instead of having to pay extra for it. Paying extra puts more pressure on small companies to deliver the firewall and complete the configuration, especially if they have hundreds or thousands of policies. It's very painful to move through these policies line by line. The stability has room for improvement. When it comes to Secure SD-WAN, everything is fine. They are going the right way. SD-WAN is very promising. They can provide the SD-WAN solution separately, but they will not take this approach because even the smallest firewall can support the features, so there is no need to have a separate service or appliance. They are following the right steps, and there is nothing to be improved. Feature-wise, I'm really satisfied with the new release, and the features they have added. For now, it's fine.
Alexander Azikov - PeerSpot reviewer
Provide a seamless experience for end users with internet duplication feature
The setup and onboarding process is very straightforward - I'd rate it a ten out of ten for ease. We use CatoCloud as our cloud provider. They have points of presence, and we connect to the nearest one to our physical location. All the routing, inspection, and logic for what to route, block, or allow happens in the cloud, not on the local device. Our deployment took a couple of weeks because we installed the sites manually. If we had a team to help switch locally, it could have been done in a week. The deployment process is straightforward. We set up all the sites in their cloud system; then, they ship the sockets directly to the location or our main office. We connect the device to the internet, it gets activated, we assign it to a specific site inside the cloud, and it's online and ready to use. It's very easy.
Luis Corrochano - PeerSpot reviewer
A stable and scalable solution that helps to cut cost by reducing MPLs
My customers use the solution to have better control and knowledge about the applications inside ONE Access. It also helps them cut costs by reducing MPLs and using better internet access from FTTH.  The solution is expensive. Its support can be better.  The tool is stable.  The solution is more…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Fortigate represents a really scalable way of delivering perimeter network security, some level of layer 7 security, WAF, and also a way to create a meshed ADVPN solution."
"I think that the UTM features are the most value, as it truly protects my infrastructure."
"The most valuable feature is the SSL VPN, as it allows us to connect and it separates this product from other firewalls."
"The ease of setting the solution up is a valuable aspect for us."
"The most valuable features of Fortinet FortiGate are the ease of use and the UI. It has always provided me with what I needed. I have no need for additional costs that other solutions have, such as Sophos."
"With FortiClient, you can easily connect when you are home, check out what you want to do, and connect to your network when you are not at work. You can switch on servers and you can check what is wrong."
"Unified Threat Management (UTM) features."
"The multi-tenancy feature is most valuable. It integrates very well with FortiManager and FortiAnalyzer."
"The most valuable features of Cato Networks are the always-on VPN for remote workers and centralized management. Additionally, web filtering and antivirus are good."
"It's a cloud-based solution that integrates well with everything."
"The visibility control and security aspects are amazing."
"It's a pretty straightforward solution."
"When I first encountered Cato, I didn't know how to use it, but after a week of training, I could onboard our systems to it, so the solution was easy to learn and navigate."
"The most valuable feature of Cato Networks is the CASB and the documentation is useful."
"The query and the SD-WAN are useful features of the solution."
"The product is very simple, and everything can be done very quickly."
"It gives you that level of visibility to understand what's going on between layer four and layer seven."
"I've worked with several SD-WAN solutions over the past few years, and the product felt more like an automated provisioning tool. Unlike solutions from Palo Alto or other SD-WANs orchestrated by a SaaS solution, Juniper Contrail SD-WAN already had the files and built their SaaS to orchestrate the configuration. Initially, you didn't do much, but then it started adding some routing capabilities."
"It supports desktop management, network management, and SD-WAN policies."
"The support is very good from Juniper and from the local distributors."
"My customers use the solution to have better control and knowledge about the applications inside ONE Access. It also helps them cut costs by reducing MPLs and using better internet access from FTTH."
"The solution is more specific about what's happening since it explains where the problem may lie and points out areas where there is a problem. So, we like that it provides more visibility."
 

Cons

"The solution is very expensive."
"One of the features that I would like to have is to do with endpoint production, it should be integrated. For example, the firewall gets notified of any kind of forensic event that needs to be done, such as if there is a ransomware attack and how it originated, all those records have to be available from the firewall, which is not."
"Sometimes you do need to know some CLI commands, so it's a bit harder for technicians or new people that don't know it."
"They can do more tests before they release new versions because I would like to be more assured. We had some experiences where they release something new and great, but some of the old features are disabled or they don't work well, which impacts the product satisfaction. The manufacturer should be able to prove that everything works or not only that it might work. This is applicable to most of the other services, software, and hardware companies. They all should work on this. We cannot trust every new release, such as a beta release, on the first day. We wait for some comments on the forums and from other companies that we know. We always wait a few weeks before we use the updated version. They should also extend the VPN client application, especially for Linux versions. Currently, it has an application for Linux devices, but it doesn't work the way we want to connect to the VPN. They use only the old connection, not the new one. They have VPN client applications for Windows and Mac, but they can add more useful features to better manage the devices and monitor the current health of each device. Such features would be helpful for our company."
"They should make the rule sets more understandable for the end user. When you're trying to explain to somebody how a computer network is secured, sometimes it's difficult for an end user or customer to understand. If there was a way to make the terminology more accessible to the end user, the set up could be easier. They should translate the technical jargon to an easily relatable and understandable conversation for the end user, the customer, that would be brilliant. Particularly in an environment where the IT structure is audited regularly, there's always pressure from the auditor to up the standards and up the security and you get your USCERT's that come out and there's a warning about this and the customer will want to lock out so much and when you apply it they run into issue where they can't search the internet or print to their remote office. Of course they can't print to your remote office, they just locked it up. They should make the language more understandable for the customer. If there's a product out there that made the jargon understandable to John Q. Public, I would buy that."
"There are some problems that support cannot give you a logical reason as to why it happened. For example, I had a case where I was dealing with a WhatsApp application that was giving issues. Technical support gave more than one reason it could be giving issues, but none of them solved the problem. Eventually I solved the problem, but it was far from the solutions that support had given."
"The pricing could always be better."
"Scalability for Fortinet FortiGate needs to be improved. SD-WAN security for this solution also needs some improvement."
"They can't do one-to-one NAT (Network Address Translation) in AP (their access point), and that is something that Palo Alto can do."
"I am located in South Korea, and I can say that most people here have no idea about Cato Networks. I think Cato Networks should promote its network services in various countries."
"The tool needs to be more granular. Its reports are not very in-depth."
"There isn't much to improve as we have a close relationship with them, providing information for research and development."
"The tool should improve its interface."
"The different languages in the user interface should be enhanced."
"There's no principal in Malaysia, only a distributor."
"I'd rate Cato SASE Cloud Platform's pricing as about five or six out of ten. It's not the cheapest solution, but it is cheaper than Palo Alto and even VeloCloud."
"The only issue was the switch we got, which was a little problematic because it was PoC equipment, and we had a little problem with that."
"The solution is expensive. Its support can be better."
"The solution installs similarly to competitors. It is not more difficult or easier. However, it could be easier and take less time for the installation."
"Implementing new branches or changing existing ones in Juniper Contrail SD-WAN wasn't as straightforward as with other solutions like Meraki SD-WAN, which is almost plug-and-play with its zero-touch provisioning. In Juniper Contrail SD-WAN, it was more challenging."
"Areas for improvement in the Juniper Contrail SD-WAN solution include the on-premises deployment process."
"The training could be better. When it comes to the demo dashboard capability, I feel like it could be much easier for our customers to use. Our last customer complained about this."
 

Pricing and Cost Advice

"The price is fair for what we get with FortiGate."
"Its price is affordable and lesser than Cisco. Cisco is expensive. In terms of licensing, there is only one issue. If a customer's license has expired a month ago and they do the renewal after one month, Fortinet renews the license from the start of the previous month. The activation of the product is done from the previous month, not from the date of renewal. The customers usually shout and complain that because they are paying today, the renewal should start from today. The support contract renewals or licensing should be renewed from the date of renewal, but Fortinet starts from the day it had expired. It is a loss for customers. They might have had some problems because of which they did not take the license one month before. Fortinet should work on this. Cisco doesn't do this. Cisco always starts from the day they apply for the license."
"This is not a cheap solution but it isn't expensive, either. It's a good solution for the right price."
"It was worth the money overall. It's good value."
"I would say that all things considered, the pricing is pretty good."
"I give the pricing a nine out of ten."
"In the Asian economy in which we operate, FortiGate is expensive."
"Its pricing is good. The advantages of Fortinet FortiGate over its competitors include good pricing and meeting our requirements at a lower cost."
"The solution's pricing is flexible."
"You pay yearly based on the speed of your network. If you increase the speed of your network, you increase the cost for your throughput. It is by bandwidth for the most part and then licenses for VPN. There is some per-seat licensing for VPN access, but the majority of it is minimal. It is like $30 a year per client. The rest is based on how much bandwidth you'll use. You pay for that upfront for the year, and if you have to increase it, you increase it, and then they let you send more data through. There are no additional costs in addition to the standard licensing fees."
"I rate the price of Cato Networks a four out of five."
"I'd rate Cato SASE Cloud Platform's pricing as about five or six out of ten. It's not the cheapest solution, but it is cheaper than Palo Alto and even VeloCloud. We've been working with them for a while and have significant discounts. Our licensing costs vary because we keep adding sites, but it's about 280 per month per site. This includes additional features beyond the base product, starting at around 200."
"The price is not an issue for us, as it is priced more competitively than some other vendors."
"The pricing is on the higher side, almost an eight out of ten."
"The platform is expensive."
"The solution is reasonably priced since Cato Networks provides features like SASE and monitoring, which I am very happy with currently."
"The licensing structure is very flexible."
"They are neither very expensive nor cheap. So, we can consider its pricing somewhere in the middle."
"The cost of the solution is a little expensive. The hardware is a one-time purchase fee and the software is purchased on an annual basis. There are additional costs for other software features that are available which are on an annual basis, such as extra capacity."
report
Use our free recommendation engine to learn which Software Defined WAN (SD-WAN) Solutions solutions are best for your needs.
850,671 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Educational Organization
20%
Computer Software Company
14%
Comms Service Provider
7%
Manufacturing Company
6%
Computer Software Company
26%
Manufacturing Company
11%
Financial Services Firm
8%
Comms Service Provider
6%
Educational Organization
33%
Computer Software Company
13%
Financial Services Firm
8%
Real Estate/Law Firm
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

Which is the better NGFW: Fortinet Fortigate or Cisco Firepower?
When you compare these firewalls you can identify them with different features, advantages, practices and usage a...
What is the biggest difference between Sophos XG and FortiGate?
From my experience regarding both the Sophos and FortiGate firewalls, I personally would rather use FortiGate. I know...
What are the biggest technical differences between Sophos UTM and Fortinet FortiGate?
As a solution, Sophos UTM offers a lot of functionality, it scales well, and the stability and performance are quite ...
What do you like most about Cato Networks?
The solution is a simple WAN solution. We've onboarded the socket on the Cato platform, and it provides connectivity....
What is your primary use case for Cato Networks?
I use Cato SASE Cloud Platform primarily as a single vendor, integrated SD-WAN plus SASE solution.
What advice do you have for others considering Cato Networks?
I rate Cato SASE Cloud Platform at 9.5 out of 10. There is always room for improvement, especially in edge security f...
What do you like most about Juniper Contrail SD-WAN?
I've worked with several SD-WAN solutions over the past few years, and the product felt more like an automated provis...
What is your experience regarding pricing and costs for Juniper Contrail SD-WAN?
My advice regarding setup costs, pricing, and licensing for Juniper Contrail SD-WAN would be to carefully evaluate an...
What needs improvement with Juniper Contrail SD-WAN?
Implementing new branches or changing existing ones in Juniper Contrail SD-WAN wasn't as straightforward as with othe...
 

Also Known As

FortiGate 60b, FortiGate 60c, FortiGate 80c, FortiGate 50b, FortiGate 200b, FortiGate 110c, FortiGate, Fortinet Firewall
Cato Networks
Contrail SD-WAN
 

Overview

 

Sample Customers

Amazon Web Services, Microsoft, IBM, Cisco, Dell, HP, Oracle, Verizon, AT&T, T-Mobile, Sprint, Vodafone, Orange, BT Group, Telstra, Deutsche Telekom, Comcast, Time Warner Cable, CenturyLink, NTT Communications, Tata Communications, SoftBank, China Mobile, Singtel, Telus, Rogers Communications, Bell Canada, Telkom Indonesia, Telkom South Africa, Telmex, Telia Company, Telkom Kenya
Paysafe, AdRoll, Pet Lovers Centre, Arlington Orthopedics, Humphreys & Partners Architects
Allied Pinnacle
Find out what your peers are saying about Cato SASE Cloud Platform vs. Juniper Contrail SD-WAN and other solutions. Updated: April 2025.
850,671 professionals have used our research since 2012.