No more typing reviews! Try our Samantha, our new voice AI agent.

Check Point Cloud Firewall (formerly CloudGuard Network Security) vs Sangfor NGAF comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Apr 15, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Fortinet FortiGate
Sponsored
Ranking in Firewalls
1st
Average Rating
8.4
Reviews Sentiment
6.8
Number of Reviews
591
Ranking in other categories
Secure Web Gateways (SWG) (2nd), Intrusion Detection and Prevention Software (IDPS) (1st), Software Defined WAN (SD-WAN) Solutions (1st), WAN Edge (1st), ZTNA (1st), Unified Threat Management (UTM) (1st)
Check Point Cloud Firewall ...
Ranking in Firewalls
8th
Average Rating
8.6
Reviews Sentiment
7.4
Number of Reviews
167
Ranking in other categories
Managed Security Services Providers (MSSP) (1st), Software Defined WAN (SD-WAN) Solutions (5th), Cloud and Data Center Security (6th), WAN Edge (3rd), Unified Threat Management (UTM) (4th)
Sangfor NGAF
Ranking in Firewalls
22nd
Average Rating
8.0
Reviews Sentiment
6.5
Number of Reviews
34
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of May 2026, in the Firewalls category, the mindshare of Fortinet FortiGate is 16.0%, down from 21.6% compared to the previous year. The mindshare of Check Point Cloud Firewall (formerly CloudGuard Network Security) is 2.1%, up from 0.4% compared to the previous year. The mindshare of Sangfor NGAF is 1.1%, down from 1.2% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Firewalls Mindshare Distribution
ProductMindshare (%)
Fortinet FortiGate16.0%
Check Point Cloud Firewall (formerly CloudGuard Network Security)2.1%
Sangfor NGAF1.1%
Other80.8%
Firewalls
 

Featured Reviews

Abhinandan Yadav - PeerSpot reviewer
Network Security Engineer at a consultancy with 51-200 employees
Unified security and sd-wan have improved uptime and cut wan costs for multi-site branches
Users report stability issues in certain versions, which requires regular updates. Real-world attacks have also highlighted the need for urgent patching of vulnerabilities.Fortinet FortiGate, while a powerful and feature-rich web firewall, could improve in areas like firmware stability, documentation, and ease of use. The learning curve can be steep for some users. For beginners, support quality can vary, and frequent updates with occasional vulnerabilities call for careful patch management. However, once Fortinet FortiGate is configured, it remains highly reliable and efficient. Customer support needs improvement, as I find it very slow, with reports from other users reflecting that customer support is inadequate.
Viral Shaa - PeerSpot reviewer
IT Security Analyst at Eos Energy Enterprises, Inc.
Cloud security has unified hybrid policies and now protects critical energy workloads continuously
I would say Check Point Cloud Firewall (formerly CloudGuard Network Security) is valuable due to its hybrid cloud security features. It offers granular policy management across the on-premises and cloud environments, giving administrators consistent control for configuration drift. We need to change the policy and the inbound and outbound traffic settings, indicating what traffic must be blocked or allowed, and this capability with Check Point provides significant input into our security strategy. Check Point Cloud Firewall (formerly CloudGuard Network Security) provides unified security management across both hybrid clouds and on-premises environments. Unified security management affects my security operations positively, as we maintain critical systems on the cloud that require strong security and air gap networks. This cloud-native routing and policy installation helps close gaps in protecting critical applications and environments from exposure to the public cloud. From an administrator's perspective, Check Point Cloud Firewall (formerly CloudGuard Network Security) enhances our organization with clearer and more intuitive logging, making decisions easier to understand without deep investigation. In the CloudGuard UI, I can see which threats have triggered alerts, and this information is available on the unified dashboard that provides details of the threat analysis upon alert. As a small team, we log into the console to check specific alerts for high or low network usage or machine shutdowns. If needed, I tune the configuration policy, and the visualizing tools with reporting functionality simplify tracking changes made on the firewall, including the relevant source IP or device names. We ingest logs into our SIEM for detailed oversight, which allows us to monitor any administrative changes. Check Point Cloud Firewall (formerly CloudGuard Network Security) has significantly reduced our organizational risk. We clearly understand our threat landscape and the associated risks. Onboarding the CloudGuard solution directly into our cloud environment has significantly lowered the risks throughout the network and it is easy to launch. When we assess our security posture with third-party assessments, we gain granular visibility into our network pre- and post-CloudGuard installation, showing how we have addressed significant risks and secured vulnerabilities.
Zaid Farooqui - PeerSpot reviewer
CIO at Indus Motor Company
Enhanced threat detection with integrated security features and good support
We are using application firewalling, WAF, and SD-WAN. The capabilities are mostly within the box. For example, you will get web application firewall WAF as part and parcel of this. SD-WAN is also bundled. It integrates with their SIEM and SOAR solutions very nicely. Lastly, the pricing point is very cost-efficient as well.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Fortinet provides us all that we need for security."
"Fortinet FortiGate is user-friendly and affordable."
"The most valuable feature is the FortiManager for centralized management."
"The best features of this tool include threat protection, email filtering, and web filtering, and FortiAnalyzer's integration with the firewall and FortiSASE is beneficial."
"It's safe and secures my network and applications in some sites."
"The features that I have found most valuable are that it is good to use, and most importantly, the pricing. The customer especially likes the discount when they trade up or something like that."
"We saved a bundle by not needing all the past appliances from an NGFW."
"The most valuable feature is the bundled subscription, which is IPS, TV and web filtering."
"We have unified management. It is one of the advantages of this product."
"The URL filtering provides a lot of added value compared to the Azure Firewall."
"I like the firewall and the virtual machine. I also like that it's compatible with Amazon Web Services and Azure."
"The most valuable features are the ease of administration with the cloud management extension and the cloud licensing model."
"The number of options it gives for deployment or security is valuable. When it comes to security, it has a feature that is super awesome for zero-day-based attacks. Their IPS is also very capable. We tested other firewalls, and we understood that it is the best one in the market."
"Workflows across the company ecosystem have can flow smoothly without experiencing any challenges."
"CloudGuard Network Security has helped reduce our organizational risk by about 15%."
"The most valuable feature is that we can use the same manager server that we use on our own Check Point firewalls. We integrated CloudGuard on that manager and we can use the same kind of protections that we use on the on-prem firewalls, like the IPS and antivirus policy. We can have the same kind of protection on the Cloud environment that we have on-premise."
"It enables us to not only detect but also prevent various types of incoming threats, allowing us to take appropriate corrective actions and exercise control over the network."
"I think Sangfor NGAF is more valuable than Cisco products because of its simplicity and ease of management. If I compare it with Palo Alto and Cisco, both are quite complex products. And if I compare it with FortiGate firewalls from Fortinet, I have also used all these products. Fortinet and Sangfor NGAF are similar products because the applications behind the application and policy layers are almost identical."
"It is a stable solution."
"It offers application control features."
"Sangfor NGAF specializes in ransomware detection and helps to protect our network from ransomware threats and malware."
"Sangfor NGAF's standout feature is its powerful application control, enabling precise restrictions on mobile user access to approved applications."
"Sangfor has the best capabilities for securing connections, securing web browsers, securing servers, and general threat protection."
"We use Sangfor NGAF primarily for security, which has helped save our files from being encrypted by ransomware."
 

Cons

"The web interface could be made better."
"The firewall engine is not so strong as of now, in my opinion... My second concern is that, while they have Zero-day vulnerability and anti-malware features, the threat engine needs to be strengthened, its efficiency can be increased."
"Some features in Fortinet FortiGate need improvement as we discover when calling support that certain actions must be done from the command line."
"There are SD-WAN network monitoring, SD-WAN features, Industrial Databases, Internet of Things, Detection, etc., however, we do have not licenses for those features. We thought that if you bought a product, you should have all of the features it offers. Why should you need to make so many extra purchases to enable features? They should have one price for the entire offering."
"I could not configure sFlow from the FortiGate graphical user interface. I realized that the sFlow configuration is available only from the CLI, and discovered that sFlow is not supported on virtual interfaces, such as VDOM links, IPsec, or GRE."
"I would like to see improvements with the antivirus and IPS as they are not working properly all the time."
"I would like some automated custom reporting."
"The most important feature to have is zero trust, which is lacking in Fortinet FortiGate IPS."
"The pricing is sometimes more expensive than some vendors."
"We have a rule that pops up from nowhere which we didn't create; when we restart our Virtual System firewall, it creates a rule which messes up all our internet connection."
"I find troubleshooting a bit challenging with Check Point Cloud Firewall (formerly CloudGuard Network Security); one area needing improvement is log clarity, as sometimes policy installation takes longer than expected, and resolving cloud-native routing conflicts requires advanced knowledge due to the differences in how AWS and GCP operate."
"CloudGuard Network Security's pricing is expensive. We have encountered issues with its licensing."
"Greater automation would reduce the need for manual configuration and management."
"Our environment basically expanded to such a large scale that it wasn't feasible for us to use CloudGuard in our multiple-account production environment."
"There is room for improvement in addressing bugs and support issues."
"Improvements needed include better integration with Azure features to match on-premises capabilities."
"Sangfor NGAF could improve the policies and default criteria. They could be much better."
"Sangfor could improve their interface capacity on the 5100 series model and upgrade their hardware from one gig to 10 gig. This would improve the overall throughput."
"The firewall system needs gradual improvements because there are more threats and challenges in the world every day."
"I believe that IAM and NGFW need to merge into a single box, instead of there being two separate box solutions."
"I would be happy if Sangfor developed a firewall designed specifically for home use, as well as for small businesses such as clinics and so on. A household version of the Sangfor firewall for your personal computer or laptop would be ideal, in my opinion."
"They need to improve their research team and they need to study their data to analyze it and build the product."
"Scalability for any network device is not very easy in terms of vertical scalability."
"The interface and user experience are horrible."
 

Pricing and Cost Advice

"I give the pricing of the solution a six out of ten."
"If you compare Fortinet FortiGate with Sophos and other firewall products available in the market, this solution is affordable."
"Its pricing is good. It's average or normal as compared to Palo Alto and Check Point firewalls."
"The price is fair compared to the other competitors."
"If you are looking for a quality product, it will come at a higher price. Expecting them to be significantly cheaper is unrealistic. In terms of pricing, it is a bit costly. However, the functionality and support offered are worth it."
"As far as I'm aware, in our case, it's just a yearly pricing arrangement with no additional licensing costs."
"Fortinet is reasonable in pricing and licensing. Overall, FortiGate is affordable. The licensing fee can be a little high, depending on the budget for your project."
"Fortinet bundles FortiGate with other products and because of this, the price is a little expensive to some SMB enterprises."
"We are using our BYOL. We are using our existing Check Point discounts to work with licensing. Overall, it is very competitive. Its pricing is reasonable to me."
"The pricing is pretty high, not just for your capital, for what you have to pay upfront, but for what you pay for your annual software renewals as well, compared to a lot of other vendors. Check Point is near the top, as far as how much it's going to cost you."
"It is an expensive product, but when you realize that you need it, it does not feel so expensive. We have had a good experience with them as partners. They have helped us with designing and having good architecture and the best equipment at the best prices. We find it a good deal."
"Licensing is simply by the number of hosts that you are looking to protect within your environment. It makes it much easier to ensure that you are covering your environment."
"Although I don't have specifics for pricing, based on my overall experience, I can conclude that Check Point provides the best pricing when comparing to other vendors."
"The product's licensing costs are yearly."
"I know that we have an enterprise agreement with Check Point. That gives us some benefits, but I do not have more information about that."
"The tool's pricing is not cheap."
"The pricing is reasonable."
"The solution has a TCO that is 32% to 50% less than Sophos, Fortinet, and SonicWall."
"For four to five physical appliances for a licensed firewall, it costs approximately $4,000."
"It is one of the cheapest tools in the market."
"Price-wise, I would not consider Sangfor NGAF to be a cheap product. It is an expensive firewall solution, though not as expensive as something like Palo Alto, which is costly. However, the higher price point is justifiable given the feature set the tool provides that other firewalls may not offer in a single dedicated appliance."
"The license of Sangfor NGAF can be purchased at different interval lengths, such as annually or three years. They offer a range of packages to choose from, such as combo or hybrid packages. We are using the complete solution package which includes IM, NGF and SSL VPN, and WAF."
"The price falls in the mid-range, neither exceptionally low nor high."
"For over 2000 users, the cost is around 5000 to 6000 USD. If you want a web application firewall, you have to purchase an additional license for it."
report
Use our free recommendation engine to learn which Firewalls solutions are best for your needs.
896,467 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
10%
Comms Service Provider
10%
Manufacturing Company
9%
Financial Services Firm
7%
Outsourcing Company
10%
Computer Software Company
9%
Financial Services Firm
9%
Manufacturing Company
7%
Manufacturing Company
11%
Comms Service Provider
10%
Financial Services Firm
10%
Computer Software Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business367
Midsize Enterprise135
Large Enterprise193
By reviewers
Company SizeCount
Small Business71
Midsize Enterprise41
Large Enterprise79
By reviewers
Company SizeCount
Small Business15
Midsize Enterprise10
Large Enterprise10
 

Questions from the Community

Which is the better NGFW: Fortinet Fortigate or Cisco Firepower?
When you compare these firewalls you can identify them with different features, advantages, practices and usage a...
What is the biggest difference between Sophos XG and FortiGate?
From my experience regarding both the Sophos and FortiGate firewalls, I personally would rather use FortiGate. I know...
What are the biggest technical differences between Sophos UTM and Fortinet FortiGate?
As a solution, Sophos UTM offers a lot of functionality, it scales well, and the stability and performance are quite ...
What is your experience regarding pricing and costs for Check Point CloudGuard Network Security?
We have encountered a few subscription-based licensing models for the virtual gateway and security enablement. We hav...
What needs improvement with Check Point CloudGuard Network Security?
I find troubleshooting a bit challenging with Check Point Cloud Firewall (formerly CloudGuard Network Security); one ...
What is your primary use case for Check Point CloudGuard Network Security?
My usual use cases for Check Point Cloud Firewall (formerly CloudGuard Network Security) involve onboarding as an ene...
What is your experience regarding pricing and costs for Sangfor NGAF?
The licensing cost is quite high compared to other available firewalls in the market.
What needs improvement with Sangfor NGAF?
The cost of licensing is very high compared to other firewalls available here. There should be improvements in hardwa...
What is your primary use case for Sangfor NGAF?
We are hosting applications over the platform, including websites and NAT traffic from our side. Because it's deploye...
 

Also Known As

Fortinet FortiGate Next-Generation Firewall
CloudGuard IaaS, Check Point vSEC, CloudGuard IaaS, Check Point Virtual Systems, Check Point CloudGuard Network Security
Sangfor NGAF Firewall Platform
 

Overview

 

Sample Customers

Amazon Web Services, Microsoft, IBM, Cisco, Dell, HP, Oracle, Verizon, AT&T, T-Mobile, Sprint, Vodafone, Orange, BT Group, Telstra, Deutsche Telekom, Comcast, Time Warner Cable, CenturyLink, NTT Communications, Tata Communications, SoftBank, China Mobile, Singtel, Telus, Rogers Communications, Bell Canada, Telkom Indonesia, Telkom South Africa, Telmex, Telia Company, Telkom Kenya
Physicians Choice Laboratory Services, Helvetica Insurance
The Ministry of Science, Technology, and Innovation (Indonesia), Lawson, Inc. (Philippines), Universiti Sultan Zainal Abidin (Indonesia), TEK Automotive (Italy), etc.
Find out what your peers are saying about Check Point Cloud Firewall (formerly CloudGuard Network Security) vs. Sangfor NGAF and other solutions. Updated: April 2026.
896,467 professionals have used our research since 2012.