Try our new research platform with insights from 80,000+ expert users

Check Point CloudGuard Network Security vs Juniper Contrail SD-WAN comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Sep 16, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Fortinet FortiGate
Sponsored
Ranking in Software Defined WAN (SD-WAN) Solutions
1st
Ranking in WAN Edge
1st
Average Rating
8.4
Reviews Sentiment
7.2
Number of Reviews
330
Ranking in other categories
Firewalls (2nd)
Check Point CloudGuard Netw...
Ranking in Software Defined WAN (SD-WAN) Solutions
3rd
Ranking in WAN Edge
3rd
Average Rating
8.6
Reviews Sentiment
7.5
Number of Reviews
152
Ranking in other categories
Firewalls (8th), Managed Security Services Providers (MSSP) (1st), Cloud and Data Center Security (6th), Unified Threat Management (UTM) (6th)
Juniper Contrail SD-WAN
Ranking in Software Defined WAN (SD-WAN) Solutions
14th
Ranking in WAN Edge
14th
Average Rating
7.4
Reviews Sentiment
6.6
Number of Reviews
6
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of May 2025, in the Software Defined WAN (SD-WAN) Solutions category, the mindshare of Fortinet FortiGate is 21.1%, up from 20.8% compared to the previous year. The mindshare of Check Point CloudGuard Network Security is 1.4%, up from 0.6% compared to the previous year. The mindshare of Juniper Contrail SD-WAN is 0.9%, up from 0.9% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Software Defined WAN (SD-WAN) Solutions
 

Featured Reviews

EhabAli - PeerSpot reviewer
Efficient, user-friendly, and affordable
In the past, NSS Labs was utilized to test files and verify the numbers and datasheets. It would be beneficial to have an organization or testing lab that can verify the numbers in our datasheets since changes are frequently made, which can be inconvenient for review. For instance, when comparing different competitors such as Forcepoint, Palo Alto, and Check Point, the throughput or numbers in the datasheet may be lower than the actual numbers. Conversely, Fortinet typically reports very high numbers, but they cannot be replicated in the real world. Therefore, it would be advantageous for them to partner with a neutral testing organization such as NSS Labs to validate these numbers, thus providing more credibility and comfort to everyone regarding the accuracy of the datasheets. For the migration, everyone has a firewall in use and I am selling Fortinet. Typically, I am replacing another firewall. Previously, there was a tool available to convert configurations from one firewall, such as Palo Alto, to Fortinet, but this tool is no longer free. If it could be made free again, it would be very beneficial. This tool shows a lot of promise and is very good. Making it free would help many companies deliver their products in a more efficient and integrated way. It would also be more valuable to include the tool with the firewall package or license instead of having to pay extra for it. Paying extra puts more pressure on small companies to deliver the firewall and complete the configuration, especially if they have hundreds or thousands of policies. It's very painful to move through these policies line by line. The stability has room for improvement. When it comes to Secure SD-WAN, everything is fine. They are going the right way. SD-WAN is very promising. They can provide the SD-WAN solution separately, but they will not take this approach because even the smallest firewall can support the features, so there is no need to have a separate service or appliance. They are following the right steps, and there is nothing to be improved. Feature-wise, I'm really satisfied with the new release, and the features they have added. For now, it's fine.
Martin Raška - PeerSpot reviewer
Unification of security features strengthens network protection
The overall network security is good. It's big-picture, all in one bundle. It's valuable to have everything in one place instead of spreading across different products. Unified security management positively affects a company's security operations. They have one unified view of the security. I can connect multiple gateways to the management and have it in one place. I can have reporting and views in a single pane of glass on the consolidated platform. It's easy to use. The management is the best on the market. It's very easy to work with, read, understand, and navigate. It helps increase our customer's security posture. We can see in some cases CloudGuard improves our customers' posture overall.
Luis Corrochano - PeerSpot reviewer
A stable and scalable solution that helps to cut cost by reducing MPLs
My customers use the solution to have better control and knowledge about the applications inside ONE Access. It also helps them cut costs by reducing MPLs and using better internet access from FTTH.  The solution is expensive. Its support can be better.  The tool is stable.  The solution is more…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Its user interface is good, and it is always working fine."
"The flexibility and ease of configuration are the most valuable features."
"There are lots of features and most of them are deployed for internet security. Users are protected if they accidentally go to some malicious sites."
"We use a southern institution that's audited for IT security and the reporting that automatically comes off the unit makes it much easier to meet compliance standards and makes it easier as far as the amount of time that has to be spent to compile that information. If you get your reporting set up correctly when you initially set it up, you just select the one you want and hit print. The auditing trail on it is the best feature."
"UTM/NGFW features and FortiCloud for logs and backups are awesome."
"I find the ease of configuring specific policies to be the most valuable feature of the Fortinet FortiGate firewall."
"FortiGate's web and URL filtering are unlike any other firewall I've used. The functionality of URL filtering in those solutions is problematic because everything is encrypted, and firewalls can't break that encryption protocol. Fortinet has an SSL proxy, so the encryption is done before the packet ever leaves the FortiGate. The URL filter is definitely one of the most helpful features."
"Fortigate represents a really scalable way of delivering perimeter network security, some level of layer 7 security, WAF, and also a way to create a meshed ADVPN solution."
"We get good insights into security, and we are more secure because we have more insights than we would get from other products."
"Any kind of cloud environment anywhere can be protected through this effortlessly."
"Overall, it is an excellent solution, and I would rate it a ten out of ten."
"A unique architecture makes this product stand out from other solutions."
"It matches what we have on-prem. We kept the same management and the same functionality that we were having on-prem. It has simplified things for us because there is no new dashboard to touch."
"CloudGuard Network Security provides us with unified security management across hybrid clouds as well as on-premise."
"The product has allowed us to develop applications from the cloud - even with large environments and well-segmented security lines."
"The Identity Awareness blade and dynamic tagging in Azure are valuable because they make access management automatic. Instead of manually setting up access for each new resource, it happens automatically based on the same access policy. This dynamic setup is scalable."
"My customers use the solution to have better control and knowledge about the applications inside ONE Access. It also helps them cut costs by reducing MPLs and using better internet access from FTTH."
"The support is very good from Juniper and from the local distributors."
"It gives you that level of visibility to understand what's going on between layer four and layer seven."
"I've worked with several SD-WAN solutions over the past few years, and the product felt more like an automated provisioning tool. Unlike solutions from Palo Alto or other SD-WANs orchestrated by a SaaS solution, Juniper Contrail SD-WAN already had the files and built their SaaS to orchestrate the configuration. Initially, you didn't do much, but then it started adding some routing capabilities."
"The solution is more specific about what's happening since it explains where the problem may lie and points out areas where there is a problem. So, we like that it provides more visibility."
"It supports desktop management, network management, and SD-WAN policies."
 

Cons

"Fortinet FortiGate should improve the VPN tokens."
"The anti-malware engine could use an upgrade."
"The pricing could be a bit better, especially when you consider how they have the most basic offering priced."
"Difficult to add or define, and not that easy to configure and manage."
"The command line is complicated, and the interface could be better."
"Fortinet FortiGate could improve by having better visibility. Palo Alto has better visibility."
"Fortinet FortiGate could improve by having more capabilities for troubleshooting VPN connections. For example, I do get some feedback about the current status, but I could use some history and logging of important events. The information is logged in our Syslog server, but I could use that information from the device. If they could provide a GUI to have some more insight on what's going with my VPN would be useful."
"You do need some IT knowledge in order to effectively work with the solution."
"Making it even easier is a good way to improve it more. When it's easier to use, there are fewer mistakes."
"The deployment was not easy."
"CloudGuard functions just like any other firewall. It functions very well. The only thing that could maybe be improved would be to integrate some tools that are not integrated with the SmartConsole, like the SmartView Monitor that we need to open on a different application to access."
"Check Point CloudGuard Network Security needs to improve the management of the actual firewalls. Improvement is also needed for the consolidated UI of different security aspects."
"We have had occasional issues with two gateways that used to break or are broken. We are not sure yet."
"The relationship between AWS and Check Point could be better. We had issues related to the type of instance and how it interconnects with AWS or cloud-native solutions. We overcame the pain points that we had, and now, AWS is evolving in a way that will facilitate how Check Point works. Our pain points were minimized, but they were there."
"They can improve their security features to the next advanced level so that their efficiency in catching the malware can become 100%, and there is no scope for any data loss or leakage from the system due to any issue."
"The connection to the on-premises management requires using the CLI. It's not just a click, and you cannot edit in the management to prepare everything. You need to do it online and in real time. After that, you must execute a script, and then you should be happy that it appears in the management."
"The solution is expensive. Its support can be better."
"The training could be better. When it comes to the demo dashboard capability, I feel like it could be much easier for our customers to use. Our last customer complained about this."
"Implementing new branches or changing existing ones in Juniper Contrail SD-WAN wasn't as straightforward as with other solutions like Meraki SD-WAN, which is almost plug-and-play with its zero-touch provisioning. In Juniper Contrail SD-WAN, it was more challenging."
"The only issue was the switch we got, which was a little problematic because it was PoC equipment, and we had a little problem with that."
"The solution installs similarly to competitors. It is not more difficult or easier. However, it could be easier and take less time for the installation."
"Areas for improvement in the Juniper Contrail SD-WAN solution include the on-premises deployment process."
 

Pricing and Cost Advice

"The price depends on the size of the company. From the beginning, you just want to know the internet bandwidths, speed, and the number of users to be able to offer the right product and model. They have a lot of products in FortiGate according to the size of the company, like 200D and 300D."
"By default, they give SD-WAN along with the firewall. They don't have separate licensing for the SD-WAN functionality. However, they have security licenses that are sold separately on a subscription basis. Customers can consume these security features to protect their users from internet traffic."
"For the price, I'd rate it a ten because it's very cost-effective."
"The license for Fortinet FortiGate is affordable in my country."
"The pricing depends on the FortiGate model we are using, ranging from $3,000 to $20,000 US dollars."
"It has been two years. I don't remember the actual price, but it was affordable. We buy the boxes and then use the license for three years."
"The initial setup is super straight forward and as far as the licensing goes for the small product that we have, the pricing was pretty competitive. It wasn't as simple and as cheap as a SonicWall but for the service we would get it was a good price."
"The pricing is perfect."
"I know that we have an enterprise agreement with Check Point. That gives us some benefits, but I do not have more information about that."
"We pay approximately ‎€150,000 ($166,000 USD) per year."
"It is an expensive product, but when you realize that you need it, it does not feel so expensive. We have had a good experience with them as partners. They have helped us with designing and having good architecture and the best equipment at the best prices. We find it a good deal."
"There is flexibility in the different licensing models that are offered."
"Check Point CloudGuard Network Security's pricing is far better than Palo Alto's because Palo Alto is very expensive."
"I like the flexibility because I am pretty sure you can use the same license on Azure or AWS. I forgot the name of the license, but there is a specific type you can use that lets you interchange them, and that is pretty good. I like that."
"It is more expensive than other solutions and would be more competetive in the market if it came down in price."
"I do not know the exact price, but it is fairly priced. It is neither cheap nor costly."
"They are neither very expensive nor cheap. So, we can consider its pricing somewhere in the middle."
"The cost of the solution is a little expensive. The hardware is a one-time purchase fee and the software is purchased on an annual basis. There are additional costs for other software features that are available which are on an annual basis, such as extra capacity."
"The licensing structure is very flexible."
report
Use our free recommendation engine to learn which Software Defined WAN (SD-WAN) Solutions solutions are best for your needs.
850,028 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Educational Organization
20%
Computer Software Company
14%
Comms Service Provider
7%
Manufacturing Company
6%
Computer Software Company
22%
Financial Services Firm
13%
Manufacturing Company
7%
Retailer
6%
Educational Organization
32%
Computer Software Company
13%
Government
8%
Financial Services Firm
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

Which is the better NGFW: Fortinet Fortigate or Cisco Firepower?
When you compare these firewalls you can identify them with different features, advantages, practices and usage a...
What is the biggest difference between Sophos XG and FortiGate?
From my experience regarding both the Sophos and FortiGate firewalls, I personally would rather use FortiGate. I know...
What are the biggest technical differences between Sophos UTM and Fortinet FortiGate?
As a solution, Sophos UTM offers a lot of functionality, it scales well, and the stability and performance are quite ...
What do you like most about Check Point CloudGuard Network Security?
The tool's most valuable feature is its management console.
What is your experience regarding pricing and costs for Check Point CloudGuard Network Security?
Pricing in Jamaica is a major issue, with users often citing it as a reason for not using Check Point.
What needs improvement with Check Point CloudGuard Network Security?
They could improve the documentation. The interface is fine for me since I have been using it for some time.
What do you like most about Juniper Contrail SD-WAN?
I've worked with several SD-WAN solutions over the past few years, and the product felt more like an automated provis...
What is your experience regarding pricing and costs for Juniper Contrail SD-WAN?
My advice regarding setup costs, pricing, and licensing for Juniper Contrail SD-WAN would be to carefully evaluate an...
What needs improvement with Juniper Contrail SD-WAN?
Implementing new branches or changing existing ones in Juniper Contrail SD-WAN wasn't as straightforward as with othe...
 

Also Known As

FortiGate 60b, FortiGate 60c, FortiGate 80c, FortiGate 50b, FortiGate 200b, FortiGate 110c, FortiGate, Fortinet Firewall
CloudGuard IaaS, Check Point vSEC, CloudGuard IaaS, Check Point Virtual Systems, Check Point CloudGuard Network Security
Contrail SD-WAN
 

Overview

 

Sample Customers

Amazon Web Services, Microsoft, IBM, Cisco, Dell, HP, Oracle, Verizon, AT&T, T-Mobile, Sprint, Vodafone, Orange, BT Group, Telstra, Deutsche Telekom, Comcast, Time Warner Cable, CenturyLink, NTT Communications, Tata Communications, SoftBank, China Mobile, Singtel, Telus, Rogers Communications, Bell Canada, Telkom Indonesia, Telkom South Africa, Telmex, Telia Company, Telkom Kenya
Physicians Choice Laboratory Services, Helvetica Insurance
Allied Pinnacle
Find out what your peers are saying about Check Point CloudGuard Network Security vs. Juniper Contrail SD-WAN and other solutions. Updated: April 2025.
850,028 professionals have used our research since 2012.