Try our new research platform with insights from 80,000+ expert users

Check Point NGFW vs Sophos XGS comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Apr 6, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
7.5
Fortinet FortiGate is valued for affordability, cost savings, enhanced security, operational efficiency, quick implementation, and long-term ROI benefits.
Sentiment score
7.5
Check Point NGFW delivers ROI with enhanced security, productivity, and efficiency, providing cost savings and increased satisfaction for organizations.
Sentiment score
2.5
Sophos XGS offers valuable ransomware protection for small businesses, reducing operational costs despite higher licensing fees.
Clients are now comfortable and not wasting productive hours on IT support.
The automation part is giving us a cost benefit and speed; we can react faster.
It's a very useful tool to mitigate and protect your enterprise.
This is a time-saving measure because we don't need to deploy a cluster or a firewall each time; we just create a virtual system on the management server using the same appliance.
Incident response time has reduced significantly, and downtime due to network issues has been minimized, leading to an improved return on investment.
I have seen a return on investment with Check Point NGFW in terms of time saved and fewer people needed for operations.
The costs have increased with Sophos XGS in the last few years, with license prices going up by 30%, doubling from $2,500 to about $5,000, which is a big challenge for us.
 

Customer Service

Sentiment score
7.0
Fortinet FortiGate's customer service varies, with praise for responsiveness but criticism for slow, sometimes inadequate technical support.
Sentiment score
7.2
Check Point NGFW support is generally praised for expertise but criticized for inconsistent response times and lower-tier support issues.
Sentiment score
6.9
Sophos XGS customer service varies, praised for responsiveness but criticized for slow responses and expertise in initial support stages.
I would rate their support for FortiGate a nine out of ten.
They offer very accurate solutions.
The quick resolution of issues with Fortinet FortiGate is due to the support of the company and the fact that the equipment is easy to work with.
The support team we engaged was knowledgeable and well-versed with the application.
We have escalated issues to Check Point technical support multiple times and have received timely and very good responses.
Even challenging issues like those with VPNs have been resolved efficiently with their help.
Any issues are quickly addressed by their support team, which is not common among all OEM manufacturers.
The technical support of Sophos rates at 10.
The response time from Sophos technical support can be slow in most cases, which can be challenging.
 

Scalability Issues

Sentiment score
7.3
Fortinet FortiGate scales well for diverse enterprises, though planning and licensing are crucial to avoid hardware limitations.
Sentiment score
8.1
Check Point NGFW provides scalable solutions with high performance and flexibility, supporting cloud environments and dynamic business growth.
Sentiment score
7.0
Sophos XGS is versatile for various environments, but some hardware limitations exist, suitable for small to medium enterprises.
They scale up really well from smaller models like the FortiGate 40 and 50 to bigger sites with the FortiGate 100 for more throughput - up to enterprise datacenters.
The variation comes in terms of the interfaces and throughputs, but from a security perspective, you get the same benefit, irrespective of whether you have an entry-level unit or an enterprise.
We determine sizing based on multiple factors: number of users, available links, traffic types, server count, services in use, and whether services will be published.
If specified correctly, even the smaller boxes offer high session and bandwidth rates, making the solution highly scalable, even up to telco-level requirements.
Scalability must be carefully planned for, considering future growth and user base increases.
They offer multiple solutions from SMBs to enterprise data centers, making it an easily scalable solution with no issues in scalability.
I can change what I want easily without interfering with other services or routines.
I would rate its scalability seven out of ten since modules can be added.
 

Stability Issues

Sentiment score
7.9
Fortinet FortiGate is generally stable and reliable, with minor issues arising from new features, firmware updates, or hardware constraints.
Sentiment score
7.9
Check Point NGFW is praised for stability, scalability, and reliability with minor issues typically resolved through updates.
Sentiment score
7.6
Sophos XGS is praised for stability and reliability, with high ratings despite occasional performance drops when capacity limits are exceeded.
We're experiencing 99.999% availability consistently.
I would rate the stability of Fortinet FortiGate a ten out of ten.
We have not had any problems with the operating systems or maintenance of subscriptions.
While the solution is generally stable, there are complications, such as requiring SmartConsole for deployment and upgrades, which can be time-consuming.
I have worked with Check Point products for 15 years and haven't found any stability or performance issues.
The use of Check Point firewalls has helped improve our security posture without any downtime.
It is rated at nine out of ten for stability and is very reliable.
Sophos XGS is stable now, and I would rate its stability as a ten out of ten.
When Sophos introduced firmware version twenty, there was a bug in DCC.
 

Room For Improvement

Fortinet FortiGate needs enhancements in firmware, usability, integration, support, reporting, VPN, cloud integration, and documentation for seamless use.
Check Point NGFW users face stability, compatibility, interface, support, pricing issues, and request better integration and training resources.
Sophos XGS requires improved integration, scalability, and support, while addressing high costs and complex configurations for better user experience.
By providing an integrated solution, users would have access to all features and functionalities within a single window, eliminating the need to navigate through multiple windows.
Investing in a solution that can accommodate such growth would be more cost-effective than repeatedly purchasing new hardware.
The constant daily revisions necessitate meticulous identification of the relevant documents to prevent the use of outdated information that could jeopardize our environment.
Other products, like FortiGate, are perceived as more intuitive because they are easier to configure from the start.
More granularity and control for threat prevention, especially on the OT side, would be beneficial.
I believe Check Point NGFW can be improved by making its initial configuration and deployment easier in the future because the first-time setup is really hard.
It would be beneficial if Sophos XGS offered an end-to-end solution with competitive pricing.
The DDNS features are essential for any organization, as it is better not to have a static IP address from an ISP.
After version 18.5, creating a NAT rule has become more complex, requiring the creation of a separate policy and an additional component.
 

Setup Cost

Fortinet FortiGate offers competitive pricing with upfront affordability, simple licensing, and long-term value, despite potentially high renewal costs.
Check Point NGFW is costly with complex licensing, though negotiable for budget flexibility and valued for security features.
Sophos XGS offers flexible pricing with competitive discounts, balancing cost-effectiveness and functionality compared to rivals like Fortinet and Palo Alto.
The most expensive part is the renewal of the license subscription.
FortiGate is priced lower than Palo Alto.
Last year, I renewed the support for three years, which can sometimes be expensive but depends on the security benefits and how it helps us.
In comparison to Fortinet and other products, the pricing may be considered high.
Compared to other solutions, the pricing of Check Point NGFW is high.
The perception is that Check Point NGFW is expensive, especially when all software modules are included.
The last instance I purchased was for three years, around $3,700 for SDG 125.
pricing is rated eight out of ten, indicating that it may be relatively expensive.
Sophos XGS is quite expensive, potentially a nine out of ten in terms of cost.
 

Valuable Features

Fortinet FortiGate delivers robust security features and intuitive management, offering scalable and affordable network protection solutions.
Check Point NGFW provides comprehensive, high-performance security with threat prevention, application control, and seamless third-party integration.
Sophos XGS provides centralized management, strong security features, and scalability, ensuring efficient and cost-effective network control across industries.
The firewall, IPS, and VPN functions are the most valuable features.
FortiGate provides solid protection against viruses, malware, and other threats.
In terms of security, we have not experienced any security flaws or loopholes, and it has proven to be quite stable.
The firewall's default behavior of blocking all traffic, including a cleanup rule that blocks everything from external to internal sources, is highly valuable for protecting our network.
The most valuable features in my experience include perimeter firewalling, cloud and mobile security, application control, URL filtering, DLP, threat prevention, intrusion protection, and safeguarding against malware, botnets, and zero-day attacks.
Since implementing it, we have noticed a lot less getting through that maybe other antivirus within firewalls had failed to catch.
It's able to detect cloud applications like Zoom or Microsoft Teams and allows traffic shaping based on the application.
I find it much easier than others, like FortiGate, which is complicated in its installation, but Sophos XGS is really easy.
The threat detection capabilities are effective, especially against CNC and certain viruses not coming through emails.
 

Categories and Ranking

Fortinet FortiGate
Sponsored
Ranking in Firewalls
2nd
Average Rating
8.4
Reviews Sentiment
7.2
Number of Reviews
357
Ranking in other categories
Software Defined WAN (SD-WAN) Solutions (1st), WAN Edge (1st)
Check Point NGFW
Ranking in Firewalls
5th
Average Rating
8.8
Reviews Sentiment
7.4
Number of Reviews
323
Ranking in other categories
Unified Threat Management (UTM) (1st)
Sophos XGS
Ranking in Firewalls
11th
Average Rating
8.0
Reviews Sentiment
6.6
Number of Reviews
84
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of June 2025, in the Firewalls category, the mindshare of Fortinet FortiGate is 21.4%, up from 17.8% compared to the previous year. The mindshare of Check Point NGFW is 3.0%, down from 3.2% compared to the previous year. The mindshare of Sophos XGS is 2.5%, up from 1.1% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Firewalls
 

Featured Reviews

Jorge Martínez - PeerSpot reviewer
Offers good SD-WAN capabilities and integrates easily with Fortinet devices
I am not part of the initial setup or deployment process since I work in presales. The setup or deployment is quite easy, as you can do a one-touch deployment that automatically connects to the FortiManager cloud when you connect it to a broadband or dynamic IP, allowing you to start the configuration from that point. We usually sell it for on-premises setups. It's on the cloud only when the client has virtual machines or their own service. Sometimes they have a service on the cloud like AWS, but it's more difficult to sell now because AWS has an e-commerce option where you can buy FortiGate directly. The only thing you need is someone to manage and configure.
Manikandan Kannan - PeerSpot reviewer
Streamlined management through dual-interface configuration capabilities with excellent support
We use Check Point NGFW for security purposes. Our clients use it for security reasons, as mentioned during the call The most valuable feature is the availability of two consoles. In the normal GA login, I can create interfaces and configure interface IPs, while in the SmartConsole, I manage the…
Nassif  Kaleny - PeerSpot reviewer
Dynamic web and mail filtering contribute to improved security measures
The reporting system is very poor. I cannot trace any traffic to our site if it feels some threats. It just tells me that there is something during a certain time but does not provide information about the type of threats or how to get rid of them. This needs improvement.
report
Use our free recommendation engine to learn which Firewalls solutions are best for your needs.
856,873 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Educational Organization
15%
Computer Software Company
15%
Comms Service Provider
8%
Manufacturing Company
6%
Educational Organization
47%
Computer Software Company
9%
Financial Services Firm
6%
Manufacturing Company
3%
Computer Software Company
13%
Manufacturing Company
9%
Comms Service Provider
8%
Educational Organization
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

Which is the better NGFW: Fortinet Fortigate or Cisco Firepower?
When you compare these firewalls you can identify them with different features, advantages, practices and usage a...
What is the biggest difference between Sophos XG and FortiGate?
From my experience regarding both the Sophos and FortiGate firewalls, I personally would rather use FortiGate. I know...
What are the biggest technical differences between Sophos UTM and Fortinet FortiGate?
As a solution, Sophos UTM offers a lot of functionality, it scales well, and the stability and performance are quite ...
How does Check Point NGFW compare with Fortinet Fortigate?
I have experience on both from Disti and channel experience. Please find below my comments (nothing new as such). -Ch...
Which would you recommend - Azure Firewall or Check Point NGFW?
Azure Firewall is easy to use and provides excellent support. Valuable features include integration into the overall ...
What do you like most about Check Point NGFW?
Check Point NGFW provides essential security, featuring no-obligation access for secure connections, strong intrusion...
What do you like most about Sophos XGS?
The policies are the greatest feature. They allow us to configure granular control over our network traffic.
What is your experience regarding pricing and costs for Sophos XGS?
I am satisfied with the price, rating it a nine. There are no extra expenses required after buying the product.
What needs improvement with Sophos XGS?
There is room for improvement in Sophos XGS, specifically in three areas: slowness, centralized synchronization, and ...
 

Also Known As

FortiGate 60b, FortiGate 60c, FortiGate 80c, FortiGate 50b, FortiGate 200b, FortiGate 110c, FortiGate, Fortinet Firewall
Check Point NG Firewall, Check Point Next Generation Firewall
No data available
 

Overview

 

Sample Customers

Amazon Web Services, Microsoft, IBM, Cisco, Dell, HP, Oracle, Verizon, AT&T, T-Mobile, Sprint, Vodafone, Orange, BT Group, Telstra, Deutsche Telekom, Comcast, Time Warner Cable, CenturyLink, NTT Communications, Tata Communications, SoftBank, China Mobile, Singtel, Telus, Rogers Communications, Bell Canada, Telkom Indonesia, Telkom South Africa, Telmex, Telia Company, Telkom Kenya
Control Southern, Optimal Media
Information Not Available
Find out what your peers are saying about Check Point NGFW vs. Sophos XGS and other solutions. Updated: June 2025.
856,873 professionals have used our research since 2012.