Try our new research platform with insights from 80,000+ expert users

Cisco Catalyst SD-WAN vs Citrix SD-WAN [EOL] comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Oct 12, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Fortinet FortiGate
Sponsored
Average Rating
8.4
Reviews Sentiment
6.9
Number of Reviews
580
Ranking in other categories
Secure Web Gateways (SWG) (2nd), Firewalls (1st), Intrusion Detection and Prevention Software (IDPS) (1st), Software Defined WAN (SD-WAN) Solutions (1st), WAN Edge (1st), ZTNA (1st), Unified Threat Management (UTM) (1st)
Cisco Catalyst SD-WAN
Average Rating
8.0
Reviews Sentiment
6.8
Number of Reviews
97
Ranking in other categories
Network Management Applications (6th), Software Defined WAN (SD-WAN) Solutions (2nd), WAN Edge (2nd)
Citrix SD-WAN [EOL]
Average Rating
8.2
Reviews Sentiment
7.4
Number of Reviews
22
Ranking in other categories
No ranking in other categories
 

Q&A Highlights

OT
Assistant Vice President - IT at Au small finance bank
May 08, 2020
 

Featured Reviews

Vasu Gala - PeerSpot reviewer
Manager, Information Technology Operation/Presales at TechMonarch
A stable solution with an intuitive interface and quick customer service
I have been working with Fortinet FortiGate, WatchGuard, Sophos, and SonicWall. I'm not as comfortable with SonicWall because of their UI and limitations. I prefer Fortinet above all other options. When it comes to configuration, I am confident in my ability to handle various tasks, including creating policies such as firewall rules, web policies, and application policies. Additionally, I can configure VPNs and implement load balancing, among other tasks. Overall, I feel much more comfortable working with Fortinet. Fortinet has made significant improvements by integrating AI with firewalls for threat analysis and prevention. In the past 2-3 years, they have launched FortiSASE and SIEM, and they also provide SOC services. Both Palo Alto and Fortinet FortiGate are excellent. While Fortinet FortiGate comes at higher prices, the functionality and support justify the cost. They promptly resolve firmware issues and inform all support providers about configuration changes.
Henry Rosenstiehl - PeerSpot reviewer
Solution Architect at Sonda S.A.
Comprehensive support and ease of implementation enhance operational efficiency
With Cisco Catalyst SD-WAN, I have centralized orchestration and management. The transport independence of MPLS or connectivity and internet connectivity is another excellent feature. End-to-end segmentation is also provided. I use the application-aware routing feature. Cisco Catalyst SD-WAN supports dynamic police-based routing decisions based on application type or different performance metrics such as jitter or latency. The benefit of that feature is that it improves user experience. The principal benefit of application-aware routing is that critical applications are prioritized or routed over the best performing paths to reduce outages and service degradation. There is full visibility of applications. Cisco Catalyst SD-WAN has integrated security features which include base firewall, URL filtering, IPS, and secure segmentation, and it supports integration with other Cisco products such as Umbrella or Snort. This feature is beneficial for the client because the information is secure. It is important that Cisco Catalyst SD-WAN supports cloud, on-premises, and hybrid environments for my organization because it allows for scalability and faster deployment in the cloud. It reduces operational needs because I don't need to manage physical controller hardware, and updates and maintenance can be centralized and automated. The zero-touch provisioning feature is very important for the speed of deploying new branch locations. I can deliver the device to the branch, and it is important because simplified deployment makes the implementation start more easily since devices are auto-configured and authenticate without manual intervention.
Rohit Ghorpade - PeerSpot reviewer
Cloud network engineer at Bajaj Allianz General Insurance Co. Ltd.
A scalable solution for MCN controller but lacks technical supports, upgrades
There are a few things that can be improved, are domain-based routing and the slowness of virtual parts, and it may be due to the wrong configuration, which we have been unable to find out. Previously, we faced some issues with the slowness part. Apart from that, feature like end gateway level antivirus. We are currently using a NetFlow proxy to establish a virtual position for the NetFlow. Our current environment has many use cases, but we are not using them on the Citrix SD-WAN. When I navigate the NCL part, it involves configuration. I want to highlight this disadvantage. Sometimes, when we push the configuration, it tries to push it to all branch locations. This process takes a lot of time, nearly 30 minutes, to push a single change from the NCL. Overall, I don't think Citrix meets our use cases what we have. This is based on my feedback after using it for the past year and working on this Citrix SD-WAN. However, from my experience, it is the worst solution I have seen. There's no domain-based routing, which is horrible. That's why we are moving to other products. We have checked our use case requirements with Fortinet, Palo Alto, and they meet them. I will consider the PoC or another OEM. There are many things in the area you need to be prompt, like the automation part. If any link or device goes down, alerting notification, etc. We need to perform and highlight so many things to your management. This should be improved.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Good anti-malware and web filtering features."
"In terms of security, we have not experienced any security flaws or loopholes, and it has proven to be quite stable."
"FortiGate's web and URL filtering are unlike any other firewall I've used. The functionality of URL filtering in those solutions is problematic because everything is encrypted, and firewalls can't break that encryption protocol. Fortinet has an SSL proxy, so the encryption is done before the packet ever leaves the FortiGate. The URL filter is definitely one of the most helpful features."
"The solution has helped our organization secure our network and connect remote sites."
"The ECC management and the GUI that offers single interface management are the most valuable features of Fortinet FortiGate."
"The management console is pretty simple, so anyone who understands networking can initially deploy the solution."
"The solution can scale well."
"From the firewall perspective, the rules and policies are very sufficient and easy to use."
"You can easily scale the product."
"The solution has great scalability."
"The solution is stable and reliable."
"Troubleshooting is swift, allowing for fast turnaround times whenever we encounter an issue."
"You get security, all of the service you need, and it's easy to deploy."
"The most valuable features are zero-disk provisioning and link load balancing on an application basis."
"The most valuable feature is the ease of central management."
"The solution sufficiently provides ISPs."
"The most valuable feature is its reliability."
"The tool is quite cost-effective because it replaces the need for MPLS, which is a bit expensive...Citrix SD-WAN doesn't need much maintenance."
"We are using it widely for the local record for SaaS-based applications. Another valuable feature is a local breakout."
"The VPN and the load balancing are the most valuable features."
"The SD-WAN solution as it is already is quite feature-rich and the upgrade process is very simple."
"The best feature is the backup capability, where all of the users' computers are tied into a central data repository."
"The most valuable feature is security, as it gives me the port bindings that cannot be accomplished using other solutions."
"The solution is brilliant, the way it calculates its paths and trails is great."
 

Cons

"At the moment, the main concern is the pricing and the type of licensing."
"They could do more work on FortiAnalyzer in terms of the data and the information coming from it."
"FortiGate can improve its token system, as it requires a purchase before use."
"Previously it had a hiccup around a bug within the authentication VPN due to the firmware, but after updating, it's easier to control."
"The advanced models are expensive."
"The feedback that I have received is that the performance could be better, and the user experience is not as good compared to a previous solution we used. It could be more user-friendly. Of course, it still works fine for our operations."
"In terms of pricing, the solution is a bit expensive, but I think it was a better option than Checkpoint, which is why I replaced it."
"FortiLink is the interface on the firewall that allows you to extend switch management across all of your switches in the network. The problem with it is that you can't use multiple interfaces unless you set them up in a lag. Only then you can run them. So, it forces you to use a core type of switch to propagate that management out to the rest of the switches, and then it is running the case at 200. It leaves you with 18 ports on the firewall because it is also a layer-three router that could also be used as a switch, but as soon as you do that, you can't really use them. They could do a little bit more clean up in the way the stacking interface works. Some use cases and the documentation on the FortiLink checking interface are a little outdated. I can find stuff on version 5 or more, but it is hard to find information on some of the newer firmware. The biggest thing I would like to see is some improvement in the switch management feature. I would like to be able to relegate some of the ports, which are on the firewall itself, to act as a switch to take advantage of those ports. Some of these firewalls have clarity ports on them. If I can use those, it would mean that I need to buy two less switches, which saves time. I get why they don't, but I would still like to see it because it would save a little bit of space in the server rack."
"The initial setup could be a bit less complex."
"As a seller, I still find Cisco Catalyst SD-WAN to be a little complicated."
"The installation is not easy. If you have experience and it is not your first time doing the installation, it can be easier."
"It would be very helpful if we had better access to a knowledge base, or online documentation, to help both us and our customers learn to use this solution."
"Simplifying the definition and implementation could add significant value, as it can be complex due to multiple product integrations and customization requirements."
"The product needs to have more understanding staff in their support team. The tool needs to provide support in every stage of deployment. We did not get the expected support from their team. The product is also not easy to use."
"The solution is a bit complicated."
"The solution could be a bit cheaper."
"I would like to see support for additional reporting."
"The initial setup could be a bit easier."
"Given that Citrix SD-WAN solved all our problems by providing us with everything we needed to unify communications with our branches and data centers, I cannot suggest anything further in terms of improvements."
"Overall, network security and next-generation firewall features are areas that they can improve on."
"The price is the only thing that could be improved. Citrix is not a cheap solution."
"The reports need to be improved. We need to have them customized but they don't have that right now. I would like for them to have better system predictions. We don't have that right now. My system may be working fine right now but after making some changes, that can change."
"The firewall reporting could be easier to use and filter. (It works well enough, but if I need to give an area for improvement, I think this would be it.). The built-in reporting on the product in this regard is not great."
"Citrix SD-WAN's knowledge base has a few missing things, so you may need to seek help from support."
 

Pricing and Cost Advice

"This is not a cheap solution but it isn't expensive, either. It's a good solution for the right price."
"The solution is very expensive so pricing is rated a one out of ten."
"It's a year based license."
"Work through partners for the best pricing."
"There is a license required to use Fortinet FortiGate with all the features. It has to be updated with the threats on an ongoing basis for the signatures to prevent threats and a license is needed to receive those security updates."
"Licensing is usually on a three-year period."
"There is only a standard license cost to use the solution."
"The license for Fortinet FortiGate is affordable in my country."
"Licensing is on a subscription basis."
"Cost-wise, Cisco SD-WAN is comparatively high."
"The pricing for Cisco SD-WAN is more expensive than other brands or solutions, such as Fortinet and Palo Alto Networks, so it's one out of ten."
"Cloud subscription management must be paid for, although this does not incur a perpetual fee."
"The costs are a bit on the high side."
"You have to pay between 3000 and 10,000 euros, or something in that range. The core switches Nexus cost me between 10,000 and 20,000 euros."
"It's costly. The cost is high compared to competitors."
"The price of Cisco SD-WAN could improve, it is expensive. The cost of the solution is approximately 30 percent higher than competitors."
"The price is relatively expensive."
"It would be helpful to have a demo license available for customers who want to prove the concept and conduct a proof of concept (POC) before committing to the solution. This is particularly important for customers in Egypt who often require a demonstration of the solution's features and compatibility with their needs before making any investment or incurring costs. Providing a demo license would allow customers to assess whether the solution would meet their needs or not."
"The price of the subscription should be cheaper."
"I'm not quite sure of the price ranges. Roughly, the hidden devices can scale up to $20K for one appliance. However, the branch CPs are USD $1,000 to $2,500."
"The license was a one-time purchase. It's expensive."
"It's a little bit on the high side compared to the other products."
"It depends on the scale. In our case, it would have been better if we had known about the life cycling steps, but otherwise, it is worth the money."
"As NetScaler is now, I find it quite pricey."
report
Use our free recommendation engine to learn which Software Defined WAN (SD-WAN) Solutions solutions are best for your needs.
879,371 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
14%
Comms Service Provider
9%
Manufacturing Company
8%
Financial Services Firm
6%
Computer Software Company
12%
Financial Services Firm
12%
Manufacturing Company
8%
Comms Service Provider
7%
Computer Software Company
21%
Manufacturing Company
9%
Government
7%
Retailer
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business357
Midsize Enterprise132
Large Enterprise188
By reviewers
Company SizeCount
Small Business44
Midsize Enterprise15
Large Enterprise43
By reviewers
Company SizeCount
Small Business7
Midsize Enterprise5
Large Enterprise10
 

Questions from the Community

Which is the better NGFW: Fortinet Fortigate or Cisco Firepower?
When you compare these firewalls you can identify them with different features, advantages, practices and usage a...
What is the biggest difference between Sophos XG and FortiGate?
From my experience regarding both the Sophos and FortiGate firewalls, I personally would rather use FortiGate. I know...
What are the biggest technical differences between Sophos UTM and Fortinet FortiGate?
As a solution, Sophos UTM offers a lot of functionality, it scales well, and the stability and performance are quite ...
What do you like most about Cisco SD-WAN?
When considering the most valuable features of Cisco SD-WAN, the decoupling of self-monitoring stands out significant...
What is your experience regarding pricing and costs for Cisco SD-WAN?
The pricing of Cisco Catalyst SD-WAN is rated between eight and nine out of ten, where ten is the most expensive.
What needs improvement with Cisco SD-WAN?
More or less, it's the same with Cisco in terms of complexity and pricing, so there's not much of a difference. They ...
What needs improvement with Citrix SD-WAN?
The solution's licensing model could be improved. Citrix SD-WAN is a good product from a technical point of view. How...
What advice do you have for others considering Citrix SD-WAN?
If a customer already has Citrix NetScaler and is not looking to change anything in their existing environment, we pr...
 

Also Known As

Fortinet FortiGate Next-Generation Firewall
Cisco SD-WAN
Citrix CloudBridge, WOC, NetScaler SD-WAN
 

Overview

 

Sample Customers

Amazon Web Services, Microsoft, IBM, Cisco, Dell, HP, Oracle, Verizon, AT&T, T-Mobile, Sprint, Vodafone, Orange, BT Group, Telstra, Deutsche Telekom, Comcast, Time Warner Cable, CenturyLink, NTT Communications, Tata Communications, SoftBank, China Mobile, Singtel, Telus, Rogers Communications, Bell Canada, Telkom Indonesia, Telkom South Africa, Telmex, Telia Company, Telkom Kenya
Doyle Research, Ashton Metzler & Associates
AIDS Healthcare Foundation, Cornerstone Home Lending Inc., Dallara, ecVision, Essar, Eurofred, Groupe Promutuel, HMSHost Corporation, Royal Caribbean Cruise Lines Ltd, Royal Caribbean International
Find out what your peers are saying about Fortinet, Cisco, Check Point Software Technologies and others in Software Defined WAN (SD-WAN) Solutions. Updated: December 2025.
879,371 professionals have used our research since 2012.