Try our new research platform with insights from 80,000+ expert users

Citrix SD-WAN [EOL] vs Forcepoint Next Generation Firewall comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Oct 12, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Fortinet FortiGate
Sponsored
Average Rating
8.4
Reviews Sentiment
6.9
Number of Reviews
584
Ranking in other categories
Secure Web Gateways (SWG) (2nd), Firewalls (1st), Intrusion Detection and Prevention Software (IDPS) (1st), Software Defined WAN (SD-WAN) Solutions (1st), WAN Edge (1st), ZTNA (1st), Unified Threat Management (UTM) (1st)
Citrix SD-WAN [EOL]
Average Rating
8.2
Reviews Sentiment
7.4
Number of Reviews
22
Ranking in other categories
No ranking in other categories
Forcepoint Next Generation ...
Average Rating
7.6
Reviews Sentiment
6.4
Number of Reviews
51
Ranking in other categories
Firewalls (19th), Software Defined WAN (SD-WAN) Solutions (8th), WAN Edge (8th)
 

Featured Reviews

Vasu Gala - PeerSpot reviewer
Manager, Information Technology Operation/Presales at TechMonarch
A stable solution with an intuitive interface and quick customer service
I have been working with Fortinet FortiGate, WatchGuard, Sophos, and SonicWall. I'm not as comfortable with SonicWall because of their UI and limitations. I prefer Fortinet above all other options. When it comes to configuration, I am confident in my ability to handle various tasks, including creating policies such as firewall rules, web policies, and application policies. Additionally, I can configure VPNs and implement load balancing, among other tasks. Overall, I feel much more comfortable working with Fortinet. Fortinet has made significant improvements by integrating AI with firewalls for threat analysis and prevention. In the past 2-3 years, they have launched FortiSASE and SIEM, and they also provide SOC services. Both Palo Alto and Fortinet FortiGate are excellent. While Fortinet FortiGate comes at higher prices, the functionality and support justify the cost. They promptly resolve firmware issues and inform all support providers about configuration changes.
Rohit Ghorpade - PeerSpot reviewer
Cloud network engineer at Bajaj Allianz General Insurance Co. Ltd.
A scalable solution for MCN controller but lacks technical supports, upgrades
There are a few things that can be improved, are domain-based routing and the slowness of virtual parts, and it may be due to the wrong configuration, which we have been unable to find out. Previously, we faced some issues with the slowness part. Apart from that, feature like end gateway level antivirus. We are currently using a NetFlow proxy to establish a virtual position for the NetFlow. Our current environment has many use cases, but we are not using them on the Citrix SD-WAN. When I navigate the NCL part, it involves configuration. I want to highlight this disadvantage. Sometimes, when we push the configuration, it tries to push it to all branch locations. This process takes a lot of time, nearly 30 minutes, to push a single change from the NCL. Overall, I don't think Citrix meets our use cases what we have. This is based on my feedback after using it for the past year and working on this Citrix SD-WAN. However, from my experience, it is the worst solution I have seen. There's no domain-based routing, which is horrible. That's why we are moving to other products. We have checked our use case requirements with Fortinet, Palo Alto, and they meet them. I will consider the PoC or another OEM. There are many things in the area you need to be prompt, like the automation part. If any link or device goes down, alerting notification, etc. We need to perform and highlight so many things to your management. This should be improved.
reviewer2774055 - PeerSpot reviewer
Cybersecurity Engineer at a tech consulting company with 51-200 employees
Improved network segmentation has reduced lateral movement while the interface still needs modernization
For threat prevention, I noticed on another customer that there were repeated scanning and exploit attempts against some public-facing service running on HTTPS. I configured Forcepoint Next Generation Firewall to handle IPS by enabling it with critical and high severity signatures only to reduce false positives. I turned on IP reputation filtering to filter out known malicious networks, applied rate limiting on specific services in the DMZ, and logged events centrally for correlation. As a result, exploit attempts were much less than before, being blocked before reaching the back-end servers from the firewall itself, with no performance degradation on the applications. The security team received clear and actionable logs that were centralized, so they knew what was happening all the time. Strong network segmentation is my favorite feature that Forcepoint Next Generation Firewall offers. The policies are very deterministic and readable, and it has excellent east-west blocking and least privilege architecture. Application awareness identifies traffic beyond just the port itself; I can identify the application using a specific port and block risky applications even if they use allowed ports, which is great for environments with shadow IT. The integrated threat prevention is also very good, with IPS featuring well-tuned signatures and reputation-based filtering that blocks known bad actors before they can touch any applications. It supports both IPsec and SSL VPN tunnels, along with site-to-site, client-to-site, and hybrid cloud links, integrating well with Active Directory and LDAP. Additionally, centralized log management and reporting are very actionable and structured, with clarity in the policies for auditing. Overall, its stability and reliability are commendable. A real example of how Forcepoint Next Generation Firewall's readable policies and application awareness features made my work easier was fixing a flat network problem without breaking actual applications. I inherited an environment where users, application servers, and databases were loosely segmented, with port-based and messy firewall rules. Security audits flagged lateral movement risks, and application owners were scared of outages if I tightened security too much. Forcepoint Next Generation Firewall made it easy by providing very easy-to-read and logical policies. I built policies that are clear, showing communications from the user zone to the application zone to specific applications, or from the app zone to the database zone, using only required database protocols. By default, I applied a deny rule between zones unless explicitly allowed by the readable rules I implemented. The policy view clarified who talks to whom, which rules exist, why they exist, and the business function they support, effectively stopping port abuse. Security posture has definitely improved greatly since using Forcepoint Next Generation Firewall. From a flat or semi-flat network, I now have clear zone-based segmentation, with increased operational efficiency. The admins using the firewall have rules that are easy to read and intent-based, making changes easier to review and approve. There is less fear that one wrong rule could break production and fewer outages caused by security changes, without hidden matches or rule shadowing surprises. Clear hit count visibility helps me clean unused rules, leading to much fewer outages caused by changes on the firewalls. The centralized log management with supported log types provides better visibility for the SOC team and the SIEM team, as Forcepoint Next Generation Firewall sends very easy-to-parse and search clear logs to the SOC team. I did see measurable, defensible results after using Forcepoint Next Generation Firewall, including fewer security incidents reaching the back-end servers. This reduction is due to strong segmentation, application awareness, and IPS features, leading to a 60 to 70 percent reduction in security alerts that actually reach the servers. DMZ exploit attempts dropped to near zero, and no lateral movement incidents were detected post network segmentation. Additionally, overall SOC efficiency improved due to well-structured and contextual logs reflecting clear policy intent, resulting in a 35 to 40 percent reduction in mean time to triage. SOC analysts stopped chasing noise and false positives, as they had much clearer logs to use confidently.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Its usability is good. We can easily navigate the system, and we have a very good user experience."
"It is complemented by other equipment, such as the Fortinet switch, and it is integrated with other tools that help to prevent cyberattacks, including a web filter, IPS, and application control."
"The threat prevention is the solution's most valuable aspect."
"The best features of Fortinet FortiGate are that it does the job effectively and protects our environment."
"Web filtering is the most useful feature."
"Their interface is very easy to use, it is without bugs."
"Fortinet FortiGate's most valuable features are the UTM package which provides internet blocking restrictions and load balancing. Additionally, the solution is easy to use and the security reporting is good. The security fabric which they have launched Fortinet FortiGate IPS, it's very good in terms of giving details."
"The product is stable and strong."
"They have a zero downtime failover mechanism, where, when there's a link failure or a link weakness, or bad link conditions, they provide the ability to fail back seamlessly."
"The zero-touch deployment is most valuable for us."
"The SD-WAN solution as it is already is quite feature-rich and the upgrade process is very simple."
"Downtime for branch offices is now almost zero. We have 100% real-time visibility into all of our lines. MPLS links have been replaced with lower-cost links, saving a larger percentage of line costs. Overall, I see SD-WAN as a must. And the Citrix SD-WAN product has delivered on expectations and exceeded them. (With later firmware updates we now have good firewall capabilities in the product too)."
"The VPN and the load balancing are the most valuable features."
"The most valuable feature is security, as it gives me the port bindings that cannot be accomplished using other solutions."
"The solution's most valuable feature is load balancing."
"The reliability of connectivity is most valuable."
"When comparing this solution to others this one has better reporting, user management, and is easy to use."
"One of the most valuable features is having the ability to cluster multiple firewalls even if they are different versions."
"The VPN is great."
"The product's initial setup phase is easy."
"With Forcepoint, this process is simplified compared to others like Fortinet."
"We like the scalability of Forcepoint because with the Forcepoint NGFW solution, we can scale anything. The solution has central management, so we can manage all the branches and devices centrally in one controller."
"It is a scalable solution."
"Forcepoint Next Generation Firewall is quite affordable, cheaper than other brands like Palo Alto or Check Point, with a lot of capabilities, very stable, and very well-made, making it a really good product for its price when compared to other vendors."
 

Cons

"FortiGate NGFW can improve technical support. The engineer who answers the technical support call, email, or phone call, whatever the medium may be. The response time is very bad."
"The solution needs to improve its support."
"It could use more templates for third-party site-to-site VPN setups other than FortiGate and Cisco."
"They should provide us with a CSV number for patch updates. It will help us block specific signatures as well."
"Fortinet FortiGate could improve their documentation on forward error correction and failover technologies."
"Fortinet's support team consists of a huge networking team, because of which there is a delay in response at times."
"Even though our currency in this part of the world is becoming increasingly weak, the pricing is now expensive for us. I have tried pushing Fortinet FortiGate to some customers, however, sometimes the transactions don't conclude due to pricing issues."
"It should come integrated or have its own type of network monitor tool in a module. There should just be one package, and you are good to go."
"The price could be improved, it's an expensive solution."
"I would like to see more customization to adjust for the WAN lock-out due to our unexpected power outages."
"The communication around the life cycle would have been really helpful. The main issue we have had is related to the life cycle because some of the things that we are using were discontinued. They were discontinued within a year after we had purchased it, which is a bit painful. If we had known that, we would've made some other decisions."
"Citrix SD-WAN's knowledge base has a few missing things, so you may need to seek help from support."
"I would like to see support for additional reporting."
"The only improvement for Citrix SD-WAN would be to lower its cost."
"Citrix SD-WAN does not have the SD-WAN with one optimization in a single license. Other competitors have this option and it should be added to this solution."
"The reports need to be improved. We need to have them customized but they don't have that right now. I would like for them to have better system predictions. We don't have that right now. My system may be working fine right now but after making some changes, that can change."
"Forcepoint Next Generation Firewall can be improved with better response from support."
"Next Generation Firewall's configuration could be improved."
"The network interface could be better, and it could be cheaper."
"Making this solution easier to use would be an improvement."
"The security features need to be improved."
"They should have a local vendor who can provide support. Most of the support is overseas, so the time zones can be a problem."
"Sometimes Forcepoint Next Generation Firewall is not really stable at all. It has many freezes for no reason, and local support needs to reboot it physically by unplugging the power cable and plugging it back in."
"They should have a GUI on the product itself, not a separate management tool to be used on the management server or on a server to be used to manage the file. It should be all in one device. The device should be controlled through its own GUI. They also have to improve the learning center and the documents as the documents don't really help."
 

Pricing and Cost Advice

"It's very affordable."
"It is quite affordable for our customers. There is a separate cost for IPS, antivirus, web filtering, and other features. They have a great choice of licenses. You can go for the license that you want, which is quite useful."
"In the Asian economy in which we operate, FortiGate is expensive."
"They are very competitive, but we like to have the factory warranty taken care of."
"It is expensive. You need to pay for the subscription every year, which is very expensive. The subscription includes technical support and hardware exchange in case of failure."
"It's a year based license."
"It's very competitive."
"No comment."
"It depends on the scale. In our case, it would have been better if we had known about the life cycling steps, but otherwise, it is worth the money."
"I'm not quite sure of the price ranges. Roughly, the hidden devices can scale up to $20K for one appliance. However, the branch CPs are USD $1,000 to $2,500."
"The price is relatively expensive."
"It is a bit expensive. A cheaper product would be good, but everybody likes things to be cheaper. We bought the devices up front, and then we pay for the annual support."
"Citrix SD-WAN is quite an affordable product."
"It's a little bit on the high side compared to the other products."
"As NetScaler is now, I find it quite pricey."
"I believe that Citrix SD-WAN is a good investment, but I do not have the information to be more specific."
"I believe the licensing fee is for one year, three years, and five years, or something like that. If you wants to increase the support level from a simpler level to platinum, I think that there's a cost. There are differences between every kind of support, but I don't know the numbers."
"There is a license required to use this solution and we can purchase it for one, two, three, or five years."
"The solution is expensive."
"Forcepoint is very expensive but it's really secure."
"It could be cheaper like Fortinet."
"It requires a yearly subscription."
"The pricing of the solution is normally competitive with other products."
"It is an affordable product. We purchase its yearly license."
report
Use our free recommendation engine to learn which Software Defined WAN (SD-WAN) Solutions solutions are best for your needs.
883,760 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
11%
Comms Service Provider
10%
Manufacturing Company
8%
Financial Services Firm
6%
Computer Software Company
9%
Marketing Services Firm
9%
Manufacturing Company
7%
Government
7%
Computer Software Company
10%
Manufacturing Company
9%
Financial Services Firm
7%
Government
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business359
Midsize Enterprise133
Large Enterprise190
By reviewers
Company SizeCount
Small Business7
Midsize Enterprise5
Large Enterprise10
By reviewers
Company SizeCount
Small Business29
Midsize Enterprise10
Large Enterprise12
 

Questions from the Community

Which is the better NGFW: Fortinet Fortigate or Cisco Firepower?
When you compare these firewalls you can identify them with different features, advantages, practices and usage a...
What is the biggest difference between Sophos XG and FortiGate?
From my experience regarding both the Sophos and FortiGate firewalls, I personally would rather use FortiGate. I know...
What are the biggest technical differences between Sophos UTM and Fortinet FortiGate?
As a solution, Sophos UTM offers a lot of functionality, it scales well, and the stability and performance are quite ...
What needs improvement with Citrix SD-WAN?
The solution's licensing model could be improved. Citrix SD-WAN is a good product from a technical point of view. How...
What advice do you have for others considering Citrix SD-WAN?
If a customer already has Citrix NetScaler and is not looking to change anything in their existing environment, we pr...
What is your experience regarding pricing and costs for Forcepoint Next Generation Firewall?
My experience with pricing, setup cost, and licensing is limited because I do not work with pricing, but I have exper...
What needs improvement with Forcepoint Next Generation Firewall?
Forcepoint Next Generation Firewall can be improved, perhaps in the user interface and policy management. While the p...
 

Also Known As

Fortinet FortiGate Next-Generation Firewall
Citrix CloudBridge, WOC, NetScaler SD-WAN
Forcepoint NGFW, Stonesoft Next Generation Firewall, McAfee Network Security Platform, Intel Security Network Security Platform
 

Overview

 

Sample Customers

Amazon Web Services, Microsoft, IBM, Cisco, Dell, HP, Oracle, Verizon, AT&T, T-Mobile, Sprint, Vodafone, Orange, BT Group, Telstra, Deutsche Telekom, Comcast, Time Warner Cable, CenturyLink, NTT Communications, Tata Communications, SoftBank, China Mobile, Singtel, Telus, Rogers Communications, Bell Canada, Telkom Indonesia, Telkom South Africa, Telmex, Telia Company, Telkom Kenya
AIDS Healthcare Foundation, Cornerstone Home Lending Inc., Dallara, ecVision, Essar, Eurofred, Groupe Promutuel, HMSHost Corporation, Royal Caribbean Cruise Lines Ltd, Royal Caribbean International
California Department of Corrections and Rehabilitation (CDCR)
Find out what your peers are saying about Fortinet, Cisco, Check Point Software Technologies and others in Software Defined WAN (SD-WAN) Solutions. Updated: March 2026.
883,760 professionals have used our research since 2012.