No more typing reviews! Try our Samantha, our new voice AI agent.

Forcepoint Next Generation Firewall vs Fortinet FortiGate vs Sangfor NGAF comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Mindshare comparison

As of April 2026, in the Firewalls category, the mindshare of Forcepoint Next Generation Firewall is 0.6%, up from 0.4% compared to the previous year. The mindshare of Fortinet FortiGate is 18.3%, down from 21.1% compared to the previous year. The mindshare of Sangfor NGAF is 1.0%, down from 1.2% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Firewalls Mindshare Distribution
ProductMindshare (%)
Fortinet FortiGate18.3%
Forcepoint Next Generation Firewall0.6%
Sangfor NGAF1.0%
Other80.1%
Firewalls
 

Featured Reviews

reviewer2774055 - PeerSpot reviewer
Cybersecurity Engineer at a tech consulting company with 51-200 employees
Improved network segmentation has reduced lateral movement while the interface still needs modernization
For threat prevention, I noticed on another customer that there were repeated scanning and exploit attempts against some public-facing service running on HTTPS. I configured Forcepoint Next Generation Firewall to handle IPS by enabling it with critical and high severity signatures only to reduce false positives. I turned on IP reputation filtering to filter out known malicious networks, applied rate limiting on specific services in the DMZ, and logged events centrally for correlation. As a result, exploit attempts were much less than before, being blocked before reaching the back-end servers from the firewall itself, with no performance degradation on the applications. The security team received clear and actionable logs that were centralized, so they knew what was happening all the time. Strong network segmentation is my favorite feature that Forcepoint Next Generation Firewall offers. The policies are very deterministic and readable, and it has excellent east-west blocking and least privilege architecture. Application awareness identifies traffic beyond just the port itself; I can identify the application using a specific port and block risky applications even if they use allowed ports, which is great for environments with shadow IT. The integrated threat prevention is also very good, with IPS featuring well-tuned signatures and reputation-based filtering that blocks known bad actors before they can touch any applications. It supports both IPsec and SSL VPN tunnels, along with site-to-site, client-to-site, and hybrid cloud links, integrating well with Active Directory and LDAP. Additionally, centralized log management and reporting are very actionable and structured, with clarity in the policies for auditing. Overall, its stability and reliability are commendable. A real example of how Forcepoint Next Generation Firewall's readable policies and application awareness features made my work easier was fixing a flat network problem without breaking actual applications. I inherited an environment where users, application servers, and databases were loosely segmented, with port-based and messy firewall rules. Security audits flagged lateral movement risks, and application owners were scared of outages if I tightened security too much. Forcepoint Next Generation Firewall made it easy by providing very easy-to-read and logical policies. I built policies that are clear, showing communications from the user zone to the application zone to specific applications, or from the app zone to the database zone, using only required database protocols. By default, I applied a deny rule between zones unless explicitly allowed by the readable rules I implemented. The policy view clarified who talks to whom, which rules exist, why they exist, and the business function they support, effectively stopping port abuse. Security posture has definitely improved greatly since using Forcepoint Next Generation Firewall. From a flat or semi-flat network, I now have clear zone-based segmentation, with increased operational efficiency. The admins using the firewall have rules that are easy to read and intent-based, making changes easier to review and approve. There is less fear that one wrong rule could break production and fewer outages caused by security changes, without hidden matches or rule shadowing surprises. Clear hit count visibility helps me clean unused rules, leading to much fewer outages caused by changes on the firewalls. The centralized log management with supported log types provides better visibility for the SOC team and the SIEM team, as Forcepoint Next Generation Firewall sends very easy-to-parse and search clear logs to the SOC team. I did see measurable, defensible results after using Forcepoint Next Generation Firewall, including fewer security incidents reaching the back-end servers. This reduction is due to strong segmentation, application awareness, and IPS features, leading to a 60 to 70 percent reduction in security alerts that actually reach the servers. DMZ exploit attempts dropped to near zero, and no lateral movement incidents were detected post network segmentation. Additionally, overall SOC efficiency improved due to well-structured and contextual logs reflecting clear policy intent, resulting in a 35 to 40 percent reduction in mean time to triage. SOC analysts stopped chasing noise and false positives, as they had much clearer logs to use confidently.
Vasu Gala - PeerSpot reviewer
Manager, Information Technology Operation/Presales at TechMonarch
A stable solution with an intuitive interface and quick customer service
I have been working with Fortinet FortiGate, WatchGuard, Sophos, and SonicWall. I'm not as comfortable with SonicWall because of their UI and limitations. I prefer Fortinet above all other options. When it comes to configuration, I am confident in my ability to handle various tasks, including creating policies such as firewall rules, web policies, and application policies. Additionally, I can configure VPNs and implement load balancing, among other tasks. Overall, I feel much more comfortable working with Fortinet. Fortinet has made significant improvements by integrating AI with firewalls for threat analysis and prevention. In the past 2-3 years, they have launched FortiSASE and SIEM, and they also provide SOC services. Both Palo Alto and Fortinet FortiGate are excellent. While Fortinet FortiGate comes at higher prices, the functionality and support justify the cost. They promptly resolve firmware issues and inform all support providers about configuration changes.
Zaid Farooqui - PeerSpot reviewer
CIO at Indus Motor Company
Enhanced threat detection with integrated security features and good support
We are using application firewalling, WAF, and SD-WAN. The capabilities are mostly within the box. For example, you will get web application firewall WAF as part and parcel of this. SD-WAN is also bundled. It integrates with their SIEM and SOAR solutions very nicely. Lastly, the pricing point is very cost-efficient as well.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"I have two offices, and I can route the internet of both offices using the same product. The connectivity is great."
"The central security management center and the content management center are very good."
"The URL filtering is the most valuable aspect of the product."
"The most valuable feature is SD-WAN."
"Forcepoint is my favorite enterprise firewall."
"The people we deal with is a local partner in Cambodia and we can get good support from them."
"With Forcepoint, this process is simplified compared to others like Fortinet."
"I like the IPS. IPS is the master feature. I depend on the firewall and sandbox."
"The next-generation firewall features are the solution's most valuable aspect."
"The SD-WAN feature is the most valuable. This feature evolved from link load balancing. It has helped us in terms of our uptime and privatizing applications whenever we experience an outage. The SD-WAN feature has been a plus for us. Two-factor authentication has allowed us to add more users in terms of remote working. We have two-factor authentication for remote workers to authenticate them before they get on the network."
"We find it's good for managing the network and offers good defense against attacks."
"Customers want to load balance more than six internet lines, and FortiGate is the only solution that can accomplish this."
"I would recommend using Fortinet FortiGate because of its usability."
"The benefits Fortinet FortiGate provides include easy connectivity, user-friendliness, scalability, and easy configuration management."
"The technical support is good."
"The most valuable features of Fortinet FortiGate IPS are firewall and filtering."
"It is a stable solution."
"The top functionality is the reporting feature."
"Sangfor NGAF's standout feature is its powerful application control, enabling precise restrictions on mobile user access to approved applications."
"The product is very fast and reliable."
"Sangfor's tech features and technologies are more powerful than those of the other solution providers in terms of security. They also have big solutions in terms of cybersecurity."
"We can utilize our own network rather than paying for a private one."
"I think this solution is a very good example of a proactive solution that can detect problems and immediately fix the problems or issues."
"The absolute best part of Sangfor NGAF is their support. It's a 24/7 support channel, and the last time I requested their assistance I got a reply within three minutes. They helped solve the problem immediately."
 

Cons

"Making this solution easier to use would be an improvement."
"We feel the product's technical support could be better, as this relates to the solution itself, to the installation of the product, and to having a proper understanding of the case."
"Next Generation Firewall's configuration could be improved."
"I would like to see more sizing in the next release, and the roadmap should be clear."
"They should provide more details on potential cyber threats."
"My experience with this Forcepoint Next Generation Firewall wasn't very pleasant due to its complexity. For example, the firewall loses some features when working in a cluster, which is a huge challenge. It caused me several weeks to solve an issue to make the VPN work, even after opening several cases with support. Also, the debug, which should provide essential knowledge about everything going on, the flow of traffic, and how the engine works, wasn't very informative in identifying the issue."
"It's a complicated firewall. Until you come to know the firewall inducers, most people don't like the firewall because the components for the firewall are a little bit complex. User-friendliness is a little bit tough. It needs to be user-friendly when creating policies, and pushing policies. Committing takes more time compared to Palo Alto."
"The endpoint protection capabilities of the product are an area of concern where improvements are required."
"Sometimes it's super hard to figure out what's wrong with a FortiGate VPN unless you know the commands on the CLI to see the flow and how to interpret it."
"I would like to see the licensing aspect improved because there is a feature we were yearning to use, the bandwidth monitoring feature, but it's licensed separately."
"The support team for Fortinet FortiGate needs to be more customer friendly."
"FortiOS is not simple."
"The setup is pretty complex and not easy to implement."
"There are some problems that support cannot give you a logical reason as to why it happened. Technical support gave more than one reason it could be giving issues, but none of them solved the problem."
"I want some additional features. For example, I want something to ensure that when we are using Google email or Microsoft email, or Google Workspace, emails can only be accessed on designated machines given to our employees. I would like them to access data from designated machines, not from any machine. It should work for designated mobiles and laptops. I don't know if Fortinet provides something like that out of the box."
"Fortinet FortiGate SWG could improve the price, it is expensive."
"The solution should be able to work in a hybrid setup."
"The solution has too many bugs and these slow down the implementation."
"The web interface needs to be improved, making it more user-friendly."
"Sangfor could improve their interface capacity on the 5100 series model and upgrade their hardware from one gig to 10 gig. This would improve the overall throughput."
"I feel Sangfor should follow the hierarchy and close deals via resellers instead of closing it all with their own team."
"The firewall system needs gradual improvements because there are more threats and challenges every day."
"I believe that IAM and NGFW need to merge into a single box, instead of there being two separate box solutions."
"The solution has too many bugs and these slow down the implementation."
 

Pricing and Cost Advice

"We have found the price could be reduced. It is a little expensive."
"I consider Forcepoint Next Generation Firewall's price to be good."
"The pricing of the solution is normally competitive with other products."
"It requires a yearly subscription."
"It could be cheaper like Fortinet."
"Everything in Forcepoint comes with an individual license, which is kind of a problem. In our last meeting, they said that it may change at the beginning of 2021, and they will try to merge some licenses together. Customers will get more features than what they got previously. We will wait and see."
"The solution is expensive."
"Forcepoint is very expensive but it's really secure."
"The price of Fortinet FortiGate is better than Cisco, Check Point, and Palo Alto. In terms of pricing, it's probably a better-priced firewall solution overall."
"Setup costs and pricing depends on many variables, but it's mostly affordable."
"I'll rate FortiGate's pricing a five out of ten since it is moderately priced."
"When you look at these end security systems and firewalls, these firewalls even five years ago were $50,000 or perhaps $25,000 to implement in some types of customer sites. Now we're talking about tools that are $1,000. In this case, it might have been $500 or something like that."
"Before choosing a piece of equipment you have to take into account the cost-benefit offered by each one. Sometimes it is not worth paying a very cheap price to have a minimum level of security."
"When comparing this solution to others, I would rate it a ten out of ten in terms of pricing. However, the issue of requiring a separate license for redundancy is a drawback, and I would rate it a nine out of ten."
"The price is fine."
"The pricing or licensing of Fortinet FortiGate is quite effective as it offers different bundles that aggregate most required features, while also allowing clients the option to select specific components alone."
"The product is very cost-effective compared to other brands or vendors."
"It costs about 8 to 10 thousand dollars per year for 500 users, standard licensing fees included."
"Price-wise, I would not consider Sangfor NGAF to be a cheap product. It is an expensive firewall solution, though not as expensive as something like Palo Alto, which is costly. However, the higher price point is justifiable given the feature set the tool provides that other firewalls may not offer in a single dedicated appliance."
"The pricing is reasonable."
"For four to five physical appliances for a licensed firewall, it costs approximately $4,000."
"I rate the product price as one on a scale of one to ten, where one is low price and ten is high price."
"The license of Sangfor NGAF can be purchased at different interval lengths, such as annually or three years. They offer a range of packages to choose from, such as combo or hybrid packages. We are using the complete solution package which includes IM, NGF and SSL VPN, and WAF."
"In my opinion, the price of the tool is good in the Pakistani market. We can easily get discounts if needed."
report
Use our free recommendation engine to learn which Firewalls solutions are best for your needs.
885,667 professionals have used our research since 2012.
 

Comparison Review

it_user216600 - PeerSpot reviewer
Senior Technical Consultant with 51-200 employees
Jan 3, 2016
Sophos UTM vs. Fortinet FortiGate
I have used both Sophos and Fortinet products in production and I have found the Sophos UTM appliances (hardware and virtual) to be a better fit most of the time -- with a few caveats which I will touch on below. In both instances, the transition from TMG will be mostly straightforward. The main…
 

Top Industries

By visitors reading reviews
Construction Company
10%
Manufacturing Company
9%
Computer Software Company
9%
Financial Services Firm
7%
Computer Software Company
11%
Comms Service Provider
10%
Manufacturing Company
8%
Financial Services Firm
6%
Manufacturing Company
11%
Comms Service Provider
8%
Financial Services Firm
8%
Computer Software Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business29
Midsize Enterprise10
Large Enterprise12
By reviewers
Company SizeCount
Small Business364
Midsize Enterprise135
Large Enterprise190
By reviewers
Company SizeCount
Small Business15
Midsize Enterprise10
Large Enterprise10
 

Questions from the Community

What is your experience regarding pricing and costs for Forcepoint Next Generation Firewall?
My experience with pricing, setup cost, and licensing is limited because I do not work with pricing, but I have exper...
What needs improvement with Forcepoint Next Generation Firewall?
I found one problem with Forcepoint Next Generation Firewall. They still do not have any VPN clients for Windows comp...
Which is the better NGFW: Fortinet Fortigate or Cisco Firepower?
When you compare these firewalls you can identify them with different features, advantages, practices and usage a...
What is the biggest difference between Sophos XG and FortiGate?
From my experience regarding both the Sophos and FortiGate firewalls, I personally would rather use FortiGate. I know...
What are the biggest technical differences between Sophos UTM and Fortinet FortiGate?
As a solution, Sophos UTM offers a lot of functionality, it scales well, and the stability and performance are quite ...
What do you like most about Sangfor NGAF?
I think Sangfor NGAF is more valuable than Cisco products because of its simplicity and ease of management. If I comp...
What is your experience regarding pricing and costs for Sangfor NGAF?
The licensing cost is quite high compared to other available firewalls in the market.
What needs improvement with Sangfor NGAF?
The cost of licensing is very high compared to other firewalls available here. There should be improvements in hardwa...
 

Also Known As

Forcepoint NGFW, Stonesoft Next Generation Firewall, McAfee Network Security Platform, Intel Security Network Security Platform
Fortinet FortiGate Next-Generation Firewall
Sangfor NGAF Firewall Platform
 

Overview

 

Sample Customers

California Department of Corrections and Rehabilitation (CDCR)
Amazon Web Services, Microsoft, IBM, Cisco, Dell, HP, Oracle, Verizon, AT&T, T-Mobile, Sprint, Vodafone, Orange, BT Group, Telstra, Deutsche Telekom, Comcast, Time Warner Cable, CenturyLink, NTT Communications, Tata Communications, SoftBank, China Mobile, Singtel, Telus, Rogers Communications, Bell Canada, Telkom Indonesia, Telkom South Africa, Telmex, Telia Company, Telkom Kenya
The Ministry of Science, Technology, and Innovation (Indonesia), Lawson, Inc. (Philippines), Universiti Sultan Zainal Abidin (Indonesia), TEK Automotive (Italy), etc.
Find out what your peers are saying about Fortinet, Netgate, Sophos and others in Firewalls. Updated: March 2026.
885,667 professionals have used our research since 2012.