No more typing reviews! Try our Samantha, our new voice AI agent.

Forcepoint Next Generation Firewall vs Hillstone T-Series comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Sep 16, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Fortinet FortiGate
Sponsored
Ranking in Firewalls
1st
Average Rating
8.4
Reviews Sentiment
6.9
Number of Reviews
589
Ranking in other categories
Secure Web Gateways (SWG) (2nd), Intrusion Detection and Prevention Software (IDPS) (1st), Software Defined WAN (SD-WAN) Solutions (1st), WAN Edge (1st), ZTNA (1st), Unified Threat Management (UTM) (1st)
Forcepoint Next Generation ...
Ranking in Firewalls
19th
Average Rating
7.6
Reviews Sentiment
6.4
Number of Reviews
51
Ranking in other categories
Software Defined WAN (SD-WAN) Solutions (8th), WAN Edge (8th)
Hillstone T-Series
Ranking in Firewalls
43rd
Average Rating
7.4
Number of Reviews
3
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of March 2026, in the Firewalls category, the mindshare of Fortinet FortiGate is 18.3%, down from 21.1% compared to the previous year. The mindshare of Forcepoint Next Generation Firewall is 0.6%, up from 0.4% compared to the previous year. The mindshare of Hillstone T-Series is 0.3%, up from 0.1% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Firewalls Mindshare Distribution
ProductMindshare (%)
Fortinet FortiGate18.3%
Forcepoint Next Generation Firewall0.6%
Hillstone T-Series0.3%
Other80.8%
Firewalls
 

Featured Reviews

Vasu Gala - PeerSpot reviewer
Manager, Information Technology Operation/Presales at TechMonarch
A stable solution with an intuitive interface and quick customer service
I have been working with Fortinet FortiGate, WatchGuard, Sophos, and SonicWall. I'm not as comfortable with SonicWall because of their UI and limitations. I prefer Fortinet above all other options. When it comes to configuration, I am confident in my ability to handle various tasks, including creating policies such as firewall rules, web policies, and application policies. Additionally, I can configure VPNs and implement load balancing, among other tasks. Overall, I feel much more comfortable working with Fortinet. Fortinet has made significant improvements by integrating AI with firewalls for threat analysis and prevention. In the past 2-3 years, they have launched FortiSASE and SIEM, and they also provide SOC services. Both Palo Alto and Fortinet FortiGate are excellent. While Fortinet FortiGate comes at higher prices, the functionality and support justify the cost. They promptly resolve firmware issues and inform all support providers about configuration changes.
reviewer2774055 - PeerSpot reviewer
Cybersecurity Engineer at a tech consulting company with 51-200 employees
Improved network segmentation has reduced lateral movement while the interface still needs modernization
For threat prevention, I noticed on another customer that there were repeated scanning and exploit attempts against some public-facing service running on HTTPS. I configured Forcepoint Next Generation Firewall to handle IPS by enabling it with critical and high severity signatures only to reduce false positives. I turned on IP reputation filtering to filter out known malicious networks, applied rate limiting on specific services in the DMZ, and logged events centrally for correlation. As a result, exploit attempts were much less than before, being blocked before reaching the back-end servers from the firewall itself, with no performance degradation on the applications. The security team received clear and actionable logs that were centralized, so they knew what was happening all the time. Strong network segmentation is my favorite feature that Forcepoint Next Generation Firewall offers. The policies are very deterministic and readable, and it has excellent east-west blocking and least privilege architecture. Application awareness identifies traffic beyond just the port itself; I can identify the application using a specific port and block risky applications even if they use allowed ports, which is great for environments with shadow IT. The integrated threat prevention is also very good, with IPS featuring well-tuned signatures and reputation-based filtering that blocks known bad actors before they can touch any applications. It supports both IPsec and SSL VPN tunnels, along with site-to-site, client-to-site, and hybrid cloud links, integrating well with Active Directory and LDAP. Additionally, centralized log management and reporting are very actionable and structured, with clarity in the policies for auditing. Overall, its stability and reliability are commendable. A real example of how Forcepoint Next Generation Firewall's readable policies and application awareness features made my work easier was fixing a flat network problem without breaking actual applications. I inherited an environment where users, application servers, and databases were loosely segmented, with port-based and messy firewall rules. Security audits flagged lateral movement risks, and application owners were scared of outages if I tightened security too much. Forcepoint Next Generation Firewall made it easy by providing very easy-to-read and logical policies. I built policies that are clear, showing communications from the user zone to the application zone to specific applications, or from the app zone to the database zone, using only required database protocols. By default, I applied a deny rule between zones unless explicitly allowed by the readable rules I implemented. The policy view clarified who talks to whom, which rules exist, why they exist, and the business function they support, effectively stopping port abuse. Security posture has definitely improved greatly since using Forcepoint Next Generation Firewall. From a flat or semi-flat network, I now have clear zone-based segmentation, with increased operational efficiency. The admins using the firewall have rules that are easy to read and intent-based, making changes easier to review and approve. There is less fear that one wrong rule could break production and fewer outages caused by security changes, without hidden matches or rule shadowing surprises. Clear hit count visibility helps me clean unused rules, leading to much fewer outages caused by changes on the firewalls. The centralized log management with supported log types provides better visibility for the SOC team and the SIEM team, as Forcepoint Next Generation Firewall sends very easy-to-parse and search clear logs to the SOC team. I did see measurable, defensible results after using Forcepoint Next Generation Firewall, including fewer security incidents reaching the back-end servers. This reduction is due to strong segmentation, application awareness, and IPS features, leading to a 60 to 70 percent reduction in security alerts that actually reach the servers. DMZ exploit attempts dropped to near zero, and no lateral movement incidents were detected post network segmentation. Additionally, overall SOC efficiency improved due to well-structured and contextual logs reflecting clear policy intent, resulting in a 35 to 40 percent reduction in mean time to triage. SOC analysts stopped chasing noise and false positives, as they had much clearer logs to use confidently.
TahirMahmood - PeerSpot reviewer
IT Manager at Zubair Feeds
Is stable and has a user-friendly dashboard and a good interface
We installed Hillstone T-Series after a ransomware attack. The dashboard and user interface are very good We cannot secure a specific IP class with this firewall. Another loophole with Hillstone T-Series is that when we connect through WiFi and turn our hot spot on, all who connect through the…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Fortinet FortiGate IPS has an easy-to-use interface and configuration."
"The combined license for the network, the next-generation firewall, and the integration with SD-WAN for all branches are what I consider to be the best features. It's effective for multi-branch customers."
"The overall features of Fortinet FortiGate SWG are good."
"Its administrative panel is very intuitive and simple, and we are able to filter everything on our network and also use the VPN feature, which is important these days when people are working remotely during COVID."
"I prefer FortiGate because it has a lot of other solutions embedded within it and is the easiest for our technicians to operate."
"FortiGate Secure SD-WAN includes best-of-breed next-generation firewall (NGFW) security, SD-WAN, advanced routing, and WAN optimization capabilities, delivering a security-driven networking WAN edge transformation in a unified offering."
"It's a flexible solution."
"The services from Fortinet products are very, very good, the WIFI that Fortinet provides for us is fantastic, the VPN tunnel is very stable with more than one option which is helpful, and it is a very, very, very useful tool."
"I have found that Forcepoint Next Generation Firewall is easy to use, highly secure, and the main VPN tunnel is created automatically which is a benefit."
"The most valuable feature is SD-WAN."
"The most valuable feature is the console management."
"I have found that Forcepoint Next Generation Firewall is easy to use, highly secure, and the main VPN tunnel is created automatically which is a benefit."
"Next Generation Firewall's best feature is that it can be managed on one platform."
"One of the most valuable features is having the ability to cluster multiple firewalls even if they are different versions."
"When comparing this solution to others this one has better reporting, user management, and is easy to use."
"They offer templates that provide detailed reports categorized by user, device, and internal network access."
"The only firewall able to monitor traffic from a CCTV network. Can detect unauthorized devices plugged into the network, which standard firewalls can't do."
"It has been stable so far."
"We installed Hillstone T-Series after a ransomware attack. The dashboard and user interface are very good."
"We found some limitations with Fortinet FortiGate, and we are satisfied with Hillstone T-Series right now."
"Hillstone supports IOT setup and detecting intrusions from IOT or CCTV connectivity, and with this solution, we can also detect unauthorized devices plugged into the CCTV network and sound the alarm to the administrator."
 

Cons

"My only complaint about FortiGate is a lack of QinQ VLAN tunneling."
"The SD-WAN functionality is a bit overly complicated and not fully documented."
"The people we are working with are not able to configure MFA. They are having some technical issues. Fortinet needs to ensure that its partners are well-trained."
"The graphical user interface of Fortinet FortiGate SWG is an area of concern where improvements are required."
"The customization could be improved. Cisco, for example, is much better at this."
"Fortinet technical support is lacking, as OEM support is slightly better."
"It is complicated to manage different kinds of on-premise boxes."
"It should provide better visibility over the network and more information in the form of reports for the end users."
"My team is looking for more throughput and better integration with our security framework."
"They should have a local vendor who can provide support. Most of the support is overseas, so the time zones can be a problem."
"Forcepoint Next Generation Firewall is overall good, but AI enabled features are not available."
"My team is looking for more throughput and better integration with our security framework."
"However, one downside that I see is that they need to improve some network functionality."
"They should have a GUI on the product itself, not a separate management tool to be used on the management server or on a server to be used to manage the file."
"This solution would be improved with the inclusion of custom reporting."
"The initial setup of the Forcepoint Next Generation Firewall has areas that are difficult."
"Licensing is not cheap, but there are customers who will buy because they understand that this has a cost involved and they will cater their budget for that."
"They have a very good technical support team, but I think there are some communication issues due to language differences."
"Another loophole with Hillstone T-Series is that when we connect through WiFi and turn our hot spot on, all who connect through the hotspot get all the functions, and the security does not work."
"Licensing is not cheap."
"They have a very good technical support team, but I think there are some communication issues due to language differences."
 

Pricing and Cost Advice

"We have the full license that included all of the features and support."
"The price of FortiGate is comparable to that of most other firewall solutions and is more affordable than Cisco."
"I do not have first-hand experience with the rice of Fortinet FortiGate, but I have heard the price was reasonable."
"A year or two years back, its price was competitive and reasonable. That was one of the reasons that people easily switched to Fortinet. Over the last two years, the prices have increased drastically. However, the prices of others have also increased. An advantage is there from the price point but not as much as it was previously."
"They are more expensive than others."
"Our licensing costs are on a yearly basis."
"FortiGate SWG is a cost-effective solution well-suited for organisations of all sizes."
"I would rate pricing to be about four or five out of ten, it is reasonable."
"It requires a yearly subscription."
"I consider Forcepoint Next Generation Firewall's price to be good."
"We have just a subscription for the cloud, and this license is great. The license is so good."
"It is an affordable product. We purchase its yearly license."
"The big advantage of this solution is that we can select the right model for our requirements, which is not too expensive."
"The training that they offer to their end-customers. It's quite expensive, I believe it costs roughly $11,000"
"It could be cheaper like Fortinet."
"I believe the licensing fee is for one year, three years, and five years, or something like that. If you wants to increase the support level from a simpler level to platinum, I think that there's a cost. There are differences between every kind of support, but I don't know the numbers."
"We got a much cheaper price than that provided by Fortinet right now."
"On a scale from one to ten, with one being low and ten being high price, I would rate the price of Hillstone T-Series at three. There are no additional costs other than renewal costs."
report
Use our free recommendation engine to learn which Firewalls solutions are best for your needs.
885,376 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
11%
Comms Service Provider
9%
Manufacturing Company
8%
Financial Services Firm
6%
Manufacturing Company
9%
Computer Software Company
9%
Construction Company
8%
Financial Services Firm
7%
No data available
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business364
Midsize Enterprise135
Large Enterprise190
By reviewers
Company SizeCount
Small Business29
Midsize Enterprise10
Large Enterprise12
No data available
 

Questions from the Community

Which is the better NGFW: Fortinet Fortigate or Cisco Firepower?
When you compare these firewalls you can identify them with different features, advantages, practices and usage a...
What is the biggest difference between Sophos XG and FortiGate?
From my experience regarding both the Sophos and FortiGate firewalls, I personally would rather use FortiGate. I know...
What are the biggest technical differences between Sophos UTM and Fortinet FortiGate?
As a solution, Sophos UTM offers a lot of functionality, it scales well, and the stability and performance are quite ...
What is your experience regarding pricing and costs for Forcepoint Next Generation Firewall?
My experience with pricing, setup cost, and licensing is limited because I do not work with pricing, but I have exper...
What needs improvement with Forcepoint Next Generation Firewall?
I found one problem with Forcepoint Next Generation Firewall. They still do not have any VPN clients for Windows comp...
Ask a question
Earn 20 points
 

Also Known As

Fortinet FortiGate Next-Generation Firewall
Forcepoint NGFW, Stonesoft Next Generation Firewall, McAfee Network Security Platform, Intel Security Network Security Platform
Hillstone T-Series Intelligent Next-Generation Firewalls, Hillstone iNGFW
 

Overview

 

Sample Customers

Amazon Web Services, Microsoft, IBM, Cisco, Dell, HP, Oracle, Verizon, AT&T, T-Mobile, Sprint, Vodafone, Orange, BT Group, Telstra, Deutsche Telekom, Comcast, Time Warner Cable, CenturyLink, NTT Communications, Tata Communications, SoftBank, China Mobile, Singtel, Telus, Rogers Communications, Bell Canada, Telkom Indonesia, Telkom South Africa, Telmex, Telia Company, Telkom Kenya
California Department of Corrections and Rehabilitation (CDCR)
University of Córdoba
Find out what your peers are saying about Forcepoint Next Generation Firewall vs. Hillstone T-Series and other solutions. Updated: March 2026.
885,376 professionals have used our research since 2012.