Try our new research platform with insights from 80,000+ expert users

Forcepoint Next Generation Firewall vs Juniper Contrail SD-WAN comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Sep 16, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Fortinet FortiGate
Sponsored
Ranking in Software Defined WAN (SD-WAN) Solutions
1st
Ranking in WAN Edge
1st
Average Rating
8.4
Reviews Sentiment
7.2
Number of Reviews
330
Ranking in other categories
Firewalls (2nd)
Forcepoint Next Generation ...
Ranking in Software Defined WAN (SD-WAN) Solutions
11th
Ranking in WAN Edge
12th
Average Rating
7.6
Reviews Sentiment
6.7
Number of Reviews
44
Ranking in other categories
Firewalls (27th)
Juniper Contrail SD-WAN
Ranking in Software Defined WAN (SD-WAN) Solutions
14th
Ranking in WAN Edge
14th
Average Rating
7.4
Reviews Sentiment
6.6
Number of Reviews
6
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of May 2025, in the Software Defined WAN (SD-WAN) Solutions category, the mindshare of Fortinet FortiGate is 21.1%, up from 20.8% compared to the previous year. The mindshare of Forcepoint Next Generation Firewall is 2.2%, up from 2.1% compared to the previous year. The mindshare of Juniper Contrail SD-WAN is 0.9%, up from 0.9% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Software Defined WAN (SD-WAN) Solutions
 

Featured Reviews

EhabAli - PeerSpot reviewer
Efficient, user-friendly, and affordable
In the past, NSS Labs was utilized to test files and verify the numbers and datasheets. It would be beneficial to have an organization or testing lab that can verify the numbers in our datasheets since changes are frequently made, which can be inconvenient for review. For instance, when comparing different competitors such as Forcepoint, Palo Alto, and Check Point, the throughput or numbers in the datasheet may be lower than the actual numbers. Conversely, Fortinet typically reports very high numbers, but they cannot be replicated in the real world. Therefore, it would be advantageous for them to partner with a neutral testing organization such as NSS Labs to validate these numbers, thus providing more credibility and comfort to everyone regarding the accuracy of the datasheets. For the migration, everyone has a firewall in use and I am selling Fortinet. Typically, I am replacing another firewall. Previously, there was a tool available to convert configurations from one firewall, such as Palo Alto, to Fortinet, but this tool is no longer free. If it could be made free again, it would be very beneficial. This tool shows a lot of promise and is very good. Making it free would help many companies deliver their products in a more efficient and integrated way. It would also be more valuable to include the tool with the firewall package or license instead of having to pay extra for it. Paying extra puts more pressure on small companies to deliver the firewall and complete the configuration, especially if they have hundreds or thousands of policies. It's very painful to move through these policies line by line. The stability has room for improvement. When it comes to Secure SD-WAN, everything is fine. They are going the right way. SD-WAN is very promising. They can provide the SD-WAN solution separately, but they will not take this approach because even the smallest firewall can support the features, so there is no need to have a separate service or appliance. They are following the right steps, and there is nothing to be improved. Feature-wise, I'm really satisfied with the new release, and the features they have added. For now, it's fine.
OusaidAbaz - PeerSpot reviewer
Provides decent protection for the LAN but complicated interface
We had some licensing issues with its web filtering capabilities. That's why we migrated our web filtering to Cisco Umbrella. Moreover, the interface is complicated. It's difficult to locate all the necessary menus and functions. For example, one of the many issues is with SSH. Even now, we haven't successfully opened the port to connect using SSH mode when we want to change the configuration. It's like a black box—not very open to changes and customization. It's simply not easy to configure. There are other problems, too. For example regarding Forcepoint's Websense component. We had a lot of problems managing the web settings within Websense. That's why we migrated to Cisco Umbrella for cloud-based web filtering. It's not that Forcepoint is inherently bad. The issue is that it's not user-friendly. It is not easy to use. The developers need to redesign the interface (GUI) for better management. It is very difficult to manage. For example, simple actions require too many clicks compared to FortiGate or Palo Alto. That's the main problem.
Luis Corrochano - PeerSpot reviewer
A stable and scalable solution that helps to cut cost by reducing MPLs
My customers use the solution to have better control and knowledge about the applications inside ONE Access. It also helps them cut costs by reducing MPLs and using better internet access from FTTH.  The solution is expensive. Its support can be better.  The tool is stable.  The solution is more…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The SD-WAN feature of Fortinet FortiGate has been most impactful in maintaining our network's integrity."
"The SD-WAN function is very developed. It has SD-WAN functionality with security features in one device. We can manage from one single console SD-WAN and the security policy."
"FortiGate has a very strong unified threat management system."
"The customization potential is quite impressive."
"The features that we have found most valuable are the SSL VPN and the User Portal."
"What's most important is the ease of use."
"FortiGate firewalls are easy to manage through a user-friendly web interface. They also have advanced features like DDoS and DLP. However, I wouldn't recommend enabling all of these features on one device because it can cause performance issues."
"It's very good and very stable for businesses. It works very well."
"The people we deal with is a local partner in Cambodia and we can get good support from them."
"The most valuable features of Forcepoint Next Generation Firewall are the advanced threat protection, including features like IPS and DDoS prevention, which help avoid internal DDoS attacks."
"It provides decent protection for the LAN, especially in run mode."
"The most valuable feature is controlling the traffic and the logging. They have real-time logins for traffic logs. Troubleshooting was very easy for me."
"The most valuable feature is SD-WAN."
"They offer templates that provide detailed reports categorized by user, device, and internal network access."
"One of the most valuable features is having the ability to cluster multiple firewalls even if they are different versions."
"Technical support has been quite helpful in the past."
"It supports desktop management, network management, and SD-WAN policies."
"The solution is more specific about what's happening since it explains where the problem may lie and points out areas where there is a problem. So, we like that it provides more visibility."
"My customers use the solution to have better control and knowledge about the applications inside ONE Access. It also helps them cut costs by reducing MPLs and using better internet access from FTTH."
"The support is very good from Juniper and from the local distributors."
"It gives you that level of visibility to understand what's going on between layer four and layer seven."
"I've worked with several SD-WAN solutions over the past few years, and the product felt more like an automated provisioning tool. Unlike solutions from Palo Alto or other SD-WANs orchestrated by a SaaS solution, Juniper Contrail SD-WAN already had the files and built their SaaS to orchestrate the configuration. Initially, you didn't do much, but then it started adding some routing capabilities."
 

Cons

"There are SD-WAN network monitoring, SD-WAN features, Industrial Databases, Internet of Things, Detection, etc., however, we do have not licenses for those features. We thought that if you bought a product, you should have all of the features it offers. Why should you need to make so many extra purchases to enable features? They should have one price for the entire offering."
"They should make the rule sets more understandable for the end user. When you're trying to explain to somebody how a computer network is secured, sometimes it's difficult for an end user or customer to understand. If there was a way to make the terminology more accessible to the end user, the set up could be easier. They should translate the technical jargon to an easily relatable and understandable conversation for the end user, the customer, that would be brilliant. Particularly in an environment where the IT structure is audited regularly, there's always pressure from the auditor to up the standards and up the security and you get your USCERT's that come out and there's a warning about this and the customer will want to lock out so much and when you apply it they run into issue where they can't search the internet or print to their remote office. Of course they can't print to your remote office, they just locked it up. They should make the language more understandable for the customer. If there's a product out there that made the jargon understandable to John Q. Public, I would buy that."
"Fortinet technical support is lacking, as OEM support is slightly better."
"It is stable, but its stability can be improved."
"There is room for improvement related to the logging and reporting aspect."
"The ease of use could be improved."
"Fortinet FortiGate can improve by integrating the web application firewall and the DDoS protection part of the solution. Having a WAF feature, web application firewall, and proxy together would be a good benefit."
"Fortinet doesn't provide multiple virtual firewalls which would facilitate end users and customers."
"They need to work on stability, it has not been the best in our experience."
"You do need knowledge of the solution in order to set the product up properly."
"In larger companies with extensive infrastructure, retrieving logs for a longer period of time can sometimes take a bit longer than desired."
"The solution's support could use improvement."
"The security features need to be improved."
"Management could be better. They can improve the management. I think all our customers can't accept firewalls that have standalone management. So, they prefer Fortinet or Palo Alto. But overall, inspection and other features are working fine."
"Its management center should be easier to use. The management interface of Forcepoint is unique and a little bit different from some of the firewall solutions on which people might have worked before. Sometimes, the customers say that it is not very friendly, and we help them with how to use this management interface. It just takes a little bit of time, and after some time, it gets easy to manage or use. It is quite similar to Palo Alto, Fortinet, and legacy Juniper solutions. Their support should be faster. We have received complaints that they are not responding fast, which is not good for the vendor and us."
"Forcepoint is a little difficult to configure compared to its competitors."
"The only issue was the switch we got, which was a little problematic because it was PoC equipment, and we had a little problem with that."
"The solution is expensive. Its support can be better."
"Areas for improvement in the Juniper Contrail SD-WAN solution include the on-premises deployment process."
"The solution installs similarly to competitors. It is not more difficult or easier. However, it could be easier and take less time for the installation."
"Implementing new branches or changing existing ones in Juniper Contrail SD-WAN wasn't as straightforward as with other solutions like Meraki SD-WAN, which is almost plug-and-play with its zero-touch provisioning. In Juniper Contrail SD-WAN, it was more challenging."
"The training could be better. When it comes to the demo dashboard capability, I feel like it could be much easier for our customers to use. Our last customer complained about this."
 

Pricing and Cost Advice

"We purchased a five-year bundle package, which worked out cheaper than competing solutions."
"Other firewalls are more expensive than Fortinet FortiGate, such as the Azure firewall."
"The price for the Fortinet FortiGate is reasonable. Secure SD-WAN is free of charge. If you have their firewall, it's free of charge. It's very tempting."
"The price of FortiGate is reasonable as I plan to buy new switches. The initial gadgets are already booted, and the pricing seems normal on the market. As for additional costs, I haven't subscribed to many extra features, so I'm only using what I need. Last year, I renewed the support for three years, which can sometimes be expensive but depends on the security benefits and how it helps us."
"Licensing is usually on a three-year period."
"There is a license to use Fortinet FortiGate."
"Fortinet Secure SD-WAN delivered the lowest total cost of ownership (TCO) per Mbps among all other vendors."
"The price depends on the size of the company. From the beginning, you just want to know the internet bandwidths, speed, and the number of users to be able to offer the right product and model. They have a lot of products in FortiGate according to the size of the company, like 200D and 300D."
"The big advantage of this solution is that we can select the right model for our requirements, which is not too expensive."
"The training that they offer to their end-customers. It's quite expensive, I believe it costs roughly $11,000"
"Next Generation Firewall is moderately priced."
"It is an affordable product. We purchase its yearly license."
"It could be cheaper like Fortinet."
"Forcepoint Next Generation Firewall is reasonable, it is priced the same as other firewalls."
"The pricing should be more competitive against other vendors in the market."
"The cost is fair, but it could be improved."
"The licensing structure is very flexible."
"The cost of the solution is a little expensive. The hardware is a one-time purchase fee and the software is purchased on an annual basis. There are additional costs for other software features that are available which are on an annual basis, such as extra capacity."
"They are neither very expensive nor cheap. So, we can consider its pricing somewhere in the middle."
report
Use our free recommendation engine to learn which Software Defined WAN (SD-WAN) Solutions solutions are best for your needs.
850,028 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Educational Organization
20%
Computer Software Company
14%
Comms Service Provider
7%
Manufacturing Company
6%
Computer Software Company
18%
Manufacturing Company
10%
Financial Services Firm
10%
Government
9%
Educational Organization
32%
Computer Software Company
13%
Government
8%
Financial Services Firm
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

Which is the better NGFW: Fortinet Fortigate or Cisco Firepower?
When you compare these firewalls you can identify them with different features, advantages, practices and usage a...
What is the biggest difference between Sophos XG and FortiGate?
From my experience regarding both the Sophos and FortiGate firewalls, I personally would rather use FortiGate. I know...
What are the biggest technical differences between Sophos UTM and Fortinet FortiGate?
As a solution, Sophos UTM offers a lot of functionality, it scales well, and the stability and performance are quite ...
What is your experience regarding pricing and costs for Forcepoint Next Generation Firewall?
The licensing model is dependent on negotiation skills, but there is room for improvement. The costs can be high sinc...
What needs improvement with Forcepoint Next Generation Firewall?
The licensing model should be more flexible. I recommend that additional features be included in a single license to ...
What do you like most about Juniper Contrail SD-WAN?
I've worked with several SD-WAN solutions over the past few years, and the product felt more like an automated provis...
What is your experience regarding pricing and costs for Juniper Contrail SD-WAN?
My advice regarding setup costs, pricing, and licensing for Juniper Contrail SD-WAN would be to carefully evaluate an...
What needs improvement with Juniper Contrail SD-WAN?
Implementing new branches or changing existing ones in Juniper Contrail SD-WAN wasn't as straightforward as with othe...
 

Also Known As

FortiGate 60b, FortiGate 60c, FortiGate 80c, FortiGate 50b, FortiGate 200b, FortiGate 110c, FortiGate, Fortinet Firewall
Forcepoint NGFW, Stonesoft Next Generation Firewall, McAfee Network Security Platform, Intel Security Network Security Platform
Contrail SD-WAN
 

Overview

 

Sample Customers

Amazon Web Services, Microsoft, IBM, Cisco, Dell, HP, Oracle, Verizon, AT&T, T-Mobile, Sprint, Vodafone, Orange, BT Group, Telstra, Deutsche Telekom, Comcast, Time Warner Cable, CenturyLink, NTT Communications, Tata Communications, SoftBank, China Mobile, Singtel, Telus, Rogers Communications, Bell Canada, Telkom Indonesia, Telkom South Africa, Telmex, Telia Company, Telkom Kenya
California Department of Corrections and Rehabilitation (CDCR)
Allied Pinnacle
Find out what your peers are saying about Forcepoint Next Generation Firewall vs. Juniper Contrail SD-WAN and other solutions. Updated: April 2025.
850,028 professionals have used our research since 2012.