No more typing reviews! Try our Samantha, our new voice AI agent.

Forcepoint Next Generation Firewall vs Sophos UTM vs Trellix Intrusion Prevention System comparison

Why PeerSpot?
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Featured Reviews

Ajit Pratap Kundan - PeerSpot reviewer
Manager Solution Consulting at Accops Systems Pvt Ltd
Unified security management has improved traffic control and simplified remote workforce access
Forcepoint Next Generation Firewall does help in vulnerability identification and response by providing a single unified console through which I am able to monitor and manage infrastructure. The URL filtering capability of Forcepoint Next Generation Firewall helps in blocking malicious sites. We have to take care of both known threats and unknown threats. The firewall takes care of known threats, and we protect ourselves from unknown threats such as malicious code and malware that we cannot create firewall rules for. With these routing capabilities and policies, only whitelisted things get processed or passed. The biggest advantages of Forcepoint Next Generation Firewall, especially as a partner, service provider, and integrator, are that it is very easy to integrate these APIs with our solution, and most of the features I am getting in the clientless mode. Even with the client mode, it is easy to integrate with our client, allowing the customer to get a single client to address all the features of the firewall as well as the GTNA perspective. The flexibility of deployment, especially for the government and defense sectors, is that they want an on-premises solution, while the rest of the PSUs or enterprise segment are comfortable with the cloud offering, which is the SaaS offering and the way to go in the future.
HR
CEO at iSource GmbH
Integrated security tools have supported critical infrastructure and improved network performance
Regarding Secureworks Taegis VDR Vulnerability Management, I do not have all these shortcuts in my head. Perhaps I have to ask my technicians, but we are in full stress because we have to change this entire firewall equipment, also the entire access points, because of the end of life. We also have the full product in for XDR and extensions. We are also part of the webinars from Sophos. It would be better if there were also some important webinars in German. Everything needs improvement, because also the wireless, also RED box and so on. The handling was much easier on the old equipment than on the new XGS. I think there should also be a little more automatic for SD-WAN routing and so on. Because we have to learn some things from the basic completely new because it is different than Sophos UTM, the XGS. The features that could be improved about Sophos UTM include the new features we have in XGS with a simpler interface. For example, in Sophos UTM, we could define IP hosts and use this IP host. We did not have to insert on every, for example, for wide area networks, we had to put the IP addresses from the other side by hand. In Sophos UTM, we could define it under definitions and then use this IP host where we needed it. In the new XGS, if there is a change in the IP address, we have to do it on all, for example, site-to-site VPN tunnels and so on. We have much more work and it is not so easy because we have to check all the definitions. It is also, for example, some of the male technicians like me, we have a biology handicap. For example, male technicians in Europe also have a red-green problem. So we use these light colors on the interface. In some cases, it is not easy to see the, for example, letters or numbers because of the contrast.
BS
Large account Manager at Softcell Technologies Limited
Has offered reliable threat protection and detailed network insights but could expand features beyond existing capabilities
The best features of Trellix Intrusion Prevention System include advanced ATP (Advanced Threat Protection), which uses signatures, behavior analysis, and machine learning to stop zero-day exploits and malware advanced persistent threats (APTs). They track and collect data from APTs, which allows them to track malicious files entering the environment. The system offers inline prevention and real-time automatic blocking of malicious packets before they reach the network. It integrates with the Trellix ecosystem and provides application visibility and control. The solution provides deep insight into network traffic, applications, and protocols for better information. All packets coming through the application are analyzed and reported. They share intelligence updates regularly to protect from different malicious files and sector-specific threats. It supports both on-premise and cloud environments.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The solution offers sandboxing, which can be integrated at any time."
"I don't have anything bad to say about the product. I absolutely love it."
"Overall, it is an excellent product, highly reliable, and among the top contenders; Forcepoint Next Generation Firewall is well known."
"The most valuable feature is controlling the traffic and the logging. They have real-time logins for traffic logs. Troubleshooting was very easy for me."
"The most valuable features of Forcepoint Next Generation Firewall are the advanced threat protection, including features like IPS and DDoS prevention, which help avoid internal DDoS attacks."
"I like the Firewall and the IPS."
"The support is great. They also have very good categorization. It's very good. It captures a lot of threats."
"It is stable and scalable. In addition, their support is great. When you ask them for something, they provide support, and if required, they also involve the R&D team to help you to resolve the issues in your configuration."
"The product has provided us with unified threat management as well as comprehensive list of reports."
"It has helped by identifying threats within the company. If there are computers or servers that are compromised, then we are able to identify them right away in the system."
"Sophos UTM provides security for our network here and access through a VPN connection for our remote users. It also offers the flexibility to create different tools for accessibility."
"A nice UTM appliance with a good GUI and reports."
"Beyond the initial cost, licenses are charged for annually, but they are good value for the service we receive."
"Sophos is a unified solution. We have anti-virus protection, firewall rules, knotting, and DACC all in one box."
"The most valuable features of Sophos UTM are the ease of use, it is very user-friendly. You can understand what they implement in the new firmware, and it's easy to manage the firewalls."
"Configuration troubleshooting is eased by the use of the color-coded, live firewall log."
"The ability to centrally manage all the IPS sensors, track the different security events generated by it, and customize the different policies, depending on their location."
"The solution is very stable, reliable, and free of bugs or glitches, and it does not crash or freeze."
"Great monitoring feature."
"We use a lot of the functions this solution provides such as the firewall and the ability to check aliases, and we can monitor and show the traffic that's moving in and out."
"It improved my security by stopping an attack to the signature base, or the behavior base."
"Overall the solution is very good. It offers great protection and gives us a good overview of what is on the network."
"There's a good dashboard you can drill down into. It helps you easily locate intrusions and the source of attacks."
"McAfee NSP is much more stable than Cisco."
 

Cons

"It's a complicated firewall. Until you come to know the firewall inducers, most people don't like the firewall because the components for the firewall are a little bit complex. User-friendliness is a little bit tough. It needs to be user-friendly when creating policies, and pushing policies. Committing takes more time compared to Palo Alto."
"Configuration is not easy because it has an old-fashioned interface. The configuration interface is highly complex, and it's been the same for years. They have to change the interface."
"However, one downside that I see is that they need to improve some network functionality."
"Sometimes Forcepoint Next Generation Firewall is not really stable at all. It has many freezes for no reason, and local support needs to reboot it physically by unplugging the power cable and plugging it back in."
"The centralized management console of Forcepoint Next Generation Firewall is something we have been struggling with because everybody has their own approach, but most customers have mixed solutions."
"The solution isn't scalable."
"If I want to allow access to Facebook, yet not allow the user to access videos, then I am not able to do it with this product."
"Forcepoint Next Generation Firewall can be improved with better response from support."
"They could reduce the price."
"It really needs to update IPSec to enable IKEv2."
"We had some problems with the configuration. They had provided a CloudFormation template, and we had to go several rounds to make it work."
"In Sophos UTM there is always a problem with the routing tables. If you want to see the routing table, you have to use the UI. You can't do it via a web browser. The routing table is better in Fortinet."
"I would like this solution to support ICAP. Also, they no longer support on-premises management, and are forcing clients to use centralized management via the cloud, which I don't agree with."
"If you enable the intrusion prevention option in the firewall any Wordpress deployments on a Plesk server behind the firewall slows down to a crawl, and there is no fix yet."
"SUM cannot manage app control Improve app control system as a whole Extend support for SG until XG has improved significantly."
"Sophos UTM could be simplified, and they can improve on the many other features, like SD-WAN and load balancing."
"The area of concern where the tool needs improvement is how the product prompts users at a network level that helps prevent any wireless network attacks through alerts and notifications."
"The solution needs to improve the graphical interface. And they had a limitation in some of the sensor modems as well."
"The management component could be simplified."
"The deployment was a little difficult, I did it myself."
"There are limited resources for configuration guidance."
"Trellix Intrusion Prevention System does not provide virtual patching."
"The platform’s GUI could be the latest."
"The Network Security Managers could be more stable, agile, and work faster. When it comes to instability, there is room for improvement."
 

Pricing and Cost Advice

"There is a license required to use this solution and we can purchase it for one, two, three, or five years."
"I believe the licensing fee is for one year, three years, and five years, or something like that. If you wants to increase the support level from a simpler level to platinum, I think that there's a cost. There are differences between every kind of support, but I don't know the numbers."
"We have just a subscription for the cloud, and this license is great. The license is so good."
"Forcepoint Next Generation Firewall is reasonable, it is priced the same as other firewalls."
"We would love to take other solution from Forcepoint, but unfortunately the price is too high. That's why we are not considering using Forcepoing for our proxy and DLB. They have a very good DLB, but the matter in the end is the cost."
"It is an affordable product. We purchase its yearly license."
"It requires a yearly subscription."
"The pricing of the solution is normally competitive with other products."
"The price is something that one will need to consider."
"I think the pricing of Sophos is very fair."
"We originally purchased the solution through the AWS Marketplace. I started my proof of concept doing pay-as-you-go, then moved to a VAR for a 'Bring Your Own Licence' (BYOL) licensing model. The BYOL license still requires you to accept the terms of the AWS Marketplace to deploy."
"Sophos UTM has very reasonable pricing."
"If you would like to run an active-passive HA system, you only need to buy an additional hardware without subscription. At other vendors, you need subscription for both devices.​"
"Sophos UTM's pricing is on the cheaper side."
"Sophos UTM is moderately priced, but it could be improved."
"Sophos offers free training when selling their products from within the partner portal.​"
"The tool is competitively priced."
"I rate the product’s pricing an eight out of ten."
report
Use our free recommendation engine to learn which Firewalls solutions are best for your needs.
912,069 professionals have used our research since 2012.
 

Comparison Review

it_user216600 - PeerSpot reviewer
Senior Technical Consultant with 51-200 employees
Jan 3, 2016
Sophos UTM vs. Fortinet FortiGate
I have used both Sophos and Fortinet products in production and I have found the Sophos UTM appliances (hardware and virtual) to be a better fit most of the time -- with a few caveats which I will touch on below. In both instances, the transition from TMG will be mostly straightforward. The main…
 

Top Industries

By visitors reading reviews
Construction Company
13%
Financial Services Firm
10%
Manufacturing Company
9%
Outsourcing Company
8%
Outsourcing Company
13%
Construction Company
12%
Comms Service Provider
10%
Manufacturing Company
8%
Comms Service Provider
13%
Manufacturing Company
11%
Construction Company
8%
Outsourcing Company
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business29
Midsize Enterprise11
Large Enterprise14
By reviewers
Company SizeCount
Small Business75
Midsize Enterprise28
Large Enterprise27
By reviewers
Company SizeCount
Small Business6
Midsize Enterprise6
Large Enterprise6
 

Questions from the Community

What is your experience regarding pricing and costs for Forcepoint Next Generation Firewall?
In terms of price, I would say Forcepoint Next Generation Firewall is not expensive. It is very much comparable to ot...
What needs improvement with Forcepoint Next Generation Firewall?
The negative side of Forcepoint Next Generation Firewall is that the ZTNA part is missing. For that, we have to integ...
What is your primary use case for Forcepoint Next Generation Firewall?
The major use cases for Forcepoint Next Generation Firewall are in government turnkey projects where we require a lot...
What are the biggest technical differences between Sophos UTM and Fortinet FortiGate?
As a solution, Sophos UTM offers a lot of functionality, it scales well, and the stability and performance are quite ...
What is your experience regarding pricing and costs for Sophos UTM?
The pricing for Sophos UTM is reasonable; I do not have an issue with it, though I was considering RED because I have...
What needs improvement with Sophos UTM?
Regarding Secureworks Taegis VDR Vulnerability Management, I do not have all these shortcuts in my head. Perhaps I ha...
What needs improvement with McAfee Network Security Platform?
Trellix Intrusion Prevention System does not provide virtual patching. Patching involves updates on the OS side to ad...
What is your primary use case for McAfee Network Security Platform?
We do not use Trellix Intrusion Prevention System; rather, we sell the Trellix Intrusion Prevention System solution. ...
What advice do you have for others considering McAfee Network Security Platform?
I have experience working with other tools, specifically Trellix solutions such as DLP, EDR, and MDR, as well as with...
 

Also Known As

Forcepoint NGFW, Stonesoft Next Generation Firewall, McAfee Network Security Platform, Intel Security Network Security Platform
Astaro
McAfee Network Security Platform, McAfee NSP, IntruShield Network Intrusion Prevention System, IntruShield Network IPS
 

Overview

 

Sample Customers

California Department of Corrections and Rehabilitation (CDCR)
One Housing Group
Desjardins Group, HollyFrontier, Nubia, Agbar, WNS Global Services, INAIL, Universidad de Las Américas Puebla (UDLAP), Cook County, China Pacific Insurance, Bank Central Asia, California Department of Corrections and Rehabilitation, City of Chicago, Macquarie Telecom, Sutherland Global Services, Texas Tech University Health Sciences Center, United Automotive Electronic Systems
Find out what your peers are saying about Fortinet, Netgate, Cisco and others in Firewalls. Updated: August 2026.
912,069 professionals have used our research since 2012.