Try our new research platform with insights from 80,000+ expert users

Forcepoint Next Generation Firewall vs Netgate pfSense Plus Firewall/VPN/Router comparison

Sponsored
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Fortinet FortiGate
Sponsored
Ranking in Firewalls
1st
Average Rating
8.4
Reviews Sentiment
6.9
Number of Reviews
580
Ranking in other categories
Secure Web Gateways (SWG) (2nd), Intrusion Detection and Prevention Software (IDPS) (1st), Software Defined WAN (SD-WAN) Solutions (1st), WAN Edge (1st), ZTNA (1st), Unified Threat Management (UTM) (1st)
Forcepoint Next Generation ...
Ranking in Firewalls
21st
Average Rating
7.6
Reviews Sentiment
6.6
Number of Reviews
49
Ranking in other categories
Software Defined WAN (SD-WAN) Solutions (9th), WAN Edge (8th)
Netgate pfSense Plus Firewa...
Ranking in Firewalls
27th
Average Rating
9.4
Reviews Sentiment
4.3
Number of Reviews
3
Ranking in other categories
No ranking in other categories
 

Featured Reviews

Vasu Gala - PeerSpot reviewer
Manager, Information Technology Operation/Presales at TechMonarch
A stable solution with an intuitive interface and quick customer service
I have been working with Fortinet FortiGate, WatchGuard, Sophos, and SonicWall. I'm not as comfortable with SonicWall because of their UI and limitations. I prefer Fortinet above all other options. When it comes to configuration, I am confident in my ability to handle various tasks, including creating policies such as firewall rules, web policies, and application policies. Additionally, I can configure VPNs and implement load balancing, among other tasks. Overall, I feel much more comfortable working with Fortinet. Fortinet has made significant improvements by integrating AI with firewalls for threat analysis and prevention. In the past 2-3 years, they have launched FortiSASE and SIEM, and they also provide SOC services. Both Palo Alto and Fortinet FortiGate are excellent. While Fortinet FortiGate comes at higher prices, the functionality and support justify the cost. They promptly resolve firmware issues and inform all support providers about configuration changes.
reviewer2774055 - PeerSpot reviewer
Cybersecurity Engineer at a tech consulting company with 51-200 employees
Improved network segmentation has reduced lateral movement while the interface still needs modernization
For threat prevention, I noticed on another customer that there were repeated scanning and exploit attempts against some public-facing service running on HTTPS. I configured Forcepoint Next Generation Firewall to handle IPS by enabling it with critical and high severity signatures only to reduce false positives. I turned on IP reputation filtering to filter out known malicious networks, applied rate limiting on specific services in the DMZ, and logged events centrally for correlation. As a result, exploit attempts were much less than before, being blocked before reaching the back-end servers from the firewall itself, with no performance degradation on the applications. The security team received clear and actionable logs that were centralized, so they knew what was happening all the time. Strong network segmentation is my favorite feature that Forcepoint Next Generation Firewall offers. The policies are very deterministic and readable, and it has excellent east-west blocking and least privilege architecture. Application awareness identifies traffic beyond just the port itself; I can identify the application using a specific port and block risky applications even if they use allowed ports, which is great for environments with shadow IT. The integrated threat prevention is also very good, with IPS featuring well-tuned signatures and reputation-based filtering that blocks known bad actors before they can touch any applications. It supports both IPsec and SSL VPN tunnels, along with site-to-site, client-to-site, and hybrid cloud links, integrating well with Active Directory and LDAP. Additionally, centralized log management and reporting are very actionable and structured, with clarity in the policies for auditing. Overall, its stability and reliability are commendable. A real example of how Forcepoint Next Generation Firewall's readable policies and application awareness features made my work easier was fixing a flat network problem without breaking actual applications. I inherited an environment where users, application servers, and databases were loosely segmented, with port-based and messy firewall rules. Security audits flagged lateral movement risks, and application owners were scared of outages if I tightened security too much. Forcepoint Next Generation Firewall made it easy by providing very easy-to-read and logical policies. I built policies that are clear, showing communications from the user zone to the application zone to specific applications, or from the app zone to the database zone, using only required database protocols. By default, I applied a deny rule between zones unless explicitly allowed by the readable rules I implemented. The policy view clarified who talks to whom, which rules exist, why they exist, and the business function they support, effectively stopping port abuse. Security posture has definitely improved greatly since using Forcepoint Next Generation Firewall. From a flat or semi-flat network, I now have clear zone-based segmentation, with increased operational efficiency. The admins using the firewall have rules that are easy to read and intent-based, making changes easier to review and approve. There is less fear that one wrong rule could break production and fewer outages caused by security changes, without hidden matches or rule shadowing surprises. Clear hit count visibility helps me clean unused rules, leading to much fewer outages caused by changes on the firewalls. The centralized log management with supported log types provides better visibility for the SOC team and the SIEM team, as Forcepoint Next Generation Firewall sends very easy-to-parse and search clear logs to the SOC team. I did see measurable, defensible results after using Forcepoint Next Generation Firewall, including fewer security incidents reaching the back-end servers. This reduction is due to strong segmentation, application awareness, and IPS features, leading to a 60 to 70 percent reduction in security alerts that actually reach the servers. DMZ exploit attempts dropped to near zero, and no lateral movement incidents were detected post network segmentation. Additionally, overall SOC efficiency improved due to well-structured and contextual logs reflecting clear policy intent, resulting in a 35 to 40 percent reduction in mean time to triage. SOC analysts stopped chasing noise and false positives, as they had much clearer logs to use confidently.
Jim Voige - PeerSpot reviewer
Site Manager at a consultancy with 11-50 employees
High availability routing has secured our network and delivers reliable support every day
One downside of Netgate pfSense Plus Firewall_VPN_Router is the need for a better understanding of what hardware it would run on. Right now, we're using Netgate's hardware, but I'm interested in knowing if there are other hardware options available, particularly heavier duty hardware, because the Supermicro 1537 version we have only has a single power supply, which is a shortcoming in an IT environment where dual power supplies are ideal. The pricing for the hardware of Netgate pfSense Plus Firewall_VPN_Router is steep, which is one reason I'd explore other options. I'm familiar with the costs of Supermicro servers, and I believe Netgate charges a premium for their server hardware without enough upside to justify it. The pricing is not justified.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"FortiGate Next Generation Firewall's design is good...I am very impressed with the product's stability."
"The initial setup is straightforward."
"Fortinet FortiGate's ease of management is the most valuable feature."
"Our project needs to link two sides through the internet. One of these was in Cairo and the other in another city. We used FortiGate as the integrating solution between the two locations, i.e. the Fortinet 30E & 100E."
"The system is very easy to scale."
"There are multiple features I have found to be valuable, such as encryption and integrated security features."
"The ease of use, concise reports, and threat identification are very user-friendly and valuable."
"The interface is user-friendly, so it's easy to add policies and block traffic."
"It is a stable solution, and there are no issues so far."
"The product's initial setup phase is easy."
"The initial setup is very easy."
"The VPN is great."
"The Forcepoint Next Generation Firewall is a scalable product."
"I like the IPS. IPS is the master feature. I depend on the firewall and sandbox."
"When comparing this solution to others this one has better reporting, user management, and is easy to use."
"The people we deal with is a local partner in Cambodia and we can get good support from them."
"Overall, the entire Netgate pfSense Plus Firewall_VPN_Router product has been reliable, though some of their smaller gear aimed at remote offices hasn't been cost-effective."
"It's very simple to use, efficient, up to date, and the hardware is very available; it's very safe."
"I do not have complaints about Netgate pfSense Plus Firewall_VPN_Router with Firewall, VPN, and Router; it is really comfortable for use, and it does a pretty good job."
 

Cons

"While the security is good, we'd always prefer if it was even better to ensure protection."
"The AI with Fortinet FortiGate is not very well integrated on their devices, and their cloud infrastructure is not as good as Cisco's."
"There should be more testing before releasing software since it can be a little buggy sometimes when new features come out after updates."
"A lack of integration between our data centers."
"The price of FortiGate should be reduced because there are some other leading products that are cheaper."
"Fortigate's hardware capacities could be improved."
"I want some additional features. For example, I want something to ensure that when we are using Google email or Microsoft email, or Google Workspace, emails can only be accessed on designated machines given to our employees. I would like them to access data from designated machines, not from any machine. It should work for designated mobiles and laptops. I don't know if Fortinet provides something like that out of the box."
"I would like to see more advanced developments of a wireless controller in the future."
"They need to improve their alerts."
"Technical support is sometimes slow to respond, and it takes longer to resolve issues."
"They should have a GUI on the product itself, not a separate management tool to be used on the management server or on a server to be used to manage the file. It should be all in one device. The device should be controlled through its own GUI. They also have to improve the learning center and the documents as the documents don't really help."
"Something that I've noticed that Forcepoint lacks, is the training that they offer to their end-customers"
"Forcepoint Next Generation Firewall could change its interface, allowing standard or direct connect modes to be configured."
"Configuration is not easy because it has an old-fashioned interface. The configuration interface is highly complex, and it's been the same for years. They have to change the interface."
"My experience with this Forcepoint Next Generation Firewall wasn't very pleasant due to its complexity. For example, the firewall loses some features when working in a cluster, which is a huge challenge. It caused me several weeks to solve an issue to make the VPN work, even after opening several cases with support. Also, the debug, which should provide essential knowledge about everything going on, the flow of traffic, and how the engine works, wasn't very informative in identifying the issue."
"We feel the product's technical support could be better, as this relates to the solution itself, to the installation of the product, and to having a proper understanding of the case."
"The effectiveness of Netgate pfSense Plus Firewall_VPN_Router traffic shaping is quite good, but I am not very satisfied with the interface for control."
"The pricing for the hardware of Netgate pfSense Plus Firewall_VPN_Router is steep, which is one reason I'd explore other options."
 

Pricing and Cost Advice

"Pricing is good. They offer a lot of things, the most important is the support. Every time you upgrade your license, you also get insurance for the equipment. If you have any problem with equipment, they send in new equipment."
"Although the solution's pricing is high, compared with other products, it may be cheap."
"It was probably about $2,500 per firewall. It was all included. It included support, services, threat management software, and 24/7 FortiCare on it. Cisco products are more expensive."
"It was worth the money overall. It's good value."
"The price is okay."
"We are on an annual license to use Fortinet FortiGate."
"The price is okay, so far so good."
"The license is too expensive to renew. The license renewal process is also complex."
"It is expensive."
"The solution is expensive."
"We have just a subscription for the cloud, and this license is great. The license is so good."
"The big advantage of this solution is that we can select the right model for our requirements, which is not too expensive."
"Forcepoint is very expensive but it's really secure."
"It requires a yearly subscription."
"It could be cheaper like Fortinet."
"The pricing of the solution is normally competitive with other products."
Information not available
report
Use our free recommendation engine to learn which Firewalls solutions are best for your needs.
881,114 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
12%
Comms Service Provider
9%
Manufacturing Company
8%
Financial Services Firm
6%
Manufacturing Company
11%
Computer Software Company
9%
Financial Services Firm
9%
Government
8%
No data available
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business357
Midsize Enterprise133
Large Enterprise188
By reviewers
Company SizeCount
Small Business28
Midsize Enterprise10
Large Enterprise11
No data available
 

Questions from the Community

Which is the better NGFW: Fortinet Fortigate or Cisco Firepower?
When you compare these firewalls you can identify them with different features, advantages, practices and usage a...
What is the biggest difference between Sophos XG and FortiGate?
From my experience regarding both the Sophos and FortiGate firewalls, I personally would rather use FortiGate. I know...
What are the biggest technical differences between Sophos UTM and Fortinet FortiGate?
As a solution, Sophos UTM offers a lot of functionality, it scales well, and the stability and performance are quite ...
What is your experience regarding pricing and costs for Forcepoint Next Generation Firewall?
My experience with pricing, setup cost, and licensing is limited because I do not work with pricing, but I have exper...
What needs improvement with Forcepoint Next Generation Firewall?
Forcepoint Next Generation Firewall is overall good, but AI enabled features are not available. Many templates and AI...
What needs improvement with Netgate pfSense Plus Firewall/VPN/Router?
One downside of Netgate pfSense Plus Firewall_VPN_Router is the need for a better understanding of what hardware it w...
What is your primary use case for Netgate pfSense Plus Firewall/VPN/Router?
We use Netgate pfSense Plus Firewall_VPN_Router as a high availability BGP solution.
What advice do you have for others considering Netgate pfSense Plus Firewall/VPN/Router?
We use the Plus version of Netgate pfSense Plus Firewall_VPN_Router, which comes automatically with any Netgate hardw...
 

Also Known As

Fortinet FortiGate Next-Generation Firewall
Forcepoint NGFW, Stonesoft Next Generation Firewall, McAfee Network Security Platform, Intel Security Network Security Platform
No data available
 

Overview

Information not available
 

Sample Customers

Amazon Web Services, Microsoft, IBM, Cisco, Dell, HP, Oracle, Verizon, AT&T, T-Mobile, Sprint, Vodafone, Orange, BT Group, Telstra, Deutsche Telekom, Comcast, Time Warner Cable, CenturyLink, NTT Communications, Tata Communications, SoftBank, China Mobile, Singtel, Telus, Rogers Communications, Bell Canada, Telkom Indonesia, Telkom South Africa, Telmex, Telia Company, Telkom Kenya
California Department of Corrections and Rehabilitation (CDCR)
Information Not Available
Find out what your peers are saying about Forcepoint Next Generation Firewall vs. Netgate pfSense Plus Firewall/VPN/Router and other solutions. Updated: January 2026.
881,114 professionals have used our research since 2012.