Try our new research platform with insights from 80,000+ expert users

Forcepoint Next Generation Firewall vs Sangfor NGAF comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Jan 25, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Fortinet FortiGate
Sponsored
Ranking in Firewalls
1st
Average Rating
8.4
Reviews Sentiment
6.9
Number of Reviews
587
Ranking in other categories
Secure Web Gateways (SWG) (2nd), Intrusion Detection and Prevention Software (IDPS) (1st), Software Defined WAN (SD-WAN) Solutions (1st), WAN Edge (1st), ZTNA (1st), Unified Threat Management (UTM) (1st)
Forcepoint Next Generation ...
Ranking in Firewalls
19th
Average Rating
7.6
Reviews Sentiment
6.4
Number of Reviews
51
Ranking in other categories
Software Defined WAN (SD-WAN) Solutions (8th), WAN Edge (8th)
Sangfor NGAF
Ranking in Firewalls
26th
Average Rating
8.0
Reviews Sentiment
6.5
Number of Reviews
34
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of March 2026, in the Firewalls category, the mindshare of Fortinet FortiGate is 18.3%, down from 21.1% compared to the previous year. The mindshare of Forcepoint Next Generation Firewall is 0.6%, up from 0.4% compared to the previous year. The mindshare of Sangfor NGAF is 1.0%, down from 1.2% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Firewalls Mindshare Distribution
ProductMindshare (%)
Fortinet FortiGate18.3%
Forcepoint Next Generation Firewall0.6%
Sangfor NGAF1.0%
Other80.1%
Firewalls
 

Featured Reviews

Vasu Gala - PeerSpot reviewer
Manager, Information Technology Operation/Presales at TechMonarch
A stable solution with an intuitive interface and quick customer service
I have been working with Fortinet FortiGate, WatchGuard, Sophos, and SonicWall. I'm not as comfortable with SonicWall because of their UI and limitations. I prefer Fortinet above all other options. When it comes to configuration, I am confident in my ability to handle various tasks, including creating policies such as firewall rules, web policies, and application policies. Additionally, I can configure VPNs and implement load balancing, among other tasks. Overall, I feel much more comfortable working with Fortinet. Fortinet has made significant improvements by integrating AI with firewalls for threat analysis and prevention. In the past 2-3 years, they have launched FortiSASE and SIEM, and they also provide SOC services. Both Palo Alto and Fortinet FortiGate are excellent. While Fortinet FortiGate comes at higher prices, the functionality and support justify the cost. They promptly resolve firmware issues and inform all support providers about configuration changes.
reviewer2774055 - PeerSpot reviewer
Cybersecurity Engineer at a tech consulting company with 51-200 employees
Improved network segmentation has reduced lateral movement while the interface still needs modernization
For threat prevention, I noticed on another customer that there were repeated scanning and exploit attempts against some public-facing service running on HTTPS. I configured Forcepoint Next Generation Firewall to handle IPS by enabling it with critical and high severity signatures only to reduce false positives. I turned on IP reputation filtering to filter out known malicious networks, applied rate limiting on specific services in the DMZ, and logged events centrally for correlation. As a result, exploit attempts were much less than before, being blocked before reaching the back-end servers from the firewall itself, with no performance degradation on the applications. The security team received clear and actionable logs that were centralized, so they knew what was happening all the time. Strong network segmentation is my favorite feature that Forcepoint Next Generation Firewall offers. The policies are very deterministic and readable, and it has excellent east-west blocking and least privilege architecture. Application awareness identifies traffic beyond just the port itself; I can identify the application using a specific port and block risky applications even if they use allowed ports, which is great for environments with shadow IT. The integrated threat prevention is also very good, with IPS featuring well-tuned signatures and reputation-based filtering that blocks known bad actors before they can touch any applications. It supports both IPsec and SSL VPN tunnels, along with site-to-site, client-to-site, and hybrid cloud links, integrating well with Active Directory and LDAP. Additionally, centralized log management and reporting are very actionable and structured, with clarity in the policies for auditing. Overall, its stability and reliability are commendable. A real example of how Forcepoint Next Generation Firewall's readable policies and application awareness features made my work easier was fixing a flat network problem without breaking actual applications. I inherited an environment where users, application servers, and databases were loosely segmented, with port-based and messy firewall rules. Security audits flagged lateral movement risks, and application owners were scared of outages if I tightened security too much. Forcepoint Next Generation Firewall made it easy by providing very easy-to-read and logical policies. I built policies that are clear, showing communications from the user zone to the application zone to specific applications, or from the app zone to the database zone, using only required database protocols. By default, I applied a deny rule between zones unless explicitly allowed by the readable rules I implemented. The policy view clarified who talks to whom, which rules exist, why they exist, and the business function they support, effectively stopping port abuse. Security posture has definitely improved greatly since using Forcepoint Next Generation Firewall. From a flat or semi-flat network, I now have clear zone-based segmentation, with increased operational efficiency. The admins using the firewall have rules that are easy to read and intent-based, making changes easier to review and approve. There is less fear that one wrong rule could break production and fewer outages caused by security changes, without hidden matches or rule shadowing surprises. Clear hit count visibility helps me clean unused rules, leading to much fewer outages caused by changes on the firewalls. The centralized log management with supported log types provides better visibility for the SOC team and the SIEM team, as Forcepoint Next Generation Firewall sends very easy-to-parse and search clear logs to the SOC team. I did see measurable, defensible results after using Forcepoint Next Generation Firewall, including fewer security incidents reaching the back-end servers. This reduction is due to strong segmentation, application awareness, and IPS features, leading to a 60 to 70 percent reduction in security alerts that actually reach the servers. DMZ exploit attempts dropped to near zero, and no lateral movement incidents were detected post network segmentation. Additionally, overall SOC efficiency improved due to well-structured and contextual logs reflecting clear policy intent, resulting in a 35 to 40 percent reduction in mean time to triage. SOC analysts stopped chasing noise and false positives, as they had much clearer logs to use confidently.
Zaid Farooqui - PeerSpot reviewer
CIO at Indus Motor Company
Enhanced threat detection with integrated security features and good support
We are using application firewalling, WAF, and SD-WAN. The capabilities are mostly within the box. For example, you will get web application firewall WAF as part and parcel of this. SD-WAN is also bundled. It integrates with their SIEM and SOAR solutions very nicely. Lastly, the pricing point is very cost-efficient as well.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"We've found the solution to be pretty stable."
"FortiGate SD-WAN facilitated a smooth transition for our customers between their two internet service providers, ensuring uninterrupted connectivity without any downtime."
"When you start looking at the cost of the license for all the things that you get, Fortinet is by far the best option."
"Fortinet is the best choice for small enterprises because it provides security as per their requirement and comes under their budget, making the pricing very acceptable for medium-level and small-level enterprise customers."
"The IPsec tunnels are very easily created, and quite interoperable with devices from other vendors."
"We can use our devices to check all of the perimeters. It secures email websites."
"FortiGate is flexible and easy to use."
"It has a good UI and overall integration, including FortiGate Manager for controlling all firewalls from a single place."
"The most valuable feature is the console management."
"Previously, it was very difficult to handle all traffic because multiple locations experienced downtime, firewalls went down, and internet connectivity issues occurred, but after Forcepoint SD-WAN solutions were deployed across different locations, all traffic goes through Wi-Fi solutions, which are directly connected to Forcepoint Next Generation Firewall, making it very easy, time-saving, and improving security."
"The Forcepoint Next Generation Firewall is a scalable product."
"It is a stable solution, and there are no issues so far."
"The most valuable feature is controlling the traffic and the logging. They have real-time logins for traffic logs. Troubleshooting was very easy for me."
"It is stable and scalable. In addition, their support is great. When you ask them for something, they provide support, and if required, they also involve the R&D team to help you to resolve the issues in your configuration."
"Technical support has been quite helpful in the past."
"Forcepoint Next Generation Firewall is quite affordable, cheaper than other brands like Palo Alto or Check Point, with a lot of capabilities, very stable, and very well-made, making it a really good product for its price when compared to other vendors."
"The price versus value is good because the solution is less expensive than Sophos, Fortinet, or SonicWall."
"I think Sangfor NGAF is more valuable than Cisco products because of its simplicity and ease of management. If I compare it with Palo Alto and Cisco, both are quite complex products. And if I compare it with FortiGate firewalls from Fortinet, I have also used all these products. Fortinet and Sangfor NGAF are similar products because the applications behind the application and policy layers are almost identical."
"The VPN connectivity feature is really nice."
"I think the tool has the feature to detect and kill ransomware in three seconds."
"The most valuable features are the WAN optimization, the internet access gateway (IAG), and the central console, which allows us to implement on their firewall."
"Sangfor NGAF specializes in ransomware detection and helps to protect our network from ransomware threats and malware."
"The product is very fast and reliable."
"While the features are not dissimilar to other brands, configuration is much more simple, which works out great for Indonesian people."
 

Cons

"It is somewhat expensive compared to other solutions such as Sophos."
"In our case, the deployment options of FortiGate Next Generation Firewall (NGFW) are not scalable, but in terms of connectivity to other companies, that's exactly what we needed, and that's exactly what it does perfectly, what is needed."
"Fortinet FortiGate could improve if it had a cloud-managed solution."
"I think the only issue that needs improvement is the interface."
"The stability and performance of Fortinet FortiGate are mixed, as some features are quite good and very stable while others are quite new and very buggy."
"I would suggest that Fortinet add sandboxing to their solution."
"The tech support is not excellent; this is where Fortinet saves money compared to others... But plenty of free, clear and public documentation is available and this compensates for the most part the tech support shortcomings."
"The UI could be improved."
"Something that I've noticed that Forcepoint lacks, is the training that they offer to their end-customers"
"Configuration is not easy because it has an old-fashioned interface. The configuration interface is highly complex, and it's been the same for years. They have to change the interface."
"They should have a local vendor who can provide support. Most of the support is overseas, so the time zones can be a problem."
"Sometimes Forcepoint Next Generation Firewall is not really stable at all. It has many freezes for no reason, and local support needs to reboot it physically by unplugging the power cable and plugging it back in."
"If I want to allow access to Facebook, yet not allow the user to access videos, then I am not able to do it with this product."
"They should have a GUI on the product itself, not a separate management tool to be used on the management server or on a server to be used to manage the file. It should be all in one device. The device should be controlled through its own GUI. They also have to improve the learning center and the documents as the documents don't really help."
"The company should update the URL filtering database. They need to enhance the URL filtering and make it easier to customize."
"A VPN client feature is missing in our region, which we hope Forcepoint will address in future updates."
"It does not offer any recommendations on how to mitigate or control attacks."
"The cost of licensing is very high compared to other firewalls available here."
"Sangfor NGAF could improve the policies and default criteria. They could be much better."
"The firewall system needs gradual improvements because there are more threats and challenges every day."
"Sangfor need greater exposer in the market because the market is mainly saturated by Fortinet. The user experience of Fortinet is quite different compared to NGAF. If we want to switch our users from Fortinet to NGAF, we have to convince them that the user experience will be much easier once once they start to use it."
"Sangfor could improve their interface capacity on the 5100 series model and upgrade their hardware from one gig to 10 gig. This would improve the overall throughput."
"The solution has too many bugs and these slow down the implementation."
"There is room for improvement in dependency on certain infrastructure, like the DNS dependency on the current DNS server that the company has. It should be standalone. It should not depend on any other DNS server."
 

Pricing and Cost Advice

"Our licensing costs are on a yearly basis."
"The product is expensive."
"They are very competitive, but we like to have the factory warranty taken care of."
"There is an annual license to use this solution. The prices have been increasing over the years."
"It is not the cheapest one, but its price is very competitive."
"Cost-wise, there is not much difference from Sophos, but feature-wise, we get more features."
"The price of Fortinet FortiGate is reasonable for an SME."
"Its licenses cost the same for different subscription plans."
"It is an affordable product. We purchase its yearly license."
"The big advantage of this solution is that we can select the right model for our requirements, which is not too expensive."
"I consider Forcepoint Next Generation Firewall's price to be good."
"It could be cheaper like Fortinet."
"The training that they offer to their end-customers. It's quite expensive, I believe it costs roughly $11,000"
"The solution is expensive."
"The pricing should be more competitive against other vendors in the market."
"We would love to take other solution from Forcepoint, but unfortunately the price is too high. That's why we are not considering using Forcepoing for our proxy and DLB. They have a very good DLB, but the matter in the end is the cost."
"For over 2000 users, the cost is around 5000 to 6000 USD. If you want a web application firewall, you have to purchase an additional license for it."
"The solution has a TCO that is 32% to 50% less than Sophos, Fortinet, and SonicWall."
"When it comes to the price of firewall solutions, Sangfor NGAF takes the cake."
"Sangfor NGAF price is reasonable and there is an annual license. However, the maintenance cost can be a bit high."
"For four to five physical appliances for a licensed firewall, it costs approximately $4,000."
"I rate the product price as one on a scale of one to ten, where one is low price and ten is high price."
"We purchased one year technical support and return to factory support, and we also purchased one-year technical support services. So those were additional."
"The product is very cost-effective compared to other brands or vendors."
report
Use our free recommendation engine to learn which Firewalls solutions are best for your needs.
884,873 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
11%
Comms Service Provider
10%
Manufacturing Company
8%
Financial Services Firm
6%
Manufacturing Company
10%
Computer Software Company
10%
Financial Services Firm
8%
Government
7%
Manufacturing Company
12%
Comms Service Provider
9%
Financial Services Firm
8%
Computer Software Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business360
Midsize Enterprise135
Large Enterprise190
By reviewers
Company SizeCount
Small Business29
Midsize Enterprise10
Large Enterprise12
By reviewers
Company SizeCount
Small Business15
Midsize Enterprise10
Large Enterprise10
 

Questions from the Community

Which is the better NGFW: Fortinet Fortigate or Cisco Firepower?
When you compare these firewalls you can identify them with different features, advantages, practices and usage a...
What is the biggest difference between Sophos XG and FortiGate?
From my experience regarding both the Sophos and FortiGate firewalls, I personally would rather use FortiGate. I know...
What are the biggest technical differences between Sophos UTM and Fortinet FortiGate?
As a solution, Sophos UTM offers a lot of functionality, it scales well, and the stability and performance are quite ...
What is your experience regarding pricing and costs for Forcepoint Next Generation Firewall?
My experience with pricing, setup cost, and licensing is limited because I do not work with pricing, but I have exper...
What needs improvement with Forcepoint Next Generation Firewall?
I found one problem with Forcepoint Next Generation Firewall. They still do not have any VPN clients for Windows comp...
What do you like most about Sangfor NGAF?
I think Sangfor NGAF is more valuable than Cisco products because of its simplicity and ease of management. If I comp...
What is your experience regarding pricing and costs for Sangfor NGAF?
The licensing cost is quite high compared to other available firewalls in the market.
What needs improvement with Sangfor NGAF?
The cost of licensing is very high compared to other firewalls available here. There should be improvements in hardwa...
 

Also Known As

Fortinet FortiGate Next-Generation Firewall
Forcepoint NGFW, Stonesoft Next Generation Firewall, McAfee Network Security Platform, Intel Security Network Security Platform
Sangfor NGAF Firewall Platform
 

Overview

 

Sample Customers

Amazon Web Services, Microsoft, IBM, Cisco, Dell, HP, Oracle, Verizon, AT&T, T-Mobile, Sprint, Vodafone, Orange, BT Group, Telstra, Deutsche Telekom, Comcast, Time Warner Cable, CenturyLink, NTT Communications, Tata Communications, SoftBank, China Mobile, Singtel, Telus, Rogers Communications, Bell Canada, Telkom Indonesia, Telkom South Africa, Telmex, Telia Company, Telkom Kenya
California Department of Corrections and Rehabilitation (CDCR)
The Ministry of Science, Technology, and Innovation (Indonesia), Lawson, Inc. (Philippines), Universiti Sultan Zainal Abidin (Indonesia), TEK Automotive (Italy), etc.
Find out what your peers are saying about Forcepoint Next Generation Firewall vs. Sangfor NGAF and other solutions. Updated: March 2026.
884,873 professionals have used our research since 2012.