No more typing reviews! Try our Samantha, our new voice AI agent.

Forcepoint Next Generation Firewall vs Sophos UTM vs Trellix Intrusion Prevention System comparison

Why PeerSpot?
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Featured Reviews

Ajit Pratap Kundan - PeerSpot reviewer
Manager Solution Consulting at Accops Systems Pvt Ltd
Unified security management has improved traffic control and simplified remote workforce access
Forcepoint Next Generation Firewall does help in vulnerability identification and response by providing a single unified console through which I am able to monitor and manage infrastructure. The URL filtering capability of Forcepoint Next Generation Firewall helps in blocking malicious sites. We have to take care of both known threats and unknown threats. The firewall takes care of known threats, and we protect ourselves from unknown threats such as malicious code and malware that we cannot create firewall rules for. With these routing capabilities and policies, only whitelisted things get processed or passed. The biggest advantages of Forcepoint Next Generation Firewall, especially as a partner, service provider, and integrator, are that it is very easy to integrate these APIs with our solution, and most of the features I am getting in the clientless mode. Even with the client mode, it is easy to integrate with our client, allowing the customer to get a single client to address all the features of the firewall as well as the GTNA perspective. The flexibility of deployment, especially for the government and defense sectors, is that they want an on-premises solution, while the rest of the PSUs or enterprise segment are comfortable with the cloud offering, which is the SaaS offering and the way to go in the future.
HR
CEO at iSource GmbH
Integrated security tools have supported critical infrastructure and improved network performance
Regarding Secureworks Taegis VDR Vulnerability Management, I do not have all these shortcuts in my head. Perhaps I have to ask my technicians, but we are in full stress because we have to change this entire firewall equipment, also the entire access points, because of the end of life. We also have the full product in for XDR and extensions. We are also part of the webinars from Sophos. It would be better if there were also some important webinars in German. Everything needs improvement, because also the wireless, also RED box and so on. The handling was much easier on the old equipment than on the new XGS. I think there should also be a little more automatic for SD-WAN routing and so on. Because we have to learn some things from the basic completely new because it is different than Sophos UTM, the XGS. The features that could be improved about Sophos UTM include the new features we have in XGS with a simpler interface. For example, in Sophos UTM, we could define IP hosts and use this IP host. We did not have to insert on every, for example, for wide area networks, we had to put the IP addresses from the other side by hand. In Sophos UTM, we could define it under definitions and then use this IP host where we needed it. In the new XGS, if there is a change in the IP address, we have to do it on all, for example, site-to-site VPN tunnels and so on. We have much more work and it is not so easy because we have to check all the definitions. It is also, for example, some of the male technicians like me, we have a biology handicap. For example, male technicians in Europe also have a red-green problem. So we use these light colors on the interface. In some cases, it is not easy to see the, for example, letters or numbers because of the contrast.
BS
Large account Manager at Softcell Technologies Limited
Has offered reliable threat protection and detailed network insights but could expand features beyond existing capabilities
The best features of Trellix Intrusion Prevention System include advanced ATP (Advanced Threat Protection), which uses signatures, behavior analysis, and machine learning to stop zero-day exploits and malware advanced persistent threats (APTs). They track and collect data from APTs, which allows them to track malicious files entering the environment. The system offers inline prevention and real-time automatic blocking of malicious packets before they reach the network. It integrates with the Trellix ecosystem and provides application visibility and control. The solution provides deep insight into network traffic, applications, and protocols for better information. All packets coming through the application are analyzed and reported. They share intelligence updates regularly to protect from different malicious files and sector-specific threats. It supports both on-premise and cloud environments.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The feature that we like the most about Forcepoint is that we know the technology and have confidence in it. We can have several functionalities to simplify operations and management. We can combine functionalities like log ownership to review the number of devices in the infrastructure."
"The solution offers sandboxing, which can be integrated at any time."
"Forcepoint's stability is satisfactory, for the most part."
"When it comes to the detection rate of the IP, it is the most powerful solution for detection-ready tests, like evasion techniques etc."
"Next Generation Firewall's best feature is that it can be managed on one platform."
"The most valuable feature is controlling the traffic and the logging. They have real-time logins for traffic logs. Troubleshooting was very easy for me."
"Forcepoint Next Generation Firewall has impacted my organization positively by making it very easy to work and offering a more competitive price compared to other vendors."
"They offer templates that provide detailed reports categorized by user, device, and internal network access."
"This is a very stable product."
"The most valuable feature of Sophos UTM is the endpoint protection feature."
"It is not an easy task to protect your web servers from the big bad internet. The Web Server Protection in this solution does it elegantly and, if configured correctly, even hides the server's base system from prying eyes."
"In terms of quality and functionality, Sophos is very useful and better than the competition."
"It has allowed us to design a bespoke cloud space for our clients, while still having an excellent level of protection."
"The most valuable features of Sophos UTM are the ease of use, it is very user-friendly. You can understand what they implement in the new firmware, and it's easy to manage the firewalls."
"The initial setup is easy."
"The IT Admin or IT Security in any organization would like to have Sophos UTM because it is full of all the features you think about for enterprise."
"The best features of Trellix Intrusion Prevention System include advanced ATP (Advanced Threat Protection), which uses signatures, behavior analysis, and machine learning to stop zero-day exploits and malware advanced persistent threats (APTs)."
"Overall the solution is very good. It offers great protection and gives us a good overview of what is on the network."
"The initial setup is straightforward."
"The most valuable features in Trellix for me are the automated signature updates. It is a great and convenient feature."
"Great monitoring feature."
"The solution can scale."
"The product is worth the investment."
"There's a good dashboard you can drill down into. It helps you easily locate intrusions and the source of attacks."
 

Cons

"Management could be better. They can improve the management."
"Making this solution easier to use would be an improvement. The implementation could be made easier."
"They should provide more details on potential cyber threats."
"We would love to take another solution from Forcepoint, but unfortunately, the price is too high."
"Forcepoint Next Generation Firewall should make some improvements because there is some instability with their software. Sometimes it could lag or become over-utilized, you need to clear some caches and do some restarts, and sometimes some traffic is being blocked and the reason is not entirely clear."
"Forcepoint is a little difficult to configure compared to its competitors."
"The interface is complicated. It's difficult to locate all the necessary menus and functions."
"Forcepoint Next Generation Firewall is overall good, but AI enabled features are not available."
"The only time we face a problem or issues is when we place a ticket. We have found that response is very slow."
"I don't believe it has improved our organization; I don't actually like the product because of the features it is missing."
"It really needs to update IPSec to enable IKEv2."
"I would like some features that are available in other brands. For example, I sometimes a person is using too much bandwidth, and it isn't easy to find this information in Sophos. Also, we have to switch connections manually when we are using a VPN and lose the MPLS connection. It isn't automatic."
"In short, the UI and UX are the areas of improvement in Sophos UTM and similar solutions compared to Palo Alto."
"The support could be better."
"Everything needs improvement, because also the wireless, also RED box and so on. The handling was much easier on the old equipment than on the new XGS."
"Anti-phishing functionality should be improved."
"We would like to have a simpler version. Some settings and functions on the McAfee console are complex and complicated. I want the management console to be simpler."
"In terms of high-security attacks, not all of them are developed. You cannot do a rule that includes all high severities."
"The technical support has room for improvement."
"The pricing could be improved."
"The solution needs to improve the graphical interface. And they had a limitation in some of the sensor modems as well."
"Some of the documentation is not as straightforward as it could be. It's much too general - especially in areas related to updates."
"The platform’s GUI could be the latest."
"There are limited resources for configuration guidance."
 

Pricing and Cost Advice

"It requires a yearly subscription."
"Next Generation Firewall is moderately priced."
"There is a license required to use this solution and we can purchase it for one, two, three, or five years."
"Forcepoint is very expensive but it's really secure."
"We have just a subscription for the cloud, and this license is great. The license is so good."
"It is an affordable product. We purchase its yearly license."
"The cost is fair, but it could be improved."
"It could be cheaper like Fortinet."
"The solution is very low cost compared to competitors. You have a good firewall, a lot of functions for less than the price of some omni firewall competitors."
"There was an up-front charge of around $70,000, to purchase the hub and license. Beyond the initial cost, licenses are charged for annually, but they are good value for the service we receive."
"For under 50 users, MSP licensing is profitable."
"It will cost approximately $67 US per device. We have 300 devices in our organization."
"Both the technical and cost aspects are feasible since it is possible to obtain and use the device as a PnP solution."
"Sophos UTM has very reasonable pricing."
"There is a license for the device and for the software. We pay annually for the solution and the cost is competitive."
"Go to a vendor and let them assess your needs so you can get a right-sized device."
"I rate the product’s pricing an eight out of ten."
"The tool is competitively priced."
report
Use our free recommendation engine to learn which Firewalls solutions are best for your needs.
912,069 professionals have used our research since 2012.
 

Comparison Review

it_user216600 - PeerSpot reviewer
Senior Technical Consultant with 51-200 employees
Jan 3, 2016
Sophos UTM vs. Fortinet FortiGate
I have used both Sophos and Fortinet products in production and I have found the Sophos UTM appliances (hardware and virtual) to be a better fit most of the time -- with a few caveats which I will touch on below. In both instances, the transition from TMG will be mostly straightforward. The main…
 

Top Industries

By visitors reading reviews
Construction Company
13%
Financial Services Firm
10%
Manufacturing Company
9%
Outsourcing Company
8%
Outsourcing Company
13%
Construction Company
12%
Comms Service Provider
10%
Manufacturing Company
8%
Comms Service Provider
13%
Manufacturing Company
11%
Construction Company
8%
Outsourcing Company
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business29
Midsize Enterprise11
Large Enterprise14
By reviewers
Company SizeCount
Small Business75
Midsize Enterprise28
Large Enterprise27
By reviewers
Company SizeCount
Small Business6
Midsize Enterprise6
Large Enterprise6
 

Questions from the Community

What is your experience regarding pricing and costs for Forcepoint Next Generation Firewall?
In terms of price, I would say Forcepoint Next Generation Firewall is not expensive. It is very much comparable to ot...
What needs improvement with Forcepoint Next Generation Firewall?
The negative side of Forcepoint Next Generation Firewall is that the ZTNA part is missing. For that, we have to integ...
What is your primary use case for Forcepoint Next Generation Firewall?
The major use cases for Forcepoint Next Generation Firewall are in government turnkey projects where we require a lot...
What are the biggest technical differences between Sophos UTM and Fortinet FortiGate?
As a solution, Sophos UTM offers a lot of functionality, it scales well, and the stability and performance are quite ...
What is your experience regarding pricing and costs for Sophos UTM?
The pricing for Sophos UTM is reasonable; I do not have an issue with it, though I was considering RED because I have...
What needs improvement with Sophos UTM?
Regarding Secureworks Taegis VDR Vulnerability Management, I do not have all these shortcuts in my head. Perhaps I ha...
What needs improvement with McAfee Network Security Platform?
Trellix Intrusion Prevention System does not provide virtual patching. Patching involves updates on the OS side to ad...
What is your primary use case for McAfee Network Security Platform?
We do not use Trellix Intrusion Prevention System; rather, we sell the Trellix Intrusion Prevention System solution. ...
What advice do you have for others considering McAfee Network Security Platform?
I have experience working with other tools, specifically Trellix solutions such as DLP, EDR, and MDR, as well as with...
 

Also Known As

Forcepoint NGFW, Stonesoft Next Generation Firewall, McAfee Network Security Platform, Intel Security Network Security Platform
Astaro
McAfee Network Security Platform, McAfee NSP, IntruShield Network Intrusion Prevention System, IntruShield Network IPS
 

Overview

 

Sample Customers

California Department of Corrections and Rehabilitation (CDCR)
One Housing Group
Desjardins Group, HollyFrontier, Nubia, Agbar, WNS Global Services, INAIL, Universidad de Las Américas Puebla (UDLAP), Cook County, China Pacific Insurance, Bank Central Asia, California Department of Corrections and Rehabilitation, City of Chicago, Macquarie Telecom, Sutherland Global Services, Texas Tech University Health Sciences Center, United Automotive Electronic Systems
Find out what your peers are saying about Fortinet, Netgate, Cisco and others in Firewalls. Updated: August 2026.
912,069 professionals have used our research since 2012.