No more typing reviews! Try our Samantha, our new voice AI agent.

Forcepoint Next Generation Firewall vs Stormshield Network Security comparison

Sponsored
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Fortinet FortiGate
Sponsored
Average Rating
8.4
Reviews Sentiment
6.9
Number of Reviews
589
Ranking in other categories
Secure Web Gateways (SWG) (2nd), Firewalls (1st), Intrusion Detection and Prevention Software (IDPS) (1st), Software Defined WAN (SD-WAN) Solutions (1st), WAN Edge (1st), ZTNA (1st), Unified Threat Management (UTM) (1st)
Forcepoint Next Generation ...
Average Rating
7.6
Reviews Sentiment
6.4
Number of Reviews
51
Ranking in other categories
Firewalls (19th), Software Defined WAN (SD-WAN) Solutions (8th), WAN Edge (8th)
Stormshield Network Security
Average Rating
7.8
Reviews Sentiment
5.4
Number of Reviews
18
Ranking in other categories
Unified Threat Management (UTM) (12th)
 

Featured Reviews

Vasu Gala - PeerSpot reviewer
Manager, Information Technology Operation/Presales at TechMonarch
A stable solution with an intuitive interface and quick customer service
I have been working with Fortinet FortiGate, WatchGuard, Sophos, and SonicWall. I'm not as comfortable with SonicWall because of their UI and limitations. I prefer Fortinet above all other options. When it comes to configuration, I am confident in my ability to handle various tasks, including creating policies such as firewall rules, web policies, and application policies. Additionally, I can configure VPNs and implement load balancing, among other tasks. Overall, I feel much more comfortable working with Fortinet. Fortinet has made significant improvements by integrating AI with firewalls for threat analysis and prevention. In the past 2-3 years, they have launched FortiSASE and SIEM, and they also provide SOC services. Both Palo Alto and Fortinet FortiGate are excellent. While Fortinet FortiGate comes at higher prices, the functionality and support justify the cost. They promptly resolve firmware issues and inform all support providers about configuration changes.
reviewer2774055 - PeerSpot reviewer
Cybersecurity Engineer at a tech consulting company with 51-200 employees
Improved network segmentation has reduced lateral movement while the interface still needs modernization
For threat prevention, I noticed on another customer that there were repeated scanning and exploit attempts against some public-facing service running on HTTPS. I configured Forcepoint Next Generation Firewall to handle IPS by enabling it with critical and high severity signatures only to reduce false positives. I turned on IP reputation filtering to filter out known malicious networks, applied rate limiting on specific services in the DMZ, and logged events centrally for correlation. As a result, exploit attempts were much less than before, being blocked before reaching the back-end servers from the firewall itself, with no performance degradation on the applications. The security team received clear and actionable logs that were centralized, so they knew what was happening all the time. Strong network segmentation is my favorite feature that Forcepoint Next Generation Firewall offers. The policies are very deterministic and readable, and it has excellent east-west blocking and least privilege architecture. Application awareness identifies traffic beyond just the port itself; I can identify the application using a specific port and block risky applications even if they use allowed ports, which is great for environments with shadow IT. The integrated threat prevention is also very good, with IPS featuring well-tuned signatures and reputation-based filtering that blocks known bad actors before they can touch any applications. It supports both IPsec and SSL VPN tunnels, along with site-to-site, client-to-site, and hybrid cloud links, integrating well with Active Directory and LDAP. Additionally, centralized log management and reporting are very actionable and structured, with clarity in the policies for auditing. Overall, its stability and reliability are commendable. A real example of how Forcepoint Next Generation Firewall's readable policies and application awareness features made my work easier was fixing a flat network problem without breaking actual applications. I inherited an environment where users, application servers, and databases were loosely segmented, with port-based and messy firewall rules. Security audits flagged lateral movement risks, and application owners were scared of outages if I tightened security too much. Forcepoint Next Generation Firewall made it easy by providing very easy-to-read and logical policies. I built policies that are clear, showing communications from the user zone to the application zone to specific applications, or from the app zone to the database zone, using only required database protocols. By default, I applied a deny rule between zones unless explicitly allowed by the readable rules I implemented. The policy view clarified who talks to whom, which rules exist, why they exist, and the business function they support, effectively stopping port abuse. Security posture has definitely improved greatly since using Forcepoint Next Generation Firewall. From a flat or semi-flat network, I now have clear zone-based segmentation, with increased operational efficiency. The admins using the firewall have rules that are easy to read and intent-based, making changes easier to review and approve. There is less fear that one wrong rule could break production and fewer outages caused by security changes, without hidden matches or rule shadowing surprises. Clear hit count visibility helps me clean unused rules, leading to much fewer outages caused by changes on the firewalls. The centralized log management with supported log types provides better visibility for the SOC team and the SIEM team, as Forcepoint Next Generation Firewall sends very easy-to-parse and search clear logs to the SOC team. I did see measurable, defensible results after using Forcepoint Next Generation Firewall, including fewer security incidents reaching the back-end servers. This reduction is due to strong segmentation, application awareness, and IPS features, leading to a 60 to 70 percent reduction in security alerts that actually reach the servers. DMZ exploit attempts dropped to near zero, and no lateral movement incidents were detected post network segmentation. Additionally, overall SOC efficiency improved due to well-structured and contextual logs reflecting clear policy intent, resulting in a 35 to 40 percent reduction in mean time to triage. SOC analysts stopped chasing noise and false positives, as they had much clearer logs to use confidently.
Zsolt Jónás - PeerSpot reviewer
System Administrator at NaxoNet
Advanced GUI and layered security have supported compliance and simplified intrusion prevention
I haven't had a task that I couldn't solve with Stormshield Network Security. The active-active high availability solution would be beneficial because currently, if you build a high availability solution with Stormshield Network Security, you have a main device and another one is a backup device. The HA can switch between them, but it would be good to have a master-master solution, not just a master-slave one. I could set a URL that I can call to update the DNS record. Currently, Stormshield Network Security devices support DynDNS, which is not a usual feature request from a server environment. I have my own solution instead of DynDNS because I don't prefer it, so I have my own service for that. However, the GUI does not support using a custom service instead of DynDNS. I had to solve it in the console on Stormshield Network Security device, but it would be much better if it was reachable on the GUI. I had to figure out a trick for the IPsec configuration. In the IPsec config, we have to provide the remote side's IP address, but it's always changing. This means that an office, for example a company that has an office but without a fixed IP address, cannot be used with IPsec VPN.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The response is very quick and they can visually resolve our problems in a short period."
"The product has an inbuilt IPS software. We can configure it to block specific anonymous attacks that are happening."
"It has improved our organization with control data."
"The most useful features of Fortinet FortiGate IPS are you can create a virtual firewall within it, most other firewalls do not have this feature. You are able to manage your network and have network segmentation within your firewall. Additionally, you can create virtual switches within the firewall and have policy management, such as firewall and access policy."
"The most valuable features are the policies, filtering, and configuration."
"Fortinet FortiGate is pretty robust. The updates and firmware releases are pretty timely. They have a good product revision and review system, so they are constantly reviewing their configuration and the different mechanisms that are used on Fortinet FortiGate."
"I think it's very easy to implement this solution because one person can do it."
"We can use our devices to check all of the perimeters. It secures email websites."
"The people we deal with is a local partner in Cambodia and we can get good support from them."
"When our customer needs some optimization, along with performance and security, if they want everything in one package, I recommend Forcepoint because they have everything."
"When our customer needs some optimization, along with performance and security. If they want everything in one package, I recommend Forcepoint because they have everything."
"It provides decent protection for the LAN, especially in run mode."
"Technical support has been quite helpful in the past."
"Overall, it is an excellent product, highly reliable, and among the top contenders; Forcepoint Next Generation Firewall is well known."
"I found the initial setup process to be very simple and straightforward."
"We're trying to use all the firewall's features. Most of the features were effective, but the usability is a huge concern."
"The tool's most valuable feature is its dashboard, which helps you manage different aspects of a single page."
"The solution has improved my organization because I can see what traffic is happening and I can use it to block and prevent attacks."
"Fortinet, Dell SonicWall and Check Point because these products offer a wide range of features that are not available with Netasq."
"The StormShield solution has enabled us to fully implement best practices from Microsoft in the cloud : the hub and spoke architecture."
"Stormshield is a very strong firewall and very easy to configure and maintain."
"Stormshield is pretty robust, compared to other products like Fortinet, as you get more security with Stormshield and spend less money."
"The performance of this solution is good."
"The scalability of the solution is good."
 

Cons

"Sometimes you do need to know some CLI commands, so it's a bit harder for technicians or new people that don't know it."
"It would be a benefit if Fortinet would release a one-stop solution that is better integrated with other products and an automated emergency response system."
"Reporting is limited to providing an external appliance for improving the reporting capabilities of the FortiAnalyzer. It does not offer a central management and is also sold separably as an appliance."
"I often ask for help from the local provider. I haven't found the required efficient help."
"There are SD-WAN network monitoring, SD-WAN features, Industrial Databases, Internet of Things, Detection, etc., however, we do have not licenses for those features. We thought that if you bought a product, you should have all of the features it offers. Why should you need to make so many extra purchases to enable features? They should have one price for the entire offering."
"There are some issues with the scalability of Fortinet FortiGate. Certain products and models need to be scalable, but they're not."
"The scalability of the device is limited."
"Lacks training for new features."
"The solution isn't scalable."
"We feel the product's technical support could be better, as this relates to the solution itself, to the installation of the product, and to having a proper understanding of the case."
"Forcepoint would be improved if there were more training available."
"The support from Forcepoint Next Generation Firewall is not good, their response is not quick, we have had to wait a while."
"We spent a lot of time and received help from different people, and it was still a failure in the end. We disposed of the product."
"It's a complicated firewall. Until you come to know the firewall inducers, most people don't like the firewall because the components for the firewall are a little bit complex. User-friendliness is a little bit tough. It needs to be user-friendly when creating policies, and pushing policies. Committing takes more time compared to Palo Alto."
"My experience with this Forcepoint Next Generation Firewall wasn't very pleasant due to its complexity. For example, the firewall loses some features when working in a cluster, which is a huge challenge. It caused me several weeks to solve an issue to make the VPN work, even after opening several cases with support. Also, the debug, which should provide essential knowledge about everything going on, the flow of traffic, and how the engine works, wasn't very informative in identifying the issue."
"The solution needs to build upon its network functionality. It needs to be a bit smarter."
"With Stormshield, there are difficulties joining things, and it can be complex depending on the architecture."
"The biggest issue was their support department was not able to help us, then everything stops. This is a no-go area for me."
"Stormshield Network Security is quite expensive."
"The SD card could be more secure."
"The product must improve its pricing."
"A more user-friendly interface would be helpful."
"This is not a next-generation firewall."
"Not all the fields are activated yet and we were informed that it will take at least one month."
 

Pricing and Cost Advice

"It was worth the money overall. It's good value."
"FortiGate SWG is a cost-effective solution well-suited for organisations of all sizes."
"Its pricing is competitive with other solutions."
"It has a competitive price."
"It is around $50,000 per month."
"The pricing is comprehensive and clear. You can easily understand what you are purchasing, including which features correspond to each license and maintenance contract. Overall, the information is straightforward. Additionally, compared to other vendors, their prices are competitive."
"I would rate pricing to be about four or five out of ten, it is reasonable."
"The Indian market is different than the European and American markets. When you compare they need to be a bit more aggressive on pricing."
"I believe the licensing fee is for one year, three years, and five years, or something like that. If you wants to increase the support level from a simpler level to platinum, I think that there's a cost. There are differences between every kind of support, but I don't know the numbers."
"The training that they offer to their end-customers. It's quite expensive, I believe it costs roughly $11,000"
"It is an affordable product. We purchase its yearly license."
"Forcepoint Next Generation Firewall is reasonable, it is priced the same as other firewalls."
"There is a need to make payments towards the licensing charges attached to the product. The product is not expensive."
"We have just a subscription for the cloud, and this license is great. The license is so good."
"The big advantage of this solution is that we can select the right model for our requirements, which is not too expensive."
"The solution is expensive."
"I think the price is good."
"We bought a three-year license, and we renew it whenever it expires. The price could be better. It's always very expensive."
"The SN200 series costs between $500 USD and $600 USD per year, whereas the SN700 series costs approximately $1,000 annually."
"The pricing could be better."
"We chose Stormshield for its price, as the Azure firewall was too expensive."
"For mid-sized companies, they sell their appliances for good prices."
"The price of this solution and the price of support are ok."
report
Use our free recommendation engine to learn which Firewalls solutions are best for your needs.
885,311 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
11%
Comms Service Provider
9%
Manufacturing Company
8%
Financial Services Firm
6%
Manufacturing Company
9%
Computer Software Company
9%
Construction Company
8%
Financial Services Firm
7%
Comms Service Provider
16%
Computer Software Company
14%
Manufacturing Company
11%
Government
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business363
Midsize Enterprise135
Large Enterprise190
By reviewers
Company SizeCount
Small Business29
Midsize Enterprise10
Large Enterprise12
By reviewers
Company SizeCount
Small Business10
Midsize Enterprise5
Large Enterprise2
 

Questions from the Community

Which is the better NGFW: Fortinet Fortigate or Cisco Firepower?
When you compare these firewalls you can identify them with different features, advantages, practices and usage a...
What is the biggest difference between Sophos XG and FortiGate?
From my experience regarding both the Sophos and FortiGate firewalls, I personally would rather use FortiGate. I know...
What are the biggest technical differences between Sophos UTM and Fortinet FortiGate?
As a solution, Sophos UTM offers a lot of functionality, it scales well, and the stability and performance are quite ...
What is your experience regarding pricing and costs for Forcepoint Next Generation Firewall?
My experience with pricing, setup cost, and licensing is limited because I do not work with pricing, but I have exper...
What needs improvement with Forcepoint Next Generation Firewall?
I found one problem with Forcepoint Next Generation Firewall. They still do not have any VPN clients for Windows comp...
What advice do you have for others considering Stormshield Network Security?
The tool is like a firewall and works well. I don't have any issue with it. I rate it an eight out of ten.
 

Also Known As

Fortinet FortiGate Next-Generation Firewall
Forcepoint NGFW, Stonesoft Next Generation Firewall, McAfee Network Security Platform, Intel Security Network Security Platform
NETASQ Firewalls
 

Overview

 

Sample Customers

Amazon Web Services, Microsoft, IBM, Cisco, Dell, HP, Oracle, Verizon, AT&T, T-Mobile, Sprint, Vodafone, Orange, BT Group, Telstra, Deutsche Telekom, Comcast, Time Warner Cable, CenturyLink, NTT Communications, Tata Communications, SoftBank, China Mobile, Singtel, Telus, Rogers Communications, Bell Canada, Telkom Indonesia, Telkom South Africa, Telmex, Telia Company, Telkom Kenya
California Department of Corrections and Rehabilitation (CDCR)
ACESUR group, Ministry of Education Oman, Anios Laboratories, Zain, DLM Location
Find out what your peers are saying about Forcepoint Next Generation Firewall vs. Stormshield Network Security and other solutions. Updated: March 2026.
885,311 professionals have used our research since 2012.