Try our new research platform with insights from 80,000+ expert users

Forcepoint Next Generation Firewall vs Stormshield Network Security comparison

Sponsored
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Fortinet FortiGate
Sponsored
Average Rating
8.4
Reviews Sentiment
6.9
Number of Reviews
580
Ranking in other categories
Secure Web Gateways (SWG) (2nd), Firewalls (1st), Intrusion Detection and Prevention Software (IDPS) (1st), Software Defined WAN (SD-WAN) Solutions (1st), WAN Edge (1st), ZTNA (1st), Unified Threat Management (UTM) (1st)
Forcepoint Next Generation ...
Average Rating
7.6
Reviews Sentiment
6.6
Number of Reviews
49
Ranking in other categories
Firewalls (21st), Software Defined WAN (SD-WAN) Solutions (9th), WAN Edge (8th)
Stormshield Network Security
Average Rating
7.8
Reviews Sentiment
6.0
Number of Reviews
17
Ranking in other categories
Unified Threat Management (UTM) (11th)
 

Featured Reviews

Vasu Gala - PeerSpot reviewer
Manager, Information Technology Operation/Presales at TechMonarch
A stable solution with an intuitive interface and quick customer service
I have been working with Fortinet FortiGate, WatchGuard, Sophos, and SonicWall. I'm not as comfortable with SonicWall because of their UI and limitations. I prefer Fortinet above all other options. When it comes to configuration, I am confident in my ability to handle various tasks, including creating policies such as firewall rules, web policies, and application policies. Additionally, I can configure VPNs and implement load balancing, among other tasks. Overall, I feel much more comfortable working with Fortinet. Fortinet has made significant improvements by integrating AI with firewalls for threat analysis and prevention. In the past 2-3 years, they have launched FortiSASE and SIEM, and they also provide SOC services. Both Palo Alto and Fortinet FortiGate are excellent. While Fortinet FortiGate comes at higher prices, the functionality and support justify the cost. They promptly resolve firmware issues and inform all support providers about configuration changes.
reviewer2774055 - PeerSpot reviewer
Cybersecurity Engineer at a tech consulting company with 51-200 employees
Improved network segmentation has reduced lateral movement while the interface still needs modernization
For threat prevention, I noticed on another customer that there were repeated scanning and exploit attempts against some public-facing service running on HTTPS. I configured Forcepoint Next Generation Firewall to handle IPS by enabling it with critical and high severity signatures only to reduce false positives. I turned on IP reputation filtering to filter out known malicious networks, applied rate limiting on specific services in the DMZ, and logged events centrally for correlation. As a result, exploit attempts were much less than before, being blocked before reaching the back-end servers from the firewall itself, with no performance degradation on the applications. The security team received clear and actionable logs that were centralized, so they knew what was happening all the time. Strong network segmentation is my favorite feature that Forcepoint Next Generation Firewall offers. The policies are very deterministic and readable, and it has excellent east-west blocking and least privilege architecture. Application awareness identifies traffic beyond just the port itself; I can identify the application using a specific port and block risky applications even if they use allowed ports, which is great for environments with shadow IT. The integrated threat prevention is also very good, with IPS featuring well-tuned signatures and reputation-based filtering that blocks known bad actors before they can touch any applications. It supports both IPsec and SSL VPN tunnels, along with site-to-site, client-to-site, and hybrid cloud links, integrating well with Active Directory and LDAP. Additionally, centralized log management and reporting are very actionable and structured, with clarity in the policies for auditing. Overall, its stability and reliability are commendable. A real example of how Forcepoint Next Generation Firewall's readable policies and application awareness features made my work easier was fixing a flat network problem without breaking actual applications. I inherited an environment where users, application servers, and databases were loosely segmented, with port-based and messy firewall rules. Security audits flagged lateral movement risks, and application owners were scared of outages if I tightened security too much. Forcepoint Next Generation Firewall made it easy by providing very easy-to-read and logical policies. I built policies that are clear, showing communications from the user zone to the application zone to specific applications, or from the app zone to the database zone, using only required database protocols. By default, I applied a deny rule between zones unless explicitly allowed by the readable rules I implemented. The policy view clarified who talks to whom, which rules exist, why they exist, and the business function they support, effectively stopping port abuse. Security posture has definitely improved greatly since using Forcepoint Next Generation Firewall. From a flat or semi-flat network, I now have clear zone-based segmentation, with increased operational efficiency. The admins using the firewall have rules that are easy to read and intent-based, making changes easier to review and approve. There is less fear that one wrong rule could break production and fewer outages caused by security changes, without hidden matches or rule shadowing surprises. Clear hit count visibility helps me clean unused rules, leading to much fewer outages caused by changes on the firewalls. The centralized log management with supported log types provides better visibility for the SOC team and the SIEM team, as Forcepoint Next Generation Firewall sends very easy-to-parse and search clear logs to the SOC team. I did see measurable, defensible results after using Forcepoint Next Generation Firewall, including fewer security incidents reaching the back-end servers. This reduction is due to strong segmentation, application awareness, and IPS features, leading to a 60 to 70 percent reduction in security alerts that actually reach the servers. DMZ exploit attempts dropped to near zero, and no lateral movement incidents were detected post network segmentation. Additionally, overall SOC efficiency improved due to well-structured and contextual logs reflecting clear policy intent, resulting in a 35 to 40 percent reduction in mean time to triage. SOC analysts stopped chasing noise and false positives, as they had much clearer logs to use confidently.
Benjamin - PeerSpot reviewer
Network Engineer at ACS2I
The intrusion detection system helps our organization by automatically detecting and responding to potential threats
The tool's most valuable feature is its dashboard, which helps you manage different aspects of a single page. The intrusion detection system helps our organization by automatically detecting and responding to potential threats. It operates similarly to Darktrace, which detects and responds automatically based on the security rules you apply. Initially, you configure everything to block, and then you can whitelist specific items as needed.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"What I appreciate the most about Fortinet FortiGate is that it has a very large integration using Fabric, which they call Fabric Connectors."
"The product is easy to install since we only need to follow the user manual, documents, and articles provided by Fortinet to install the product."
"The most valuable feature of FortiGate Next Generation Firewall is its SD-WAN."
"The solution is extremely reliable."
"FortiGate Next Generation Firewall (NGFW) 's most valuable features are reporting and filtering."
"Fortinet FortiGate is stable. It's used across all the countries, this is the way most multinationals run their system."
"It is a one box solution, which covers most of the edge device’s requirements."
"The wireless control is helpful."
"Technical support has been quite helpful in the past."
"Forcepoint Next Generation Firewall has impacted my organization positively by making it very easy to work and offering a more competitive price compared to other vendors."
"The VPN is great."
"It is a scalable solution."
"I have found that Forcepoint Next Generation Firewall is easy to use, highly secure, and the main VPN tunnel is created automatically which is a benefit."
"The central security management center and the content management center are very good."
"They offer templates that provide detailed reports categorized by user, device, and internal network access."
"The product's initial setup phase is easy."
"The tool's most valuable feature is its dashboard, which helps you manage different aspects of a single page. The intrusion detection system helps our organization by automatically detecting and responding to potential threats. It operates similarly to Darktrace, which detects and responds automatically based on the security rules you apply. Initially, you configure everything to block, and then you can whitelist specific items as needed."
"The solution has improved my organization because I can see what traffic is happening and I can use it to block and prevent attacks."
"Ease of use is the best feature of the product."
"I like that it works fine. Stormshield is a very good solution."
"It's an easy, straightforward management platform to use."
"Our organization's main concern is stability, and this is a stable solution."
"The most valuable features are the IPS, the firewall function, and the price."
"The scalability of the solution is good."
 

Cons

"They could simplify their deployment process, especially when customers have existing devices."
"The Web-filter in this solution is not very good."
"I don't really have anything negative to say as far as Fortinet firewalls are concerned. If anything, they can support a user a little bit better. They can stop being so time-sensitive about how much time the support call has taken, and they can help you do it yourself."
"Fortinet FortiGate is a very good device overall, though it can be improved in certain areas regarding the licenses, particularly the big one called unified threat management, which has many capabilities."
"I need user-behavior analytics, to find threat scenarios from inside the organization, insider attacks. That would be very helpful for us. In addition, I would like next-generation features for small and medium businesses. These businesses require UTM, all in one product. Fortinet must include it."
"The room for improvement is about the global delivery time period. Usually I need to wait for almost one month to deliver it overseas. So if you can shorten the deliver time it'd be great."
"Technical support for this solution can be improved."
"There is room for improvement in pricing."
"They should have a local vendor who can provide support. Most of the support is overseas, so the time zones can be a problem."
"My experience with this Forcepoint Next Generation Firewall wasn't very pleasant due to its complexity. For example, the firewall loses some features when working in a cluster, which is a huge challenge. It caused me several weeks to solve an issue to make the VPN work, even after opening several cases with support. Also, the debug, which should provide essential knowledge about everything going on, the flow of traffic, and how the engine works, wasn't very informative in identifying the issue."
"Its interface is complex when compared with a firewall like FortiGate. Forcepoint Next Generation Firewall needs a management console, whereas FortiGate doesn't need any console. When you have a few devices, a console is not really necessary. It's good to have a private console only when you have a lot of devices."
"Forcepoint Next Generation Firewall can be improved with better response from support."
"The security features need to be improved."
"I would like to see more sizing in the next release, and the roadmap should be clear."
"They need to increase the local support here. There are also some bugs or fixes on which they need to work. They very well know about these bugs. In terms of licensing, I would like them to either increase the number of features in a single license or make licensing more flexible."
"The endpoint protection capabilities of the product are an area of concern where improvements are required."
"This solution has a big problem with web filtering and it needs to be improved."
"This is not a next-generation firewall."
"With Stormshield, there are difficulties joining things, and it can be complex depending on the architecture."
"The filtering configuration could be better. We have some difficulties with the filtering configuration and the filter extension. It's not that easy. It's not that straightforward. In the next release, I would like to see a reporting system. Stormshield doesn't have any tutorials on how to do the configuration and things like that. They just have documentation on the website. If you want to configure, for example, Cisco or Fortinet, you can find tutorials on YouTube. They show you how to configure the features, and so on. In Stormshield, there is nothing on social media or the internet on how to configure different things. The lack of documentation or the lack of material makes it difficult for others to adopt this solution."
"The product must improve its pricing."
"A more user-friendly interface would be helpful."
"Improvement is needed in terms of the technical support of the manufacturer."
"It could be better if it were more user-friendly. It's too complicated for us to use it. The price could be better as well."
 

Pricing and Cost Advice

"The solution is more expensive than Sophos. It could be cheaper. The licensing is on a yearly basis. We have had it for about three years. We must only pay extra for the license, additional requirements, and the hardware box."
"I rate the product's pricing a seven out of ten. The additional cost depends on the extra feature requirements."
"It's an expensive solution"
"I give the pricing a nine out of ten."
"The licensing scheme of Fortinet is better than Cisco. It is more logical."
"Cost-wise, there is not much difference from Sophos, but feature-wise, we get more features."
"The price depends on the size of the company. From the beginning, you just want to know the internet bandwidths, speed, and the number of users to be able to offer the right product and model. They have a lot of products in FortiGate according to the size of the company, like 200D and 300D."
"I would say that all things considered, the pricing is pretty good."
"The solution is expensive."
"The pricing of the solution is normally competitive with other products."
"The big advantage of this solution is that we can select the right model for our requirements, which is not too expensive."
"We have found the price could be reduced. It is a little expensive."
"The cost is fair, but it could be improved."
"There is a need to make payments towards the licensing charges attached to the product. The product is not expensive."
"It is an affordable product. We purchase its yearly license."
"I believe the licensing fee is for one year, three years, and five years, or something like that. If you wants to increase the support level from a simpler level to platinum, I think that there's a cost. There are differences between every kind of support, but I don't know the numbers."
"We chose Stormshield for its price, as the Azure firewall was too expensive."
"I think the price is good."
"The price of this solution and the price of support are ok."
"The SN200 series costs between $500 USD and $600 USD per year, whereas the SN700 series costs approximately $1,000 annually."
"For mid-sized companies, they sell their appliances for good prices."
"The pricing could be better."
"We bought a three-year license, and we renew it whenever it expires. The price could be better. It's always very expensive."
report
Use our free recommendation engine to learn which Firewalls solutions are best for your needs.
881,114 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
12%
Comms Service Provider
9%
Manufacturing Company
8%
Financial Services Firm
6%
Manufacturing Company
11%
Computer Software Company
9%
Financial Services Firm
9%
Government
8%
Comms Service Provider
16%
Computer Software Company
15%
Manufacturing Company
9%
Government
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business357
Midsize Enterprise133
Large Enterprise188
By reviewers
Company SizeCount
Small Business28
Midsize Enterprise10
Large Enterprise11
By reviewers
Company SizeCount
Small Business9
Midsize Enterprise5
Large Enterprise2
 

Questions from the Community

Which is the better NGFW: Fortinet Fortigate or Cisco Firepower?
When you compare these firewalls you can identify them with different features, advantages, practices and usage a...
What is the biggest difference between Sophos XG and FortiGate?
From my experience regarding both the Sophos and FortiGate firewalls, I personally would rather use FortiGate. I know...
What are the biggest technical differences between Sophos UTM and Fortinet FortiGate?
As a solution, Sophos UTM offers a lot of functionality, it scales well, and the stability and performance are quite ...
What is your experience regarding pricing and costs for Forcepoint Next Generation Firewall?
My experience with pricing, setup cost, and licensing is limited because I do not work with pricing, but I have exper...
What needs improvement with Forcepoint Next Generation Firewall?
Forcepoint Next Generation Firewall is overall good, but AI enabled features are not available. Many templates and AI...
What advice do you have for others considering Stormshield Network Security?
The tool is like a firewall and works well. I don't have any issue with it. I rate it an eight out of ten.
 

Also Known As

Fortinet FortiGate Next-Generation Firewall
Forcepoint NGFW, Stonesoft Next Generation Firewall, McAfee Network Security Platform, Intel Security Network Security Platform
NETASQ Firewalls
 

Overview

 

Sample Customers

Amazon Web Services, Microsoft, IBM, Cisco, Dell, HP, Oracle, Verizon, AT&T, T-Mobile, Sprint, Vodafone, Orange, BT Group, Telstra, Deutsche Telekom, Comcast, Time Warner Cable, CenturyLink, NTT Communications, Tata Communications, SoftBank, China Mobile, Singtel, Telus, Rogers Communications, Bell Canada, Telkom Indonesia, Telkom South Africa, Telmex, Telia Company, Telkom Kenya
California Department of Corrections and Rehabilitation (CDCR)
ACESUR group, Ministry of Education Oman, Anios Laboratories, Zain, DLM Location
Find out what your peers are saying about Forcepoint Next Generation Firewall vs. Stormshield Network Security and other solutions. Updated: December 2025.
881,114 professionals have used our research since 2012.