No more typing reviews! Try our Samantha, our new voice AI agent.

Fortinet FortiGate-VM vs Sangfor NGAF comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Jan 25, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Fortinet FortiGate
Sponsored
Ranking in Firewalls
1st
Average Rating
8.4
Reviews Sentiment
6.9
Number of Reviews
592
Ranking in other categories
Secure Web Gateways (SWG) (2nd), Intrusion Detection and Prevention Software (IDPS) (1st), Software Defined WAN (SD-WAN) Solutions (1st), WAN Edge (1st), ZTNA (1st), Unified Threat Management (UTM) (1st)
Fortinet FortiGate-VM
Ranking in Firewalls
10th
Average Rating
8.4
Reviews Sentiment
6.8
Number of Reviews
143
Ranking in other categories
No ranking in other categories
Sangfor NGAF
Ranking in Firewalls
21st
Average Rating
8.0
Reviews Sentiment
6.5
Number of Reviews
34
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of June 2026, in the Firewalls category, the mindshare of Fortinet FortiGate is 15.1%, down from 21.7% compared to the previous year. The mindshare of Fortinet FortiGate-VM is 2.2%, up from 1.9% compared to the previous year. The mindshare of Sangfor NGAF is 1.1%, down from 1.3% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Firewalls Mindshare Distribution
ProductMindshare (%)
Fortinet FortiGate15.1%
Fortinet FortiGate-VM2.2%
Sangfor NGAF1.1%
Other81.6%
Firewalls
 

Featured Reviews

JK
IP Network Security Specialist at MTN Ghana
Process-Level CPU Visibility: Introduce detailed CPU-usage metrics per subsystem (e.g., IPS engine, logging) so administrators can quickly identify and address performance spikes.
Analytics with FortiAnalyzer. Being able to pull in logs not just from our FortiGates but from all our other firewalls and then get them in one view has been a game changer. Whether I’m building an executive dashboard or doing a deep dive forensics session, I get everything I need without navigating consoles.Straightforward Application Control. FortiGate spots and blocks unwanted apps (eq. like BitTorrent or streaming services) with accuracy. Segmentation with VDOMs. We’ve carved our data center into four logical ‘mini-firewalls’ enterprise, core, billing, and WAF—all on one box. Each has its own rules and logs, and any traffic between them still gets inspected. It’s like having multiple appliances without the extra hardware. Always-Up-to-Date Threat Feeds. Daily signature updates and AI-driven threat sensing mean we’re blocking the latest vulnerabilities almost as soon as they’re announced.
KO
Network Administrator at THK Co Ltd
Faced hardware limitations and setup challenges but have improved network protection over time
I spent much time finding exact firmware on Aruba which was working with these guns, but it is not optimal because it is not the latest version, so there could be potential security problems. We decided to replace those access points with another one. I personally have trouble because I don't know the exact life cycle of Fortinet FortiGate-VM boxes. I don't know if the life of boxes is five years or something else; we moved from our previous company, which sold us to other companies. Before 10 years, we had a special department that took care of core networks, including firewalls. After that, this responsibility fell to me and my colleague. It is not easy to set up these Fortinet FortiGate-VM boxes properly because we didn't have previous experience with this kind of solution. At first, we set up only a few rules that were not secure enough, and over a couple of years, we improved the settings and security of these Fortinet FortiGate-VM boxes. Currently, I have one Fortinet FortiGate-VM that needs to be replaced next year, and this box is not so powerful, so I need to redirect some traffic to another Fortinet FortiGate-VM. It is stable, but because the CPU processor of this box is not powerful, I need to redirect some traffic to another box. In the future, I need to choose a higher-level box to prevent potential troubles with the power of this box.
Zaid Farooqui - PeerSpot reviewer
CIO at Indus Motor Company
Enhanced threat detection with integrated security features and good support
We are using application firewalling, WAF, and SD-WAN. The capabilities are mostly within the box. For example, you will get web application firewall WAF as part and parcel of this. SD-WAN is also bundled. It integrates with their SIEM and SOAR solutions very nicely. Lastly, the pricing point is very cost-efficient as well.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The technical support is great."
"I think when you look at this product, you must realize that the box hardware and software are very stable, and the pricing is perfect."
"This is a quality product with ok support, and it is better than the competition we've tried."
"Fortinet FortiGate is a stable solution."
"With Fortinet, we're able to control how users utilize resources and pull back on certain things while allowing more access in others, which has led to fewer expenses, less time wasted addressing issues related to reporting, and more order and better analysis of exactly what is going on in the network."
"The security for endpoints is the most valuable. It is very secure for our workers. It allows us to secure a transaction and enable security for a specific segment in the workflow."
"This solution has a unique range of features that are not available with any other product."
"The most valuable features of Fortinet FortiGate are the different types of profiling. It has been the most effective for me. The WAF and the antivirus profile are the most effective in network protection."
"Fortinet FortiGate has impacted our cost savings and security efficiency positively."
"Fortinet-VM is more scalable than the hardware version, because if you want a more scalable firewall, you can get a VM, install it on a high-end server, and have much higher performance in packaging all these policies and hardware security features."
"Real-time threat response is really good, and sandboxing and all the signatures are most of the time accurate."
"Operations have been flawless."
"I'm very happy with this product and would rate it at a ten out of ten."
"There is an interesting possibility of building a tunnel to a firewall from access points. We use this feature for small branch offices with one to two employees with access to central RDP servers."
"The user interface, stability, and scalability are the most valuable features."
"The customer care center of Fortinet is good. For all the requests that we have done, they work as fast as possible, so this is a good point for Fortinet.​"
"The solution is quite safe and good, and furthermore, it is very good for different environments."
"The top functionality is the reporting feature."
"The absolute best part of Sangfor NGAF is their support; it's a 24/7 support channel, and the last time I requested their assistance I got a reply within three minutes and they helped solve the problem immediately."
"The most valuable features are the WAN optimization, the internet access gateway (IAG), and the central console, which allows us to implement on their firewall."
"The VPN connectivity feature is really nice."
"In terms of the most valuable features, the IPS report is quick and updated, and performance is also valuable."
"In four steps one can configure the entire firewall."
"Sangfor NGAF works accordingly with our customers, the solution has good performance, is easy to use, and integrates well with the endpoints."
 

Cons

"The scalability of the device is limited."
"We faced some technical issues on the Fortinet side."
"More advanced AI capabilities would be beneficial in future updates."
"Regarding challenges, customers initially faced issues like internet dropping, but after firmware upgrades, everything worked well."
"The only issue that I have is with FortiNAC. The firewall is fine, but the FortiNAC interface is a little bit too jumbled or too complicated, not as straightforward as it is on the Fortinet FortiGate firewall and FortiAnalyzer."
"Fortinet's support team consists of a huge networking team, because of which there is a delay in response at times."
"Usually, we sell the bundle with the UTM or threat management piece with IPS, IDS. Other providers, such as Palo Alto, are ahead in terms of safe functionality. So, for me, delivering truly safe service is probably something that still needs to be improved."
"The reports provided by the equipment could be more detailed, and not so dependent on the FortiAnalyzer."
"The product's initial setup phase is a bit complex."
"Fortinet could improve the availability and delivery of its products. It takes four to six weeks for every purchase to arrive."
"We occasionally have issues when we are doing firmware updates."
"In the Philippine market, where cybersecurity is still growing but not yet fully mature, we have many clients who have Fortinet FortiGate-VM or hardware. However, we cannot really position the Fabric if the licenses, renewal parts, or other components have monetary requirements that hinder full utilization."
"The user interface needs to be improved."
"Some of the compatibility and technical support issues are reasons why I rate it eight instead of nine or ten; the rest of everything is good."
"The interface needs to be updated and simplified."
"Scalability is a problem because the solution is VM."
"An area of improvement for Sangfor NGAF could be in the field of reporting and logging."
"I would be happy if Sangfor developed a firewall designed specifically for home use, as well as for small businesses such as clinics and so on. A household version of the Sangfor firewall for your personal computer or laptop would be ideal, in my opinion."
"The GUI needs to be improved, lacks logic in some areas."
"They need to increase the number of ports in the firewall."
"The solution should be able to work in a hybrid setup."
"Our experience with its customer support was quite challenging."
"The support offered by the product has certain shortcomings where improvements are required. The knowledge levels and response time of the support team need improvement."
"The product must provide more IPS features."
 

Pricing and Cost Advice

"The price is okay, so far so good."
"If the customer is looking for SD-WAN, it comes free with FortiGate."
"We pay for the license of Fortinet FortiGate IPS annually. There are not any extra costs."
"Setup cost may be not so low, as you expect, because it depends on different factors, but TCO for 5 years may pleasantly surprise you."
"The price of FortiGate is good."
"The solution is very expensive so pricing is rated a one out of ten."
"Licensing for Fortinet FortiGate is on a yearly basis. Pricing for it is a bit high. It could be cheaper."
"The license of Fortinet FortiGate should be reduced."
"On a scale of one to ten, where ten is very expensive, I rate the solution around two or three. I think the solution's prices are okay, considering the services and features they offer."
"There should be a reduction in the setup price and licensing costs."
"VMs can be affordable, but for high-demand scenarios, I'd still recommend the hardware. For the cost, it's a ten out of ten."
"Fortinet FortiGate-VM is a very expensive solution."
"The price is similar to Symantec Endpoint, but it's more expensive than Forcepoint solutions. Fortinet is better than Forcepoint."
"The product is expensive. Users can opt for a one-year, two-year, three-year, or five-year subscription model when it comes to licensing."
"We pay for a yearly license."
"We can tailor the suitable license for the customer, whether they require UTB or enterprise features. The options are flexible based on their needs."
"The license of Sangfor NGAF can be purchased at different interval lengths, such as annually or three years. They offer a range of packages to choose from, such as combo or hybrid packages. We are using the complete solution package which includes IM, NGF and SSL VPN, and WAF."
"Sangfor NGAF is a cheaply priced product, especially if I consider the previous product that was used in my company."
"I rate the product price as one on a scale of one to ten, where one is low price and ten is high price."
"Sangfor is cheaper than competing vendors."
"The price falls in the mid-range, neither exceptionally low nor high."
"The product is very cost-effective compared to other brands or vendors."
"In my opinion, the price of the tool is good in the Pakistani market. We can easily get discounts if needed."
"The solution has a TCO that is 32% to 50% less than Sophos, Fortinet, and SonicWall."
report
Use our free recommendation engine to learn which Firewalls solutions are best for your needs.
902,417 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Comms Service Provider
10%
Computer Software Company
9%
Manufacturing Company
9%
Financial Services Firm
7%
Financial Services Firm
9%
Computer Software Company
8%
Construction Company
7%
Comms Service Provider
7%
Financial Services Firm
10%
Manufacturing Company
10%
Comms Service Provider
10%
Construction Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business369
Midsize Enterprise139
Large Enterprise195
By reviewers
Company SizeCount
Small Business72
Midsize Enterprise34
Large Enterprise39
By reviewers
Company SizeCount
Small Business15
Midsize Enterprise10
Large Enterprise10
 

Questions from the Community

Which is the better NGFW: Fortinet Fortigate or Cisco Firepower?
When you compare these firewalls you can identify them with different features, advantages, practices and usage a...
What is the biggest difference between Sophos XG and FortiGate?
From my experience regarding both the Sophos and FortiGate firewalls, I personally would rather use FortiGate. I know...
What are the biggest technical differences between Sophos UTM and Fortinet FortiGate?
As a solution, Sophos UTM offers a lot of functionality, it scales well, and the stability and performance are quite ...
Features comparison between Palo Alto and Fortinet firewalls
In the best tradition of these questions, Feature-wise both are quite similar, but each has things it's better at, it...
Which would you recommend - FortiGate VM or Azure Firewall?
Both of these solutions are excellent options that provide flexible scalability and solid security. Fortinet Fortigat...
What is your experience regarding pricing and costs for Fortinet FortiGate-VM?
From our perspective, it's quite good. When we have the visibility, we will make our policies depending on the threat...
What is your experience regarding pricing and costs for Sangfor NGAF?
The licensing cost is quite high compared to other available firewalls in the market.
What needs improvement with Sangfor NGAF?
The cost of licensing is very high compared to other firewalls available here. There should be improvements in hardwa...
What is your primary use case for Sangfor NGAF?
We are hosting applications over the platform, including websites and NAT traffic from our side. Because it's deploye...
 

Also Known As

Fortinet FortiGate Next-Generation Firewall
FortiGate Virtual Appliance, FortiGate-VM
Sangfor NGAF Firewall Platform
 

Overview

 

Sample Customers

Amazon Web Services, Microsoft, IBM, Cisco, Dell, HP, Oracle, Verizon, AT&T, T-Mobile, Sprint, Vodafone, Orange, BT Group, Telstra, Deutsche Telekom, Comcast, Time Warner Cable, CenturyLink, NTT Communications, Tata Communications, SoftBank, China Mobile, Singtel, Telus, Rogers Communications, Bell Canada, Telkom Indonesia, Telkom South Africa, Telmex, Telia Company, Telkom Kenya
Security7 Networks, COOPENAE
The Ministry of Science, Technology, and Innovation (Indonesia), Lawson, Inc. (Philippines), Universiti Sultan Zainal Abidin (Indonesia), TEK Automotive (Italy), etc.
Find out what your peers are saying about Fortinet FortiGate-VM vs. Sangfor NGAF and other solutions. Updated: June 2026.
902,417 professionals have used our research since 2012.