Try our new research platform with insights from 80,000+ expert users

Netgate pfSense vs Sophos XGS comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Sep 16, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
7.5
Fortinet FortiGate is valued for affordability, cost savings, enhanced security, operational efficiency, quick implementation, and long-term ROI benefits.
Sentiment score
7.9
Netgate pfSense offers cost-effective, high-performance solutions, replacing pricier options and improving network stability, efficiency, and security.
Sentiment score
2.5
Sophos XGS offers valuable ransomware protection for small businesses, reducing operational costs despite higher licensing fees.
Clients are now comfortable and not wasting productive hours on IT support.
The automation part is giving us a cost benefit and speed; we can react faster.
It's a very useful tool to mitigate and protect your enterprise.
If they can save their data from attackers then it would save them at least two days of not working plus the cost of recovery, which would be much more than the cost of the system and maintenance.
Since the memory leak fixes, it's been incredibly stable and requires minimal maintenance.
In four years of using it, that payment of 189 dollars per year has already paid off.
The costs have increased with Sophos XGS in the last few years, with license prices going up by 30%, doubling from $2,500 to about $5,000, which is a big challenge for us.
 

Customer Service

Sentiment score
7.0
Fortinet FortiGate's customer service varies, with praise for responsiveness but criticism for slow, sometimes inadequate technical support.
Sentiment score
8.0
Netgate pfSense offers reliable community resources and praised paid support, despite occasional inconsistencies with complex technical issues.
Sentiment score
6.9
Sophos XGS customer service varies, praised for responsiveness but criticized for slow responses and expertise in initial support stages.
I would rate their support for FortiGate a nine out of ten.
They offer very accurate solutions.
The quick resolution of issues with Fortinet FortiGate is due to the support of the company and the fact that the equipment is easy to work with.
When I provide detailed information about the problem, they've been able to reply quickly with a solution or go research the problem and get back to us quickly with a fix.
They are highly responsive.
I couldn't imagine having better support.
Any issues are quickly addressed by their support team, which is not common among all OEM manufacturers.
The technical support of Sophos rates at 10.
The response time from Sophos technical support can be slow in most cases, which can be challenging.
 

Scalability Issues

Sentiment score
7.3
Fortinet FortiGate scales well for diverse enterprises, though planning and licensing are crucial to avoid hardware limitations.
Sentiment score
7.0
Netgate pfSense is scalable and cost-effective, managing large networks efficiently with adaptable hardware and seamless expansion capabilities.
Sentiment score
7.0
Sophos XGS is versatile for various environments, but some hardware limitations exist, suitable for small to medium enterprises.
They scale up really well from smaller models like the FortiGate 40 and 50 to bigger sites with the FortiGate 100 for more throughput - up to enterprise datacenters.
The variation comes in terms of the interfaces and throughputs, but from a security perspective, you get the same benefit, irrespective of whether you have an entry-level unit or an enterprise.
We determine sizing based on multiple factors: number of users, available links, traffic types, server count, services in use, and whether services will be published.
If I put things into a certain context and say that we have a network that has around 100 people, then you don't put up a device that can manage 100 people. Instead, you need to get a device that can manage 150 to 200 people, and then you can create room for growth.
I don't think Netgate pfSense can offer much scalability for big enterprises.
Even with a jump from a 50 megabit to a 500 megabit internet connection and approximately 65 active VPN clients, our firewall operates smoothly without any strain.
I can change what I want easily without interfering with other services or routines.
I would rate its scalability seven out of ten since modules can be added.
 

Stability Issues

Sentiment score
7.9
Fortinet FortiGate is generally stable and reliable, with minor issues arising from new features, firmware updates, or hardware constraints.
Sentiment score
6.9
Users highly rate Netgate pfSense's stability, attributing rare issues mainly to hardware rather than the software itself.
Sentiment score
7.6
Sophos XGS is praised for stability and reliability, with high ratings despite occasional performance drops when capacity limits are exceeded.
We're experiencing 99.999% availability consistently.
I would rate the stability of Fortinet FortiGate a ten out of ten.
We have not had any problems with the operating systems or maintenance of subscriptions.
I rate the solution's stability a ten out of ten.
I've noticed a substantial improvement in stability and ease of use for upgrades and patching over the past year or two.
When I replace consumer routers with pfSense for small businesses with two or three employees, they are often amazed to discover the router can run for a year without a reboot.
It is rated at nine out of ten for stability and is very reliable.
Sophos XGS is stable now, and I would rate its stability as a ten out of ten.
When Sophos introduced firmware version twenty, there was a bug in DCC.
 

Room For Improvement

Fortinet FortiGate needs enhancements in firmware, usability, integration, support, reporting, VPN, cloud integration, and documentation for seamless use.
Netgate pfSense needs better GUI usability, management, consistent updates, improved performance, intuitive interfaces, and strategic communication.
Sophos XGS requires improved integration, scalability, and support, while addressing high costs and complex configurations for better user experience.
By providing an integrated solution, users would have access to all features and functionalities within a single window, eliminating the need to navigate through multiple windows.
Investing in a solution that can accommodate such growth would be more cost-effective than repeatedly purchasing new hardware.
The constant daily revisions necessitate meticulous identification of the relevant documents to prevent the use of outdated information that could jeopardize our environment.
There is some trade-off between having a certain level of security and maintaining acceptable performance.
If I need to go between different VLANs, I have VLAN 19.1 and VLAN 19.2, and I strictly use Netgate pfSense, but it doesn't route very efficiently and works quite slowly.
They should support the idea of configuration management as code from source code and provide a more robust API for managing the pfSense configuration.
It would be beneficial if Sophos XGS offered an end-to-end solution with competitive pricing.
The DDNS features are essential for any organization, as it is better not to have a static IP address from an ISP.
After version 18.5, creating a NAT rule has become more complex, requiring the creation of a separate policy and an additional component.
 

Setup Cost

Fortinet FortiGate offers competitive pricing with upfront affordability, simple licensing, and long-term value, despite potentially high renewal costs.
Netgate pfSense is cost-effective, open-source, integrates key functions, and offers affordable subscriptions, appealing to budget-focused enterprises.
Sophos XGS offers flexible pricing with competitive discounts, balancing cost-effectiveness and functionality compared to rivals like Fortinet and Palo Alto.
The most expensive part is the renewal of the license subscription.
FortiGate is priced lower than Palo Alto.
Last year, I renewed the support for three years, which can sometimes be expensive but depends on the security benefits and how it helps us.
The price of setup is approximately €500 to €800, which also includes the initial monitoring.
You can acquire a decent embedded PC for around a hundred dollars and install pfSense on it, effectively creating a robust firewall solution.
The product is free of cost.
The last instance I purchased was for three years, around $3,700 for SDG 125.
pricing is rated eight out of ten, indicating that it may be relatively expensive.
Sophos XGS is quite expensive, potentially a nine out of ten in terms of cost.
 

Valuable Features

Fortinet FortiGate delivers robust security features and intuitive management, offering scalable and affordable network protection solutions.
Netgate pfSense is praised for its performance, flexibility, robust features, and user-friendly interface, enhancing security and scalability.
Sophos XGS provides centralized management, strong security features, and scalability, ensuring efficient and cost-effective network control across industries.
The firewall, IPS, and VPN functions are the most valuable features.
FortiGate provides solid protection against viruses, malware, and other threats.
In terms of security, we have not experienced any security flaws or loopholes, and it has proven to be quite stable.
With pfSense, network configurations adhere to standard practices, facilitating troubleshooting without the need for complex overlays or policies.
The price point is the most valuable aspect of the solution.
I like the tool's flexibility in the sense that you do not have to buy an appliance. You can put it on your own hardware, and it can be very simplistic hardware with simple configurations.
It's able to detect cloud applications like Zoom or Microsoft Teams and allows traffic shaping based on the application.
I find it much easier than others, like FortiGate, which is complicated in its installation, but Sophos XGS is really easy.
The threat detection capabilities are effective, especially against CNC and certain viruses not coming through emails.
 

Categories and Ranking

Fortinet FortiGate
Sponsored
Ranking in Firewalls
2nd
Average Rating
8.4
Reviews Sentiment
7.2
Number of Reviews
357
Ranking in other categories
Software Defined WAN (SD-WAN) Solutions (1st), WAN Edge (1st)
Netgate pfSense
Ranking in Firewalls
1st
Average Rating
8.6
Reviews Sentiment
7.3
Number of Reviews
217
Ranking in other categories
No ranking in other categories
Sophos XGS
Ranking in Firewalls
11th
Average Rating
8.0
Reviews Sentiment
6.6
Number of Reviews
84
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of June 2025, in the Firewalls category, the mindshare of Fortinet FortiGate is 21.4%, up from 17.8% compared to the previous year. The mindshare of Netgate pfSense is 12.7%, down from 21.7% compared to the previous year. The mindshare of Sophos XGS is 2.5%, up from 1.1% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Firewalls
 

Featured Reviews

Jorge Martínez - PeerSpot reviewer
Offers good SD-WAN capabilities and integrates easily with Fortinet devices
I am not part of the initial setup or deployment process since I work in presales. The setup or deployment is quite easy, as you can do a one-touch deployment that automatically connects to the FortiManager cloud when you connect it to a broadband or dynamic IP, allowing you to start the configuration from that point. We usually sell it for on-premises setups. It's on the cloud only when the client has virtual machines or their own service. Sometimes they have a service on the cloud like AWS, but it's more difficult to sell now because AWS has an e-commerce option where you can buy FortiGate directly. The only thing you need is someone to manage and configure.
Vincent Hamm - PeerSpot reviewer
I appreciate the depth of what the solution can do and the simplicity of the initial setup
We do a lot of managed services and are currently trying to get people off of L2TP VPN. Apparently, we can download a mobile config file from a configured NetGate device, and we're primarily Apple. We've experimented with it on a device that's not a production device, and we can't seem to get the phase one IPSec set correctly so that the Apple config will accept it. We've tried looking at the documentation but haven't found anything. While it's not the highest priority, it is rather frustrating. We'd like to do this, and the feature is right there, but we can't get it configured. We certainly don't want to try it on a production machine because it will break the current VPN. I would like to download the Apple mobile config so that I can tell it to configure my VPN connection to do that. We have some cross-platform things. So there's also a Windows VPN. You can download a script or a PowerShell, put it on a Windows machine, and it can connect to the VPN. It would be nice if I could say I want Mac only, Windows only, or both. I wish it could configure the IPSec phase one and phase two, or at least give me solid instructions on how to configure that. It doesn't supply out-of-the-box visibility to drive decisions. You get 75 log lines, so if you're trying to troubleshoot something, you have to look at one log and then another. It integrates with SysLog systems, but our customers are not at the level where they want to pay for some third-party SysLog system. Usually, we can get things taken care of fairly quickly. I would like to have the ability to control all my devices from one place. With Ubiquiti, you can get a controller that allows you to control all of your Wi-Fi devices, switches, and routers. From one area, you can switch to that customer and see what's happening in their environment. That's not part of pfSense. I understand why it's not because pfSense is open source and community supported. That's something that someone in the community needs to pick up and run with. It's not something the pfSense can easily implement. If they could, that'd be great.
Nassif  Kaleny - PeerSpot reviewer
Dynamic web and mail filtering contribute to improved security measures
The reporting system is very poor. I cannot trace any traffic to our site if it feels some threats. It just tells me that there is something during a certain time but does not provide information about the type of threats or how to get rid of them. This needs improvement.
report
Use our free recommendation engine to learn which Firewalls solutions are best for your needs.
856,873 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Educational Organization
15%
Computer Software Company
15%
Comms Service Provider
8%
Manufacturing Company
6%
Computer Software Company
16%
Comms Service Provider
12%
Educational Organization
6%
Government
6%
Computer Software Company
13%
Manufacturing Company
9%
Comms Service Provider
8%
Educational Organization
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

Which is the better NGFW: Fortinet Fortigate or Cisco Firepower?
When you compare these firewalls you can identify them with different features, advantages, practices and usage a...
What is the biggest difference between Sophos XG and FortiGate?
From my experience regarding both the Sophos and FortiGate firewalls, I personally would rather use FortiGate. I know...
What are the biggest technical differences between Sophos UTM and Fortinet FortiGate?
As a solution, Sophos UTM offers a lot of functionality, it scales well, and the stability and performance are quite ...
Help me find the best open source router
You don't really specify what type of router you are looking for but if you are talking about a gateway router I reco...
How do I choose between Fortinet FortiGate and pfSense?
Fortinet’s Fortigate is a firewall solution we use and are very much satisfied with its performance. We find Fortigat...
What is the difference between PfSense and OPNsense?
Two of the most common and well recognized firewalls, PfSense and OPNsense both support site-to-site IPsec VPN and cl...
What do you like most about Sophos XGS?
The policies are the greatest feature. They allow us to configure granular control over our network traffic.
What is your experience regarding pricing and costs for Sophos XGS?
I am satisfied with the price, rating it a nine. There are no extra expenses required after buying the product.
What needs improvement with Sophos XGS?
There is room for improvement in Sophos XGS, specifically in three areas: slowness, centralized synchronization, and ...
 

Also Known As

FortiGate 60b, FortiGate 60c, FortiGate 80c, FortiGate 50b, FortiGate 200b, FortiGate 110c, FortiGate, Fortinet Firewall
No data available
No data available
 

Overview

 

Sample Customers

Amazon Web Services, Microsoft, IBM, Cisco, Dell, HP, Oracle, Verizon, AT&T, T-Mobile, Sprint, Vodafone, Orange, BT Group, Telstra, Deutsche Telekom, Comcast, Time Warner Cable, CenturyLink, NTT Communications, Tata Communications, SoftBank, China Mobile, Singtel, Telus, Rogers Communications, Bell Canada, Telkom Indonesia, Telkom South Africa, Telmex, Telia Company, Telkom Kenya
Nerds On Site Inc., RKC Development Inc., Expertech, Fisher's Technology, Ncisive, Consulting, CPURX, Vaughn's Computer House Calls, Imeretech LLC, Digital Crisis, Carolina Digital Phone, Technigogo Technology Services, The Simple Solution, SwiftecITInc, Rocky Mountain Tech Team, Free Range Geeks, Alaska Computer Geeks, Lark Information Technology, Renaissance Systems Inc., Cutting Edge Computers, Caretech LLC, GoVanguard, Network Touch Ltd, P.C. Solutions.Net, Vision Voice and Data Systems LLC, Montgomery Technologies, Techforce, Concero Networks, ASONInc, CPS Electronics and Consulting, Darkwire.net LLC, IT Specialists, MBS-Net Inc., VOICE1 LLC, Advantage Networking Inc., Powerhouse Systems, Doxa Multimedia Inc., Pro Computer Service, Virtual IT Services, A&J Computers Inc., Envision IT LLC, CommunicaONE Inc., Bone Computer Inc., Amax Engineering Corporation, QPG Ltd. Co., IT 101 Inc., Perfect Cloud Solutions, Applied Technology Group Inc., The Digital Sun Group LLC, Firespring
Information Not Available
Find out what your peers are saying about Netgate pfSense vs. Sophos XGS and other solutions. Updated: June 2025.
856,873 professionals have used our research since 2012.