No more typing reviews! Try our Samantha, our new voice AI agent.

OPNsense vs Sangfor NGAF comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Jan 25, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Fortinet FortiGate
Sponsored
Ranking in Firewalls
1st
Average Rating
8.4
Reviews Sentiment
6.9
Number of Reviews
592
Ranking in other categories
Secure Web Gateways (SWG) (2nd), Intrusion Detection and Prevention Software (IDPS) (1st), Software Defined WAN (SD-WAN) Solutions (1st), WAN Edge (1st), ZTNA (1st), Unified Threat Management (UTM) (1st)
OPNsense
Ranking in Firewalls
5th
Average Rating
8.2
Reviews Sentiment
6.6
Number of Reviews
47
Ranking in other categories
No ranking in other categories
Sangfor NGAF
Ranking in Firewalls
21st
Average Rating
8.0
Reviews Sentiment
6.5
Number of Reviews
34
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of June 2026, in the Firewalls category, the mindshare of Fortinet FortiGate is 15.1%, down from 21.7% compared to the previous year. The mindshare of OPNsense is 8.5%, down from 10.7% compared to the previous year. The mindshare of Sangfor NGAF is 1.1%, down from 1.3% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Firewalls Mindshare Distribution
ProductMindshare (%)
Fortinet FortiGate15.1%
OPNsense8.5%
Sangfor NGAF1.1%
Other75.3%
Firewalls
 

Featured Reviews

JK
IP Network Security Specialist at MTN Ghana
Process-Level CPU Visibility: Introduce detailed CPU-usage metrics per subsystem (e.g., IPS engine, logging) so administrators can quickly identify and address performance spikes.
Analytics with FortiAnalyzer. Being able to pull in logs not just from our FortiGates but from all our other firewalls and then get them in one view has been a game changer. Whether I’m building an executive dashboard or doing a deep dive forensics session, I get everything I need without navigating consoles.Straightforward Application Control. FortiGate spots and blocks unwanted apps (eq. like BitTorrent or streaming services) with accuracy. Segmentation with VDOMs. We’ve carved our data center into four logical ‘mini-firewalls’ enterprise, core, billing, and WAF—all on one box. Each has its own rules and logs, and any traffic between them still gets inspected. It’s like having multiple appliances without the extra hardware. Always-Up-to-Date Threat Feeds. Daily signature updates and AI-driven threat sensing mean we’re blocking the latest vulnerabilities almost as soon as they’re announced.
Moutaz Sheikh Alard - PeerSpot reviewer
ISO 27001 Lead Implementer at a consultancy with 11-50 employees
Has helped simulate enterprise security setups and strengthens network segmentation practices
For my capstone, I use OPNsense for my project and its broader benefits for enterprise and cybersecurity context. OPNsense is an open source based firewall and routing platform. It offers enterprise-grade features such as intrusion detection and prevention system, VPN support, traffic shaping, and web filtering, all without license cost. This platform has a modular design, a clean web-based GUI, and frequent updates that prioritize security and usability. It competes with commercial firewalls such as Cisco ASA, FortiGate, and Palo Alto, but stands out because it's community-driven, cost-effective, and transparent. I find OPNsense's feature of acting as a central firewall and gateway most valuable, providing robust point segmentation between the internal network and DMZs in my capstone project, intrusion detection to monitor malicious traffic, VPN services for secure remote access, and logging and monitoring for compliance and auditing. This allows me to simulate a real-world enterprise environment on a smaller scale, demonstrating both security hardening and network efficiency. OPNsense impacts my projects and home network positively because its cost-effectiveness is perfect for lab and enterprise setup without expensive licensing. The flexibility, easy VLAN and DMZ configuration supports different zones such as web servers, mail servers, and log servers. The security-first design for IDS/IPS integration helps me showcase modern defense-in-depth strategies. The user-friendly management through the web GUI makes it possible to manage complex firewall rules clearly, which is critical when documenting and presenting a capstone. Scalability is also an advantage. Although my project is lab-based, OPNsense can scale into production deployments in SMBs and enterprise.
Zaid Farooqui - PeerSpot reviewer
CIO at Indus Motor Company
Enhanced threat detection with integrated security features and good support
We are using application firewalling, WAF, and SD-WAN. The capabilities are mostly within the box. For example, you will get web application firewall WAF as part and parcel of this. SD-WAN is also bundled. It integrates with their SIEM and SOAR solutions very nicely. Lastly, the pricing point is very cost-efficient as well.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Fortinet FortiGate has positively impacted my organization with its cost-effectiveness because it provides features that are very similar to others, but at a much lower cost, and everything my organization needs is available with Fortinet FortiGate."
"Fortinet FortiGate IPS has an easy-to-use interface and configuration."
"The initial setup is very straightforward and easy, with wizards helping to configure the device efficiently."
"The solution's application control is very powerful."
"Previously, we were using another firewall device, Sophos. Compared to that, Fortinet FortiGate provides more features and better security."
"In a scenario where FortiGate Next Generation Firewall (NGFW) notably enhanced my customer's network performance, we discussed many points."
"The product is very user-friendly, it is quite scalable, I love the interface, the power is great, and I have a limited embedded team in IT with one man on the team for 1,000 users who can manage all the infrastructure due to the fact that the console is very easy, and the people are very happy with the results pertaining to that interface."
"The most valuable feature is the deep inspection for traffic, which is capable of identifying zero-day attacks."
"It has firewall and VPN capabilities, which are very valuable features."
"I feel that its valuable features are that it is simple and free."
"URL blocking, Wireguard, Tail Scale, Engine Blocker, and VPN are the most valuable features for me."
"It's open source."
"OPNsense can be deployed in the cloud and on-premises, and I have used OPNsense in many different types of companies, such as financial and metropolitan."
"We saved up to half a million Egyptian pounds, which is nearly $100,000 yearly on licensing or subscription using this kind of software, and the network attacks reduced by approximately 60% after using that, even without customizing the custom configuration yet."
"OPNsense is easy to scale when running on the hardware."
"The initial implementation process is simple."
"We've found the technical support to be helpful."
"It is a stable solution."
"While the features are not dissimilar to other brands, configuration is much more simple, which works out great for Indonesian people."
"The top functionality is the reporting feature."
"We use Sangfor NGAF primarily for security, which has helped save our files from being encrypted by ransomware."
"The tool's performance is good."
"The built-in features function as intended, providing exceptional value."
"Sangfor NGAF works accordingly with our customers, the solution has good performance, is easy to use, and integrates well with the endpoints."
 

Cons

"They have not yet extended to the cloud."
"Fortinet FortiGate is a firewall solution and once it's deployed, you can rest assured that your system is secure."
"Fortinet needs more memory to save the log files. We need it to save the logs on the hardware and not in the cloud. I know this feature is available in FortiCloud, but if we need this log locally, it is not available."
"It would be helpful to have a better tool for migrating all policy rules using an automatic script."
"The issue with Fortinet FortiGate is the many security CVEs around; I have read there are probably multiple critical CVEs above 9.0 in Fortinet FortiGate products."
"The learning curve is a bit higher."
"FortiGate can only retain logs for 24 hours or 7 days. I'm not sure if it holds them for a longer period, such as for a month."
"At the moment, the main concern is the pricing and the type of licensing. Fortinet offers different types of licensing, and my idea is that the best approach is to have only one, two, or a maximum of three types of licensing."
"There is room for improvement in SSL inspection."
"While they do have paid options that actually gives better features, for most of the clients, if they tend to take a paid option will instead opt for Fortinet."
"Pricing in my opinion is just too expensive. It makes no sense. It moves in the direction of a monopoly."
"OPNsense struggles to handle large volumes of voice traffic, indicating scalability issues in that specific use case."
"An area for improvement in OPNsense is the hardware, which needs to be updated more frequently. DNS blocking is another good feature I want to be added to the solution. pfSense has a peer-blocking feature that I also want to see in OPNsense."
"We did not like the fact that you have to configure everything with the graphic user interface. We have used other firewalls, such as FortiGate, that you can configure via code. OPNsense is not easy to integrate. When you are deploying via GitHub or another source repository, this is not possible. That's one thing we didn't like much."
"The interface of the solution is an area with shortcomings."
"The reporting part could be better."
"I would be happy if Sangfor developed a firewall designed specifically for home use, as well as for small businesses such as clinics and so on. A household version of the Sangfor firewall for your personal computer or laptop would be ideal, in my opinion."
"I feel Sangfor should follow the hierarchy and close deals via resellers instead of closing it all with their own team."
"The cost of licensing is very high compared to other firewalls available here. There should be improvements in hardware scalability, allowing for more storage and memory capacity."
"An area of improvement for Sangfor NGAF could be in the field of reporting and logging."
"Our experience with its customer support was quite challenging."
"The reporting and log management could be improved."
"We have deployed many firewalls and have faced two or three faulty devices that we have to replace over a year because their power supply was faulty."
"The tool is expensive."
 

Pricing and Cost Advice

"The pricing is justified. It's a little pricey, but what you pay for is what you get."
"The licensing costs are very low."
"The licensing cost is at the intermediate level."
"It was pretty affordable. We did go a little bit above MSRP, but the service pack that was included was quite worth the additional costs. It is competitively priced compared to other major players in the market. It is significantly cheaper than Check Point, which is a primary competitor. Additionally, its pricing is comparable to that of Cisco's ASA and a few other vendors."
"The product is expensive compared to one of its competitors."
"Although the solution's pricing is high, compared with other products, it may be cheap."
"Fortinet FortiGate SWG is an affordable solution."
"FortiGate's pricing falls within the mid-range when compared to other leading firewall solutions."
"It is not an expensive product. Basically, I deployed it because it was the fastest solution to satisfy our needs in open source."
"There are no licensing costs for OPNsence."
"I've used the free version. My computer with two network cards at home allows me to try as many different software options as I want. I did pay for the license, but it was for the Zenarmor license, which is the packet inspection tool. They use AI for packet inspection, which integrates with OPNsense and pfSense."
"I would rate the pricing a nine out of ten, especially considering the availability of a free community edition."
"Its pricing is unbeatable in comparison to other firewalls. You can have a small instance that could be €80 a month with the hardware underneath. Azure Firewall and FortiGate are out of the question at this price. If you are on a public cloud, you need the underlying infrastructure. Other than that, there is no additional cost. If you have it on-prem, you have to buy the server or the appliance. The hardware cost is replaced with the infrastructure cost in the cloud. You also have costs for the public IPs and underlying VMs, but that's not related to OPNsense. It would be the same for a FortiGate deployment on Azure. You need a FortiGate license, and you need the underlying infrastructure that scales up depending on your needs."
"OPNsense is open source software so at this time it is free for us to use."
"The price of OPNsense is good."
"It is free."
"For over 2000 users, the cost is around 5000 to 6000 USD. If you want a web application firewall, you have to purchase an additional license for it."
"The pricing is reasonable."
"The price is unmatcheable."
"It costs about 8 to 10 thousand dollars per year for 500 users, standard licensing fees included."
"The product is very cost-effective compared to other brands or vendors."
"The license of Sangfor NGAF can be purchased at different interval lengths, such as annually or three years. They offer a range of packages to choose from, such as combo or hybrid packages. We are using the complete solution package which includes IM, NGF and SSL VPN, and WAF."
"It is one of the cheapest tools in the market."
"Sangfor NGAF is a cheaply priced product, especially if I consider the previous product that was used in my company."
report
Use our free recommendation engine to learn which Firewalls solutions are best for your needs.
902,417 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Comms Service Provider
10%
Computer Software Company
9%
Manufacturing Company
9%
Financial Services Firm
7%
Comms Service Provider
17%
Computer Software Company
10%
Manufacturing Company
8%
Financial Services Firm
6%
Financial Services Firm
10%
Manufacturing Company
10%
Comms Service Provider
10%
Construction Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business369
Midsize Enterprise139
Large Enterprise195
By reviewers
Company SizeCount
Small Business32
Midsize Enterprise6
Large Enterprise8
By reviewers
Company SizeCount
Small Business15
Midsize Enterprise10
Large Enterprise10
 

Questions from the Community

Which is the better NGFW: Fortinet Fortigate or Cisco Firepower?
When you compare these firewalls you can identify them with different features, advantages, practices and usage a...
What is the biggest difference between Sophos XG and FortiGate?
From my experience regarding both the Sophos and FortiGate firewalls, I personally would rather use FortiGate. I know...
What are the biggest technical differences between Sophos UTM and Fortinet FortiGate?
As a solution, Sophos UTM offers a lot of functionality, it scales well, and the stability and performance are quite ...
What is the difference between PfSense and OPNsense?
Two of the most common and well recognized firewalls, PfSense and OPNsense both support site-to-site IPsec VPN and cl...
What is your experience regarding pricing and costs for OPNsense?
Setup cost is almost zero as one can simulate the whole environment using open source version. Pricing seems fair eno...
What needs improvement with OPNsense?
When I talk about VPN, I am not completely satisfied with the VPN functions of OPNsense. What I have received so far ...
What is your experience regarding pricing and costs for Sangfor NGAF?
The licensing cost is quite high compared to other available firewalls in the market.
What needs improvement with Sangfor NGAF?
The cost of licensing is very high compared to other firewalls available here. There should be improvements in hardwa...
What is your primary use case for Sangfor NGAF?
We are hosting applications over the platform, including websites and NAT traffic from our side. Because it's deploye...
 

Also Known As

Fortinet FortiGate Next-Generation Firewall
No data available
Sangfor NGAF Firewall Platform
 

Overview

 

Sample Customers

Amazon Web Services, Microsoft, IBM, Cisco, Dell, HP, Oracle, Verizon, AT&T, T-Mobile, Sprint, Vodafone, Orange, BT Group, Telstra, Deutsche Telekom, Comcast, Time Warner Cable, CenturyLink, NTT Communications, Tata Communications, SoftBank, China Mobile, Singtel, Telus, Rogers Communications, Bell Canada, Telkom Indonesia, Telkom South Africa, Telmex, Telia Company, Telkom Kenya
1. Deciso B.V. 2. iXsystems, Inc.  3. EuroBSDCon  4. Netgate  5. Claranet  6. Voleatech  7. Open Systems AG  8. Securebit AG  9. Proxmox Server Solutions GmbH  10. AVM Computersysteme Vertriebs GmbH  Additional customers include: T-Systems International GmbH, Deutsche Telekom AG, Vodafone GmbH, 1&1 IONOS SE, OVHcloud, Hetzner Online GmbH, Strato AG, PlusServer GmbH, Host Europe GmbH, United Internet AG, 1&1 Versatel Deutschland GmbH, QSC AG, Bechtle AG, Cancom SE, Computacenter AG & Co. oHG, T-Systems Multimedia Solutions GmbH, Atos SE, Capgemini SE, Accenture plc, IBM Corporation, Hewlett Packard Enterprise Company, Cisco Systems, Inc.
The Ministry of Science, Technology, and Innovation (Indonesia), Lawson, Inc. (Philippines), Universiti Sultan Zainal Abidin (Indonesia), TEK Automotive (Italy), etc.
Find out what your peers are saying about OPNsense vs. Sangfor NGAF and other solutions. Updated: June 2026.
902,417 professionals have used our research since 2012.