No more typing reviews! Try our Samantha, our new voice AI agent.

Palo Alto Networks NG Firewalls vs Sangfor NGAF comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Jan 25, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Fortinet FortiGate
Sponsored
Ranking in Firewalls
1st
Average Rating
8.4
Reviews Sentiment
6.9
Number of Reviews
592
Ranking in other categories
Secure Web Gateways (SWG) (2nd), Intrusion Detection and Prevention Software (IDPS) (1st), Software Defined WAN (SD-WAN) Solutions (1st), WAN Edge (1st), ZTNA (1st), Unified Threat Management (UTM) (1st)
Palo Alto Networks NG Firew...
Ranking in Firewalls
6th
Average Rating
8.6
Reviews Sentiment
7.1
Number of Reviews
199
Ranking in other categories
No ranking in other categories
Sangfor NGAF
Ranking in Firewalls
21st
Average Rating
8.0
Reviews Sentiment
6.5
Number of Reviews
34
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of June 2026, in the Firewalls category, the mindshare of Fortinet FortiGate is 15.1%, down from 21.7% compared to the previous year. The mindshare of Palo Alto Networks NG Firewalls is 5.1%, up from 3.7% compared to the previous year. The mindshare of Sangfor NGAF is 1.1%, down from 1.3% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Firewalls Mindshare Distribution
ProductMindshare (%)
Fortinet FortiGate15.1%
Palo Alto Networks NG Firewalls5.1%
Sangfor NGAF1.1%
Other78.7%
Firewalls
 

Featured Reviews

JK
IP Network Security Specialist at MTN Ghana
Process-Level CPU Visibility: Introduce detailed CPU-usage metrics per subsystem (e.g., IPS engine, logging) so administrators can quickly identify and address performance spikes.
Analytics with FortiAnalyzer. Being able to pull in logs not just from our FortiGates but from all our other firewalls and then get them in one view has been a game changer. Whether I’m building an executive dashboard or doing a deep dive forensics session, I get everything I need without navigating consoles.Straightforward Application Control. FortiGate spots and blocks unwanted apps (eq. like BitTorrent or streaming services) with accuracy. Segmentation with VDOMs. We’ve carved our data center into four logical ‘mini-firewalls’ enterprise, core, billing, and WAF—all on one box. Each has its own rules and logs, and any traffic between them still gets inspected. It’s like having multiple appliances without the extra hardware. Always-Up-to-Date Threat Feeds. Daily signature updates and AI-driven threat sensing mean we’re blocking the latest vulnerabilities almost as soon as they’re announced.
Nitin Yadav - PeerSpot reviewer
Network & Security Engineer at Arrow PC Network Pvt.Ltd.
Strong threat prevention has reduced phishing and malware while I monitor traffic in depth
Palo Alto Networks NG Firewalls offers application and user awareness, which allow me to control traffic based on threats. The product includes threat prevention, advanced threat prevention, and deep packet inspection that really helps prevent issues in our network. Deep packet inspection inspects full traffic content, even inside applications and encrypted sessions. Deep packet inspection makes a very practical difference day to day because it lets me see and control what is actually inside the traffic, not just the open port or IP. I have real visibility of which application is running instead of just seeing HTTPS. Palo Alto Networks NG Firewalls WildFire sandboxing is really good at detecting and blocking zero-day malware automatically, along with its GlobalProtect and DNS security features. Using Palo Alto Networks NG Firewalls positively impacts my organization by providing strong security, better visibility, faster response, and simplified operations. After deploying Palo Alto Networks NG Firewalls in our network, it blocks malicious traffic and prevents compromises that occurred before Palo Alto Networks NG Firewalls. I can now block outside IPs to prevent issues. After Palo Alto Networks NG Firewalls installation, I reduced 60 to 70 percent of malware and phishing attacks. Its threat prevention and DNS security features detect these attacks, block malicious domains, and reduce manual efforts for the security team.
Zaid Farooqui - PeerSpot reviewer
CIO at Indus Motor Company
Enhanced threat detection with integrated security features and good support
We are using application firewalling, WAF, and SD-WAN. The capabilities are mostly within the box. For example, you will get web application firewall WAF as part and parcel of this. SD-WAN is also bundled. It integrates with their SIEM and SOAR solutions very nicely. Lastly, the pricing point is very cost-efficient as well.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The security fabric is excellent."
"The web tutor and automatic rules by schedule are good features."
"FortiGate has threat protection, antivirus, and even SSL encryption and decryption, and a few customers also use this firewall for web filtering and application control."
"In terms of security, Fortinet FortiGate SWG is superior compared to Cisco."
"Fortinet FortiGate saves a lot of time in expert hours from an expert engineer because the administration of the Fortinet FortiGate solution is easy, which may lead to fewer hours of an engineer spent on Fortinet FortiGate."
"The product is very stable, easy to troubleshoot, and configure, so it has reduced the time it takes for support."
"It is easy to use and performs very well."
"The most valuable features of Fortinet FortiGate are the ability to work in proxy mode, which other solutions, such as Palo Alto cannot. There are some features that are better that come at no extra license or subscriptions cost, such as basic SD-WAN. The DLT is useful, other solutions have the same feature too, such as Palo Alto."
"By switching to Palo Alto Networks NG Firewalls, we made use of the Panorama management tool to manage all our firewalls, making the management side much easier and providing visibility from their monitoring to see the traffic, which we were not able to do before with our previous firewall manufacturer."
"As long as you are comfortable with the price point, you are not going to make a mistake going this way."
"Its machine learning seems pretty good, and it seems like it is catching quite a few things."
"The product's most valuable features are the ease of deployment, regularly updated security information, and robust hardware."
"As far as a firewall solution, it is one of the best ones that I have seen."
"It was valuable in inspecting packets and analyzing traffic patterns. It helped us understand where people were going and what kind of interactions they were doing. We could go to the level of controlling access and uploads/downloads."
"We have not had to replace hardware routers nor purchase additional hardware. So, that has provided a little bit of an ROI."
"The most valuable feature is threat prevention."
"This product is very user-friendly, and its Layer 7 security is very much improved."
"You might try Sangfor if you are on a tight budget. The price is affordable, and Sangfor offers a lot of features. We don't have any complaints about Sangfor."
"Sangfor NGAF works accordingly with our customers, the solution has good performance, is easy to use, and integrates well with the endpoints."
"It is a stable solution."
"When it comes to the price of firewall solutions, Sangfor NGAF takes the cake, as it is cheaper than Fortinet, Sophos, Check Point and Palo Alto."
"We've found the technical support to be helpful."
"The capabilities are mostly within the box."
"The solution is quite safe and good, and furthermore, it is very good for different environments."
 

Cons

"FortiGate IPS is somewhat pricey compared to other solutions. There is also room for improvement in terms of the radio signals. The FortiGate WiFi has a relatively short range. I've found there is a lag in its zero-day malware response that could be better, and FortiGate could integrate better with other brands of equipment or identity management solutions."
"The reporting in Fortinet FortiGate could improve. Customers are having to purchase additional reporting components. When I have used the Sophos solution it is a complete solution, in Fortinet FortiGate you have to use additional tools to have the features needed."
"I need user-behavior analytics, to find threat scenarios from inside the organization, insider attacks. That would be very helpful for us. In addition, I would like next-generation features for small and medium businesses. These businesses require UTM, all in one product. Fortinet must include it."
"The price could be improved."
"Fortinet FortiGate firewall is good, but other products like the switching part and all that fabric, in handling very audio-video traffic, sometimes it struggles on the switching part, but on the routing part, it is fine."
"There should be better customization in the IPS."
"From a pricing perspective, I would rate them a six."
"The feature which gives us a lot of pain is ASIC architecture."
"They could improve their support and pricing and maybe integration. It's a little more expensive that Check Point but the quality is better. Integration with firewall endpoints could be better. Palo Alto does have very good malware or antivirus protection. I think they could improve on that front."
"Scalability is not really the case. Since the NextGen Firewalls are hardware-based, if I want to scale up, I need new hardware. It is not really scalable."
"There is a bit of limitation with its next-generation capabilities. They could be better. In terms of logs, I feel like I am a bit limited as an administrator. While I see a lot of logs, and that is good, it could be better."
"I would like a collaboration system and reporting ASA policy needs to be smarter."
"The customer-facing side needs to be improved in terms of the engagement and involvement of support staff."
"Could also use better customer support."
"If you enable SSL you will face a problem. The throughput of the firewall will be degraded. SSL is a big issue on all firewalls. All products suffer from issues with SSL, but Palo Alto firewalls suffer more from it."
"I think automation and machine learning can be improved to make bulk configurations simpler, easier, and faster."
"The setup phase is quite complex."
"It would be ideal if the solution offered SD-WAN capabilities."
"An area of improvement for Sangfor NGAF could be in the field of reporting and logging."
"Sangfor could improve their interface capacity on the 5100 series model and upgrade their hardware from one gig to 10 gig. This would improve the overall throughput."
"The cost of licensing is very high compared to other firewalls available here. There should be improvements in hardware scalability, allowing for more storage and memory capacity."
"The tool is expensive."
"I feel Sangfor should follow the hierarchy and close deals via resellers instead of closing it all with their own team."
"They need to improve their research team and they need to study their data to analyze it and build the product."
 

Pricing and Cost Advice

"It is an expensive solution."
"The price of FortiGate is comparable to that of most other firewall solutions and is more affordable than Cisco."
"FortiGate SWG is a cost-effective solution well-suited for organisations of all sizes."
"There is a subscription-based model to use Fortinet FortiGate. We pay annually for the solution along with the support. If you want to have all the updates, and security patches you will need to renew your support."
"As far as I'm aware, in our case, it's just a yearly pricing arrangement with no additional licensing costs."
"The price of FortiGate is average and I would say that based on the top five products available on the market, it is in the affordable range."
"It's an expensive solution."
"The price of FortiGate is reasonable as I plan to buy new switches. The initial gadgets are already booted, and the pricing seems normal on the market. As for additional costs, I haven't subscribed to many extra features, so I'm only using what I need. Last year, I renewed the support for three years, which can sometimes be expensive but depends on the security benefits and how it helps us."
"The solution’s cost is a little high compared to other products."
"The cost of Palo Alto Network NG Firewalls is significantly higher compared to Huawei."
"Palo Alto Networks NG Firewalls are expensive compared to other solutions."
"The product is expensive compared to competing products but uses a similar type of pricing model based on hardware, software and maintenance."
"It can be quite expensive, but there's a good incentive for the three-year contracts. The part that is especially confusing is for the virtual environment. The credits or the licensing system can be very confusing."
"Palo Alto Networks NG Firewalls are the Cadillac standard, and you do pay Cadillac pricing. However, the protection is worth the steep price."
"We were very happy when they released the PA-440s. Previously, we had been looking at the PA-820s, which were a bit of overkill for us. Price-wise and capability-wise, the PA-820s hit the nail on the head for us."
"Paul Alto is the most expensive solution in this category."
"I rate the product price as one on a scale of one to ten, where one is low price and ten is high price."
"It costs about 8 to 10 thousand dollars per year for 500 users, standard licensing fees included."
"The price falls in the mid-range, neither exceptionally low nor high."
"The license of Sangfor NGAF can be purchased at different interval lengths, such as annually or three years. They offer a range of packages to choose from, such as combo or hybrid packages. We are using the complete solution package which includes IM, NGF and SSL VPN, and WAF."
"We purchased one year technical support and return to factory support, and we also purchased one-year technical support services. So those were additional."
"In my opinion, the price of the tool is good in the Pakistani market. We can easily get discounts if needed."
"The solution has a TCO that is 32% to 50% less than Sophos, Fortinet, and SonicWall."
"If one is very cheap and ten is very expensive, I rate the tool's price as three out of ten."
report
Use our free recommendation engine to learn which Firewalls solutions are best for your needs.
902,270 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Comms Service Provider
10%
Computer Software Company
9%
Manufacturing Company
9%
Financial Services Firm
7%
Manufacturing Company
10%
Computer Software Company
9%
Financial Services Firm
9%
Comms Service Provider
6%
Financial Services Firm
10%
Manufacturing Company
10%
Comms Service Provider
10%
Construction Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business369
Midsize Enterprise139
Large Enterprise195
By reviewers
Company SizeCount
Small Business77
Midsize Enterprise57
Large Enterprise87
By reviewers
Company SizeCount
Small Business15
Midsize Enterprise10
Large Enterprise10
 

Questions from the Community

Which is the better NGFW: Fortinet Fortigate or Cisco Firepower?
When you compare these firewalls you can identify them with different features, advantages, practices and usage a...
What is the biggest difference between Sophos XG and FortiGate?
From my experience regarding both the Sophos and FortiGate firewalls, I personally would rather use FortiGate. I know...
What are the biggest technical differences between Sophos UTM and Fortinet FortiGate?
As a solution, Sophos UTM offers a lot of functionality, it scales well, and the stability and performance are quite ...
What is a better choice, Azure Firewall or Palo Alto Networks NG Firewalls?
Azure Firewall Vs. Palo Alto Network NG Firewalls Both solutions provide stellar stability and security. Azure Firew...
Features comparison between Palo Alto and Fortinet firewalls
In the best tradition of these questions, Feature-wise both are quite similar, but each has things it's better at, it...
Which is better - Palo Alto Networks NG Firewalls or Sophos XG?
Palo Alto Networks NG Firewalls have both great features and performance. I like that Palo Alto has regular threat si...
What is your experience regarding pricing and costs for Sangfor NGAF?
The licensing cost is quite high compared to other available firewalls in the market.
What needs improvement with Sangfor NGAF?
The cost of licensing is very high compared to other firewalls available here. There should be improvements in hardwa...
What is your primary use case for Sangfor NGAF?
We are hosting applications over the platform, including websites and NAT traffic from our side. Because it's deploye...
 

Also Known As

Fortinet FortiGate Next-Generation Firewall
Palo Alto NGFW, Palo Alto Networks Next-Generation Firewall
Sangfor NGAF Firewall Platform
 

Overview

 

Sample Customers

Amazon Web Services, Microsoft, IBM, Cisco, Dell, HP, Oracle, Verizon, AT&T, T-Mobile, Sprint, Vodafone, Orange, BT Group, Telstra, Deutsche Telekom, Comcast, Time Warner Cable, CenturyLink, NTT Communications, Tata Communications, SoftBank, China Mobile, Singtel, Telus, Rogers Communications, Bell Canada, Telkom Indonesia, Telkom South Africa, Telmex, Telia Company, Telkom Kenya
SkiStar AB, Ada County, Global IT Services PSF, Southern Cross Hospitals, Verge Health, University of Portsmouth, Austrian Airlines, The Heinz Endowments
The Ministry of Science, Technology, and Innovation (Indonesia), Lawson, Inc. (Philippines), Universiti Sultan Zainal Abidin (Indonesia), TEK Automotive (Italy), etc.
Find out what your peers are saying about Palo Alto Networks NG Firewalls vs. Sangfor NGAF and other solutions. Updated: June 2026.
902,270 professionals have used our research since 2012.