Try our new research platform with insights from 80,000+ expert users

Palo Alto Networks PA-Series vs Sangfor NGAF comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Apr 6, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Fortinet FortiGate
Sponsored
Ranking in Firewalls
2nd
Average Rating
8.4
Reviews Sentiment
7.2
Number of Reviews
330
Ranking in other categories
Software Defined WAN (SD-WAN) Solutions (1st), WAN Edge (1st)
Palo Alto Networks PA-Series
Ranking in Firewalls
15th
Average Rating
8.6
Reviews Sentiment
7.3
Number of Reviews
32
Ranking in other categories
No ranking in other categories
Sangfor NGAF
Ranking in Firewalls
19th
Average Rating
8.0
Reviews Sentiment
6.5
Number of Reviews
36
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of May 2025, in the Firewalls category, the mindshare of Fortinet FortiGate is 21.4%, up from 17.7% compared to the previous year. The mindshare of Palo Alto Networks PA-Series is 0.5%, up from 0.1% compared to the previous year. The mindshare of Sangfor NGAF is 1.3%, up from 0.9% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Firewalls
 

Featured Reviews

EhabAli - PeerSpot reviewer
Efficient, user-friendly, and affordable
In the past, NSS Labs was utilized to test files and verify the numbers and datasheets. It would be beneficial to have an organization or testing lab that can verify the numbers in our datasheets since changes are frequently made, which can be inconvenient for review. For instance, when comparing different competitors such as Forcepoint, Palo Alto, and Check Point, the throughput or numbers in the datasheet may be lower than the actual numbers. Conversely, Fortinet typically reports very high numbers, but they cannot be replicated in the real world. Therefore, it would be advantageous for them to partner with a neutral testing organization such as NSS Labs to validate these numbers, thus providing more credibility and comfort to everyone regarding the accuracy of the datasheets. For the migration, everyone has a firewall in use and I am selling Fortinet. Typically, I am replacing another firewall. Previously, there was a tool available to convert configurations from one firewall, such as Palo Alto, to Fortinet, but this tool is no longer free. If it could be made free again, it would be very beneficial. This tool shows a lot of promise and is very good. Making it free would help many companies deliver their products in a more efficient and integrated way. It would also be more valuable to include the tool with the firewall package or license instead of having to pay extra for it. Paying extra puts more pressure on small companies to deliver the firewall and complete the configuration, especially if they have hundreds or thousands of policies. It's very painful to move through these policies line by line. The stability has room for improvement. When it comes to Secure SD-WAN, everything is fine. They are going the right way. SD-WAN is very promising. They can provide the SD-WAN solution separately, but they will not take this approach because even the smallest firewall can support the features, so there is no need to have a separate service or appliance. They are following the right steps, and there is nothing to be improved. Feature-wise, I'm really satisfied with the new release, and the features they have added. For now, it's fine.
Deminda Dilan - PeerSpot reviewer
Good for enterprise-level businesses and offers many features like URL filtering and antivirus capabilities
Palo Alto can improve the web application firewall (WAF) feature at layer 7. Currently, I don't think it's available. If they can improve that, it would be better. We wouldn't need to purchase a separate WAF solution because they already have advanced URL filtering. But I don't think that advanced URL filtering has the same features as a dedicated WAF, like F5 or other solutions. That is an area for improvement. If they can improve the WAF feature, customers won't have to buy a separate WAF solution. They could do it with the same Palo Alto firewall, perhaps through a subscription-based model. So the web application firewall feature has to be improved.
Zaid Farooqui - PeerSpot reviewer
Enhanced threat detection with integrated security features and good support
We are using application firewalling, WAF, and SD-WAN. The capabilities are mostly within the box. For example, you will get web application firewall WAF as part and parcel of this. SD-WAN is also bundled. It integrates with their SIEM and SOAR solutions very nicely. Lastly, the pricing point is very cost-efficient as well.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The features that I have found most valuable are the SD-WAN and their IP4 policy."
"The solution provides good threat intelligence feeds."
"Reliability is the best feature. We faced some issues when we were setting it up, but the service, portal, and administration are good."
"There are great templates, so you don't have to customize them if you don't want to. You do have the option to custom create some folders and some reports, however, with what is there, you don't really need to go through extra effort, as they already give you a lot of predefined views of reports and so forth."
"The solution is very user friendly. The user interface in particular is quite nice."
"The stability of the solution is excellent, as it is with other Fortinet products."
"The main benefit is the grouping of our security monitoring."
"One of the nice things about FortiGate is that it can be deployed on the cloud or on-premises. You can actually do both. That's the biggest reason why I stick with this solution as opposed to something like Cisco Meraki. Another nice thing is that I can log directly into a FortiGate or get to it through their FortiCloud access products. They're pretty reliable and consistent. One of the reasons why I started using the product was their single pane of management. I can deploy their line of firewalls in conjunction with their switching and access points, and I can manage the entire network from one interface. I don't have to log into one interface for the firewall, another one for the access points, and another one for the switches. These firewalls have access point controller functionality built right into the system, so I don't even have to purchase additional devices to manage them."
"The product's most valuable feature is web filtering."
"It is a scalable solution."
"It functions very well in data centers."
"It offers a seamless transition from one option to another, making it exceptionally versatile and user-friendly in an enterprise setting."
"Palo Alto blocks the new threats better than other tools."
"It is a stable solution. Stability-wise, I rate the solution a ten out of ten."
"The product's initial setup process was simple."
"A valuable feature that we can consider is the deployment time, which is significantly reduced. It is almost 90% faster compared to other solutions."
"It seems to be a durable, stable product."
"Sangfor NGAF works accordingly with our customers. The solution has good performance, easy to use, and integrates well with the endpoints."
"I think the tool has the feature to detect and kill ransomware in three seconds."
"The product is very fast and reliable."
"The VPN connectivity feature is really nice."
"It's a very simple to use product."
"Sangfor has the best capabilities for securing connections, securing web browsers, securing servers, and general threat protection."
"It enables us to not only detect but also prevent various types of incoming threats, allowing us to take appropriate corrective actions and exercise control over the network."
 

Cons

"The logs need to be better. They need to be more visible and easier to access."
"The pricing could be reduced or include the first year warranty."
"It claims it does DLP, but the degree and level of controls are very basic."
"I prefer Palo Alto over Fortinet FortiGate. Its IPS engine is not better than the Palo Alto version. The monitoring tool needs improvement, and the syslog configuration needs enhancement."
"Some features of Fortinet FortiGate are actually fee enabled that are inconvenient for deploying in production. Other issues relate to isolation with Cisco products and your server."
"Difficult to add or define, and not that easy to configure and manage."
"I would suggest that Fortinet add sandboxing to their solution."
"I think the only issue that needs improvement is the interface."
"I encountered a slight issue with the application portal, which was not functioning correctly."
"In future releases, maybe Palo Alto can enhance and enlarge their portfolio with SIEM solutions. They already have an endpoint protection solution, SOAR solution, that's fine. But when it comes to standalone IDS/IPS solution or email security solution, for example, we don't have any product in that category for Palo Alto."
"The product's gateway services can be improved."
"Palo Alto should integrate artificial intelligence for security purposes in the background for well-known threats and new risks coming to the market."
"The support has been shaky. Initially, it took one or two hours to get a Palo Alto engineer, which is quite slow. I expect faster response times."
"I experienced some problems with AWS cloud parameters connected to Palo Alto firewall."
"Currently, they are not protected with any data security when they work from home or outside the network. They surf the Internet directly and should implement a proxy or firewall to monitor the data between the endpoint and the internet."
"Palo Alto Networks PA-Series is complicated to configure compared to one of its competitors."
"The cost of licensing is very high compared to other firewalls available here. There should be improvements in hardware scalability, allowing for more storage and memory capacity."
"It has an issue with the Sangfor Cloud Platform rather than the firewall. When we run a virtual machine, the window tabs display Chinese characters."
"The cost of licensing is very high compared to other firewalls available here."
"They need to increase the number of ports in the firewall."
"Sangfor NGAF could improve by refining its application control policies, especially in addressing challenges with certain types of applications."
"The GUI needs to be improved, lacks logic in some areas."
"I feel Sangfor should follow the hierarchy and close deals via resellers instead of closing it all with their own team."
"The solution should be able to work in a hybrid setup."
 

Pricing and Cost Advice

"Its price could be better."
"​We saved a bundle by not needing all the past appliances from an NGFW.​"
"The pricing depends on the FortiGate model we are using, ranging from $3,000 to $20,000 US dollars."
"Licensing is usually on a three-year period."
"If you compare Fortinet FortiGate with Sophos and other firewall products available in the market, this solution is affordable."
"It's a very full-featured and it's priced well solution."
"The value is the capability of having multiple services with one unique license, not having the limitation per user licensing schema, like other vendors."
"The cost is too high... They have to focus on more features with less cost for the customer. If you see the market, where it's going, there are a lot of players offering more features for less cost."
"The pricing is fair."
"From my perspective, managing the price is important, especially because we're a small business. For larger organizations like Barclays, we provide our requirements to the client, and they place the order on BigFix. It's their responsibility to consider their budget and make decisions accordingly. We appreciate the features we get, but the cost-sharing still depends on the client."
"The cost varies depending on the device model, with entry-level firewalls priced around $1,300 to $1,500, while higher-end models can reach prices of several hundred thousand dollars."
"The product is offered to users at high prices compared to the pricing model of the other vendors in the market."
"With Palo Alto, even when you enable all the modules, it still provides the exact throughput they advertise."
"The tool's pricing was reasonable when we bought the product. We pay around 60,000 dollars per year."
"Palo Alto’s pricing is way higher than any other solution provider."
"Palo Alto Networks PA-Series's price is much higher than other firewall brands."
"The product is very cost-effective compared to other brands or vendors."
"I rate the product price as one on a scale of one to ten, where one is low price and ten is high price."
"It costs about 8 to 10 thousand dollars per year for 500 users, standard licensing fees included."
"Sangfor NGAF price is reasonable and there is an annual license. However, the maintenance cost can be a bit high."
"For over 2000 users, the cost is around 5000 to 6000 USD. If you want a web application firewall, you have to purchase an additional license for it."
"For four to five physical appliances for a licensed firewall, it costs approximately $4,000."
"The price is unmatcheable."
"The pricing is reasonable."
report
Use our free recommendation engine to learn which Firewalls solutions are best for your needs.
849,686 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Educational Organization
20%
Computer Software Company
14%
Comms Service Provider
7%
Manufacturing Company
6%
Computer Software Company
17%
Manufacturing Company
13%
University
8%
Comms Service Provider
8%
Computer Software Company
13%
Manufacturing Company
10%
Financial Services Firm
9%
Educational Organization
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

Which is the better NGFW: Fortinet Fortigate or Cisco Firepower?
When you compare these firewalls you can identify them with different features, advantages, practices and usage a...
What is the biggest difference between Sophos XG and FortiGate?
From my experience regarding both the Sophos and FortiGate firewalls, I personally would rather use FortiGate. I know...
What are the biggest technical differences between Sophos UTM and Fortinet FortiGate?
As a solution, Sophos UTM offers a lot of functionality, it scales well, and the stability and performance are quite ...
What do you like most about Palo Alto Networks PA-Series?
The reporting feature and application ID functionality within Palo Alto Networks PA-Series are incredibly valuable to...
What needs improvement with Palo Alto Networks PA-Series?
The interface of Palo Alto Networks PA-Series should be made much more user-friendly.
What do you like most about Sangfor NGAF?
I think Sangfor NGAF is more valuable than Cisco products because of its simplicity and ease of management. If I comp...
What is your experience regarding pricing and costs for Sangfor NGAF?
The licensing cost is quite high compared to other available firewalls in the market.
What needs improvement with Sangfor NGAF?
The cost of licensing is very high compared to other firewalls available here. There should be improvements in hardwa...
 

Also Known As

FortiGate 60b, FortiGate 60c, FortiGate 80c, FortiGate 50b, FortiGate 200b, FortiGate 110c, FortiGate, Fortinet Firewall
No data available
Sangfor NGAF Firewall Platform
 

Overview

 

Sample Customers

Amazon Web Services, Microsoft, IBM, Cisco, Dell, HP, Oracle, Verizon, AT&T, T-Mobile, Sprint, Vodafone, Orange, BT Group, Telstra, Deutsche Telekom, Comcast, Time Warner Cable, CenturyLink, NTT Communications, Tata Communications, SoftBank, China Mobile, Singtel, Telus, Rogers Communications, Bell Canada, Telkom Indonesia, Telkom South Africa, Telmex, Telia Company, Telkom Kenya
Information Not Available
The Ministry of Science, Technology, and Innovation (Indonesia), Lawson, Inc. (Philippines), Universiti Sultan Zainal Abidin (Indonesia), TEK Automotive (Italy), etc.
Find out what your peers are saying about Palo Alto Networks PA-Series vs. Sangfor NGAF and other solutions. Updated: April 2025.
849,686 professionals have used our research since 2012.