Try our new research platform with insights from 80,000+ expert users

Sangfor NGAF vs Sophos XG comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Apr 6, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Fortinet FortiGate
Sponsored
Ranking in Firewalls
2nd
Average Rating
8.4
Reviews Sentiment
7.2
Number of Reviews
330
Ranking in other categories
Software Defined WAN (SD-WAN) Solutions (1st), WAN Edge (1st)
Sangfor NGAF
Ranking in Firewalls
19th
Average Rating
8.0
Reviews Sentiment
6.5
Number of Reviews
36
Ranking in other categories
No ranking in other categories
Sophos XG
Ranking in Firewalls
4th
Average Rating
8.0
Reviews Sentiment
7.0
Number of Reviews
207
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of May 2025, in the Firewalls category, the mindshare of Fortinet FortiGate is 21.4%, up from 17.7% compared to the previous year. The mindshare of Sangfor NGAF is 1.3%, up from 0.9% compared to the previous year. The mindshare of Sophos XG is 11.5%, up from 9.2% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Firewalls
 

Featured Reviews

EhabAli - PeerSpot reviewer
Efficient, user-friendly, and affordable
In the past, NSS Labs was utilized to test files and verify the numbers and datasheets. It would be beneficial to have an organization or testing lab that can verify the numbers in our datasheets since changes are frequently made, which can be inconvenient for review. For instance, when comparing different competitors such as Forcepoint, Palo Alto, and Check Point, the throughput or numbers in the datasheet may be lower than the actual numbers. Conversely, Fortinet typically reports very high numbers, but they cannot be replicated in the real world. Therefore, it would be advantageous for them to partner with a neutral testing organization such as NSS Labs to validate these numbers, thus providing more credibility and comfort to everyone regarding the accuracy of the datasheets. For the migration, everyone has a firewall in use and I am selling Fortinet. Typically, I am replacing another firewall. Previously, there was a tool available to convert configurations from one firewall, such as Palo Alto, to Fortinet, but this tool is no longer free. If it could be made free again, it would be very beneficial. This tool shows a lot of promise and is very good. Making it free would help many companies deliver their products in a more efficient and integrated way. It would also be more valuable to include the tool with the firewall package or license instead of having to pay extra for it. Paying extra puts more pressure on small companies to deliver the firewall and complete the configuration, especially if they have hundreds or thousands of policies. It's very painful to move through these policies line by line. The stability has room for improvement. When it comes to Secure SD-WAN, everything is fine. They are going the right way. SD-WAN is very promising. They can provide the SD-WAN solution separately, but they will not take this approach because even the smallest firewall can support the features, so there is no need to have a separate service or appliance. They are following the right steps, and there is nothing to be improved. Feature-wise, I'm really satisfied with the new release, and the features they have added. For now, it's fine.
Zaid Farooqui - PeerSpot reviewer
Enhanced threat detection with integrated security features and good support
We are using application firewalling, WAF, and SD-WAN. The capabilities are mostly within the box. For example, you will get web application firewall WAF as part and parcel of this. SD-WAN is also bundled. It integrates with their SIEM and SOAR solutions very nicely. Lastly, the pricing point is very cost-efficient as well.
Mohamad Charara - PeerSpot reviewer
Security features improve protection while integration and resource management require enhancements
Sophos XG ( /products/sophos-xg-reviews ) is not easy to navigate and to use, and the integration capabilities are lacking. It cannot integrate properly with solutions like Darktrace ( /products/darktrace-reviews ). The VPN client on mobiles, especially Android phones, has issues. It is resource-greedy, causing performance problems even on new computers. Improvements are needed in resource management and integration with other security solutions.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The SD-WAN feature of Fortinet FortiGate has been most impactful in maintaining our network's integrity."
"The most valuable feature is the policy routing and application control."
"The Fortinet FortiGate local partners were good. I did not have direct contact with Fortinet support."
"We use the filtering feature the most. It has filtering and inbuilt securities. We can create customized rules to define which users can access a particular type of site. We can create policies inside the firewall."
"The SD-WAN feature of Fortinet FortiGate has been most impactful in maintaining our network's integrity."
"The features that I have found most valuable are that it is good to use, and most importantly, the pricing. The customer especially likes the discount when they trade up or something like that."
"I'm looking forward to FortiGate's dashboard features, insights, application oversight, and monitoring, which could help us significantly."
"The most useful functionality of Fortinet FortiGate is the user interface, multiple engines, and their cloud with the latest integrations. Additionally, the Security Fabric tool is very good."
"Sangfor NGAF specializes in ransomware detection and helps to protect our network from ransomware threats and malware."
"It seems to be a durable, stable product."
"Sangfor is a good solution that provides a WAF and firewall solution. Most other vendors, like Sophos and Fortinet and Cisco, only provide one solution. That's a valuable feature of Sangfor."
"In terms of the most valuable features, the IPS report is quick and updated. Performance is also valuable."
"Particularly good in the DPI where we can inspect inbound and outbound traffic."
"The capabilities are mostly within the box."
"We can utilize our own network rather than paying for a private one."
"The top functionality is the reporting feature."
"I particularly like the visibility it provides into network traffic, allowing us to identify and address issues efficiently."
"The firewall feature of Sophos XG has been the most effective for threat prevention."
"IPS works smoothly."
"This is a very stable solution."
"Sophos is easy to use."
"In terms of the functionality, I think it's pretty straightforward. It's easy to pick up. It's also user-friendly."
"The performance of Sophos XG is generally good and it is stable."
"The valuable features of this solution are the VPN, load balancer, and the QoS for splitting the ISP band."
 

Cons

"It could use better throughput on some of the smaller boxes for the branch offices."
"Its reporting and pricing need improvement."
"I don't really have anything negative to say as far as Fortinet firewalls are concerned. If anything, they can support a user a little bit better. They can stop being so time-sensitive about how much time the support call has taken, and they can help you do it yourself."
"I would like to see a more intuitive dashboard."
"They can do more tests before they release new versions because I would like to be more assured. We had some experiences where they release something new and great, but some of the old features are disabled or they don't work well, which impacts the product satisfaction. The manufacturer should be able to prove that everything works or not only that it might work. This is applicable to most of the other services, software, and hardware companies. They all should work on this. We cannot trust every new release, such as a beta release, on the first day. We wait for some comments on the forums and from other companies that we know. We always wait a few weeks before we use the updated version. They should also extend the VPN client application, especially for Linux versions. Currently, it has an application for Linux devices, but it doesn't work the way we want to connect to the VPN. They use only the old connection, not the new one. They have VPN client applications for Windows and Mac, but they can add more useful features to better manage the devices and monitor the current health of each device. Such features would be helpful for our company."
"The solution could be more secure and stable."
"The solution lacks multi-language support."
"Some of the features in the graphical user interface do not work, which requires that we used the command-line-interface."
"Sangfor has recently increased their prices."
"The firewall system needs gradual improvements because there are more threats and challenges every day."
"I feel Sangfor should follow the hierarchy and close deals via resellers instead of closing it all with their own team."
"The cost of licensing is very high compared to other firewalls available here. There should be improvements in hardware scalability, allowing for more storage and memory capacity."
"The tool's support is an area of concern where improvements are required."
"The tool is expensive."
"The solution should be able to work in a hybrid setup."
"The GUI needs to be improved, lacks logic in some areas."
"Support could be improved."
"I would like to have remote access to clients using a static IP for a certain period of time."
"They should expand their DDoS feature. It's basic. They need to enhance it."
"We are facing some problems on this firmware version, version 18, that require improvement. We want to improve the email security because it doesn't give proper security with the data protection. Also, our clients are facing some problems where most of the sites which they're accessing are getting blocked. I want to improve those sites, that email security, and the data protection on the Firmware version 18."
"Network security is in need of improvement."
"The cloud support needs to be improved."
"It could offer a DNS Filter for blocking botnet networks."
"I would like to have a more efficient login process."
 

Pricing and Cost Advice

"Work through partners for the best pricing."
"Fortinet FortiGate is expensive."
"As far as I'm aware, in our case, it's just a yearly pricing arrangement with no additional licensing costs."
"We purchased a five-year bundle package, which worked out cheaper than competing solutions."
"It has a competitive price."
"Its pricing is good. The advantages of Fortinet FortiGate over its competitors include good pricing and meeting our requirements at a lower cost."
"Fortinet FortiGate is cheaper than Palo Alto. It is about 20% cheaper."
"I would rate the pricing a five out of ten"
"Price-wise, I would not consider Sangfor NGAF to be a cheap product. It is an expensive firewall solution, though not as expensive as something like Palo Alto, which is costly. However, the higher price point is justifiable given the feature set the tool provides that other firewalls may not offer in a single dedicated appliance."
"-"
"The product is very cost-effective compared to other brands or vendors."
"The price falls in the mid-range, neither exceptionally low nor high."
"Sangfor is cheaper than competing vendors."
"For four to five physical appliances for a licensed firewall, it costs approximately $4,000."
"The solution has a TCO that is 32% to 50% less than Sophos, Fortinet, and SonicWall."
"It is one of the cheapest tools in the market."
"On a scale from one to ten, where one is cheap and ten is expensive, I rate the solution's pricing a seven out of ten."
"For every firewall, you will need to pay the license for the following year. If they don't pay for the license renewal, they basically won't get the support from Sophos."
"The price is cheaper than that of some competing vendors."
"Support costs are approximately 50 percent."
"The licensing for Sophos XG is based on the number of users, so I get the module from the sizing of the customer."
"Its licensing cost is around 700 bucks a year or something like that. It is 100 bucks a month at the most. It seems to be standard licensing with no additional costs."
"The solution is priced well."
"The price is fair."
report
Use our free recommendation engine to learn which Firewalls solutions are best for your needs.
849,686 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Educational Organization
21%
Computer Software Company
14%
Comms Service Provider
7%
Manufacturing Company
6%
Computer Software Company
13%
Manufacturing Company
10%
Financial Services Firm
9%
Educational Organization
6%
Computer Software Company
16%
Comms Service Provider
9%
Manufacturing Company
7%
Financial Services Firm
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

Which is the better NGFW: Fortinet Fortigate or Cisco Firepower?
When you compare these firewalls you can identify them with different features, advantages, practices and usage a...
What is the biggest difference between Sophos XG and FortiGate?
From my experience regarding both the Sophos and FortiGate firewalls, I personally would rather use FortiGate. I know...
What are the biggest technical differences between Sophos UTM and Fortinet FortiGate?
As a solution, Sophos UTM offers a lot of functionality, it scales well, and the stability and performance are quite ...
What do you like most about Sangfor NGAF?
I think Sangfor NGAF is more valuable than Cisco products because of its simplicity and ease of management. If I comp...
What is your experience regarding pricing and costs for Sangfor NGAF?
The licensing cost is quite high compared to other available firewalls in the market.
What needs improvement with Sangfor NGAF?
The cost of licensing is very high compared to other firewalls available here. There should be improvements in hardwa...
Which is better - Palo Alto Networks NG Firewalls or Sophos XG?
Palo Alto Networks NG Firewalls have both great features and performance. I like that Palo Alto has regular threat si...
What are the main differences in features between Sophos XG and FortiGate 80F?
Hi Arvind P , The Sophos XG firewall has a number of models right from XG86 to XG135w under the 1U Desktop Form Fact...
 

Also Known As

FortiGate 60b, FortiGate 60c, FortiGate 80c, FortiGate 50b, FortiGate 200b, FortiGate 110c, FortiGate, Fortinet Firewall
Sangfor NGAF Firewall Platform
No data available
 

Overview

 

Sample Customers

Amazon Web Services, Microsoft, IBM, Cisco, Dell, HP, Oracle, Verizon, AT&T, T-Mobile, Sprint, Vodafone, Orange, BT Group, Telstra, Deutsche Telekom, Comcast, Time Warner Cable, CenturyLink, NTT Communications, Tata Communications, SoftBank, China Mobile, Singtel, Telus, Rogers Communications, Bell Canada, Telkom Indonesia, Telkom South Africa, Telmex, Telia Company, Telkom Kenya
The Ministry of Science, Technology, and Innovation (Indonesia), Lawson, Inc. (Philippines), Universiti Sultan Zainal Abidin (Indonesia), TEK Automotive (Italy), etc.
Information Not Available
Find out what your peers are saying about Sangfor NGAF vs. Sophos XG and other solutions. Updated: April 2025.
849,686 professionals have used our research since 2012.