Try our new research platform with insights from 80,000+ expert users

Sangfor NGAF vs Sophos XG comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Apr 6, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Fortinet FortiGate
Sponsored
Ranking in Firewalls
2nd
Average Rating
8.4
Reviews Sentiment
7.2
Number of Reviews
357
Ranking in other categories
Software Defined WAN (SD-WAN) Solutions (1st), WAN Edge (1st)
Sangfor NGAF
Ranking in Firewalls
19th
Average Rating
8.0
Reviews Sentiment
6.5
Number of Reviews
34
Ranking in other categories
No ranking in other categories
Sophos XG
Ranking in Firewalls
4th
Average Rating
8.2
Reviews Sentiment
7.1
Number of Reviews
214
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of June 2025, in the Firewalls category, the mindshare of Fortinet FortiGate is 21.4%, up from 17.8% compared to the previous year. The mindshare of Sangfor NGAF is 1.3%, up from 0.9% compared to the previous year. The mindshare of Sophos XG is 11.3%, up from 9.3% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Firewalls
 

Featured Reviews

Jorge Martínez - PeerSpot reviewer
Offers good SD-WAN capabilities and integrates easily with Fortinet devices
I am not part of the initial setup or deployment process since I work in presales. The setup or deployment is quite easy, as you can do a one-touch deployment that automatically connects to the FortiManager cloud when you connect it to a broadband or dynamic IP, allowing you to start the configuration from that point. We usually sell it for on-premises setups. It's on the cloud only when the client has virtual machines or their own service. Sometimes they have a service on the cloud like AWS, but it's more difficult to sell now because AWS has an e-commerce option where you can buy FortiGate directly. The only thing you need is someone to manage and configure.
Zaid Farooqui - PeerSpot reviewer
Enhanced threat detection with integrated security features and good support
We are using application firewalling, WAF, and SD-WAN. The capabilities are mostly within the box. For example, you will get web application firewall WAF as part and parcel of this. SD-WAN is also bundled. It integrates with their SIEM and SOAR solutions very nicely. Lastly, the pricing point is very cost-efficient as well.
TarunPanchal - PeerSpot reviewer
Decades of expertise lead to seamless installations and robust security
I typically use the Sophos XG Firewall to enhance my cybersecurity by using all layers. The intrusion prevention system impacts my security posture effectively, as we have not faced any ransomware or cyber threats. I have more than 800 servers live from Sophos. The synchronized security feature has proven to be very beneficial, and I have not encountered any issues. Sophos XG Firewall has contributed to reducing overall costs because it helps save money. We purchased endpoint security for the first time last year, and even without endpoint security, it provides comprehensive security. Sophos XG uses AI effectively to enhance threat detection and response, securing from AI at the packet level.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Fortinet FortiGate is easy to use. Anyone can easily maintain it."
"The solution has very good threat and content filtering switches."
"Fortinet FortiGate is among the best options in the market."
"It's super reliable. I don't think I've ever had a reliability issue with it."
"It's very similar to a Cisco firewall, yet less expensive."
"The integration with Active Directory is one of the good features. Most of the customers are now looking for the Single Sign-on feature. So, being able to integrate Active Directory with the firewall is useful. It is also easy."
"The application control features, such as Facebook blocking and Spotify blocking, are the most valuable."
"The combined license for the network, the next-generation firewall, and the integration with SD-WAN for all branches are what I consider to be the best features. It's effective for multi-branch customers."
"It is a stable solution."
"In four steps one can configure the entire firewall."
"You might try Sangfor if you are on a tight budget. The price is affordable, and Sangfor offers a lot of features. We don't have any complaints about Sangfor."
"The most valuable features are the WAN optimization, the internet access gateway (IAG), and the central console, which allows us to implement on their firewall."
"Sangfor NGAF's standout feature is its powerful application control, enabling precise restrictions on mobile user access to approved applications."
"Sangfor NGAF specializes in ransomware detection and helps to protect our network from ransomware threats and malware."
"We've found the technical support to be helpful."
"I think the tool has the feature to detect and kill ransomware in three seconds."
"It is a scalable solution."
"It's a product that is in continuous improvement and is following what the customer is asking for. They are taking inputs and designing new releases specifically according to the client and their needs."
"I like the fact that it can self remove malware and do updates on the cloud via Sophos Central."
"In my experience, the solution was easy to use, has lots of features, and is easy to configure."
"The most valuable feature of this solution is flexibility."
"I would recommend Sophos XG due to its good value for money, despite its integration issues."
"The solution is easy to set up and configure."
"It has a very friendly interface like the Cyberoam iNG units, it has customizable policies, it has proper templates that you can even modify, and you can customize the rules, down to each single user."
 

Cons

"Some configuration elements cannot be easily altered once created."
"Some of the web policy reports could be improved."
"There were quite a few problems with the stability of the system."
"Fortinet FortiGate could improve by having better visibility. Palo Alto has better visibility."
"Currently, FortiGate is providing SSL VPN. But they're missing some features that are available in Palo Alto's SSL VPN."
"The platform's compatibility with Wi-Fi equipment needs improvement."
"FortiGate support could do some improvements on their IPv6 configuration. Right now it's still in the very early stage for utilizing in an enterprise level network environment."
"Its price could be better."
"The solution should be able to work in a hybrid setup."
"The reporting and log management could be improved."
"It has an issue with the Sangfor Cloud Platform rather than the firewall. When we run a virtual machine, the window tabs display Chinese characters."
"An area for improvement would be the number of ports defined on the box. In the next release, I would like them to develop their provisioning stage of enrolling end devices."
"It does not offer any recommendations on how to mitigate or control attacks."
"The setup phase is quite complex."
"The cost of licensing is very high compared to other firewalls available here."
"The GUI needs to be improved, lacks logic in some areas."
"The pricing has gotten much higher."
"The user interface could be improved and more bandwidth management would be helpful."
"Sophos XG's user interface has some room for improvement."
"Let's say I set up a rule to block users from accessing YouTube or Facebook. The rule will only block the HTTP traffic, which is non-secure traffic... The problem comes when you are trying to block, or allow, similar traffic that uses HTTPS. You have to create a certificate and import it into the users' web browsers, whatever they are using... The problem occurs when you're dealing with roaming users who use laptops and have to move between different sites that have different types of policies applied to them. You have to import all sorts of certificates from each site into their browser. Doing so will most probably conflict with something else that is totally irrelevant and cause a problem."
"It could offer a DNS Filter for blocking botnet networks."
"Sophos XG could improve by being more stable and for it to be able to be used for large enterprises."
"The solution is tied to the US dollar. You need to pay whatever the equivalent is in your own currency, and, if the exchange is bad, it can really add to the cost."
"The GUI and support could be better. I think there are other products that we are going to deploy instead of Sophos. We have already upgraded a month ago because the interfaces and support for Sophos are really weak. But other products like Juniper, Cisco, or FortiGate are better than Sophos. It's also complicated, and the end-user or client does not understand it."
 

Pricing and Cost Advice

"Fortinet is reasonable in pricing and licensing. Overall, FortiGate is affordable. The licensing fee can be a little high, depending on the budget for your project."
"Its pricing is competitive with other solutions."
"I think the price of Fortinet FortiGate is very reasonable."
"Fortinet FortiGate is cost-efficient. Palo Alto is expensive, but Fortinet FortiGate is not."
"Pricing is good. They offer a lot of things, the most important is the support. Every time you upgrade your license, you also get insurance for the equipment. If you have any problem with equipment, they send in new equipment."
"As far as I'm aware, in our case, it's just a yearly pricing arrangement with no additional licensing costs."
"We pay for the solution annually."
"Fortinet FortiGate gives you most of the features in one license."
"The license of Sangfor NGAF can be purchased at different interval lengths, such as annually or three years. They offer a range of packages to choose from, such as combo or hybrid packages. We are using the complete solution package which includes IM, NGF and SSL VPN, and WAF."
"The solution has a TCO that is 32% to 50% less than Sophos, Fortinet, and SonicWall."
"Sangfor NGAF price is reasonable and there is an annual license. However, the maintenance cost can be a bit high."
"The product is very cost-effective compared to other brands or vendors."
"I rate the product price as one on a scale of one to ten, where one is low price and ten is high price."
"The price is unmatcheable."
"For four to five physical appliances for a licensed firewall, it costs approximately $4,000."
"It is one of the cheapest tools in the market."
"The price of Sophos in PTR is significantly higher compared to Fortinet."
"There is no need to get one edition, just the licensing, as we are talking about a common bundle which encompasses all the features."
"We are paying about $1,500 yearly for the Enterprise Plus. As far as I know, there aren't costs above this standard fee."
"Its price is fair. It is cheaper and way better than others."
"For our company, the price was reasonable."
"For every firewall, you will need to pay the license for the following year. If they don't pay for the license renewal, they basically won't get the support from Sophos."
"The price is reasonable"
"The pricing is economical."
report
Use our free recommendation engine to learn which Firewalls solutions are best for your needs.
856,873 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Educational Organization
15%
Computer Software Company
15%
Comms Service Provider
8%
Manufacturing Company
6%
Computer Software Company
12%
Manufacturing Company
10%
Financial Services Firm
9%
Educational Organization
7%
Computer Software Company
16%
Comms Service Provider
9%
Manufacturing Company
7%
Financial Services Firm
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

Which is the better NGFW: Fortinet Fortigate or Cisco Firepower?
When you compare these firewalls you can identify them with different features, advantages, practices and usage a...
What is the biggest difference between Sophos XG and FortiGate?
From my experience regarding both the Sophos and FortiGate firewalls, I personally would rather use FortiGate. I know...
What are the biggest technical differences between Sophos UTM and Fortinet FortiGate?
As a solution, Sophos UTM offers a lot of functionality, it scales well, and the stability and performance are quite ...
What do you like most about Sangfor NGAF?
I think Sangfor NGAF is more valuable than Cisco products because of its simplicity and ease of management. If I comp...
What is your experience regarding pricing and costs for Sangfor NGAF?
The licensing cost is quite high compared to other available firewalls in the market.
What needs improvement with Sangfor NGAF?
The cost of licensing is very high compared to other firewalls available here. There should be improvements in hardwa...
Which is better - Palo Alto Networks NG Firewalls or Sophos XG?
Palo Alto Networks NG Firewalls have both great features and performance. I like that Palo Alto has regular threat si...
What are the main differences in features between Sophos XG and FortiGate 80F?
Hi Arvind P , The Sophos XG firewall has a number of models right from XG86 to XG135w under the 1U Desktop Form Fact...
 

Also Known As

FortiGate 60b, FortiGate 60c, FortiGate 80c, FortiGate 50b, FortiGate 200b, FortiGate 110c, FortiGate, Fortinet Firewall
Sangfor NGAF Firewall Platform
No data available
 

Overview

 

Sample Customers

Amazon Web Services, Microsoft, IBM, Cisco, Dell, HP, Oracle, Verizon, AT&T, T-Mobile, Sprint, Vodafone, Orange, BT Group, Telstra, Deutsche Telekom, Comcast, Time Warner Cable, CenturyLink, NTT Communications, Tata Communications, SoftBank, China Mobile, Singtel, Telus, Rogers Communications, Bell Canada, Telkom Indonesia, Telkom South Africa, Telmex, Telia Company, Telkom Kenya
The Ministry of Science, Technology, and Innovation (Indonesia), Lawson, Inc. (Philippines), Universiti Sultan Zainal Abidin (Indonesia), TEK Automotive (Italy), etc.
Information Not Available
Find out what your peers are saying about Sangfor NGAF vs. Sophos XG and other solutions. Updated: June 2025.
856,873 professionals have used our research since 2012.