No more typing reviews! Try our Samantha, our new voice AI agent.

Sangfor NGAF vs WatchGuard Firebox comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Feb 15, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Fortinet FortiGate
Sponsored
Ranking in Firewalls
1st
Average Rating
8.4
Reviews Sentiment
6.9
Number of Reviews
592
Ranking in other categories
Secure Web Gateways (SWG) (2nd), Intrusion Detection and Prevention Software (IDPS) (1st), Software Defined WAN (SD-WAN) Solutions (1st), WAN Edge (1st), ZTNA (1st), Unified Threat Management (UTM) (1st)
Sangfor NGAF
Ranking in Firewalls
21st
Average Rating
8.0
Reviews Sentiment
6.5
Number of Reviews
34
Ranking in other categories
No ranking in other categories
WatchGuard Firebox
Ranking in Firewalls
9th
Average Rating
8.4
Reviews Sentiment
6.8
Number of Reviews
139
Ranking in other categories
Data Loss Prevention (DLP) (11th), Intrusion Detection and Prevention Software (IDPS) (4th), Anti-Malware Tools (6th), Endpoint Detection and Response (EDR) (13th), Application Control (3rd), Unified Threat Management (UTM) (3rd)
 

Mindshare comparison

As of June 2026, in the Firewalls category, the mindshare of Fortinet FortiGate is 15.1%, down from 21.7% compared to the previous year. The mindshare of Sangfor NGAF is 1.1%, down from 1.3% compared to the previous year. The mindshare of WatchGuard Firebox is 2.1%, down from 3.0% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Firewalls Mindshare Distribution
ProductMindshare (%)
Fortinet FortiGate15.1%
WatchGuard Firebox2.1%
Sangfor NGAF1.1%
Other81.7%
Firewalls
 

Featured Reviews

JK
IP Network Security Specialist at MTN Ghana
Process-Level CPU Visibility: Introduce detailed CPU-usage metrics per subsystem (e.g., IPS engine, logging) so administrators can quickly identify and address performance spikes.
Analytics with FortiAnalyzer. Being able to pull in logs not just from our FortiGates but from all our other firewalls and then get them in one view has been a game changer. Whether I’m building an executive dashboard or doing a deep dive forensics session, I get everything I need without navigating consoles.Straightforward Application Control. FortiGate spots and blocks unwanted apps (eq. like BitTorrent or streaming services) with accuracy. Segmentation with VDOMs. We’ve carved our data center into four logical ‘mini-firewalls’ enterprise, core, billing, and WAF—all on one box. Each has its own rules and logs, and any traffic between them still gets inspected. It’s like having multiple appliances without the extra hardware. Always-Up-to-Date Threat Feeds. Daily signature updates and AI-driven threat sensing mean we’re blocking the latest vulnerabilities almost as soon as they’re announced.
Zaid Farooqui - PeerSpot reviewer
CIO at Indus Motor Company
Enhanced threat detection with integrated security features and good support
We are using application firewalling, WAF, and SD-WAN. The capabilities are mostly within the box. For example, you will get web application firewall WAF as part and parcel of this. SD-WAN is also bundled. It integrates with their SIEM and SOAR solutions very nicely. Lastly, the pricing point is very cost-efficient as well.
Abhishek Saini - PeerSpot reviewer
Professional Services Engineer at Next7 IT
Centralized security management has improved VPN reliability and simplified daily operations
WatchGuard Firebox is a strong and reliable platform overall, but there are a few areas where improvements could make the experience even better. One area is the user interface and navigation in some management tools. While the platform is powerful, certain configurations and troubleshooting workflows can feel less intuitive compared to some newer cloud-native firewall platforms. Another point is reporting and log analysis. Although the logging features are very useful, deeper analytics and more customizable reporting dashboards would make security monitoring much more effective. Firmware upgrades and policy synchronization can sometimes require careful planning to avoid security interruptions. Overall, the core security and VPN functionality are very solid, but improving usability, reporting, and automation would make the platform even stronger. One area that could be improved is the learning curve for new administrators. While experienced engineers can work with the platform effectively, some advanced networking and security configurations can be a bit complex for junior technicians. More guided configuration workflows, smarter recommendations, and simplified troubleshooting tools would make onboarding easier. Another improvement would be more flexible reporting customization for executive-level and client-facing reports.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The secure web gateway module and the application control module are valuable. HA operations are very easy."
"The solution is easy to implement and easy to configure. The most valuable feature is FortiGate’s content filtering."
"The product is stable and strong."
"It's very easy to configure."
"It works very well. It has a lot of different functionalities. Its cost is also fine for our customers."
"The product has an inbuilt IPS software. We can configure it to block specific anonymous attacks that are happening."
"Allows for firewall rules to be programmed and named in a way that makes it “readable”"
"It offers web filtering capabilities at a more affordable price compared to other solutions like PSMs or NETGEAR."
"The stability of Sangfor NGAF is good."
"Sangfor is a good solution that provides a WAF and firewall solution; most other vendors, like Sophos and Fortinet and Cisco, only provide one solution, and that's a valuable feature of Sangfor."
"The level of support provided to local companies is good. They transform their application control and other settings according to that country."
"I think this solution is a very good example of a proactive solution that can detect problems and immediately fix the problems or issues."
"When it comes to the price of firewall solutions, Sangfor NGAF takes the cake, as it is cheaper than Fortinet, Sophos, Check Point and Palo Alto."
"I think Sangfor NGAF is more valuable than Cisco products because of its simplicity and ease of management. If I compare it with Palo Alto and Cisco, both are quite complex products. And if I compare it with FortiGate firewalls from Fortinet, I have also used all these products. Fortinet and Sangfor NGAF are similar products because the applications behind the application and policy layers are almost identical."
"Sangfor NGAF specializes in ransomware detection and helps to protect our network from ransomware threats and malware."
"The price versus value is good because the solution is less expensive than Sophos, Fortinet, or SonicWall."
"The VPN is very secure and that's of huge importance because we have remote users who depend on it to do their jobs."
"The most valuable feature is the ease of use of the interface."
"The controllability is phenomenal; I can control everything with it, anything coming in or out of my network."
"The technical support has been amazing."
"Some of the most valuable features of the Firebox include web blocking, application control, protection against brute force attacks, load balancing, SD-WAN, and VPN support. These features help us manage and secure our network efficiently."
"The solution simplifies my business. Normally, for administration, we are using NetApp System Manager on Window since it's easy to create new policies. In a short amount of time, you can create new policies based on new requirements. For example, in the last few months, many requirements changed due to the coronavirus, adding the use of new services, like Office 365, and eLearning tools, like Zoom."
"The basic functionality is fantastic. It has been performing well. I generated a report on one machine, using that as the deployment machine. When scanning the network, it discovered machines on the network and deployed the same endpoint protection from that one machine I have on my network."
"It has made firewall configuration really simple."
 

Cons

"The initial setup is complex."
"Fortinet FortiGate could be improved in terms of user friendliness at the policy level and assigning URL based and keyword based features."
"During a recent upgrade from old devices to the latest ones, corporate IT faced challenges as there was no straightforward migration process, requiring many manual steps."
"I am afraid I cannot say that I have seen a return on investment."
"They have to just improve its performance when we enable all UTM features. When you enable all the features, the performance of FortiGate, as well as of Sophos and SonicWall, goes down."
"FortiGate may include AI capabilities and integrate external threat intelligence. However, version management and backup/restore operations could be improved."
"It should provide better visibility over the network and more information in the form of reports for the end users. Its installation should also be easier."
"The room for improvement is about the global delivery time period. Usually I need to wait for almost one month to deliver it overseas. So if you can shorten the deliver time it'd be great."
"It has an issue with the Sangfor Cloud Platform rather than the firewall. When we run a virtual machine, the window tabs display Chinese characters."
"The interface and user experience are horrible."
"Our experience with its customer support was quite challenging."
"There is room for improvement in dependency on certain infrastructure, like the DNS dependency on the current DNS server that the company has. It should be standalone. It should not depend on any other DNS server."
"Scalability for any network device is not very easy in terms of vertical scalability."
"The reporting and log management could be improved."
"An area for improvement would be the number of ports defined on the box. In the next release, I would like them to develop their provisioning stage of enrolling end devices."
"The solution should be able to work in a hybrid setup."
"There's always room for improvement, especially if the threats are getting more sophisticated and the IT department cannot sufficiently meet this kind of sophistication with their own knowledge and experience. Knowing that this solution can get up to the level of addressing a lot of these threats is something that everybody wishes for. If we look at the dark web and the lawful web, they are two opposites, and if these two good and bad collide in the world of the internet, you want the best possible product—especially if you cannot get to that point of knowledge. I am just an individual and end user, with limited knowledge of usage. That's why I say there's always room for improvement, from their side and also from mine, because by knowing exactly what they can achieve and the knowledge that they can get on an everyday basis, and the portion that is understandable to me, it's an improvement for them as well."
"The data loss protection works well, but it could be easier to configure."
"Its documentation could be improved. Sometimes, you need to search a bit longer to find what you are looking for."
"The software base, the management piece that goes onto a server, is not as user-friendly as I would like. There are three different pieces that you have to manage, so it's a little bit convoluted, in my opinion."
"I think one area for improvement in this solution would be enhancing communication with tools like Active Directory. This would make the tool easier to integrate and effective for users."
"I'm pretty happy with it, but vulnerability management could improve a little bit in comparison to other parts, such as Cisco and so on."
"The only problem I have with Firebox is the grouping issue. When implementing a rule using a group of IPs, it is not possible to do that directly."
"Firebox would be improved with integration for endpoint protection solutions."
 

Pricing and Cost Advice

"It cost us around $73,000 for three years."
"The cost of Fortinet FortiGate is competitive and not expensive compared to other enterprise- grade solutions. On average, the license cost per year is around seventy percent of the firewall's purchase price."
"The price of FortiGate is comparable to that of most other firewall solutions and is more affordable than Cisco."
"We are on an annual license to use Fortinet FortiGate."
"There is a license required to use Fortinet FortiGate with all the features. It has to be updated with the threats on an ongoing basis for the signatures to prevent threats and a license is needed to receive those security updates."
"If the price of the license in Fortinet FortiGate was less expensive it would be better."
"We find the most valuable aspect of this solution is the price. It is affordable, and cheaper than other firewalls."
"While slightly more affordable than competitors, it remains relatively expensive due to its inclusive subscription."
"The price falls in the mid-range, neither exceptionally low nor high."
"Sangfor NGAF is a cheaply priced product, especially if I consider the previous product that was used in my company."
"Sangfor NGAF price is reasonable and there is an annual license. However, the maintenance cost can be a bit high."
"Price-wise, I would not consider Sangfor NGAF to be a cheap product. It is an expensive firewall solution, though not as expensive as something like Palo Alto, which is costly. However, the higher price point is justifiable given the feature set the tool provides that other firewalls may not offer in a single dedicated appliance."
"The price is unmatcheable."
"I rate the product price as one on a scale of one to ten, where one is low price and ten is high price."
"It costs about 8 to 10 thousand dollars per year for 500 users, standard licensing fees included."
"We purchased one year technical support and return to factory support, and we also purchased one-year technical support services. So those were additional."
"We don't have any other costs other than the licensing stuff."
"WatchGuard offers competitive pricing with attractive margins, benefiting both the company and its partners."
"I spent $600 or $800 on this product and I'm paying a couple of hundred dollars a year in a subscription service to keep the lights on, on it... It works out to $100 or $200 a year if you buy several years at once. It's fair."
"The solution is not expensive and customers pay for a yearly license."
"The price of the solution is not expensive, it is less than FortiGate."
"I buy a three-year renewal on the main device, which is usually around $3,000 to $4,000. They usually upgrade the device when I do it. You get a big discount when you do three years."
"The cheapest configuration, for maybe five people, is approximately $500."
"They license it. When we buy it, we buy it with a three-year license. That's the most cost-effective way to do it. So, if you're going to buy it, then buy it with the three-year licensing."
report
Use our free recommendation engine to learn which Firewalls solutions are best for your needs.
902,417 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Comms Service Provider
10%
Computer Software Company
9%
Manufacturing Company
9%
Financial Services Firm
7%
Financial Services Firm
10%
Manufacturing Company
10%
Comms Service Provider
10%
Construction Company
7%
Comms Service Provider
12%
Manufacturing Company
8%
Computer Software Company
8%
Construction Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business369
Midsize Enterprise139
Large Enterprise195
By reviewers
Company SizeCount
Small Business15
Midsize Enterprise10
Large Enterprise10
By reviewers
Company SizeCount
Small Business101
Midsize Enterprise30
Large Enterprise16
 

Questions from the Community

Which is the better NGFW: Fortinet Fortigate or Cisco Firepower?
When you compare these firewalls you can identify them with different features, advantages, practices and usage a...
What is the biggest difference between Sophos XG and FortiGate?
From my experience regarding both the Sophos and FortiGate firewalls, I personally would rather use FortiGate. I know...
What are the biggest technical differences between Sophos UTM and Fortinet FortiGate?
As a solution, Sophos UTM offers a lot of functionality, it scales well, and the stability and performance are quite ...
What is your experience regarding pricing and costs for Sangfor NGAF?
The licensing cost is quite high compared to other available firewalls in the market.
What needs improvement with Sangfor NGAF?
The cost of licensing is very high compared to other firewalls available here. There should be improvements in hardwa...
What is your primary use case for Sangfor NGAF?
We are hosting applications over the platform, including websites and NAT traffic from our side. Because it's deploye...
What is your primary use case for WatchGuard Firebox?
We are providing our services to all WatchGuard customers in the region.
What is your primary use case for WatchGuard Firebox?
We just use it as a secondary WiFi device. We're a small office and we needed to set up a WiFi device for a few of ou...
What is your primary use case for WatchGuard Firebox?
We're a hospital and we use it for developing our incoming and outgoing policies, and we also use it for VPN.
 

Also Known As

Fortinet FortiGate Next-Generation Firewall
Sangfor NGAF Firewall Platform
WatchGuard Threat Detection and Response, WatchGuard Application Control, WatchGuard Data Loss Prevention, WatchGuard Gateway AntiVirus, WatchGuard Intrusion Prevention Service
 

Overview

 

Sample Customers

Amazon Web Services, Microsoft, IBM, Cisco, Dell, HP, Oracle, Verizon, AT&T, T-Mobile, Sprint, Vodafone, Orange, BT Group, Telstra, Deutsche Telekom, Comcast, Time Warner Cable, CenturyLink, NTT Communications, Tata Communications, SoftBank, China Mobile, Singtel, Telus, Rogers Communications, Bell Canada, Telkom Indonesia, Telkom South Africa, Telmex, Telia Company, Telkom Kenya
The Ministry of Science, Technology, and Innovation (Indonesia), Lawson, Inc. (Philippines), Universiti Sultan Zainal Abidin (Indonesia), TEK Automotive (Italy), etc.
Ellips, Diecutstickers.com, Clarke Energy, NCR, Wrest Park, Homeslice Pizza, Fortessa Tableware Solutions, The Phoenix Residence
Find out what your peers are saying about Sangfor NGAF vs. WatchGuard Firebox and other solutions. Updated: June 2026.
902,417 professionals have used our research since 2012.