Sangfor NGAF offers the same features as any other firewall product in the market. In terms of the valuable feature, I would say that the low cost the product offers was one of the major deciding factors when choosing the product in our company.
Senior Manager IT at Ghandha Automobile Limited
Though support needs improvement, it offers good reliability
Pros and Cons
- "So far, the performance and reliability of the product have supported our company's critical network traffic."
- "The support offered by the product has certain shortcomings where improvements are required. The knowledge levels and response time of the support team need improvement."
What is most valuable?
What needs improvement?
There are some difficulties with the deployment of the LDAP part in Sangfor NDAF, making it an area of concern where improvements are required.
The support offered by the product has certain shortcomings where improvements are required. The knowledge levels and response time of the support team need improvement.
For how long have I used the solution?
I have been using Sangfor NGAF for three months. I am the head of the IT team in my company. My team members use Sangfor NGAF.
What do I think about the stability of the solution?
Considering that my company has been using the product for only a few months, I rate the product's stability a five out of ten.
Buyer's Guide
Sangfor NGAF
October 2025
Learn what your peers think about Sangfor NGAF. Get advice and tips from experienced pros sharing their opinions. Updated: October 2025.
873,209 professionals have used our research since 2012.
What do I think about the scalability of the solution?
The scalability offered by the product is neither bad nor good.
Around 150 users of the product, and it is double in number if you consider the handheld devices in my company.
How are customer service and support?
The services from the solution's technical support have not been as satisfying as my company expected. I rate the technical support a three out of ten.
How would you rate customer service and support?
Negative
Which solution did I use previously and why did I switch?
I have experience with Fortinet. My company chose Sangfor NGAF after Fortinet ran out of its capability to offer support, considering how the tool has become too old.
How was the initial setup?
I rate the product's deployment phase a five on a scale of one to ten, where one means it is a difficult process and ten means it is an easy process. The deployment phase can be difficult to manage in certain places, while in some other areas, it can be easy.
The solution is deployed on an on-premises model.
What's my experience with pricing, setup cost, and licensing?
I rate the product price as one on a scale of one to ten, where one is low price and ten is high price.
What other advice do I have?
As there are some problems with the product partner, my company has not been able to fit in the web-filtering functionality of the product to meet our needs.
So far, the performance and reliability of the product have supported our company's critical network traffic.
I don't recommend the product to others who plan to use it, considering that the tool has problems in areas like support and deployment.
I rate the product a four out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Technical Sales Manager at a tech services company with 1-10 employees
Good price but the interface, user experience, and performance are horrible
Pros and Cons
- "The price versus value is good because the solution is less expensive than Sophos, Fortinet, or SonicWall."
- "The interface and user experience are horrible."
What is our primary use case?
Our company uses the solution for perimeter security. We are distributors in the Middle East and Africa. We look for competitive analysis against Fortinet and Sophos.
What is most valuable?
The price versus value is good because the solution is less expensive than Sophos, Fortinet, or SonicWall.
What needs improvement?
The interface and user experience are horrible. To perform simple things, you need to jump between many screens. There is no simplicity, everything is complex.
The available information is lacking. I'm struggling to give my coworker information about how to configure. The public information available is too old and hasn't been updated.
The solution is not out-of-the-box because it requires a mandatory license.
Outside of China, the solution does not offer active-active, virtual domains, or concurrent sessions. The CCB or UTB sessions and BPM channels are very low. The solution is a Chinese product and that side is different from the rest of the world. China has version 8.0.59 but the rest of the world has 8.0.47 only.
The solution has very, very slow hardware performance.
For how long have I used the solution?
I have been using the solution for one year.
What do I think about the stability of the solution?
The solution is stable so I rate stability an nine out of ten.
What do I think about the scalability of the solution?
The solution is not really scalable because it is limited by the capability of the box. You cannot scale out or up because there are hardware limitations.
Scalability is rated a zero out of ten.
How are customer service and support?
In Asia, technical support is good but it is very weak in our region. When you are looking for information from technical support, it will take ages for them to respond but chances are good that they won't respond at all.
Even presale support is not good.
I rate support a two out of ten.
How would you rate customer service and support?
Negative
How was the initial setup?
The setup is complex because the interface is not good.
For someone who is already a professional with another product, the setup is rated a five out of ten. For someone with security experience only, the setup is rated a one out of ten.
What about the implementation team?
We implemented the solution in-house. One experienced person can deploy.
Setup for someone who is experienced with other products will take a day for configuration.
Someone who knows security but doesn't know other products like Fortinet, Sophos, or SonicWall will struggle. It takes days to fetch out between sequences and you have to jump between screens for things like ABI, email security, and DLP. It takes time to figure out the proper sequence.
What's my experience with pricing, setup cost, and licensing?
The solution has a total cost of ownership that is 32% to 50% less than Sophos, Fortinet, and SonicWall. Licenses are also less expensive than Sophos.
The solution is not out-of-the box because a license is mandatory. You cannot operate the device by itself. This makes no sense because you should be able to use the default features or operate it without a license. Even if the device is capable, you still need a license.
The four categories of licenses are features, hardware, software updates or technical support, and advanced features. The vendor insists it is mandatory to buy the minimum features license. This license mandate is very strange.
The solution might raise its prices because Fortinet is increasing between 5% to 20% depending on the product and the solution competes with Fortinet. If the leader in the industry increases prices, other vendors will likely follow.
The pricing right now is an eight out of ten because it is good.
Which other solutions did I evaluate?
Fortinet is one of the best products so I recommend its use instead. There is continuous development and good R&D for the product.
What other advice do I have?
I would not recommend use of the solution at all. There has not been one single improvement or feature update in the last year. The solution is very bad at R&D.
The solution also keeps changing names and product positioning. It used to be called Butler, then Cloud Platforms.
There is not a single Sangfor employee right now outside of China who can give an explanation of their products. They don't know how the products even work. For example, they can't explain who can book the NGAF with Neural-X, with Engine Zero, or with a Platform-X or Butler cyber command.
I rate the solution a four out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
Buyer's Guide
Sangfor NGAF
October 2025
Learn what your peers think about Sangfor NGAF. Get advice and tips from experienced pros sharing their opinions. Updated: October 2025.
873,209 professionals have used our research since 2012.
System Network Administrator at Connect Logistics
Affordable and offers powerful application control but could use refinement in its application control policies
Pros and Cons
- "Sangfor NGAF's standout feature is its powerful application control, enabling precise restrictions on mobile user access to approved applications."
- "Sangfor NGAF could improve by refining its application control policies, especially in addressing challenges with certain types of applications."
What is most valuable?
Sangfor NGAF's standout feature is its powerful application control, enabling precise restrictions on mobile user access to approved applications. The system's adept intrusion detection further fortifies our network, preventing potential threats.
What needs improvement?
Sangfor NGAF could improve by refining its application control policies, especially in addressing challenges with certain types of applications.
For how long have I used the solution?
I have been using Sangfor NGAF for ten months.
What do I think about the stability of the solution?
So far, we have not had any issues with the stability of the solution.
What do I think about the scalability of the solution?
We have approximately 250 users of Sangfor NGAF at our company, but around 400 users all around.
How are customer service and support?
The support team is excellent. Very helpful and competent.
Which solution did I use previously and why did I switch?
My company opted for Sangfor NGAF over other products because of its affordability, compact size, and easy management features. I like Sangfor more than Fortinet because it is cheaper, has a friendlier interface, and comes with great support. It just feels like a better fit for me.
How was the initial setup?
The initial setup is very easy.
What's my experience with pricing, setup cost, and licensing?
Sangfor NGAF is quite affordable.
Which other solutions did I evaluate?
What other advice do I have?
Although Sangfor NGAF is a great product, I would rate it as a six out of ten just because I'm new in this field and still exploring other options and solutions.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Deputy Manager at Askari Life
A scalable and customizable product that provides good features and a friendly support team
Pros and Cons
- "SSL VPN is the best feature."
- "The product must provide more IPS features."
What is our primary use case?
We use SSL VPN and other networking features. Our organization is not very big.
What is most valuable?
SSL VPN is the best feature.
What needs improvement?
The product must provide more IPS features. It should also provide more VPN and security features.
For how long have I used the solution?
I have been using the solution for almost four years.
What do I think about the stability of the solution?
The tool is very stable. We have not faced any issues in the past four years. We never had to reboot or restart it. It never got stuck. We did not see a single fault in four years. I rate the stability a ten out of ten.
What do I think about the scalability of the solution?
The tool is very scalable and customizable. It fulfills all our requirements. I rate the scalability a ten out of ten. More than 200 people in our organization use the solution. We plan to increase the usage as our company and its requirements grow.
How are customer service and support?
The technical support is very good. Sangfor’s local partners are very friendly.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
Previously, we used software-based firewalls.
How was the initial setup?
We faced some problems initially due to some technical issues and configurations. The product has been working fine for four years. We’re happy with it. The initial setup is moderately difficult. I rate the ease of setup a five out of ten.
The configuration and customization took seven to ten days. We have a Sangfor engineer working remotely and a Sangfor partner on-premise who coordinates with the engineer for configuration and testing purposes.
What's my experience with pricing, setup cost, and licensing?
The product is very cost-effective compared to other brands or vendors. I rate the pricing a five out of ten.
What other advice do I have?
I recommend the solution to friends. We are very happy with it. Overall, I rate the tool a nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Network Administrator at AI Processings
Good network security capabilities but lacks in logging capabilites
Pros and Cons
- "The stability of Sangfor NGAF is good."
- "An area of improvement for Sangfor NGAF could be in the field of reporting and logging."
What is our primary use case?
We are using Sangfor NGAF for the prevention of attacks in our network through the use of IPS, IDS, and web filtering features.
How has it helped my organization?
There are currently over 1000 active nodes of the solution in use, and we do not have any plans to increase usage at this time.
What is most valuable?
Our primary need is to prevent our users from misusing the Internet, which we achieve through implementing traffic shifting and bandwidth restrictions, among other features offered by Sangfor NGAF
What needs improvement?
An area of improvement for Sangfor NGAF could be in the field of reporting and logging.
For how long have I used the solution?
I have been using the Sangfor NGAF solution for three years now.
What do I think about the stability of the solution?
The stability of Sangfor NGAF is good, and I would rate it a seven out of ten. In fact, compared to its competitors, Sangfor is much better so far.
How are customer service and support?
We get good support from customer service.
How was the initial setup?
The initial setup is easy and it is user-friendly.
What's my experience with pricing, setup cost, and licensing?
We have an annual subscription, which is not expensive. In fact, compared to Fortinet, Sangfor is much more cost-effective.
Which other solutions did I evaluate?
Although we have used different solutions such as Proofpoint, Gadget Control, and FortiNet, we find Sangfor NGAF to be much better due to its security inclusion prevention feature, which is why we introduced this product.
What other advice do I have?
Overall, I would rate the solution a seven out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
A scalable and comprehensive solution that specializes in ransomware detection
Pros and Cons
- "Sangfor NGAF specializes in ransomware detection and helps to protect our network from ransomware threats and malware."
- "The firewall system needs gradual improvements because there are more threats and challenges every day."
What is our primary use case?
Sangfor NGAF specializes in ransomware detection and helps to protect our network from ransomware threats and malware. This is the primary reason we purchased this solution, and we are currently negotiating to upgrade our appliances to volume M5200 Series. Additionally, Sangfor NGAF provides a web application for financial software.
How has it helped my organization?
We use Sangfor NGAF primarily for security, which has helped save our files from being encrypted by ransomware. Our desktop PCs have essential data, like word files and excel documents.
We previously had a ransomware attack on our file server, and Sangfor NGAF protected us by alerting and disconnecting the server from the network.
What needs improvement?
The firewall system needs gradual improvements because there are more threats and challenges in the world every day. Sangfor NGAF has a comprehensive database for ransomware and viruses, but when we compare it to other solutions, the price could be more competitive.
Since we have a very comprehensive solution with Sangfor NGAF, it is hard to identify any additional features we want to add. It already provides good features for ransomware attacks and data recovery. In the past, we wanted encrypted data for a virus to be recoverable, and Sangfor offered the solution.
For how long have I used the solution?
We have been using Sangfor NGAF for four years. We use it for overall IT infrastructure protection and are currently using version 1 of Model M5100.
We currently deploy a hybrid infrastructure of cloud and on-premises. We use the solution for our accounting and financial software, websites, internet blocking, and other features. Some clients are on the cloud, and others are on-premises. We also have a Sangfor solution that filters the in and out traffic.
What do I think about the stability of the solution?
The solution is relatively stable. Interestingly, we discontinued the updates and software licenses about a year ago, and the appliance and solutions are still working. In addition, there is no limitation on the license, so services won't stop if it expires. You can also update the license at any time for a partial cost.
What do I think about the scalability of the solution?
This solution is scalable. We can add many features and lengths and expand according to our needs.
The IT specialists and engineers in my organization use this solution. Our whole organization is under the protection of Sangfor NGAF. The solution has footprints in India and Europe and many government agencies use Sangfor NGAF in Pakistan.
For deployment, we needed three people who were all IT specialists, and only one of them was from Sangfor. As a result, we deployed it with very few resources, and there were no recurring charges. Also, most people are very well-versed in technology and can multitask.
How are customer service and support?
The technical support team was very helpful, provided support, and guided us during our initial deployment. We were good to go in 15 to 20 minutes.
Which solution did I use previously and why did I switch?
We previously used Sophos and pfSense, an open-source firewall.
How was the initial setup?
The initial setup was very straightforward. The solution is out of the box, and the software and appliance can be quickly installed. It has a very nice AI feature, and we only needed to implement parameters and define some policies. The deployment took 15 to 20 minutes because we had to get familiar with the new system.
We defined WAN and LAN networks for our implementation strategy and then defined the servers. Next, we identified the modes and decided the desktop would be the best. There were other considerations but it has been four years, so it is hard to remember all of them.
What about the implementation team?
We completed our deployment in-house.
What was our ROI?
We have seen a return on investment. The systems are protected, and their operating systems are readily available. We are protected from ransomware attacks and the loss of data. This solution protects us, and it has benefits.
What's my experience with pricing, setup cost, and licensing?
On a scale of one to ten, with one being the cheapest, I rate the price a six out of ten. There are no hidden or additional costs other than what we were provided. Therefore, we are happy with our initial decisions.
Which other solutions did I evaluate?
We evaluated other options and completed some financial comparisons but the IT specialists advised that Sangfor NGAF worked well.
What other advice do I have?
I rate this product an eight out of ten because we don't know what we may need from this solution in the future. We are satisfied and hope to upgrade to a new version soon. However, right now, our current version is working fine.
In terms of advice, we would recommend Sangfor NGAF. But, a company should first prepare an analysis, compare different products, and then decide what they want.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Teamlead IT Core at SoloInsight Inc.
Next generation firewall that is scalable and one of the best on the market
Pros and Cons
- "Sangfor is a good solution that provides a WAF and firewall solution. Most other vendors, like Sophos and Fortinet and Cisco, only provide one solution. That's a valuable feature of Sangfor."
- "Sangfor could improve their interface capacity on the 5100 series model and upgrade their hardware from one gig to 10 gig. This would improve the overall throughput."
What is our primary use case?
Sangfor is an on-prem firewall I use for my local infrastructure. It is used as an aggregated interface. Behind Sangfor, I have built a data center that is deployed on high availability using a model that is 5100 CV with 10 gig ports.
What is most valuable?
Sangfor is a good solution that provides a WAF and firewall solution. Most other vendors, like Sophos and Fortinet and Cisco, only provide one solution. That's a valuable feature of Sangfor.
What needs improvement?
Sangfor could improve their interface capacity on the 5100 series model and upgrade their hardware from one gig to 10 gig. This would improve the overall throughput.
For how long have I used the solution?
I have used this solution for the last six months.
What do I think about the scalability of the solution?
This is a scalable solution. We have approximately 1,000 users.
How are customer service and support?
The technical support team are available 24/7 and if we need any assistance for Sangfor, FortiGate or Sophos, we can call their support number and they provide assistance from their L2 or L3 engineers.
How would you rate customer service and support?
Positive
How was the initial setup?
It's very easy to set up because Sangfor provided us with export and HCI capabilities. Deployment took almost one week.
The process starts with low level design for internal teams to make a design on network requirements. This contains all current and future requirements.
What's my experience with pricing, setup cost, and licensing?
For four to five physical appliances for a licensed firewall, it costs approximately $4,000.
What other advice do I have?
We have six people managing IT operations. We have not had any issues in the first six months of using this solution.
If you want to deploy a firewall in your infrastructure, Fortinet, Sangfor and Sophos are the best solutions to protect traffic.
I would rate this solution an eight out of ten.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
Presales Specialist at a tech services company with 1,001-5,000 employees
Cost-effective and has an initial setup phase
Pros and Cons
- "I think the tool has the feature to detect and kill ransomware in three seconds."
- "The tool's support is an area of concern where improvements are required."
What is our primary use case?
My company's customers use the solution as a firewall. Some prefer Sangfor NGAF as a replacement for their current existing firewall. The reason why I am proposing Sangfor NGAF is mainly because of its price point. The tool is very cost-effective compared to other brands.
What is most valuable?
The tool's most effective part stems from the product's ease of use, which is very important because the client has to manage it at the end of the day.
I think the tool has the feature to detect and kill ransomware in three seconds. The tool claims that it can kill the ransomware on the spot in three seconds and restore all the encrypted files.
What needs improvement?
The tool's support is an area of concern where improvements are required. The support should be available locally, I would say. As of now, I think the tool is moving towards offering local support. I have heard from my previous customer that the support is actually from another region, making it quite hard for them to get in touch with the technical team.
For how long have I used the solution?
I have been using Sangfor NGAF for a year. My company is a reseller of the product. I don't remember the version of the solution.
What do I think about the stability of the solution?
It is a stable solution because of the ease of use and inside the firewall itself, the tool offers WAF. Customers who hear that WAF is integrated into the firewall get interested in the solution. WAF is actually another solution. Instead of purchasing a WAF product, you get it inside Sangfor NGAF. Stability-wise, I rate the solution a nine out of ten.
What do I think about the scalability of the solution?
It is a scalable solution. Scalability-wise, I rate the solution an eight out of ten.
In our company, we deal with a wide range of things. The scalability depends on what range the customer chooses. I can't pinpoint or explain the tool's scalability aspect in detail. Different types of firewall models are available.
Under five customers of my company use the tool, and they are all enterprise businesses.
How are customer service and support?
I rate the technical support a seven out of ten.
How would you rate customer service and support?
Neutral
How was the initial setup?
If one is difficult and ten is easy to set up, I rate the product's initial setup phase an eight out of ten. I never deployed the tool. I am sharing my engineering experience.
I am not quite sure about the deployment situation.
The solution is deployed on the cloud.
What's my experience with pricing, setup cost, and licensing?
If one is very cheap and ten is very expensive, I rate the tool's price as three out of ten. I am not quite sure about the tool's pricing point.
What other advice do I have?
Sangfor NGAF has not shared how it has impacted our customer security operations with my company's sales team. If they do share such information, it is usually with the sales team while I am on the presales team. I am only a consultant, so the product doesn't share such details directly with me.
The tool helped our customers with threat mitigation strategies because it has AI functionalities that are helpful.
Suppose an enterprise customer wants a firewall as the first thing inside the company because of its cost-effectiveness. In that case, I think Sangfor NGAF can be a good option as it comes with the features and abilities of the firewall. I think it is quite a great option for enterprise users.
I rate the tool an eight out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. consultant
Buyer's Guide
Download our free Sangfor NGAF Report and get advice and tips from experienced pros
sharing their opinions.
Updated: October 2025
Product Categories
FirewallsPopular Comparisons
Fortinet FortiGate
Netgate pfSense
OPNsense
Sophos XG
Cisco Secure Firewall
Palo Alto Networks NG Firewalls
WatchGuard Firebox
Cisco Meraki MX
Check Point Quantum Force (NGFW)
SonicWall TZ
Sophos XGS
Fortinet FortiGate-VM
Juniper SRX Series Firewall
SonicWall NSa
Fortinet FortiOS
Buyer's Guide
Download our free Sangfor NGAF Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What do you recommend for a corporate firewall implementation?
- Comparison of Barracuda F800, SonicWall 5600 and Fortinet
- Sophos XG 210 vs Fortigate FG 100E
- Which is the best network firewall for a small retailer?
- When evaluating Firewalls, what aspect do you think is the most important to look for?
- Cyberoam or Fortinet?
- Fortinet, Palo Alto or Check Point?
- If you could go back, would you change your decision to buy that firewall and why?
- Sophos XG vs Fortigate UTM
- Can you recommend a solution to replace Cyberoam 200ing Firewall?
















