SaadAziz - PeerSpot reviewer
Manager IT at Sabirs' Group
Real User
Top 10
A scalable and comprehensive solution that specializes in ransomware detection
Pros and Cons
  • "Sangfor NGAF specializes in ransomware detection and helps to protect our network from ransomware threats and malware."
  • "The firewall system needs gradual improvements because there are more threats and challenges every day."

What is our primary use case?

Sangfor NGAF specializes in ransomware detection and helps to protect our network from ransomware threats and malware. This is the primary reason we purchased this solution, and we are currently negotiating to upgrade our appliances to volume M5200 Series. Additionally, Sangfor NGAF provides a web application for financial software.

How has it helped my organization?

We use Sangfor NGAF primarily for security, which has helped save our files from being encrypted by ransomware. Our desktop PCs have essential data, like word files and excel documents. 

We previously had a ransomware attack on our file server, and Sangfor NGAF protected us by alerting and disconnecting the server from the network.

What needs improvement?

The firewall system needs gradual improvements because there are more threats and challenges in the world every day. Sangfor NGAF has a comprehensive database for ransomware and viruses, but when we compare it to other solutions, the price could be more competitive.

Since we have a very comprehensive solution with Sangfor NGAF, it is hard to identify any additional features we want to add. It already provides good features for ransomware attacks and data recovery. In the past, we wanted encrypted data for a virus to be recoverable, and Sangfor offered the solution.

For how long have I used the solution?

We have been using Sangfor NGAF for four years. We use it for overall IT infrastructure protection and are currently using version 1 of Model M5100.

We currently deploy a hybrid infrastructure of cloud and on-premises. We use the solution for our accounting and financial software, websites, internet blocking, and other features. Some clients are on the cloud, and others are on-premises. We also have a Sangfor solution that filters the in and out traffic.

Buyer's Guide
Sangfor NGAF
March 2024
Learn what your peers think about Sangfor NGAF. Get advice and tips from experienced pros sharing their opinions. Updated: March 2024.
768,740 professionals have used our research since 2012.

What do I think about the stability of the solution?

The solution is relatively stable. Interestingly, we discontinued the updates and software licenses about a year ago, and the appliance and solutions are still working. In addition, there is no limitation on the license, so services won't stop if it expires. You can also update the license at any time for a partial cost.

What do I think about the scalability of the solution?

This solution is scalable. We can add many features and lengths and expand according to our needs.

The IT specialists and engineers in my organization use this solution. Our whole organization is under the protection of Sangfor NGAF. The solution has footprints in India and Europe and many government agencies use Sangfor NGAF in Pakistan.

For deployment, we needed three people who were all IT specialists, and only one of them was from Sangfor. As a result, we deployed it with very few resources, and there were no recurring charges. Also, most people are very well-versed in technology and can multitask.

How are customer service and support?

The technical support team was very helpful, provided support, and guided us during our initial deployment. We were good to go in 15 to 20 minutes.

Which solution did I use previously and why did I switch?

We previously used Sophos and pfSense, an open-source firewall. 

How was the initial setup?

The initial setup was very straightforward. The solution is out of the box, and the software and appliance can be quickly installed. It has a very nice AI feature, and we only needed to implement parameters and define some policies. The deployment took 15 to 20 minutes because we had to get familiar with the new system. 

We defined WAN and LAN networks for our implementation strategy and then defined the servers. Next, we identified the modes and decided the desktop would be the best. There were other considerations but it has been four years, so it is hard to remember all of them.

What about the implementation team?

We completed our deployment in-house.

What was our ROI?

We have seen a return on investment. The systems are protected, and their operating systems are readily available. We are protected from ransomware attacks and the loss of data. This solution protects us, and it has benefits.

What's my experience with pricing, setup cost, and licensing?

On a scale of one to ten, with one being the cheapest, I rate the price a six out of ten. There are no hidden or additional costs other than what we were provided. Therefore, we are happy with our initial decisions.

Which other solutions did I evaluate?

We evaluated other options and completed some financial comparisons but the IT specialists advised that Sangfor NGAF worked well. 

What other advice do I have?

I rate this product an eight out of ten because we don't know what we may need from this solution in the future. We are satisfied and hope to upgrade to a new version soon. However, right now, our current version is working fine.

In terms of advice, we would recommend Sangfor NGAF. But, a company should first prepare an analysis, compare different products, and then decide what they want.

Which deployment model are you using for this solution?

Hybrid Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Moeed  Mahmood - PeerSpot reviewer
Network Administrator at Chase Up
Real User
Top 5
Detects and reacts to threats in real-time
Pros and Cons
  • "It is a stable solution."
  • "The setup phase is quite complex."

What is our primary use case?

I use Sangfor NGAF since it is a good firewall product with good threat protection. The product is very useful for IPSec VPNs and SD-WAN VPNs.

What is most valuable?

The most valuable features of the solution stem from the security center or SOC-related feature, which is very good since it detects threats in real time and quickly. The tool also reacts on a timely basis.

What needs improvement?

The setup phase is quite complex. The setup process could be easier.

For how long have I used the solution?

I have been using Sangfor NGAF for six months.

What do I think about the stability of the solution?

It is a stable solution.

What do I think about the scalability of the solution?

It is a very scalable solution. I can't say that the tool is as scalable as Fortinet FortiGate's latest version.

There are around 3,000 users of the tool in my company.

How are customer service and support?

The solution's technical support was very good, cooperative, and responsive.

I am satisfied with the support team.

How was the initial setup?

The product's initial setup phase was not as straightforward as Fortinet FortiGate. As a first-time user, if you get to see the setup phase for the first time, you can do it easily the second time. The setup phase is not very hard. The tool is very easy to use.

During the deployment, the first step is to upgrade and activate the license of the product and configure interfaces, zones, objects, and policies, along with NAC and DMZ policies. The tool also helps with static routing to ensure connectivity between the head office and stores. The aforementioned steps were taken to make the product operational.

What's my experience with pricing, setup cost, and licensing?

Sangfor NGAF is a cheaply priced product, especially if I consider the previous product that was used in my company.

Firewall products function with licenses. Without licenses, the tool's main features, like intrusion prevention, web access firewall, DNS, or IDS, will not be activated if you don't buy the license.

What other advice do I have?

Speaking about how Sangfor NGAF improved our company's network performance, I would say that I had installed the product at our head office, where we use it for internal policies and DMZ zones. It is a very useful firewall. Previously, we used Fortinet products, but now, Sangfor NGAF is fully operational in our network, and we use it to block ISPs and the internet and manage rules or traffic, like DMZ to LAN. Other VPNs like IPSec VPNs work in Sangfor, and it serves as a very good feature in the tool. I even loved the SD-WAN VPN feature of the tool.

The application control feature helps manage our company's network traffic in a very good manner. I have been using the tool for the last six months, and I am quite satisfied with the product's performance.

Speaking about the intrusion prevention system of the tool, I have some logs that can state the source of the attacks and which have been blocked in a timely manner by the product. The tool's threat management capabilities and ability to deal with DDoS attacks are good and very useful.

The deployment affected our company's team's workload since the team was available at the premises of the organization during the deployment phase.

I recommend the product to those who want to buy it to protect and manage their networks with the product. It is quite a useful product.

I can't speak much about the benefits of the tool since everyone uses the product for their own needs. In terms of benefits, Sangfor NGAF's price is better than Fortinet FortiGate.

I rate the tool an eight and a half out of ten.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
Flag as inappropriate
PeerSpot user
Buyer's Guide
Sangfor NGAF
March 2024
Learn what your peers think about Sangfor NGAF. Get advice and tips from experienced pros sharing their opinions. Updated: March 2024.
768,740 professionals have used our research since 2012.
KhurshidAhmed - PeerSpot reviewer
Senior Manager IT at Ghandha Automobile Limited
Real User
Top 20
Though support needs improvement, it offers good reliability
Pros and Cons
  • "So far, the performance and reliability of the product have supported our company's critical network traffic."
  • "The support offered by the product has certain shortcomings where improvements are required. The knowledge levels and response time of the support team need improvement."

What is most valuable?

Sangfor NGAF offers the same features as any other firewall product in the market. In terms of the valuable feature, I would say that the low cost the product offers was one of the major deciding factors when choosing the product in our company.

What needs improvement?

There are some difficulties with the deployment of the LDAP part in Sangfor NDAF, making it an area of concern where improvements are required.

The support offered by the product has certain shortcomings where improvements are required. The knowledge levels and response time of the support team need improvement.

For how long have I used the solution?

I have been using Sangfor NGAF for three months. I am the head of the IT team in my company. My team members use Sangfor NGAF.

What do I think about the stability of the solution?

Considering that my company has been using the product for only a few months, I rate the product's stability a five out of ten.

What do I think about the scalability of the solution?

The scalability offered by the product is neither bad nor good.

Around 150 users of the product, and it is double in number if you consider the handheld devices in my company.

How are customer service and support?

The services from the solution's technical support have not been as satisfying as my company expected. I rate the technical support a three out of ten.

How would you rate customer service and support?

Negative

Which solution did I use previously and why did I switch?

I have experience with Fortinet. My company chose Sangfor NGAF after Fortinet ran out of its capability to offer support, considering how the tool has become too old.

How was the initial setup?

I rate the product's deployment phase a five on a scale of one to ten, where one means it is a difficult process and ten means it is an easy process. The deployment phase can be difficult to manage in certain places, while in some other areas, it can be easy.

The solution is deployed on an on-premises model.

What's my experience with pricing, setup cost, and licensing?

I rate the product price as one on a scale of one to ten, where one is low price and ten is high price.

What other advice do I have?

As there are some problems with the product partner, my company has not been able to fit in the web-filtering functionality of the product to meet our needs.

So far, the performance and reliability of the product have supported our company's critical network traffic.

I don't recommend the product to others who plan to use it, considering that the tool has problems in areas like support and deployment.

I rate the product a four out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Flag as inappropriate
PeerSpot user
Wajeeh Ul Hasan . - PeerSpot reviewer
Network Administrator at Shaheed Zulfiqar Ali Bhutto Institute of Science and Technology
Real User
Top 5
Integrates well, reliable, and different pricing models available
Pros and Cons
  • "The most valuable feature of Sangfor NGAF is its integration."
  • "Sangfor NGAF could improve the policies and default criteria. They could be much better."

What is our primary use case?

Sangfor NGAF is a complete firewall solution.

What is most valuable?

The most valuable feature of Sangfor NGAF is its integration.

What needs improvement?

Sangfor NGAF could improve the policies and default criteria. They could be much better.

For how long have I used the solution?

I have been using Sangfor NGAF for approximately three years.

What do I think about the stability of the solution?

Sangfor NGAF is stable.

What do I think about the scalability of the solution?

The scalability of Sangfor NGAF is good.

We are using the Sangfor NGAF as our firewall, we have approximately 6,000 to 8,000 end users who are passing through. We have approximately 10 to 15 people using the Sangfor SSL VPN feature remotely from home.

How are customer service and support?

The support from Sangfor NGAF here in Pakistan is great. Whenever I have an issue the support helps me out efficiently.

I rate the support from Sangfor NGAF a five out of five.

How would you rate customer service and support?

Positive

How was the initial setup?

The initial setup of Sangfor NGAF is straightforward. Sophos and Fortinet have more difficult initial setups.

I rate the initial setup of Sangfor NGAF a five out of five.

What's my experience with pricing, setup cost, and licensing?

The license of Sangfor NGAF can be purchased at different interval lengths, such as annually or three years. They offer a range of packages to choose from, such as combo or hybrid packages. We are using the complete solution package which includes IM, NGF and SSL VPN, and WAF

We have purchased the support for three years.

What other advice do I have?

My advice to others is they should try the solution. I have experienced other solutions, such as Fortinet and I feel much better using this solution overall.

I rate Sangfor NGAF a nine out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
Network Administrator at Government College University
Real User
Top 20
Great for inspecting traffic on a very granular level but the GUI lacks logic in some areas
Pros and Cons
  • "Particularly good in the DPI where we can inspect inbound and outbound traffic."
  • "The GUI needs to be improved, lacks logic in some areas."

What is our primary use case?

This solution is our firewall. I'm a network administrator.

What is most valuable?

Sangfor serves most of the basic purposes of a firewall. It's particularly good in the DPI where we can inspect the inbound and outbound traffic on a very granular level. It gives a very good predictive measure as well as the current measure of things going on in our network. When it comes to the VPNs, it has a very good throughput when remote users connect, particularly when it comes to site-to-site VPNs, where it provides a good analysis module. You can analyze inbound traffic and different policies on this. It gives us value for money overall.

What needs improvement?

I think the GUI needs to be improved, there are a lot of areas where the panes do not make sense. They have put the NAT in the policy section but at the same time the DPI is in the network pane. The placement of different options in the menu system of this firewall is not that logical and often doesn't make a lot of sense. The operational procedures are a little tricky and require some technical skills. A level one person will have problems. The compatibility needs to be improved. 

For how long have I used the solution?

I've been using this solution for three years. 

What do I think about the stability of the solution?

We have been experiencing power failures but the solution has been very stable, both from the hardware and the software perspective. We have built a lot of VPN solutions for the firewalls including Cisco, Firewall 2, and pfSense, and it has been very good with that. 

What do I think about the scalability of the solution?

We don't require a very highly scalable coefficient but I believe it's scalable. 

How are customer service and support?

The technical support is very good. They have a local vendor they have hired for the technical support and if anything cannot be resolved remotely, they come to us. They are very agile and very technically supportive.

How would you rate customer service and support?

Positive

How was the initial setup?

The initial setup was a little complex because we were previously dealing with command line scenarios and we were not very comfortable with the GUI which is a little complex. 

What's my experience with pricing, setup cost, and licensing?

Our licensing costs are around $15,000 per year which is nominal compared to other solutions. 

What other advice do I have?

Whether or not this solution is good for you depends on your network. If you have sufficient technical support, then you can go for an open-source solution. Without that and if you have the funds, then this is a good solution. If not, then most of what firewalls do these days can be handled by an open-source solution.

This is a new solution in our country where the price tag really matters. They have targeted the public sector and I'm seeing more and more people moving towards Sangfor because it's cheaper than other products, and the support is quite good. 

I rate the solution seven out of 10. 

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
FarisKhan - PeerSpot reviewer
Enterprise System Engineer at Innolytix Pakistan Pvt Ltd
Real User
Scalable security solution deployed across multiple industries and is well priced compared to competitors
Pros and Cons
  • "The level of support provided to local companies is good. They transform their application control and other settings according to that country."
  • "Sangfor need greater exposer in the market because the market is mainly saturated by Fortinet. The user experience of Fortinet is quite different compared to NGAF. If we want to switch our users from Fortinet to NGAF, we have to convince them that the user experience will be much easier once once they start to use it."

What is our primary use case?

We have this solution deployed across multiple industries including education, pharmaceutical and different textile industries. This is a good product for network security and is popular right now. Sangfor is cheaper than well-known products like Fortinet and Palo Alto Firewall NGFS.

What is most valuable?

The level of support provided to local companies is good. They transform their application control and other settings according to that country. 

What needs improvement?

Sangfor need greater exposer in the market because the market is mainly saturated by Fortinet. The user experience of Fortinet is quite different compared to NGAF. If we want to switch our users from Fortinet to NGAF, we have to convince them that the user experience will be much easier once once they start to use it. 

What do I think about the stability of the solution?

We have deployed many firewalls and have faced two or three faulty devices that we have to replace over a year because their power supply was faulty. Some customers use the device for over five years and they have worked fine but got slower with the time.

What do I think about the scalability of the solution?

This is a scalable solution. 

How are customer service and support?

I can vouch for the local support team. They are more than competitive in the market. They are always available for small and big customers. They are onsite whenever we need it and assist with any problem or deployment scenario and are willing to discuss it at any time. I would rate them a three out of five. 

Which solution did I use previously and why did I switch?

I have previously used Fortinet. Fortinet is quite a mature product and offers so many features. Sangfor lack a bit in that area. Sangfor include a local database for URLs and other applications. When using Fortinet, you cannot block a local website by default. 

How was the initial setup?

The simple deployment of a network on NGF is quite simple and their guides are quite simple as well. The do lack visual guides that are easier for some customers to follow. It's easy to configure a normal deployment scenario for networking and ET. When it comes to high level security and highly advanced features, you need to have some experience in that area to actually apply that on this firewall.

If you're experienced, it would take two or three hour maximum, depending on how many customers are using the policy and how much detailed configuration is needed. I would rate our experience with the setup an eight out of ten. 

We have faced some of the issues after deployment with URL filtering which we have logged a ticket for. Our customers are unable to access certain websites. We have diagnosed the problem but we are unable to identify the URL signature or what is blocking the IAM and preventing access to that site. 

What's my experience with pricing, setup cost, and licensing?

For over 2000 users, the cost is around 5000 to 6000 USD. If you want a web application firewall, you have to purchase an additional license for it. By default, they provide you with 10 SSL and a VPN. If you want more than 10, you have to pay more. From a pricing perspective, I would rate them a four out of five.

What other advice do I have?

They have a huge product line for large companies and we have deployed a firewall for over 5000 to 10000 users. It is suitable for all type of environments. I would advise others to spend one to two months after deployment on Sangfor to configure the many settings for security services. You have to work on it, keep looking at the logs and make changes as you go. You need this time to analyze, make future risk assessments and reconfigure the work from time to time. Only once this is done, can you consider deployment complete. 

It offers good value for money and is much cheaper compared to other firewalls. I would suggest Sangfor to those who are cost conscious. 

I would rate this solution a seven out of ten.

Which deployment model are you using for this solution?

Hybrid Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
Shiraz Ali - PeerSpot reviewer
Networking Solutions Specialist at GBM
Real User
Top 5
An affordable solution that is reliable and provides a quick response
Pros and Cons
  • "The product is very fast and reliable."
  • "The solution should be able to work in a hybrid setup."

What is our primary use case?

We use the solution to connect and protect all the internal servers. All publicly accessible websites and servers are connected to the solution.

What is most valuable?

The product is very fast and reliable. It has a quick response.

What needs improvement?

The solution should be able to work in a hybrid setup.

For how long have I used the solution?

I have been using the solution for one and a half years.

What do I think about the scalability of the solution?

Around 150 users are using the solution in my organization. Both internal and external traffic goes through the firewall because the firewall is placed on the main data center.

How are customer service and support?

If we have any issues, we read the documentation. If the issue cannot be fixed, we can contact the support team. I have not contacted the support team yet. I configure things by myself.

Which solution did I use previously and why did I switch?

We were using Cisco’s firewall before. It ended support. We cannot use the products that have ended support. Cisco and Sangfor work similarly, but their GUIs are different.

How was the initial setup?

The initial setup is very easy.

What's my experience with pricing, setup cost, and licensing?

It is one of the cheapest tools in the market. The choice depends on the customer’s budget.

What other advice do I have?

Overall, I rate the product a nine out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Flag as inappropriate
PeerSpot user
Infrastructure Department Head at a manufacturing company with 11-50 employees
Real User
Top 20
Robust security features with scalability challenges
Pros and Cons
  • "It enables us to not only detect but also prevent various types of incoming threats, allowing us to take appropriate corrective actions and exercise control over the network."
  • "It does not offer any recommendations on how to mitigate or control attacks."

What is our primary use case?

The system comprises three primary functionalities: defense solutions, detection solutions, and the ability to identify, block, and analyze network traffic. It enables us to not only detect but also prevent various types of incoming threats, allowing us to take appropriate corrective actions and exercise control over the network.

How has it helped my organization?

We have observed numerous threats targeting our network from both internal and external sources. While we have reports detailing these incidents, we currently lack a clear method for prioritizing internal threats.

What is most valuable?

The information provided alerts us to the presence of threats from specific sources, which is highly beneficial.

What needs improvement?

It does not offer any recommendations on how to mitigate or control attacks.

For how long have I used the solution?

I have been using it for three years.

What do I think about the stability of the solution?

We face occasional stability issues. I would rate it seven out of ten.

What do I think about the scalability of the solution?

It doesn't offer significant scalability features.

How are customer service and support?

In the event of a performance issue, such as users reporting slow access to specific websites, we conduct an internal investigation to identify the root cause. If it's determined to be a problem with the equipment, we escalate the issue to the vendor for resolution.

How would you rate customer service and support?

Neutral

What about the implementation team?

When we installed the equipment, we depended on an external consulting party to guide us through the setup and functionality for approximately two weeks. The project team, consisting of both project members and experts in the field, were actively engaged during this period.

What's my experience with pricing, setup cost, and licensing?

The pricing is reasonable. At the time of our decision to acquire the equipment, we were working with a constrained budget and it turned out to be the most suitable choice to meet our specific requirements

Which other solutions did I evaluate?

We considered FortiGate as an option but ultimately decided on Sangfor NGAF due to its more favorable pricing.

What other advice do I have?

I hope that its distributor possesses a high level of product knowledge, and the same applies to Sangfor itself as the principal company. This would enable customers to have a more seamless and enriching experience with the product, eliminating any barriers or disconnect between our team, the customers, and the software. Overall, I would rate it seven out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Flag as inappropriate
PeerSpot user
Buyer's Guide
Download our free Sangfor NGAF Report and get advice and tips from experienced pros sharing their opinions.
Updated: March 2024
Product Categories
Firewalls
Buyer's Guide
Download our free Sangfor NGAF Report and get advice and tips from experienced pros sharing their opinions.