We performed a comparison between Check Point NGFW and Sangfor NGAF based on real PeerSpot user reviews.
Find out in this report how the two Firewalls solutions compare in terms of features, pricing, service and support, easy of deployment, and ROI."There are lots of features and most of them are deployed for internet security. Users are protected if they accidentally go to some malicious sites."
"The solution is stable."
"I like Fortinet FortiGate's antispam filter, SPN, and clustering features."
"The CLI is robust and powerful, enabling rapid, consistent changes via SSH."
"FortiGate's web and URL filtering are unlike any other firewall I've used. The functionality of URL filtering in those solutions is problematic because everything is encrypted, and firewalls can't break that encryption protocol. Fortinet has an SSL proxy, so the encryption is done before the packet ever leaves the FortiGate. The URL filter is definitely one of the most helpful features."
"Fortinet has a very good solution for Secure SD-WAN. One very good feature is that they have robust and simple FortiOS through which they provide all solutions. That's their strength. There's not much complexity involved with the Secure SD-WAN solution of Fortinet as compared to Cisco's solution, which has a lot of flexibility but complexity also comes with that flexibility."
"It does a lot for you for intrusion protection and as an antivirus. The threat management bundle is worth the money. You don't need another company to monitor your web traffic for you. You can do everything yourself on the firewall. You restrict your own black list for people on the firewall. You don't need to pay some other company for another product to do that for you. The firewall can do that for you. So, it's an easy-to-use product for people to be independent. They don't need to rely on other vendors to do what the firewall can do. They can do everything."
"It's a firewall that secures our internal network. I have been using it since 2013, and I find that most of the features are advanced, and very user friendly."
"It creates granular security policies based on users or groups to identify, block or limit the usage of web applications."
"The most valuable feature is the centralized management, which gives us control over all of the Check Point gateways."
"The packet inspections have been a strong point. Our identity collectors have also been helpful. In many ways, Check Point has been a step up from our SonicWalls that we had in-house before that. There's a lot of additional flexibility that we didn't have before."
"We can build the new firewalls with minimum efforts."
"The application control and URL filtering features are valuable since they allow very granular control of what is coming in and out of a network."
"Admins and executives are more at ease with the compliance engine within the software as it measures how many of the security requirements we're compliant with, making their work much more accessible from that standpoint."
"We use Check Point to complete the network compliance rules."
"It is easy to control from the central management system. For example, if we have 10 firewalls, and we want to push that same configuration among them, we can use this solution's central management system to do that simultaneously. So, there is time saving in that way. The time savings does depend on the situation. For example, if I am running half an hour of work on each firewall, that will take around 300 minutes. However, if I do this work from the central management system, then it will only take 30 minutes to push the same configuration to those same 10 devices."
"Sangfor NGAF works accordingly with our customers. The solution has good performance, easy to use, and integrates well with the endpoints."
"Sangfor has the best capabilities for securing connections, securing web browsers, securing servers, and general threat protection."
"The most valuable features are the WAN optimization, the internet access gateway (IAG), and the central console, which allows us to implement on their firewall."
"The VPN connectivity feature is really nice."
"We've found the technical support to be helpful."
"The built-in features function as intended, providing exceptional value."
"Particularly good in the DPI where we can inspect inbound and outbound traffic."
"SSL VPN is the best feature."
"To some degree, it's almost a question as to why some of this stuff isn't simpler. For example, for an AP deployment, while it's integrated, the number of steps that you have to go through in order to get the AP up, seems like a lot."
"I haven't had a single issue since using Fortinet."
"We were not able to build a full-mesh VPN; however, I am not sure if this was the fault of Fortinet FortiGate."
"For the migration, everyone has a firewall in use and I am selling Fortinet. Typically, I am replacing another firewall. Previously, there was a tool available to convert configurations from one firewall, such as Palo Alto, to Fortinet, but this tool is no longer free. If it could be made free again, it would be very beneficial."
"I think the only issue that needs improvement is the interface."
"The support is the main thing that needs to be improved."
"They need to improve their technical support."
"The solution needs to improve its integration with cybersecurity."
"We'd like an option that can convert other vendors' NGFW configurations to supported Check Point NGFW config for ease of migration."
"It would be nice if there is a mobile-friendly console for our techs."
"This product has room for improvement in technical support for Africa."
"The management of memory in the hardware needs to improve. They have had a lot of issues with memory leakage."
"The virtual infrastructure of the central management requires a huge amount of resources to work properly and manage all the logs without problems."
"The product or services can be improved from the cost and the pricing perspective."
"I would like there to be a way to run packets that capture more easily in the GUI environment. Right now, if we want to read packet captures, we have to do so from the command line."
"It's too expensive for mid-market companies."
"Our experience with its customer support was quite challenging."
"Sangfor could improve their interface capacity on the 5100 series model and upgrade their hardware from one gig to 10 gig. This would improve the overall throughput."
"Sangfor has recently increased their prices."
"The GUI needs to be improved, lacks logic in some areas."
"Occasional issues with breaches which are dealt with expediently."
"An area of improvement for Sangfor NGAF could be in the field of reporting and logging."
"The reporting and log management could be improved."
"Sangfor NGAF could improve by refining its application control policies, especially in addressing challenges with certain types of applications."
Check Point NGFW is ranked 5th in Firewalls with 279 reviews while Sangfor NGAF is ranked 20th in Firewalls with 31 reviews. Check Point NGFW is rated 8.8, while Sangfor NGAF is rated 8.0. The top reviewer of Check Point NGFW writes "Good antivirus protection and URL filtering with very good user identification capabilities". On the other hand, the top reviewer of Sangfor NGAF writes "Affordable, easy to configure firewall with fast, responsive support". Check Point NGFW is most compared with Palo Alto Networks NG Firewalls, Sophos XG, Cisco Secure Firewall, Netgate pfSense and KerioControl, whereas Sangfor NGAF is most compared with Sophos XG, Palo Alto Networks NG Firewalls, Netgate pfSense, Fortinet FortiOS and Huawei NGFW. See our Check Point NGFW vs. Sangfor NGAF report.
See our list of best Firewalls vendors.
We monitor all Firewalls reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.