We are using their product for Internet filtering as the Internet gateway. Previously, we were using FortiGate for this purpose and replaced it with Sangfor IAM. We are also using their firewall, NGAF, for core firewalling.
Sangfor NGAF offers a user-friendly firewall solution with a strong virus database and competitive pricing. It supports SSL VPN connectivity, intrusion detection, and is known for easy deployment and integration capabilities.


| Product | Mindshare (%) |
|---|---|
| Sangfor NGAF | 1.1% |
| Fortinet FortiGate | 15.1% |
| OPNsense | 8.5% |
| Other | 75.3% |
| Type | Title | Date | |
|---|---|---|---|
| Category | Firewalls | Jun 21, 2026 | Download |
| Product | Reviews, tips, and advice from real users | Jun 21, 2026 | Download |
| Comparison | Sangfor NGAF vs Fortinet FortiGate | Jun 21, 2026 | Download |
| Comparison | Sangfor NGAF vs Netgate pfSense | Jun 21, 2026 | Download |
| Comparison | Sangfor NGAF vs Sophos Firewall | Jun 21, 2026 | Download |
| Title | Rating | Mindshare | Recommending | |
|---|---|---|---|---|
| Fortinet FortiGate | 4.2 | 15.1% | 92% | 592 interviewsAdd to research |
| Netgate pfSense | 4.3 | 8.0% | 94% | 221 interviewsAdd to research |
| Company Size | Count |
|---|---|
| Small Business | 15 |
| Midsize Enterprise | 9 |
| Large Enterprise | 9 |
| Company Size | Count |
|---|---|
| Small Business | 153 |
| Midsize Enterprise | 79 |
| Large Enterprise | 179 |
Sangfor NGAF is a comprehensive security platform providing robust network protection through its application control and detailed threat insights. While effective in preventing threats and ensuring network security, it has areas needing improvement such as real-time reporting and system support. It delivers secure internet and VPN connections, proficiently handling malware threats. However, it faces challenges with user experience, reporting capabilities, hardware scalability, and needs better third-party integration. Licensing costs are noted to be high, and there are performance variations between versions.
What are the key features of Sangfor NGAF?Sangfor NGAF is widely used across industries including education, healthcare, and finance for its reliable network security. It is favored for securing internal servers, offering robust threat protection, and managing bandwidth efficiently at a budget-friendly rate.
Sangfor NGAF was previously known as Sangfor NGAF Firewall Platform.
The Ministry of Science, Technology, and Innovation (Indonesia), Lawson, Inc. (Philippines), Universiti Sultan Zainal Abidin (Indonesia), TEK Automotive (Italy), etc.
| Author info | Rating | Review Summary |
|---|---|---|
| CIO at Indus Motor Company | 4.5 | I switched from FortiGate and Palo Alto to Sangfor NGAF for core firewalling and Internet filtering. Its integrated WAF, SD-WAN capabilities, and competitive pricing offered better ROI. I noticed integration with SIEM and SOAR is excellent. |
| Network Administrator at GC University Lahore | 4.0 | We use Sangfor NGAF for hosting applications like websites and NAT traffic; its standout feature is its comprehensive reporting, aiding in attack categorization and mitigation. However, it is costly and could benefit from hardware scalability and virtualization options. |
| Deputy Manager IT at National Insurance Company Limited | 4.0 | We primarily use Sangfor NGAF for secure internet and VPN connectivity. Its standout features include SSL VPN and URL filtering. While switching from open-source PSMs, we noticed its infrastructure dependency could improve, particularly on DNS servers. Cost-effective for public sector needs. |
| Network Engineer at INTERNATIONAL ISLAMIC UNIVERSITY ISLAMABAD | 5.0 | We use Sangfor NGAF for filtering, benefiting from its protection against ransomware and firewall attacks, and application control features. Its user-friendly interface and cost-effective license renewal make it preferable to previous solutions like Huawei and Fortinet firewalls. However, its support for YouTube and the Internet needs improvement. |
| Head of IT Governance, Cybersecurity & Network Infrastructure at Indus Motor Company | 4.5 | I find Sangfor NGAF more valuable than Cisco due to its simplicity and superior reporting capabilities. It resembles FortiGate but excels with its web application firewall features. However, it is pricey compared to its competitors. |
| Network Administrator at Chase Up | 4.0 | I use Sangfor NGAF because it is an effective firewall product with robust threat protection, valuable for IPSec and SD-WAN VPNs. Its real-time threat detection is impressive, though the setup is complex and could be simplified. |
| Chief Information Officer at Patel Hospital | 3.0 | I use Sangfor NGAF in our hospital for secure internet and application management. It offers strong confidentiality and availability, but its real-time reporting needs improvement. While Fortinet is superior, Sangfor suits budget-conscious organizations requiring less stringent security. |
| Deputy Manager at Askari Life | 4.5 | In our organization, we use Sangfor NGAF for its excellent SSL VPN feature. While we're satisfied, we seek enhancements in IPS, VPN, and security features. Having previously used software-based firewalls, we see room for improvement in these areas. |
| IT Infrastructure and Server Specialist at a consultancy with 51-200 employees | 5.0 | I use Sangfor NGAF as a stable, affordable, all-in-one security firewall. Its exceptional 24/7 support and hardware warranty are outstanding. I rate it 10/10, though I desire a home-use version. |
| Senior Manager IT at Ghandha Automobile Limited | 2.0 | I found Sangfor NGAF to be a cost-effective firewall solution with features comparable to other products. However, improvements are needed in LDAP deployment and support services. We opted for Sangfor after Fortinet no longer met our needs. |

We are using their product for Internet filtering as the Internet gateway. Previously, we were using FortiGate for this purpose and replaced it with Sangfor IAM. We are also using their firewall, NGAF, for core firewalling.
Threat detection in my previous organization, it was amazing because right after we implemented Sangfor NGAF Cyber Command, we started getting a lot of alerts that we were unaware of.
We are using application firewalling, WAF, and SD-WAN. The capabilities are mostly within the box. For example, you will get web application firewall WAF as part and parcel of this. SD-WAN is also bundled. It integrates with their SIEM and SOAR solutions very nicely. Lastly, the pricing point is very cost-efficient as well.
We will probably invest a little more time into the VDI solution - not specifically for security but for desktop computing VDI solutions.
I have been using Sangfor NGAF since 2018. I implemented their IAM. In 2021 to 2022, I implemented their firewall solution in my previous organization. And now in 2024, I have implemented their firewall at my current workplace.
It's pretty stable. Since 2018, I have never encountered any stability issues.
Scalability for any network device is not very easy in terms of vertical scalability. But if, for example, we grew and became 2000 users, we would have to go for a migration plan where you put another capable box for 2000 people and do a migration. In terms of migration, there should be no problem because the underlying architecture is the same.
The support structure is excellent locally and from China as well. In Pakistan, we don't have many principal presences, so having support from the principal team in China is great.
Positive
I was using Cisco ASA in my previous organization. In my current organization, we were using Palo Alto. The Palo Alto device was not sized properly, and it did not have a WAF capability for which we had to get a subscription. Also, it was creating a bottleneck in my network, so we had to switch.
The initial setup is very easy. I would rate it a nine out of ten.
In my deployment team, there were three people. From the principal, there was one person, and from the partner side, there were two people. So six people were involved in the deployment process.
Since the cost is pretty reasonable, it gives us a 30-35% advantage over other product solutions. So the ROI is better.
There is some difference in terms of pricing compared to Palo Alto. Sangfor NGAF is around 30% to 35% more cost-effective than other products.
I have already used Fortinet, Cisco, and Palo Alto, which are basically the mainstream players in Pakistan. I have no other products locally present in Pakistan to evaluate.
Do not compare them only from a price point. Compare them from a technical aspect as well. Do a deep-dive investigation instead of relying on sources like Gartner because their comparison is very subjective. Instead, rely on third-party testing organizations like NSS Lab and AB Test. Do the testing yourself and compare all the functionality and features.
I'd rate the solution nine out of ten.
We are hosting applications over the platform, including websites and NAT traffic from our side. Because it's deployed in our data center, which is fully operational, we have various applications hosted there, websites, FTP portals, making it quite comprehensive. Essentially, it performs all the tasks that a firewall does.
The top functionality is the reporting feature. It effectively describes attacks, categorizes them, and recommends mitigation actions. It's crucial for security administrators when dealing with attacks. This aspect is very user-friendly and easy to understand. It adds significant value to our data center operations.
The cost of licensing is very high compared to other firewalls available here. There should be improvements in hardware scalability, allowing for more storage and memory capacity. Making the solution available as a virtual appliance would be more feasible for data centers, avoiding the need for physical hardware.
The solution is very stable and has not shown any instability issues.
While the physical scalability is present with ten-gigabyte ports, the internal hardware scalability is complex and limited. It should allow for additional memory and storage for reporting purposes.
I have no experience with their technical support, as the GUI is self-descriptive and user-friendly. I haven't needed to contact them.
Positive
I have used Huawei, H3C, Cisco Firepower, and certain open-source firewalls alongside Sangfor, including Palo Alto.
The initial setup was conducted by a representative from Sangfor itself, so I have no direct experience with it.
A representative from Sangfor set up the solution for the first installation.
The licensing cost is quite high compared to other available firewalls in the market.
I have been using Huawei, H3C, Cisco Firepower, and some open-source firewalls in parallell. Additionally, I'm aware of Palo Alto's capabilities.

It is primarily used for providing secure Internet connectivity to devices, to endpoints, and to provide secure VPN connectivity to the network for remote users. That's the primary usage right now.
The VPN connectivity feature is really nice. The SSL VPN feature is really nice, and the URL filtering for Internet connectivity is really nice. That's one of the best features for us.
There is room for improvement in dependency on certain infrastructure, like the DNS dependency on the current DNS server that the company has. It should be standalone. It should not depend on any other DNS server.
I would rate the stability a nine out of ten. It is a stable solution.
I would rate the scalability an eight out of ten. It's not a ten because sometimes scalability depends on the hardware, and every hardware has limitations. So they can improve that. Otherwise, we have to purchase new hardware.
There are 200 end-users around using this solution in our company.
We used open-source PSMs. We switched to this solution because of the dependency on hardware and feature sets. The features were not as good as Sangfor's.
I would rate my experience with the initial setup a five out of ten. It is neither too difficult nor too easy. It was a bit complex.
We used the partner's support department to set it up for the first time. It was a bit difficult. The deployment process took one week.
The partners were engaged, and the technical resource of the partner in Pakistan, whom we purchased it from, was on our premises. He configured the basic rules that we required for the initial setup, license, and everything. From that period onwards, we are managing it ourselves. So, an on-site technical engineer was used. Two people are required for the deployment.
I would rate the pricing model a five out of ten, where one is expensive and ten is cheap.
We purchased one year of technical support and returned to factory support. So those were additional.
We evaluated Fortinet and Sophos. We opted for Sanfor NGAF because we are a public sector organization, so cost is very important. But we have to consider what is the best price for the requirements we require. So, we have to go through a process to get pricing from every company. If Sangfor was fulfilling our basic features, that's why it was cheaper than the other two options and provided all the features.
If it fulfills the basic features, it is cheaper than and better than, cost-effective than the other two brands, Fortinet and Sophos.
Overall, I would rate the solution an eight out of ten.

We use the solution for filtering.
The solution protects against ransomware and firewall attacks. It also offers application control features. It protects different ports for endpoints and different threats. Its interface is very good.
The support for YouTube or the Internet is not enough.
I have been using Sangfor NGAF as a user for 3 years.
I rate the solution’s stability a ten out of ten.
The solution’s scalability is good.
I rate the solution’s scalability a ten out of ten.
If there is any problem we face regarding the firewall, then we contact Sangfor and they quickly respond to us.
Positive
We have used Huawei and Fortinet firewalls before. Sangfor has low licence renewal cost compared to other servers.
The initial setup is easy and takes three hours to complete. Two people are required for the deployment.
The product is very cheap.
I rate the product’s pricing one out of ten, where one is cheap and ten is expensive.
The solution is easy to maintain. One person is enough for it. It is easy to integrate with other solutions like Active Directory and Windows server.
Sangfor has a very low cost. So, every company or organisation can easily afford this product.
Overall, I rate the solution a ten out of ten.

I think Sangfor NGAF is more valuable than Cisco products because of its simplicity and ease of management. If I compare it with Palo Alto and Cisco, both are quite complex products. And if I compare it with FortiGate firewalls from Fortinet, I have also used all these products. Fortinet and Sangfor NGAF are similar products because the applications behind the application and policy layers are almost identical.
I think Sangfor NGAF is very strong in the reporting area compared to Palo Alto and Cisco. It has much better reporting capabilities. The tool has a good web application firewall feature. Cisco and Fortinet products don't provide such rich WAF features.
The tool is expensive.
I have been working with the product for three to four years.
I am happy with the support for Sangfor NGAF. In Pakistan, local support is available from the principal vendor, and support from the Chinese team is also available. Most of the time, the local support engineers are technically skilled and capable of fulfilling all requirements.
The tool's deployment is easy.
Price-wise, I would not consider Sangfor NGAF to be a cheap product. It is an expensive firewall solution, though not as expensive as something like Palo Alto, which is costly.
However, the higher price point is justifiable given the feature set the tool provides that other firewalls may not offer in a single dedicated appliance.
From an administration perspective, Sangfor NGAF provides ease of management and straightforward steps. The overall control of the firewall is easy. I rate the overall product a nine out of ten.

I use Sangfor NGAF since it is a good firewall product with good threat protection. The product is very useful for IPSec VPNs and SD-WAN VPNs.
The most valuable features of the solution stem from the security center or SOC-related feature, which is very good since it detects threats in real time and quickly. The tool also reacts on a timely basis.
The setup phase is quite complex. The setup process could be easier.
I have been using Sangfor NGAF for six months.
It is a stable solution.
It is a very scalable solution. I can't say that the tool is as scalable as Fortinet FortiGate's latest version.
There are around 3,000 users of the tool in my company.
The solution's technical support was very good, cooperative, and responsive.
I am satisfied with the support team.
The product's initial setup phase was not as straightforward as Fortinet FortiGate. As a first-time user, if you get to see the setup phase for the first time, you can do it easily the second time. The setup phase is not very hard. The tool is very easy to use.
During the deployment, the first step is to upgrade and activate the license of the product and configure interfaces, zones, objects, and policies, along with NAC and DMZ policies. The tool also helps with static routing to ensure connectivity between the head office and stores. The aforementioned steps were taken to make the product operational.
Sangfor NGAF is a cheaply priced product, especially if I consider the previous product that was used in my company.
Firewall products function with licenses. Without licenses, the tool's main features, like intrusion prevention, web access firewall, DNS, or IDS, will not be activated if you don't buy the license.
Speaking about how Sangfor NGAF improved our company's network performance, I would say that I had installed the product at our head office, where we use it for internal policies and DMZ zones. It is a very useful firewall. Previously, we used Fortinet products, but now, Sangfor NGAF is fully operational in our network, and we use it to block ISPs and the internet and manage rules or traffic, like DMZ to LAN. Other VPNs like IPSec VPNs work in Sangfor, and it serves as a very good feature in the tool. I even loved the SD-WAN VPN feature of the tool.
The application control feature helps manage our company's network traffic in a very good manner. I have been using the tool for the last six months, and I am quite satisfied with the product's performance.
Speaking about the intrusion prevention system of the tool, I have some logs that can state the source of the attacks and which have been blocked in a timely manner by the product. The tool's threat management capabilities and ability to deal with DDoS attacks are good and very useful.
The deployment affected our company's team's workload since the team was available at the premises of the organization during the deployment phase.
I recommend the product to those who want to buy it to protect and manage their networks with the product. It is quite a useful product.
I can't speak much about the benefits of the tool since everyone uses the product for their own needs. In terms of benefits, Sangfor NGAF's price is better than Fortinet FortiGate.
I rate the tool an eight and a half out of ten.

As a hospital with 500 users, we use Sangfor NGAF for secure internet connections, VPN access, and protecting our cloud applications. It also helps manage our in-house applications, includes WAF for added security, and ensures email security for our communication needs.
In our hospital, Sangfor NGAF works well for us in terms of ensuring confidentiality and availability, which are crucial in the healthcare industry.
Sangfor could improve by providing better real-time reporting, as the current reports don't offer the level of detail we need, especially for runtime insights. We find ourselves relying on other applications for this purpose. While performance is okay for our healthcare setup with 500 desktops, it might need closer consideration for industries like finance with more specific requirements.
I have been working with Sangfor NGAF for two years.
It is a stable solution.
Sangfor is not highly scalable. If we need better performance or additional features, we have to replace the entire unit with a higher-capacity model. It has limitations, like only four available WAN ports, and expanding requires adding cards. Currently, we use another router for internal DMZ.
I'm not entirely satisfied with Sangfor's technical support. There have been instances where the local partners lacked the required expertise, and I had to reach out directly to Sangfor for assistance. The limited number of experts in the market and the availability issues contribute to the challenges. While the principal company has good resources, they are often engaged with other customers. Overall, I would rate the support as a five out of ten.
Neutral
While I have experience with Fortinet and find its feature set superior, Sangfor is a good solution for organizations with budget considerations. For high-security industries like finance, I would still recommend Fortinet or other top-tier options.
The initial setup was simple. Deployment of Sangfor typically takes a week, depending on the policies and nature of the business. We usually involve two to three people—a network administrator and an expert in the specific firewall. The vendor's expertise is also essential for a smooth deployment. Maintaining the solution is quite easy.
Sangfor falls into the mid-range for pricing, between more affordable options and pricier alternatives like Fortinet. The pricing is slightly higher than the support costs but remains reasonable, with yearly licensing.
Overall, I would rate Sangfor NGAF as a six out of ten.

We use SSL VPN and other networking features. Our organization is not very big.
SSL VPN is the best feature.
The product must provide more IPS features. It should also provide more VPN and security features.
I have been using the solution for almost four years.
The tool is very stable. We have not faced any issues in the past four years. We never had to reboot or restart it. It never got stuck. We did not see a single fault in four years. I rate the stability a ten out of ten.
The tool is very scalable and customizable. It fulfills all our requirements. I rate the scalability a ten out of ten. More than 200 people in our organization use the solution. We plan to increase the usage as our company and its requirements grow.
The technical support is very good. Sangfor’s local partners are very friendly.
Positive
Previously, we used software-based firewalls.
We faced some problems initially due to some technical issues and configurations. The product has been working fine for four years. We’re happy with it. The initial setup is moderately difficult. I rate the ease of setup a five out of ten.
The configuration and customization took seven to ten days. We have a Sangfor engineer working remotely and a Sangfor partner on-premise who coordinates with the engineer for configuration and testing purposes.
The product is very cost-effective compared to other brands or vendors. I rate the pricing a five out of ten.
I recommend the solution to friends. We are very happy with it. Overall, I rate the tool a nine out of ten.

We use Sangfor NGAF's next-generation firewall as a security firewall which includes a web application firewall, web app filtering, and URL filtering. It also helps us defend against botnet attacks and similar threats.
In my office, there are about three people who are involved in the direct use of it, although not too many others know about the firewall yet because it's a new product.
The absolute best part of Sangfor NGAF is their support. It's a 24/7 support channel, and the last time I requested their assistance I got a reply within three minutes. They helped solve the problem immediately.
Sangfor also gives you a warranty for any issues or defects with their hardware. If you find any issue, they will replace the hardware within five working days. We send any hardware that is faulty to our local country partner and they will do the RMA.
When it comes to deployment environments, I like that you have options. If you want a hardware firewall, then you can use their hardware. Conversely, if you want a cloud firewall, then they can provide that, too.
I would be happy if Sangfor developed a firewall designed specifically for home use, as well as for small businesses such as clinics and so on. A household version of the Sangfor firewall for your personal computer or laptop would be ideal, in my opinion.
I have used Sangfor NGAF for about four years.
Sangfor NGAF is very stable and comes with a hardware warranty where they will replace the defective hardware within five working days. So if something goes wrong, you don't have to fix it, but instead you can just get it replaced.
Sangfor have divided their firewalls into several categories, so you have multiple options with regard to scalability and how many users you need to account for.
For example, if you've got low bandwidth requirements, you might want to deploy the 5200 model. But as you go into higher bandwidths, you will have to deploy the 5300 model or higher.
My recent experience with their support was wonderful. I had an error come up on my Google Chromecast device, where it would simply restart over and over again because it was blocked on the firewall.
When I opened a ticket with Sangfor support to help solve this problem, one of their support members called me within three minutes and asked about the issue. They discovered what was wrong and resolved it. From this experience alone, I can say their support is the very best.
Positive
It's very easy to set up. They provide support services on a 24/7 basis, and with this support it makes everything easier to install, configure, and troubleshoot. I would give them a perfect score for support.
If you know you have around 200+ computer users on your network, then the Sangfor NGAF 5200-F-I model would be the minimum recommended model for that amount of users. This model includes modules for packet filtering, deep packet inspection, malware scanning, DSCP filtration, and many other features.
The 5200-F-I model costs around $5,000 once-off, and then around $1,000 per year for the license renewal for both the hardware and software. The $5,000 payment includes deployment, all the modules, the initial license costs till the next year, and deployment support calls. It covers basically everything to get started, and I would rate the pricing as 5/5 stars in terms of competitiveness.
When evaluating Sangfor NGAF with its competitors' products, the first thing I would note is that the other solutions are not likely to fulfill their hardware warranties within five business days, as Sangfor does.
Another advantage of Sangfor is cost. Many other firewall companies offer their products at a high licensing cost, and the modules that come with these solutions are also very costly. In contrast, the Sangfor firewall is not only highly affordable to procure, but it's also very cheap to deploy.
Finally, when you compare Sangfor with Fortinet, for instance, there is a big difference when it comes to configuration. With Fortinet, you typically have multiple different products to configure for various purposes, such as FortiEDR and FortiAnalyzer. All these products from Fortinet have to be configured with the different algorithms and modules that they suggest. But in Sangfor NGAF, everything is in one window.
I would rate Sangfor NGAF a ten out of ten.

Sangfor NGAF offers the same features as any other firewall product in the market. In terms of the valuable feature, I would say that the low cost the product offers was one of the major deciding factors when choosing the product in our company.
There are some difficulties with the deployment of the LDAP part in Sangfor NDAF, making it an area of concern where improvements are required.
The support offered by the product has certain shortcomings where improvements are required. The knowledge levels and response time of the support team need improvement.
I have been using Sangfor NGAF for three months. I am the head of the IT team in my company. My team members use Sangfor NGAF.
Considering that my company has been using the product for only a few months, I rate the product's stability a five out of ten.
The scalability offered by the product is neither bad nor good.
Around 150 users of the product, and it is double in number if you consider the handheld devices in my company.
The services from the solution's technical support have not been as satisfying as my company expected. I rate the technical support a three out of ten.
Negative
I have experience with Fortinet. My company chose Sangfor NGAF after Fortinet ran out of its capability to offer support, considering how the tool has become too old.
I rate the product's deployment phase a five on a scale of one to ten, where one means it is a difficult process and ten means it is an easy process. The deployment phase can be difficult to manage in certain places, while in some other areas, it can be easy.
The solution is deployed on an on-premises model.
I rate the product price as one on a scale of one to ten, where one is low price and ten is high price.
As there are some problems with the product partner, my company has not been able to fit in the web-filtering functionality of the product to meet our needs.
So far, the performance and reliability of the product have supported our company's critical network traffic.
I don't recommend the product to others who plan to use it, considering that the tool has problems in areas like support and deployment.
I rate the product a four out of ten.