Try our new research platform with insights from 80,000+ expert users

Cisco Catalyst SD-WAN vs Forcepoint Next Generation Firewall comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Sep 16, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
5.8
Fortinet FortiGate offers cost-effective, robust security, reducing expenses, enhancing efficiency, easy implementation, quick ROI, and improved network management.
Sentiment score
6.4
Organizations see significant ROI with Cisco Catalyst SD-WAN through cost reduction, improved efficiency, and enhanced reliability within 12 months.
Sentiment score
6.0
Forcepoint Next Generation Firewall is praised for cost-efficiency, reducing expenses, staffing needs, and enhancing overall cybersecurity management.
Clients are now comfortable and not wasting productive hours on IT support.
Managing Director at a manufacturing company with 10,001+ employees
The automation part is giving us a cost benefit and speed; we can react faster.
BDM Fortinet & BDM Teamlead at Exclusive Networks
It's a very useful tool to mitigate and protect your enterprise.
Staff Infrastructure & Security Engineer at Mozn Systems
They are now back to do that with the remainder of their company, so they've realized the value in 12 months and are willing to invest in the remainder of their organization.
Information Technology Consultant at Island Networks
Cybersecurity ROI could be $1 or $100 million, depending on the risk of data behind it.
Sales Manager at Mega tech S.A
It is easy and offers different solutions for each solution type with small, mid, and large scale options available.
Senior Network Engineer at Anthology
I did see a return on investment with Forcepoint Next Generation Firewall, as mentioned by the efficiency improvements and the metrics related to how much I cut investigation time, the number of incidents, and the ease of making changes or pushing new configurations.
Cybersecurity Engineer at a tech consulting company with 51-200 employees
 

Customer Service

Sentiment score
6.6
Fortinet FortiGate's customer service is generally praised for responsiveness, though some users experience delays in critical situations.
Sentiment score
7.4
Cisco Catalyst SD-WAN support is praised for responsiveness and expertise, though occasional outsourced support delays are noted.
Sentiment score
5.9
Forcepoint Next Generation Firewall support faces delays and mixed reviews, with appreciated expertise but needs improvement in speed.
The quick resolution of issues with Fortinet FortiGate is due to the support of the company and the fact that the equipment is easy to work with.
IT Manager at a consultancy with 10,001+ employees
I would rate the technical support for Fortinet FortiGate a ten out of ten.
NAC Support at Rah Infotech Pvt Ltd
As a solution provider, when I encounter problems, I connect directly with Fortinet support, and they provide solutions within a very short time.
Manager, Information Technology Operation/Presales at TechMonarch
The principal third-level support is very good.
Technology supervisor at a non-profit with 1-10 employees
I would consider Cisco support a 10 out of 10.
Information Technology Consultant at Island Networks
I would rate Cisco's support, their customer service, and technical support as excellent.
Solution Architect at Sonda S.A.
Unlike Fortinet where you can escalate an issue and quickly get responses from the development team, Forcepoint's process seems slow and challenging.
Sales Manager at Mega tech S.A
TAC engineers are very experienced and troubleshoot issues within the expected timeframe with no problems.
Senior Network Engineer at Anthology
Technical support is sometimes slow to respond, and it takes longer to resolve issues.
Head of IT Department at Mana
 

Scalability Issues

Sentiment score
7.1
Fortinet FortiGate is scalable and popular for SMEs but requires careful design and may incur scaling costs and licensing constraints.
Sentiment score
7.4
Cisco Catalyst SD-WAN is scalable, versatile, and preferred for businesses, despite occasional licensing or deployment complexities.
Sentiment score
7.3
Forcepoint NGFW excels in scalability, supporting diverse enterprises with seamless expansion, SD-WAN capabilities, and efficient traffic management.
They scale up really well from smaller models like the FortiGate 40 and 50 to bigger sites with the FortiGate 100 for more throughput - up to enterprise datacenters.
IT Manager at Daltons Limited
The variation comes in terms of the interfaces and throughputs, but from a security perspective, you get the same benefit, irrespective of whether you have an entry-level unit or an enterprise.
Cewa Solutions Architect at a tech services company with 11-50 employees
We determine sizing based on multiple factors: number of users, available links, traffic types, server count, services in use, and whether services will be published.
General Surgery Specialist at Helwan University Cairo
Cisco SD-WAN is highly scalable and can be expanded to more than 10,000 sites.
Technical Consultant at Vertex Techno Solutions (B) Pvt Ltd
The ease of configuration and features like zero-touch provisioning enhance the scalability of Cisco SD-WAN, especially in disaster recovery situations.
Engineer at Routz
It is done through static whitelisting of the IPs, which is not a scalable solution since IPs can change at any time.
Network Manager at HPCL
I can have one management node similar to Palo Alto Panorama, with multiple nodes covering different sites, data centers, or zones.
Cybersecurity Engineer at a tech consulting company with 51-200 employees
There are restrictions in the firewall manager and limitations when deploying for cloud environments.
Head of IT Department at Mana
Forcepoint Next Generation Firewall is scalable and can grow with my organization's needs.
Cyber Security Specialist at a comms service provider with 501-1,000 employees
 

Stability Issues

Sentiment score
7.7
Fortinet FortiGate is praised for its stability, with effective long-term performance and improvements in newer firmware versions.
Sentiment score
7.4
Cisco Catalyst SD-WAN is highly stable and reliable, with minor update bugs overshadowed by robust performance and industry approval.
Sentiment score
7.9
Forcepoint Next Generation Firewall is stable and reliable, but complex deployments may face occasional instability requiring configuration adjustments.
We're experiencing 99.999% availability consistently.
Manager, Information Technology at a consumer goods company with 11-50 employees
I would rate the stability of Fortinet FortiGate a ten out of ten.
NAC Support at Rah Infotech Pvt Ltd
Currently, we are experiencing a general outage of one of the main internet service providers of the Dominican Republic, and we have not been impacted in our operations because with SD-WAN, we have another internet service provider and we are working with the second WAN connection without any disruption.
CISO at a financial services firm with 1,001-5,000 employees
While some software-related issues and bugs were encountered, they did not cause the whole environment to crash.
Engineer at Routz
A simple issue in the control connections between the fabric causes numerous complexities.
Network Manager at HPCL
It has many freezes for no reason.
Cyber Security Specialist at a comms service provider with 501-1,000 employees
 

Room For Improvement

Fortinet FortiGate needs enhanced UI, simplified licensing, improved performance, reporting, third-party integration, and expanded automation features.
Cisco Catalyst SD-WAN needs improvement in pricing, integration, support, user-friendly interfaces, cloud compatibility, documentation, and enhanced security.
Forcepoint Next Generation Firewall requires a friendlier interface, better support, flexible licensing, and enhanced integration with comprehensive documentation.
These sessions should be around five to ten minutes long, allowing users and partners to quickly grasp the information without disrupting their daily tasks.
Managing Director at a manufacturing company with 10,001+ employees
The solution should be able to implement machine learning and analytics of all the logs for threat detection and protection.
Senior Systems Engineer at Caribbean Development Company
It would be better for customers to get immediate replacements even with a standard subscription.
Director at a tech services company with 11-50 employees
Now, they change frequently, making it difficult to obtain long-term support.
Technology supervisor at a non-profit with 1-10 employees
Including more features like integrating with Splunk for monitoring vulnerabilities would help eliminate the need for other SOC solutions.
Technical Consultant at Vertex Techno Solutions (B) Pvt Ltd
The negative, or the downside of Cisco is the knowledge base; you need to be a little bit more tech-savvy and network-savvy to work with Cisco, while Juniper is a lot more user-friendly from what I can see, especially in terms of configuration and any kind of roll back.
Information Technology Consultant at Island Networks
Fast response and efficient handling of issues, similar to how Fortinet responds, would be great.
Sales Manager at Mega tech S.A
AI improvements could be beneficial, as having AI capabilities has become an important checkmark feature.
CEO at a comms service provider with 11-50 employees
I recommend that additional features be included in a single license to avoid the need for extra licensing costs.
Head of IT Department at Mana
 

Setup Cost

Enterprise buyers find Fortinet FortiGate costly initially, but cheaper overall, despite some high renewal and setup costs.
Cisco Catalyst SD-WAN is costly but valued for quality; pricing involves complex subscription-based hardware and software expenses.
Forcepoint Next Generation Firewall offers varied, competitive pricing, with costs influenced by licensing models, support, and selected features.
Last year, I renewed the support for three years, which can sometimes be expensive but depends on the security benefits and how it helps us.
Network & System Admin at Invoke Studios
It offers cost savings as it is generally cheaper than the competition.
IT Infrastructure Architect at Apotek 1
It is about 20% cheaper.
Network Security Engineer at TD SYNNEX
Its pricing is justifiable due to the comprehensive solution it offers.
Technical Consultant at Vertex Techno Solutions (B) Pvt Ltd
It is also relatively cost-effective for smaller businesses when using the Meraki version.
Engineer at Routz
The pricing of Cisco Catalyst SD-WAN is rated between eight and nine out of ten, where ten is the most expensive.
Technology supervisor at a non-profit with 1-10 employees
The costs can be high since additional features require separate licenses.
Head of IT Department at Mana
In terms of pricing, I would place Forcepoint in the middle when compared to other firewalls like Fortinet and Palo Alto.
Sales Manager at Mega tech S.A
 

Valuable Features

Fortinet FortiGate provides robust, flexible security solutions with key features like web filtering, SSL VPN, SD-WAN, and centralized management.
Cisco Catalyst SD-WAN provides robust security, efficient management, and scalability for enterprises with its comprehensive, automated networking solutions.
Forcepoint Next Generation Firewall provides robust security features, scalability, and user-friendly management for efficient threat prevention and network segmentation.
These features help reduce our downtime, manage the ISPs, and deploy SLAs for all the website traffic.
Head IT at Burraq Cyber Security Solutions
The most valuable feature of FortiGate is FortiView which provides proactive monitoring.
General Manager Group IT at DART GLOBAL LOGISTICS PTE. LTD.
We got a firewall and gave an SSL VPN to my client to connect to their servers, after which, such kind of activities involving ransomware attacks stopped.
Owner at Mindware Computer Solutions
It also provides robust security features, including port security, analysis, mirroring, and multiple other security solutions.
Technology supervisor at a non-profit with 1-10 employees
Cisco Catalyst SD-WAN has integrated security features which include base firewall, URL filtering, IPS, and secure segmentation.
Solution Architect at Sonda S.A.
Integration capabilities provide comprehensive security.
Technical Consultant at Vertex Techno Solutions (B) Pvt Ltd
Forcepoint Next Generation Firewall has impacted my organization positively by making it very easy to work and offering a more competitive price compared to other vendors.
Cyber Security Specialist at a comms service provider with 501-1,000 employees
Forcepoint Next Generation Firewall has positively impacted my organization by providing always-on perimeter security.
Responsabile System and Security at a energy/utilities company with 501-1,000 employees
Strong network segmentation is my favorite feature that Forcepoint Next Generation Firewall offers.
Cybersecurity Engineer at a tech consulting company with 51-200 employees
 

Categories and Ranking

Fortinet FortiGate
Sponsored
Ranking in Software Defined WAN (SD-WAN) Solutions
1st
Ranking in WAN Edge
1st
Average Rating
8.4
Reviews Sentiment
6.9
Number of Reviews
580
Ranking in other categories
Secure Web Gateways (SWG) (2nd), Firewalls (1st), Intrusion Detection and Prevention Software (IDPS) (1st), ZTNA (1st), Unified Threat Management (UTM) (1st)
Cisco Catalyst SD-WAN
Ranking in Software Defined WAN (SD-WAN) Solutions
2nd
Ranking in WAN Edge
2nd
Average Rating
8.0
Reviews Sentiment
6.7
Number of Reviews
98
Ranking in other categories
Network Management Applications (5th)
Forcepoint Next Generation ...
Ranking in Software Defined WAN (SD-WAN) Solutions
9th
Ranking in WAN Edge
8th
Average Rating
7.6
Reviews Sentiment
6.6
Number of Reviews
49
Ranking in other categories
Firewalls (21st)
 

Mindshare comparison

As of January 2026, in the Software Defined WAN (SD-WAN) Solutions category, the mindshare of Fortinet FortiGate is 13.9%, down from 20.1% compared to the previous year. The mindshare of Cisco Catalyst SD-WAN is 11.2%, down from 15.9% compared to the previous year. The mindshare of Forcepoint Next Generation Firewall is 2.3%, up from 1.9% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Software Defined WAN (SD-WAN) Solutions Market Share Distribution
ProductMarket Share (%)
Fortinet FortiGate13.9%
Cisco Catalyst SD-WAN11.2%
Forcepoint Next Generation Firewall2.3%
Other72.6%
Software Defined WAN (SD-WAN) Solutions
 

Featured Reviews

Vasu Gala - PeerSpot reviewer
Manager, Information Technology Operation/Presales at TechMonarch
A stable solution with an intuitive interface and quick customer service
I have been working with Fortinet FortiGate, WatchGuard, Sophos, and SonicWall. I'm not as comfortable with SonicWall because of their UI and limitations. I prefer Fortinet above all other options. When it comes to configuration, I am confident in my ability to handle various tasks, including creating policies such as firewall rules, web policies, and application policies. Additionally, I can configure VPNs and implement load balancing, among other tasks. Overall, I feel much more comfortable working with Fortinet. Fortinet has made significant improvements by integrating AI with firewalls for threat analysis and prevention. In the past 2-3 years, they have launched FortiSASE and SIEM, and they also provide SOC services. Both Palo Alto and Fortinet FortiGate are excellent. While Fortinet FortiGate comes at higher prices, the functionality and support justify the cost. They promptly resolve firmware issues and inform all support providers about configuration changes.
ND
Network Manager at HPCL
Faced complex visibility and policy challenges but have improved basic traffic routing control
I have found some other solutions more insightful and user-friendly as compared to Cisco Catalyst SD-WAN, but the basic SD-WAN functionality is good enough. I am using it only because it was done as a pilot project, specifically for my 60 to 70 sites. For the majority of the sites, I am using Fortinet's Secure SD-WAN solution and I found that more viable and more in alignment with my requirements. For example, there is not any Internet Service Database available in Cisco Catalyst SD-WAN intrinsically. If I want to write a policy based on applications, I am not able to write it, at least in Cisco Catalyst SD-WAN Viptela deployment that we have done, and that is fairly easy to do in Fortinet. The second issue is the logging capability. I think the visibility that Fortinet Secure SD-WAN has is not even comparable. Cisco Catalyst SD-WAN does not provide that sort of insight or control as far as traffic steering is concerned. With respect to the SLAs, I barely know which sort of SLAs are violated in Cisco Catalyst SD-WAN, so I do not have clear visibility on where the traffic is moving from at my spoke or hub locations. I believe Fortinet gives me a very clear picture of where the traffic is going. Overall visibility, whether it is data traffic or logs, is much better in Fortinet compared to Cisco Catalyst SD-WAN. The complexity of Cisco Catalyst SD-WAN Viptela is noticeable and quite complicated to configure. If something breaks, you have to involve TAC and others to fix it. On the contrary, you can work with underlays. Even if your IPsec overlay tunnel is down, it does not impact your production. Thus, we find Fortinet's solution significantly better than Cisco Catalyst SD-WAN solution. I have used Application-aware Routing in Cisco Catalyst SD-WAN. However, I found it to be very complicated, especially regarding policy writing. For my breakout of VC traffic, we had to write a bunch of IP addresses for Zoom, Webex, and others. Presently, it can only identify Webex as an application, and I highly doubt whether there is any application identification for Zoom and other platforms, as we were not able to find it during our implementation. It is done through static whitelisting of the IPs, which is not a scalable solution since IPs can change at any time. Overall, the application-aware routing policies are not as flexible and scalable as the Internet Service Database feature of Fortinet provides. The struggles encompass policy writing, logging capabilities, traffic visibility, and complex configuration. There is also the issue of load balancing. We have faced considerable challenges with traffic load balancing between the links. Although the SLA targets are configurable, understanding how traffic flows is challenging, making troubleshooting exceedingly difficult. Overall, I find it a quite complicated solution with not that much operational usability.
reviewer2774055 - PeerSpot reviewer
Cybersecurity Engineer at a tech consulting company with 51-200 employees
Improved network segmentation has reduced lateral movement while the interface still needs modernization
For threat prevention, I noticed on another customer that there were repeated scanning and exploit attempts against some public-facing service running on HTTPS. I configured Forcepoint Next Generation Firewall to handle IPS by enabling it with critical and high severity signatures only to reduce false positives. I turned on IP reputation filtering to filter out known malicious networks, applied rate limiting on specific services in the DMZ, and logged events centrally for correlation. As a result, exploit attempts were much less than before, being blocked before reaching the back-end servers from the firewall itself, with no performance degradation on the applications. The security team received clear and actionable logs that were centralized, so they knew what was happening all the time. Strong network segmentation is my favorite feature that Forcepoint Next Generation Firewall offers. The policies are very deterministic and readable, and it has excellent east-west blocking and least privilege architecture. Application awareness identifies traffic beyond just the port itself; I can identify the application using a specific port and block risky applications even if they use allowed ports, which is great for environments with shadow IT. The integrated threat prevention is also very good, with IPS featuring well-tuned signatures and reputation-based filtering that blocks known bad actors before they can touch any applications. It supports both IPsec and SSL VPN tunnels, along with site-to-site, client-to-site, and hybrid cloud links, integrating well with Active Directory and LDAP. Additionally, centralized log management and reporting are very actionable and structured, with clarity in the policies for auditing. Overall, its stability and reliability are commendable. A real example of how Forcepoint Next Generation Firewall's readable policies and application awareness features made my work easier was fixing a flat network problem without breaking actual applications. I inherited an environment where users, application servers, and databases were loosely segmented, with port-based and messy firewall rules. Security audits flagged lateral movement risks, and application owners were scared of outages if I tightened security too much. Forcepoint Next Generation Firewall made it easy by providing very easy-to-read and logical policies. I built policies that are clear, showing communications from the user zone to the application zone to specific applications, or from the app zone to the database zone, using only required database protocols. By default, I applied a deny rule between zones unless explicitly allowed by the readable rules I implemented. The policy view clarified who talks to whom, which rules exist, why they exist, and the business function they support, effectively stopping port abuse. Security posture has definitely improved greatly since using Forcepoint Next Generation Firewall. From a flat or semi-flat network, I now have clear zone-based segmentation, with increased operational efficiency. The admins using the firewall have rules that are easy to read and intent-based, making changes easier to review and approve. There is less fear that one wrong rule could break production and fewer outages caused by security changes, without hidden matches or rule shadowing surprises. Clear hit count visibility helps me clean unused rules, leading to much fewer outages caused by changes on the firewalls. The centralized log management with supported log types provides better visibility for the SOC team and the SIEM team, as Forcepoint Next Generation Firewall sends very easy-to-parse and search clear logs to the SOC team. I did see measurable, defensible results after using Forcepoint Next Generation Firewall, including fewer security incidents reaching the back-end servers. This reduction is due to strong segmentation, application awareness, and IPS features, leading to a 60 to 70 percent reduction in security alerts that actually reach the servers. DMZ exploit attempts dropped to near zero, and no lateral movement incidents were detected post network segmentation. Additionally, overall SOC efficiency improved due to well-structured and contextual logs reflecting clear policy intent, resulting in a 35 to 40 percent reduction in mean time to triage. SOC analysts stopped chasing noise and false positives, as they had much clearer logs to use confidently.
report
Use our free recommendation engine to learn which Software Defined WAN (SD-WAN) Solutions solutions are best for your needs.
880,954 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
12%
Comms Service Provider
9%
Manufacturing Company
8%
Financial Services Firm
6%
Computer Software Company
11%
Financial Services Firm
11%
Manufacturing Company
8%
Comms Service Provider
7%
Manufacturing Company
11%
Computer Software Company
9%
Financial Services Firm
9%
Government
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business357
Midsize Enterprise133
Large Enterprise188
By reviewers
Company SizeCount
Small Business44
Midsize Enterprise15
Large Enterprise44
By reviewers
Company SizeCount
Small Business28
Midsize Enterprise10
Large Enterprise11
 

Questions from the Community

Which is the better NGFW: Fortinet Fortigate or Cisco Firepower?
When you compare these firewalls you can identify them with different features, advantages, practices and usage a...
What is the biggest difference between Sophos XG and FortiGate?
From my experience regarding both the Sophos and FortiGate firewalls, I personally would rather use FortiGate. I know...
What are the biggest technical differences between Sophos UTM and Fortinet FortiGate?
As a solution, Sophos UTM offers a lot of functionality, it scales well, and the stability and performance are quite ...
What do you like most about Cisco SD-WAN?
When considering the most valuable features of Cisco SD-WAN, the decoupling of self-monitoring stands out significant...
What is your experience regarding pricing and costs for Cisco SD-WAN?
The pricing of Cisco Catalyst SD-WAN is rated between eight and nine out of ten, where ten is the most expensive.
What needs improvement with Cisco SD-WAN?
More or less, it's the same with Cisco in terms of complexity and pricing, so there's not much of a difference. They ...
What is your experience regarding pricing and costs for Forcepoint Next Generation Firewall?
My experience with pricing, setup cost, and licensing is limited because I do not work with pricing, but I have exper...
What needs improvement with Forcepoint Next Generation Firewall?
Forcepoint Next Generation Firewall is overall good, but AI enabled features are not available. Many templates and AI...
 

Also Known As

Fortinet FortiGate Next-Generation Firewall
Cisco SD-WAN
Forcepoint NGFW, Stonesoft Next Generation Firewall, McAfee Network Security Platform, Intel Security Network Security Platform
 

Overview

 

Sample Customers

Amazon Web Services, Microsoft, IBM, Cisco, Dell, HP, Oracle, Verizon, AT&T, T-Mobile, Sprint, Vodafone, Orange, BT Group, Telstra, Deutsche Telekom, Comcast, Time Warner Cable, CenturyLink, NTT Communications, Tata Communications, SoftBank, China Mobile, Singtel, Telus, Rogers Communications, Bell Canada, Telkom Indonesia, Telkom South Africa, Telmex, Telia Company, Telkom Kenya
Doyle Research, Ashton Metzler & Associates
California Department of Corrections and Rehabilitation (CDCR)
Find out what your peers are saying about Cisco Catalyst SD-WAN vs. Forcepoint Next Generation Firewall and other solutions. Updated: January 2026.
880,954 professionals have used our research since 2012.