Try our new research platform with insights from 80,000+ expert users

Citrix SD-WAN [EOL] vs Fortinet FortiGate comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Dec 29, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Citrix SD-WAN [EOL]
Average Rating
8.2
Reviews Sentiment
7.4
Number of Reviews
22
Ranking in other categories
No ranking in other categories
Fortinet FortiGate
Average Rating
8.4
Reviews Sentiment
7.2
Number of Reviews
317
Ranking in other categories
Firewalls (2nd), Software Defined WAN (SD-WAN) Solutions (1st), WAN Edge (1st)
 

Featured Reviews

Rohit Ghorpade - PeerSpot reviewer
A scalable solution for MCN controller but lacks technical supports, upgrades
There are a few things that can be improved, are domain-based routing and the slowness of virtual parts, and it may be due to the wrong configuration, which we have been unable to find out. Previously, we faced some issues with the slowness part. Apart from that, feature like end gateway level antivirus. We are currently using a NetFlow proxy to establish a virtual position for the NetFlow. Our current environment has many use cases, but we are not using them on the Citrix SD-WAN. When I navigate the NCL part, it involves configuration. I want to highlight this disadvantage. Sometimes, when we push the configuration, it tries to push it to all branch locations. This process takes a lot of time, nearly 30 minutes, to push a single change from the NCL. Overall, I don't think Citrix meets our use cases what we have. This is based on my feedback after using it for the past year and working on this Citrix SD-WAN. However, from my experience, it is the worst solution I have seen. There's no domain-based routing, which is horrible. That's why we are moving to other products. We have checked our use case requirements with Fortinet, Palo Alto, and they meet them. I will consider the PoC or another OEM. There are many things in the area you need to be prompt, like the automation part. If any link or device goes down, alerting notification, etc. We need to perform and highlight so many things to your management. This should be improved.
EhabAli - PeerSpot reviewer
Efficient, user-friendly, and affordable
In the past, NSS Labs was utilized to test files and verify the numbers and datasheets. It would be beneficial to have an organization or testing lab that can verify the numbers in our datasheets since changes are frequently made, which can be inconvenient for review. For instance, when comparing different competitors such as Forcepoint, Palo Alto, and Check Point, the throughput or numbers in the datasheet may be lower than the actual numbers. Conversely, Fortinet typically reports very high numbers, but they cannot be replicated in the real world. Therefore, it would be advantageous for them to partner with a neutral testing organization such as NSS Labs to validate these numbers, thus providing more credibility and comfort to everyone regarding the accuracy of the datasheets. For the migration, everyone has a firewall in use and I am selling Fortinet. Typically, I am replacing another firewall. Previously, there was a tool available to convert configurations from one firewall, such as Palo Alto, to Fortinet, but this tool is no longer free. If it could be made free again, it would be very beneficial. This tool shows a lot of promise and is very good. Making it free would help many companies deliver their products in a more efficient and integrated way. It would also be more valuable to include the tool with the firewall package or license instead of having to pay extra for it. Paying extra puts more pressure on small companies to deliver the firewall and complete the configuration, especially if they have hundreds or thousands of policies. It's very painful to move through these policies line by line. The stability has room for improvement. When it comes to Secure SD-WAN, everything is fine. They are going the right way. SD-WAN is very promising. They can provide the SD-WAN solution separately, but they will not take this approach because even the smallest firewall can support the features, so there is no need to have a separate service or appliance. They are following the right steps, and there is nothing to be improved. Feature-wise, I'm really satisfied with the new release, and the features they have added. For now, it's fine.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"They have a zero downtime failover mechanism, where, when there's a link failure or a link weakness, or bad link conditions, they provide the ability to fail back seamlessly."
"The zero-touch deployment is most valuable for us."
"The tool is quite cost-effective because it replaces the need for MPLS, which is a bit expensive...Citrix SD-WAN doesn't need much maintenance."
"The most valuable feature of Citrix SD-WAN is customization. You are able to customize the solution to your needs."
"It lowered our Internet costs and gave me the flexibility to choose providers based on each location's connectivity."
"The best feature is the backup capability, where all of the users' computers are tied into a central data repository."
"The reliability of connectivity is most valuable."
"The solution's most valuable feature is load balancing."
"The license management is very valuable. You can get a new license each year, or you can enroll every two to four years. You can get the logs, and you will get the information on the risk in your network and the entire organization. With this information, you can take action on your actives, computers, or devices. You can bring your own device as an SSE."
"The next-gen features, the unified threat management capabilities are something that just about everybody is interested in at this point."
"I think that the UTM features are the most value, as it truly protects my infrastructure."
"The IPsec tunnels are very easily created, and quite interoperable with devices from other vendors."
"The Intrusion Prevention System and the web filtering are both working well."
"We have found it to be very reliable and that's why our teams and various users in our company use it as our main firewall every day."
"FortiGate firewalls are easy to manage through a user-friendly web interface. They also have advanced features like DDoS and DLP. However, I wouldn't recommend enabling all of these features on one device because it can cause performance issues."
"Using this product makes the VPN seamless and almost invisible to me in the sense that I don't have to think about it."
 

Cons

"The only improvement for Citrix SD-WAN would be to lower its cost."
"There are a few things that can be improved, are domain-based routing and the slowness of virtual parts, and it may be due to the wrong configuration, which we have been unable to find out."
"Citrix SD-WAN does not have the SD-WAN with one optimization in a single license. Other competitors have this option and it should be added to this solution."
"The price could be improved, it's an expensive solution."
"Even though the monitoring is pretty good, there is some room for improvement there."
"Enhancements are needed to improve the stability."
"Overall, network security and next-generation firewall features are areas that they can improve on."
"The communication around the life cycle would have been really helpful. The main issue we have had is related to the life cycle because some of the things that we are using were discontinued. They were discontinued within a year after we had purchased it, which is a bit painful. If we had known that, we would've made some other decisions."
"Fortinet FortiGate could improve if it had a cloud-managed solution."
"The main aspect of FortiGate that could be improved is load balancing. Our management team does not want to buy another appliance for only load balancing."
"With the addition of some features, it is possible that FortiGate can be used in all verticals."
"WAN load-balancing could be a lot better at detecting when a link is poor or inconsistent, and not just flat out dead."
"The firewall engine is not so strong as of now, in my opinion... My second concern is that, while they have Zero-day vulnerability and anti-malware features, the threat engine needs to be strengthened, its efficiency can be increased."
"The pricing could be reduced or include the first year warranty."
"The user interface could be improved."
"The command line is complicated, and the interface could be better."
 

Pricing and Cost Advice

"The price is relatively expensive."
"As NetScaler is now, I find it quite pricey."
"The license was a one-time purchase. It's expensive."
"Citrix SD-WAN is quite an affordable product."
"It is a bit expensive. A cheaper product would be good, but everybody likes things to be cheaper. We bought the devices up front, and then we pay for the annual support."
"The price of the subscription should be cheaper."
"I'm not quite sure of the price ranges. Roughly, the hidden devices can scale up to $20K for one appliance. However, the branch CPs are USD $1,000 to $2,500."
"I believe that Citrix SD-WAN is a good investment, but I do not have the information to be more specific."
"Fortinet is competitive price-wise."
"Fortinet FortiGate is reasonably priced."
"The licensing scheme of Fortinet is better than Cisco. It is more logical."
"The price of Fortinet FortiGate is better than Cisco, Check Point, and Palo Alto. In terms of pricing, it's probably a better-priced firewall solution overall."
"​We saved a bundle by not needing all the past appliances from an NGFW.​"
"Fortinet FortiGate's price can be reduced."
"Our licensing costs are on a yearly basis."
"It is affordable. Palo Alto is much more expensive than Fortinet."
report
Use our free recommendation engine to learn which Software Defined WAN (SD-WAN) Solutions solutions are best for your needs.
831,265 professionals have used our research since 2012.
 

Comparison Review

it_user216600 - PeerSpot reviewer
Jan 3, 2016
Sophos UTM vs. Fortinet FortiGate
I have used both Sophos and Fortinet products in production and I have found the Sophos UTM appliances (hardware and virtual) to be a better fit most of the time -- with a few caveats which I will touch on below. In both instances, the transition from TMG will be mostly straightforward. The main…
 

Top Industries

By visitors reading reviews
Computer Software Company
24%
Real Estate/Law Firm
8%
Financial Services Firm
8%
Manufacturing Company
6%
Educational Organization
22%
Computer Software Company
14%
Comms Service Provider
6%
Manufacturing Company
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about Citrix SD-WAN?
It lowered our Internet costs and gave me the flexibility to choose providers based on each location's connectivity.
What is your experience regarding pricing and costs for Citrix SD-WAN?
It is on the expensive side. I would give it an eight out of ten in terms of costliness. In my region, the approximate cost for the Citrix SD-WAN license is around $150 per user per year. However, ...
What needs improvement with Citrix SD-WAN?
The solution's licensing model could be improved. Citrix SD-WAN is a good product from a technical point of view. However, when you compare its licensing with the prices of competitors, you will se...
Which is the better NGFW: Fortinet Fortigate or Cisco Firepower?
When you compare these firewalls you can identify them with different features, advantages, practices and usage at large. In my opinion, Fortinet would be the best option and l use Fortinet too...
What is the biggest difference between Sophos XG and FortiGate?
From my experience regarding both the Sophos and FortiGate firewalls, I personally would rather use FortiGate. I know the firewalls change every 5 to 7 years as stated but you really do need to upg...
What are the biggest technical differences between Sophos UTM and Fortinet FortiGate?
As a solution, Sophos UTM offers a lot of functionality, it scales well, and the stability and performance are quite good. The most valuable features for me are their web and email filtering. I wou...
 

Also Known As

Citrix CloudBridge, WOC, NetScaler SD-WAN
FortiGate 60b, FortiGate 60c, FortiGate 80c, FortiGate 50b, FortiGate 200b, FortiGate 110c, FortiGate, Fortinet Firewall
 

Learn More

 

Overview

 

Sample Customers

AIDS Healthcare Foundation, Cornerstone Home Lending Inc., Dallara, ecVision, Essar, Eurofred, Groupe Promutuel, HMSHost Corporation, Royal Caribbean Cruise Lines Ltd, Royal Caribbean International
Amazon Web Services, Microsoft, IBM, Cisco, Dell, HP, Oracle, Verizon, AT&T, T-Mobile, Sprint, Vodafone, Orange, BT Group, Telstra, Deutsche Telekom, Comcast, Time Warner Cable, CenturyLink, NTT Communications, Tata Communications, SoftBank, China Mobile, Singtel, Telus, Rogers Communications, Bell Canada, Telkom Indonesia, Telkom South Africa, Telmex, Telia Company, Telkom Kenya
Find out what your peers are saying about Fortinet, Cisco, Check Point Software Technologies and others in Software Defined WAN (SD-WAN) Solutions. Updated: January 2025.
831,265 professionals have used our research since 2012.