Try our new research platform with insights from 80,000+ expert users

Citrix SD-WAN [EOL] vs Fortinet FortiGate comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Mar 30, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Citrix SD-WAN [EOL]
Average Rating
8.2
Reviews Sentiment
7.4
Number of Reviews
22
Ranking in other categories
No ranking in other categories
Fortinet FortiGate
Average Rating
8.4
Reviews Sentiment
7.2
Number of Reviews
328
Ranking in other categories
Firewalls (2nd), Software Defined WAN (SD-WAN) Solutions (1st), WAN Edge (1st)
 

Featured Reviews

Rohit Ghorpade - PeerSpot reviewer
A scalable solution for MCN controller but lacks technical supports, upgrades
There are a few things that can be improved, are domain-based routing and the slowness of virtual parts, and it may be due to the wrong configuration, which we have been unable to find out. Previously, we faced some issues with the slowness part. Apart from that, feature like end gateway level antivirus. We are currently using a NetFlow proxy to establish a virtual position for the NetFlow. Our current environment has many use cases, but we are not using them on the Citrix SD-WAN. When I navigate the NCL part, it involves configuration. I want to highlight this disadvantage. Sometimes, when we push the configuration, it tries to push it to all branch locations. This process takes a lot of time, nearly 30 minutes, to push a single change from the NCL. Overall, I don't think Citrix meets our use cases what we have. This is based on my feedback after using it for the past year and working on this Citrix SD-WAN. However, from my experience, it is the worst solution I have seen. There's no domain-based routing, which is horrible. That's why we are moving to other products. We have checked our use case requirements with Fortinet, Palo Alto, and they meet them. I will consider the PoC or another OEM. There are many things in the area you need to be prompt, like the automation part. If any link or device goes down, alerting notification, etc. We need to perform and highlight so many things to your management. This should be improved.
EhabAli - PeerSpot reviewer
Efficient, user-friendly, and affordable
In the past, NSS Labs was utilized to test files and verify the numbers and datasheets. It would be beneficial to have an organization or testing lab that can verify the numbers in our datasheets since changes are frequently made, which can be inconvenient for review. For instance, when comparing different competitors such as Forcepoint, Palo Alto, and Check Point, the throughput or numbers in the datasheet may be lower than the actual numbers. Conversely, Fortinet typically reports very high numbers, but they cannot be replicated in the real world. Therefore, it would be advantageous for them to partner with a neutral testing organization such as NSS Labs to validate these numbers, thus providing more credibility and comfort to everyone regarding the accuracy of the datasheets. For the migration, everyone has a firewall in use and I am selling Fortinet. Typically, I am replacing another firewall. Previously, there was a tool available to convert configurations from one firewall, such as Palo Alto, to Fortinet, but this tool is no longer free. If it could be made free again, it would be very beneficial. This tool shows a lot of promise and is very good. Making it free would help many companies deliver their products in a more efficient and integrated way. It would also be more valuable to include the tool with the firewall package or license instead of having to pay extra for it. Paying extra puts more pressure on small companies to deliver the firewall and complete the configuration, especially if they have hundreds or thousands of policies. It's very painful to move through these policies line by line. The stability has room for improvement. When it comes to Secure SD-WAN, everything is fine. They are going the right way. SD-WAN is very promising. They can provide the SD-WAN solution separately, but they will not take this approach because even the smallest firewall can support the features, so there is no need to have a separate service or appliance. They are following the right steps, and there is nothing to be improved. Feature-wise, I'm really satisfied with the new release, and the features they have added. For now, it's fine.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"We are using it widely for the local record for SaaS-based applications. Another valuable feature is a local breakout."
"The solution is brilliant, the way it calculates its paths and trails is great."
"The most valuable feature is security, as it gives me the port bindings that cannot be accomplished using other solutions."
"It lowered our Internet costs and gave me the flexibility to choose providers based on each location's connectivity."
"The most valuable feature of Citrix SD-WAN is customization. You are able to customize the solution to your needs."
"The best feature is the backup capability, where all of the users' computers are tied into a central data repository."
"Downtime for branch offices is now almost zero. We have 100% real-time visibility into all of our lines. MPLS links have been replaced with lower-cost links, saving a larger percentage of line costs. Overall, I see SD-WAN as a must. And the Citrix SD-WAN product has delivered on expectations and exceeded them. (With later firmware updates we now have good firewall capabilities in the product too)."
"The solution's most valuable feature is load balancing."
"Reliability is the best feature. We faced some issues when we were setting it up, but the service, portal, and administration are good."
"The solution is very, very easy to use."
"The stability and scalability of this solution are satisfactory. Its SD-WAN, VPN, and URL filtering features are very useful."
"It increases security posture and is helpful for firewall reporting, intrusion protection, web filtering, and SD-WAN implementation."
"The scalability of Fortinet FortiGate is good."
"The most valuable features are SD-WAN, application control, IPS control, and FortiSandbox."
"The solution has very good threat and content filtering switches."
"We use a southern institution that's audited for IT security and the reporting that automatically comes off the unit makes it much easier to meet compliance standards and makes it easier as far as the amount of time that has to be spent to compile that information. If you get your reporting set up correctly when you initially set it up, you just select the one you want and hit print. The auditing trail on it is the best feature."
 

Cons

"Enhancements are needed to improve the stability."
"I would like to either see the price reduced or have it packaged with other products to give better value for the money."
"The price is the only thing that could be improved. Citrix is not a cheap solution."
"Even though the monitoring is pretty good, there is some room for improvement there."
"Citrix should continue to offer a perpetual licensing model because it is very important to us."
"Citrix SD-WAN's knowledge base has a few missing things, so you may need to seek help from support."
"The firewall reporting could be easier to use and filter. (It works well enough, but if I need to give an area for improvement, I think this would be it.). The built-in reporting on the product in this regard is not great."
"The reports need to be improved. We need to have them customized but they don't have that right now. I would like for them to have better system predictions. We don't have that right now. My system may be working fine right now but after making some changes, that can change."
"The only issue that I have is with FortiNAC. The firewall is fine, but the FortiNAC interface is a little bit too jumbled or too complicated, not as straightforward as it is on the Fortinet FortiGate firewall and FortiAnalyzer."
"With the standard support subscription, if the device goes down, the customer has to first ship the box, and then Fortinet sends the replacement. With the higher support, the customer has to ship the device after they have the replacement. It would be better for customers to get immediate replacements even with a standard subscription."
"There are some problems that support cannot give you a logical reason as to why it happened. For example, I had a case where I was dealing with a WhatsApp application that was giving issues. Technical support gave more than one reason it could be giving issues, but none of them solved the problem. Eventually I solved the problem, but it was far from the solutions that support had given."
"Fortinet could improve the windows opener or the virtual IP solutions for opening windows. The virtual IP settings need improvement as firewalls are trending in new development directions."
"I think the only issue that needs improvement is the interface."
"There is one big configuration file with no separations for the unique VDOMs. Maybe they could separate individual VDOM configuration files with the root VDOM configuration file referencing the individual VDOM config files.​"
"The platform's interface could improve."
"My only complaint about FortiGate is a lack of QinQ VLAN tunneling. I haven't found this feature in any Fortinet product. You can do this on all Cisco routers, including the smaller models. However, QinQ isn't available on the biggest, most expensive Fortinet units. They still don't have that. I think now we're on software version 6.0, and they still haven't found a solution for QinQ. It isn't a dealbreaker, but that's my main complaint."
 

Pricing and Cost Advice

"It would be helpful to have a demo license available for customers who want to prove the concept and conduct a proof of concept (POC) before committing to the solution. This is particularly important for customers in Egypt who often require a demonstration of the solution's features and compatibility with their needs before making any investment or incurring costs. Providing a demo license would allow customers to assess whether the solution would meet their needs or not."
"I'm not quite sure of the price ranges. Roughly, the hidden devices can scale up to $20K for one appliance. However, the branch CPs are USD $1,000 to $2,500."
"The price of the subscription should be cheaper."
"As NetScaler is now, I find it quite pricey."
"The license was a one-time purchase. It's expensive."
"I believe that Citrix SD-WAN is a good investment, but I do not have the information to be more specific."
"It's a little bit on the high side compared to the other products."
"It is a bit expensive. A cheaper product would be good, but everybody likes things to be cheaper. We bought the devices up front, and then we pay for the annual support."
"Setup cost may be not so low, as you expect, because it depends on different factors, but TCO for 5 years may pleasantly surprise you."
"We have the full version of Fortinet FortiGate and we are on a three-year contract with a commitment of five years."
"The pricing or licensing of Fortinet FortiGate is quite effective as it offers different bundles that aggregate most required features, while also allowing clients the option to select specific components alone."
"Fortinet Secure SD-WAN delivered the lowest total cost of ownership (TCO) per Mbps among all other vendors."
"Fortinet FortiGate gives you most of the features in one license."
"The price of Fortinet FortiGate is reasonable for an SME."
"It is not a very costly product if you compare it with other products. The return on investment is also good. If you compare the return of investment and money that you are spending on this product with Palo Alto, Cisco, Check Point, and other solutions, the investment is very less. We are happy with this solution. The optional licenses are there, and you can choose which one you want and which one to avoid."
"The price of Fortinet FortiGate is reasonable."
report
Use our free recommendation engine to learn which Software Defined WAN (SD-WAN) Solutions solutions are best for your needs.
848,989 professionals have used our research since 2012.
 

Comparison Review

it_user216600 - PeerSpot reviewer
Jan 3, 2016
Sophos UTM vs. Fortinet FortiGate
I have used both Sophos and Fortinet products in production and I have found the Sophos UTM appliances (hardware and virtual) to be a better fit most of the time -- with a few caveats which I will touch on below. In both instances, the transition from TMG will be mostly straightforward. The main…
 

Top Industries

By visitors reading reviews
Computer Software Company
26%
Real Estate/Law Firm
9%
Financial Services Firm
8%
Retailer
5%
Educational Organization
21%
Computer Software Company
14%
Comms Service Provider
7%
Manufacturing Company
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about Citrix SD-WAN?
It lowered our Internet costs and gave me the flexibility to choose providers based on each location's connectivity.
What is your experience regarding pricing and costs for Citrix SD-WAN?
It is on the expensive side. I would give it an eight out of ten in terms of costliness. In my region, the approximate cost for the Citrix SD-WAN license is around $150 per user per year. However, ...
What needs improvement with Citrix SD-WAN?
The solution's licensing model could be improved. Citrix SD-WAN is a good product from a technical point of view. However, when you compare its licensing with the prices of competitors, you will se...
Which is the better NGFW: Fortinet Fortigate or Cisco Firepower?
When you compare these firewalls you can identify them with different features, advantages, practices and usage at large. In my opinion, Fortinet would be the best option and l use Fortinet too...
What is the biggest difference between Sophos XG and FortiGate?
From my experience regarding both the Sophos and FortiGate firewalls, I personally would rather use FortiGate. I know the firewalls change every 5 to 7 years as stated but you really do need to upg...
What are the biggest technical differences between Sophos UTM and Fortinet FortiGate?
As a solution, Sophos UTM offers a lot of functionality, it scales well, and the stability and performance are quite good. The most valuable features for me are their web and email filtering. I wou...
 

Also Known As

Citrix CloudBridge, WOC, NetScaler SD-WAN
FortiGate 60b, FortiGate 60c, FortiGate 80c, FortiGate 50b, FortiGate 200b, FortiGate 110c, FortiGate, Fortinet Firewall
 

Overview

 

Sample Customers

AIDS Healthcare Foundation, Cornerstone Home Lending Inc., Dallara, ecVision, Essar, Eurofred, Groupe Promutuel, HMSHost Corporation, Royal Caribbean Cruise Lines Ltd, Royal Caribbean International
Amazon Web Services, Microsoft, IBM, Cisco, Dell, HP, Oracle, Verizon, AT&T, T-Mobile, Sprint, Vodafone, Orange, BT Group, Telstra, Deutsche Telekom, Comcast, Time Warner Cable, CenturyLink, NTT Communications, Tata Communications, SoftBank, China Mobile, Singtel, Telus, Rogers Communications, Bell Canada, Telkom Indonesia, Telkom South Africa, Telmex, Telia Company, Telkom Kenya
Find out what your peers are saying about Fortinet, Cisco, Check Point Software Technologies and others in Software Defined WAN (SD-WAN) Solutions. Updated: March 2025.
848,989 professionals have used our research since 2012.