Try our new research platform with insights from 80,000+ expert users

Fortinet FortiOS vs Sangfor NGAF comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Jan 5, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Fortinet FortiGate
Sponsored
Ranking in Firewalls
2nd
Average Rating
8.4
Reviews Sentiment
7.2
Number of Reviews
317
Ranking in other categories
Software Defined WAN (SD-WAN) Solutions (1st), WAN Edge (1st)
Fortinet FortiOS
Ranking in Firewalls
28th
Average Rating
8.4
Reviews Sentiment
8.4
Number of Reviews
76
Ranking in other categories
No ranking in other categories
Sangfor NGAF
Ranking in Firewalls
19th
Average Rating
8.0
Reviews Sentiment
6.5
Number of Reviews
36
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of January 2025, in the Firewalls category, the mindshare of Fortinet FortiGate is 20.3%, up from 17.4% compared to the previous year. The mindshare of Fortinet FortiOS is 0.9%, down from 1.0% compared to the previous year. The mindshare of Sangfor NGAF is 1.2%, up from 0.8% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Firewalls
 

Featured Reviews

EhabAli - PeerSpot reviewer
Efficient, user-friendly, and affordable
In the past, NSS Labs was utilized to test files and verify the numbers and datasheets. It would be beneficial to have an organization or testing lab that can verify the numbers in our datasheets since changes are frequently made, which can be inconvenient for review. For instance, when comparing different competitors such as Forcepoint, Palo Alto, and Check Point, the throughput or numbers in the datasheet may be lower than the actual numbers. Conversely, Fortinet typically reports very high numbers, but they cannot be replicated in the real world. Therefore, it would be advantageous for them to partner with a neutral testing organization such as NSS Labs to validate these numbers, thus providing more credibility and comfort to everyone regarding the accuracy of the datasheets. For the migration, everyone has a firewall in use and I am selling Fortinet. Typically, I am replacing another firewall. Previously, there was a tool available to convert configurations from one firewall, such as Palo Alto, to Fortinet, but this tool is no longer free. If it could be made free again, it would be very beneficial. This tool shows a lot of promise and is very good. Making it free would help many companies deliver their products in a more efficient and integrated way. It would also be more valuable to include the tool with the firewall package or license instead of having to pay extra for it. Paying extra puts more pressure on small companies to deliver the firewall and complete the configuration, especially if they have hundreds or thousands of policies. It's very painful to move through these policies line by line. The stability has room for improvement. When it comes to Secure SD-WAN, everything is fine. They are going the right way. SD-WAN is very promising. They can provide the SD-WAN solution separately, but they will not take this approach because even the smallest firewall can support the features, so there is no need to have a separate service or appliance. They are following the right steps, and there is nothing to be improved. Feature-wise, I'm really satisfied with the new release, and the features they have added. For now, it's fine.
RaynoPowell - PeerSpot reviewer
Great IPS and DNS filtering with useful tutorials available  
We don't really find a lot of issues on it. If I really have to complain about something, and there's not much, is the free VPN solution is a bit limited. Then again, it is a free solution. That's essentially it. Nothing else on the FortiGate or on the Fortinet OS side is really an issue. That's one of the main reasons why we use them: everything works and works well. For what we use, there isn't really any missing feature. In fact, we actually want to get rid of some of the features that they have due to the fact that, for the security model that we need to implement, having more features actually opens up potential risk. We actually would like to have a device that is more focused specifically on OT environments the operational technologies. We would prefer a device that's stripped down, that doesn't have all the other fluff in the more enterprise system. We actually want a feature where we can remove features that are there that we don't use. That is actually a thing that we find. We use it now in an operational technology environment. We use normal IT equipment. However, it's not a normal IT network. It differs significantly from a normal corporate IT environment. In a normal corporate IT environment, you like the fluff, and the additional features, and you can click, click, click, and you're done. However, all of those features you add to a device open up risk for us. And that is something we do differently in the OT environment in operational technology. We prefer to not have the fluff. We prefer to have only what is needed for the device to do what it needs to do. For example, imagine an additional feature for some sort of additional VPN technology has been added. However, it's not really needed for the OT environment, and it's not configured on the device, yet there's some sort of security threat in there. Now, all of a sudden, somebody can hack your system, and he's in there, and he's switching the lights on and off the entire city. And you don't know about it due to the fact that the additional fluff that we added to the system, we weren't aware of that issue was on there. You can enable and disable certain modules in it. However, with disabling, nobody can really tell us if that module is disabled. Is it really disabled? Is it actually unloaded? Is it uninstalling Word from your laptop, or is it just not running Word?
Zaid Farooqui - PeerSpot reviewer
Enhanced threat detection with integrated security features and good support
We are using application firewalling, WAF, and SD-WAN. The capabilities are mostly within the box. For example, you will get web application firewall WAF as part and parcel of this. SD-WAN is also bundled. It integrates with their SIEM and SOAR solutions very nicely. Lastly, the pricing point is very cost-efficient as well.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"FortiGate improved our security. It's one of the best hardware firewalls."
"A strong point of FortiGate is the graphical interface is complete and easy to use."
"Using this product makes the VPN seamless and almost invisible to me in the sense that I don't have to think about it."
"The FortiGate controls the user's activities and maximizes my bandwidth use overall."
"It blocks the vulnerabilities that can negatively impact us."
"The most valuable features of Fortinet FortiGate are the ease of use and there are several operating systems that can include the hardware capacities. In the newer releases, the resources were more useful because they were included in the operating system."
"User-friendly and affordable security solution that's recommended for SMB customers. This solution has good technical support."
"The CLI is robust and powerful, enabling rapid, consistent changes via SSH."
"I find filtering traffic, filtering web traffic, session traffic, and managing the network as valuable features."
"The SSL VPN is fee for use is most attractive."
"The most valuable features of Fortinet FortiOS are its simplicity, highly user-centric, and performs well. The line speed and for heavy traffic, is helpful for us."
"The solution is very user friendly."
"It's simple to use in terms of inbound and outbound traffic management."
"The solution is extremely scalable."
"The firewall options in FortiOS allow us to open up access to our vendors for EDI and all its features."
"This is an easy means of setting up high-availabilty firewall protection."
"Sangfor NGAF works accordingly with our customers. The solution has good performance, easy to use, and integrates well with the endpoints."
"The price versus value is good because the solution is less expensive than Sophos, Fortinet, or SonicWall."
"You might try Sangfor if you are on a tight budget. The price is affordable, and Sangfor offers a lot of features. We don't have any complaints about Sangfor."
"So far, the performance and reliability of the product have supported our company's critical network traffic."
"Technical support is very good."
"While the features are not dissimilar to other brands, configuration is much more simple, which works out great for Indonesian people."
"Sangfor's tech features and technologies are more powerful than those of the other solution providers in terms of security. They also have big solutions in terms of cybersecurity."
"We can utilize our own network rather than paying for a private one."
 

Cons

"I think there could be more QoS features"
"Reporting is limited to providing an external appliance for improving the reporting capabilities of the FortiAnalyzer. It does not offer a central management and is also sold separably as an appliance."
"It would be nice if FortiGate incorporated some built-in endpoint protection features. I would also like a built-in SOC dashboard for managing multiple Fortinet firewalls."
"Monitoring and reporting could be better."
"Fortinet FortiGate could improve by having a frequent ask questions(FAQ) area for people to receive quick answers to popular questions. Additionally, it would be beneficial to have an SMS notification feature. For example, if you cannot access your email you could receive an SMS message."
"It can be a little bit more user-friendly in terms of policy definition and implementation. It seems a little bit complicated, and it could be simplified."
"Fortinet FortiGate could improve by having more storage in the hardware for log data."
"Performance and technical support are the main issues with this solution."
"For me, it is important to be able to block VPN applications, like Facebook, so I would like to see that included in the next release. With this version, if you want to block or allow a site, you now have to drag all the domains related to this site."
"The GUI could be improved to make it more usable, easier to administer, and easier to configure."
"The main challenge with Fortinet FortiOS is integration with third-party solutions. I don't see any other areas for improvement. Nowadays, all products work well for 50-60 percent of needs. We must only fulfill 60-70 percent of client requirements because they don't use 100 percent of product features. Banks and financial sectors might need more security features. I don't work much in banking, but they often use multiple products for different security layers, not just firewalls. They might use various products or APIs for different purposes. In the end, clients use the products that suit their needs."
"The threat time interval lags a little, especially if there's a heavy load on the firewall."
"Fortinet's central management needs to be improved. FortiManager's technical tool provider ability should manage all Fortinet security products. Right now, FortiManager only manages the configuration of FortiGate."
"Fortinet needs to make this solution even more robust. Sometimes when we get a DDoS attack, the cannot withstand it. We can run out of sessions very easily. That said, I suppose if you want more a robust system, then you could purchase higher-end solutions, which are more expensive. Still, I would like to see more protection from even in the low-end version."
"The solution could improve the log retention and reports."
"The technical support is good. However, during the holidays they can get a little slow to respond."
"Sangfor has recently increased their prices."
"Our experience with its customer support was quite challenging."
"Lacks consistency in terms of filtering certain websites and applications."
"The interface and user experience are horrible."
"Sangfor NGAF could improve the policies and default criteria. They could be much better."
"The support for YouTube or the Internet is not enough."
"Scalability for any network device is not very easy in terms of vertical scalability."
"Occasional issues with breaches which are dealt with expediently."
 

Pricing and Cost Advice

"Other firewalls are more expensive than Fortinet FortiGate, such as the Azure firewall."
"It has been two years. I don't remember the actual price, but it was affordable. We buy the boxes and then use the license for three years."
"They are very competitive, but we like to have the factory warranty taken care of."
"Licensing for Fortinet FortiGate is on a yearly basis. Pricing for it is a bit high. It could be cheaper."
"It is an inexpensive solution."
"We find the most valuable aspect of this solution is the price. It is affordable, and cheaper than other firewalls."
"Their licensing costs are annual. The UTM feature license along with their support is called FortiCare. We include that as a part of the annual maintenance cost. Palo Alto or Juniper also have an annual subscription charge for UTM. Price, of course, can always be more competitive, but it is not the most expensive product. The price-performance ratio is quite high for FortiGate."
"We are on an annual license to use Fortinet FortiGate."
"We pay $100,000. That covers the cost of the hardware that we run the VN's on. That also includes any SGNA costs for the internal support tech."
"The price of Fortinet FortiOS is reasonable and it is paid annually. You are able to select the features that you want."
"The price of Fortinet FortiOS has been reasonable."
"We had a three-year license to use Fortinet FortiOS and we are going to renew it this year."
"It is not cheap; it is also not expensive. It is somewhere in the middle."
"The solution is quite affordable and I rate the cost a four out of ten."
"The Fortinet solutions can be a bit expensive."
"The price of Fortinet FortiOS is comparable to other similar solutions on the market. We are on an annual license to use the solution."
"We purchased one year technical support and return to factory support, and we also purchased one-year technical support services. So those were additional."
"Sangfor NGAF is a cheaply priced product, especially if I consider the previous product that was used in my company."
"The pricing is reasonable."
"The product is very cost-effective compared to other brands or vendors."
"When it comes to the price of firewall solutions, Sangfor NGAF takes the cake."
"If one is very cheap and ten is very expensive, I rate the tool's price as three out of ten."
"Sangfor is cheaper than competing vendors."
"The license of Sangfor NGAF can be purchased at different interval lengths, such as annually or three years. They offer a range of packages to choose from, such as combo or hybrid packages. We are using the complete solution package which includes IM, NGF and SSL VPN, and WAF."
report
Use our free recommendation engine to learn which Firewalls solutions are best for your needs.
831,158 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Educational Organization
22%
Computer Software Company
14%
Comms Service Provider
6%
Manufacturing Company
6%
Computer Software Company
18%
Financial Services Firm
9%
Manufacturing Company
8%
Government
8%
Computer Software Company
13%
Manufacturing Company
11%
Financial Services Firm
8%
Educational Organization
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

Which is the better NGFW: Fortinet Fortigate or Cisco Firepower?
When you compare these firewalls you can identify them with different features, advantages, practices and usage a...
What is the biggest difference between Sophos XG and FortiGate?
From my experience regarding both the Sophos and FortiGate firewalls, I personally would rather use FortiGate. I know...
What are the biggest technical differences between Sophos UTM and Fortinet FortiGate?
As a solution, Sophos UTM offers a lot of functionality, it scales well, and the stability and performance are quite ...
Features comparison between Palo Alto and Fortinet firewalls
In the best tradition of these questions, Feature-wise both are quite similar, but each has things it's better at, it...
What do you like most about Fortinet FortiOS?
The SSL VPN is fee for use is most attractive.
What is your experience regarding pricing and costs for Fortinet FortiOS?
Regarding the cost, the initial purchase is relatively cheap because it comes bundled. However, the subscription rene...
What do you like most about Sangfor NGAF?
I think Sangfor NGAF is more valuable than Cisco products because of its simplicity and ease of management. If I comp...
What is your experience regarding pricing and costs for Sangfor NGAF?
The licensing cost is quite high compared to other available firewalls in the market.
What needs improvement with Sangfor NGAF?
The cost of licensing is very high compared to other firewalls available here. There should be improvements in hardwa...
 

Also Known As

FortiGate 60b, FortiGate 60c, FortiGate 80c, FortiGate 50b, FortiGate 200b, FortiGate 110c, FortiGate, Fortinet Firewall
No data available
Sangfor NGAF Firewall Platform
 

Overview

 

Sample Customers

Amazon Web Services, Microsoft, IBM, Cisco, Dell, HP, Oracle, Verizon, AT&T, T-Mobile, Sprint, Vodafone, Orange, BT Group, Telstra, Deutsche Telekom, Comcast, Time Warner Cable, CenturyLink, NTT Communications, Tata Communications, SoftBank, China Mobile, Singtel, Telus, Rogers Communications, Bell Canada, Telkom Indonesia, Telkom South Africa, Telmex, Telia Company, Telkom Kenya
Black Gold Regional Schools, Amadeus Hospitality, Jefferson County, Chunghwa Telecom, City of Boroondara, Dimension Data
The Ministry of Science, Technology, and Innovation (Indonesia), Lawson, Inc. (Philippines), Universiti Sultan Zainal Abidin (Indonesia), TEK Automotive (Italy), etc.
Find out what your peers are saying about Fortinet FortiOS vs. Sangfor NGAF and other solutions. Updated: January 2025.
831,158 professionals have used our research since 2012.