OPNsense and Sangfor NGAF are competing network security products. Sangfor NGAF appears to have the upper hand due to its advanced threat detection and superior customer service, despite higher pricing and some scalability issues.
Features: OPNsense is praised for its flexibility, extensive plugin system, and frequent updates. Sangfor NGAF stands out with its advanced threat detection, integrated security modules, and zero-day vulnerability protection.
Room for Improvement: OPNsense could improve its documentation, simplify its configuration process, and streamline user assistance. Sangfor NGAF users desire better scalability options, more intuitive policy management, and enhanced adaptability and ease of policy adjustments.
Ease of Deployment and Customer Service: OPNsense is noted for a straightforward deployment process but occasionally lacks comprehensive customer service. Sangfor NGAF offers smooth deployment and responsive support, making it easier for new users to get started and receive help when needed.
Pricing and ROI: OPNsense is considered cost-effective with a good ROI, particularly for its low setup costs. Sangfor NGAF, despite its higher price, is seen as valuable due to its advanced capabilities and greater long-term ROI. Users feel that the extra investment in Sangfor NGAF is justified by the enhanced security.
The response time for a critical priority one issue was over four hours and they only responded because we threatened legal action for them violating our support contract.
They say they will respond in 24 hours, but I have received responses in a maximum of one hour, which is impressive.
The technical support from Fortinet FortiGate is 24 hours a day seven days a week, and 365 days a year.
I know a couple of people on the forum that actually develop the tool, and they are helpful.
Within approximately an hour or two I was receiving a response, I was really impressed with the support.
The heavy part was the Azure part, and we are specialists there.
FortiWAN supports OSPF but does not support the BGP protocol.
Fortinet VPN and DDoS capabilities are great, yet we need to provide a solution that enables CASB and integration to the cloud.
The relationship between their accounts team and my leadership team seems to be the reason for phasing out FortiGate.
Our primary focus is to ensure the protection of customers' and consumers' data and critical IT/Dynamic infrastructure.
For high availability, it's crucial to have a method in place where a designated component oversees the entire process.
The problem is integration with a virtual server.
The devices will usually fail way before reaching the capacity advertised in the data sheets, especially when you activate several of the features the device can handle.
The solution is working and it is still stable even across all of these devices and servers.
We have over 10,000 users behind it.
We only use OPNsense now. We migrated from FortiGate.
It is especially scalable if you use the VM version because you only have to provision more resources.
If a customer is starting in the cloud and has 100 or 200 users, I would always recommend OPNsense.
The cost of the original deployment fell below £5,000, and licenses are priced at around £3,000.
Every time you upgrade your license, you also get insurance for the equipment.
Overall, FortiGate is affordable.
There are no licensing costs for OPNsense.
The main cost is the hardware.
I believe that costs between $900 to $1000 a year.
All of these issues were resolved in v5.2.
Stability has dramatically improved over the previous main version branch of FortiOS; 5.2.x and 5.4.x are stable enough for critical environments.
Overall, the devices have been very stable.
When I check to see if the second one would take over, it failed.
There are no bugs or glitches.
It appears to be rather reliable, though, with the stated data points above, it is not yet ready for the enterprise yet.
The two most valuable features are VPN and firewalling.
WiFi network for visitors isolated from our corporate WiFi network using only one unit
Allows for firewall rules to be programmed and named in a way that makes it 'readable'
The most valuable thing about this product is that it is very easy to use.
With the visibility, you can see the data source, data destination, the source port, destination port, protocols, the most used, the malicious files that have been detected and blocked, the countries the customer has visited, and the IPs based on Suricata.
The VPN server feature is the most valuable.
Fortinet FortiGate offers comprehensive network security and firewall protection across multiple locations. It effectively manages data traffic and secures environments with features like VPN, intrusion prevention, and UTM controls.
Organizations rely on Fortinet FortiGate for its robust integration with advanced security policies, ensuring significant protection for enterprises, cloud environments, and educational sectors. It facilitates network segmentation, application-level security, and authentication management, securing communication within and between locations such as branches and data centers. Its efficient SD-WAN and UTM features enable streamlined data management and enhanced threat protection capabilities. Users appreciate its centralized management, facilitating seamless operations across diverse environments.
What are the key features of Fortinet FortiGate?Fortinet FortiGate is crucial in sectors like education, offering robust networks for secure data flow between campuses and facilitating remote learning. In enterprise environments, it allows efficient management of application traffic and security across multiple branches, while in the cloud, it seamlessly integrates with diverse platforms to enhance security infrastructure.
OPNsense is widely used for firewall functionalities, intrusion detection, VPN and IPSec, content filtering, securing network traffic, and remote access. It protects internal networks and manages servers securely, suitable for small to medium-sized businesses.
OPNsense is a comprehensive firewall solution leveraging open-source technology. It integrates with third-party modules like WireGuard and CrowdSec, enhancing its security capabilities. Offering on-premises and cloud deployment, it features an intuitive graphical interface, advanced reporting, VPN functionality, IDS/IPS features, and high scalability. Users find it ideal for small businesses and home networks due to its stability and ease of use. Frequent updates and an active community support its continuous improvement. However, it needs advancements in VPN selection, scalability, and technical documentation. Enhanced high availability, threat intelligence, and integration with virtualization platforms are required. User feedback suggests improvements in connectivity, alerting, traffic monitoring, and antivirus protection.
What are the key features of OPNsense?OPNsense is implemented across various industries to secure network infrastructure and ensure reliable connectivity. In fintech, it safeguards sensitive financial data while maintaining compliance. Educational institutions deploy it to protect student information and enable secure remote learning environments. Healthcare organizations use it to secure patient data and comply with HIPAA regulations. By integrating with tools like WireGuard and CrowdSec, businesses enhance their cybersecurity posture and streamline network management, making OPNsense a versatile choice for diverse operational needs.
Sangfor Next Generation Firewall (also known as NGAF) is a converged security solution providing protection against advanced threat, malware, viruses, ransomware and web-based attacks using integrated security features like firewall, IPS, anti-virus, anti-malware, APT, URL filtering, Cloud Sandbox, and WAF. As the world's first AI-enabled and fully integrated Next Generation Firewall & Web Application Firewall (WAF), NGAF offering the security visibility, real-time detection and response, simplified operation and maintenance and high-performance application layer security needed to operate an enterprise network in total security. Tested and proven to provide cutting-edge network security by ICSA Labs and endorsed by Gartner Inc., NGAF harnesses the power of Sangfor’s Neural-X threat intelligence and analytics platform and Engine Zero’s innovative malware detection to provide next-generation protection for today’s enterprise.
We monitor all Firewalls reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.