Try our new research platform with insights from 80,000+ expert users

Sangfor NGAF vs Stormshield Network Security comparison

Sponsored
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Fortinet FortiGate
Sponsored
Average Rating
8.4
Reviews Sentiment
6.9
Number of Reviews
587
Ranking in other categories
Secure Web Gateways (SWG) (2nd), Firewalls (1st), Intrusion Detection and Prevention Software (IDPS) (1st), Software Defined WAN (SD-WAN) Solutions (1st), WAN Edge (1st), ZTNA (1st), Unified Threat Management (UTM) (1st)
Sangfor NGAF
Average Rating
8.0
Reviews Sentiment
6.5
Number of Reviews
34
Ranking in other categories
Firewalls (26th)
Stormshield Network Security
Average Rating
7.8
Reviews Sentiment
6.0
Number of Reviews
18
Ranking in other categories
Unified Threat Management (UTM) (12th)
 

Featured Reviews

Vasu Gala - PeerSpot reviewer
Manager, Information Technology Operation/Presales at TechMonarch
A stable solution with an intuitive interface and quick customer service
I have been working with Fortinet FortiGate, WatchGuard, Sophos, and SonicWall. I'm not as comfortable with SonicWall because of their UI and limitations. I prefer Fortinet above all other options. When it comes to configuration, I am confident in my ability to handle various tasks, including creating policies such as firewall rules, web policies, and application policies. Additionally, I can configure VPNs and implement load balancing, among other tasks. Overall, I feel much more comfortable working with Fortinet. Fortinet has made significant improvements by integrating AI with firewalls for threat analysis and prevention. In the past 2-3 years, they have launched FortiSASE and SIEM, and they also provide SOC services. Both Palo Alto and Fortinet FortiGate are excellent. While Fortinet FortiGate comes at higher prices, the functionality and support justify the cost. They promptly resolve firmware issues and inform all support providers about configuration changes.
Zaid Farooqui - PeerSpot reviewer
CIO at Indus Motor Company
Enhanced threat detection with integrated security features and good support
We are using application firewalling, WAF, and SD-WAN. The capabilities are mostly within the box. For example, you will get web application firewall WAF as part and parcel of this. SD-WAN is also bundled. It integrates with their SIEM and SOAR solutions very nicely. Lastly, the pricing point is very cost-efficient as well.
Zsolt Jónás - PeerSpot reviewer
System Administrator at NaxoNet
Advanced GUI and layered security have supported compliance and simplified intrusion prevention
I haven't had a task that I couldn't solve with Stormshield Network Security. The active-active high availability solution would be beneficial because currently, if you build a high availability solution with Stormshield Network Security, you have a main device and another one is a backup device. The HA can switch between them, but it would be good to have a master-master solution, not just a master-slave one. I could set a URL that I can call to update the DNS record. Currently, Stormshield Network Security devices support DynDNS, which is not a usual feature request from a server environment. I have my own solution instead of DynDNS because I don't prefer it, so I have my own service for that. However, the GUI does not support using a custom service instead of DynDNS. I had to solve it in the console on Stormshield Network Security device, but it would be much better if it was reachable on the GUI. I had to figure out a trick for the IPsec configuration. In the IPsec config, we have to provide the remote side's IP address, but it's always changing. This means that an office, for example a company that has an office but without a fixed IP address, cannot be used with IPsec VPN.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The best part of this product is that you have the same functionalities throughout the range of products, whether you deploy a small firewall or a big one, it's the same and you have the same functionality almost, so that's one of the benefits."
"The product is easy to install since we only need to follow the user manual, documents, and articles provided by Fortinet to install the product."
"The management console is pretty simple, so anyone who understands networking can initially deploy the solution."
"Overall, the pricing of the solution is very good. The product offers good value."
"Great product with too many features at the right price."
"It has upscaled our security posture, especially regarding external connectivity, because any access or connection from the company has to go through the Fortinet FortiGate firewall."
"I find Fortinet FortiGate to be quite stable, as I have never heard of any issues where they broke or malfunctioned; they are always working."
"It's very similar to a Cisco firewall, yet less expensive."
"Sangfor NGAF specializes in ransomware detection and helps to protect our network from ransomware threats and malware."
"The top functionality is the reporting feature."
"Sangfor has the best capabilities for securing connections, securing web browsers, securing servers, and general threat protection."
"SSL VPN is the best feature."
"I think Sangfor NGAF is more valuable than Cisco products because of its simplicity and ease of management. If I compare it with Palo Alto and Cisco, both are quite complex products. And if I compare it with FortiGate firewalls from Fortinet, I have also used all these products. Fortinet and Sangfor NGAF are similar products because the applications behind the application and policy layers are almost identical."
"In four steps one can configure the entire firewall."
"It enables us to not only detect but also prevent various types of incoming threats, allowing us to take appropriate corrective actions and exercise control over the network."
"I think the tool has the feature to detect and kill ransomware in three seconds."
"Our organization's main concern is stability, and this is a stable solution."
"The most valuable features of this solution are the URL filtering database, which is great and contains all internet categories, the highly scalable interface that I can turn into what I want including hybrid, bridge, or router mode, the security with no back doors that is more secure than other solutions, and the hardware performance that is also better than others."
"This solution is quick and easy to configure."
"It's an easy, straightforward management platform to use."
"I like that it works fine. Stormshield is a very good solution."
"Fortinet, Dell SonicWall and Check Point because these products offer a wide range of features that are not available with Netasq."
"Stormshield is pretty robust, compared to other products like Fortinet, as you get more security with Stormshield and spend less money."
"Filters and URL filtering helped us to optimize our bandwidth."
 

Cons

"Some features of Fortinet FortiGate are actually fee enabled that are inconvenient for deploying in production."
"The performance could be a bit better. Right now, I find it to be lacking. Having good performance is very important for our work."
"The room for improvement is about the global delivery time period. Usually I need to wait for almost one month to deliver it overseas."
"FortiLink is the interface on the firewall that allows you to extend switch management across all of your switches in the network. The problem with it is that you can't use multiple interfaces unless you set them up in a lag. Only then you can run them. So, it forces you to use a core type of switch to propagate that management out to the rest of the switches, and then it is running the case at 200. It leaves you with 18 ports on the firewall because it is also a layer-three router that could also be used as a switch, but as soon as you do that, you can't really use them. They could do a little bit more clean up in the way the stacking interface works. Some use cases and the documentation on the FortiLink checking interface are a little outdated. I can find stuff on version 5 or more, but it is hard to find information on some of the newer firmware. The biggest thing I would like to see is some improvement in the switch management feature. I would like to be able to relegate some of the ports, which are on the firewall itself, to act as a switch to take advantage of those ports. Some of these firewalls have clarity ports on them. If I can use those, it would mean that I need to buy two less switches, which saves time. I get why they don't, but I would still like to see it because it would save a little bit of space in the server rack."
"Sometimes it's super hard to figure out what's wrong with a FortiGate VPN unless you know the commands on the CLI to see the flow and how to interpret it."
"The solution can have more features in a single box that can be multi-applied to integrate everything."
"The support we receive when we need to upgrade is not satisfactory and has room for improvement."
"The one concern I have with Fortinet FortiGate is the firmware versions, which often have many bugs when upgraded, leading us to revert back to older versions multiple times in my lifecycle."
"I believe that IAM and NGFW need to merge into a single box, instead of there being two separate box solutions."
"The cost of licensing is very high compared to other firewalls available here. There should be improvements in hardware scalability, allowing for more storage and memory capacity."
"The solution has too many bugs and these slow down the implementation."
"The tool's support is an area of concern where improvements are required."
"Sangfor NGAF could improve the policies and default criteria. They could be much better."
"The product must provide more IPS features."
"The setup phase is quite complex."
"They need to improve their research team and they need to study their data to analyze it and build the product."
"The SD card could be more secure."
"A more user-friendly interface would be helpful."
"The main area of this product that has room for improvement is pricing. Stormshield Network Security is quite expensive."
"With Stormshield, there are difficulties joining things, and it can be complex depending on the architecture."
"Not all the fields are activated yet and we were informed that it will take at least one month."
"It could be better if it were more user-friendly. It's too complicated for us to use it. The price could be better as well."
"An application firewall like other next generation firewalls have."
"This solution has a big problem with web filtering and it needs to be improved."
 

Pricing and Cost Advice

"For the price, I'd rate it a ten because it's very cost-effective."
"Pricing and licensing is a little bit complicated in FortiGate. They are always on the higher side. This is one issue that we always raise with the company that they should reduce the price according to Indian market requirements. There are no costs in addition to the standard licensing fees."
"The price is really low. It's cheap in comparison to the cost of Cisco or CheckPoint, for example."
"The pricing is based on a licensing model for each IPS in your environment."
"Price-wise, it's at a good price point for our market."
"Its price is good."
"Go for long term pricing negotiated at the time of purchase."
"Fortinet is the least expensive solution."
"For over 2000 users, the cost is around 5000 to 6000 USD. If you want a web application firewall, you have to purchase an additional license for it."
"When it comes to the price of firewall solutions, Sangfor NGAF takes the cake."
"The solution has a TCO that is 32% to 50% less than Sophos, Fortinet, and SonicWall."
"It costs about 8 to 10 thousand dollars per year for 500 users, standard licensing fees included."
"I rate the product price as one on a scale of one to ten, where one is low price and ten is high price."
"If one is very cheap and ten is very expensive, I rate the tool's price as three out of ten."
"The license of Sangfor NGAF can be purchased at different interval lengths, such as annually or three years. They offer a range of packages to choose from, such as combo or hybrid packages. We are using the complete solution package which includes IM, NGF and SSL VPN, and WAF."
"Sangfor NGAF price is reasonable and there is an annual license. However, the maintenance cost can be a bit high."
"For mid-sized companies, they sell their appliances for good prices."
"We bought a three-year license, and we renew it whenever it expires. The price could be better. It's always very expensive."
"The pricing could be better."
"I think the price is good."
"We chose Stormshield for its price, as the Azure firewall was too expensive."
"The SN200 series costs between $500 USD and $600 USD per year, whereas the SN700 series costs approximately $1,000 annually."
"The price of this solution and the price of support are ok."
report
Use our free recommendation engine to learn which Firewalls solutions are best for your needs.
884,933 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
11%
Comms Service Provider
10%
Manufacturing Company
8%
Financial Services Firm
6%
Manufacturing Company
12%
Comms Service Provider
9%
Financial Services Firm
8%
Computer Software Company
7%
Comms Service Provider
17%
Computer Software Company
15%
Manufacturing Company
10%
Government
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business360
Midsize Enterprise135
Large Enterprise190
By reviewers
Company SizeCount
Small Business15
Midsize Enterprise10
Large Enterprise10
By reviewers
Company SizeCount
Small Business10
Midsize Enterprise5
Large Enterprise2
 

Questions from the Community

Which is the better NGFW: Fortinet Fortigate or Cisco Firepower?
When you compare these firewalls you can identify them with different features, advantages, practices and usage a...
What is the biggest difference between Sophos XG and FortiGate?
From my experience regarding both the Sophos and FortiGate firewalls, I personally would rather use FortiGate. I know...
What are the biggest technical differences between Sophos UTM and Fortinet FortiGate?
As a solution, Sophos UTM offers a lot of functionality, it scales well, and the stability and performance are quite ...
What do you like most about Sangfor NGAF?
I think Sangfor NGAF is more valuable than Cisco products because of its simplicity and ease of management. If I comp...
What is your experience regarding pricing and costs for Sangfor NGAF?
The licensing cost is quite high compared to other available firewalls in the market.
What needs improvement with Sangfor NGAF?
The cost of licensing is very high compared to other firewalls available here. There should be improvements in hardwa...
What advice do you have for others considering Stormshield Network Security?
The tool is like a firewall and works well. I don't have any issue with it. I rate it an eight out of ten.
 

Also Known As

Fortinet FortiGate Next-Generation Firewall
Sangfor NGAF Firewall Platform
NETASQ Firewalls
 

Overview

 

Sample Customers

Amazon Web Services, Microsoft, IBM, Cisco, Dell, HP, Oracle, Verizon, AT&T, T-Mobile, Sprint, Vodafone, Orange, BT Group, Telstra, Deutsche Telekom, Comcast, Time Warner Cable, CenturyLink, NTT Communications, Tata Communications, SoftBank, China Mobile, Singtel, Telus, Rogers Communications, Bell Canada, Telkom Indonesia, Telkom South Africa, Telmex, Telia Company, Telkom Kenya
The Ministry of Science, Technology, and Innovation (Indonesia), Lawson, Inc. (Philippines), Universiti Sultan Zainal Abidin (Indonesia), TEK Automotive (Italy), etc.
ACESUR group, Ministry of Education Oman, Anios Laboratories, Zain, DLM Location
Find out what your peers are saying about Sangfor NGAF vs. Stormshield Network Security and other solutions. Updated: March 2026.
884,933 professionals have used our research since 2012.