The system comprises three primary functionalities: defense solutions, detection solutions, and the ability to identify, block, and analyze network traffic. It enables us to not only detect but also prevent various types of incoming threats, allowing us to take appropriate corrective actions and exercise control over the network.
Infrastructure Department Head at a manufacturing company with 11-50 employees
Robust security features with scalability challenges
Pros and Cons
- "It enables us to not only detect but also prevent various types of incoming threats, allowing us to take appropriate corrective actions and exercise control over the network."
- "It does not offer any recommendations on how to mitigate or control attacks."
What is our primary use case?
How has it helped my organization?
We have observed numerous threats targeting our network from both internal and external sources. While we have reports detailing these incidents, we currently lack a clear method for prioritizing internal threats.
What is most valuable?
The information provided alerts us to the presence of threats from specific sources, which is highly beneficial.
What needs improvement?
It does not offer any recommendations on how to mitigate or control attacks.
Buyer's Guide
Sangfor NGAF
January 2025
Learn what your peers think about Sangfor NGAF. Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
832,138 professionals have used our research since 2012.
For how long have I used the solution?
I have been using it for three years.
What do I think about the stability of the solution?
We face occasional stability issues. I would rate it seven out of ten.
What do I think about the scalability of the solution?
It doesn't offer significant scalability features.
How are customer service and support?
In the event of a performance issue, such as users reporting slow access to specific websites, we conduct an internal investigation to identify the root cause. If it's determined to be a problem with the equipment, we escalate the issue to the vendor for resolution.
How would you rate customer service and support?
Neutral
What about the implementation team?
When we installed the equipment, we depended on an external consulting party to guide us through the setup and functionality for approximately two weeks. The project team, consisting of both project members and experts in the field, were actively engaged during this period.
What's my experience with pricing, setup cost, and licensing?
The pricing is reasonable. At the time of our decision to acquire the equipment, we were working with a constrained budget and it turned out to be the most suitable choice to meet our specific requirements
Which other solutions did I evaluate?
We considered FortiGate as an option but ultimately decided on Sangfor NGAF due to its more favorable pricing.
What other advice do I have?
I hope that its distributor possesses a high level of product knowledge, and the same applies to Sangfor itself as the principal company. This would enable customers to have a more seamless and enriching experience with the product, eliminating any barriers or disconnect between our team, the customers, and the software. Overall, I would rate it seven out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Great for inspecting traffic on a very granular level but the GUI lacks logic in some areas
Pros and Cons
- "Particularly good in the DPI where we can inspect inbound and outbound traffic."
- "The GUI needs to be improved, lacks logic in some areas."
What is our primary use case?
This solution is our firewall. I'm a network administrator.
What is most valuable?
Sangfor serves most of the basic purposes of a firewall. It's particularly good in the DPI where we can inspect the inbound and outbound traffic on a very granular level. It gives a very good predictive measure as well as the current measure of things going on in our network. When it comes to the VPNs, it has a very good throughput when remote users connect, particularly when it comes to site-to-site VPNs, where it provides a good analysis module. You can analyze inbound traffic and different policies on this. It gives us value for money overall.
What needs improvement?
I think the GUI needs to be improved, there are a lot of areas where the panes do not make sense. They have put the NAT in the policy section but at the same time the DPI is in the network pane. The placement of different options in the menu system of this firewall is not that logical and often doesn't make a lot of sense. The operational procedures are a little tricky and require some technical skills. A level one person will have problems. The compatibility needs to be improved.
For how long have I used the solution?
I've been using this solution for three years.
What do I think about the stability of the solution?
We have been experiencing power failures but the solution has been very stable, both from the hardware and the software perspective. We have built a lot of VPN solutions for the firewalls including Cisco, Firewall 2, and pfSense, and it has been very good with that.
What do I think about the scalability of the solution?
We don't require a very highly scalable coefficient but I believe it's scalable.
How are customer service and support?
The technical support is very good. They have a local vendor they have hired for the technical support and if anything cannot be resolved remotely, they come to us. They are very agile and very technically supportive.
How would you rate customer service and support?
Positive
How was the initial setup?
The initial setup was a little complex because we were previously dealing with command line scenarios and we were not very comfortable with the GUI which is a little complex.
What's my experience with pricing, setup cost, and licensing?
Our licensing costs are around $15,000 per year which is nominal compared to other solutions.
What other advice do I have?
Whether or not this solution is good for you depends on your network. If you have sufficient technical support, then you can go for an open-source solution. Without that and if you have the funds, then this is a good solution. If not, then most of what firewalls do these days can be handled by an open-source solution.
This is a new solution in our country where the price tag really matters. They have targeted the public sector and I'm seeing more and more people moving towards Sangfor because it's cheaper than other products, and the support is quite good.
I rate the solution seven out of 10.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Sangfor NGAF
January 2025
Learn what your peers think about Sangfor NGAF. Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
832,138 professionals have used our research since 2012.
Enterprise System Engineer at Innolytix Pakistan Pvt Ltd
Scalable security solution deployed across multiple industries and is well priced compared to competitors
Pros and Cons
- "The level of support provided to local companies is good. They transform their application control and other settings according to that country."
- "Sangfor need greater exposer in the market because the market is mainly saturated by Fortinet. The user experience of Fortinet is quite different compared to NGAF. If we want to switch our users from Fortinet to NGAF, we have to convince them that the user experience will be much easier once once they start to use it."
What is our primary use case?
We have this solution deployed across multiple industries including education, pharmaceutical and different textile industries. This is a good product for network security and is popular right now. Sangfor is cheaper than well-known products like Fortinet and Palo Alto Firewall NGFS.
What is most valuable?
The level of support provided to local companies is good. They transform their application control and other settings according to that country.
What needs improvement?
Sangfor need greater exposer in the market because the market is mainly saturated by Fortinet. The user experience of Fortinet is quite different compared to NGAF. If we want to switch our users from Fortinet to NGAF, we have to convince them that the user experience will be much easier once once they start to use it.
What do I think about the stability of the solution?
We have deployed many firewalls and have faced two or three faulty devices that we have to replace over a year because their power supply was faulty. Some customers use the device for over five years and they have worked fine but got slower with the time.
What do I think about the scalability of the solution?
This is a scalable solution.
How are customer service and support?
I can vouch for the local support team. They are more than competitive in the market. They are always available for small and big customers. They are onsite whenever we need it and assist with any problem or deployment scenario and are willing to discuss it at any time. I would rate them a three out of five.
Which solution did I use previously and why did I switch?
I have previously used Fortinet. Fortinet is quite a mature product and offers so many features. Sangfor lack a bit in that area. Sangfor include a local database for URLs and other applications. When using Fortinet, you cannot block a local website by default.
How was the initial setup?
The simple deployment of a network on NGF is quite simple and their guides are quite simple as well. The do lack visual guides that are easier for some customers to follow. It's easy to configure a normal deployment scenario for networking and ET. When it comes to high level security and highly advanced features, you need to have some experience in that area to actually apply that on this firewall.
If you're experienced, it would take two or three hour maximum, depending on how many customers are using the policy and how much detailed configuration is needed. I would rate our experience with the setup an eight out of ten.
We have faced some of the issues after deployment with URL filtering which we have logged a ticket for. Our customers are unable to access certain websites. We have diagnosed the problem but we are unable to identify the URL signature or what is blocking the IAM and preventing access to that site.
What's my experience with pricing, setup cost, and licensing?
For over 2000 users, the cost is around 5000 to 6000 USD. If you want a web application firewall, you have to purchase an additional license for it. By default, they provide you with 10 SSL and a VPN. If you want more than 10, you have to pay more. From a pricing perspective, I would rate them a four out of five.
What other advice do I have?
They have a huge product line for large companies and we have deployed a firewall for over 5000 to 10000 users. It is suitable for all type of environments. I would advise others to spend one to two months after deployment on Sangfor to configure the many settings for security services. You have to work on it, keep looking at the logs and make changes as you go. You need this time to analyze, make future risk assessments and reconfigure the work from time to time. Only once this is done, can you consider deployment complete.
It offers good value for money and is much cheaper compared to other firewalls. I would suggest Sangfor to those who are cost conscious.
I would rate this solution a seven out of ten.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Director Technology & Service Delivery at Innolytix Pakistan Pvt Ltd
Simple with easy to master user interface, great support and good value
Pros and Cons
- "It's a very simple to use product."
- "Occasional issues with breaches which are dealt with expediently."
What is our primary use case?
We are based in Pakistan and when it comes to firewalls we have partnerships with several companies - Sangfor, Sophos and Fortinet. I'm the director of technology and service.
What is most valuable?
Almost all vendors in this category have the same features, but the big advantage in Sangfor is that it's very easy to use. The graphical user interface is so easy that a child could configure it. The other nice thing about Sangfor is the price tag. Almost every customer is pleasantly surprised by the low cost. When you compare it with the networking and firewall leaders like Cisco, it's very good value.
What needs improvement?
These days there are lots of breaches and vulnerabilities which you can see if you do some research. Sangfor has similar issues with one or two products where customers have had problems. The company deaks with these things immediately and quickly brings out new firmware to solve the issue so I'm not aware of any deficiency in the solution. If a customer finds a feature lacking, we open a ticket to support and Sangfor comes up with the appropriate new firmware within 10 days. If you were to do the same with other vendors, it would normally take four to five months to get the new feature.
For how long have I used the solution?
I've been using the solution for two years.
What do I think about the stability of the solution?
This is a very stable solution.
What do I think about the scalability of the solution?
The scalability is good. You normally plan for a certain number of users in your environment so that you can size the firewall accordingly. Sangfor provides a buffer for growth of between 15%-30%.
How are customer service and technical support?
Sangfor has fabulous technical support, they are always there. If there's a problem in someone's environment, the data engineers usually visit there within no time to support them.
How was the initial setup?
The way it works in Pakistan is that we have Sangfor technical staff with us and they deal with the technical session, sizing and firewall recommendation, and ultimately implementation. The initial setup doesn't take long.
What other advice do I have?
It's important to note that the performance of the solution depends on the initial pre-working and sizing. The sizing is handled by the company and they know their product, so they normally size it very well. They also put in provision for future growth so there's never an issue of performance.
There's no such thing as 100% so I would rate this solution a nine out of 10.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: partner
Solution Architect at Megaplus
Effective security for small and medium businesses with challenges related to scalability and integration
Pros and Cons
- "The built-in features function as intended, providing exceptional value."
- "Our experience with its customer support was quite challenging."
What is our primary use case?
Sangfor NGAF offers built-in Web Application Firewall capabilities, making it a valuable choice for securing WAF servers. We have implemented this feature in numerous deployments, particularly in the fields of financial management and enterprise environments.
What is most valuable?
We have established an SD-WAN infrastructure with Sangfor NGAF, which has proven to be highly beneficial. The built-in features function as intended, providing exceptional value.
What needs improvement?
It is a relatively new product in the market, so we are dealing with challenges related to security and malware detection. It will need time to assess its strengths and weaknesses thoroughly. We discovered that the SD-WAN capability is available within this product. It also includes built-in Value-Added Security Technology, which can be cost-effective, but improvements are needed, particularly in enhancing malware detection. Another area for improvement is integrating with other third-party providers' solutions for a more seamless security ecosystem.
For how long have I used the solution?
We have been working with it for two and a half years.
What do I think about the stability of the solution?
In terms of stability, there have been occasional issues, such as glitches and disruptions, leading to periods of downtime. Improvement in this area is necessary. I would rate it five out of ten.
What do I think about the scalability of the solution?
Scalability is a key aspect, and we haven't thoroughly tested its compatibility with various other products yet. I would rate it five out of ten.
How are customer service and support?
Our experience with its customer support was quite challenging. There's room for improvement in this aspect.
How was the initial setup?
The initial setup is remarkably straightforward and user-friendly.
What's my experience with pricing, setup cost, and licensing?
The price falls in the mid-range, neither exceptionally low nor high. I would rate it seven out of ten.
What other advice do I have?
Deploying Sangfor NGAF proves highly advantageous for small and medium-sized businesses. Overall, I would rate it seven out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Senior Presales Consultant at Megaplus
Great bandwidth management and vulnerability assessment
Pros and Cons
- "In four steps one can configure the entire firewall."
- "I believe that IAM and NGFW need to merge into a single box, instead of there being two separate box solutions."
What is our primary use case?
I believe I am using the recently updated firmware of version 4.0.
What is most valuable?
User-wise, the bandwidth management is one of the most valuable features. Also, certain features are available in the NGFW.
The solution self-diagnoses everything, which we refer to as vulnerability assessment. It automatically runs on one's network and lists the pros and cons. I consider it to be very catchy.
What needs improvement?
I believe that IAM and NGFW need to merge into a single box, instead of there being two separate box solutions.
For how long have I used the solution?
I have been working with Sangfor NGAF for around three years.
What do I think about the stability of the solution?
So far, the solution has shown itself to be very stable.
What do I think about the scalability of the solution?
The solution is scalable and I can upgrade it to 40, which I consider to be a good thing.
How are customer service and technical support?
Technical support is very good. In a single call, the support person can come on site or address ones needs remotely within minutes.
Which solution did I use previously and why did I switch?
Prior to Sangfor NGAF we worked with Fortinet.
We switched because the previous solution did not readily make available support personnel. Also, while we considered the product to be stable, we felt the support to be very slow.
How was the initial setup?
The setup was easy from the get go. In four steps one can configure the entire firewall.
Give or take, it took no more than two or three hours.
What's my experience with pricing, setup cost, and licensing?
The price is very cheap. It cannot be matched.
Which other solutions did I evaluate?
While Palo Alto claims to be pioneers in vulnerability assessment and risk management, I could not find references on the website to support this. Only Sangfor firewall has the requisite vulnerability assessment.
Moreover, Palo Alto and Sangfor are pretty much equal in terms of technology and interfaces. I was doing research to verify the vulnerability and risk assessments claims promoted on the website, as I was unable to find these.
What other advice do I have?
I am a customer and use Sangfor NGAF 5600 in my premises.
There are more than 2,000 users making use of the solution in my company.
The solution is quite safe and good. Furthermore, it is very good for different environments.
I rate Sangfor NGAF as a nine-point-five out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Owner at InternetWorld Solutions Sdn Bhd
Integrates well, high performance, and responsive support
Pros and Cons
- "Sangfor NGAF works accordingly with our customers. The solution has good performance, easy to use, and integrates well with the endpoints."
What is our primary use case?
Sangfor NGAF can be used as a firewall for protecting servers, data, users, and access to the internet.
What is most valuable?
Sangfor NGAF works accordingly with our customers. The solution has good performance, easy to use, and integrates well with the endpoints.
For how long have I used the solution?
I have been using Sangfor NGAF for approximately one year.
What do I think about the stability of the solution?
We have sold a few units to our customers and we have not had an issue with the stability.
What do I think about the scalability of the solution?
We have customers in small to medium-sized companies.
We have less than 110 customers that are using this solution.
How are customer service and support?
Their technical support is good, they are responsive. They have been able to resolve all of the issues that we faced.
How was the initial setup?
The installation is easy, and the time it takes depends on the customer's environment. Doing the policies could take additional time.
What about the implementation team?
We have approximately four people that support the solution. We have experience in deploying and maintaining the solution. Though the company could offer better training to us.
What's my experience with pricing, setup cost, and licensing?
Sangfor NGAF price is reasonable and there is an annual license. However, the maintenance cost can be a bit high.
Fortinet solutions sell at a very cheap price upfront, but after that maintenance fees, which they keep increasing it can become expensive. I hope Sangfor does not follow that model.
Which other solutions did I evaluate?
I have evaluated other solutions, such as Fortinet.
What other advice do I have?
I would recommend this solution to others.
I have clients that are switching from Fortinet to Sangfor NGAF because the price of Fortinet's service is increasing. Sangfor NGAF has good integration with their endpoints which makes it a very attractive offering.
Sangfor is arranging much-needed training for resellers. There needs to be better marketing awareness not for the reseller, but for the consumer here in Malaysia. Sangfor needs to do some advertisements to attract more market awareness. Relying on resellers can be difficult when the market is very large. However, resellers do focus on their product, they also try to engage, and hire more.
I rate Sangfor NGAF an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer:
Deputy Manager IT at a computer software company with 201-500 employees
Priced well with good end-user security features, but the web interface should be more user-friendly
Pros and Cons
- "Sangfor has the best capabilities for securing connections, securing web browsers, securing servers, and general threat protection."
- "The web interface needs to be improved, making it more user-friendly."
What is our primary use case?
We primarily use this product as an intrusion prevention system.
How has it helped my organization?
Sangfor has the best capabilities for securing connections, securing web browsers, securing servers, and general threat protection.
What is most valuable?
The most valuable part of this product is the set of end-user security features.
What needs improvement?
The web interface needs to be improved, making it more user-friendly.
For how long have I used the solution?
I have been working Sangfor for the last 20 years. I have only recently installed the NGAF, so I am still learning about it.
How was the initial setup?
The initial set was easy.
What about the implementation team?
I installed it myself.
What's my experience with pricing, setup cost, and licensing?
Sangfor is cheaper than competing vendors.
Which other solutions did I evaluate?
I evaluated several other options and found that Palo Alto and Sangfor were the best two. Ultimately, I chose Sangfor.
Price-wise, Sangfor was cheaper than the others and Palo Alto was more expensive than Fortinet.
What other advice do I have?
My advice is that if you have a large enough budget then implement Palo Alto. Alternatively, with a lesser budget, I recommend using Sangfor.
I would rate this solution a seven out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Download our free Sangfor NGAF Report and get advice and tips from experienced pros
sharing their opinions.
Updated: January 2025
Product Categories
FirewallsPopular Comparisons
Fortinet FortiGate
Netgate pfSense
OPNsense
Sophos XG
Cisco Secure Firewall
Palo Alto Networks NG Firewalls
Check Point NGFW
WatchGuard Firebox
SonicWall TZ
Juniper SRX Series Firewall
Untangle NG Firewall
Fortinet FortiGate-VM
SonicWall NSa
Sophos XGS
Fortinet FortiOS
Buyer's Guide
Download our free Sangfor NGAF Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What do you recommend for a corporate firewall implementation?
- Comparison of Barracuda F800, SonicWall 5600 and Fortinet
- Sophos XG 210 vs Fortigate FG 100E
- Which is the best network firewall for a small retailer?
- When evaluating Firewalls, what aspect do you think is the most important to look for?
- Cyberoam or Fortinet?
- Fortinet, Palo Alto or Check Point?
- If you could go back, would you change your decision to buy that firewall and why?
- Sophos XG vs Fortigate UTM
- Can you recommend a solution to replace Cyberoam 200ing Firewall?