No more typing reviews! Try our Samantha, our new voice AI agent.

Arista NDR vs Forcepoint Next Generation Firewall comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Arista NDR
Average Rating
9.0
Reviews Sentiment
7.6
Number of Reviews
14
Ranking in other categories
Network Traffic Analysis (NTA) (9th), Network Detection and Response (NDR) (17th)
Forcepoint Next Generation ...
Average Rating
7.6
Reviews Sentiment
6.5
Number of Reviews
52
Ranking in other categories
Firewalls (18th), Software Defined WAN (SD-WAN) Solutions (8th), WAN Edge (7th)
 

Mindshare comparison

While both are Network Security Systems solutions, they serve different purposes. Arista NDR is designed for Network Detection and Response (NDR) and holds a mindshare of 3.3%, down 4.1% compared to last year.
Forcepoint Next Generation Firewall, on the other hand, focuses on Firewalls, holds 0.9% mindshare, up 0.4% since last year.
Network Detection and Response (NDR) Mindshare Distribution
ProductMindshare (%)
Arista NDR3.3%
Darktrace14.8%
Vectra AI11.2%
Other70.7%
Network Detection and Response (NDR)
Firewalls Mindshare Distribution
ProductMindshare (%)
Forcepoint Next Generation Firewall0.9%
Fortinet FortiGate16.0%
OPNsense8.9%
Other74.2%
Firewalls
 

Featured Reviews

it_user1719513 - PeerSpot reviewer
Chief Technology Officer at a financial services firm with 11-50 employees
it's much easier to create your own queries and hunt for threats
We take in IOCs from my SOC and from AlienVault, and then we focus on traffic that hits IOCs and alerts us to it. The one thing that the Awake platform lacks is the ability to automate the ingestion of IOCs rather than having to import CSV files or JSON files manually. Awake didn't support the manual importation of CSV and JSON in version 3.0, but they added it in version 4.0. It's helpful, but it still has to be a specific CSV format. Automated IOCs are on the roadmap. Hopefully, they will be able to automate the ingestion of IOCs by Q1 next year. I'm currently leveraging Mind Meld, an open-source tool by Palo Alto, to ingest IOCs from external parties. I aggregate those lists and spit them out as a massive list of domains, hashes, file names, IPS. Then we aggregate those into their own specific categories, like a URL category. Awake ingests that just like the Palo Alto firewall does, and then it alerts me if traffic attempts to go into it. Some of that is already on the Palo Alto firewall, which blocks it, but that doesn't mean that there is no attempted communication. I want to know if there's a communication attempt because there might be an indicator on that specific device trying to reach an IOC. Yes, my Palo Alto blocked it, but there's still something odd sitting there, and what if it can reach a different IOC that I don't have information about? I want to focus on it. I could do that by leveraging Awake if it could ingest the IOCs automatically. That's something I leverage Awake for today. I still have to manually import it, which is cumbersome because I have to manipulate the files that I get from the different IOC providers into a specific format that it understands. Once they add the ability to automate that, it'll be more useful.
Ajit Pratap Kundan - PeerSpot reviewer
Pre Sales Lead Government & Defense at Accops Systems Pvt Ltd
Unified security management has improved traffic control and simplified remote workforce access
Forcepoint Next Generation Firewall does help in vulnerability identification and response by providing a single unified console through which I am able to monitor and manage infrastructure. The URL filtering capability of Forcepoint Next Generation Firewall helps in blocking malicious sites. We have to take care of both known threats and unknown threats. The firewall takes care of known threats, and we protect ourselves from unknown threats such as malicious code and malware that we cannot create firewall rules for. With these routing capabilities and policies, only whitelisted things get processed or passed. The biggest advantages of Forcepoint Next Generation Firewall, especially as a partner, service provider, and integrator, are that it is very easy to integrate these APIs with our solution, and most of the features I am getting in the clientless mode. Even with the client mode, it is easy to integrate with our client, allowing the customer to get a single client to address all the features of the firewall as well as the GTNA perspective. The flexibility of deployment, especially for the government and defense sectors, is that they want an on-premises solution, while the rest of the PSUs or enterprise segment are comfortable with the cloud offering, which is the SaaS offering and the way to go in the future.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The interface itself is clean and easy to use, yet customizable. I like that I can create my own dashboards fairly easily so that I can see what is important to me. Also, the query language is pretty easy to use. I haven't needed to use it a ton, but as I need to go in and do different queries based on their requests, it has been fairly simple to use."
"Awake has really easy of use; it was just far easier to use as far as seeing rich, actionable data than LogRythm, with less of a learning curve to understand what they were trying to represent."
"Arista NDR's scalability is very good, making it easy to add more hardware components. You can order additional hardware and integrate it by stacking it with the existing setup. This feature cannot be seen in other NDR tools."
"The security knowledge graph has been very helpful in the sense that whenever you try a new security solution, especially one that's in the detection and response market, you're always worried about getting a lot of false positives or getting too many alerts and not being able to pick out the good from the bad or things that are actual security incidents versus normal day to day operations. We've been pleasantly surprised that Awake does a really good job of only alerting about things that we actually want to look into and understand. They do a good job of understanding normal operations out-of-the-box."
"It gives us something that is almost like an auditing tool for all of our network controls, to see how they are performing. This is related to compliance so that we can see how we are doing with what we have already implemented. There are things that we implemented, but we really didn't know if they were working or not. We have that visibility now."
"This solution’s encrypted traffic analysis helps us stay in compliance with government regulations. It is all about understanding data exfiltration, what is ingressing and egressing in our network. One common attack vector is exfiltrating data using encryption. My capabilities to see potential data exfiltration over encrypted traffic is second to none now."
"The most valuable feature is the ability to see suspicious activity for devices inside my network. It helps me to quickly identify that activity and do analysis to see if it's expected or I need to mitigate that activity quickly."
"The most valuable portion is that they offer a threat-hunting service. Using their platform, and all of the data that they're collecting, they actually help us be proactive by having really expert folks that have insight, not just into our accounts, but into other accounts as well. They can be proactive and say, 'Well, we saw this incident at some other customer. We ran that same kind of analysis for you and we didn't see that type of activity in your network.'"
"Forcepoint Next Generation Firewall has positively impacted my organization by providing always-on perimeter security."
"Forcepoint Next Generation Firewall is quite affordable, cheaper than other brands like Palo Alto or Check Point, with a lot of capabilities, very stable, and very well-made, making it a really good product for its price when compared to other vendors."
"The most valuable feature is the console management."
"Previously, it was very difficult to handle all traffic because multiple locations experienced downtime, firewalls went down, and internet connectivity issues occurred, but after Forcepoint SD-WAN solutions were deployed across different locations, all traffic goes through Wi-Fi solutions, which are directly connected to Forcepoint Next Generation Firewall, making it very easy, time-saving, and improving security."
"The feature that we like the most about Forcepoint is that we know the technology and have confidence in it. We can have several functionalities to simplify operations and management. We can combine functionalities like log ownership to review the number of devices in the infrastructure."
"We are a platinum partner of Forcepoint, and it is a stable solution with no issues so far."
"The initial setup is very easy."
"The product's initial setup phase is easy."
 

Cons

"One thing I would like to see is a little bit more education or experience on AWS cloud for their managed services team."
"While the appliance is very good, and I think they're working on it, it would probably help if they integrated the management team cases into the appliance so that everything we are working on with them would be accessible on our platform, on the dashboard, on the portal. Right now, Awake is just an additional team that uses the appliance that we use and then we communicate with them directly. Communication isn't through the portal."
"When I looked at the competitors, such as Darktrace, they all have prettier interfaces. If Awake could make it a little more user-friendly, that would go a long way."
"There's room for improvement with some of the definitions, because I don't have time and I'm not a Tier 4 analyst. I believe that is something they're working towards."
"While the appliance is very good, and I think they're working on it, it would probably help if they integrated the MNDR generated cases into the appliance so that everything we are working on with them would be accessible on one platform, on the dashboard, on the portal."
"When I looked at the competitors, such as Darktrace, they all have prettier interfaces. If Awake could make it a little more user-friendly, that would go a long way."
"They've been focused on really developing their data science, their ability to detect, but over time, they need to be able to tie into other systems because other systems might detect something that they don't."
"I would like to see a bit more in terms of encrypted traffic. With the advent of programs that live off the land, a smart attacker is going to leverage encryption to execute their operation. So I would like to see improvements there, where possible. Currently, we're not going to be decrypting encrypted traffic. What other approaches could be used?"
"The solution needs to add an antivirus profile and anti-spyware profile, not just policies and VPN."
"I would like to see more sizing in the next release, and the roadmap should be clear."
"They need to improve their alerts."
"We feel the product's technical support could be better, as this relates to the solution itself, to the installation of the product, and to having a proper understanding of the case."
"The security features need to be improved."
"When it comes to a complex deployment, the rules, firewall features, SD-WAN core features, and auto-scaling can cause the device to be not quite stable."
"The network interface could be better, and it could be cheaper."
"The network interface could be better, and it could be cheaper."
 

Pricing and Cost Advice

"The solution has saved thousands of dollars within the first day. Our ROI has to be in the tens of thousands of dollars since October last year."
"We switched to Awake Security because they were able to offer a model that was significantly less expensive and the value that we get out of it is higher."
"The pricing seems pretty reasonable for what we get out of it. We also found it to be more competitive than some other vendors that we've looked at."
"The solution is very good and the pricing is also better than others..."
"Awake Security was the least expensive among their competitors. Everyone was within $15,000 of each other. The other solutions were not providing the MNDR service, which is standard with Awake Security's pricing/licensing model."
"Awake's pricing was very competitive. It's not a cheap option though. It's an investment to utilize it, but it's one that we decided was worth the cost, with the managed services. At our scale, it was a much better option to utilize their software and their managed services to handle this, rather than hiring another person to be an analyst. It was quite cost-effective for us."
"Because I represent a hedge fund, I have some leverage. I told them that they had to meet my conditions if they wanted me as a client. It was the same way with Awake. They wanted an initial four-year agreement. Initially, we signed on for a one-year contract, but they wanted the four-year deal when it came time for the renewal. I told them that I was not doing that. I said that they either had to do it on my terms, or I'd go somewhere else."
"It is expensive."
"The pricing of the solution is normally competitive with other products."
"The pricing should be more competitive against other vendors in the market."
"Everything in Forcepoint comes with an individual license, which is kind of a problem. In our last meeting, they said that it may change at the beginning of 2021, and they will try to merge some licenses together. Customers will get more features than what they got previously. We will wait and see."
"The cost is fair, but it could be improved."
"Next Generation Firewall is moderately priced."
"There is a need to make payments towards the licensing charges attached to the product. The product is not expensive."
"There is a license required to use this solution and we can purchase it for one, two, three, or five years."
report
Use our free recommendation engine to learn which Network Detection and Response (NDR) solutions are best for your needs.
893,244 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
10%
Computer Software Company
8%
Government
8%
Comms Service Provider
7%
Construction Company
10%
Manufacturing Company
9%
Financial Services Firm
9%
Computer Software Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business5
Midsize Enterprise2
Large Enterprise7
By reviewers
Company SizeCount
Small Business29
Midsize Enterprise11
Large Enterprise14
 

Questions from the Community

Ask a question
Earn 20 points
What is your experience regarding pricing and costs for Forcepoint Next Generation Firewall?
In terms of price, I would say Forcepoint Next Generation Firewall is not expensive. It is very much comparable to other vendors, and pricing is not a problem, especially for the Asian market, with...
What needs improvement with Forcepoint Next Generation Firewall?
The negative side of Forcepoint Next Generation Firewall is that the ZTNA part is missing. For that, we have to integrate a third-party component with Forcepoint Next Generation Firewall to complet...
 

Also Known As

Awake Security Platform
Forcepoint NGFW, Stonesoft Next Generation Firewall, McAfee Network Security Platform, Intel Security Network Security Platform
 

Overview

 

Sample Customers

- Dolby Laboratories- Seattle Genetics- ARM Energy- Ooma- Prophix- Yapstone
California Department of Corrections and Rehabilitation (CDCR)
Find out what your peers are saying about Darktrace, Vectra AI, TrendAI and others in Network Detection and Response (NDR). Updated: May 2026.
893,244 professionals have used our research since 2012.