No more typing reviews! Try our Samantha, our new voice AI agent.

Cato SASE Cloud Platform vs Citrix SD-WAN [EOL] comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Oct 12, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cloudflare Web Application ...
Sponsored
Average Rating
8.6
Reviews Sentiment
7.4
Number of Reviews
26
Ranking in other categories
Web Application Firewall (WAF) (5th)
Cato SASE Cloud Platform
Average Rating
9.0
Reviews Sentiment
7.5
Number of Reviews
31
Ranking in other categories
WAN Optimization (2nd), Intrusion Detection and Prevention Software (IDPS) (11th), Cloud Access Security Brokers (CASB) (6th), Software Defined WAN (SD-WAN) Solutions (4th), WAN Edge (6th), ZTNA as a Service (7th), Secure Access Service Edge (SASE) (3rd), Remote Browser Isolation (RBI) (2nd)
Citrix SD-WAN [EOL]
Average Rating
8.2
Reviews Sentiment
7.4
Number of Reviews
22
Ranking in other categories
No ranking in other categories
 

Featured Reviews

DB
CTO at PlayNirvana
Advanced security reporting has protected high-traffic betting platforms from constant attacks
I don't see room for improvement to Cloudflare Web Application Firewall. One thing I don't know much about because we have a dedicated IT team for that, and I'm not involved with Cloudflare much anymore. But if I were to compare them to F5, I would like to see more features that F5 offers. F5 has an option to bring the whole infrastructure, the whole WAF and all their packages, Bot Management, and everything else on your infrastructure. You need to install certain services from their side, and then you can choose if you would like requests to hit your servers immediately or if requests need to be proxied through F5 backbone. That would be a nice addition because we have 90% of the traffic as legit traffic coming from whitelisted servers. If it comes from whitelisted servers, I don't need to go every request through the backbone; I could easily just IP whitelist everything. Then I could maybe have Bot Management on my infrastructure that drastically reduces the price of Cloudflare. I would like to see Push CDN more improved in the next release of Cloudflare Web Application Firewall. And maybe something similar to Pushpin that Fastly has, which is an option where you can push messages that then can be scaled globally over the network. From our perspective, if we have a listener that listens for stock updates, I would just need to have one processor that pushes those updates to the Cloudflare API, and then Cloudflare would broadcast that message to all listeners. Cloudflare will check the order of the message, and if you, as a customer, are not connected or have some kind of network issue, when you reconnect, you will receive the latest state and missing updates.
reviewer2697738 - PeerSpot reviewer
Product & Services Integrator at a comms service provider with 10,001+ employees
Cloud security has unified global network design and has simplified threat visibility
I think all of the functionalities, such as the secure web gateway feature, are quite good. I also believe Cato SASE Cloud Platform is one of the only solutions that has not only a software firewall solution but also a physical software solution where you can change the company's firewalls and put in sockets from Cato SASE Cloud Platform, which I see as an advantage for them. The single-pass architecture has improved user experience with Cato SASE Cloud Platform as it provides security teams in companies a platform where they can easily obtain information if there are breaches or security issues. I assess the benefit of integrating WAN optimization as good. There is ease in making rules between WAN optimization, especially when it comes to global connections because of all their points of presence that are spread over the world. I think the real-time threat protection of Cato SASE Cloud Platform is also good. Their points of presence are quite efficient, and I do not see any delays in that area.
Rohit Ghorpade - PeerSpot reviewer
Cloud Network Engineer at a insurance company with 5,001-10,000 employees
A scalable solution for MCN controller but lacks technical supports, upgrades
There are a few things that can be improved, are domain-based routing and the slowness of virtual parts, and it may be due to the wrong configuration, which we have been unable to find out. Previously, we faced some issues with the slowness part. Apart from that, feature like end gateway level antivirus. We are currently using a NetFlow proxy to establish a virtual position for the NetFlow. Our current environment has many use cases, but we are not using them on the Citrix SD-WAN. When I navigate the NCL part, it involves configuration. I want to highlight this disadvantage. Sometimes, when we push the configuration, it tries to push it to all branch locations. This process takes a lot of time, nearly 30 minutes, to push a single change from the NCL. Overall, I don't think Citrix meets our use cases what we have. This is based on my feedback after using it for the past year and working on this Citrix SD-WAN. However, from my experience, it is the worst solution I have seen. There's no domain-based routing, which is horrible. That's why we are moving to other products. We have checked our use case requirements with Fortinet, Palo Alto, and they meet them. I will consider the PoC or another OEM. There are many things in the area you need to be prompt, like the automation part. If any link or device goes down, alerting notification, etc. We need to perform and highlight so many things to your management. This should be improved.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"We like that there's load balancing, firewall capabilities, DDoS protection, et cetera, all covered by Cloudflare."
"I'm highly satisfied. It's remarkably user-friendly, enabling me to quickly identify issues, and deploy solutions, and it offers the necessary features."
"The integration of Cloudflare with Cloud Suite is its most valuable feature."
"The solution protects our application, which runs on the HTTP protocol, from DDoS attacks."
"Cloudflare has positively impacted my organization by making it easier for me to handle and set up DNS for multiple clients; I can easily go in and access their accounts, make changes they need, and it's a one-stop shop."
"Cloudflare WAF provides protection through rules and functionalities like Cloudflare's SDRAP."
"Some of the most valuable features of Cloudflare Web Application Firewall include its DNS zone setup and the zero trust policy."
"It is a SaaS solution unlike much of the competition."
"The Cato SASE Cloud Platform supports my customers' needs for connectivity and security by removing the throttling from the headquarters and putting a firewall in the cloud, instead of having to use a costly MPLS network to perform security inspection on all traffic from various branches."
"Unified management and internet duplication are our most valuable features. They provide a seamless experience for end users—if one link goes down, they can still work without noticing."
"Cato SASE Cloud Platform's self-healing model is the most valuable feature."
"This solution has allowed us to have more points of presence around the world, improved bandwidth across different areas, and provided data leak prevention, CASB, a better dashboard, and the ability to drill down into security problems in a few clicks."
"The product is efficient and easy to use."
"My customer saves millions of pesos when we remove the line dependency for MPLS/IPVPN for domestic and international sites."
"It is quite simple and easy to use."
"It is a stable solution...it is a scalable solution."
"It lowered our Internet costs and gave me the flexibility to choose providers based on each location's connectivity."
"We migrated an online gambling company in South Africa off MPLS onto our SD-WAN solution, and they're saving millions every month purely on MPLS spend."
"The reliability of connectivity is most valuable."
"Citrix SD-WAN helps us in re-routing certain traffic, for example, local internet breakouts for Office 365, and it also helps us to be more agile when we are opening new offices or when we are moving locations."
"It provides a more fluid experience to end-users when they're using their applications or desktops."
"The other banks, bank branches, require good connectivity, which is very important for a branch to have, and they managed to have an SLA of almost 100%."
"CIFS optimisation is really good and benefits are realised if using ICA also."
"We are using it widely for the local record for SaaS-based applications. Another valuable feature is a local breakout."
 

Cons

"The reporting could be more granular."
"The blocked logs are difficult to read at times."
"If they add logs history within the Cloudflare offering, that would be a great benefit."
"The product can improve by having more multitenancy capability, which is currently not available."
"It would be ideal if the solution offered better log integration and more integration with different platforms."
"The solution's learning curve can still be further reduced"
"A key challenge arises when dealing with numerous integrations with HVAC systems. Depending on the specifics, there might be some configuration mismatches, which necessitate specific support."
"It would be ideal if the solution offered better log integration and more integration with different platforms."
"We would like the product to continue to improve its security."
"They can't do one-to-one NAT (Network Address Translation) in AP (their access point), and that is something that Palo Alto can do."
"Cato Networks could improve their intrusion detection."
"Cato Networks could improve their intrusion detection. There is not a lot in place."
"A little tweaking or improvement of the UI in terms of logging when troubleshooting would be an improvement because it's very detailed."
"Its functionality is a bit limited in some areas as compared to a Cisco solution. It is not as granular; it doesn't have the manageability, feature set, and capabilities of a larger or an enterprise-level solution."
"A little tweaking or improvement of the UI in terms of logging when troubleshooting would be an improvement because it's very detailed."
"They should add more sophisticated security features. It should also be integrated into the cloud."
"The price could be improved, it's an expensive solution."
"The communication around the life cycle would have been really helpful. The main issue we have had is related to the life cycle because some of the things that we are using were discontinued. They were discontinued within a year after we had purchased it, which is a bit painful. If we had known that, we would've made some other decisions."
"The firewall reporting could be easier to use and filter. (It works well enough, but if I need to give an area for improvement, I think this would be it.). The built-in reporting on the product in this regard is not great."
"The solution's licensing model could be improved."
"The initial setup is not that easy."
"The reports need to be improved. We need to have them customized but they don't have that right now. I would like for them to have better system predictions. We don't have that right now. My system may be working fine right now but after making some changes, that can change."
"I would like to see more customization to adjust for the WAN lock-out due to our unexpected power outages."
"The solution's licensing model could be improved."
 

Pricing and Cost Advice

"Cloudflare offers different types of subscriptions for businesses, enterprises, and personal users, and the pricing is negotiable."
"What's my experience with pricing, setup cost, and licensing? I believe the pricing is not the best, but it's reasonable and acceptable. We also use the McAfee system in parallel. In terms of pricing, its okay - not great, but not bad either. It falls in the middle, which is acceptable. In terms of support licensing, last time, we were searching for a solution, and we considered products from resellers rather than directly from the cloud provider. However, the pricing we encountered was exceptionally high. As a result, we are inclined to select support from the reseller."
"The pricing model is very straightforward compared to the competition. You just pay per month for the product and usage."
"We pay $210 per month for CloudFlare WAF."
"It is not too pricey."
"It starts at $20 and can easily go up to $200 monthly"
"The solution's pricing option needs to be more transparent for enterprise clients."
"The annual licensing fee is $10,000 USD."
"I'd rate Cato SASE Cloud Platform's pricing as about five or six out of ten. It's not the cheapest solution, but it is cheaper than Palo Alto and even VeloCloud. We've been working with them for a while and have significant discounts. Our licensing costs vary because we keep adding sites, but it's about 280 per month per site. This includes additional features beyond the base product, starting at around 200."
"The pricing is on the higher side, almost an eight out of ten."
"Cato Networks seems more expensive than Cisco Meraki."
"The product is very competitively priced, and that's compelling. They don't charge the customer based on the operational cost like other brands such as Palo Alto. Cato has its own fully-fledged cloud, with their own data centers, equipment, and so on, which is an advantage. I rate the solution five out of five for affordability."
"If you compare with VeloCloud, the price is the same or even cheaper."
"The solution is reasonably priced since Cato Networks provides features like SASE and monitoring, which I am very happy with currently."
"The solution has reasonable pricing. It has a yearly subscription. The pricing depends on the permit to code. Sometimes, we need to increase the permit, and the cost will automatically change. There's no fixed cost. Unless we request additional modules such as DNS security, ELP, and decent features, there will be no additional cost."
"Cato Networks is an expensive product, but it works out of the box, so that's the usual trade-off, make versus buy. If you decide to buy a product that doesn't require much programming, then you'd want to go for Cato Networks, which will work naturally, and immediately without any complex setup. However, the product is a little bit more expensive than the competitors. On a scale of one to five, I'd rate the pricing for Cato Networks as four."
"The price of the subscription should be cheaper."
"It is a bit expensive. A cheaper product would be good, but everybody likes things to be cheaper. We bought the devices up front, and then we pay for the annual support."
"I'm not quite sure of the price ranges. Roughly, the hidden devices can scale up to $20K for one appliance. However, the branch CPs are USD $1,000 to $2,500."
"It's a little bit on the high side compared to the other products."
"The price is relatively expensive."
"The license was a one-time purchase. It's expensive."
"Citrix SD-WAN is quite an affordable product."
"I believe that Citrix SD-WAN is a good investment, but I do not have the information to be more specific."
report
Use our free recommendation engine to learn which WAN Optimization solutions are best for your needs.
893,244 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Construction Company
17%
Comms Service Provider
9%
Financial Services Firm
9%
Computer Software Company
7%
Manufacturing Company
14%
Computer Software Company
11%
Financial Services Firm
9%
Comms Service Provider
9%
Construction Company
12%
Manufacturing Company
9%
Marketing Services Firm
8%
Computer Software Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business16
Midsize Enterprise6
Large Enterprise6
By reviewers
Company SizeCount
Small Business15
Midsize Enterprise7
Large Enterprise11
By reviewers
Company SizeCount
Small Business7
Midsize Enterprise5
Large Enterprise10
 

Questions from the Community

What needs improvement with Cloudflare Web Application Firewall?
I don't see room for improvement to Cloudflare Web Application Firewall. One thing I don't know much about because we...
What is your primary use case for Cloudflare Web Application Firewall?
We are using Cloudflare Web Application Firewall's advanced reporting and analytics tools with their Zero Trust, so e...
What is your primary use case for Cato Networks?
I can see that I am a consultant at a reseller and I am the architect of Cato SASE Cloud Platform designs. In the bas...
What advice do you have for others considering Cato Networks?
It is difficult to find types of companies I would not recommend Cato SASE Cloud Platform to, and I believe you can u...
What is your experience regarding pricing and costs for Cato Networks?
I do not find it particularly expensive, but for some companies, they may not have the budget to be at that level of ...
What needs improvement with Citrix SD-WAN?
The solution's licensing model could be improved. Citrix SD-WAN is a good product from a technical point of view. How...
What advice do you have for others considering Citrix SD-WAN?
If a customer already has Citrix NetScaler and is not looking to change anything in their existing environment, we pr...
 

Also Known As

Cloudflare WAF
Cato Networks
Citrix CloudBridge, WOC, NetScaler SD-WAN
 

Overview

 

Sample Customers

crunchbase, udacity, marketo, okcupid, zendesk
Paysafe, AdRoll, Pet Lovers Centre, Arlington Orthopedics, Humphreys & Partners Architects
AIDS Healthcare Foundation, Cornerstone Home Lending Inc., Dallara, ecVision, Essar, Eurofred, Groupe Promutuel, HMSHost Corporation, Royal Caribbean Cruise Lines Ltd, Royal Caribbean International
Find out what your peers are saying about Riverbed, Cato Networks, Hewlett Packard Enterprise and others in WAN Optimization. Updated: April 2026.
893,244 professionals have used our research since 2012.