No more typing reviews! Try our Samantha, our new voice AI agent.

Check Point Quantum Force (NGFW) vs Sangfor NGAF comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Mar 1, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Fortinet FortiGate
Sponsored
Ranking in Firewalls
1st
Average Rating
8.4
Reviews Sentiment
6.9
Number of Reviews
592
Ranking in other categories
Secure Web Gateways (SWG) (2nd), Intrusion Detection and Prevention Software (IDPS) (1st), Software Defined WAN (SD-WAN) Solutions (1st), WAN Edge (1st), ZTNA (1st), Unified Threat Management (UTM) (1st)
Check Point Quantum Force (...
Ranking in Firewalls
7th
Average Rating
8.8
Reviews Sentiment
7.2
Number of Reviews
347
Ranking in other categories
Unified Threat Management (UTM) (2nd)
Sangfor NGAF
Ranking in Firewalls
21st
Average Rating
8.0
Reviews Sentiment
6.5
Number of Reviews
34
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of June 2026, in the Firewalls category, the mindshare of Fortinet FortiGate is 15.1%, down from 21.7% compared to the previous year. The mindshare of Check Point Quantum Force (NGFW) is 3.0%, up from 2.9% compared to the previous year. The mindshare of Sangfor NGAF is 1.1%, down from 1.3% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Firewalls Mindshare Distribution
ProductMindshare (%)
Fortinet FortiGate15.1%
Check Point Quantum Force (NGFW)3.0%
Sangfor NGAF1.1%
Other80.8%
Firewalls
 

Featured Reviews

Mageshwaran S - PeerSpot reviewer
Solution Architect at airtel
Enables customers to manage security effortlessly with intuitive features and easy integration
In terms of improvements for Fortinet FortiGate, they could offer evaluation licenses, as compared to Meraki, which provides a 90-day evaluation. In Fortinet FortiGate, they do not provide standard evaluation licenses; instead, we need to request them from the OEM through the account manager for POCs. If we want to conduct a demo, we need to work with real hardware. In comparison to Cisco, we have DCloud, which helps with providing demos to customers, but in Meraki, I need to reach out to them, book a lab, and they need to provide all the hardware. I need remote access and L3 engineers to program it; only then can I offer a real-time demo to the customer.
DS
Network Security Engineer at Connecting Cyber Networks
Advanced threat prevention has protected our perimeter and simplifies daily security operations
Check Point Quantum Force (NGFW) can be improved in several areas. First, the interface could be a little more intuitive for new users. The Smart Console is powerful, but it has a steep learning curve when you start using it. Some simple functions for common tasks would help. Second, the initial setup and configuration take quite a bit of time and expertise. It would be helpful if there were more guides, wizards, or templates to speed that up. Third, the price model could be more transparent and flexible. The license cost can add up quickly, specifically when you want to add more advanced features. Finally, I would appreciate seeing better integration with some third-party security tools we use. Right now, we have to do a lot of manual work to make everything talk to each other. Overall, these are minor things. The core product is really solid and does what it is supposed to do very well. The documentation could be more comprehensive in some areas. When we run into issues, the documentation does not have clear answers, so we end up contacting support. Speaking of support, the response time could be faster sometimes. We have had cases where we need help with a certain security issue, and it takes longer than we would prefer to get a response. As for features, it would be nice to have more general reporting options so we can customize reports for different teams and stakeholders without having to do manual work afterward. One more thing, better mobile access to the dashboard would be helpful. Sometimes we need to check on security alerts when we are away from the office, and the mobile experience is not as smooth as it could be. Again, these are improvements that would make it even better, not issues with the core product itself.
Zaid Farooqui - PeerSpot reviewer
CIO at Indus Motor Company
Enhanced threat detection with integrated security features and good support
We are using application firewalling, WAF, and SD-WAN. The capabilities are mostly within the box. For example, you will get web application firewall WAF as part and parcel of this. SD-WAN is also bundled. It integrates with their SIEM and SOAR solutions very nicely. Lastly, the pricing point is very cost-efficient as well.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"I am content with its user interface and functionalities."
"I like the security that Fortigate offers; it has great URL filtering with a next-generation firewall that can do internet routing, plus give us advanced layer seven application control."
"The technical support is great."
"We use it for our paralegal security, our internet operations, and network zone segmentation."
"All of the features of Fortinet FortiGate are useful and the security protection is good."
"The initial setup is very straightforward and easy, with wizards helping to configure the device efficiently."
"The most valuable features are SD-WAN, application control, IPS control, and FortiSandbox."
"The user interface is intuitive; anyone can configure the firewall with little knowledge of the product, and the back-end is robust with good security."
"I recommend this product, as it offers good value and is a high-quality solution."
"After deploying Check Point Quantum Force (NGFW), we are very secure from cyber threats; our resources are protected, and our endpoint devices are prevented from downloading malicious files."
"The initial setup is straightforward."
"We can manage which users have access to certain websites."
"By deploying Check Point, it has made it easier to manage everything from a single interface. The management dashboard and policies are on its single pane of glass."
"The ability to split single hardware into multiple virtuals along with support for dynamic routing using BGP is very useful for our environment."
"The AI feature of Check Point Quantum Force (NGFW) is excellent; we don't have to configure the NAT policy in the firewall because once we configure the object, we enable the NATting for that object."
"The tool provides great security."
"We've found the technical support to be helpful."
"It offers application control features."
"In our hospital, Sangfor NGAF works well for us in terms of ensuring confidentiality and availability, which are crucial in the healthcare industry."
"The absolute best part of Sangfor NGAF is their support; it's a 24/7 support channel, and the last time I requested their assistance I got a reply within three minutes and they helped solve the problem immediately."
"The support from Sangfor NGAF here in Pakistan is great."
"I think this solution is a very good example of a proactive solution that can detect problems and immediately fix the problems or issues."
"The price versus value is good because the solution is less expensive than Sophos, Fortinet, or SonicWall."
"Sangfor NGAF's standout feature is its powerful application control, enabling precise restrictions on mobile user access to approved applications."
 

Cons

"Fortinet FortiGate is a firewall solution and once it's deployed, you can rest assured that your system is secure."
"The support package being an additional extra, even with an enterprise package purchase, is pathetic. Though I haven't had direct experience with support, the fact that it doesn't come by default, which is very misleading compared to other brands, warrants a rating of two out of ten."
"The tech support is not excellent; this is where Fortinet saves money compared to others... But plenty of free, clear and public documentation is available and this compensates for the most part the tech support shortcomings."
"The area that Fortinet may improve is customer support. When you have an incident, situation, or open a case, the support is not as good as Cisco or other platforms I have tested."
"In most cases, the IPS engine uses too many resources, which makes Fortinet FortiGate devices unstable."
"The reporting in Fortinet FortiGate could improve. Customers are having to purchase additional reporting components. When I have used the Sophos solution it is a complete solution, in Fortinet FortiGate you have to use additional tools to have the features needed."
"One of the most important areas for improvement for Fortinet FortiGate is the limited resources for tests. I was limited to a few interfaces for one month, and it would be great if Fortinet could improve these features in their test versions."
"Deploying FortiGate is hard."
"While the Smart Console is powerful, I find that it can feel heavy and slow with a large rules base, where a simple policy change sometimes takes longer than expected, impacting agility in a fast-moving environment."
"The whole solution has room for improvement."
"It could greatly improve our customer experience by centralizing management."
"Of the areas of improvement that I want to see in this product, without a doubt, one is the technical support. In this time of globalization, with so many cyberattacks and risks, the Check Point support staff take a long time to attend to incidents due to the high demand."
"In terms of what could be improved, I would say the application control and the visibility. I'd like granularity where you can have all the levels of policies that are defined, including the intel threat. It depends on what kind of intel threat the company has."
"Check Point can improve in the VPN sector because I still have a problem using VPN in active-active with its R82 feature since it can only incorporate with active tunnel route mode to route mode and policy-based to policy-based."
"There is room for improvement in application-based filtering, as with other firewalls available in the market today."
"I would like the user interface to be more user-friendly. I want the UI to be easier to use than Check Point's competitors."
"The product must provide more IPS features."
"An area for improvement would be the number of ports defined on the box. In the next release, I would like them to develop their provisioning stage of enrolling end devices."
"There is room for improvement in dependency on certain infrastructure, like the DNS dependency on the current DNS server that the company has. It should be standalone. It should not depend on any other DNS server."
"The reporting and log management could be improved."
"They need to improve their research team and they need to study their data to analyze it and build the product."
"The support for YouTube or the Internet is not enough."
"Sangfor NGAF could improve the policies and default criteria. They could be much better."
"Sangfor need greater exposer in the market because the market is mainly saturated by Fortinet. The user experience of Fortinet is quite different compared to NGAF. If we want to switch our users from Fortinet to NGAF, we have to convince them that the user experience will be much easier once once they start to use it."
 

Pricing and Cost Advice

"The product is expensive compared to one of its competitors."
"The price is fine."
"We pay $500 per year for the license."
"Fortinet FortiGate is cost-efficient. Palo Alto is expensive, but Fortinet FortiGate is not."
"It was worth the money overall. It's good value."
"It is more affordable than Check Point and Palo Alto. Another thing is that all the features and the OS remain the same irrespective of the size of the device. Pricing-wise, Fortinet typically provides one-year support with the firewall appliance. There is also an option for three years which is how their licensing works."
"While Fortinet FortiGate has a higher price point compared to Sophos XG, its user-friendly interface justifies the cost."
"It is a good product from a price perspective versus functionality."
"The solution is indeed costly."
"Check Point needs to lower its price drastically, and the licensing model is very complex."
"The pricing of Check Point is fair when compared to others."
"It is more expensive than Cisco ASA but cheaper than Palo Alto."
"Before you buy, check which features you need, and if possible, I recommend signing up for at least a three-year license."
"The price is high in comparison to other solutions."
"I rate the solution's pricing an eight out of ten. It costs around 100,000-200,000 dollars per month. Besides standard licensing fees, we paid extra for enterprise-level premium support. There were also onboarding costs factored in. These additional costs made it more expensive overall. The total cost was around 100,000 dollars, which was challenging for our budget. Check Point was also pricey, not much different from Palo Alto Networks. However, we decided switching to Check Point was better because it offered more capabilities for a similar price."
"I don't see that Check Point is very high, but it is geared more towards enterprises."
"For four to five physical appliances for a licensed firewall, it costs approximately $4,000."
"Sangfor is cheaper than competing vendors."
"The price falls in the mid-range, neither exceptionally low nor high."
"If one is very cheap and ten is very expensive, I rate the tool's price as three out of ten."
"Sangfor NGAF is a cheaply priced product, especially if I consider the previous product that was used in my company."
"If you know you have around 200+ computer users on your network, then the Sangfor NGAF 5200-F-I model would be the minimum recommended model for that amount of users. This model includes modules for packet filtering, deep packet inspection, malware scanning, DSCP filtration, and many other features."
"The price could be more competitive."
"It is one of the cheapest tools in the market."
report
Use our free recommendation engine to learn which Firewalls solutions are best for your needs.
900,747 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Comms Service Provider
10%
Computer Software Company
9%
Manufacturing Company
9%
Financial Services Firm
7%
Outsourcing Company
13%
Financial Services Firm
11%
Construction Company
10%
Computer Software Company
10%
Financial Services Firm
11%
Manufacturing Company
10%
Comms Service Provider
9%
Construction Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business370
Midsize Enterprise138
Large Enterprise195
By reviewers
Company SizeCount
Small Business163
Midsize Enterprise94
Large Enterprise199
By reviewers
Company SizeCount
Small Business15
Midsize Enterprise10
Large Enterprise10
 

Questions from the Community

Which is the better NGFW: Fortinet Fortigate or Cisco Firepower?
When you compare these firewalls you can identify them with different features, advantages, practices and usage a...
What is the biggest difference between Sophos XG and FortiGate?
From my experience regarding both the Sophos and FortiGate firewalls, I personally would rather use FortiGate. I know...
What are the biggest technical differences between Sophos UTM and Fortinet FortiGate?
As a solution, Sophos UTM offers a lot of functionality, it scales well, and the stability and performance are quite ...
How does Check Point NGFW compare with Fortinet Fortigate?
I have experience on both from Disti and channel experience. Please find below my comments (nothing new as such). -Ch...
Which would you recommend - Azure Firewall or Check Point NGFW?
Azure Firewall is easy to use and provides excellent support. Valuable features include integration into the overall ...
What is your experience regarding pricing and costs for Check Point NGFW?
Our experience with pricing for Check Point Quantum Force (NGFW) has been mixed. The initial setup costs were fairly ...
What is your experience regarding pricing and costs for Sangfor NGAF?
The licensing cost is quite high compared to other available firewalls in the market.
What needs improvement with Sangfor NGAF?
The cost of licensing is very high compared to other firewalls available here. There should be improvements in hardwa...
What is your primary use case for Sangfor NGAF?
We are hosting applications over the platform, including websites and NAT traffic from our side. Because it's deploye...
 

Also Known As

Fortinet FortiGate Next-Generation Firewall
Check Point NG Firewall, Check Point Next Generation Firewall
Sangfor NGAF Firewall Platform
 

Overview

 

Sample Customers

Amazon Web Services, Microsoft, IBM, Cisco, Dell, HP, Oracle, Verizon, AT&T, T-Mobile, Sprint, Vodafone, Orange, BT Group, Telstra, Deutsche Telekom, Comcast, Time Warner Cable, CenturyLink, NTT Communications, Tata Communications, SoftBank, China Mobile, Singtel, Telus, Rogers Communications, Bell Canada, Telkom Indonesia, Telkom South Africa, Telmex, Telia Company, Telkom Kenya
Control Southern, Optimal Media
The Ministry of Science, Technology, and Innovation (Indonesia), Lawson, Inc. (Philippines), Universiti Sultan Zainal Abidin (Indonesia), TEK Automotive (Italy), etc.
Find out what your peers are saying about Check Point Quantum Force (NGFW) vs. Sangfor NGAF and other solutions. Updated: June 2026.
900,747 professionals have used our research since 2012.