Try our new research platform with insights from 80,000+ expert users

Cisco Catalyst SD-WAN vs Citrix SD-WAN [EOL] comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Oct 12, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Fortinet FortiGate
Sponsored
Average Rating
8.4
Reviews Sentiment
6.9
Number of Reviews
580
Ranking in other categories
Secure Web Gateways (SWG) (2nd), Firewalls (1st), Intrusion Detection and Prevention Software (IDPS) (1st), Software Defined WAN (SD-WAN) Solutions (1st), WAN Edge (1st), ZTNA (1st), Unified Threat Management (UTM) (1st)
Cisco Catalyst SD-WAN
Average Rating
8.0
Reviews Sentiment
6.7
Number of Reviews
98
Ranking in other categories
Network Management Applications (5th), Software Defined WAN (SD-WAN) Solutions (2nd), WAN Edge (2nd)
Citrix SD-WAN [EOL]
Average Rating
8.2
Reviews Sentiment
7.4
Number of Reviews
22
Ranking in other categories
No ranking in other categories
 

Q&A Highlights

OT
Assistant Vice President - IT at Au small finance bank
May 08, 2020
 

Featured Reviews

Vasu Gala - PeerSpot reviewer
Manager, Information Technology Operation/Presales at TechMonarch
A stable solution with an intuitive interface and quick customer service
I have been working with Fortinet FortiGate, WatchGuard, Sophos, and SonicWall. I'm not as comfortable with SonicWall because of their UI and limitations. I prefer Fortinet above all other options. When it comes to configuration, I am confident in my ability to handle various tasks, including creating policies such as firewall rules, web policies, and application policies. Additionally, I can configure VPNs and implement load balancing, among other tasks. Overall, I feel much more comfortable working with Fortinet. Fortinet has made significant improvements by integrating AI with firewalls for threat analysis and prevention. In the past 2-3 years, they have launched FortiSASE and SIEM, and they also provide SOC services. Both Palo Alto and Fortinet FortiGate are excellent. While Fortinet FortiGate comes at higher prices, the functionality and support justify the cost. They promptly resolve firmware issues and inform all support providers about configuration changes.
ND
Network Manager at HPCL
Faced complex visibility and policy challenges but have improved basic traffic routing control
I have found some other solutions more insightful and user-friendly as compared to Cisco Catalyst SD-WAN, but the basic SD-WAN functionality is good enough. I am using it only because it was done as a pilot project, specifically for my 60 to 70 sites. For the majority of the sites, I am using Fortinet's Secure SD-WAN solution and I found that more viable and more in alignment with my requirements. For example, there is not any Internet Service Database available in Cisco Catalyst SD-WAN intrinsically. If I want to write a policy based on applications, I am not able to write it, at least in Cisco Catalyst SD-WAN Viptela deployment that we have done, and that is fairly easy to do in Fortinet. The second issue is the logging capability. I think the visibility that Fortinet Secure SD-WAN has is not even comparable. Cisco Catalyst SD-WAN does not provide that sort of insight or control as far as traffic steering is concerned. With respect to the SLAs, I barely know which sort of SLAs are violated in Cisco Catalyst SD-WAN, so I do not have clear visibility on where the traffic is moving from at my spoke or hub locations. I believe Fortinet gives me a very clear picture of where the traffic is going. Overall visibility, whether it is data traffic or logs, is much better in Fortinet compared to Cisco Catalyst SD-WAN. The complexity of Cisco Catalyst SD-WAN Viptela is noticeable and quite complicated to configure. If something breaks, you have to involve TAC and others to fix it. On the contrary, you can work with underlays. Even if your IPsec overlay tunnel is down, it does not impact your production. Thus, we find Fortinet's solution significantly better than Cisco Catalyst SD-WAN solution. I have used Application-aware Routing in Cisco Catalyst SD-WAN. However, I found it to be very complicated, especially regarding policy writing. For my breakout of VC traffic, we had to write a bunch of IP addresses for Zoom, Webex, and others. Presently, it can only identify Webex as an application, and I highly doubt whether there is any application identification for Zoom and other platforms, as we were not able to find it during our implementation. It is done through static whitelisting of the IPs, which is not a scalable solution since IPs can change at any time. Overall, the application-aware routing policies are not as flexible and scalable as the Internet Service Database feature of Fortinet provides. The struggles encompass policy writing, logging capabilities, traffic visibility, and complex configuration. There is also the issue of load balancing. We have faced considerable challenges with traffic load balancing between the links. Although the SLA targets are configurable, understanding how traffic flows is challenging, making troubleshooting exceedingly difficult. Overall, I find it a quite complicated solution with not that much operational usability.
Rohit Ghorpade - PeerSpot reviewer
Cloud network engineer at Bajaj Allianz General Insurance Co. Ltd.
A scalable solution for MCN controller but lacks technical supports, upgrades
There are a few things that can be improved, are domain-based routing and the slowness of virtual parts, and it may be due to the wrong configuration, which we have been unable to find out. Previously, we faced some issues with the slowness part. Apart from that, feature like end gateway level antivirus. We are currently using a NetFlow proxy to establish a virtual position for the NetFlow. Our current environment has many use cases, but we are not using them on the Citrix SD-WAN. When I navigate the NCL part, it involves configuration. I want to highlight this disadvantage. Sometimes, when we push the configuration, it tries to push it to all branch locations. This process takes a lot of time, nearly 30 minutes, to push a single change from the NCL. Overall, I don't think Citrix meets our use cases what we have. This is based on my feedback after using it for the past year and working on this Citrix SD-WAN. However, from my experience, it is the worst solution I have seen. There's no domain-based routing, which is horrible. That's why we are moving to other products. We have checked our use case requirements with Fortinet, Palo Alto, and they meet them. I will consider the PoC or another OEM. There are many things in the area you need to be prompt, like the automation part. If any link or device goes down, alerting notification, etc. We need to perform and highlight so many things to your management. This should be improved.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Since deploying FortiGate 3401E clusters, we have observed: Dramatic Reduction in Risk Exposure—blocked peer-to-peer and unauthorized applications (e.g., BitTorrent) at the perimeter and east-west segments, eliminating a major source of malware and bandwidth abuse."
"The features that we have found most valuable are the SSL VPN and the User Portal."
"The best features of Fortinet FortiGate include its easy configuration and user interface."
"I like its ability to prevent external intrusion into our database. It's so fun."
"It's an easy solution to set up."
"The most important features of Fortinet FortiGate are the Intrusion Prevention System (IPS) and firewall control applications."
"Its stability is the most valuable."
"The integration of SD-WAN capabilities with Fortinet FortiGate has positively impacted application performance."
"The solution sufficiently provides ISPs."
"The most valuable features, application awareness, and failover resilience, stand out as key considerations for users."
"There is minimum blind space in this solution."
"Cisco SD-WAN is a good product."
"Cisco SD-WAN's most valuable feature is the ease of transition."
"It's very easy to manage and monitor the network's health and security using the solution."
"If I have to give a neutral view of all the SD-WAN platforms that I have known so far, Cisco is good in routing."
"It is a very scalable solution."
"The zero-touch deployment is most valuable for us."
"The main advantage of Citrix SD-WAN is that it enables fast communication between our branches and data centers. And, with its cloud management features, it also makes the process of adding new branches into our company network much easier."
"It allows us to use additional VPNs, offering more options compared to other VPN solutions."
"It lowered our Internet costs and gave me the flexibility to choose providers based on each location's connectivity."
"The stability is the main feature of Citrix SD-WAN. You can also upgrade the data packages or have less transmission."
"The most valuable feature is security, as it gives me the port bindings that cannot be accomplished using other solutions."
"We are using it widely for the local record for SaaS-based applications. Another valuable feature is a local breakout."
"The best feature is the backup capability, where all of the users' computers are tied into a central data repository."
 

Cons

"Web security solutions can be improved."
"At the moment, the main concern is the pricing and the type of licensing. Fortinet offers different types of licensing, and my idea is that the best approach is to have only one, two, or a maximum of three types of licensing."
"We were not able to build a full-mesh VPN; however, I am not sure if this was the fault of Fortinet FortiGate."
"It claims it does DLP, but the degree and level of controls are very basic."
"In the next release, maybe the documentation on how to use this solution could be improved."
"Fortinet needs more memory to save the log files. We need it to save the logs on the hardware and not in the cloud. I know this feature is available in FortiCloud, but if we need this log locally, it is not available."
"Though the tool's GUI is user-friendly, it can be considered as an area with certain shortcomings where improvements are required."
"Fortinet FortiGate SWG should be localised to specific regions to comply with local data privacy regulations because of the data privacy rules in the countries. In the Middle East, data organisation and KFA requirements are stringent."
"Better pricing and greater security would be nice to see."
"It should also be much more affordable for a larger number of customers."
"The solution should be more user-friendly."
"I would like to see features related to security compliance, including a view of compliance with standards. With this, I should be able to do an audit of my network with SDWAN."
"This solution could be improved with a simpler implementation process and licensing model."
"The UI has room for improvement."
"Cisco SD-WAN could improve on the ease of integration, the configuration should be easier. At the moment the process is more command line based and it would be better if it was able to be done through an interface."
"In the next release, Cisco should focus on simplifying the configuration of SD-WAN. SD-WAN has a lot of room to grow."
"Enhancements are needed to improve the stability."
"The firewall reporting could be easier to use and filter. (It works well enough, but if I need to give an area for improvement, I think this would be it.). The built-in reporting on the product in this regard is not great."
"Even though the monitoring is pretty good, there is some room for improvement there."
"I would like to see more customization to adjust for the WAN lock-out due to our unexpected power outages."
"There are a few things that can be improved, are domain-based routing and the slowness of virtual parts, and it may be due to the wrong configuration, which we have been unable to find out."
"The communication around the life cycle would have been really helpful. The main issue we have had is related to the life cycle because some of the things that we are using were discontinued. They were discontinued within a year after we had purchased it, which is a bit painful. If we had known that, we would've made some other decisions."
"Citrix SD-WAN's knowledge base has a few missing things, so you may need to seek help from support."
"I would like to either see the price reduced or have it packaged with other products to give better value for the money."
 

Pricing and Cost Advice

"The price of Fortinet FortiGate is the lowest in the market."
"Fortinet has more device options that are affordable for small businesses than Palo Alto, and its enterprise-level models are also cheaper. Palo Alto also has a separate license for VPN connections and SD-WAN, but FortiGate offers these features standard."
"Fortinet FortiGate is expensive."
"FortiGate Next Generation Firewall costs our company around $12000 per year."
"There is a need to pay for a license for the product."
"​We saved a bundle by not needing all the past appliances from an NGFW.​"
"The price of Fortinet FortiGate is better than Cisco, Check Point, and Palo Alto. In terms of pricing, it's probably a better-priced firewall solution overall."
"The license of Fortinet FortiGate should be reduced."
"We pay for the Cisco Customer Care support, which is a couple of hundred dollars."
"The cost of Cisco SD-WAN is high and has room for improvement compared to competitors such as Fortinet which has similar functionality."
"Cisco is more expensive than FortiGate."
"The license model is too complex with too many flavors and options. You might not be able to see it from an end user's point of view, but from a telco point of view, their license model is too complex. They should have a flexible license model. If you want to have good pricing, you need to buy it for a two-year, four-year, or five-year license immediately. Some other vendors have much more flexible license models."
"It is expensive. The license limitation is there in terms of bandwidth. Basically, Cisco is always good in terms of performance and related things. However, if you want to have a license, for example, for 100 Mbps, they charge you because of their 100 Mbps. If you want to go without the license of 300 Mbps, it is a bandwidth license as well. This is not happening with other vendors. That is the reason why we moved away from Cisco. The bill gets a little bit high. I do remember that one time we were trying to increase the bandwidth for at least five devices, and the license got as high as 20-grand for five devices, only for the license. It was expensive for us at the time. Our company is not a big company, but it is a solid company. The price was very high, and we moved away from Cisco because of the price."
"It's costly. The cost is high compared to competitors."
"The product's license is expensive."
"It is going to be on a yearly basis. There are no additional costs."
"I believe that Citrix SD-WAN is a good investment, but I do not have the information to be more specific."
"It would be helpful to have a demo license available for customers who want to prove the concept and conduct a proof of concept (POC) before committing to the solution. This is particularly important for customers in Egypt who often require a demonstration of the solution's features and compatibility with their needs before making any investment or incurring costs. Providing a demo license would allow customers to assess whether the solution would meet their needs or not."
"It depends on the scale. In our case, it would have been better if we had known about the life cycling steps, but otherwise, it is worth the money."
"As NetScaler is now, I find it quite pricey."
"The price is relatively expensive."
"It is a bit expensive. A cheaper product would be good, but everybody likes things to be cheaper. We bought the devices up front, and then we pay for the annual support."
"Citrix SD-WAN is quite an affordable product."
"The license was a one-time purchase. It's expensive."
report
Use our free recommendation engine to learn which Software Defined WAN (SD-WAN) Solutions solutions are best for your needs.
881,082 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
12%
Comms Service Provider
9%
Manufacturing Company
8%
Financial Services Firm
6%
Financial Services Firm
11%
Computer Software Company
11%
Manufacturing Company
8%
Comms Service Provider
7%
Computer Software Company
12%
Government
8%
Educational Organization
8%
Manufacturing Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business357
Midsize Enterprise133
Large Enterprise188
By reviewers
Company SizeCount
Small Business44
Midsize Enterprise15
Large Enterprise44
By reviewers
Company SizeCount
Small Business7
Midsize Enterprise5
Large Enterprise10
 

Questions from the Community

Which is the better NGFW: Fortinet Fortigate or Cisco Firepower?
When you compare these firewalls you can identify them with different features, advantages, practices and usage a...
What is the biggest difference between Sophos XG and FortiGate?
From my experience regarding both the Sophos and FortiGate firewalls, I personally would rather use FortiGate. I know...
What are the biggest technical differences between Sophos UTM and Fortinet FortiGate?
As a solution, Sophos UTM offers a lot of functionality, it scales well, and the stability and performance are quite ...
What do you like most about Cisco SD-WAN?
When considering the most valuable features of Cisco SD-WAN, the decoupling of self-monitoring stands out significant...
What is your experience regarding pricing and costs for Cisco SD-WAN?
The pricing of Cisco Catalyst SD-WAN is rated between eight and nine out of ten, where ten is the most expensive.
What needs improvement with Cisco SD-WAN?
More or less, it's the same with Cisco in terms of complexity and pricing, so there's not much of a difference. They ...
What needs improvement with Citrix SD-WAN?
The solution's licensing model could be improved. Citrix SD-WAN is a good product from a technical point of view. How...
What advice do you have for others considering Citrix SD-WAN?
If a customer already has Citrix NetScaler and is not looking to change anything in their existing environment, we pr...
 

Also Known As

Fortinet FortiGate Next-Generation Firewall
Cisco SD-WAN
Citrix CloudBridge, WOC, NetScaler SD-WAN
 

Overview

 

Sample Customers

Amazon Web Services, Microsoft, IBM, Cisco, Dell, HP, Oracle, Verizon, AT&T, T-Mobile, Sprint, Vodafone, Orange, BT Group, Telstra, Deutsche Telekom, Comcast, Time Warner Cable, CenturyLink, NTT Communications, Tata Communications, SoftBank, China Mobile, Singtel, Telus, Rogers Communications, Bell Canada, Telkom Indonesia, Telkom South Africa, Telmex, Telia Company, Telkom Kenya
Doyle Research, Ashton Metzler & Associates
AIDS Healthcare Foundation, Cornerstone Home Lending Inc., Dallara, ecVision, Essar, Eurofred, Groupe Promutuel, HMSHost Corporation, Royal Caribbean Cruise Lines Ltd, Royal Caribbean International
Find out what your peers are saying about Fortinet, Cisco, Check Point Software Technologies and others in Software Defined WAN (SD-WAN) Solutions. Updated: December 2025.
881,082 professionals have used our research since 2012.