Try our new research platform with insights from 80,000+ expert users

Cisco Secure Firewall vs Sangfor NGAF comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Jan 4, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Fortinet FortiGate
Sponsored
Ranking in Firewalls
1st
Average Rating
8.4
Reviews Sentiment
6.9
Number of Reviews
587
Ranking in other categories
Secure Web Gateways (SWG) (2nd), Intrusion Detection and Prevention Software (IDPS) (1st), Software Defined WAN (SD-WAN) Solutions (1st), WAN Edge (1st), ZTNA (1st), Unified Threat Management (UTM) (1st)
Cisco Secure Firewall
Ranking in Firewalls
5th
Average Rating
8.2
Reviews Sentiment
7.0
Number of Reviews
456
Ranking in other categories
Cisco Security Portfolio (3rd)
Sangfor NGAF
Ranking in Firewalls
26th
Average Rating
8.0
Reviews Sentiment
6.5
Number of Reviews
34
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of March 2026, in the Firewalls category, the mindshare of Fortinet FortiGate is 18.3%, down from 21.1% compared to the previous year. The mindshare of Cisco Secure Firewall is 7.5%, up from 5.5% compared to the previous year. The mindshare of Sangfor NGAF is 1.0%, down from 1.2% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Firewalls Mindshare Distribution
ProductMindshare (%)
Fortinet FortiGate18.3%
Cisco Secure Firewall7.5%
Sangfor NGAF1.0%
Other73.2%
Firewalls
 

Featured Reviews

Vasu Gala - PeerSpot reviewer
Manager, Information Technology Operation/Presales at TechMonarch
A stable solution with an intuitive interface and quick customer service
I have been working with Fortinet FortiGate, WatchGuard, Sophos, and SonicWall. I'm not as comfortable with SonicWall because of their UI and limitations. I prefer Fortinet above all other options. When it comes to configuration, I am confident in my ability to handle various tasks, including creating policies such as firewall rules, web policies, and application policies. Additionally, I can configure VPNs and implement load balancing, among other tasks. Overall, I feel much more comfortable working with Fortinet. Fortinet has made significant improvements by integrating AI with firewalls for threat analysis and prevention. In the past 2-3 years, they have launched FortiSASE and SIEM, and they also provide SOC services. Both Palo Alto and Fortinet FortiGate are excellent. While Fortinet FortiGate comes at higher prices, the functionality and support justify the cost. They promptly resolve firmware issues and inform all support providers about configuration changes.
Phil Shiflett - PeerSpot reviewer
Senior Manager, Network Engineering at TTi Power Equipment
Unified policies streamline network management but complex licensing requires attention
Cisco Secure Firewall has some growth opportunities in terms of visibility and control capabilities regarding managing encrypted traffic. It has the ability to analyze encrypted traffic, and there is potential for more integration with APIs and AI to enhance these capabilities. Cisco Secure Firewall needs improvement in deployment time and the capability to access the CLI during support calls. I often encounter issues when technical support uses a CLI that is not familiar to me while troubleshooting through the GUI. My ongoing complaint for the last six years has been the lack of CLI functionality, which hinders my ability to work on the firewall, alongside concerns regarding deployment time. For the next release, they should look at the features offered by competitors such as Fortinet, including the ability to perform packet capture directly from the interface. If they enhanced their troubleshooting efficiency related to packet capture for each specific rule, it would simplify the process significantly.
Zaid Farooqui - PeerSpot reviewer
CIO at Indus Motor Company
Enhanced threat detection with integrated security features and good support
We are using application firewalling, WAF, and SD-WAN. The capabilities are mostly within the box. For example, you will get web application firewall WAF as part and parcel of this. SD-WAN is also bundled. It integrates with their SIEM and SOAR solutions very nicely. Lastly, the pricing point is very cost-efficient as well.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The SD-WAN is the most valuable feature."
"All of the features of Fortinet FortiGate are useful and the security protection is good."
"The most useful features of Fortinet FortiGate IPS are you can create a virtual firewall within it, most other firewalls do not have this feature, you are able to manage your network and have network segmentation within your firewall, and additionally, you can create virtual switches within the firewall and have policy management, such as firewall and access policy."
"The main benefit I have seen from using Fortinet FortiGate is the protection it offers because I can see threats that come through in real-time, and if they are blocked, I can see that."
"This solution has helped our organization by having strong functions and a reliable firewall."
"The IPS is good. It protect my network from attackers."
"Throughout the last six years we have been using Fortigate firewalls, and the experience we gained is only positive."
"It has been very stable and reliable."
"The most valuable features for my client are the ASDM and monitoring."
"The remote access, VPN, and ACL features are valuable. We are using role-based access for individuals."
"Once you get the ASA set up properly, it can run for a whole year without any major issues, apart from the normal daily administration."
"Its VPN and ASN features are very stable."
"The AnyConnect VPN has solved a lot of remote access problems."
"It is one of the fastest solutions, if not the fastest, in the security technology space. This gives us peace of mind knowing that as soon as a new attack comes online that we will be protected in short order. From that perspective, no one really comes close now to Firepower, which is hugely valuable to us from an upcoming new attack prevention perspective."
"Its VPN and ASN features are very stable, and it is easy to configure."
"I have experience with URL filtering, and it is very good for URL filtering. You can filter URLs based on the categories, and it does a good job. It can also do deep packet inspection."
"The support from Sangfor NGAF here in Pakistan is great."
"We've found the technical support to be helpful."
"When it comes to the price of firewall solutions, Sangfor NGAF takes the cake, as it is cheaper than Fortinet, Sophos, Check Point and Palo Alto."
"It enables us to not only detect but also prevent various types of incoming threats, allowing us to take appropriate corrective actions and exercise control over the network."
"We are Sangfor Gold partners and I'd recommend this solution for the SMB market, as it is cost-effective and reliable."
"Sangfor NGAF's standout feature is its powerful application control, enabling precise restrictions on mobile user access to approved applications."
"In terms of the most valuable features, the IPS report is quick and updated. Performance is also valuable."
"The most valuable features are the WAN optimization, the internet access gateway (IAG), and the central console, which allows us to implement on their firewall."
 

Cons

"The solution could improve the integration."
"They could simplify their deployment process, especially when customers have existing devices."
"It can be a little bit more user-friendly in terms of policy definition and implementation. It seems a little bit complicated, and it could be simplified."
"We also have FortiAnalyzer deployed here, so we want to enable the soft functionality of FortiGate and built-in compression for a firewall VPN use case. We want the ability to deploy a gateway for HTTPS enabled on this firewall. It is currently only for use in our headquarters."
"When we cluster the two Fortinet FortiGate boxes together we have some issues."
"Fortinet FortiGate could be improved in terms of user friendliness at the policy level and assigning URL based and keyword based features."
"The configuration part was challenging, especially converting configurations from another OEM to FortiGate."
"FortiLink is the interface on the firewall that allows you to extend switch management across all of your switches in the network. The problem with it is that you can't use multiple interfaces unless you set them up in a lag. Only then you can run them. So, it forces you to use a core type of switch to propagate that management out to the rest of the switches, and then it is running the case at 200. It leaves you with 18 ports on the firewall because it is also a layer-three router that could also be used as a switch, but as soon as you do that, you can't really use them. They could do a little bit more clean up in the way the stacking interface works. Some use cases and the documentation on the FortiLink checking interface are a little outdated. I can find stuff on version 5 or more, but it is hard to find information on some of the newer firmware. The biggest thing I would like to see is some improvement in the switch management feature. I would like to be able to relegate some of the ports, which are on the firewall itself, to act as a switch to take advantage of those ports. Some of these firewalls have clarity ports on them. If I can use those, it would mean that I need to buy two less switches, which saves time. I get why they don't, but I would still like to see it because it would save a little bit of space in the server rack."
"We have encountered problems when implementing new signatures and new versions on our firewall. Sometimes, there is a short outage of our services, and we have not been able to understand what's going on. This is an area for improvement, and it would be good to have a way to monitor and understand why there is an outage."
"If I could improve Cisco Secure Firewall, I feel that even with my experience, I have difficulty navigating some of the logs and trying to find specific flows, whether it is the source address or the pre-NAT address."
"Stability issues due to memory issues in the cluster environment and Firepower misbehaved due to non-responding of service/process."
"If I want to activate IPS features on it, I have to buy another license. If I want Cisco AnyConnect, I have to buy another license. That's where we have challenges."
"The cloud does not precisely mimic what is on-premises."
"We found the initial setup much more difficult to do even simple things, like setting up VPN tunnels."
"Its user interface is good, but it could be better. Currently, you have to know what to do before you can manage a device. If you don't know what to do, you can mess things up. There are some devices that are easier, such as FortiGate. The user interface of FortiGate is more intuitive. It is very easy to log in and configure things."
"The pricing is quite high."
"The firewall system needs gradual improvements because there are more threats and challenges in the world every day."
"Sangfor NGAF could improve by refining its application control policies, especially in addressing challenges with certain types of applications."
"Our experience with its customer support was quite challenging."
"The reporting and log management could be improved."
"They need to improve their research team and they need to study their data to analyze it and build the product."
"I would be happy if Sangfor developed a firewall designed specifically for home use, as well as for small businesses such as clinics and so on. A household version of the Sangfor firewall for your personal computer or laptop would be ideal, in my opinion."
"Sangfor NGAF could improve the policies and default criteria. They could be much better."
"They need to increase the number of ports in the firewall."
 

Pricing and Cost Advice

"The price is relatively expensive compared to other solutions which are providing similar features."
"The value is the capability of having multiple services with one unique license, not having the limitation per user licensing schema, like other vendors."
"It is cheaper and more competitive compared to other options. For example, when comparing Palo Alto products to others, Palo Alto tends to be more expensive. If you compare Cisco's platform, including Cisco Meraki, with Fortinet products, you'll notice that Cisco's offerings are generally higher priced than Fortinet's firewall solutions."
"We are currently evaluating a Palo Alto solution, and the pricing could be a reason for going for Palo Alto."
"The pricing depends on the FortiGate model we are using, ranging from $3,000 to $20,000 US dollars."
"The price could be lower."
"While Fortinet FortiGate has a higher price point compared to Sophos XG, its user-friendly interface justifies the cost."
"Fortinet FortiGate is cost-efficient. Palo Alto is expensive, but Fortinet FortiGate is not."
"We have a perpetual license for all of our firewalls. For some of the features, we purchase them on demand. The pricing is decent but it could always be cheaper, we would be happier."
"Pricing is high, but it is essentially a corporate decision."
"Cisco is not for a small mom-and-pop shop because of the cost, but if you're in a regulated industry where a breach could cost you a million dollars, it's a bargain."
"This product requires licenses for advanced features including Snort, IPS, and malware detection."
"Pretty much everything is included in the price for what we are using."
"It's acceptable and comparable to other products."
"In terms of scalability, it is really expensive. It is scalable, but when it comes to pricing, the upgrading is a bit high."
"Licensing is not only for Secure Firewalls, and it's too complicated."
"It costs about 8 to 10 thousand dollars per year for 500 users, standard licensing fees included."
"In my opinion, the price of the tool is good in the Pakistani market. We can easily get discounts if needed."
"Sangfor is cheaper than competing vendors."
"The license of Sangfor NGAF can be purchased at different interval lengths, such as annually or three years. They offer a range of packages to choose from, such as combo or hybrid packages. We are using the complete solution package which includes IM, NGF and SSL VPN, and WAF."
"If you know you have around 200+ computer users on your network, then the Sangfor NGAF 5200-F-I model would be the minimum recommended model for that amount of users. This model includes modules for packet filtering, deep packet inspection, malware scanning, DSCP filtration, and many other features."
"For four to five physical appliances for a licensed firewall, it costs approximately $4,000."
"Price-wise, I would not consider Sangfor NGAF to be a cheap product. It is an expensive firewall solution, though not as expensive as something like Palo Alto, which is costly. However, the higher price point is justifiable given the feature set the tool provides that other firewalls may not offer in a single dedicated appliance."
"The price is unmatcheable."
report
Use our free recommendation engine to learn which Firewalls solutions are best for your needs.
885,264 professionals have used our research since 2012.
 

Comparison Review

it_user206346 - PeerSpot reviewer
Security Consultant at Webernetz.net - Network Security Consulting
Mar 11, 2015
Cisco ASA vs. Palo Alto Networks
Cisco ASA vs. Palo Alto: Management Goodies You often have comparisons of both firewalls concerning security components. Of course, a firewall must block attacks, scan for viruses, build VPNs, etc. However, in this post I am discussing the advantages and disadvantages from both vendors concerning…
 

Top Industries

By visitors reading reviews
Computer Software Company
11%
Comms Service Provider
10%
Manufacturing Company
8%
Financial Services Firm
6%
Computer Software Company
12%
Manufacturing Company
9%
Comms Service Provider
7%
University
6%
Manufacturing Company
12%
Financial Services Firm
8%
Comms Service Provider
8%
Computer Software Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business360
Midsize Enterprise135
Large Enterprise190
By reviewers
Company SizeCount
Small Business186
Midsize Enterprise129
Large Enterprise231
By reviewers
Company SizeCount
Small Business15
Midsize Enterprise10
Large Enterprise10
 

Questions from the Community

Which is the better NGFW: Fortinet Fortigate or Cisco Firepower?
When you compare these firewalls you can identify them with different features, advantages, practices and usage a...
What is the biggest difference between Sophos XG and FortiGate?
From my experience regarding both the Sophos and FortiGate firewalls, I personally would rather use FortiGate. I know...
What are the biggest technical differences between Sophos UTM and Fortinet FortiGate?
As a solution, Sophos UTM offers a lot of functionality, it scales well, and the stability and performance are quite ...
Which is better - Fortinet FortiGate or Cisco ASA Firewall?
One of our favorite things about Fortinet Fortigate is that you can deploy on the cloud or on premises. Fortinet Fort...
How does Cisco's ASA firewall compare with the Firepower NGFW?
It is easy to integrate Cisco ASA with other Cisco products and also other NAC solutions. When you understand the Cis...
Which is better - Meraki MX or Cisco ASA Firewall?
Cisco Adaptive Security Appliance (ASA) software is the operating software for the Cisco ASA suite. It supports netw...
What do you like most about Sangfor NGAF?
I think Sangfor NGAF is more valuable than Cisco products because of its simplicity and ease of management. If I comp...
What is your experience regarding pricing and costs for Sangfor NGAF?
The licensing cost is quite high compared to other available firewalls in the market.
What needs improvement with Sangfor NGAF?
The cost of licensing is very high compared to other firewalls available here. There should be improvements in hardwa...
 

Also Known As

Fortinet FortiGate Next-Generation Firewall
Cisco Adaptive Security Appliance (ASA) Firewall, Cisco ASA NGFW, Adaptive Security Appliance, Cisco Sourcefire Firewalls, Cisco ASAv, Cisco Firepower NGFW Firewall, Cisco Secure Firewall ASA Virtual - BYOL
Sangfor NGAF Firewall Platform
 

Overview

 

Sample Customers

Amazon Web Services, Microsoft, IBM, Cisco, Dell, HP, Oracle, Verizon, AT&T, T-Mobile, Sprint, Vodafone, Orange, BT Group, Telstra, Deutsche Telekom, Comcast, Time Warner Cable, CenturyLink, NTT Communications, Tata Communications, SoftBank, China Mobile, Singtel, Telus, Rogers Communications, Bell Canada, Telkom Indonesia, Telkom South Africa, Telmex, Telia Company, Telkom Kenya
There are more than one million Adaptive Security Appliances deployed globally. Top customers include First American Financial Corp., Genzyme, Frankfurt Airport, Hansgrohe SE, Rio Olympics, The French Laundry, Rackspace, and City of Tomorrow.
The Ministry of Science, Technology, and Innovation (Indonesia), Lawson, Inc. (Philippines), Universiti Sultan Zainal Abidin (Indonesia), TEK Automotive (Italy), etc.
Find out what your peers are saying about Cisco Secure Firewall vs. Sangfor NGAF and other solutions. Updated: March 2026.
885,264 professionals have used our research since 2012.